McAfee HISCDE-AB-IA Product Guide - Page 106

Table 25: MS SQL Database Server, Table 26: Unix Apache and iPlanet, Description, Variable

Page 106 highlights

Appendix A - Writing Custom Signatures and Exceptions Rule structure Variable IIS_Exe_Dirs IIS_Ftp_Dir IIS_FTP_USR IIS_FtpLogDir IIS_IUSR IIS_IUSRD IIS_IWAM IIS_LogFileDir IIS_LVirt_Root IIS_Processes IIS_Services Table 25: MS SQL Database Server Variable MSSQL_Allowed_Access_Paths MSSQL_Allowed_Execution_Paths MSSQL_Allowed_Modification_Paths MSSQL_Auxiliary_Services MSSQL_Core_Services MSSQL_Data_Paths MSSQL_DataRoot_Paths MSSQL_Instances MSSQL_Registry_Paths Table 26: Unix Apache and iPlanet Variable UAPACHE_Bins UAPACHE_CgiRoots UAPACHE_ConfDirs UAPACHE_DocRoots UAPACHE_Logs UAPACHE_Logs_dir UAPACHE_Roots UAPACHE_Users UAPACHE_VcgiRoots Description Virtual directories that allow file execution including system root and IIS root" FTP site root directories Local ftp Anonymous user account name FTP log files directory Local web anonymous user account name Domain web anonymous user account name The IIS Web Application Manager user account name Web log files directory All IIS virtual directories Processes with access rights to IIS resources All the services needed for IIS to work properly Description Directories like \WINNT and \WINNT\System32 that are accessible Directories like \WINNT and \WINNT\System32 that are executable Directories like \WINNT\Temp that are modifiable The auxiliary MS SQL services found on the system The core MS SQL services found on the system All other data files associated with MS SQL that may be outside of the MSSQL_DataRoot_Path directory The path to the MS SQL data files for each instance The name of each installed MS SQL instance All registry locations associated with MS SQL Description Path to Apache binaries Path to CGI roots Directories containing Apache configuration files Path to document roots Apache log files Log file directory Apache web roots Users that Apache runs as Path to CGI roots of virtual servers 106 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Description
Variable
Virtual directories that allow file execution including system
root and IIS root"
IIS_Exe_Dirs
FTP site root directories
IIS_Ftp_Dir
Local ftp Anonymous user account name
IIS_FTP_USR
FTP log files directory
IIS_FtpLogDir
Local web anonymous user account name
IIS_IUSR
Domain web anonymous user account name
IIS_IUSRD
The IIS Web Application Manager user account name
IIS_IWAM
Web log files directory
IIS_LogFileDir
All IIS virtual directories
IIS_LVirt_Root
Processes with access rights to IIS resources
IIS_Processes
All the services needed for IIS to work properly
IIS_Services
Table 25: MS SQL Database Server
Description
Variable
Directories like \WINNT and \WINNT\System32 that are
accessible
MSSQL_Allowed_Access_Paths
Directories like \WINNT and \WINNT\System32 that are
executable
MSSQL_Allowed_Execution_Paths
Directories like \WINNT\Temp that are modifiable
MSSQL_Allowed_Modification_Paths
The auxiliary MS SQL services found on the system
MSSQL_Auxiliary_Services
The core MS SQL services found on the system
MSSQL_Core_Services
All other data files associated with MS SQL that may be
outside of the MSSQL_DataRoot_Path directory
MSSQL_Data_Paths
The path to the MS SQL data files for each instance
MSSQL_DataRoot_Paths
The name of each installed MS SQL instance
MSSQL_Instances
All registry locations associated with MS SQL
MSSQL_Registry_Paths
Table 26: Unix Apache and iPlanet
Description
Variable
Path to Apache binaries
UAPACHE_Bins
Path to CGI roots
UAPACHE_CgiRoots
Directories containing Apache configuration files
UAPACHE_ConfDirs
Path to document roots
UAPACHE_DocRoots
Apache log files
UAPACHE_Logs
Log file directory
UAPACHE_Logs_dir
Apache web roots
UAPACHE_Roots
Users that Apache runs as
UAPACHE_Users
Path to CGI roots of virtual servers
UAPACHE_VcgiRoots
Appendix A — Writing Custom Signatures and Exceptions
Rule structure
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
106