McAfee HISCDE-AB-IA Product Guide - Page 123

Classes and directives per Windows platform, Windows 2003, R2, R2 SP2, 32- and 64-bit 2K3

Page 123 highlights

Appendix A - Writing Custom Signatures and Exceptions Windows custom signatures Section db_user_name sp_name sp_param_char_len_one... sp_param_one... sp_param_orign_len-one... sql_line_comment sql_original_query sql_query sql_user_password transport directives Values Notes Name of the user if SQL authentication was used, and "Trusted User" if Windows authentication is used. Example: sa Stored procedure name. This should match a stored procedure name. A stored procedure is identified by a supplied list of procedure names that is included for every SQL agent release (currently SPList.txt in the Agent directory). Contains the length of the parameter in number of characters. Contains the value of the parameter. Contains the length of the parameter in number of bytes. This value is set to 1 if the query includes a single line comment "-" containing a single quote. This contains the full SQL query exactly as it was received (including strings and whitespaces). This is the SQL query string with string values, whitespaces, and everything behind the comments stripped out. This is set to 1 if the password This is always be set to 0 for non-SQL users. is NULL and 0 otherwise. On MSSQL 2005/2008, this is hard coded to: Shared memory (LPC). sql:request. For incoming SQL requests Classes and directives per Windows platform A list of the effective classess and directives per Windows platform: • Windows XP, SP2, SP3, 32- and 64-bit (XP) • Windows 2003, R2, R2 SP2, 32- and 64-bit (2K3) • Windows Vista, 32- and 64-bit (V) • Windows 2008 R2, (32- and 64-bit (2K8) • Windows 7, 32- and 64-bit (7) McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 123

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Notes
Values
Section
Example: sa
Name of the user if SQL
authentication was used, and
db_user_name
"Trusted User" if Windows
authentication is used.
This should match a stored procedure name. A
stored procedure is identified by a supplied list of
Stored procedure name.
sp_name
procedure names that is included for every SQL
agent release (currently SPList.txt in the Agent
directory).
Contains the length of the
parameter in number of
characters.
sp_param_char_len_one...
Contains the value of the
parameter.
sp_param_one...
Contains the length of the
parameter in number of bytes.
sp_param_orign_len-one...
This value is set to 1 if the query
includes a single line comment
"-" containing a single quote.
sql_line_comment
This contains the full SQL query
exactly as it was received
sql_original_query
(including strings and
whitespaces).
This is the SQL query string with
string values, whitespaces, and
sql_query
everything behind the comments
stripped out.
This is always be set to 0 for non-SQL users.
This is set to 1 if the password
is NULL and 0 otherwise.
sql_user_password
On MSSQL 2005/2008, this is
hard coded to: Shared memory
(LPC).
transport
For incoming SQL requests
sql:request.
directives
Classes and directives per Windows platform
A list of the effective classess and directives per Windows platform:
Windows XP, SP2, SP3, 32- and 64-bit (XP)
Windows 2003, R2, R2 SP2, 32- and 64-bit (2K3)
Windows Vista, 32- and 64-bit (V)
Windows 2008 R2, (32- and 64-bit (2K8)
Windows 7, 32- and 64-bit (7)
Appendix A — Writing Custom Signatures and Exceptions
Windows custom signatures
123
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5