McAfee HISCDE-AB-IA Product Guide - Page 133

Solaris class UNIX_map

Page 133 highlights

Appendix A - Writing Custom Signatures and Exceptions Non-Windows custom signatures ... } would apply only to the file in the zone "app_zone" and not in the global zone. Note that in this release, web server protection cannot be restricted to a particular zone. Solaris class UNIX_map The following table lists the possible sections and values for the Solaris class Unix_map: Section Class Id level time user_name Executable zone directives Values UNIX_map See Common sections. Notes Use this class to map UNIX files or devices into memory. Name of the zone to which the Solaris 10 or later. signature applies mmap:mprotect Sets the access protection of memory pages. mmap:mmap Maps files or devices into memory. Solaris class UNIX_GUID The following table lists the possible sections and values for the Solaris class UNIX_GUID: Section Class Id level time user_name Executable zone directives Values UNIX_GUID See Common sections. Notes Use this class to set Unix access rights flags that allow users to run an executable with the permissions of the executable's owner or group. Name of the zone to which the Solaris 10 or later. signature applies guid:setuid Sets user ID to allow a user to run an executable with the permissions of the executable's owner. guid:seteuid Sets effective user ID. guid:setreuid Sets the real and effective user ID. guid:setgid Sets group ID to allow a group to run an executable with the permissions of the executable's group. guid:setegid Sets effective group ID. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 133

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

... }
would apply only to the file in the zone "app_zone" and not in the global zone.
Note that in this release, web server protection cannot be restricted to a particular zone.
Solaris class UNIX_map
The following table lists the possible sections and values for the Solaris class Unix_map:
Notes
Values
Section
Use this class to map UNIX files or devices into
memory.
UNIX_map
Class
See
Common sections
.
Id
level
time
user_name
Executable
Solaris 10 or later.
Name of the zone to which the
signature applies
zone
Sets the access protection of memory pages.
mmap:mprotect
directives
Maps files or devices into memory.
mmap:mmap
Solaris class UNIX_GUID
The following table lists the possible sections and values for the Solaris class UNIX_GUID:
Notes
Values
Section
Use this class to set Unix access rights flags that
allow users to run an executable with the
permissions of the executable's owner or group.
UNIX_GUID
Class
See
Common sections
.
Id
level
time
user_name
Executable
Solaris 10 or later.
Name of the zone to which the
signature applies
zone
Sets user ID to allow a user to run an executable
with the permissions of the executable's owner.
guid:setuid
directives
Sets effective user ID.
guid:seteuid
Sets the real and effective user ID.
guid:setreuid
Sets group ID to allow a group to run an
executable with the permissions of the
executable's group.
guid:setgid
Sets effective group ID.
guid:setegid
Appendix A — Writing Custom Signatures and Exceptions
Non-Windows custom signatures
133
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5