Solaris Class Unix_Map; Solaris Class Unix_Guid - McAfee HISCDE-AB-IA - Host Intrusion Prevention Product Manual

Product guide for use with epolicy orchestrator 4.5
Table of Contents

Advertisement

Appendix A — Writing Custom Signatures and Exceptions
Non-Windows custom signatures
... }
would apply only to the file in the zone "app_zone" and not in the global zone.
Note that in this release, web server protection cannot be restricted to a particular zone.

Solaris class UNIX_map

The following table lists the possible sections and values for the Solaris class Unix_map:
Section
Class
Id
level
time
user_name
Executable
zone
directives

Solaris class UNIX_GUID

The following table lists the possible sections and values for the Solaris class UNIX_GUID:
Section
Class
Id
level
time
user_name
Executable
zone
directives
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
Values
UNIX_map
See Common sections .
Name of the zone to which the
signature applies
mmap:mprotect
mmap:mmap
Values
UNIX_GUID
See Common sections .
Name of the zone to which the
signature applies
guid:setuid
guid:seteuid
guid:setreuid
guid:setgid
guid:setegid
Notes
Use this class to map UNIX files or devices into
memory.
Solaris 10 or later.
Sets the access protection of memory pages.
Maps files or devices into memory.
Notes
Use this class to set Unix access rights flags that
allow users to run an executable with the
permissions of the executable's owner or group.
Solaris 10 or later.
Sets user ID to allow a user to run an executable
with the permissions of the executable's owner.
Sets effective user ID.
Sets the real and effective user ID.
Sets group ID to allow a group to run an
executable with the permissions of the
executable's group.
Sets effective group ID.
133

Advertisement

Table of Contents
loading

This manual is also suitable for:

Host intrusion prevention 8.0

Table of Contents