Project

General

Profile

Actions

Feature #1017

closed

Add support for content-range

Added by Eric Leblond about 9 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Effort:
Difficulty:
Label:

Description

The 'Content-Range' is currently not supported by libhtp. For suricata this means that the information that 'Content-Range' has been used in a request is not seen anywhere. This is an issue for file extraction. There is no possible strategy to rebuild easily a binary with an external script if the content information is not present.

An other point is that this could trigger error on md5sum checking. For example, if an alert fires when a unknown file is downloaded from a server (by checking md5 list) then using 'Content-Range' will lead to a different md5 and then result in an invalid alert. Regarding this point, adding a simple header match to 'Content-Range' could help not to fire.

To add this support, libhtp would need to be patched and then suricata will need to be updated.


Related issues 1 (0 open1 closed)

Is duplicate of Feature #1576: http: byte-range supportClosedPhilippe AntoineActions
Actions #2

Updated by Andreas Herz about 7 years ago

  • Assignee set to OISF Dev
Actions #3

Updated by Victor Julien about 7 years ago

Related to #1576

Actions #4

Updated by Victor Julien almost 4 years ago

Actions #5

Updated by Victor Julien about 3 years ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Philippe Antoine
  • Target version changed from TBD to 6.0.0beta1
Actions #6

Updated by Philippe Antoine about 3 years ago

To me, this is a duplicate of #1576
Am I missing something ?

Actions #7

Updated by Philippe Antoine almost 3 years ago

  • Status changed from Assigned to In Review
Actions #8

Updated by Philippe Antoine over 2 years ago

  • Status changed from In Review to Closed
  • Target version changed from 6.0.0beta1 to TBD
Actions #9

Updated by Victor Julien over 2 years ago

  • Assignee deleted (Philippe Antoine)
  • Target version deleted (TBD)
Actions #10

Updated by Victor Julien over 2 years ago

Actions #11

Updated by Victor Julien over 2 years ago

Actions

Also available in: Atom PDF