Project

General

Profile

Actions

Feature #1514

closed

SSH softwareversion regex should allow colon

Added by Antti Tönkyrä about 7 years ago. Updated about 7 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Trojaned PuTTY builds have become more common recently, one method to catch some of them is to look for the version string. Current master does not always allow this since : is not a valid character for ssh.softwareversion. (ex. Putty-Local: Timestamp HH:MM:SS)

I made a pull request on GitHub regarding the issue at https://github.com/inliniac/suricata/pull/1491

Actions #1

Updated by Victor Julien about 7 years ago

  • Target version set to 3.0RC1
Actions #2

Updated by Victor Julien about 7 years ago

  • Status changed from New to Assigned
  • Assignee set to Antti Tönkyrä
Actions #3

Updated by Victor Julien about 7 years ago

  • Status changed from Assigned to Closed
  • % Done changed from 0 to 100
Actions

Also available in: Atom PDF