Project

General

Profile

Actions

Support #1532

closed

File Extraction but truncate into several file.x and file.x.meta

Added by hao chen over 8 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:

Description

when I use suricata2.1beta4 to file_extraction, I used my chrome to download a PDF document, the document is 981.1kb . But the result is the pdf document truncated into several file.x (1 to 20),and these total size of the files are 1.1mb, I could not understand why. I'm poor in English, but hope you can understand what I mean.


Files

files.rules (3.14 KB) files.rules file rules hao chen, 10/08/2015 01:28 AM
suricata.yaml (49 KB) suricata.yaml config yaml hao chen, 10/08/2015 01:28 AM
test2.pcap (7.73 MB) test2.pcap pcap file hao chen, 10/12/2015 07:24 PM
test3.pcap (1.05 MB) test3.pcap hao chen, 10/15/2015 11:27 AM
eve.json (28.4 KB) eve.json hao chen, 10/15/2015 11:30 AM
files-json.log (3.84 KB) files-json.log hao chen, 10/15/2015 11:30 AM
file.1.meta (633 Bytes) file.1.meta hao chen, 10/15/2015 11:31 AM
file.2.meta (633 Bytes) file.2.meta hao chen, 10/15/2015 11:31 AM
file.1 (64 KB) file.1 hao chen, 10/15/2015 11:31 AM
file.2 (775 KB) file.2 hao chen, 10/15/2015 11:31 AM
Actions #1

Updated by Victor Julien over 8 years ago

  • Priority changed from Immediate to Normal

Are you able to reproduce this behaviour with a pcap recording on the PDF transfer?

Updated by hao chen over 8 years ago

I have lose some data by using Suricata 2.0.9 file extraction with a pcap recording on the PDF transfer, some of my wanted file ware truncated into several file.x and file.x.meta, these truncated files is not full.
suricata pcap url : http://pan.baidu.com/s/1i3AkDA9

Actions #3

Updated by hao chen over 8 years ago

this is my eve.json file url:http://pan.baidu.com/s/1dDDGPOl

Actions #4

Updated by Peter Manev over 8 years ago

Apologies for double posting - but i answered to the wrong ticket before.

That could explain why is it truncated.
Can you try to reproduce that with a much smaller pcap (than 1.5GB)?

Actions #5

Updated by hao chen over 8 years ago

before that , can you tell me my files.rules and suricata.yaml is right?

Actions #7

Updated by Peter Manev over 8 years ago

Can you please try to narrow it down to one pcap/one pdf (with an md5 sum) case.

From what I am seeing there is none of the size of the pdfs that you are quoting in that pcap (I tried even looking with different file carving tools tools). There is some size but not the one that is supported to be - from what you mentioned before.

Updated by hao chen over 8 years ago

First, I'm sorry to make some troubles for you to explain my question and thank you very much for your patience. This time I produce a pcap with single pdf using the suricata.yaml and files.rules above. And the eve.json generated when I used suricata to read pcap. The result files is two.The pdf url is : http://www.freescale.com/files/analog/doc/data_sheet/MC145018.pdf, I used firefox to download it.

Actions #9

Updated by Peter Manev over 8 years ago

Actions #10

Updated by Victor Julien over 7 years ago

  • Assignee deleted (Victor Julien)
Actions #11

Updated by Andreas Herz over 7 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD
Actions #12

Updated by Victor Julien over 5 years ago

  • Status changed from New to Closed
  • Assignee deleted (OISF Dev)
  • Target version deleted (TBD)
Actions

Also available in: Atom PDF