Actions
Bug #208
closedregression v100 and git today cause FN
Affected Versions:
Effort:
Difficulty:
Label:
Description
Hi,
Congratulations for first Suricata release.
with two rules and joigned pcap file, I have a FN (no alert):
alert tcp any any -> any 25 (msg:"suricata smtp"; flow:to_server,established; content:"EHLO "; nocase; depth:5; classtype:attempted-user; sid:9404481; rev:1;)
alert tcp any any <> any 0 (msg:"BAD TRAFFIC tcp port 0 traffic"; flow:stateless; classtype:misc-activity; sid:524; rev:8;)
If you disable (second) sid 524, (first) sid 9404481 fire.
tested with v1.0.0 and git today (102092a89c8c48080853e9402325b4ee0e114697).
no FN (alert) on v0.9.2 or v0.9.1.
Please Check.
Regards
Rmkml
Files
Actions