Project

General

Profile

Actions

Feature #2213

open

file matching: allow generic file matching / store

Added by Victor Julien about 4 years ago. Updated almost 4 years ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Currently if you want to match on all protocols Suricata supports for file matching you need a rule for each protocol:

alert http .... filename:"blah";
alert smtp .... filename:"blah";
...

Perhaps 'alert tcp ... filename:"blah"' would be enough.
Or perhaps use 'alert file ... filename:"blah"' as a special protocol.


Related issues

Related to Bug #2249: rule with file keyword used with ip or tcp not seen as invalidNewOISF DevActions
Actions #1

Updated by Andreas Herz about 4 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD

If we want to stay consistent I would prefer alert ip so it's similiar to normal rules.

Actions #2

Updated by Eric Leblond almost 4 years ago

This feature is also a bug as there is no warning on a rule like:

alert ip any any -> any any (msg:"guess what"; filemd5:test.md5; sid: 1; rev: 1;)

Which is a non working rule.

Actions #3

Updated by Victor Julien almost 4 years ago

Please open a separate ticket for that.

Actions #4

Updated by Victor Julien about 2 years ago

  • Related to Bug #2249: rule with file keyword used with ip or tcp not seen as invalid added
Actions

Also available in: Atom PDF