https://redmine.openinfosecfoundation.org/
https://redmine.openinfosecfoundation.org/favicon.ico?1701117002
2010-12-29T00:04:51Z
Open Information Security Foundation
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=982
2010-12-29T00:04:51Z
delta yeh
delta.yeh@gmail.com
<ul></ul><p>how about</p>
<p>app-layer-modules:<br /> -http<br /> -ftp<br /> -ssh</p>
<p>those module not in this list would not be enabled.</p>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=998
2011-01-05T12:08:04Z
Victor Julien
victor@inliniac.net
<ul></ul><p>I think I would prefer something like:</p>
<p>app-layer-parsers:<br /> - http<br /> enabled: yes<br /> - ftp<br /> enabled: no</p>
<p>This would allow us to add other options to them...</p>
<p>Thoughts?</p>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=1131
2011-05-24T22:25:42Z
delta yeh
delta.yeh@gmail.com
<ul></ul><p>Victor Julien wrote:</p>
<blockquote>
<p>I think I would prefer something like:</p>
<p>app-layer-parsers:<br />- http<br />enabled: yes<br />- ftp<br />enabled: no</p>
<p>This would allow us to add other options to them...</p>
<p>Thoughts?</p>
</blockquote>
<p>Sounds good to me!</p>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=1151
2011-06-23T05:19:44Z
Victor Julien
victor@inliniac.net
<ul><li><strong>Assignee</strong> changed from <i>Victor Julien</i> to <i>Anonymous</i></li></ul><p>This would be fairly easy to implement as we can just disable the parser registration for the disabled protocols.</p>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=1309
2011-10-28T10:30:34Z
delta yeh
delta.yeh@gmail.com
<ul></ul><p>Victor Julien wrote:</p>
<blockquote>
<p>This would be fairly easy to implement as we can just disable the parser registration for the disabled protocols.</p>
</blockquote>
<p>I will take this.</p>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=1371
2011-11-07T11:26:11Z
Victor Julien
victor@inliniac.net
<ul><li><strong>Status</strong> changed from <i>New</i> to <i>Assigned</i></li><li><strong>Assignee</strong> changed from <i>Anonymous</i> to <i>delta yeh</i></li><li><strong>Target version</strong> set to <i>1.2</i></li></ul><p>Cool, thanks!</p>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=1505
2012-01-05T10:10:21Z
Victor Julien
victor@inliniac.net
<ul><li><strong>Target version</strong> changed from <i>1.2</i> to <i>TBD</i></li></ul><p>Have you been able to look into this?</p>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=2095
2012-08-23T03:13:05Z
Victor Julien
victor@inliniac.net
<ul><li><strong>Assignee</strong> changed from <i>delta yeh</i> to <i>Anoop Saldanha</i></li><li><strong>Target version</strong> changed from <i>TBD</i> to <i>1.4beta2</i></li></ul>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=2261
2012-09-29T03:07:22Z
Victor Julien
victor@inliniac.net
<ul><li><strong>Target version</strong> changed from <i>1.4beta2</i> to <i>1.4beta3</i></li></ul>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=2437
2012-11-01T07:16:16Z
Victor Julien
victor@inliniac.net
<ul><li><strong>Priority</strong> changed from <i>Normal</i> to <i>Low</i></li></ul>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=2489
2012-11-14T12:08:43Z
Victor Julien
victor@inliniac.net
<ul><li><strong>Target version</strong> changed from <i>1.4beta3</i> to <i>1.4rc1</i></li></ul>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=2536
2012-11-26T12:18:11Z
Anoop Saldanha
anoopsaldanha@gmail.com
<ul></ul><p><a class="external" href="https://github.com/inliniac/suricata/pull/222">https://github.com/inliniac/suricata/pull/222</a></p>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=2554
2012-11-29T05:21:14Z
Victor Julien
victor@inliniac.net
<ul><li><strong>Target version</strong> changed from <i>1.4rc1</i> to <i>2.0rc2</i></li></ul>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=2779
2013-02-06T21:20:38Z
Anoop Saldanha
anoopsaldanha@gmail.com
<ul></ul><p><a class="external" href="https://github.com/inliniac/suricata/pull/279">https://github.com/inliniac/suricata/pull/279</a></p>
<p>The above PR does a lot more than provide a feature to enable/disable app layer modules.</p>
<p>We have an update PP proto detection engine, feature to enable proto detection/parser both of which are now separate options in the conf file, ability to specify detection ports in conf file, sig port validation.</p>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=3129
2013-07-09T07:12:14Z
Victor Julien
victor@inliniac.net
<ul><li><strong>Priority</strong> changed from <i>Low</i> to <i>Normal</i></li><li><strong>Target version</strong> changed from <i>2.0rc2</i> to <i>2.0beta2</i></li></ul>
Suricata - Feature #234: add option disable/enable individual app layer protocol inspection modules
https://redmine.openinfosecfoundation.org/issues/234?journal_id=3477
2013-10-08T11:12:49Z
Anoop Saldanha
anoopsaldanha@gmail.com
<ul><li><strong>Status</strong> changed from <i>Assigned</i> to <i>Closed</i></li></ul><p>Fix merged -</p>
<p><a class="external" href="https://github.com/inliniac/suricata/pull/567">https://github.com/inliniac/suricata/pull/567</a><br /><a class="external" href="https://buildbot.suricata-ids.org/builders/poona/builds/9">https://buildbot.suricata-ids.org/builders/poona/builds/9</a></p>