Actions
Bug #2528
closed
JT
PC
krb parser not always parsing tgs responses
Bug #2528:
krb parser not always parsing tgs responses
Affected Versions:
Effort:
Difficulty:
Label:
Description
I am testing out the krb5 parser and I am seeing what appear to be
inconsistent results.
One pcap (krb5.good.pcap) parses out the tgs response in the json log.
The second pcap (krb5.bad.pcap) doesn't parse out the tgs response in
the json log.
Attached are the logs from the suricata runs, build info and pcaps.
After some initial troubleshooting in IRC, victorj/pollux said it looks like there is an issue in krb5 parser as well as possibly something additional in suricata.
Files
Actions