Project

General

Profile

Actions

Bug #317

closed

Invalid Rules

Added by Peter Manev over 12 years ago. Updated about 3 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
medium
Difficulty:
low
Label:

Description

Please find attached some tests with invalid rule keywords combinations (bad "grammar") that should not be loaded by the engine, nevertheless they are getting loaded.
modifiers and rule keywords - distance,within, depth, offset...

Snort corrected some of the issues they had - ""Improved error checking for invalid combinations of "depth", "offset", "distance", and "within" modifiers in rules. Rules that mix relative and non-relative options on the same content will now cause errors."" - http://blog.snort.org/2010/12/snort-2903-is-coming-soon.html
dated back in Dec 2010, some of them are still not addressed, I believe.

Please find a comparison of invalid rules and if they load or not. I have tested all the bad rules with Sur 1.0.4/1.0.5/git master, Snort 2.8.5.1/2.9.0.5/current beta, the results are in the spreadsheet attached.
Thanks


Files

InvalidRules.tar.bz2 (14.9 KB) InvalidRules.tar.bz2 Peter Manev, 08/19/2011 06:26 AM
InvalidRules.xls (13 KB) InvalidRules.xls Peter Manev, 08/19/2011 06:26 AM
InvalidRulesUpdated.xls (14 KB) InvalidRulesUpdated.xls Peter Manev, 10/31/2011 09:27 AM
InvalidRulesUpdatedwithCategories.xls (18.5 KB) InvalidRulesUpdatedwithCategories.xls Eileen Donlon, 11/04/2011 11:53 AM

Related issues 1 (0 open1 closed)

Related to Suricata - Bug #2982: invalid dsize distance rule being loaded by suricataClosedJeff LucovskyActions
Actions

Also available in: Atom PDF