Project

General

Profile

Actions

Feature #341

closed

urilen option to match on raw uri

Added by Victor Julien about 13 years ago. Updated almost 13 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

By default Suricata's urilen matches on the normalized buffer. Snort 2.9.1 added support for matching on both the raw and normalized buffers:

urilen:min<>max[,<uribuf>];
urilen:[<|>]<number>[,<uribuf>];
<uribuf> : "norm" | "raw" 

It seems that Snort selects the raw uri by default.


Files

Actions

Also available in: Atom PDF