Project

General

Profile

Actions

Bug #366

closed

suppress (threshold.config) does not work with "track by_src"

Added by Peter Manev about 13 years ago. Updated about 13 years ago.

Status:
Closed
Priority:
High
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

As pointed out by David Wharton, there is a problem with "track by_src" when using suppress rules in threshold.config
It does work when using "track by_dst".

1.1beta3 (rev 7bf1de0)

to test (generate an alert) the particular rule you should use
root# wget silverlight.dlservice.microsoft.com/download/D/C/2/DC2D5838-9138-4D25-AA92-52F61F7C51E6/runtime/Silverlight.exe

version 1.1beta3 (rev 18da4a8)
behaves the same way

thanks


Files

suricata.yaml (25.4 KB) suricata.yaml Peter Manev, 11/01/2011 11:07 AM
threshold.config (309 Bytes) threshold.config Peter Manev, 11/01/2011 11:07 AM
supress.rule (219 Bytes) supress.rule Peter Manev, 11/01/2011 11:07 AM
suppresstest.pcap (2.14 KB) suppresstest.pcap Peter Manev, 11/02/2011 03:48 AM
supress.rule (219 Bytes) supress.rule Peter Manev, 11/02/2011 03:48 AM
threshold.config (1.07 KB) threshold.config Peter Manev, 11/02/2011 03:48 AM
suricata.yaml (25.4 KB) suricata.yaml Peter Manev, 11/02/2011 03:48 AM
0001-threshold-introduce-SigGetThresholdTypeIter-function.patch (2.96 KB) 0001-threshold-introduce-SigGetThresholdTypeIter-function.patch Eric Leblond, 11/02/2011 09:31 AM
0002-threshold-fix-thresholding-on-signature-with-multipl.patch (1.57 KB) 0002-threshold-fix-thresholding-on-signature-with-multipl.patch Eric Leblond, 11/02/2011 09:31 AM
Actions

Also available in: Atom PDF