Project

General

Profile

Actions

Bug #3772

closed

DNP3 probing parser does not detect the proper direction in midstream

Added by Philippe Antoine over 4 years ago. Updated about 4 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:
Needs backport, Protocol

Description

From https://github.com/OISF/suricata/pull/5063/files#r438691794

Reproducer with attached pcap, run with --set stream.midstream=true

DNP3ProbingParser should set *rdir = 1 with the right conditions
Wireshark filter dnp3.ctl & 0x80 indicates a request


Files

dnp3_confirm.pcap (121 Bytes) dnp3_confirm.pcap Philippe Antoine, 06/16/2020 07:30 AM

Related issues 2 (0 open2 closed)

Copied to Suricata - Bug #3793: DNP3 probing parser does not detect the proper direction in midstreamRejectedActions
Copied to Suricata - Bug #3794: DNP3 probing parser does not detect the proper direction in midstreamClosedJeff LucovskyActions
Actions #1

Updated by Philippe Antoine over 4 years ago

  • Status changed from New to In Review
  • Assignee set to Philippe Antoine
Actions #2

Updated by Jeff Lucovsky over 4 years ago

  • Copied to Bug #3793: DNP3 probing parser does not detect the proper direction in midstream added
Actions #3

Updated by Jeff Lucovsky over 4 years ago

  • Copied to Bug #3794: DNP3 probing parser does not detect the proper direction in midstream added
Actions #4

Updated by Victor Julien over 4 years ago

  • Target version set to 6.0.0beta1
Actions #5

Updated by Victor Julien over 4 years ago

  • Status changed from In Review to Closed
Actions #6

Updated by Philippe Antoine over 4 years ago

  • Status changed from Closed to In Review
Actions #7

Updated by Philippe Antoine over 4 years ago

  • Target version changed from 6.0.0beta1 to 6.0.0rc1
Actions #8

Updated by Victor Julien over 4 years ago

  • Target version changed from 6.0.0rc1 to 6.0.0
Actions #9

Updated by Victor Julien about 4 years ago

  • Status changed from In Review to Closed
Actions

Also available in: Atom PDF