Project

General

Profile

Actions

Bug #3772

closed
PA PA

DNP3 probing parser does not detect the proper direction in midstream

Bug #3772: DNP3 probing parser does not detect the proper direction in midstream

Added by Philippe Antoine almost 6 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:
Needs backport, Protocol

Description

From https://github.com/OISF/suricata/pull/5063/files#r438691794

Reproducer with attached pcap, run with --set stream.midstream=true

DNP3ProbingParser should set *rdir = 1 with the right conditions
Wireshark filter dnp3.ctl & 0x80 indicates a request


Files

dnp3_confirm.pcap (121 Bytes) dnp3_confirm.pcap Philippe Antoine, 06/16/2020 07:30 AM

Related issues 2 (0 open2 closed)

Copied to Suricata - Bug #3793: DNP3 probing parser does not detect the proper direction in midstreamRejectedActions
Copied to Suricata - Bug #3794: DNP3 probing parser does not detect the proper direction in midstreamClosedJeff LucovskyActions

PA Updated by Philippe Antoine almost 6 years ago Actions #1

  • Status changed from New to In Review
  • Assignee set to Philippe Antoine

JL Updated by Jeff Lucovsky almost 6 years ago Actions #2

  • Copied to Bug #3793: DNP3 probing parser does not detect the proper direction in midstream added

JL Updated by Jeff Lucovsky almost 6 years ago Actions #3

  • Copied to Bug #3794: DNP3 probing parser does not detect the proper direction in midstream added

VJ Updated by Victor Julien almost 6 years ago Actions #4

  • Target version set to 6.0.0beta1

VJ Updated by Victor Julien almost 6 years ago Actions #5

  • Status changed from In Review to Closed

PA Updated by Philippe Antoine over 5 years ago Actions #6

  • Status changed from Closed to In Review

PA Updated by Philippe Antoine over 5 years ago Actions #7

  • Target version changed from 6.0.0beta1 to 6.0.0rc1

VJ Updated by Victor Julien over 5 years ago Actions #8

  • Target version changed from 6.0.0rc1 to 6.0.0

VJ Updated by Victor Julien over 5 years ago Actions #9

  • Status changed from In Review to Closed
Actions

Also available in: PDF Atom