Project

General

Profile

Actions

Bug #3780

open

Negated content with distance FP

Added by Francis Trudeau over 2 years ago. Updated about 2 months ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:
Needs backport to 6.0

Description

The following signature:

alert udp any any -> any any (msg:"Negated content with distance test"; content:"|C0 0C 00 10 00 01|"; content:!"v=spf"; distance:0; sid:30303; rev:1;)

This rule alerts on the attached pcap. The attached pcap has 'v=spf' in the packet after the hex content in the signature.

Tested with 6.0.0-dev (e5fd47dcf 2020-05-01), 5.0.3, 4.1.8, 4.0.7.


Files

negated_content_distance.pcap (708 Bytes) negated_content_distance.pcap Francis Trudeau, 06/24/2020 05:12 PM

Subtasks 1 (1 open0 closed)

Task #5482: create SV tests to demonstrate false positive behavior for negated content and distance (bug 3780)NewOISF DevActions
Actions #1

Updated by Victor Julien about 2 months ago

  • Status changed from New to Assigned
  • Assignee set to Victor Julien
  • Priority changed from Normal to High
  • Target version set to 7.0rc1
  • Label Needs backport to 6.0 added
Actions #2

Updated by Juliana Fajardini Reichow about 2 months ago

  • Related to Task #5482: create SV tests to demonstrate false positive behavior for negated content and distance (bug 3780) added
Actions #3

Updated by Victor Julien about 2 months ago

  • Subtask #5482 added
Actions

Also available in: Atom PDF