Project

General

Profile

Actions

Bug #404

closed

FN with suricata v121 and POP3 reply question

Added by rmkml rmkml about 12 years ago. Updated almost 12 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Hi,
Suricata not fire with this signature and joigned pcap file:
alert tcp any 110 -> any any (msg:"pop3 suricata reply"; flow:to_client,established; content:"-ERR"; nocase; depth:4; offset:0; classtype:misc-attack; sid:9116511; rev:1;)

but fire with this signature: (only changed depth)
alert tcp any 110 -> any any (msg:"pop3 suricata reply"; flow:to_client,established; content:"-ERR"; nocase; depth:53; offset:0; classtype:misc-attack; sid:9116511; rev:1;)

Im curious why first signature not fire ?
Of course, snort fire with two signatures.
Regards
Rmkml


Files

exemple_pop3_reply_suricata.pcap (1.08 KB) exemple_pop3_reply_suricata.pcap rmkml rmkml, 01/23/2012 02:04 PM
Actions

Also available in: Atom PDF