Project

General

Profile

Actions

Feature #4121

closed

Feature #4201: http2: full protocol support

http2: support file inspection API

Added by Victor Julien about 4 years ago. Updated almost 4 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Originally reported as a bug with a single sig, this is really about properly supporting the file inspection API.

Adding alert http2 any any -> any any (flow:established,to_client; filemd5:test.md5; sid:5; rev:1;) with 15560fc6a1e4845498d8d952691afb11 in test.md5 should trigger just a single alert in SV test http2-basic, yet it generates 23 alerts.

Setting private as this first triggers #4120.


Related issues 1 (0 open1 closed)

Related to Suricata - Bug #4076: http2: Memory leak when parsing signature with filestoreClosedPhilippe AntoineActions
Actions

Also available in: Atom PDF