Project

General

Profile

Bug #4210

Alert not generated with 2 rules - http.request body (alone) and http.request_body/url_decode

Added by Jeff Lucovsky 7 months ago. Updated 5 months ago.

Status:
Closed
Priority:
High
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

From https://forum.suricata.io/t/transformation-keyword-cant-trigger-an-alert/881/3

Use the attached pcap

These 2 rules generate 2 alerts

alert http any any -> $HOME_NET any (msg: "detect (/etc/passwd)"; flow:to_server,established; http.request_body; url_decode; content:"/etc/passwd"; nocase; sid:1001;)
alert http any any -> $HOME_NET any (msg: "detect (/etc/passwd)"; flow:to_server,established; http.request_body; url_decode; content:"/etc/passwd"; nocase; sid:1002;)

These 2 rules generate 0 alerts

alert http any any -> $HOME_NET any (msg: "detect (/etc/passwd)"; flow:to_server,established; http.request_body;content:"/etc/passwd"; nocase; sid:1001;)
alert http any any -> $HOME_NET any (msg:"detect (/etc/passwd)"; flow:to_server,established; http.request_body; url_decode; content:"/etc/passwd"; nocase; sid:1002;)


Files

http-forum.pcap (2.03 KB) http-forum.pcap Jeff Lucovsky, 12/08/2020 02:33 PM

Related issues

Is duplicate of Bug #4199: Transformation keyword can’t trigger an alert ClosedVictor JulienActions
#1

Updated by Victor Julien 7 months ago

  • Priority changed from Normal to High
#2

Updated by Victor Julien 7 months ago

Is this a duplicate of #4199?

#3

Updated by Jeff Lucovsky 6 months ago

  • Status changed from Assigned to Closed

Dup of 4199

#4

Updated by Victor Julien 6 months ago

  • Is duplicate of Bug #4199: Transformation keyword can’t trigger an alert added
#5

Updated by Jeff Lucovsky 5 months ago

  • Label deleted (Needs backport to 6.0)

Also available in: Atom PDF