Project

General

Profile

Actions

Feature #470

closed

Feature #775: libhtp 0.5 support

gzip extension support incomplete

Added by Victor Julien almost 12 years ago. Updated almost 11 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

The current git master supports FNAME and FCOMMENT gzip extensions. Support for FEXTRA and FHCRC is missing: http://www.gzip.org/zlib/rfc-gzip.html

If a gzip stream is encountered that contains an unsupported flag, the "http.gzip_decompression_failed" app layer event is set.

Support needs to be added to libhtp, not Suricata itself.

When complete, patches need to be submitted to upstream libhtp.

Actions

Also available in: Atom PDF