Project

General

Profile

Actions

Bug #5110

open

Bug #5076: keyword content does not work over reassembled TCP

keyword content does not work over reassembled TCP (6.0.x backport)

Added by Jeff Lucovsky 8 months ago. Updated 8 days ago.

Status:
Assigned
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Using rule
alert ip any any -> any any (content:"HTTP/2.loc"; sid:11;)

on attached pcap

with stream.reassembly.toserver-chunk-size=25

does not trigger an alert

It does trigger the alert without the setting.

I fear we might have an evasion if I split the packets over the default value of 2560...

Actions #1

Updated by Jeff Lucovsky 8 months ago

  • Copied from Bug #5076: keyword content does not work over reassembled TCP added
Actions #2

Updated by Victor Julien 6 months ago

  • Target version changed from 6.0.5 to 6.0.6
Actions #3

Updated by Jeff Lucovsky 4 months ago

  • Parent task set to #5076
Actions #4

Updated by Jeff Lucovsky 4 months ago

  • Subject changed from keyword content does not work over reassembled TCP to keyword content does not work over reassembled TCP (6.0.x backport)
Actions #5

Updated by Victor Julien 4 months ago

  • Target version changed from 6.0.6 to 6.0.7
Actions #6

Updated by Victor Julien 16 days ago

  • Target version changed from 6.0.7 to 6.0.8
Actions #7

Updated by Victor Julien 8 days ago

  • Target version changed from 6.0.8 to 6.0.9
Actions

Also available in: Atom PDF