Project

General

Profile

Actions

Bug #6578

closed
PA PA

ssh: no alert on packet with Message Code: New Keys (21)

Bug #6578: ssh: no alert on packet with Message Code: New Keys (21)

Added by Philippe Antoine over 2 years ago. Updated about 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Cf https://forum.suricata.io/t/can-not-get-ssh-alert/4223/8

Because of ssh parser setting APP_LAYER_PARSER_NO_INSPECTION right away and preventing detection on this packet


Subtasks 2 (0 open2 closed)

Bug #6579: ssh: no alert on packet with Message Code: New Keys (21) (6.0.x backport)RejectedActions
Bug #6580: ssh: no alert on packet with Message Code: New Keys (21) (7.0.x backport)ClosedPhilippe AntoineActions

OT Updated by OISF Ticketbot over 2 years ago Actions #1

  • Subtask #6579 added

OT Updated by OISF Ticketbot over 2 years ago Actions #2

  • Label deleted (Needs backport to 6.0)

OT Updated by OISF Ticketbot over 2 years ago Actions #3

  • Subtask #6580 added

OT Updated by OISF Ticketbot over 2 years ago Actions #4

  • Label deleted (Needs backport to 7.0)

PA Updated by Philippe Antoine over 2 years ago Actions #5

  • Status changed from Assigned to In Review

PA Updated by Philippe Antoine about 2 years ago Actions #7

  • Status changed from In Review to Resolved

VJ Updated by Victor Julien about 2 years ago Actions #8

  • Status changed from Resolved to Closed
Actions

Also available in: PDF Atom