Project

General

Profile

Actions

Feature #6853

open

Support of variables from byte_math / byte_extract in bsize / dsize comparisons

Added by Julian Wecke 9 months ago. Updated 10 days ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

When doing a size comparison with dsize or bsize one might want to reference a variable extracted with byte_math or byte_extract.

An example use case: you have protocol with a size field. Such field you might want to compare with the payload/packet size. Either to ensure it's actually that protocol you are looking for or to detect anomalies indicating something like overflow attacks.

Alternatively having a to having that feature at dsize and bsize an implementation at byte_test to compare against those size values would be equality helpful.

Actions

Also available in: Atom PDF