Actions
Bug #7279
closeddns: protocol detection is not strict enough
Affected Versions:
Effort:
Difficulty:
Label:
Description
From https://github.com/OISF/suricata/pull/11794 and TLPR pcaps from QA showing the deviation
Actions
Added by Philippe Antoine about 1 year ago. Updated 11 months ago.
Description
From https://github.com/OISF/suricata/pull/11794 and TLPR pcaps from QA showing the deviation
It accepts as DNS custom protocol data exfiltration traffic on port 53 with later app-layer parser error on TLP pcap