Actions
Bug #7279
closeddns: protocol detection is not strict enough
Affected Versions:
Effort:
Difficulty:
Label:
Description
From https://github.com/OISF/suricata/pull/11794 and TLPR pcaps from QA showing the deviation
Actions
Added by Philippe Antoine over 1 year ago. Updated about 1 year ago.
Description
From https://github.com/OISF/suricata/pull/11794 and TLPR pcaps from QA showing the deviation
It accepts as DNS custom protocol data exfiltration traffic on port 53 with later app-layer parser error on TLP pcap