Project

General

Profile

Actions

Feature #7536

open
AD OD

detect/ldap: add keywords for LDAP BindRequest

Feature #7536: detect/ldap: add keywords for LDAP BindRequest

Added by Alice da Silva Akaki about 1 year ago. Updated 4 months ago.

Status:
New
Priority:
High
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

ldap.bind_request.version, an integer between 1 and 127
ldap.bind_request.authentication, enum + an octet string

Eve fields to match:
ldap.request.bind_request.version

ldap.request.bind_request.sasl.mechanism
ldap.request.bind_request.sasl.credentials


Related issues 2 (2 open0 closed)

Related to Suricata - Feature #7470: detect/ldap: add ldap.bind.version keywordAssignedOISF DevActions
Blocks Suricata - Task #7452: ldap: add keywords to match outputIn ProgressOISF DevActions

PA Updated by Philippe Antoine about 1 year ago Actions #1

  • Blocks Task #7452: ldap: add keywords to match output added

PA Updated by Philippe Antoine about 1 year ago Actions #2

ldap.bind_request.authentication is an enum + an octet string...

AD Updated by Alice da Silva Akaki about 1 year ago Actions #3

  • Description updated (diff)

AD Updated by Alice da Silva Akaki about 1 year ago Actions #4

  • Subject changed from detect: add keywords for BindRequest to detect/ldap: add keywords for LDAP BindRequest

PA Updated by Philippe Antoine about 1 year ago Actions #5

  • Priority changed from Normal to High

PA Updated by Philippe Antoine about 1 year ago Actions #6

Idea for ldap.request.bind.auth keyword : have it a sticky buffer but with required option, like ldap.request.bind.auth: sasl; content: "toto"; and the parser only accepts the 4 different auth mechanisms defined in ldap asn1

PA Updated by Philippe Antoine about 1 year ago Actions #7

  • Related to Feature #7470: detect/ldap: add ldap.bind.version keyword added

PA Updated by Philippe Antoine 10 months ago Actions #8

  • Target version changed from 8.0.0 to 9.0.0-beta1

JF Updated by Juliana Fajardini Reichow 4 months ago Actions #9

  • Assignee changed from Alice da Silva Akaki to OISF Dev

Hi there, considering our stale tickets policy, I'm unclaiming this ticket. Feel free to ask to work on this or another again, if you have time in the future :)

Actions

Also available in: PDF Atom