Project

General

Profile

Actions

Feature #7566

open

dcerpc: applayer events for anomalous parsing results

Added by Shivani Bhardwaj about 1 year ago. Updated 10 days ago.

Status:
Assigned
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

dcerpc lacks event handling which is important to convey what a possible issue could have led to an unexpected behavior.


Files

rough_potato_broken_2.pcap (143 KB) rough_potato_broken_2.pcap pcap with dcerpc Artem Kartunchikov, 04/02/2025 12:02 PM
stats.log (5.17 KB) stats.log Artem Kartunchikov, 04/02/2025 12:03 PM
packets_stats.log (10 KB) packets_stats.log Artem Kartunchikov, 04/02/2025 12:03 PM
locks_stats.log (1.52 KB) locks_stats.log Artem Kartunchikov, 04/02/2025 12:03 PM

Related issues 1 (1 open0 closed)

Related to Suricata - Bug #5133: dcerpc: logs not created after unhandled packet such as auth3ResolvedPhilippe AntoineActions
Actions #1

Updated by Victor Julien about 1 year ago

  • Target version changed from 8.0.0-beta1 to 8.0.0-rc1

Updated by Artem Kartunchikov 12 months ago

I again encounter this issue but with other pcap file

Actions #3

Updated by Victor Julien 10 months ago

  • Target version changed from 8.0.0-rc1 to 9.0.0-beta1
Actions #4

Updated by Artem Kartunchikov 9 months ago

Also, I think it would be great if instead of the parser getting into an error state and shutting down, it would just skip the unknown RPC calls and continue analyzing the stream

Actions #5

Updated by Philippe Antoine 10 days ago

Artem Kartunchikov wrote in #note-4:

Also, I think it would be great if instead of the parser getting into an error state and shutting down, it would just skip the unknown RPC calls and continue analyzing the stream

See https://github.com/OISF/suricata/pull/15022

Actions #6

Updated by Philippe Antoine 10 days ago

  • Related to Bug #5133: dcerpc: logs not created after unhandled packet such as auth3 added
Actions

Also available in: Atom PDF