Project

General

Profile

Actions

Feature #7566

open
SB SB

dcerpc: applayer events for anomalous parsing results

Feature #7566: dcerpc: applayer events for anomalous parsing results

Added by Shivani Bhardwaj about 1 year ago. Updated about 1 month ago.

Status:
Assigned
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

dcerpc lacks event handling which is important to convey what a possible issue could have led to an unexpected behavior.


Files

rough_potato_broken_2.pcap (143 KB) rough_potato_broken_2.pcap pcap with dcerpc Artem Kartunchikov, 04/02/2025 12:02 PM
stats.log (5.17 KB) stats.log Artem Kartunchikov, 04/02/2025 12:03 PM
packets_stats.log (10 KB) packets_stats.log Artem Kartunchikov, 04/02/2025 12:03 PM
locks_stats.log (1.52 KB) locks_stats.log Artem Kartunchikov, 04/02/2025 12:03 PM

Related issues 2 (1 open1 closed)

Related to Suricata - Bug #5133: dcerpc: logs not created after unhandled packet such as auth3ClosedPhilippe AntoineActions
Copied to Suricata - Feature #8426: rdp: applayer events for anomalous parsing resultsAssignedOISF DevActions

VJ Updated by Victor Julien about 1 year ago Actions #1

  • Target version changed from 8.0.0-beta1 to 8.0.0-rc1

AK Updated by Artem Kartunchikov about 1 year ago Actions #2

I again encounter this issue but with other pcap file

VJ Updated by Victor Julien 10 months ago Actions #3

  • Target version changed from 8.0.0-rc1 to 9.0.0-beta1

AK Updated by Artem Kartunchikov 10 months ago Actions #4

Also, I think it would be great if instead of the parser getting into an error state and shutting down, it would just skip the unknown RPC calls and continue analyzing the stream

PA Updated by Philippe Antoine about 1 month ago Actions #5

Artem Kartunchikov wrote in #note-4:

Also, I think it would be great if instead of the parser getting into an error state and shutting down, it would just skip the unknown RPC calls and continue analyzing the stream

See https://github.com/OISF/suricata/pull/15022

PA Updated by Philippe Antoine about 1 month ago Actions #6

  • Related to Bug #5133: dcerpc: logs not created after unhandled packet such as auth3 added

PA Updated by Philippe Antoine 19 days ago Actions #7

  • Copied to Feature #8426: rdp: applayer events for anomalous parsing results added
Actions

Also available in: PDF Atom