Feature #7566
open
dcerpc: applayer events for anomalous parsing results
Added by Shivani Bhardwaj 4 months ago.
Updated 10 days ago.
Description
dcerpc lacks event handling which is important to convey what a possible issue could have led to an unexpected behavior.
Files
- Target version changed from 8.0.0-beta1 to 8.0.0-rc1
I again encounter this issue but with other pcap file
- Target version changed from 8.0.0-rc1 to 9.0.0-beta1
Also, I think it would be great if instead of the parser getting into an error state and shutting down, it would just skip the unknown RPC calls and continue analyzing the stream
Also available in: Atom
PDF