Project

General

Profile

Actions

Bug #7772

open

Bug #7638: detect: incorrect rule ordering with more complex flowbit chains

flowbits: no-op set and isset combinations are accepted

Added by Shivani Bhardwaj 2 days ago. Updated 1 day ago.

Status:
In Review
Priority:
High
Target version:
Affected Versions:
Effort:
Difficulty:
low
Label:

Description

For example, rules like

alert tcp any any -> any any (msg:"set + isset flowbit"; http.method; content:"GET"; flowbits:set,abc; flowbits:isset,abc; sid:111)

Actions #1

Updated by Shivani Bhardwaj 2 days ago

  • Description updated (diff)
  • Priority changed from Normal to High
Actions #2

Updated by Shivani Bhardwaj 1 day ago

  • Status changed from Assigned to In Review
  • Difficulty set to low
Actions

Also available in: Atom PDF