Project

General

Profile

Actions

Bug #7773

open

Bug #7638: detect: incorrect rule ordering with more complex flowbit chains

flowbits: no-op unset + isnotset combinations are accepted

Added by Shivani Bhardwaj 22 days ago. Updated 11 days ago.

Status:
Assigned
Priority:
High
Target version:
Affected Versions:
Effort:
Difficulty:
low
Label:

Description

For example, a rule like:

alert tcp any any -> any any (msg:"unset + isnotset"; flowbits:isnotset,abc; http.method; content:"GET"; flowbits:unset,abc; sid:111)

Actions #1

Updated by Shivani Bhardwaj 22 days ago

  • Description updated (diff)
  • Priority changed from Normal to High
Actions #2

Updated by Shivani Bhardwaj 19 days ago

  • Difficulty set to low
Actions #3

Updated by Shivani Bhardwaj 11 days ago

  • Target version changed from 8.0.0 to 9.0.0-beta1
Actions

Also available in: Atom PDF