Project

General

Profile

Actions

Bug #7773

open

Bug #7638: detect: incorrect rule ordering with more complex flowbit chains

flowbits: no-op unset + isnotset combinations are accepted

Added by Shivani Bhardwaj 2 days ago. Updated 2 days ago.

Status:
Assigned
Priority:
High
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

For example, a rule like:

alert tcp any any -> any any (msg:"unset + isnotset"; flowbits:isnotset,abc; http.method; content:"GET"; flowbits:unset,abc; sid:111)

Actions #1

Updated by Shivani Bhardwaj 2 days ago

  • Description updated (diff)
  • Priority changed from Normal to High
Actions

Also available in: Atom PDF