Project

General

Profile

Actions

Bug #7774

open

Bug #7638: detect: incorrect rule ordering with more complex flowbit chains

flowbits: unneeded set + toggle combinations are accepted

Added by Shivani Bhardwaj about 1 month ago. Updated 12 days ago.

Status:
In Review
Priority:
High
Target version:
Affected Versions:
Effort:
Difficulty:
low
Label:

Description

For example, a rule like:

alert tcp any any -> any any (msg:"set + toggle"; http.method; content:"GET"; flowbits:set,abc; flowbits:toggle,abc; sid:111;)

Actions #1

Updated by Shivani Bhardwaj about 1 month ago

  • Description updated (diff)
  • Priority changed from Normal to High
Actions #2

Updated by Shivani Bhardwaj about 1 month ago

  • Difficulty set to low
Actions #3

Updated by Shivani Bhardwaj about 1 month ago

  • Target version changed from 8.0.0 to 9.0.0-beta1
Actions #4

Updated by Philippe Antoine 18 days ago

  • Affected Versions 8.0.0 added
Actions #6

Updated by Shivani Bhardwaj 12 days ago

  • Status changed from Assigned to In Review
Actions

Also available in: Atom PDF