- Login: jmtaylor90
- Email: firstname.lastname@example.org
- Registered on: 12/01/2015
- Last connection: 02/01/2021
- 06:32 PM Suricata Bug #4286 (New): FN occurs when using negated isdataat with http_cookie keyword
- Given a sample of traffic such as:
GET /somestuff HTTP/1.1
- 03:04 PM Suricata Bug #3684: Specific rule is not firing against pcap if other rule is enabled
- After some additional testing against the new releases I can no longer produce/reproduce the errors I was seeing.
- 12:18 PM Suricata Bug #3684: Specific rule is not firing against pcap if other rule is enabled
- A scenario we ran into the other day seems to be related to this issue. Specifically we are seeing what appear to be ...
- 09:00 PM Suricata Feature #3626 (Closed): implement from_end byte_jump keyword
- from_end is documented:
- 01:22 PM Suricata Bug #3450: signature with sticky buffer with subsequent pcre check in a different buffer loads but will never match
- Victor Julien wrote:
> What if you reset the sticky buffer before the pcre? By adding a pkt_data; before it.
- 06:44 PM Suricata Bug #3450 (Closed): signature with sticky buffer with subsequent pcre check in a different buffer loads but will never match
- alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"suri 5 pcre fun"; flow:established,to_server; http.method; conten...
- 08:34 PM Suricata Bug #3359: suricata.log ownership not being set to run-as user/group
- Forgot to add this is on EL7.7
- 08:32 PM Suricata Bug #3359 (New): suricata.log ownership not being set to run-as user/group
- we are running Suricata 5.0 and have the following in our suricata.yaml:...
- 09:36 PM Suricata Feature #3297: more verbose dcerpc logging
- looking at the pcaps I have there is a bit much to sanitize. I emailed the pcaps and logs to Victor. I will gather/or...
- 01:48 PM Suricata Bug #3240: Dataset hash-size or prealloc invalid value logging
- Hi Andreas!
I did end up sending a PR, in discussions on GH it looks related maybe to something Shivani is working...
Also available in: Atom