- Login: jmtaylor90
- Email: firstname.lastname@example.org
- Registered on: 12/01/2015
- Last connection: 05/10/2022
- 08:46 PM Suricata Documentation #5182: userguide: better document rule keywords
- Juliana Fajardini Reichow wrote in #note-3:
> Jason Taylor wrote in #note-2:
> > I was looking at the http keyword ...
- 08:20 PM Suricata Documentation #5182: userguide: better document rule keywords
- I was looking at the http keyword docs at https://suricata.readthedocs.io/en/latest/rules/http-keywords.html and it g...
- 08:37 PM Suricata Bug #5220 (Assigned): fast_pattern specification in base64_data shouldn't be allowed
- It seems that specifying a fast_pattern in base64_data is ignored both from an error/warning standpoint and from an a...
- 12:34 AM Suricata Bug #569: display syntax requirement on keyword parsing error
- It looks like the last discussion that was had around this was in https://github.com/OISF/suricata/pull/4251. Are the...
- 06:32 PM Suricata Bug #4286 (New): FN occurs when using negated isdataat with http_cookie keyword
- Given a sample of traffic such as:
GET /somestuff HTTP/1.1
- 03:04 PM Suricata Bug #3684: Specific rule is not firing against pcap if other rule is enabled
- After some additional testing against the new releases I can no longer produce/reproduce the errors I was seeing.
- 12:18 PM Suricata Bug #3684: Specific rule is not firing against pcap if other rule is enabled
- A scenario we ran into the other day seems to be related to this issue. Specifically we are seeing what appear to be ...
- 09:00 PM Suricata Feature #3626 (Closed): implement from_end byte_jump keyword
- from_end is documented:
- 01:22 PM Suricata Bug #3450: signature with sticky buffer with subsequent pcre check in a different buffer loads but will never match
- Victor Julien wrote:
> What if you reset the sticky buffer before the pcre? By adding a pkt_data; before it.
- 06:44 PM Suricata Bug #3450 (Closed): signature with sticky buffer with subsequent pcre check in a different buffer loads but will never match
- alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"suri 5 pcre fun"; flow:established,to_server; http.method; conten...
Also available in: Atom