General

Profile

Anoop Saldanha

Issues

Projects

Activity

08/07/2016

02:41 AM Suricata Optimization #1791: Kernel Drops: Thread occasionally Spike to 100%
Hi Zach,
Wanted to see if you are still seeing the issue, or did the issue solve itself? If it is the later, what...

12/01/2015

10:08 PM Suricata Support #1609: 3.0RC1 file extraction

Hao,
Not sure what's the aim file is(is that the pdf file?), but I do see data
in the pcaps for (2). For http...

04/08/2015

11:39 PM Suricata Bug #1442: HTTP URL parser
Lucky b56 wrote:
> Yes. It's a malware trying to communicate with their custom HTTP server I believe.
It's more l...

10/20/2014

01:25 AM Suricata Revision b334b8a6: CUDA: Update the inspection engine to inform the cuda module that it
doesn't need the gpu results and to release the packet for the next run.
Previously the inspection engine wouldn't i...

07/16/2014

09:28 AM Suricata Feature #1239: Best effort TCP stack
The resynchronization idea is possible, yeah. We had planned to use synchronization against a PDU record boundary fo...

05/26/2014

07:43 AM Suricata Feature #1194: Implement http_args keyword to match http arguments - query string or body

alert tcp any any -> any any (http_args; content:"argument"; sid:1;)
alert tcp any any -> any any (http_args; cont...
10:35 PM Suricata Feature #1194: Implement http_args keyword to match http arguments - query string or body
The idea is to make this a sticky buffer. Does that sound fine?
Currently all the http keywords are modifiers. W...

05/21/2014

06:27 AM Suricata Feature #1194 (New): Implement http_args keyword to match http arguments - query string or body

We can use a http_args keyword that would match on the "name = value"
pairs of http arguments from the query stri...

04/15/2014

12:09 PM Suricata Bug #1180: Possible problem in stream tracking
I'm probably wondering if this is because the tcp state transitions for both client and server are maintained in one ...

04/03/2014

09:02 AM Suricata Bug #1163: HTP Segfault

Just wondering if it is the below situation -
The request is still waiting on the response. The response comes ...

Also available in: Atom