- Login: asaldanha
- Email: firstname.lastname@example.org
- Registered on: 11/09/2009
- Last connection: 08/07/2016
- 02:41 AM Suricata Support #1791: Kernel Drops: Thread occasionally Spike to 100%
- Hi Zach,
Wanted to see if you are still seeing the issue, or did the issue solve itself? If it is the later, what...
- 10:08 PM Suricata Support #1609: 3.0RC1 file extraction
Not sure what's the aim file is(is that the pdf file?), but I do see data
in the pcaps for (2). For http...
- 11:39 PM Suricata Bug #1442: HTTP URL parser
- Lucky b56 wrote:
> Yes. It's a malware trying to communicate with their custom HTTP server I believe.
It's more l...
- 09:28 AM Suricata Feature #1239: Best effort TCP stack
- The resynchronization idea is possible, yeah. We had planned to use synchronization against a PDU record boundary fo...
- 07:43 AM Suricata Feature #1194: Implement http_args keyword to match http arguments - query string or body
alert tcp any any -> any any (http_args; content:"argument"; sid:1;)
alert tcp any any -> any any (http_args; cont...
- 10:35 PM Suricata Feature #1194: Implement http_args keyword to match http arguments - query string or body
- The idea is to make this a sticky buffer. Does that sound fine?
Currently all the http keywords are modifiers. W...
- 06:27 AM Suricata Feature #1194 (New): Implement http_args keyword to match http arguments - query string or body
We can use a http_args keyword that would match on the "name = value"
pairs of http arguments from the query stri...
- 12:09 PM Suricata Bug #1180: Possible problem in stream tracking
- I'm probably wondering if this is because the tcp state transitions for both client and server are maintained in one ...
- 09:02 AM Suricata Bug #1163: HTP Segfault
Just wondering if it is the below situation -
The request is still waiting on the response. The response comes ...
- 08:39 PM Suricata Optimization #1039: Packetpool should be a stack
- Right, the cuda-packet-return issue lies outside the packetpool.
From cuda perspective though, the advantage with ...
Also available in: Atom