General

Profile

GT Gianni Tedesco

  • Login: scaramanga
  • Registered on: 05/06/2021
  • Last sign in: 02/26/2026

Issues

open closed Total
Assigned issues 1 1 2
Reported issues 1 2 3

Projects

Project Roles Registered on
Suricata Developer 11/02/2024
Suricata-Update Developer 11/02/2024

Activity

02/26/2026

GT 11:59 AM Suricata Feature #8329 (New): Implement ERSPAN type 3
Apparently there are devices which support ERSPAN type 3, but not ERSPAN type 2.
I propose to add ERSPAN type 3 support so that suricata can receive traffic from such sources.
Gianni Tedesco

11/01/2024

GT 06:29 AM Suricata Feature #6695: tls: log extensions
Okay, I have a patch for the client part, I will make the PR shortly Gianni Tedesco

10/18/2024

GT 04:02 AM Suricata Bug #4499: Sudden and enormous memory leak
I think the issue went away with some upgrade along the way. Either that or changes to config or rules (unintentionally) solved it. Gianni Tedesco

08/09/2024

GT 05:13 AM Suricata Feature #6695: tls: log extensions
I would like to add to the TLS EVE output the following fields:
1. cipher suite list to client struct
2. cipher suite selected (to a new server struct?)
3. client extensions list to client struct
4. server extensions list to server s...
Gianni Tedesco

04/05/2024

GT 02:42 AM Suricata Bug #6782: streaming/buffer: crash in HTTP body handling
Ran with ASAN and debug compile and got the following output, not sure much more helpful it is than previous backtrace: Gianni Tedesco

03/22/2024

GT 08:45 AM Suricata Bug #6782: streaming/buffer: crash in HTTP body handling
A bit of extra context here. The systems this is happening on, it's happening pretty regularly (eg. every 10 minutes), the issue is that they're on 10GB NICs, which are almost fully saturated with traffic, single threaded (due to broadco... Gianni Tedesco

03/21/2024

GT 02:44 AM Suricata Bug #6634: tls: Invalid ja3 due to double client hello
And another discrepancy, which I am not sure about and investigating a bit more is that, sometimes the EVE JSON reports "TLS 1.3", but both ja3-strings are saying 771 (TLS 1.2). Not sure why this is. Gianni Tedesco
GT 02:32 AM Suricata Bug #6634: tls: Invalid ja3 due to double client hello
I am also seeing a case where only two fields are being output, this also seems invalid: "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53" Gianni Tedesco

03/18/2024

GT 05:12 AM Suricata Feature #6379: ja4: support for TLS and QUIC
It would be good if all the fields required for JA4 can be exported in the EVE TLS event meta-data, that way JA4's (or alternative fingerprint algorithms) can be computed independently of Suricata.
We, at rapid7, are collecting passiv...
Gianni Tedesco

03/17/2024

GT 11:36 AM Suricata Bug #6634: tls: Invalid ja3 due to double client hello
Can confirm we are seeing exactly this problem on approx 0.005% of TLS sessions Gianni Tedesco

Also available in: Atom