General

Profile

Jason Ish

Issues

open closed Total
Assigned issues 90 502 592
Reported issues 110 291 401

Projects

Project Roles Registered on
Suricata Developer, OISF Team, OISF Manager 11/09/2009
Suricata-Update Developer, OISF Team, OISF Manager 10/31/2017

Activity

06/10/2024

07:52 PM Suricata Bug #6281: dns: structure of query differs between "alert" and "dns" event types
Ping @regit, as we started to talking about this over #6400 I think. Jason Ish
07:50 PM Suricata Bug #6281 (In Review): dns: structure of query differs between "alert" and "dns" event types
PR for review: https://github.com/OISF/suricata/pull/11283 Jason Ish

06/06/2024

10:36 PM Suricata Feature #3952: mDNS protocol implementation
Related to #6281. MDNS actually uses the ability to have multiple queries in the request which is one of the logging... Jason Ish

06/04/2024

10:37 PM Suricata Bug #6281: dns: structure of query differs between "alert" and "dns" event types
Draft PR addressing requests: https://github.com/OISF/suricata/pull/11238 Jason Ish
07:12 PM Suricata Bug #6281: dns: structure of query differs between "alert" and "dns" event types
Theres also #6400 which is another reason for a version bump as well.
Jason Ish
07:10 PM Suricata Bug #6281: dns: structure of query differs between "alert" and "dns" event types
Victor Julien wrote in #note-12:
> Does this mean we're doing a @version:3@ record type?
I suppose we should. We...
Jason Ish
05:42 PM Suricata Bug #6281: dns: structure of query differs between "alert" and "dns" event types
For DNS requests we'll see the following breaking change:
*Before*...
Jason Ish
03:53 PM Suricata Bug #7004: app-layer: wrong tx may be logged for stream rules
The description updated to better reflect the actual error of the misleading TX data being logged with an alert. Jason Ish

06/03/2024

03:23 PM Suricata Feature #7062 (New): redis: support authenticating against a redis server
With Hiredis, it looks like this is done by sending a raw "AUTH" message.
Jason Ish

05/27/2024

05:04 PM Suricata Feature #7047 (New): eve: add ip version field
Add a field to EVE records specifying the IP version.
Use case: I wanted to limit a set of eve records down to jus...
Jason Ish

Also available in: Atom