General

Profile

Jason Ish

  • Email: ish@unx.ca
  • Registered on: 11/09/2009
  • Last connection: 04/29/2017

Issues

Projects

  • Suricata (Manager, Developer, 11/09/2009)

Activity

04/13/2017

09:37 AM Suricata Bug #2095: eve: http body in alert event
Please see https://redmine.openinfosecfoundation.org/issues/2069.
So right now I'm thinking a list of buffers (in ...
03:07 AM Suricata Revision e69ce30d: template script: typo in app-layer setup script
Check for ed was failing, as it was actually looking for edx.

04/11/2017

06:28 PM Suricata Bug #2093 (Assigned): Handle TCP stream gaps.
Currently if a TCP session has a gap, app-layer parsing is aborted. For some protocols, resyncing may be impossible a...
01:18 PM Suricata Bug #2037 (Closed): travis: move off legacy support
01:18 PM Suricata Feature #1978 (Closed): Using date in logs name
Git master now has the ability to put dates in the eve log file names.
PR: https://github.com/inliniac/suricata/pu...
01:13 PM Suricata Bug #2037: travis: move off legacy support
We are now using the new container build system. See:
https://github.com/inliniac/suricata/pull/2635

04/10/2017

10:16 AM Suricata Bug #2069: logging: payload may not represent traffic the generated alert (eve and unified2)
Updating title to better represent this issue.
As noted in the previous comment, the payload is taken from the str...
09:49 AM Suricata Bug #2069: logging: payload may not represent traffic the generated alert (eve and unified2)
I was able to isolate a reproduction with just rule 2008438. It turns out that the payload being logged was about 40k...

04/07/2017

09:23 AM Suricata Bug #2039 (Closed): suricata stops processing when http-log output via unix_stream backs up
Fixed, see https://github.com/inliniac/suricata/pull/2651#issuecomment-292464512
This changes the way the socket i...
09:20 AM Suricata Bug #2049 (Closed): Empty rule files cause failure exit code without corresponding message
Fixed. https://github.com/inliniac/suricata/pull/2652#issuecomment-292464542

Also available in: Atom