From 7011d8f34cc235eaeac2787c787041a07f1afcc7 Mon Sep 17 00:00:00 2001 From: Victor Julien Date: Wed, 28 Sep 2016 15:14:00 +0200 Subject: [PATCH] doc: remove/cleanup 'guides' --- .../file-extraction/file-extraction.rst | 65 ++------- doc/userguide/file-extraction/md5.rst | 129 +----------------- doc/userguide/output/index.rst | 1 - 3 files changed, 10 insertions(+), 185 deletions(-) diff --git a/doc/userguide/file-extraction/file-extraction.rst b/doc/userguide/file-extraction/file-extraction.rst index 2cd9e710f7..001ea525cd 100644 --- a/doc/userguide/file-extraction/file-extraction.rst +++ b/doc/userguide/file-extraction/file-extraction.rst @@ -1,19 +1,10 @@ File Extraction =============== -.. toctree:: - - md5 - filemd5-and-whiteblacklisting-with-md5 - public-sha1-md5-data-sets - -Starting with Suricata version 1.2 it's possible to extract files from HTTP sessions as well as match on file name, extension and "magic". - - Architecture ~~~~~~~~~~~~ -The file extraction code works on top of the HTTP parser which itself is largely a wrapper for libhtp. The HTTP parser takes care of dechunking and unzipping the request and/or response data if necessary. The HTTP parser runs on top of the stream reassembly engine. +The file extraction code works on top of the HTTP and SMTP parsers. The HTTP parser takes care of dechunking and unzipping the request and/or response data if necessary. The HTTP/SMTP parsers runs on top of the stream reassembly engine. This means that settings in the stream engine, reassembly engine and the HTTP parser all affect the workings of the file extraction. @@ -31,53 +22,6 @@ Settings *libhtp.default-config.response-body-limit* / *libhtp.server-config..response-body-limit* is like the request body limit, only it applies to the HTTP response body. -NIC offloading -~~~~~~~~~~~~~~ - -NIC offloading should be disabled: - -:: - - - apt-get install ethtool - - -:: - - - ethtool -k eth3 - - Offload parameters for eth3: - rx-checksumming: off - tx-checksumming: off - scatter-gather: off - tcp-segmentation-offload: off - udp-fragmentation-offload: off - generic-segmentation-offload: off - generic-receive-offload: off - large-receive-offload: off - rx-vlan-offload: off - tx-vlan-offload: off - -Everything should be OFF. If it is not here is how you can disable it: - - -:: - - - ethtool -K eth3 tso off - ethtool -K eth3 gro off - ethtool -K eth3 lro off - ethtool -K eth3 gso off - ethtool -K eth3 rx off - ethtool -K eth3 tx off - ethtool -K eth3 sg off - ethtool -K eth3 rxvlan off - ethtool -K eth3 txvlan off - -NOTICE the difference between small k and a BIG K !! -Please make sure you choose the appropriate interface name (eth0,eth1,eth5...) - Output ~~~~~~ @@ -148,3 +92,10 @@ MD5 ~~~ Suricata can calculate MD5 checksums of files on the fly and log them. See :doc:`md5` for an explanation on how to enable this. + + +.. toctree:: + + md5 + public-sha1-md5-data-sets + diff --git a/doc/userguide/file-extraction/md5.rst b/doc/userguide/file-extraction/md5.rst index 3cc94cad18..7e992a7d28 100644 --- a/doc/userguide/file-extraction/md5.rst +++ b/doc/userguide/file-extraction/md5.rst @@ -3,125 +3,6 @@ Storing MD5s checksums ====================== -In this particular example we are using: Ubuntu 14.04 LTS - -Also - we are using the latest git master (git installation) - -Make sure you have libnss and libnspr installed -~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - - -:: - - - root@LTS-64-1:~/Work/tmp/oisf# dpkg -l |grep libnss - ii libnss-mdns:amd64 0.10-6 amd64 NSS module for Multicast DNS name resolution - ii libnss3:amd64 2:3.17.4-0ubuntu0.14.04.1 amd64 Network Security Service libraries - ii libnss3-1d:amd64 2:3.17.4-0ubuntu0.14.04.1 amd64 Network Security Service libraries - transitional package - ii libnss3-dev:amd64 2:3.17.4-0ubuntu0.14.04.1 amd64 Development files for the Network Security Service libraries - ii libnss3-nssdb 2:3.17.4-0ubuntu0.14.04.1 all Network Security Security libraries - shared databases - ii libnss3-tools 2:3.17.4-0ubuntu0.14.04.1 amd64 Network Security Service tools - - - -:: - - - root@LTS-64-1:~/Work/tmp/oisf# dpkg -l |grep libnspr - ii libnspr4:amd64 2:4.10.7-0ubuntu0.14.04.1 amd64 NetScape Portable Runtime Library - ii libnspr4-dev 2:4.10.7-0ubuntu0.14.04.1 amd64 Development files for the NetScape Portable Runtime library - -If not install them: - -:: - - - apt-get install libnss3-dev libnspr4-dev - -**Note:** Fedora users need to install the following: - -:: - - - nss-util - nss-util-devel - nss-devel - nspr-devel - nspr - -Get the Suricata code -~~~~~~~~~~~~~~~~~~~~~ - -Execute: - -:: - - - git clone git://phalanx.openinfosecfoundation.org/oisf.git && cd oisf - git clone https://github.com/OISF/libhtp.git -b 0.5.x - -Building Suricata -~~~~~~~~~~~~~~~~~~ - -You have to compile/install suri like this in order to enable MD5s: - -:: - - - ./autogen.sh - ./configure --with-libnss-libraries=/usr/lib --with-libnss-includes=/usr/include/nss/ --with-libnspr-libraries=/usr/lib --with-libnspr-includes=/usr/include/nspr - make clean - make - sudo make install - - -Output of configure: - - -:: - - - Suricata Configuration: -   AF_PACKET support:                       yes -   PF_RING support:                         no -   NFQueue support:                         no -   IPFW support:                            no -   DAG enabled:                             no -   Napatech enabled:                        no - -   libnss support:                          yes -   libnspr support:                         yes -   Prelude support:                         no -   PCRE jit:                                no - -This is what is important to have: - -:: - - - libnss support:                          yes - libnspr support:                         yes - -Confirm everything is built correctly: - - -:: - - - # suricata --build-info - [10010] 1/5/2012 -- 11:16:23 - (suricata.c:502) (SCPrintBuildInfo) -- This is Suricata version 1.3dev (rev e6dea5c) - [10010] 1/5/2012 -- 11:16:23 - (suricata.c:575) (SCPrintBuildInfo) -- Features: PCAP_SET_BUFF LIBPCAP_VERSION_MAJOR=1 AF_PACKET HAVE_PACKET_FANOUT LIBCAP_NG LIBNET1.1 HAVE_HTP_URI_NORMALIZE_HOOK HAVE_HTP_TX_GET_RESPONSE_HEADERS_RAW HAVE_NSS - [10010] 1/5/2012 -- 11:16:23 - (suricata.c:589) (SCPrintBuildInfo) -- 32-bits, Little-endian architecture - [10010] 1/5/2012 -- 11:16:23 - (suricata.c:591) (SCPrintBuildInfo) -- GCC version 4.4.5, C version 199901 - [10010] 1/5/2012 -- 11:16:23 - (suricata.c:597) (SCPrintBuildInfo) -- __GCC_HAVE_SYNC_COMPARE_AND_SWAP_1 - [10010] 1/5/2012 -- 11:16:23 - (suricata.c:600) (SCPrintBuildInfo) -- __GCC_HAVE_SYNC_COMPARE_AND_SWAP_2 - [10010] 1/5/2012 -- 11:16:23 - (suricata.c:603) (SCPrintBuildInfo) -- __GCC_HAVE_SYNC_COMPARE_AND_SWAP_4 - [10010] 1/5/2012 -- 11:16:23 - (suricata.c:606) (SCPrintBuildInfo) -- __GCC_HAVE_SYNC_COMPARE_AND_SWAP_8 - [10010] 1/5/2012 -- 11:16:23 - (suricata.c:613) (SCPrintBuildInfo) -- compiled with -fstack-protector - [10010] 1/5/2012 -- 11:16:23 - (suricata.c:619) (SCPrintBuildInfo) -- compiled with _FORTIFY_SOURCE=2 - -Make sure we have **HAVE_NSS** in the **Features** line. - Configuration ~~~~~~~~~~~~~ @@ -194,7 +75,7 @@ For the purpose of testing we use this rule only in a file.rules (a test/example This rule above will save all the file data for files that are opened/downloaded through HTTP -Start Suricta (-S option loads ONLY the specified rule file, with disregard if any other rules that are enabled in suricata.yaml): +Start Suricata (-S option loads ONLY the specified rule file, with disregard if any other rules that are enabled in suricata.yaml): :: @@ -203,12 +84,7 @@ Start Suricta (-S option loads ONLY the specified rule file, with disregard if a suricata -c /etc/suricata/suricata.yaml -S file.rules -i eth0 -I tried that link (Cisco Prod Brochure PDF, just googled "Cisco PDF"): - -* http://www.cisco.com/c/en/us/products/routers/3800-series-integrated-services-routers-isr/index.html - -and in file directory (/var/log/suricata/files) I got the meta data: - +Meta data: :: @@ -263,4 +139,3 @@ If you would like to log MD5s for everything and anything that passes through th force-magic: yes # force logging magic on all logged files force-md5: yes # force logging of md5 checksums -This is in short what is needed to have MD5s logged. diff --git a/doc/userguide/output/index.rst b/doc/userguide/output/index.rst index 6d9a4f2864..e0738e01f3 100644 --- a/doc/userguide/output/index.rst +++ b/doc/userguide/output/index.rst @@ -7,4 +7,3 @@ Output lua-output syslog-alerting-comp custom-http-logging - files-json/files-json.rst