Victor Julien
|
64827e3864
|
file-inspection: use filename= value from Content-Disposition where available to determine the filename in GET requests.
|
14 years ago |
Victor Julien
|
6585cb89d3
|
Fix UtilMiscParseSizeStringTest01 unittest on 32 bit.
|
14 years ago |
Anoop Saldanha
|
35435f3284
|
All http_http_stat_code modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_STAT_CODE. Also remove dummy match/free functions for stat code and stat msg
|
14 years ago |
Anoop Saldanha
|
507e1b66e0
|
All http_http_stat_msg modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_STAT_MSG
|
14 years ago |
Anoop Saldanha
|
059ee217ff
|
All http_http_raw_uri modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_RAW_URI
|
14 years ago |
Anoop Saldanha
|
b1a0d35106
|
All http_http_cookie modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_COOKIE
|
14 years ago |
Anoop Saldanha
|
49bdad9345
|
All http_http_method modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_METHOD
|
14 years ago |
Anoop Saldanha
|
97d8fc9cba
|
All http_http_raw_header modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_RAW_HEADER
|
14 years ago |
Anoop Saldanha
|
97308674ee
|
All http_http_header modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_HEADER
|
14 years ago |
Anoop Saldanha
|
1acb7cdc7d
|
All http_server_body modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_SERVER_BODY
|
14 years ago |
Anoop Saldanha
|
a5b46e727c
|
All http_client_body modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_CLIENT_BODY
|
14 years ago |
Anoop Saldanha
|
4810ee9c5f
|
All uricontent modified patterns now are DETECT_CONTENT and not DETECT_URICONTENT. Step towards unifying all content based patterns. Makes way for easier management of patterns
|
14 years ago |
Anoop Saldanha
|
93d7a6e671
|
code cleanup. Remove unused functions
|
14 years ago |
Anoop Saldanha
|
eb07c345b8
|
code cleanup - replace SigMatchAppendThreshold with SigMatchAppendSMToList
|
14 years ago |
Anoop Saldanha
|
dd7e710f35
|
code cleanup - replace SigMatchAppendPostMatch with SigMatchAppendSMToList
|
14 years ago |
Anoop Saldanha
|
a4638fb0ad
|
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
|
14 years ago |
Anoop Saldanha
|
ff38d42bf1
|
code cleanup - replace SigMatchAppendTag with SigMatchAppendSMToList
|
14 years ago |
Anoop Saldanha
|
ac68c3f893
|
code cleanup - replace SigMatchAppendDcePayload with SigMatchAppendSMToList
|
14 years ago |
Anoop Saldanha
|
6cab663bf0
|
code cleanup - replace SigMatchAppendPayload with SigMatchAppendSMToList
|
14 years ago |
Anoop Saldanha
|
c4cb37b8da
|
code cleanup - replace SigMatchAppendUricontent with SigMatchAppendSMToList
|
14 years ago |
Anoop Saldanha
|
c9af50ea0c
|
code cleanup - replace SigMatchAppendAppLayer with SigMatchAppendSMToList
|
14 years ago |
Anoop Saldanha
|
bbb9f35f26
|
code cleanup - replace SigMatchGetLastSM with SigMatchGetLastSMFromLists
|
14 years ago |
Anoop Saldanha
|
ab35b98f76
|
code cleanup - remove DetectContentGetLastPattern. Replace it with SigMatchGetLastSMFromLists
|
14 years ago |
Anoop Saldanha
|
d85ab5ab1f
|
code cleanup - remove DetectContentFindNextApplicableSM
|
14 years ago |
Anoop Saldanha
|
802350f65a
|
code cleanup - remove DetectContentHasPrevSMPattern
|
14 years ago |
Anoop Saldanha
|
9652c3672d
|
code cleanup - remove SigMatchGetLastPattern
|
14 years ago |
Anoop Saldanha
|
e851804c92
|
code cleanup - remove DetectUricontentGetLastPattern
|
14 years ago |
Anoop Saldanha
|
dcb2afb02f
|
Use sm_list to differentiate between different content types while retrieving pattern ids instead of sm_type
|
14 years ago |
Anoop Saldanha
|
83d9439877
|
DetectPatternGetId() cleanup. Remove separate search element creation for uricontent. We don't need this now since we have unified content structures for content and uricontent
|
14 years ago |
Victor Julien
|
154af56b45
|
Add a print function specially for json output that escapes all characters json requires to be escaped.
|
14 years ago |
Victor Julien
|
740ee3e7ab
|
Add referer header to .meta and json file logs.
|
14 years ago |
Victor Julien
|
337f7861a4
|
Make sure that if not built against libnss, we still compile. Only no md5 for you then\!
|
14 years ago |
Victor Julien
|
6752ccae2a
|
Add line based log file to log-file module that logs each stored file's meta data in json records.
|
14 years ago |
Victor Julien
|
12e8ce6545
|
In PrintRawUriFp, consider " unprintable.
|
14 years ago |
Victor Julien
|
69b3df96fb
|
Initial on the fly MD5 calculation for extracted files using libnss.
|
14 years ago |
Anoop Saldanha
|
2f7717a1a7
|
delete detect-recursive.[ch]
|
14 years ago |
Anoop Saldanha
|
e682796d03
|
feature #414 - support listing supported keywords. Remove support for dummy keywords __address__, __proto__, __port__. Remove support for recursive keyword and all references to it
|
14 years ago |
Anoop Saldanha
|
603d4a719a
|
remove det_ctx->payload_offset and use det_ctx->buffer_offset. Update hscd and hsmd to use the new generic content inspection engine
|
14 years ago |
Anoop Saldanha
|
d1d5507679
|
remove all old content inspection engines and references to them. We have cleaned the entire content inspection phase and improved alert accuracy
|
14 years ago |
Anoop Saldanha
|
35f1f7e8d9
|
unify payload detection engines + fix other bugs in pcre init
|
14 years ago |
Anoop Saldanha
|
9287cce674
|
raw urilen inspection moves to raw uri list. Won't make any difference wrt inspection
|
14 years ago |
Anoop Saldanha
|
0677190960
|
rebase commit for hscd and hsmd patches
|
14 years ago |
Anoop Saldanha
|
22b1f5b22b
|
fix seg fault due to wrong sm list access in hscd
|
14 years ago |
Anoop Saldanha
|
2e2398147c
|
fast pattern unittests added for http server body
|
14 years ago |
Anoop Saldanha
|
09313cf9bd
|
Support http stat code detection engine, fast pattern(mpm engine included). Fix http stat code setup function. Fix pcre option for stat msg keyword. With this the pcre options for server_body is Q, for stat_msg is Y and for stat_code is S
|
14 years ago |
Anoop Saldanha
|
2007c2711c
|
Support http stat msg detection engine, fast pattern(mpm engine included). Fix http stat msg setup function. Fix pcre option for stat msg keyword
|
14 years ago |
Victor Julien
|
9dc153c8f4
|
Fix path handling for including rule files on win32.
|
14 years ago |
Victor Julien
|
489b8b8bcc
|
Allow other yaml files to be included in the main yaml.
|
14 years ago |
Victor Julien
|
adb5d05fb5
|
Fix a FP with negated filemagic inspection.
|
14 years ago |
Victor Julien
|
0b9038b971
|
Add atomics to ticks unittests.
|
14 years ago |