Victor Julien
|
3c1ae607cf
|
Fix cuda compilation.
|
15 years ago |
Anoop Saldanha
|
33f4beb0bc
|
batching of packets support for cuda b2g mpm. Supported for both 32 and 64 bit platforms
|
15 years ago |
Victor Julien
|
b3c22cd512
|
Improve app layer proto check.
|
15 years ago |
Victor Julien
|
39cb1bdbda
|
Fix app layer sigs being recognized as decoder event only or ip only.
|
15 years ago |
Victor Julien
|
587a53b904
|
Disable per second counters as they are unreliable.
|
15 years ago |
Pablo Rincon
|
8f9bcef0e2
|
This patch for app-layer-ssl fix the bug #198 (SSLParserTest01). It seems that with -O2 and -O3, the compiler doesn't handle the initialization correctly (weird..)
|
15 years ago |
Pablo Rincon
|
7003dc5c0d
|
Fix valgrind ctx error on asn1 test 06
|
15 years ago |
Victor Julien
|
d41b5645ef
|
Make sure decoder event rules are inspected even if the packet is invalid and has no addesses or proto. Update fast log and alert debug log to display the alerts. Fixes #179.
|
15 years ago |
Victor Julien
|
92858a211d
|
Fix STREAM_EOF flag overwriting STREAM_START flag on short streams. This made us miss short HTTP sessions.
|
15 years ago |
Victor Julien
|
634b328d38
|
In case of error in pcap file reading mode, we shut the engine down hard instead of gracefully.
|
15 years ago |
Victor Julien
|
426a7de5f2
|
Fix compiler warning about incomplete prototype (2).
|
15 years ago |
Victor Julien
|
18c923318a
|
Fix bug where valid FIN packets would be rejected.
|
15 years ago |
Victor Julien
|
67429e523f
|
Fix compiler warning about incomplete prototype.
|
15 years ago |
Anoop Saldanha
|
fa373516c5
|
fixes the offset case for content matches + a case not handled by the prevous fix for multiple relative content matches. fix for payload.c dcepayload.c and uri.c
|
15 years ago |
Anoop Saldanha
|
92eb380594
|
multiple relative content matches changes for detect-engine-dcepayload.c and detect-engine-uri.c like how we did for detect-engine-payload.c
|
15 years ago |
Anoop Saldanha
|
5fb6981e9e
|
content handling changes in detect-engine-payload.c for multiple relative matches
|
15 years ago |
Anoop Saldanha
|
a059ff276e
|
byte test and byte jump update dce matching option
|
15 years ago |
Victor Julien
|
05d382f533
|
Fix broken stream engine config initialization: due wrong casts settings could be overwritten in memory.
|
15 years ago |
Victor Julien
|
ec277b292c
|
Fall back to the old mutex based queue's to see if that fixes an obscure lockup at higher optimization levels in gcc in file pcap mode.
|
15 years ago |
Victor Julien
|
ecb5fd3298
|
Add missing util-validate.h
|
15 years ago |
Pablo Rincon
|
b8b511a54e
|
Avoid mem allocations while searching on radix trees (temporal prefix)
|
15 years ago |
Victor Julien
|
1d74797b17
|
Attempt to work around NULL packets we're seeing ending up in queues when the compiler has optimized our code.
|
15 years ago |
Pablo Rincon
|
868d4614b9
|
Tag engine improvements. Output tags only on unified format. Added atomic counter for tagged hosts/sessions
|
15 years ago |
Victor Julien
|
8cdd02877f
|
Add unittests for ringbuffer.
|
15 years ago |
Victor Julien
|
e685579231
|
Add optional structure validation code.
|
15 years ago |
Victor Julien
|
b67fb5229b
|
Fix pcap file auto flow pinned runmode (disabled by default).
|
15 years ago |
Victor Julien
|
393acd77d2
|
Detection improvements: uricontent escaping now working, better negated pattern (content) handling.
|
15 years ago |
Gurvinder Singh
|
154a8b1ed9
|
fixed the build failure with profiling enabled
|
15 years ago |
Victor Julien
|
37eb2290b0
|
Add some checks for 'impossible' conditions that become possible after enabling optimizations :-/
|
15 years ago |
Victor Julien
|
1dbbdce0be
|
Add a -fno-tree-pre to our CFLAGS as it breaks the ringbuffers on Ubuntu 9.10/64 bit.
|
15 years ago |
Victor Julien
|
017b95f9ef
|
More thoroughly cleanup a Packet when we recycle it. Fixes a corner case where we'd have a invalid tcp packet but p->proto would still say IPPROTO_TCP because of a previous run. Fixes bug #187.
|
15 years ago |
William Metcalf
|
5580f3d9c2
|
PacketQueue postp added to TmEcodes for ipfw and pf_ring to silence compiler warnings
|
15 years ago |
William Metcalf
|
876057a4da
|
missing flow init in DetectTagTestPacket04 fix ut lockup on older os's
|
15 years ago |
Victor Julien
|
7454336ef5
|
Make SigWrapper private to detect-parse.c and rename to SigDuplWrapper to reflect it's use and purpose.
|
15 years ago |
Anoop Saldanha
|
9ecade76b9
|
in case of duplicate signatures used the one with the latest revision
|
15 years ago |
Pablo Rincon
|
eedafa3a17
|
Adding unittests for anchored pcres for anchored
|
15 years ago |
Pablo Rincon
|
bcb0b9ef9b
|
Moving urilen inspection to detect-engine-uri. Adding unittests for pcre /U and urilen, in combination with uricontent
|
15 years ago |
Anoop Saldanha
|
36e4b1830e
|
add pcre with U modifiers to the umatch sigmatch list. fix for bug 155
|
15 years ago |
Gurvinder Singh
|
8852b83fa7
|
flowbits, flowvars, pktvars, flow flags and app layer info added to alert-debug.log
|
15 years ago |
Pablo Rincon
|
95fef55507
|
Fix threshold handling ip addr
|
15 years ago |
Victor Julien
|
c67cf593c2
|
Disable alert-debuglog and unified1 in the default config. Add comments to the default config about pending packets, alert log types.
|
15 years ago |
Victor Julien
|
580b09c2b8
|
Make sure we inspect all outstanding reassembled stream chunks (smsg) if the stream is shutting down. Make sure to do inspect signatures that use dsize against the tcp packet payload, even if that payload was already added to the stream. Likewise, the dsize signatures are not inspected against the reassembled stream.
|
15 years ago |
Victor Julien
|
a3ff0e7210
|
Don't scan TCP packet payload if it was added to the stream. Inspect the tcp stream with the correct packet. Should fix #184 and #185.
|
15 years ago |
Victor Julien
|
d500a52b58
|
Fix valgrind error in tls unittest.
|
15 years ago |
Victor Julien
|
cff0a0bda2
|
Fix segv conditions caused by broken flow cleanup code.
|
15 years ago |
Pablo Rincon
|
a8cb8d830b
|
Fix for bug 186 and thresholding issue handling ip versions
|
15 years ago |
Victor Julien
|
6eb7eea705
|
Fix a data race for packet pool packets when defrag/tunnel code needs a packet.
|
15 years ago |
Victor Julien
|
a4cb7fced0
|
Fix thresholding code for packets that are neither (valid) ipv4 and ipv6.
|
15 years ago |
Jason MacLulich
|
ae095e585b
|
o Changed SCMalloc to DecodeThreadVarsAlloc in Decode thread initialization. (Ish) o Changed htons to noths. (Ish) o Added support for handling DAG cards running DSM modules and other non-standard ETH ERF types. o Added support for allowing gracefull restarts of the fetch thread if it fails to read an ERF properly.
|
15 years ago |
William Metcalf
|
d5590962ff
|
change LogInfo to LogDebug for icmp seq matches
|
15 years ago |