Victor Julien
2197f1a625
file-inspection: split 'file' output module into file-store and file-log. Store stores files. Log logs json records.
13 years ago
Victor Julien
8b1333a277
Add more flow lock assertions to the debug validation code.
13 years ago
Victor Julien
5ba41c7890
Fix locking error in filestore handling. Add debug validate check for asserting a flow is locked.
13 years ago
Martin Holste
25123b2044
Added license.
13 years ago
Martin Holste
c63017b2cc
Added some installation instructions to file_processor REAMDE.
13 years ago
Martin Holste
4030840212
Added contrib folder with file_processor utility which is a plugin framework for reading the files-json.log and processing and taking action based on the files observed.
13 years ago
Victor Julien
28d88746e4
Fix compiler warning and silence complaining unittests.
13 years ago
Victor Julien
860971eca0
Misc afpacket changes.
13 years ago
Victor Julien
8e48a2edfd
Fix NULL dereference in PacketPatternSearchWithStreamCtx code.
13 years ago
Eric Leblond
34b3f19465
af-packet: Implement zero copy
...
This patch adds support for zero copy to AF_PACKET running mode.
This requires to use the 'worker' mode which is the only one where
the threading architecture is simple enough to permit this without
heavy modification.
13 years ago
Eric Leblond
3593cb051e
decode: add PacketSetData funtion
...
This patch adds a function which can be used to set the payload
of a packet when a zero copy mode is used.
13 years ago
Eric Leblond
49b7b00fcf
af-packet: mmap support
...
This patch adds mmap support for af-packet. Suricata now makes
use of the ring buffer feature of AF_PACKET if 'use-mmap' variable
is set to yes on an interface.
13 years ago
Victor Julien
697e9e660f
Config should be set up in sysconfdir/suricata. Add reference to oinkmaster guide.
13 years ago
Victor Julien
73a1b97267
Improve config details overview at the end of configure.
13 years ago
Eric Leblond
b2ebd4a138
build: enable af-packet by default
13 years ago
Eric Leblond
ef46345792
Add sexy information messages to configure output.
13 years ago
Eric Leblond
5ea1b1d15e
Fix PCRE-JIT message
13 years ago
Eric Leblond
65b26e6ae5
Remove autogen.sh generated files.
13 years ago
Eric Leblond
338608842e
Improve output
13 years ago
Eric Leblond
4c3f0b258e
del rules file deleted
13 years ago
Eric Leblond
25804f5aa8
Add install-conf command to build system.
...
This patch adds support for customisation of suricata.yaml and
automatic download of emerging threat GPL rules. By running
'make install-full' after 'make install', files necessary to run
suricata are copied in the configuration directory and the latest
ruleset is downloaded and installed. Suricata can then be run
without files edition.
This patch has a special treatment for the windows build which
requires some different paths.
suricata.yaml is also updated to load all rules files provided by
emergingthreat ruleset.
13 years ago
Victor Julien
3702a33ae9
file-inspection: support POST requests that do not use multipart.
13 years ago
Victor Julien
64827e3864
file-inspection: use filename= value from Content-Disposition where available to determine the filename in GET requests.
13 years ago
Victor Julien
6585cb89d3
Fix UtilMiscParseSizeStringTest01 unittest on 32 bit.
13 years ago
Anoop Saldanha
35435f3284
All http_http_stat_code modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_STAT_CODE. Also remove dummy match/free functions for stat code and stat msg
13 years ago
Anoop Saldanha
507e1b66e0
All http_http_stat_msg modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_STAT_MSG
13 years ago
Anoop Saldanha
059ee217ff
All http_http_raw_uri modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_RAW_URI
13 years ago
Anoop Saldanha
b1a0d35106
All http_http_cookie modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_COOKIE
13 years ago
Anoop Saldanha
49bdad9345
All http_http_method modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_METHOD
13 years ago
Anoop Saldanha
97d8fc9cba
All http_http_raw_header modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_RAW_HEADER
13 years ago
Anoop Saldanha
97308674ee
All http_http_header modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_HEADER
13 years ago
Anoop Saldanha
1acb7cdc7d
All http_server_body modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_SERVER_BODY
13 years ago
Anoop Saldanha
a5b46e727c
All http_client_body modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_CLIENT_BODY
13 years ago
Anoop Saldanha
4810ee9c5f
All uricontent modified patterns now are DETECT_CONTENT and not DETECT_URICONTENT. Step towards unifying all content based patterns. Makes way for easier management of patterns
13 years ago
Anoop Saldanha
93d7a6e671
code cleanup. Remove unused functions
13 years ago
Anoop Saldanha
eb07c345b8
code cleanup - replace SigMatchAppendThreshold with SigMatchAppendSMToList
13 years ago
Anoop Saldanha
dd7e710f35
code cleanup - replace SigMatchAppendPostMatch with SigMatchAppendSMToList
13 years ago
Anoop Saldanha
a4638fb0ad
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
Anoop Saldanha
ff38d42bf1
code cleanup - replace SigMatchAppendTag with SigMatchAppendSMToList
13 years ago
Anoop Saldanha
ac68c3f893
code cleanup - replace SigMatchAppendDcePayload with SigMatchAppendSMToList
13 years ago
Anoop Saldanha
6cab663bf0
code cleanup - replace SigMatchAppendPayload with SigMatchAppendSMToList
13 years ago
Anoop Saldanha
c4cb37b8da
code cleanup - replace SigMatchAppendUricontent with SigMatchAppendSMToList
13 years ago
Anoop Saldanha
c9af50ea0c
code cleanup - replace SigMatchAppendAppLayer with SigMatchAppendSMToList
13 years ago
Anoop Saldanha
bbb9f35f26
code cleanup - replace SigMatchGetLastSM with SigMatchGetLastSMFromLists
13 years ago
Anoop Saldanha
ab35b98f76
code cleanup - remove DetectContentGetLastPattern. Replace it with SigMatchGetLastSMFromLists
13 years ago
Anoop Saldanha
d85ab5ab1f
code cleanup - remove DetectContentFindNextApplicableSM
13 years ago
Anoop Saldanha
802350f65a
code cleanup - remove DetectContentHasPrevSMPattern
13 years ago
Anoop Saldanha
9652c3672d
code cleanup - remove SigMatchGetLastPattern
13 years ago
Anoop Saldanha
e851804c92
code cleanup - remove DetectUricontentGetLastPattern
13 years ago
Anoop Saldanha
dcb2afb02f
Use sm_list to differentiate between different content types while retrieving pattern ids instead of sm_type
13 years ago