You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/rules
Philippe Antoine 51a6e69b4e rfb: limit strings length
Ticket: 8731

Adds a configurable limit to string lengths to avoid to retain
too much memory for too long, and avoid producing log events
that are too big

(cherry picked from commit f9515dc71d)
4 days ago
..
Makefile.am snmp: add snmp-events.rules file 4 months ago
README.md detect/firewall: support alert in default app policy 3 months ago
app-layer-events.rules app-layer: protocol change API 9 years ago
bittorrent-events.rules bittorrent: add bittorrent-events.rules file 4 months ago
decoder-events.rules af-packet: add event for packets truncated by af-packet 2 years ago
dhcp-events.rules dhcp: add dhcp app-layer rules file 8 years ago
dnp3-events.rules dnp3: bounds reassembly 4 months ago
dns-events.rules dns: improved handling of corrupt additionals 2 years ago
enip-events.rules enip: convert to rust 2 years ago
files.rules rules: spelling 3 years ago
ftp-events.rules ftp: do not error the flow on file before port 2 months ago
http-events.rules http1: limit the number of compression bombs per flow 2 months ago
http2-events.rules http2: protection against decompression bombs 4 months ago
ipsec-events.rules rules/ike: fix ike event names that have changed 2 years ago
kerberos-events.rules Kerberos 5: rename weak crypto to weak encryption, and log it 8 years ago
ldap-events.rules ldap: bound the number of responses 4 months ago
mdns-events.rules rules: add mdns rules 1 year ago
modbus-events.rules rules/modbus: remove rule for event that not longer exists 2 years ago
mqtt-events.rules mqtt: bounds number of messages per tx 2 months ago
nfs-events.rules nfs: limits the number of active transactions per flow 5 years ago
ntp-events.rules Add event rules for NTP events 9 years ago
pgsql-events.rules pgsql: add events 2 years ago
pop3-events.rules pop3: fix event rule 1 year ago
quic-events.rules quic: handle fragmented hello over multiple packets 2 years ago
rfb-events.rules rfb: limit strings length 4 days ago
smb-events.rules smb: checks against nbss records length 4 years ago
smtp-events.rules smtp: recover from invalid BDAT command syntax 3 weeks ago
snmp-events.rules snmp: add snmp-events.rules file 4 months ago
ssh-events.rules rules: add SSH decoder events rules 6 years ago
stream-events.rules stream: add TCP urgent handling options 2 years ago
tls-events.rules tls: implement alert parser 1 year ago
websocket-events.rules app-layer: websockets protocol support 2 years ago

README.md

Suricata Reserved SID Allocations

Unless otherwise noted, each component or protocol is allocated 1000 signature IDs.

Components

Component Start End
Decoder 2200000 2200999
Firewall 2201000 2201999
Stream 2210000 2210999
Generic App-Layer 2260000 2260999

App-Layer Protocols

Protocol Start End
SMTP 2220000 2220999
HTTP 2221000 2221999
NTP 2222000 2222999
NFS 2223000 2223999
IPsec 2224000 2224999
SMB 2225000 2225999
Kerberos 2226000 2226999
DHCP 2227000 2227999
SSH 2228000 2228999
MQTT 2229000 2229999
TLS 2230000 2230999
QUIC 2231000 2231999
FTP 2232000 2232999
POP3 2236000 2236999
LDAP 2237000 2237999
SNMP 2238000 2238999
DNS 2240000 2240999
PGSQL 2241000 2241999
mDNS 2242000 2242999
Bittorent 2243000 2243999
MODBUS 2250000 2250999
DNP3 2270000 2270999
HTTP2 2290000 2290999