Jason Ish
							
						 
						
							 
							
							
							
								
							
								8c98fa452f 
								
							
								 
							
						 
						
							
							
								
								dnp3/eve: update for regenerated dnp3 object logging code  
							
							 
							
							... 
							
							
							
							Migration from Jansson to JsonBuilder. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								bf8d8c573a 
								
							
								 
							
						 
						
							
							
								
								dnp3/eve: regenerator object logging code  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								85eaa2276c 
								
							
								 
							
						 
						
							
							
								
								scripts/dnp3-gen: update to generate JsonBuilder code  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								03efbccfe6 
								
							
								 
							
						 
						
							
							
								
								jsonbuilder: set_float, append_float methods  
							
							 
							
							... 
							
							
							
							New methods for setting and appending float values. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								ccc057fdc9 
								
							
								 
							
						 
						
							
							
								
								dnp3/eve: convert to jsonbuilder (non generated code)  
							
							 
							
							... 
							
							
							
							First step of converting DNP3 to JsonBuilder by first converting
the non-generated code. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								4976afd96a 
								
							
								 
							
						 
						
							
							
								
								script/dnp3-gen: update generator to reflect in tree changes  
							
							 
							
							... 
							
							
							
							Some changes were made to the generated files instead of the
generator script. Update the script to generate what is
in the current state of the in-tree generated files. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								6f7d8e50c8 
								
							
								 
							
						 
						
							
							
								
								src: use FatalError whenever possible  
							
							 
							
							... 
							
							
							
							Replaces all patterns of SCLogError() followed by exit() with
FatalError(). Cocci script to do this:
@@
constant C;
constant char[] msg;
@@
- SCLogError(C,
+ FatalError(SC_ERR_FATAL,
  msg);
- exit(EXIT_FAILURE);
Closes redmine ticket 3188. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								901fbae7b9 
								
							
								 
							
						 
						
							
							
								
								doc: Add byte_math documentation  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								f6a399f154 
								
							
								 
							
						 
						
							
							
								
								general: Correct typos  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								fb409664d2 
								
							
								 
							
						 
						
							
							
								
								detect: byte_math support  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								1a726731e4 
								
							
								 
							
						 
						
							
							
								
								detect: Use byte-math to byte var handling func  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								0e4ba7b13e 
								
							
								 
							
						 
						
							
							
								
								detect: Add byte_math detector  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								ac01adc260 
								
							
								 
							
						 
						
							
							
								
								detect: Add utility module for byte var handling  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								c1673908ac 
								
							
								 
							
						 
						
							
							
								
								eve/alert: minor cleanups  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								d2c48d4faf 
								
							
								 
							
						 
						
							
							
								
								eve/alert: move files logging into util func  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								3dacbcddef 
								
							
								 
							
						 
						
							
							
								
								eve/alert: move app-layer logic into a util func  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								537fb7a1c6 
								
							
								 
							
						 
						
							
							
								
								hyperscan: better error message if not compiled  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								ece29c4210 
								
							
								 
							
						 
						
							
							
								
								ssh: fix incomplete return for ssh kex  
							
							 
							
							... 
							
							
							
							In the case where we already parsed some records 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								ca6d072297 
								
							
								 
							
						 
						
							
							
								
								dcerpc: detect right parsing of empty op version  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Philippe Antoine
							
						 
						
							 
							
							
							
								
							
								abe3f6e6ef 
								
							
								 
							
						 
						
							
							
								
								rfb: set app proto for signature keyword rfb.secresult  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								a58fdcd41d 
								
							
								 
							
						 
						
							
							
								
								suricata.yaml.in: update stream-depth description  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								496306e6a9 
								
							
								 
							
						 
						
							
							
								
								doc: update stream-depth description  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								ec07f58705 
								
							
								 
							
						 
						
							
							
								
								doc: update file-store stream depth description  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								2f32d7f831 
								
							
								 
							
						 
						
							
							
								
								filestore: Use proper string in error case  
							
							 
							
							... 
							
							
							
							When make-open-files has an invalid value, the incorrect value was being
displayed improperly 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								823f6b35d0 
								
							
								 
							
						 
						
							
							
								
								filestore: Validate stream-depth when non-zero  
							
							 
							
							... 
							
							
							
							Make sure that configured non-zero values for stream-depth are
greater than stream_config.depth 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								6bb89c37f1 
								
							
								 
							
						 
						
							
							
								
								output/json: Correct clang warning  
							
							 
							
							... 
							
							
							
							This commit corrects the warning for mismatched type. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								b2c1dab2da 
								
							
								 
							
						 
						
							
							
								
								output/alert: Correct FORWARD_NULL Coverity issue.  
							
							 
							
							... 
							
							
							
							This commit corrects the FORWARD_NULL issue in AlertJson by
null-checking p->flow 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								bd22e0d7a4 
								
							
								 
							
						 
						
							
							
								
								output/ftp: Correct Coverity DEADCODE issue  
							
							 
							
							... 
							
							
							
							This commit corrects the deadcode (CID 1465224) issue in
EveFTPLogCommand. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								ac70d925f5 
								
							
								 
							
						 
						
							
							
								
								filestore: Correct Coverity RESOURCE_LEAK issue  
							
							 
							
							... 
							
							
							
							This commit corrects the RESOURCE_LEAK issue (CID 1465222) of the `FILE`
pointer. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								2d055ed1f7 
								
							
								 
							
						 
						
							
							
								
								detect: Correct Coverity REVERSE_INULL issue  
							
							 
							
							... 
							
							
							
							This commit corrects the "Null pointer dereferences" issue (CID
1465221). 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								db75675f45 
								
							
								 
							
						 
						
							
							
								
								qa: add atoi to list of banned functions  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								d27b407bc3 
								
							
								 
							
						 
						
							
							
								
								pfring: fix StringParse* warnings  
							
							 
							
							... 
							
							
							
							Closes redmine ticket 3808. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								7cbb8c44c5 
								
							
								 
							
						 
						
							
							
								
								ttl: Make IPV4 TTL uint_8t  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Shivani Bhardwaj
							
						 
						
							 
							
							
							
								
							
								4ed72addf3 
								
							
								 
							
						 
						
							
							
								
								src: remove multiple uses of atoi  
							
							 
							
							... 
							
							
							
							atoi() and related functions lack a mechanism for reporting errors for
invalid values. Replace them with calls to the appropriate
ByteExtractString* functions.
Partially closes redmine ticket 3053. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Emmanuel Thompson
							
						 
						
							 
							
							
							
								
							
								6e5d64f102 
								
							
								 
							
						 
						
							
							
								
								detect/asn1: Simplify errors and checks  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Emmanuel Thompson
							
						 
						
							 
							
							
							
								
							
								4fc45b5c60 
								
							
								 
							
						 
						
							
							
								
								detect/asn1: Update ASN1 struct lifetime  
							
							 
							
							... 
							
							
							
							- 'static is only realistic when allocating and leaking it over the
FFI boundary 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Emmanuel Thompson
							
						 
						
							 
							
							
							
								
							
								627e90a4bd 
								
							
								 
							
						 
						
							
							
								
								detect/asn1: Log out errors  
							
							 
							
							... 
							
							
							
							- Failure to parse asn1-max-frames
- Failure on asn1 detection checks 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Emmanuel Thompson
							
						 
						
							 
							
							
							
								
							
								88601b1993 
								
							
								 
							
						 
						
							
							
								
								detect/asn1: Update relative_offset keyword  
							
							 
							
							... 
							
							
							
							- To be consistent with recent C version changes
- Add checks for over/underflows 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Emmanuel Thompson
							
						 
						
							 
							
							
							
								
							
								275f6ae96f 
								
							
								 
							
						 
						
							
							
								
								detect/asn1: Remove asn1 C parser  
							
							 
							
							... 
							
							
							
							- In favor of rust parser 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Emmanuel Thompson
							
						 
						
							 
							
							
							
								
							
								7af6cdb7ec 
								
							
								 
							
						 
						
							
							
								
								detect/asn1: Update asn1 C files to use rust code  
							
							 
							
							... 
							
							
							
							Mark rust extern "C" functions as pub in asn1 module to expose via cbindgen
Update detect-asn1.c/h to use rust functions 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Emmanuel Thompson
							
						 
						
							 
							
							
							
								
							
								63704fdf13 
								
							
								 
							
						 
						
							
							
								
								rust/asn1: Introduce ASN1 rust module  
							
							 
							
							... 
							
							
							
							This module uses the `der-parser` crate to parse ASN1 objects in order to replace src/util-decode-asn1.c
It also handles the parsing of the asn1 keyword rules and detection checks performed in src/detect-asn1.c 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Emmanuel Thompson
							
						 
						
							 
							
							
							
								
							
								6b8517dc12 
								
							
								 
							
						 
						
							
							
								
								rust: Update der, kerberos and snmp parser dependencies  
							
							 
							
							... 
							
							
							
							- The update to der-parser allows us to use the latest API changes 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								dfcc8a88f6 
								
							
								 
							
						 
						
							
							
								
								util/proto: Convert validation routine to bool  
							
							 
							
							... 
							
							
							
							This commit changes the signature of the protocol validation code to
bool and simplifies the validation steps. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								1e8d4af29a 
								
							
								 
							
						 
						
							
							
								
								output/json: Improve protocol output handling  
							
							 
							
							... 
							
							
							
							Improve protocol label handling by eliminating an unneeded copy.
Additionally, unknown protocol values are no longer zero-padded. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								a06a706078 
								
							
								 
							
						 
						
							
							
								
								output/flow: Improve protocol output handling  
							
							 
							
							... 
							
							
							
							This commit improves handling of the protocol label by removing an
unnecessary copy.
Additionally, unknown protocol values are no longer zero-padded. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								5776a98f67 
								
							
								 
							
						 
						
							
							
								
								log/syslog: Improve protocol output handling  
							
							 
							
							... 
							
							
							
							Move protocol handling outside of the packet alert loop. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								0a1c36759a 
								
							
								 
							
						 
						
							
							
								
								log: Use updated SCProtoNameValid signature  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jeff Lucovsky
							
						 
						
							 
							
							
							
								
							
								a843b36c97 
								
							
								 
							
						 
						
							
							
								
								output/lua: Remove unused proto code  
							
							 
							
							... 
							
							
							
							This commit removes unused protocol string handling logic. 
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								43b9bfaed4 
								
							
								 
							
						 
						
							
							
								
								applayer template (rust): convert to JsonBuilder  
							
							 
							
							
							
						 
						
							5 years ago  
						
					 
				
					
						
							
							
								 
								Jason Ish
							
						 
						
							 
							
							
							
								
							
								d71fc50212 
								
							
								 
							
						 
						
							
							
								
								applayer template (C): convert to JsonBuilder  
							
							 
							
							
							
						 
						
							5 years ago