Eric Leblond
							
						 
						
							 
							
							
							
								
							
								b055a21d63 
								
							
								 
							
						 
						
							
							
								
								doc: create doxygen group for state detection.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								0468dbd575 
								
							
								 
							
						 
						
							
							
								
								doc: doxygenise some comments.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								a64eea9628 
								
							
								 
							
						 
						
							
							
								
								Fix minor error message.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								92d74fd480 
								
							
								 
							
						 
						
							
							
								
								doc: Add missing params in func description.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								fdfa85de37 
								
							
								 
							
						 
						
							
							
								
								Add comment to describe file content.  
							
							 
							
							... 
							
							
							
							The name of the file is not really explicit. This patch adds doxygen
to have an easy to use description in the generated documentation. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								830ca7c2c8 
								
							
								 
							
						 
						
							
							
								
								source-nfq: suppress insecable space.  
							
							 
							
							... 
							
							
							
							This patch supresses an insecable space and fixes an
indentation. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								01beefc1c9 
								
							
								 
							
						 
						
							
							
								
								pfring: improve error handling  
							
							 
							
							... 
							
							
							
							Treat TmThreadsSlotProcessPkt return. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								0d7f25580d 
								
							
								 
							
						 
						
							
							
								
								pcap: improve error handling.  
							
							 
							
							... 
							
							
							
							Treat TmThreadsSlotProcessPkt return. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								c469824bed 
								
							
								 
							
						 
						
							
							
								
								af-packet: improve error handling  
							
							 
							
							... 
							
							
							
							The return of TmThreadsSlotProcessPkt function was not handled. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								9ac51900f6 
								
							
								 
							
						 
						
							
							
								
								Fix broken macro call.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								4071d3cf57 
								
							
								 
							
						 
						
							
							
								
								PACKET_INITIALIZE is enough for packet init.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								d296223ffe 
								
							
								 
							
						 
						
							
							
								
								cuda: Suppress sprintf usage.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								6bf15bac31 
								
							
								 
							
						 
						
							
							
								
								Fix various packet access.  
							
							 
							
							... 
							
							
							
							The coccinelle based tests have detected invalid uses of access to
Packet data. This patch fixes the detected problems. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								eef3e28b17 
								
							
								 
							
						 
						
							
							
								
								invalid use of strncat.  
							
							 
							
							... 
							
							
							
							sltrlcat must be used instead. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								2be09b0c86 
								
							
								 
							
						 
						
							
							
								
								Fix Defrag unit test.  
							
							 
							
							... 
							
							
							
							This patch fixes the unittest for IPV4 defrag. The direct usage
of the pkt pointer in the Packet structure is not allowed. This
is fixed by using PacketCopyData function.
This modification was requiring some other fixes, like using
memcmp to compare data instead of an iteration on pkt pointer. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								324986694a 
								
							
								 
							
						 
						
							
							
								
								decode: improve and fix comments.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								24f15fa321 
								
							
								 
							
						 
						
							
							
								
								Don't warn about non enable non existing output module  
							
							 
							
							... 
							
							
							
							This patch modifies output module loading to only trigger alert
message for non existing modules when they are loaded. It also
warn about unified1 removal. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								3944357058 
								
							
								 
							
						 
						
							
							
								
								Remove unified related enum.  
							
							 
							
							... 
							
							
							
							This patch removes the enum related to unified1 output. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								391d813c82 
								
							
								 
							
						 
						
							
							
								
								Remove unified1 output module.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								047fcd6ade 
								
							
								 
							
						 
						
							
							
								
								Add missing case sensitive to insensitive conversions for http_header, http_raw_header, http_method, http_cookie and http_raw_uri with 'nocase' set.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								bde55578d6 
								
							
								 
							
						 
						
							
							
								
								Override HTP IDS personality normalizing the query string to lowercase. Bug  #362 .  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								7ef34b7bcc 
								
							
								 
							
						 
						
							
							
								
								Exlcude DSIZE LT case from setting the 'need payload' mask bit as it can include 0, which means no payload.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								09b5dca343 
								
							
								 
							
						 
						
							
							
								
								Consider signatures with the flags keyword to be packet inspecting only, not stream.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								30d84ab20d 
								
							
								 
							
						 
						
							
							
								
								Unlock flow in StreamTcpSegmentForEach if there is no TCP session.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								9aeadd5696 
								
							
								 
							
						 
						
							
							
								
								prelude: suppress unused variable.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								db17f3de6c 
								
							
								 
							
						 
						
							
							
								
								prelude: add stream segment dump  
							
							 
							
							... 
							
							
							
							This patch should fix  #355 . 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								2073b9db0c 
								
							
								 
							
						 
						
							
							
								
								debuglog: uses state selection system.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								1596241687 
								
							
								 
							
						 
						
							
							
								
								debuglog: fix segment logging.  
							
							 
							
							... 
							
							
							
							StreamSegmentForEach returns the number of segments or < 0 in case
of error. This patch synchronizes debuglog output module with this
behaviour. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								3644e90a2c 
								
							
								 
							
						 
						
							
							
								
								Don't set higher transaction id's in HTTP sessions than we have.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								67cea09911 
								
							
								 
							
						 
						
							
							
								
								Handle failing thread modules that are called by the Pcap file callback.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								498d1d9287 
								
							
								 
							
						 
						
							
							
								
								Update default suricata.yaml to use more sane settings for EXTERNAL_NET and AIM_SERVERS.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								bfff14aa78 
								
							
								 
							
						 
						
							
							
								
								Improve error detection in the port and address parsing in signatures. Bug  #295 .  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Anoop Saldanha
							
						 
						
							 
							
							
							
								
							
								ba6bada155 
								
							
								 
							
						 
						
							
							
								
								change rev field in Signature to u32 and use strotoul to extract the value. Cleanup some dead code/comments  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Anoop Saldanha
							
						 
						
							 
							
							
							
								
							
								ed3b44b3b5 
								
							
								 
							
						 
						
							
							
								
								fix parsing content keywords. We are more strict now. All content keywords need to be enclosed in double quotes. Better validation for sid, priority and rev keywords  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								18da4a8b73 
								
							
								 
							
						 
						
							
							
								
								Add missing cuda header file causing 'make distcheck' to fail.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								c0bc83458c 
								
							
								 
							
						 
						
							
							
								
								Bump version to 1.1beta3.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								89c38b0ced 
								
							
								 
							
						 
						
							
							
								
								prelude: fix compilation  
							
							 
							
							... 
							
							
							
							PrintInet was used without inclusion of 'util-print.h'. This was
causing a compilation failure. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								39edb23ac4 
								
							
								 
							
						 
						
							
							
								
								Support stream.inline mode in unified2 tcp segments logging.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								2e2e80b812 
								
							
								 
							
						 
						
							
							
								
								Add packet alert flag to indicate a match happened (partly) in the app layer state. Make unified2 use this flag.  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								128261cb97 
								
							
								 
							
						 
						
							
							
								
								unified2: Fix event_id computation  
							
							 
							
							... 
							
							
							
							This patch fixes event_id computation which was not incremented
for each alert. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								b3023643ec 
								
							
								 
							
						 
						
							
							
								
								unified2: fix multiple alerts case  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								7fd1e9cacc 
								
							
								 
							
						 
						
							
							
								
								unified2: synchronize IPv4 and IPv6 code  
							
							 
							
							... 
							
							
							
							IPv6 code was missing some points. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								839b0d9bfe 
								
							
								 
							
						 
						
							
							
								
								unified2: switch to event->packet->packet mode.  
							
							 
							
							... 
							
							
							
							Attach multiple packets to an event instead of using one
event data per packet. This is currrently unsupported by
reporting frontend but at least we don't have multiple
alerts. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								316f2d7289 
								
							
								 
							
						 
						
							
							
								
								unified2: segment callback log raw packet.  
							
							 
							
							... 
							
							
							
							As we don't have any trustable information about the ethernet
header, we can simply log RAW packet to avoid to confuse the
analyst. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								a03a402b83 
								
							
								 
							
						 
						
							
							
								
								unified2: set datalink to correct value.  
							
							 
							
							... 
							
							
							
							The value of datalink could have been modified if the logging
of segment was attempted. This patch restore it to a correct value. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								50ddd2df43 
								
							
								 
							
						 
						
							
							
								
								Restore old barnyard2 support.  
							
							 
							
							... 
							
							
							
							Some old version of barnyard2 were needing a workaround in the
packet header building. THis patch introduces a enable-old-barnyard2
configure flag which can be used to restore this behaviour. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								2f24987f15 
								
							
								 
							
						 
						
							
							
								
								unified2: improve packet logging logic.  
							
							 
							
							... 
							
							
							
							This patch improves packet logging logic and fix some place
regarding alert generation (event_id, ethernet header). 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Eric Leblond
							
						 
						
							 
							
							
							
								
							
								628bfcc1b9 
								
							
								 
							
						 
						
							
							
								
								stream: Change return of StreamSegmentForEach  
							
							 
							
							... 
							
							
							
							The function now returns the number of segment where the callback
has ben runned successfully. 
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Victor Julien
							
						 
						
							 
							
							
							
								
							
								c672bdd863 
								
							
								 
							
						 
						
							
							
								
								Improve atomic operation support detection.  Fixes   #342 .  
							
							 
							
							
							
						 
						
							14 years ago  
						
					 
				
					
						
							
							
								 
								Anoop Saldanha
							
						 
						
							 
							
							
							
								
							
								0edf053f31 
								
							
								 
							
						 
						
							
							
								
								if app layer inspection is disabled, immediately set the eof flag  
							
							 
							
							
							
						 
						
							14 years ago