..
Makefile.am
file: implement filesize keyword. #489 .
13 years ago
action-globals.h
…
alert-debuglog.c
free flowvar entries in flow after live rule swap. Sync flowbits entries into packet struct to be used by alert debuglog when alert debuglog is enabled
13 years ago
alert-debuglog.h
…
alert-fastlog.c
OpenBSD: introduce SCLocalTime function.
13 years ago
alert-fastlog.h
…
alert-pcapinfo.c
spelling corrections documented in redmine bug#533
13 years ago
alert-pcapinfo.h
…
alert-prelude.c
Do not use underscored config vars internally.
13 years ago
alert-prelude.h
…
alert-syslog.c
Set DROP flag for reject action so in addition to sending the rst, in IPS mode also drop the offending packet.
13 years ago
alert-syslog.h
…
alert-unified2-alert.c
inline: fix unified2 alert direction selection
13 years ago
alert-unified2-alert.h
…
app-layer-dcerpc-common.h
…
app-layer-dcerpc-udp.c
Fix compiler warning.
13 years ago
app-layer-dcerpc-udp.h
…
app-layer-dcerpc.c
dcerpc/smb/smb2: more robust error checking, cosmetic code updates.
13 years ago
app-layer-dcerpc.h
…
app-layer-detect-proto.c
Add new command line option --list-app-layer-protocols to list supported app layer protocols in sigs
13 years ago
app-layer-detect-proto.h
Add new command line option --list-app-layer-protocols to list supported app layer protocols in sigs
13 years ago
app-layer-ftp.c
Add new command line option --list-app-layer-protocols to list supported app layer protocols in sigs
13 years ago
app-layer-ftp.h
…
app-layer-htp-body.c
http: body inspection improvement
13 years ago
app-layer-htp-body.h
File carving -- enable reponse file extraction
13 years ago
app-layer-htp-file.c
filemd5: add support code for md5 handling for signatures.
13 years ago
app-layer-htp-file.h
file extract: split toserver and toclient tracking
13 years ago
app-layer-htp.c
stream/app layer: add Truncate app layer callback that is called if stream depth is reached. Use it to trunc open files in HTTP.
13 years ago
app-layer-htp.h
Convert to atomic and disable check on HTP config change.
13 years ago
app-layer-nbss.h
…
app-layer-parser.c
stream/app layer: call new Truncate callback for data gap case as well.
13 years ago
app-layer-parser.h
stream/app layer: add Truncate app layer callback that is called if stream depth is reached. Use it to trunc open files in HTTP.
13 years ago
app-layer-protos.c
…
app-layer-protos.h
…
app-layer-smb.c
dcerpc/smb/smb2: more robust error checking, cosmetic code updates.
13 years ago
app-layer-smb.h
…
app-layer-smb2.c
dcerpc/smb/smb2: more robust error checking, cosmetic code updates.
13 years ago
app-layer-smb2.h
…
app-layer-smtp.c
Add new command line option --list-app-layer-protocols to list supported app layer protocols in sigs
13 years ago
app-layer-smtp.h
Support for smtp decoder events
13 years ago
app-layer-ssh.c
Add new command line option --list-app-layer-protocols to list supported app layer protocols in sigs
13 years ago
app-layer-ssh.h
…
app-layer-ssl.c
tls: keep pointers to all certificates in chain
13 years ago
app-layer-ssl.h
tls: keep pointers to all certificates in chain
13 years ago
app-layer-tls-handshake.c
tls: keep pointers to all certificates in chain
13 years ago
app-layer-tls-handshake.h
ssl parser fix/updates
13 years ago
app-layer.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
app-layer.h
…
conf-yaml-loader.c
Add line number to warning about mangled yaml parameters. Limit number of warnings to 10.
13 years ago
conf-yaml-loader.h
…
conf.c
conf api: remove dead code
13 years ago
conf.h
Allow other yaml files to be included in the main yaml.
13 years ago
counters.c
cleaning: fix warning when building with clang.
13 years ago
counters.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
cuda-packet-batcher.c
Delay Detect threads initialization
13 years ago
cuda-packet-batcher.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
cuda-ptxdump.h
…
data-queue.c
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
data-queue.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
debug.h
…
decode-ethernet.c
…
decode-ethernet.h
…
decode-events.c
Fix bug in app layer event handling causing http event rules to fail loading.
13 years ago
decode-events.h
decode: decode IPv6-in-IPv6
13 years ago
decode-gre.c
…
decode-gre.h
…
decode-icmpv4.c
Various fixes and improvements based on feedback by Coverity analyzer.
13 years ago
decode-icmpv4.h
csum function fixes. Improves alert accuracy. FPs on invalid-csums decoder rules fixed
13 years ago
decode-icmpv6.c
icmpv6: for ICMPv6 info messages set payload ptr and length to right after 4 byte hdr.
13 years ago
decode-icmpv6.h
icmpv6: for ICMPv6 info messages set payload ptr and length to right after 4 byte hdr.
13 years ago
decode-ipv4.c
Set the packet protocol only if it can parsed without error
13 years ago
decode-ipv4.h
csum function fixes. Improves alert accuracy. FPs on invalid-csums decoder rules fixed
13 years ago
decode-ipv6.c
Add counters for IPv4 in IPv6 and IPv6 in IPv6
13 years ago
decode-ipv6.h
ipv6: improve handling of packets with duplicate (or more) ipv6 extension headers.
13 years ago
decode-ppp.c
…
decode-ppp.h
…
decode-pppoe.c
…
decode-pppoe.h
…
decode-raw.c
…
decode-raw.h
…
decode-sctp.c
…
decode-sctp.h
…
decode-sll.c
…
decode-sll.h
…
decode-tcp.c
…
decode-tcp.h
csum function fixes. Improves alert accuracy. FPs on invalid-csums decoder rules fixed
13 years ago
decode-teredo.c
Add teredo counter.
13 years ago
decode-teredo.h
Teredo tunnel supports
13 years ago
decode-udp.c
Teredo tunnel supports
13 years ago
decode-udp.h
coverity fixes
13 years ago
decode-vlan.c
…
decode-vlan.h
…
decode.c
Add counters for IPv4 in IPv6 and IPv6 in IPv6
13 years ago
decode.h
Add counters for IPv4 in IPv6 and IPv6 in IPv6
13 years ago
defrag.c
defrag: prealloc more frags.
13 years ago
defrag.h
…
detect-ack.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-ack.h
…
detect-app-layer-event.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
detect-app-layer-event.h
Support for app layer decoder events added + app_layer_event keyword added
13 years ago
detect-asn1.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-asn1.h
…
detect-byte-extract.c
byte_extract_id var now a non-global de_ctx specific var
13 years ago
detect-byte-extract.h
byte_extract_id var now a non-global de_ctx specific var
13 years ago
detect-bytejump.c
Minor unittest fixes to make Coverity happy.
13 years ago
detect-bytejump.h
…
detect-bytetest.c
Minor unittest fixes to make Coverity happy.
13 years ago
detect-bytetest.h
…
detect-classtype.c
clean classification config API
13 years ago
detect-classtype.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-content.c
Minor unittest fixes to make Coverity happy.
13 years ago
detect-content.h
http user agent keyword + mpm + inspection + fast pattern support added
13 years ago
detect-csum.c
csum function fixes. Improves alert accuracy. FPs on invalid-csums decoder rules fixed
13 years ago
detect-csum.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-dce-iface.c
Minor unittest fixes to make Coverity happy.
13 years ago
detect-dce-iface.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-dce-opnum.c
code cleanup - replace SigMatchAppendAppLayer with SigMatchAppendSMToList
13 years ago
detect-dce-opnum.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-dce-stub-data.c
code cleanup - replace SigMatchAppendAppLayer with SigMatchAppendSMToList
13 years ago
detect-dce-stub-data.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-depth.c
spelling corrections documented in redmine bug#533
13 years ago
detect-depth.h
…
detect-detection-filter.c
fix detection filter unittests to reflect recent fixes
13 years ago
detect-detection-filter.h
…
detect-distance.c
spelling corrections documented in redmine bug#533
13 years ago
detect-distance.h
…
detect-dsize.c
spelling corrections documented in redmine bug#533
13 years ago
detect-dsize.h
…
detect-engine-address-ipv4.c
…
detect-engine-address-ipv4.h
…
detect-engine-address-ipv6.c
Fix compilation with profiling enabled. Minor unittest fixes.
13 years ago
detect-engine-address-ipv6.h
…
detect-engine-address.c
Improve error reporting in case of syntax errors in the address and port vars.
13 years ago
detect-engine-address.h
bug #454 - global check to see if address and port vars are properly configured
13 years ago
detect-engine-alert.c
No longer pass StreamMsg to output for alert logging, instead use the same callback code as is used for state alerts.
13 years ago
detect-engine-alert.h
No longer pass StreamMsg to output for alert logging, instead use the same callback code as is used for state alerts.
13 years ago
detect-engine-analyzer.c
rule analyzer: make analyzer aware of http_user_agent pcre flag /V.
13 years ago
detect-engine-analyzer.h
rule analyzer: fix fast pattern analyzer reporting wrong filename (same as rule analyzer).
13 years ago
detect-engine-content-inspection.c
All http_http_stat_code modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_STAT_CODE. Also remove dummy match/free functions for stat code and stat msg
13 years ago
detect-engine-content-inspection.h
http user agent keyword + mpm + inspection + fast pattern support added
13 years ago
detect-engine-dcepayload.c
Disable dce unittests that tick off clamav. #458 .
13 years ago
detect-engine-dcepayload.h
…
detect-engine-event.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-engine-event.h
decode: decode IPv6-in-IPv6
13 years ago
detect-engine-file.c
file: implement filesize keyword. #489 .
13 years ago
detect-engine-file.h
File carving -- enable reponse file extraction
13 years ago
detect-engine-hcbd.c
file inspection: improve logging when stream.depth limit is reached. #493 .
13 years ago
detect-engine-hcbd.h
support splitting mpm ctxs based on direction v2
13 years ago
detect-engine-hcd.c
cookie header now inspects Set-Cookie headers as well
13 years ago
detect-engine-hcd.h
support splitting mpm ctxs based on direction v2
13 years ago
detect-engine-hhd.c
http header won't inspect set-cookie headers. Set-cookie part of cookie keyword now. Also update the http header inspection engine
13 years ago
detect-engine-hhd.h
bug 389 - support http response header inspection + fix bug with stateful inspection for sigs that would have both request/response inpection
13 years ago
detect-engine-hmd.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
detect-engine-hmd.h
support splitting mpm ctxs based on direction v2
13 years ago
detect-engine-hrhd.c
http_raw_header: add some debug code.
13 years ago
detect-engine-hrhd.h
support http response raw header inspection + carry out hrhd mpm on both request/response headers + add unittests for the same
13 years ago
detect-engine-hrud.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
detect-engine-hrud.h
support splitting mpm ctxs based on direction v2
13 years ago
detect-engine-hsbd.c
file inspection: improve logging when stream.depth limit is reached. #493 .
13 years ago
detect-engine-hsbd.h
support splitting mpm ctxs based on direction v2
13 years ago
detect-engine-hscd.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
detect-engine-hscd.h
rebase commit for hscd and hsmd patches
13 years ago
detect-engine-hsmd.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
detect-engine-hsmd.h
rebase commit for hscd and hsmd patches
13 years ago
detect-engine-hua.c
http user agent keyword + mpm + inspection + fast pattern support added
13 years ago
detect-engine-hua.h
http user agent keyword + mpm + inspection + fast pattern support added
13 years ago
detect-engine-iponly.c
Properly clean signature's ip only data.
13 years ago
detect-engine-iponly.h
IP Only cleanup: make most functions static. Add error message on address parsing issues.
13 years ago
detect-engine-mpm.c
Update fast_pattern engine to not use negated content as fast_pattern if we have non-negated content in the sig.
13 years ago
detect-engine-mpm.h
http user agent keyword + mpm + inspection + fast pattern support added
13 years ago
detect-engine-payload.c
tests to highlight that
13 years ago
detect-engine-payload.h
…
detect-engine-port.c
detection engine port api unittests cleanup
13 years ago
detect-engine-port.h
bug #454 - global check to see if address and port vars are properly configured
13 years ago
detect-engine-proto.c
Fix parsing of tcp-pkt and tcp-stream sigs, add unittest.
13 years ago
detect-engine-proto.h
feature #414 - support listing supported keywords. Remove support for dummy keywords __address__, __proto__, __port__. Remove support for recursive keyword and all references to it
13 years ago
detect-engine-siggroup.c
file: implement filesize keyword. #489 .
13 years ago
detect-engine-siggroup.h
file: implement filesize keyword. #489 .
13 years ago
detect-engine-sigorder.c
more coverity fixes
13 years ago
detect-engine-sigorder.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-engine-state.c
file: implement filesize keyword. #489 .
13 years ago
detect-engine-state.h
Simplify flow resetting on de_ctx update. Detect ctx id starts at 1. So in a flow 0 means uninitialized (thus set) and if we detect flow is not equal to detect id, we reset the sgh storage and de_state.
13 years ago
detect-engine-tag.c
cleaning: fix warning when building with clang.
13 years ago
detect-engine-tag.h
Introduce host table, make tag use it
13 years ago
detect-engine-threshold.c
fix rate filters that reset the sig ctx data and handled action timeouts wrongly
13 years ago
detect-engine-threshold.h
Move over src and dst thresholding to use host table. Fix a bug in threshold 'both' handling.
13 years ago
detect-engine-uri.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
detect-engine-uri.h
…
detect-engine.c
rule reloads: don't lock up main thread so clean shutdown is impossible
13 years ago
detect-engine.h
update clean up of old detection engine contexts for live rule swap
13 years ago
detect-fast-pattern.c
fast pattern cleanup - Remove FastPatternSupportEnabledForSigMatchList() and all it's associated structures
13 years ago
detect-fast-pattern.h
fast pattern cleanup - Remove FastPatternSupportEnabledForSigMatchList() and all it's associated structures
13 years ago
detect-file-data.c
disallow file_data with flow:to_server/from_client
13 years ago
detect-file-data.h
file-data: create initial keyword registration.
13 years ago
detect-fileext.c
Create separate detect API call (FileMatch) for file detection keywords. #531 .
13 years ago
detect-fileext.h
Add negation to filename and fileext, use same syntax as with content.
13 years ago
detect-filemagic.c
Create separate detect API call (FileMatch) for file detection keywords. #531 .
13 years ago
detect-filemagic.h
File carving -- enable reponse file extraction
13 years ago
detect-filemd5.c
Create separate detect API call (FileMatch) for file detection keywords. #531 .
13 years ago
detect-filemd5.h
filemd5: implement negated matching.
13 years ago
detect-filename.c
Create separate detect API call (FileMatch) for file detection keywords. #531 .
13 years ago
detect-filename.h
Add negation to filename and fileext, use same syntax as with content.
13 years ago
detect-filesize.c
file: convert filesize to new FileMatch api.
13 years ago
detect-filesize.h
file: implement filesize keyword. #489 .
13 years ago
detect-filestore.c
Create separate detect API call (FileMatch) for file detection keywords. #531 .
13 years ago
detect-filestore.h
file store: respect flowbits and other keywords
13 years ago
detect-flags.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-flags.h
…
detect-flow.c
allow only one flow option in a rule
13 years ago
detect-flow.h
…
detect-flowbits.c
variable names global vars, global no more. Moved to detection engine ctx, a place it belongs
13 years ago
detect-flowbits.h
…
detect-flowint.c
variable names global vars, global no more. Moved to detection engine ctx, a place it belongs
13 years ago
detect-flowint.h
…
detect-flowvar.c
variable names global vars, global no more. Moved to detection engine ctx, a place it belongs
13 years ago
detect-flowvar.h
…
detect-fragbits.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-fragbits.h
…
detect-fragoffset.c
Various fixes and improvements based on feedback by Coverity analyzer.
13 years ago
detect-fragoffset.h
…
detect-ftpbounce.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
detect-ftpbounce.h
…
detect-gid.c
…
detect-gid.h
…
detect-http-client-body.c
http: body inspection improvement
13 years ago
detect-http-client-body.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-http-cookie.c
spelling corrections documented in redmine bug#533
13 years ago
detect-http-cookie.h
…
detect-http-header.c
All http_http_header modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_HEADER
13 years ago
detect-http-header.h
…
detect-http-method.c
spelling corrections documented in redmine bug#533
13 years ago
detect-http-method.h
…
detect-http-raw-header.c
All http_http_raw_header modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_RAW_HEADER
13 years ago
detect-http-raw-header.h
…
detect-http-raw-uri.c
All http_http_raw_uri modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_RAW_URI
13 years ago
detect-http-raw-uri.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-http-server-body.c
http body inspection: force body inspection on stream eof.
13 years ago
detect-http-server-body.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-http-stat-code.c
All http_http_stat_code modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_STAT_CODE. Also remove dummy match/free functions for stat code and stat msg
13 years ago
detect-http-stat-code.h
All http_http_stat_code modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_STAT_CODE. Also remove dummy match/free functions for stat code and stat msg
13 years ago
detect-http-stat-msg.c
All http_http_stat_code modified patterns now are DETECT_CONTENT and not DETECT_AL_HTTP_STAT_CODE. Also remove dummy match/free functions for stat code and stat msg
13 years ago
detect-http-stat-msg.h
…
detect-http-ua.c
http user agent keyword + mpm + inspection + fast pattern support added
13 years ago
detect-http-ua.h
http user agent keyword + mpm + inspection + fast pattern support added
13 years ago
detect-http-uri.c
All uricontent modified patterns now are DETECT_CONTENT and not DETECT_URICONTENT. Step towards unifying all content based patterns. Makes way for easier management of patterns
13 years ago
detect-http-uri.h
…
detect-icmp-id.c
Various fixes and improvements based on feedback by Coverity analyzer.
13 years ago
detect-icmp-id.h
…
detect-icmp-seq.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-icmp-seq.h
…
detect-icode.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-icode.h
…
detect-id.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-id.h
…
detect-ipopts.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-ipopts.h
…
detect-ipproto.c
Minor error message cleanups
13 years ago
detect-ipproto.h
…
detect-isdataat.c
http user agent keyword + mpm + inspection + fast pattern support added
13 years ago
detect-isdataat.h
…
detect-itype.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-itype.h
…
detect-mark.c
code cleanup - replace SigMatchAppendTag with SigMatchAppendSMToList
13 years ago
detect-mark.h
…
detect-metadata.c
…
detect-metadata.h
…
detect-msg.c
…
detect-msg.h
…
detect-noalert.c
…
detect-noalert.h
…
detect-nocase.c
spelling corrections documented in redmine bug#533
13 years ago
detect-nocase.h
…
detect-offset.c
spelling corrections documented in redmine bug#533
13 years ago
detect-offset.h
…
detect-parse.c
spelling corrections documented in redmine bug#533
13 years ago
detect-parse.h
code cleanup. Remove unused functions
13 years ago
detect-pcre.c
variable names global vars, global no more. Moved to detection engine ctx, a place it belongs
13 years ago
detect-pcre.h
http user agent keyword + mpm + inspection + fast pattern support added
13 years ago
detect-pktvar.c
Improve pktvar keyword parsing and error handling.
13 years ago
detect-pktvar.h
…
detect-priority.c
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-priority.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-rawbytes.c
spelling corrections documented in redmine bug#533
13 years ago
detect-rawbytes.h
…
detect-reference.c
clean reference config API
13 years ago
detect-reference.h
…
detect-replace.c
spelling corrections documented in redmine bug#533
13 years ago
detect-replace.h
…
detect-rev.c
Use strtoul instead of strtol for sid parsing. Fixes parsing of really large sid numbers. Fixes #393 .
13 years ago
detect-rev.h
…
detect-rpc.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-rpc.h
…
detect-sameip.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-sameip.h
…
detect-seq.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-seq.h
…
detect-sid.c
Use strtoul instead of strtol for sid parsing. Fixes parsing of really large sid numbers. Fixes #393 .
13 years ago
detect-sid.h
…
detect-ssh-proto-version.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
detect-ssh-proto-version.h
…
detect-ssh-software-version.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
detect-ssh-software-version.h
…
detect-ssl-state.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
detect-ssl-state.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-ssl-version.c
tls: debug compilation fixes, new tls decoder rule for tls.error_message_encountered event.
13 years ago
detect-ssl-version.h
Various fixes and improvements based on feedback by Coverity analyzer.
13 years ago
detect-stream_size.c
Various fixes and improvements based on feedback by Coverity analyzer.
13 years ago
detect-stream_size.h
…
detect-tag.c
Fix detect tag error handling.
13 years ago
detect-tag.h
Introduce host table, make tag use it
13 years ago
detect-threshold.c
Move over src and dst thresholding to use host table. Fix a bug in threshold 'both' handling.
13 years ago
detect-threshold.h
considering the tenths of a seconds in a packet, when calculating thresholds
13 years ago
detect-tls-version.c
tls: debug compilation fixes, new tls decoder rule for tls.error_message_encountered event.
13 years ago
detect-tls-version.h
…
detect-tls.c
tls: suppress always true condition.
13 years ago
detect-tls.h
tls: adding support for fingerprint rule matching.
13 years ago
detect-tos.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-tos.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
detect-ttl.c
reject rules with an invalid ttl range
13 years ago
detect-ttl.h
…
detect-uricontent.c
http: body inspection improvement
13 years ago
detect-uricontent.h
code cleanup - remove DetectUricontentGetLastPattern
13 years ago
detect-urilen.c
Improve error message for malformed urilen value.
13 years ago
detect-urilen.h
bug #341 - support for urilen check on both norm and raw buffers
13 years ago
detect-window.c
code cleanup - replace SigMatchAppendPacket with SigMatchAppendSMToList
13 years ago
detect-window.h
…
detect-within.c
spelling corrections documented in redmine bug#533
13 years ago
detect-within.h
…
detect.c
Make sure we never underflow len in DetectLoadSigFile
13 years ago
detect.h
file: implement filesize keyword. #489 .
13 years ago
flow-alert-sid.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
flow-alert-sid.h
…
flow-bit.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
flow-bit.h
…
flow-hash.c
cleaning: fix warning when building with clang.
13 years ago
flow-hash.h
flow engine: improve scalability
13 years ago
flow-manager.c
cleaning: fix warning when building with clang.
13 years ago
flow-manager.h
flow engine: improve scalability
13 years ago
flow-private.h
Undo changes from 88b8f15663
. Atomic stack implementation had a-b-a problem.
13 years ago
flow-queue.c
Undo changes from 88b8f15663
. Atomic stack implementation had a-b-a problem.
13 years ago
flow-queue.h
Undo changes from 88b8f15663
. Atomic stack implementation had a-b-a problem.
13 years ago
flow-timeout.c
Delay Detect threads initialization
13 years ago
flow-timeout.h
flow engine: improve scalability
13 years ago
flow-util.c
cleaning: fix warning when building with clang.
13 years ago
flow-util.h
cleaning: fix warning when building with clang.
13 years ago
flow-var.c
flow: create a flow lock macro API, implement it for mutex and rwlocks. Mutex remains the default.
13 years ago
flow-var.h
…
flow.c
flow: remove unused prune-flows option
13 years ago
flow.h
file: implement filesize keyword. #489 .
13 years ago
host-queue.c
Introduce host table, make tag use it
13 years ago
host-queue.h
Introduce host table, make tag use it
13 years ago
host-timeout.c
host: convert use_cnt to a atomic var (like in flow).
13 years ago
host-timeout.h
Introduce host table, make tag use it
13 years ago
host.c
cleaning: fix warning when building with clang.
13 years ago
host.h
host: convert use_cnt to a atomic var (like in flow).
13 years ago
log-droplog.c
OpenBSD: introduce SCLocalTime function.
13 years ago
log-droplog.h
…
log-file.c
file inspection: improve logging when stream.depth limit is reached. #493 .
13 years ago
log-file.h
file extraction: add waldo option to file log module. This will store the last used file_id so extracted files won't get overwritten is Suricata is restarted.
13 years ago
log-filestore.c
file: implement filesize keyword. #489 .
13 years ago
log-filestore.h
file-inspection: split 'file' output module into file-store and file-log. Store stores files. Log logs json records.
13 years ago
log-httplog.c
Custom logging feature for log-httplog
13 years ago
log-httplog.h
…
log-pcap.c
Don't display a warning when log-pcap tries to remove an already removed file.
13 years ago
log-pcap.h
…
log-tlslog.c
tls-log: add protocol version to log message.
13 years ago
log-tlslog.h
tls: adding TLS Log support
13 years ago
output.c
…
output.h
SCConfLogOpenGeneric() abstraction for regular and AF_UNIX logs.
13 years ago
packet-queue.c
…
packet-queue.h
…
pkt-var.c
…
pkt-var.h
…
ptxdump.py
…
queue.h
…
reputation.c
…
reputation.h
…
respond-reject-libnet11.c
…
respond-reject-libnet11.h
…
respond-reject.c
…
respond-reject.h
…
runmode-af-packet.c
af-packet: improve mmaped running mode.
13 years ago
runmode-af-packet.h
…
runmode-erf-dag.c
Implement single, autofp and workers run modes for DAG interfaces. Includes multiple interface support.
13 years ago
runmode-erf-dag.h
Implement single, autofp and workers run modes for DAG interfaces. Includes multiple interface support.
13 years ago
runmode-erf-file.c
Fix minor compiler warning.
13 years ago
runmode-erf-file.h
Update the ERF file runmodes to support autofp and single.
13 years ago
runmode-ipfw.c
Rename 'worker' running mode to 'workers'
13 years ago
runmode-ipfw.h
ipfw: Add support for autofp and worker runmode
13 years ago
runmode-napatech.c
Napatech code formatting fixes.
13 years ago
runmode-napatech.h
Fix compilation without napatech tech support enabled.
13 years ago
runmode-nfq.c
Rename 'worker' running mode to 'workers'
13 years ago
runmode-nfq.h
nfq: add worker runmode support.
13 years ago
runmode-pcap-file.c
cuda pb tm should be in a thread of its own + pkt_acq should be as free as possible
13 years ago
runmode-pcap-file.h
…
runmode-pcap.c
Minor fixes for coverity issues.
13 years ago
runmode-pcap.h
…
runmode-pfring.c
cleaning: fix warning when building with clang.
13 years ago
runmode-pfring.h
…
runmodes.c
Rename 'worker' running mode to 'workers'
13 years ago
runmodes.h
free flowvar entries in flow after live rule swap. Sync flowbits entries into packet struct to be used by alert debuglog when alert debuglog is enabled
13 years ago
source-af-packet.c
af-packet: improve mmaped running mode.
13 years ago
source-af-packet.h
af-packet: improve mmaped running mode.
13 years ago
source-erf-dag.c
rx TMs shouldn't return TM_ECODE_FAILED if engine is in shutdown mode + minor cleanup
13 years ago
source-erf-dag.h
…
source-erf-file.c
rx TMs shouldn't return TM_ECODE_FAILED if engine is in shutdown mode + minor cleanup
13 years ago
source-erf-file.h
…
source-ipfw.c
rx TMs shouldn't return TM_ECODE_FAILED if engine is in shutdown mode + minor cleanup
13 years ago
source-ipfw.h
ipfw: don't use socket lock in 'worker' mode
13 years ago
source-napatech.c
rx TMs shouldn't return TM_ECODE_FAILED if engine is in shutdown mode + minor cleanup
13 years ago
source-napatech.h
Initial Napatech support by Randy Caldejon / nPulse.
13 years ago
source-nfq-prototypes.h
…
source-nfq.c
nfq: implement "fail-open" support.
13 years ago
source-nfq.h
nfq: do not use mutex in 'worker' mode
13 years ago
source-pcap-file.c
rx TMs shouldn't return TM_ECODE_FAILED if engine is in shutdown mode + minor cleanup
13 years ago
source-pcap-file.h
…
source-pcap.c
pcap: fix compilation on old libpcap
13 years ago
source-pcap.h
Add pcap workers mode.
13 years ago
source-pfring.c
rx TMs shouldn't return TM_ECODE_FAILED if engine is in shutdown mode + minor cleanup
13 years ago
source-pfring.h
pf-ring: add support for checksum verif mode
13 years ago
stream-tcp-inline.c
…
stream-tcp-inline.h
…
stream-tcp-private.h
stream: handle case where Suricata sees 3whs-ACK but server doesn't. Bug #523 .
13 years ago
stream-tcp-reassemble.c
stream/app layer: add Truncate app layer callback that is called if stream depth is reached. Use it to trunc open files in HTTP.
13 years ago
stream-tcp-reassemble.h
file inspection: improve logging when stream.depth limit is reached. #493 .
13 years ago
stream-tcp-sack.c
Another batch of minor fixed for issues found by Coverity.
13 years ago
stream-tcp-sack.h
…
stream-tcp-util.c
…
stream-tcp-util.h
…
stream-tcp.c
stream-tcp: no checksum alert if validation is off
13 years ago
stream-tcp.h
Add counters for SYN, SYN/ACK and RST TCP packets. Issue #251 .
13 years ago
stream.c
Make sure stream debug code is only used in debug mode.
13 years ago
stream.h
stream/app layer: add Truncate app layer callback that is called if stream depth is reached. Use it to trunc open files in HTTP.
13 years ago
suricata-common.h
http user agent keyword + mpm + inspection + fast pattern support added
13 years ago
suricata.c
Get rid of AppLayerHtpRegisterExtraCallbacks
13 years ago
suricata.h
Update version number to reflect we're working towards 1.4 now.
13 years ago
threads.c
…
threads.h
Fix SCSetThreadName() macros in threads.h Add FreeBSD thread naming implementation.
13 years ago
threadvars.h
restructure disabling receive threads. Introduce new flag to indicate that threads have finised running
13 years ago
tm-modules.c
Add way to profile mutex/spin locks per thread module.
13 years ago
tm-modules.h
check if all packets are processed before disabling detect threads + kill all threads <= detect after FFR + other minor fixes
13 years ago
tm-queuehandlers.c
Clean up packet pool at shut down.
13 years ago
tm-queuehandlers.h
Clean up packet pool at shut down.
13 years ago
tm-queues.c
…
tm-queues.h
…
tm-threads-common.h
tls: adding TLS Log support
13 years ago
tm-threads.c
tm-thread: suppress rarely used variable.
13 years ago
tm-threads.h
Delay Detect threads initialization
13 years ago
tmqh-flow.c
cleaning: fix warning when building with clang.
13 years ago
tmqh-flow.h
Adapt flow tmqh counters to be atomic vars. Remove support for active flows q handler. Introduce SC_ATOMIC_SET
13 years ago
tmqh-nfq.c
…
tmqh-nfq.h
…
tmqh-packetpool.c
Clean up packet pool at shut down.
13 years ago
tmqh-packetpool.h
Clean up packet pool at shut down.
13 years ago
tmqh-ringbuffer.c
Clean up packet pool at shut down.
13 years ago
tmqh-ringbuffer.h
Clean up packet pool at shut down.
13 years ago
tmqh-simple.c
Minor flowq updates.
13 years ago
tmqh-simple.h
…
util-action.c
util action api returns error code if it encounters wrong values parsing wrong action conf
13 years ago
util-action.h
util action api returns error code if it encounters wrong values parsing wrong action conf
13 years ago
util-affinity.c
Convert underscores to dashes in thread affinity type names.
13 years ago
util-affinity.h
…
util-atomic.c
sc_atomic_cas replaced with sc_atomic_set
13 years ago
util-atomic.h
add unittest for atomic operation with void *
13 years ago
util-binsearch.c
…
util-binsearch.h
…
util-bloomfilter-counting.c
Clean up for unittests code: only compile unittest api code when unittests are enabled. Fix unittest code that wasn't wrapped in the proper UNITTESTS ifdefs.
13 years ago
util-bloomfilter-counting.h
…
util-bloomfilter.c
…
util-bloomfilter.h
…
util-buffer.c
Misc buffer API update.
13 years ago
util-buffer.h
debuglog now uses the new mem buffer API. Improve file ctx locking to just the file write
13 years ago
util-byte.c
…
util-byte.h
…
util-checksum.c
Various fixes and improvements based on feedback by Coverity analyzer.
13 years ago
util-checksum.h
Assume offloading in use if 1/10th of the packets has a bad checksum.
13 years ago
util-cidr.c
…
util-cidr.h
…
util-classification-config.c
Windows build and other misc fixes.
13 years ago
util-classification-config.h
clean classification config API
13 years ago
util-clock.h
…
util-coredump-config.c
Do not use underscored config vars internally.
13 years ago
util-coredump-config.h
Enable/disable core dump in config (feature 319)
13 years ago
util-cpu.c
fix regression (clobbered register; redmine #534 )
13 years ago
util-cpu.h
…
util-crypt.c
tls: add NSS version for SHA1 computing function.
13 years ago
util-crypt.h
tls: add NSS version for SHA1 computing function.
13 years ago
util-cuda-handlers.c
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-cuda-handlers.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-cuda.c
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-cuda.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-daemon.c
OpenBSD: don't close std* to avoid problem.
13 years ago
util-daemon.h
…
util-debug-filters.c
more coverity fixes
13 years ago
util-debug-filters.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-debug.c
spelling corrections documented in redmine bug#533
13 years ago
util-debug.h
fix cppcheck analyzer warnings - bug 439
13 years ago
util-decode-asn1.c
Do not use underscored config vars internally.
13 years ago
util-decode-asn1.h
…
util-decode-der-get.c
TLS: add variable to store the error code in the decoder
13 years ago
util-decode-der-get.h
TLS: add variable to store the error code in the decoder
13 years ago
util-decode-der.c
Use SCFree instead of free in DER decoder.
13 years ago
util-decode-der.h
TLS: add variable to store the error code in the decoder
13 years ago
util-device.c
Various fixes and improvements based on feedback by Coverity analyzer.
13 years ago
util-device.h
Clean up csum detection output, misc fixes.
13 years ago
util-enum.c
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-enum.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-error.c
bug #455 - Warn users on signature event vars having precedence over threshold.conf ones
13 years ago
util-error.h
tls: adding TLS Log support
13 years ago
util-file.c
stream/app layer: add Truncate app layer callback that is called if stream depth is reached. Use it to trunc open files in HTTP.
13 years ago
util-file.h
stream/app layer: add Truncate app layer callback that is called if stream depth is reached. Use it to trunc open files in HTTP.
13 years ago
util-fix_checksum.c
…
util-fix_checksum.h
…
util-fmemopen.c
…
util-fmemopen.h
…
util-hash-lookup3.c
fix compiler warnings
13 years ago
util-hash-lookup3.h
Add a new hash datatype to do speedy lookups of read only uniform data, like md5's.
13 years ago
util-hash.c
Clean up for unittests code: only compile unittest api code when unittests are enabled. Fix unittest code that wasn't wrapped in the proper UNITTESTS ifdefs.
13 years ago
util-hash.h
Various fixes and improvements based on feedback by Coverity analyzer.
13 years ago
util-hashlist.c
…
util-hashlist.h
Various fixes and improvements based on feedback by Coverity analyzer.
13 years ago
util-host-os-info.c
bug 499 - update host os info enum map to use - instead of _ + add new unittests
13 years ago
util-host-os-info.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-ioctl.c
…
util-ioctl.h
…
util-logopenfile.c
Fix OpenBSD compilation.
13 years ago
util-logopenfile.h
SCConfLogOpenGeneric() abstraction for regular and AF_UNIX logs.
13 years ago
util-magic.c
Minor fixes for coverity issues.
13 years ago
util-magic.h
File carving -- enable reponse file extraction
13 years ago
util-mem.h
fix cppcheck analyzer warnings - bug 439
13 years ago
util-memcmp.c
…
util-memcmp.h
…
util-misc.c
Introduce util-signal.[ch]. Move our signal setup functions here
13 years ago
util-misc.h
Introduce util-signal.[ch]. Move our signal setup functions here
13 years ago
util-mpm-ac-bs.c
ac-bs and ac-gfbs mem cleanup
13 years ago
util-mpm-ac-bs.h
Support for new MPM ac-bs added
13 years ago
util-mpm-ac-gfbs.c
ac-bs and ac-gfbs mem cleanup
13 years ago
util-mpm-ac-gfbs.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-mpm-ac.c
mpm engine and ac mem free fixes
13 years ago
util-mpm-ac.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-mpm-b2g-cuda-kernel.cu
Changed my email address to anoopsaldanha@gmail.com from my current one - Should have been an amend over my previous commit, but that commit's pushed out
13 years ago
util-mpm-b2g-cuda.c
Delay Detect threads initialization
13 years ago
util-mpm-b2g-cuda.h
b2g cuda up, compiling and running
13 years ago
util-mpm-b2g.c
…
util-mpm-b2g.h
…
util-mpm-b2gc.c
…
util-mpm-b2gc.h
…
util-mpm-b2gm.c
…
util-mpm-b2gm.h
…
util-mpm-b3g.c
Openbsd: Fix some warning related to inline usage.
13 years ago
util-mpm-b3g.h
…
util-mpm-wumanber.c
Openbsd: Fix some warning related to inline usage.
13 years ago
util-mpm-wumanber.h
…
util-mpm.c
ac-bs and ac-gfbs mem cleanup
13 years ago
util-mpm.h
make mpm ctx container de_ctx specific. Also introduce global variable in mpm_ctx. this is a workaround for cleaning non global mpm_ctx's since we now don't supply the de_ctx around the detection engine API
13 years ago
util-optimize.h
…
util-path.c
Fix PathIsAbsolute function not dealing with CYGWIN. Handle absolute paths in logfile api.
13 years ago
util-path.h
Add functions to determine whether a path is absolute or relative.
13 years ago
util-pidfile.c
…
util-pidfile.h
…
util-pool.c
…
util-pool.h
…
util-print.c
debuglog now uses the new mem buffer API. Improve file ctx locking to just the file write
13 years ago
util-print.h
debuglog now uses the new mem buffer API. Improve file ctx locking to just the file write
13 years ago
util-privs.c
Remove duplicate sys/prctl.h configure check. Wrap another include in HAVE_SYS_PRCTL_H.
13 years ago
util-privs.h
…
util-profiling-locks.c
profiling: fix lock profiling int print issue.
13 years ago
util-profiling-locks.h
profiling: add per lock location profiling
13 years ago
util-profiling.c
cleaning: fix warning when building with clang.
13 years ago
util-profiling.h
Fix error in per packet detection engine profiling.
13 years ago
util-proto-name.c
…
util-proto-name.h
…
util-radix-tree.c
Minor unittest fixes to make Coverity happy.
13 years ago
util-radix-tree.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-random.c
…
util-random.h
…
util-reference-config.c
Minor fixes for coverity issues.
13 years ago
util-reference-config.h
clean reference config API
13 years ago
util-ringbuffer.c
cleaning: fix warning when building with clang.
13 years ago
util-ringbuffer.h
…
util-rohash.c
Add filemd5 keyword that loads a list of md5's to match a file's md5 against.
13 years ago
util-rohash.h
Add filemd5 keyword that loads a list of md5's to match a file's md5 against.
13 years ago
util-rule-vars.c
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-rule-vars.h
Changed my email address to anoopsaldanha at gmail dot com from my current one
13 years ago
util-runmodes.c
spelling corrections documented in redmine bug#533
13 years ago
util-runmodes.h
runmode: Add support for IPS running mode
13 years ago
util-signal.c
update clean up of old detection engine contexts for live rule swap
13 years ago
util-signal.h
code cleanup for live swap
13 years ago
util-spm-bm.c
update all spm algos to use 16 bit pattern lengths. Should compress a lot of tables
13 years ago
util-spm-bm.h
Fix typo in spm prototype declaration.
13 years ago
util-spm-bs.c
update all spm algos to use 16 bit pattern lengths. Should compress a lot of tables
13 years ago
util-spm-bs.h
update all spm algos to use 16 bit pattern lengths. Should compress a lot of tables
13 years ago
util-spm-bs2bm.c
update all spm algos to use 16 bit pattern lengths. Should compress a lot of tables
13 years ago
util-spm-bs2bm.h
update all spm algos to use 16 bit pattern lengths. Should compress a lot of tables
13 years ago
util-spm.c
update all spm algos to use 16 bit pattern lengths. Should compress a lot of tables
13 years ago
util-spm.h
update all spm algos to use 16 bit pattern lengths. Should compress a lot of tables
13 years ago
util-strlcatu.c
…
util-strlcpyu.c
…
util-syslog.c
…
util-syslog.h
…
util-threshold-config.c
Windows build and other misc fixes.
13 years ago
util-threshold-config.h
…
util-time.c
OpenBSD: introduce SCLocalTime function.
13 years ago
util-time.h
OpenBSD: introduce SCLocalTime function.
13 years ago
util-unittest-helper.c
Undo changes from 88b8f15663
. Atomic stack implementation had a-b-a problem.
13 years ago
util-unittest-helper.h
Clean up for unittests code: only compile unittest api code when unittests are enabled. Fix unittest code that wasn't wrapped in the proper UNITTESTS ifdefs.
13 years ago
util-unittest.c
Do not use underscored config vars internally.
13 years ago
util-unittest.h
Clean up for unittests code: only compile unittest api code when unittests are enabled. Fix unittest code that wasn't wrapped in the proper UNITTESTS ifdefs.
13 years ago
util-validate.h
Fix locking error in filestore handling. Add debug validate check for asserting a flow is locked.
13 years ago
util-var-name.c
variable names global vars, global no more. Moved to detection engine ctx, a place it belongs
13 years ago
util-var-name.h
variable names global vars, global no more. Moved to detection engine ctx, a place it belongs
13 years ago
util-var.c
…
util-var.h
…
util-vector.h
…
win32-misc.c
…
win32-misc.h
…
win32-service.c
…
win32-service.h
…
win32-syslog.h
…