You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/rules
Jason Ish dbaf63df5a dns: parse and alert on invalid opcodes
Accept DNS messages with an invalid opcode that are otherwise
valid. Such DNS message will create a parser event.

This is a change of behavior, previously an invalid opcode would cause
the DNS message to not be detected or parsed as DNS.

Issue: #5444
(cherry picked from commit c98c49d4ba)
3 years ago
..
Makefile.am ssh: install app-layer events rules 4 years ago
app-layer-events.rules
decoder-events.rules decode/events: add strict mode for udp.hlen_invalid; remove rule 3 years ago
dhcp-events.rules dhcp: add dhcp app-layer rules file 8 years ago
dnp3-events.rules
dns-events.rules dns: parse and alert on invalid opcodes 3 years ago
files.rules rules: fix files.rules typo 6 years ago
http-events.rules http: adds debug check against too many warnings 6 years ago
http2-events.rules http2: decompression for files 5 years ago
ipsec-events.rules rules: fix event names for ikev2 (weak authentication and DH parameters) 7 years ago
kerberos-events.rules Kerberos 5: rename weak crypto to weak encryption, and log it 8 years ago
modbus-events.rules
mqtt-events.rules mqtt: limits the number of active transactions per flow 4 years ago
nfs-events.rules
ntp-events.rules
smb-events.rules smb: checks against nbss records length 3 years ago
smtp-events.rules smtp/mime: Set event when name exceeds limit 6 years ago
ssh-events.rules rules: add SSH decoder events rules 6 years ago
stream-events.rules stream: accept and flag ack of ZWP data 3 years ago
tls-events.rules rules/tls: sync with changes to the TLS events 6 years ago