]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
dcerpc: use new sticky buffer keywords
authorShivani Bhardwaj <shivanib134@gmail.com>
Fri, 24 Dec 2021 11:21:55 +0000 (16:51 +0530)
committerVictor Julien <victor@inliniac.net>
Tue, 25 Jan 2022 11:41:25 +0000 (12:41 +0100)
tests/dcerpc/dcerpc-dce-iface-01/test.rules

index 0aaaac56241ccae373aed1feeda98fbbc05de70e..9baa643bdfaa0db5082c586a8c9604c245da8567 100644 (file)
@@ -1 +1 @@
-alert tcp any any -> any [135,139,445,1024:] (msg:"ET POLICY DCERPC  SVCCTL OpenSCManagerW Request"; flow:established,to_server; dce_iface:367abb81-9844-35f1-ad32-98f038001003; dce_opnum:15; classtype:bad-unknown; sid:1; rev:1;)
+alert tcp any any -> any [135,139,445,1024:] (msg:"ET POLICY DCERPC  SVCCTL OpenSCManagerW Request"; flow:established,to_server; dcerpc.iface:367abb81-9844-35f1-ad32-98f038001003; dcerpc.opnum:15; classtype:bad-unknown; sid:1; rev:1;)