]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
tests: add ssh keyword tests
authorVictor Julien <victor@inliniac.net>
Wed, 20 Jan 2021 15:03:36 +0000 (16:03 +0100)
committerVictor Julien <victor@inliniac.net>
Wed, 20 Jan 2021 19:42:09 +0000 (20:42 +0100)
tests/ssh-banner-only/test.rules [new file with mode: 0644]
tests/ssh-banner-only/test.yaml

diff --git a/tests/ssh-banner-only/test.rules b/tests/ssh-banner-only/test.rules
new file mode 100644 (file)
index 0000000..7638fde
--- /dev/null
@@ -0,0 +1,4 @@
+alert ssh any any -> any any (ssh.software; content:"OpenSSH"; sid:1;)
+# broken?
+#alert ssh any any -> any any (ssh.softwareversion:OpenSSH_7.4; sid:2;)
+alert ssh any any -> any any (ssh.proto; content:"2"; sid:3;)
index e40480a99f674b5117c23a34e5dd865efa4d42f7..5c4b9087a270fb525e99d0aeee860bb231baed3f 100644 (file)
@@ -15,4 +15,9 @@ checks:
         ssh.client.proto_version: "2.0"
         ssh.server.proto_version: "2.0"
         ssh.client.software_version: "OpenSSH_for_Windows_7.7"
-        ssh.server.software_version: "OpenSSH_7.4"
\ No newline at end of file
+        ssh.server.software_version: "OpenSSH_7.4"
+  - filter:
+      count: 1
+      match:
+        event_type: alert
+        alert.signature_id: 1