]> git.ipfire.org Git - thirdparty/snort3.git/commitdiff
Merge pull request #383 in SNORT/snort3 from crc/so to master
authorRuss Combs (rucombs) <rucombs@cisco.com>
Thu, 31 Mar 2016 13:54:29 +0000 (09:54 -0400)
committerRuss Combs (rucombs) <rucombs@cisco.com>
Thu, 31 Mar 2016 13:54:29 +0000 (09:54 -0400)
Squashed commit of the following:

commit 55839b32b0200f6154f485907adc52e7c863d2b3
Author: Russ Combs <rucombs@cisco.com>
Date:   Thu Mar 31 08:45:20 2016 -0400

    update example text rule

commit f56734f16753f2e7dd1f661d1c993a2406962f73
Author: Russ Combs <rucombs@cisco.com>
Date:   Thu Mar 31 08:40:58 2016 -0400

    force null terminator on text rule for sanity

commit 986b2d7628d46bd04bc49e4ce63236b9cbe57fd5
Author: Russ Combs <rucombs@cisco.com>
Date:   Thu Mar 31 08:06:36 2016 -0400

    use v2 flate calls to eliminate header and trailer issues

commit 04c71cf947965f7daadc3c43c206ba095fe66ac8
Author: Russ Combs <rucombs@cisco.com>
Date:   Wed Mar 30 14:50:04 2016 -0400

    fix so rule i/o

extra/src/so_rules/sid_18758.h
src/managers/so_manager.cc
src/parser/parse_stream.cc

index b203d2344037b77930a9a8e82733b9905907f291..1b3654f8fe350c53a1a7f51fc1327d9e1f7d6348 100644 (file)
@@ -1,48 +1,36 @@
 const uint8_t rule_18758[] =
 {
-    0x61, 0x6C, 0x65, 0x72, 0x74, 0x20, 0x74, 0x63, 0x70, 0x20, 0x24, 0x48,
-    0x4F, 0x4D, 0x45, 0x5F, 0x4E, 0x45, 0x54, 0x20, 0x61, 0x6E, 0x79, 0x20,
-    0x2D, 0x3E, 0x20, 0x24, 0x45, 0x58, 0x54, 0x45, 0x52, 0x4E, 0x41, 0x4C,
-    0x5F, 0x4E, 0x45, 0x54, 0x20, 0x24, 0x48, 0x54, 0x54, 0x50, 0x5F, 0x50,
-    0x4F, 0x52, 0x54, 0x53, 0x0A, 0x28, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x6D,
-    0x73, 0x67, 0x3A, 0x22, 0x46, 0x49, 0x4C, 0x45, 0x2D, 0x49, 0x44, 0x45,
-    0x4E, 0x54, 0x49, 0x46, 0x59, 0x20, 0x4D, 0x69, 0x63, 0x72, 0x6F, 0x73,
-    0x6F, 0x66, 0x74, 0x20, 0x57, 0x69, 0x6E, 0x64, 0x6F, 0x77, 0x73, 0x20,
-    0x56, 0x69, 0x73, 0x75, 0x61, 0x6C, 0x20, 0x42, 0x61, 0x73, 0x69, 0x63,
-    0x20, 0x73, 0x63, 0x72, 0x69, 0x70, 0x74, 0x20, 0x66, 0x69, 0x6C, 0x65,
-    0x20, 0x64, 0x6F, 0x77, 0x6E, 0x6C, 0x6F, 0x61, 0x64, 0x20, 0x72, 0x65,
-    0x71, 0x75, 0x65, 0x73, 0x74, 0x22, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20,
-    0x6D, 0x65, 0x74, 0x61, 0x64, 0x61, 0x74, 0x61, 0x3A, 0x73, 0x65, 0x72,
-    0x76, 0x69, 0x63, 0x65, 0x20, 0x68, 0x74, 0x74, 0x70, 0x3B, 0x0A, 0x20,
-    0x20, 0x20, 0x20, 0x72, 0x65, 0x66, 0x65, 0x72, 0x65, 0x6E, 0x63, 0x65,
-    0x3A, 0x75, 0x72, 0x6C, 0x2C, 0x65, 0x6E, 0x2E, 0x77, 0x69, 0x6B, 0x69,
-    0x70, 0x65, 0x64, 0x69, 0x61, 0x2E, 0x6F, 0x72, 0x67, 0x2F, 0x77, 0x69,
-    0x6B, 0x69, 0x2F, 0x56, 0x62, 0x73, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20,
-    0x63, 0x6C, 0x61, 0x73, 0x73, 0x74, 0x79, 0x70, 0x65, 0x3A, 0x6D, 0x69,
-    0x73, 0x63, 0x2D, 0x61, 0x63, 0x74, 0x69, 0x76, 0x69, 0x74, 0x79, 0x3B,
-    0x0A, 0x20, 0x20, 0x20, 0x20, 0x73, 0x69, 0x64, 0x3A, 0x31, 0x38, 0x37,
-    0x35, 0x38, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x72, 0x65, 0x76, 0x3A,
-    0x38, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x73, 0x6F, 0x69, 0x64, 0x3A,
-    0x33, 0x7C, 0x31, 0x38, 0x37, 0x35, 0x38, 0x3B, 0x0A, 0x23, 0x20, 0x65,
-    0x76, 0x65, 0x72, 0x79, 0x74, 0x68, 0x69, 0x6E, 0x67, 0x20, 0x61, 0x62,
-    0x6F, 0x76, 0x65, 0x20, 0x61, 0x70, 0x70, 0x65, 0x61, 0x72, 0x73, 0x20,
-    0x69, 0x6E, 0x20, 0x73, 0x74, 0x75, 0x62, 0x0A, 0x23, 0x20, 0x74, 0x68,
-    0x65, 0x20, 0x66, 0x6F, 0x6C, 0x6C, 0x6F, 0x77, 0x69, 0x6E, 0x67, 0x20,
-    0x64, 0x65, 0x74, 0x65, 0x63, 0x74, 0x69, 0x6F, 0x6E, 0x20, 0x6F, 0x70,
-    0x74, 0x69, 0x6F, 0x6E, 0x73, 0x20, 0x61, 0x72, 0x65, 0x20, 0x6E, 0x6F,
-    0x74, 0x20, 0x69, 0x6E, 0x20, 0x70, 0x72, 0x6F, 0x74, 0x65, 0x63, 0x74,
-    0x65, 0x64, 0x20, 0x73, 0x74, 0x75, 0x62, 0x0A, 0x20, 0x20, 0x20, 0x20,
-    0x66, 0x6C, 0x6F, 0x77, 0x3A, 0x74, 0x6F, 0x5F, 0x73, 0x65, 0x72, 0x76,
-    0x65, 0x72, 0x2C, 0x65, 0x73, 0x74, 0x61, 0x62, 0x6C, 0x69, 0x73, 0x68,
-    0x65, 0x64, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x68, 0x74, 0x74, 0x70,
-    0x5F, 0x75, 0x72, 0x69, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x63, 0x6F,
-    0x6E, 0x74, 0x65, 0x6E, 0x74, 0x3A, 0x22, 0x2E, 0x76, 0x62, 0x73, 0x22,
-    0x2C, 0x20, 0x6E, 0x6F, 0x63, 0x61, 0x73, 0x65, 0x3B, 0x0A, 0x20, 0x20,
-    0x20, 0x20, 0x70, 0x63, 0x72, 0x65, 0x3A, 0x22, 0x2F, 0x5C, 0x78, 0x32,
-    0x65, 0x76, 0x62, 0x73, 0x28, 0x5B, 0x5C, 0x3F, 0x5C, 0x78, 0x35, 0x63,
-    0x5C, 0x78, 0x32, 0x66, 0x5D, 0x7C, 0x24, 0x29, 0x2F, 0x73, 0x6D, 0x69,
-    0x22, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x73, 0x6F, 0x3A, 0x65, 0x76,
-    0x61, 0x6C, 0x3B, 0x0A, 0x29, 0x0A,
+    0x61, 0x6C, 0x65, 0x72, 0x74, 0x20, 0x74, 0x63, 0x70, 0x20, 0x24, 0x48, 0x4F, 0x4D, 0x45, 0x5F,
+    0x4E, 0x45, 0x54, 0x20, 0x61, 0x6E, 0x79, 0x20, 0x2D, 0x3E, 0x20, 0x24, 0x45, 0x58, 0x54, 0x45,
+    0x52, 0x4E, 0x41, 0x4C, 0x5F, 0x4E, 0x45, 0x54, 0x20, 0x24, 0x48, 0x54, 0x54, 0x50, 0x5F, 0x50,
+    0x4F, 0x52, 0x54, 0x53, 0x0A, 0x28, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x6D, 0x73, 0x67, 0x3A, 0x22,
+    0x46, 0x49, 0x4C, 0x45, 0x2D, 0x49, 0x44, 0x45, 0x4E, 0x54, 0x49, 0x46, 0x59, 0x20, 0x4D, 0x69,
+    0x63, 0x72, 0x6F, 0x73, 0x6F, 0x66, 0x74, 0x20, 0x57, 0x69, 0x6E, 0x64, 0x6F, 0x77, 0x73, 0x20,
+    0x56, 0x69, 0x73, 0x75, 0x61, 0x6C, 0x20, 0x42, 0x61, 0x73, 0x69, 0x63, 0x20, 0x73, 0x63, 0x72,
+    0x69, 0x70, 0x74, 0x20, 0x66, 0x69, 0x6C, 0x65, 0x20, 0x64, 0x6F, 0x77, 0x6E, 0x6C, 0x6F, 0x61,
+    0x64, 0x20, 0x72, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x22, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20,
+    0x6D, 0x65, 0x74, 0x61, 0x64, 0x61, 0x74, 0x61, 0x3A, 0x73, 0x65, 0x72, 0x76, 0x69, 0x63, 0x65,
+    0x20, 0x68, 0x74, 0x74, 0x70, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x72, 0x65, 0x66, 0x65, 0x72,
+    0x65, 0x6E, 0x63, 0x65, 0x3A, 0x75, 0x72, 0x6C, 0x2C, 0x65, 0x6E, 0x2E, 0x77, 0x69, 0x6B, 0x69,
+    0x70, 0x65, 0x64, 0x69, 0x61, 0x2E, 0x6F, 0x72, 0x67, 0x2F, 0x77, 0x69, 0x6B, 0x69, 0x2F, 0x56,
+    0x62, 0x73, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x63, 0x6C, 0x61, 0x73, 0x73, 0x74, 0x79, 0x70,
+    0x65, 0x3A, 0x6D, 0x69, 0x73, 0x63, 0x2D, 0x61, 0x63, 0x74, 0x69, 0x76, 0x69, 0x74, 0x79, 0x3B,
+    0x0A, 0x20, 0x20, 0x20, 0x20, 0x73, 0x69, 0x64, 0x3A, 0x31, 0x38, 0x37, 0x35, 0x38, 0x3B, 0x0A,
+    0x20, 0x20, 0x20, 0x20, 0x72, 0x65, 0x76, 0x3A, 0x38, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x73,
+    0x6F, 0x69, 0x64, 0x3A, 0x33, 0x7C, 0x31, 0x38, 0x37, 0x35, 0x38, 0x3B, 0x0A, 0x23, 0x20, 0x65,
+    0x76, 0x65, 0x72, 0x79, 0x74, 0x68, 0x69, 0x6E, 0x67, 0x20, 0x61, 0x62, 0x6F, 0x76, 0x65, 0x20,
+    0x61, 0x70, 0x70, 0x65, 0x61, 0x72, 0x73, 0x20, 0x69, 0x6E, 0x20, 0x73, 0x74, 0x75, 0x62, 0x0A,
+    0x23, 0x20, 0x74, 0x68, 0x65, 0x20, 0x66, 0x6F, 0x6C, 0x6C, 0x6F, 0x77, 0x69, 0x6E, 0x67, 0x20,
+    0x64, 0x65, 0x74, 0x65, 0x63, 0x74, 0x69, 0x6F, 0x6E, 0x20, 0x6F, 0x70, 0x74, 0x69, 0x6F, 0x6E,
+    0x73, 0x20, 0x61, 0x72, 0x65, 0x20, 0x6E, 0x6F, 0x74, 0x20, 0x69, 0x6E, 0x20, 0x70, 0x72, 0x6F,
+    0x74, 0x65, 0x63, 0x74, 0x65, 0x64, 0x20, 0x73, 0x74, 0x75, 0x62, 0x0A, 0x20, 0x20, 0x20, 0x20,
+    0x66, 0x6C, 0x6F, 0x77, 0x3A, 0x74, 0x6F, 0x5F, 0x73, 0x65, 0x72, 0x76, 0x65, 0x72, 0x2C, 0x65,
+    0x73, 0x74, 0x61, 0x62, 0x6C, 0x69, 0x73, 0x68, 0x65, 0x64, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20,
+    0x68, 0x74, 0x74, 0x70, 0x5F, 0x75, 0x72, 0x69, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x63, 0x6F,
+    0x6E, 0x74, 0x65, 0x6E, 0x74, 0x3A, 0x22, 0x2E, 0x76, 0x62, 0x73, 0x22, 0x2C, 0x20, 0x6E, 0x6F,
+    0x63, 0x61, 0x73, 0x65, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x70, 0x63, 0x72, 0x65, 0x3A, 0x22,
+    0x2F, 0x5C, 0x78, 0x32, 0x65, 0x76, 0x62, 0x73, 0x28, 0x5B, 0x5C, 0x3F, 0x5C, 0x78, 0x35, 0x63,
+    0x5C, 0x78, 0x32, 0x66, 0x5D, 0x7C, 0x24, 0x29, 0x2F, 0x73, 0x6D, 0x69, 0x22, 0x3B, 0x0A, 0x20,
+    0x20, 0x20, 0x20, 0x73, 0x6F, 0x3A, 0x65, 0x76, 0x61, 0x6C, 0x3B, 0x0A, 0x29, 0x0A, 0x00,
 };
 const unsigned rule_18758_len = 0;
-
index f1a62eb552af45962fa901037ae1d8c9ffaa2b96..d4a16f0b0d617de1353e04a6792cac702d51f109 100644 (file)
@@ -77,35 +77,43 @@ void SoManager::dump_plugins()
 //-------------------------------------------------------------------------
 
 // FIXIT-L eliminate this arbitrary limit on rule text size
+const unsigned window_bits = -8;
 const unsigned max_rule = 128000;
 static uint8_t so_buf[max_rule];
 
 static const uint8_t* compress(const string& text, unsigned& len)
 {
+    len = 0;
     const char* s = text.c_str();
     z_stream stream;
 
+    stream.zalloc = Z_NULL;
+    stream.zfree = Z_NULL;
+    stream.opaque = Z_NULL;
+    stream.next_in = Z_NULL;
+
+    // v2 avoids the header and trailer
+    int ret = deflateInit2(
+        &stream, Z_DEFAULT_COMPRESSION, Z_DEFLATED, window_bits, 1, Z_DEFAULT_STRATEGY);
+
+    if ( ret != Z_OK )
+        return nullptr;
+
     stream.next_in = (Bytef*)s;
     stream.avail_in = text.size();
 
     stream.next_out = so_buf;
     stream.avail_out = max_rule;
 
-    stream.zalloc = nullptr;
-    stream.zfree = nullptr;
+    ret = deflate(&stream, Z_FINISH);
+    (void)deflateEnd(&stream);
 
-    stream.total_in = 0;
-    stream.total_out = 0;
-
-    len = 0;
-
-    if ( deflateInit(&stream, Z_DEFAULT_COMPRESSION) != Z_OK )
+    if ( ret != Z_STREAM_END )
         return nullptr;
 
-    if ( deflate(&stream, Z_FINISH) == Z_STREAM_END )
-        len= stream.total_out;
+    len= stream.total_out;
+    assert(stream.avail_out > 0);
 
-    deflateEnd(&stream);
     return so_buf;
 }
 
@@ -115,22 +123,30 @@ static const char* expand(const uint8_t* data, unsigned len)
 {
     z_stream stream;
 
+    stream.zalloc = Z_NULL;
+    stream.zfree = Z_NULL;
+    stream.opaque = Z_NULL;
+    stream.next_in = Z_NULL;
+    stream.avail_in = 0;
+
+    if ( inflateInit2(&stream, window_bits) != Z_OK )
+        return nullptr;
+
     stream.next_in = (Bytef*)data;
     stream.avail_in = (uInt)len;
 
     stream.next_out = (Bytef*)so_buf;
     stream.avail_out = (uInt)(max_rule - 1);
 
-    stream.zalloc = nullptr;
-    stream.zfree = nullptr;
-
-    stream.total_in = 0;
-    stream.total_out = 0;
+    int ret = inflate(&stream, Z_FINISH);
+    (void)inflateEnd(&stream);
 
-    if ( inflateInit(&stream) != Z_OK )
+    // FIXIT-L full decompression still gets Z_BUF_ERROR ...
+    if ( ret != Z_STREAM_END and ret != Z_BUF_ERROR )
         return nullptr;
 
-    if ( inflate(&stream, Z_SYNC_FLUSH) != Z_STREAM_END )
+    // ... so we add this as a sanity check
+    if ( stream.avail_in or !stream.avail_out )
         return nullptr;
 
     assert(stream.total_out < max_rule);
@@ -146,11 +162,6 @@ static void strvrt(const string& text, string& data)
     unsigned len = 0;
     const uint8_t* d = compress(text, len);
 
-    // lose the zlib header
-    assert(len > 2 && d[0] == 0x78 && d[1] == 0x9C);
-    d += 2;
-    len -= 2;
-
     data.assign((char*)d, len);
 
     // generate xor key
@@ -159,6 +170,7 @@ static void strvrt(const string& text, string& data)
     // nonetheless this seems to work as good as the basic
     // C++ 11 default generator and uniform distribution
     uint8_t key = (uint8_t)(rand() >> 16);
+
     if ( !key )
         key = 0xA5;
 
@@ -179,9 +191,6 @@ static const char* revert(const uint8_t* data, unsigned len)
     for ( unsigned i = 0; i < len-1; i++ )
         s[i] ^= key;
 
-    // force the zlib header
-    s.insert(0, "\x78\x9C");
-
     return expand((uint8_t*)s.c_str(), s.size());
 }
 
@@ -203,9 +212,6 @@ const char* SoManager::get_so_options(const char* soid)
     if ( !api )
         return nullptr;
 
-    if ( !api->length )
-        return nullptr;
-
     const char* rule = revert(api->rule, api->length);
 
     if ( !rule )
@@ -295,6 +301,8 @@ static void get_var(const string& s, string& v)
     v = s.substr(pos, end-pos);
 }
 
+const unsigned hex_per_row = 16;
+
 void SoManager::rule_to_hex(const char*)
 {
     stringstream buffer;
@@ -310,18 +318,18 @@ void SoManager::rule_to_hex(const char*)
 
     cout << "const uint8_t rule_" << var;
     cout << "[] =" << endl;
-    cout << "{" << endl;
+    cout << "{" << endl << "   ";
     cout << hex << uppercase;
 
     for ( idx = 0; idx < data.size(); idx++ )
     {
-        if ( idx && !(idx % 12) )
-            cout << endl;
+        if ( idx && !(idx % hex_per_row) )
+            cout << endl << "   ";
 
         uint8_t u = data[idx];
-        cout << "0x" << setfill('0') << setw(2) << hex << (int)u << ", ";
+        cout << " 0x" << setfill('0') << setw(2) << hex << (int)u << ",";
     }
-    if ( idx % 16 )
+    if ( idx % hex_per_row )
         cout << endl;
 
     cout << dec;
@@ -344,16 +352,18 @@ void SoManager::rule_to_text(const char*)
 
     cout << "const uint8_t rule_" << var;
     cout << "[] =" << endl;
-    cout << "{" << endl;
+    cout << "{" << endl << "   ";
     cout << hex << uppercase;
 
-    for ( idx = 0; idx < len; idx++ )
+    for ( idx = 0; idx <= len; idx++ )
     {
-        if ( idx && !(idx % 12) )
-            cout << endl;
-        cout << "0x" << setfill('0') << setw(2) << (unsigned)data[idx] << ", ";
+        if ( idx && !(idx % hex_per_row) )
+            cout << endl << "   ";
+
+        unsigned byte = (idx == len) ? 0 : data[idx];
+        cout << " 0x" << setfill('0') << setw(2) << byte << ",";
     }
-    if ( idx % 16 )
+    if ( idx % hex_per_row )
         cout << endl;
 
     cout << dec;
index 0bc0d736e97070f243e90123f952f80ceaa89c5a..63a735b3e1e8e3c00c8e47dee4b660eff19d2ed1 100644 (file)
@@ -33,6 +33,7 @@ using namespace std;
 #include "parse_rule.h"
 #include "detection/treenodes.h"
 #include "log/messages.h"
+#include "managers/ips_manager.h"
 
 static unsigned chars = 0, tokens = 0;
 static unsigned lines = 1, comments = 0;
@@ -541,9 +542,12 @@ static bool exec(
     {
         if ( rps.tbd )
             exec(FSM_END, tok, rps, sc);
-        const char* extra = parse_rule_close(sc, rps.rtn, rps.otn);
-        if ( extra )
+
+        if ( const char* extra = parse_rule_close(sc, rps.rtn, rps.otn) )
+        {
+            IpsManager::reset_options();
             parse_body(extra, rps, sc);
+        }
         else
         {
             rps.otn = nullptr;