]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
bug-990: dns v2 and v3 tests
authorJason Ish <jason.ish@oisf.net>
Thu, 4 Jul 2024 23:56:09 +0000 (17:56 -0600)
committerVictor Julien <victor@inliniac.net>
Tue, 9 Jul 2024 10:15:24 +0000 (12:15 +0200)
As this is a DNS test move into dns/.

tests/dns/bug-990/input.pcap [moved from tests/bug-990/input.pcap with 100% similarity]
tests/dns/bug-990/test.rules [moved from tests/bug-990/test.rules with 100% similarity]
tests/dns/bug-990/test.yaml [new file with mode: 0644]
tests/dns/v2/bug-990/test.rules [new file with mode: 0644]
tests/dns/v2/bug-990/test.yaml [moved from tests/bug-990/test.yaml with 92% similarity]

diff --git a/tests/dns/bug-990/test.yaml b/tests/dns/bug-990/test.yaml
new file mode 100644 (file)
index 0000000..4b61a42
--- /dev/null
@@ -0,0 +1,44 @@
+requires:
+  min-version: 8
+
+args:
+- -k none
+
+checks:
+- filter:
+    count: 0
+    match:
+      event_type: alert
+- filter:
+    count: 1
+    match:
+      dest_ip: 192.38.129.234
+      dest_port: 53
+      dns.id: 28390
+      dns.queries[0].rrname: code.msdn.microsoft.com
+      dns.queries[0].rrtype: A
+      dns.tx_id: 0
+      dns.type: request
+      event_type: dns
+      pcap_cnt: 1
+      proto: UDP
+      src_ip: 192.168.69.156
+      src_port: 49379
+- filter:
+    count: 1
+    match:
+      app_proto: dns
+      dest_ip: 192.38.129.234
+      dest_port: 53
+      event_type: flow
+      flow.age: 0
+      flow.alerted: false
+      flow.bytes_toclient: 0
+      flow.bytes_toserver: 83
+      flow.pkts_toclient: 0
+      flow.pkts_toserver: 1
+      flow.reason: shutdown
+      flow.state: new
+      proto: UDP
+      src_ip: 192.168.69.156
+      src_port: 49379
diff --git a/tests/dns/v2/bug-990/test.rules b/tests/dns/v2/bug-990/test.rules
new file mode 100644 (file)
index 0000000..81f44a6
--- /dev/null
@@ -0,0 +1,2 @@
+#alert ip $EXTERNAL_NET any -> $HOME_NET any (msg:"BAD-TRAFFIC 0 ttl"; ttl:0; reference:url,support.microsoft.com/default.aspx?scid=kb\;EN-US\;q138268; reference:url,www.isi.edu/in-notes/rfc1122.txt; classtype:misc-activity; sid:1321; rev:8;)
+alert ip any any -> any any (msg:"BAD-TRAFFIC 0 ttl"; ttl:0; reference:url,support.microsoft.com/default.aspx?scid=kb\;EN-US\;q138268; reference:url,www.isi.edu/in-notes/rfc1122.txt; classtype:misc-activity; sid:1321; rev:8;)
similarity index 92%
rename from tests/bug-990/test.yaml
rename to tests/dns/v2/bug-990/test.yaml
index 4499ae8025f0990f794cdf9aaea3b44456f6e348..f33660258ae1fca5729f69f1e8b3d2dda297b721 100644 (file)
@@ -1,6 +1,11 @@
 args:
 - -k none
 
+env:
+  SURICATA_EVE_DNS_VERSION: 2
+
+pcap: ../../bug-990/input.pcap
+
 checks:
 - filter:
     count: 0