]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
tests: fix ftp-data direction 817/head
authorVictor Julien <victor@inliniac.net>
Sun, 1 May 2022 06:34:25 +0000 (08:34 +0200)
committerVictor Julien <victor@inliniac.net>
Mon, 2 May 2022 10:55:49 +0000 (12:55 +0200)
tests/bug-4877/test.yaml
tests/filestore-v2.7-stream-depth/test.yaml

index 54ff4116e815c4c24a8e48e90ffc9aba67958825..4b61accbcea34da92f5ef906536fab8ce793b261 100644 (file)
@@ -11,8 +11,8 @@ checks:
     count: 1
     match:
       app_proto: ftp-data
-      dest_ip: 192.168.100.16
-      dest_port: 42987
+      src_ip: 192.168.100.16
+      src_port: 42987
       event_type: fileinfo
       fileinfo.filename: test.pdf
       fileinfo.gaps: false
@@ -22,14 +22,14 @@ checks:
       fileinfo.stored: true
       fileinfo.tx_id: 0
       proto: TCP
-      src_ip: 192.168.100.230
-      src_port: 20
+      dest_ip: 192.168.100.230
+      dest_port: 20
 - filter:
     count: 1
     match:
       app_proto: ftp-data
-      dest_ip: 192.168.100.230
-      dest_port: 20
+      src_ip: 192.168.100.230
+      src_port: 20
       event_type: fileinfo
       fileinfo.filename: test.pdf
       fileinfo.gaps: false
@@ -39,14 +39,14 @@ checks:
       fileinfo.stored: true
       fileinfo.tx_id: 0
       proto: TCP
-      src_ip: 192.168.100.16
-      src_port: 52407
+      dest_ip: 192.168.100.16
+      dest_port: 52407
 - filter:
     count: 1
     match:
       app_proto: ftp-data
-      dest_ip: 192.168.100.230
-      dest_port: 20
+      src_ip: 192.168.100.230
+      src_port: 20
       event_type: fileinfo
       fileinfo.filename: notepad.exe
       fileinfo.gaps: false
@@ -56,14 +56,14 @@ checks:
       fileinfo.stored: true
       fileinfo.tx_id: 0
       proto: TCP
-      src_ip: 192.168.100.16
-      src_port: 48902
+      dest_ip: 192.168.100.16
+      dest_port: 48902
 - filter:
     count: 1
     match:
       app_proto: ftp-data
-      dest_ip: 192.168.100.16
-      dest_port: 57829
+      src_ip: 192.168.100.16
+      src_port: 57829
       event_type: fileinfo
       fileinfo.filename: notepad.exe
       fileinfo.gaps: false
@@ -73,5 +73,5 @@ checks:
       fileinfo.stored: true
       fileinfo.tx_id: 0
       proto: TCP
-      src_ip: 192.168.100.230
-      src_port: 20
+      dest_ip: 192.168.100.230
+      dest_port: 20
index 2a6a5ee968bc7eaff3052d667ef671c656f9ec73..c3e6a182cd45f91a88775808a5c4d49e40d85962 100644 (file)
@@ -4,27 +4,19 @@ requires:
     - HAVE_NSS
 
 args:
-  - -k none --runmode=single
+- -k none
+- --runmode=single
 
 pcap: input.pcap
 
 checks:
-
-  - filter:
-      requires:
-        min-version: 6
-      count: 1
-      match:
-        event_type: fileinfo
-        fileinfo.state: "CLOSED"
-        fileinfo.stored: true
-        fileinfo.size: 99400
   - filter:
-      requires:
-        lt-version: 6
       count: 1
       match:
         event_type: fileinfo
+        # TRUNCATED: fize is ~150k, we limit to 100k with stream depth
         fileinfo.state: "TRUNCATED"
         fileinfo.stored: true
         fileinfo.size: 99400
+        src_ip: 35.209.241.59
+        src_port: 20