]> git.ipfire.org Git - thirdparty/suricata-verify.git/commitdiff
smb: update pcap for test about ntlmssp
authorPhilippe Antoine <pantoine@oisf.net>
Thu, 4 May 2023 07:11:46 +0000 (09:11 +0200)
committerJason Ish <jason.ish@oisf.net>
Fri, 12 May 2023 17:23:46 +0000 (11:23 -0600)
Turning off a ntlmssp bitflag, so that we are sure we pick the
right bit which is set for version parsing.

tests/smb2-ntlmssp-order/smb2.pcap
tests/smb2-ntlmssp-order/test.yaml

index a384afcee34d6fa4be4d3688fd1a4b259734f531..b44f237fa9d8569076a41765567ce5c3f0f70498 100644 (file)
Binary files a/tests/smb2-ntlmssp-order/smb2.pcap and b/tests/smb2-ntlmssp-order/smb2.pcap differ
index f708cb367ac3fe152264136fafb3ccf2ad0e6053..6a450a0f007f292729ba2559ba96ebab745b2355 100644 (file)
@@ -2,17 +2,17 @@ requires:
   min-version: 6
 
 args:
-- --set stream.reassembly.depth=0
+- --set stream.reassembly.depth=0 -k none
 
 checks:
   - filter:
       count: 1
       match:
         event_type: smb
-        smb.id: 3
         smb.dialect: "2.02"
         smb.command: SMB2_COMMAND_SESSION_SETUP
         smb.status: STATUS_SUCCESS
         smb.ntlmssp.domain: "CONTOSO"
         smb.ntlmssp.user: "SERVER01"
         smb.ntlmssp.host: "Administrator"
+        smb.ntlmssp.version: "6.0 build 6001 rev 15"