--- /dev/null
+# Test Purpose
+
+Test that a first segment of an FTP command that is over the limited, but not
+new line terminated gets truncated.
+
+## PCAP
+
+PCAP generated with flowsynth.
--- /dev/null
+flow default tcp 1.1.1.1:5555 > 2.2.2.2:21 (tcp.initialize; mss: 9000;);
+default < (content:"220 (Ftp Server)\x0d\x0a";);
+default > (content:"USER user\x0d\x0a";);
+default < (content:"331 Please specify the password.\x0d\x0a";);
+default > (content:"PASS password\x0d\x0a";);
+default < (content:"230 Login successful.\x0d\x0a";);
+default > (content:"SYST\x0d\x0a";);
+default < (content:"215 UNIX Type: L8\x0d\x0a";);
+default > (content:"TYPE I\x0d\x0a";);
+default < (content:"200 Switching to Binary mode.\x0d\x0a";);
+default > (content:"PASV\x0d\x0a";);
+default < (content:"227 Entering Passive Mode (2,2,2,2,185,13).\x0d\x0a";);
+default > (content
+default > (content:"Z\x0d\x0a";);
+default < (content:"550 Failed to open file.\x0d\x0a";);
+default > (content:"RETR index.html\x0d\x0a";);
+default < (content:"550 Failed to open file.\x0d\x0a";);
--- /dev/null
+checks:
+ # Look for the truncated command.
+ - filter:
+ count: 1
+ match:
+ event_type: ftp
+ ftp.command: RETR
+ ftp.command_data.__len: 4091
+ ftp.command_truncated: true
+ ftp.reply_truncated: false
+
+ # Now look for the command after the truncated command.
+ - filter:
+ count: 1
+ match:
+ event_type: ftp
+ ftp.command: RETR
+ ftp.command_data: index.html
+ ftp.command_truncated: false
+ ftp.reply_truncated: false