From: Russ Combs (rucombs) Date: Thu, 31 Mar 2016 13:54:29 +0000 (-0400) Subject: Merge pull request #383 in SNORT/snort3 from crc/so to master X-Git-Tag: 3.0.0-233~492 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=3934c9cf7bf67f7fd36f8b7231e0ddc2abdb9aa2;p=thirdparty%2Fsnort3.git Merge pull request #383 in SNORT/snort3 from crc/so to master Squashed commit of the following: commit 55839b32b0200f6154f485907adc52e7c863d2b3 Author: Russ Combs Date: Thu Mar 31 08:45:20 2016 -0400 update example text rule commit f56734f16753f2e7dd1f661d1c993a2406962f73 Author: Russ Combs Date: Thu Mar 31 08:40:58 2016 -0400 force null terminator on text rule for sanity commit 986b2d7628d46bd04bc49e4ce63236b9cbe57fd5 Author: Russ Combs Date: Thu Mar 31 08:06:36 2016 -0400 use v2 flate calls to eliminate header and trailer issues commit 04c71cf947965f7daadc3c43c206ba095fe66ac8 Author: Russ Combs Date: Wed Mar 30 14:50:04 2016 -0400 fix so rule i/o --- diff --git a/extra/src/so_rules/sid_18758.h b/extra/src/so_rules/sid_18758.h index b203d2344..1b3654f8f 100644 --- a/extra/src/so_rules/sid_18758.h +++ b/extra/src/so_rules/sid_18758.h @@ -1,48 +1,36 @@ const uint8_t rule_18758[] = { - 0x61, 0x6C, 0x65, 0x72, 0x74, 0x20, 0x74, 0x63, 0x70, 0x20, 0x24, 0x48, - 0x4F, 0x4D, 0x45, 0x5F, 0x4E, 0x45, 0x54, 0x20, 0x61, 0x6E, 0x79, 0x20, - 0x2D, 0x3E, 0x20, 0x24, 0x45, 0x58, 0x54, 0x45, 0x52, 0x4E, 0x41, 0x4C, - 0x5F, 0x4E, 0x45, 0x54, 0x20, 0x24, 0x48, 0x54, 0x54, 0x50, 0x5F, 0x50, - 0x4F, 0x52, 0x54, 0x53, 0x0A, 0x28, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x6D, - 0x73, 0x67, 0x3A, 0x22, 0x46, 0x49, 0x4C, 0x45, 0x2D, 0x49, 0x44, 0x45, - 0x4E, 0x54, 0x49, 0x46, 0x59, 0x20, 0x4D, 0x69, 0x63, 0x72, 0x6F, 0x73, - 0x6F, 0x66, 0x74, 0x20, 0x57, 0x69, 0x6E, 0x64, 0x6F, 0x77, 0x73, 0x20, - 0x56, 0x69, 0x73, 0x75, 0x61, 0x6C, 0x20, 0x42, 0x61, 0x73, 0x69, 0x63, - 0x20, 0x73, 0x63, 0x72, 0x69, 0x70, 0x74, 0x20, 0x66, 0x69, 0x6C, 0x65, - 0x20, 0x64, 0x6F, 0x77, 0x6E, 0x6C, 0x6F, 0x61, 0x64, 0x20, 0x72, 0x65, - 0x71, 0x75, 0x65, 0x73, 0x74, 0x22, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, - 0x6D, 0x65, 0x74, 0x61, 0x64, 0x61, 0x74, 0x61, 0x3A, 0x73, 0x65, 0x72, - 0x76, 0x69, 0x63, 0x65, 0x20, 0x68, 0x74, 0x74, 0x70, 0x3B, 0x0A, 0x20, - 0x20, 0x20, 0x20, 0x72, 0x65, 0x66, 0x65, 0x72, 0x65, 0x6E, 0x63, 0x65, - 0x3A, 0x75, 0x72, 0x6C, 0x2C, 0x65, 0x6E, 0x2E, 0x77, 0x69, 0x6B, 0x69, - 0x70, 0x65, 0x64, 0x69, 0x61, 0x2E, 0x6F, 0x72, 0x67, 0x2F, 0x77, 0x69, - 0x6B, 0x69, 0x2F, 0x56, 0x62, 0x73, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, - 0x63, 0x6C, 0x61, 0x73, 0x73, 0x74, 0x79, 0x70, 0x65, 0x3A, 0x6D, 0x69, - 0x73, 0x63, 0x2D, 0x61, 0x63, 0x74, 0x69, 0x76, 0x69, 0x74, 0x79, 0x3B, - 0x0A, 0x20, 0x20, 0x20, 0x20, 0x73, 0x69, 0x64, 0x3A, 0x31, 0x38, 0x37, - 0x35, 0x38, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x72, 0x65, 0x76, 0x3A, - 0x38, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x73, 0x6F, 0x69, 0x64, 0x3A, - 0x33, 0x7C, 0x31, 0x38, 0x37, 0x35, 0x38, 0x3B, 0x0A, 0x23, 0x20, 0x65, - 0x76, 0x65, 0x72, 0x79, 0x74, 0x68, 0x69, 0x6E, 0x67, 0x20, 0x61, 0x62, - 0x6F, 0x76, 0x65, 0x20, 0x61, 0x70, 0x70, 0x65, 0x61, 0x72, 0x73, 0x20, - 0x69, 0x6E, 0x20, 0x73, 0x74, 0x75, 0x62, 0x0A, 0x23, 0x20, 0x74, 0x68, - 0x65, 0x20, 0x66, 0x6F, 0x6C, 0x6C, 0x6F, 0x77, 0x69, 0x6E, 0x67, 0x20, - 0x64, 0x65, 0x74, 0x65, 0x63, 0x74, 0x69, 0x6F, 0x6E, 0x20, 0x6F, 0x70, - 0x74, 0x69, 0x6F, 0x6E, 0x73, 0x20, 0x61, 0x72, 0x65, 0x20, 0x6E, 0x6F, - 0x74, 0x20, 0x69, 0x6E, 0x20, 0x70, 0x72, 0x6F, 0x74, 0x65, 0x63, 0x74, - 0x65, 0x64, 0x20, 0x73, 0x74, 0x75, 0x62, 0x0A, 0x20, 0x20, 0x20, 0x20, - 0x66, 0x6C, 0x6F, 0x77, 0x3A, 0x74, 0x6F, 0x5F, 0x73, 0x65, 0x72, 0x76, - 0x65, 0x72, 0x2C, 0x65, 0x73, 0x74, 0x61, 0x62, 0x6C, 0x69, 0x73, 0x68, - 0x65, 0x64, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x68, 0x74, 0x74, 0x70, - 0x5F, 0x75, 0x72, 0x69, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x63, 0x6F, - 0x6E, 0x74, 0x65, 0x6E, 0x74, 0x3A, 0x22, 0x2E, 0x76, 0x62, 0x73, 0x22, - 0x2C, 0x20, 0x6E, 0x6F, 0x63, 0x61, 0x73, 0x65, 0x3B, 0x0A, 0x20, 0x20, - 0x20, 0x20, 0x70, 0x63, 0x72, 0x65, 0x3A, 0x22, 0x2F, 0x5C, 0x78, 0x32, - 0x65, 0x76, 0x62, 0x73, 0x28, 0x5B, 0x5C, 0x3F, 0x5C, 0x78, 0x35, 0x63, - 0x5C, 0x78, 0x32, 0x66, 0x5D, 0x7C, 0x24, 0x29, 0x2F, 0x73, 0x6D, 0x69, - 0x22, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x73, 0x6F, 0x3A, 0x65, 0x76, - 0x61, 0x6C, 0x3B, 0x0A, 0x29, 0x0A, + 0x61, 0x6C, 0x65, 0x72, 0x74, 0x20, 0x74, 0x63, 0x70, 0x20, 0x24, 0x48, 0x4F, 0x4D, 0x45, 0x5F, + 0x4E, 0x45, 0x54, 0x20, 0x61, 0x6E, 0x79, 0x20, 0x2D, 0x3E, 0x20, 0x24, 0x45, 0x58, 0x54, 0x45, + 0x52, 0x4E, 0x41, 0x4C, 0x5F, 0x4E, 0x45, 0x54, 0x20, 0x24, 0x48, 0x54, 0x54, 0x50, 0x5F, 0x50, + 0x4F, 0x52, 0x54, 0x53, 0x0A, 0x28, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x6D, 0x73, 0x67, 0x3A, 0x22, + 0x46, 0x49, 0x4C, 0x45, 0x2D, 0x49, 0x44, 0x45, 0x4E, 0x54, 0x49, 0x46, 0x59, 0x20, 0x4D, 0x69, + 0x63, 0x72, 0x6F, 0x73, 0x6F, 0x66, 0x74, 0x20, 0x57, 0x69, 0x6E, 0x64, 0x6F, 0x77, 0x73, 0x20, + 0x56, 0x69, 0x73, 0x75, 0x61, 0x6C, 0x20, 0x42, 0x61, 0x73, 0x69, 0x63, 0x20, 0x73, 0x63, 0x72, + 0x69, 0x70, 0x74, 0x20, 0x66, 0x69, 0x6C, 0x65, 0x20, 0x64, 0x6F, 0x77, 0x6E, 0x6C, 0x6F, 0x61, + 0x64, 0x20, 0x72, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x22, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, + 0x6D, 0x65, 0x74, 0x61, 0x64, 0x61, 0x74, 0x61, 0x3A, 0x73, 0x65, 0x72, 0x76, 0x69, 0x63, 0x65, + 0x20, 0x68, 0x74, 0x74, 0x70, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x72, 0x65, 0x66, 0x65, 0x72, + 0x65, 0x6E, 0x63, 0x65, 0x3A, 0x75, 0x72, 0x6C, 0x2C, 0x65, 0x6E, 0x2E, 0x77, 0x69, 0x6B, 0x69, + 0x70, 0x65, 0x64, 0x69, 0x61, 0x2E, 0x6F, 0x72, 0x67, 0x2F, 0x77, 0x69, 0x6B, 0x69, 0x2F, 0x56, + 0x62, 0x73, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x63, 0x6C, 0x61, 0x73, 0x73, 0x74, 0x79, 0x70, + 0x65, 0x3A, 0x6D, 0x69, 0x73, 0x63, 0x2D, 0x61, 0x63, 0x74, 0x69, 0x76, 0x69, 0x74, 0x79, 0x3B, + 0x0A, 0x20, 0x20, 0x20, 0x20, 0x73, 0x69, 0x64, 0x3A, 0x31, 0x38, 0x37, 0x35, 0x38, 0x3B, 0x0A, + 0x20, 0x20, 0x20, 0x20, 0x72, 0x65, 0x76, 0x3A, 0x38, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x73, + 0x6F, 0x69, 0x64, 0x3A, 0x33, 0x7C, 0x31, 0x38, 0x37, 0x35, 0x38, 0x3B, 0x0A, 0x23, 0x20, 0x65, + 0x76, 0x65, 0x72, 0x79, 0x74, 0x68, 0x69, 0x6E, 0x67, 0x20, 0x61, 0x62, 0x6F, 0x76, 0x65, 0x20, + 0x61, 0x70, 0x70, 0x65, 0x61, 0x72, 0x73, 0x20, 0x69, 0x6E, 0x20, 0x73, 0x74, 0x75, 0x62, 0x0A, + 0x23, 0x20, 0x74, 0x68, 0x65, 0x20, 0x66, 0x6F, 0x6C, 0x6C, 0x6F, 0x77, 0x69, 0x6E, 0x67, 0x20, + 0x64, 0x65, 0x74, 0x65, 0x63, 0x74, 0x69, 0x6F, 0x6E, 0x20, 0x6F, 0x70, 0x74, 0x69, 0x6F, 0x6E, + 0x73, 0x20, 0x61, 0x72, 0x65, 0x20, 0x6E, 0x6F, 0x74, 0x20, 0x69, 0x6E, 0x20, 0x70, 0x72, 0x6F, + 0x74, 0x65, 0x63, 0x74, 0x65, 0x64, 0x20, 0x73, 0x74, 0x75, 0x62, 0x0A, 0x20, 0x20, 0x20, 0x20, + 0x66, 0x6C, 0x6F, 0x77, 0x3A, 0x74, 0x6F, 0x5F, 0x73, 0x65, 0x72, 0x76, 0x65, 0x72, 0x2C, 0x65, + 0x73, 0x74, 0x61, 0x62, 0x6C, 0x69, 0x73, 0x68, 0x65, 0x64, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, + 0x68, 0x74, 0x74, 0x70, 0x5F, 0x75, 0x72, 0x69, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x63, 0x6F, + 0x6E, 0x74, 0x65, 0x6E, 0x74, 0x3A, 0x22, 0x2E, 0x76, 0x62, 0x73, 0x22, 0x2C, 0x20, 0x6E, 0x6F, + 0x63, 0x61, 0x73, 0x65, 0x3B, 0x0A, 0x20, 0x20, 0x20, 0x20, 0x70, 0x63, 0x72, 0x65, 0x3A, 0x22, + 0x2F, 0x5C, 0x78, 0x32, 0x65, 0x76, 0x62, 0x73, 0x28, 0x5B, 0x5C, 0x3F, 0x5C, 0x78, 0x35, 0x63, + 0x5C, 0x78, 0x32, 0x66, 0x5D, 0x7C, 0x24, 0x29, 0x2F, 0x73, 0x6D, 0x69, 0x22, 0x3B, 0x0A, 0x20, + 0x20, 0x20, 0x20, 0x73, 0x6F, 0x3A, 0x65, 0x76, 0x61, 0x6C, 0x3B, 0x0A, 0x29, 0x0A, 0x00, }; const unsigned rule_18758_len = 0; - diff --git a/src/managers/so_manager.cc b/src/managers/so_manager.cc index f1a62eb55..d4a16f0b0 100644 --- a/src/managers/so_manager.cc +++ b/src/managers/so_manager.cc @@ -77,35 +77,43 @@ void SoManager::dump_plugins() //------------------------------------------------------------------------- // FIXIT-L eliminate this arbitrary limit on rule text size +const unsigned window_bits = -8; const unsigned max_rule = 128000; static uint8_t so_buf[max_rule]; static const uint8_t* compress(const string& text, unsigned& len) { + len = 0; const char* s = text.c_str(); z_stream stream; + stream.zalloc = Z_NULL; + stream.zfree = Z_NULL; + stream.opaque = Z_NULL; + stream.next_in = Z_NULL; + + // v2 avoids the header and trailer + int ret = deflateInit2( + &stream, Z_DEFAULT_COMPRESSION, Z_DEFLATED, window_bits, 1, Z_DEFAULT_STRATEGY); + + if ( ret != Z_OK ) + return nullptr; + stream.next_in = (Bytef*)s; stream.avail_in = text.size(); stream.next_out = so_buf; stream.avail_out = max_rule; - stream.zalloc = nullptr; - stream.zfree = nullptr; + ret = deflate(&stream, Z_FINISH); + (void)deflateEnd(&stream); - stream.total_in = 0; - stream.total_out = 0; - - len = 0; - - if ( deflateInit(&stream, Z_DEFAULT_COMPRESSION) != Z_OK ) + if ( ret != Z_STREAM_END ) return nullptr; - if ( deflate(&stream, Z_FINISH) == Z_STREAM_END ) - len= stream.total_out; + len= stream.total_out; + assert(stream.avail_out > 0); - deflateEnd(&stream); return so_buf; } @@ -115,22 +123,30 @@ static const char* expand(const uint8_t* data, unsigned len) { z_stream stream; + stream.zalloc = Z_NULL; + stream.zfree = Z_NULL; + stream.opaque = Z_NULL; + stream.next_in = Z_NULL; + stream.avail_in = 0; + + if ( inflateInit2(&stream, window_bits) != Z_OK ) + return nullptr; + stream.next_in = (Bytef*)data; stream.avail_in = (uInt)len; stream.next_out = (Bytef*)so_buf; stream.avail_out = (uInt)(max_rule - 1); - stream.zalloc = nullptr; - stream.zfree = nullptr; - - stream.total_in = 0; - stream.total_out = 0; + int ret = inflate(&stream, Z_FINISH); + (void)inflateEnd(&stream); - if ( inflateInit(&stream) != Z_OK ) + // FIXIT-L full decompression still gets Z_BUF_ERROR ... + if ( ret != Z_STREAM_END and ret != Z_BUF_ERROR ) return nullptr; - if ( inflate(&stream, Z_SYNC_FLUSH) != Z_STREAM_END ) + // ... so we add this as a sanity check + if ( stream.avail_in or !stream.avail_out ) return nullptr; assert(stream.total_out < max_rule); @@ -146,11 +162,6 @@ static void strvrt(const string& text, string& data) unsigned len = 0; const uint8_t* d = compress(text, len); - // lose the zlib header - assert(len > 2 && d[0] == 0x78 && d[1] == 0x9C); - d += 2; - len -= 2; - data.assign((char*)d, len); // generate xor key @@ -159,6 +170,7 @@ static void strvrt(const string& text, string& data) // nonetheless this seems to work as good as the basic // C++ 11 default generator and uniform distribution uint8_t key = (uint8_t)(rand() >> 16); + if ( !key ) key = 0xA5; @@ -179,9 +191,6 @@ static const char* revert(const uint8_t* data, unsigned len) for ( unsigned i = 0; i < len-1; i++ ) s[i] ^= key; - // force the zlib header - s.insert(0, "\x78\x9C"); - return expand((uint8_t*)s.c_str(), s.size()); } @@ -203,9 +212,6 @@ const char* SoManager::get_so_options(const char* soid) if ( !api ) return nullptr; - if ( !api->length ) - return nullptr; - const char* rule = revert(api->rule, api->length); if ( !rule ) @@ -295,6 +301,8 @@ static void get_var(const string& s, string& v) v = s.substr(pos, end-pos); } +const unsigned hex_per_row = 16; + void SoManager::rule_to_hex(const char*) { stringstream buffer; @@ -310,18 +318,18 @@ void SoManager::rule_to_hex(const char*) cout << "const uint8_t rule_" << var; cout << "[] =" << endl; - cout << "{" << endl; + cout << "{" << endl << " "; cout << hex << uppercase; for ( idx = 0; idx < data.size(); idx++ ) { - if ( idx && !(idx % 12) ) - cout << endl; + if ( idx && !(idx % hex_per_row) ) + cout << endl << " "; uint8_t u = data[idx]; - cout << "0x" << setfill('0') << setw(2) << hex << (int)u << ", "; + cout << " 0x" << setfill('0') << setw(2) << hex << (int)u << ","; } - if ( idx % 16 ) + if ( idx % hex_per_row ) cout << endl; cout << dec; @@ -344,16 +352,18 @@ void SoManager::rule_to_text(const char*) cout << "const uint8_t rule_" << var; cout << "[] =" << endl; - cout << "{" << endl; + cout << "{" << endl << " "; cout << hex << uppercase; - for ( idx = 0; idx < len; idx++ ) + for ( idx = 0; idx <= len; idx++ ) { - if ( idx && !(idx % 12) ) - cout << endl; - cout << "0x" << setfill('0') << setw(2) << (unsigned)data[idx] << ", "; + if ( idx && !(idx % hex_per_row) ) + cout << endl << " "; + + unsigned byte = (idx == len) ? 0 : data[idx]; + cout << " 0x" << setfill('0') << setw(2) << byte << ","; } - if ( idx % 16 ) + if ( idx % hex_per_row ) cout << endl; cout << dec; diff --git a/src/parser/parse_stream.cc b/src/parser/parse_stream.cc index 0bc0d736e..63a735b3e 100644 --- a/src/parser/parse_stream.cc +++ b/src/parser/parse_stream.cc @@ -33,6 +33,7 @@ using namespace std; #include "parse_rule.h" #include "detection/treenodes.h" #include "log/messages.h" +#include "managers/ips_manager.h" static unsigned chars = 0, tokens = 0; static unsigned lines = 1, comments = 0; @@ -541,9 +542,12 @@ static bool exec( { if ( rps.tbd ) exec(FSM_END, tok, rps, sc); - const char* extra = parse_rule_close(sc, rps.rtn, rps.otn); - if ( extra ) + + if ( const char* extra = parse_rule_close(sc, rps.rtn, rps.otn) ) + { + IpsManager::reset_options(); parse_body(extra, rps, sc); + } else { rps.otn = nullptr;