From: Philippe Antoine Date: Tue, 6 Dec 2022 13:28:48 +0000 (+0100) Subject: Adds test about smb ntlmssp arbitrary order X-Git-Tag: suricata-6.0.10~25 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=refs%2Fpull%2F1081%2Fhead;p=thirdparty%2Fsuricata-verify.git Adds test about smb ntlmssp arbitrary order Ticket: #5258 --- diff --git a/tests/smb2-ntlmssp-order/README.md b/tests/smb2-ntlmssp-order/README.md new file mode 100644 index 000000000..fc625cc3f --- /dev/null +++ b/tests/smb2-ntlmssp-order/README.md @@ -0,0 +1,4 @@ +PCAP +==== + +Pcap from smb2-03-rule edited to switch host and user offsets in NTLMSSP diff --git a/tests/smb2-ntlmssp-order/smb2.pcap b/tests/smb2-ntlmssp-order/smb2.pcap new file mode 100644 index 000000000..a384afcee Binary files /dev/null and b/tests/smb2-ntlmssp-order/smb2.pcap differ diff --git a/tests/smb2-ntlmssp-order/test.yaml b/tests/smb2-ntlmssp-order/test.yaml new file mode 100644 index 000000000..f708cb367 --- /dev/null +++ b/tests/smb2-ntlmssp-order/test.yaml @@ -0,0 +1,18 @@ +requires: + min-version: 6 + +args: +- --set stream.reassembly.depth=0 + +checks: + - filter: + count: 1 + match: + event_type: smb + smb.id: 3 + smb.dialect: "2.02" + smb.command: SMB2_COMMAND_SESSION_SETUP + smb.status: STATUS_SUCCESS + smb.ntlmssp.domain: "CONTOSO" + smb.ntlmssp.user: "SERVER01" + smb.ntlmssp.host: "Administrator"