From: Victor Julien Date: Thu, 7 Nov 2019 09:27:34 +0000 (+0100) Subject: tests: add bug 3277 nfsv2+filestore test X-Git-Tag: suricata-6.0.4~374 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=refs%2Fpull%2F148%2Fhead;p=thirdparty%2Fsuricata-verify.git tests: add bug 3277 nfsv2+filestore test --- diff --git a/tests/issue-3277-nfsv2-filestore/README.md b/tests/issue-3277-nfsv2-filestore/README.md new file mode 100644 index 000000000..df09c947b --- /dev/null +++ b/tests/issue-3277-nfsv2-filestore/README.md @@ -0,0 +1 @@ +Pcap from https://redmine.openinfosecfoundation.org/issues/3277 diff --git a/tests/issue-3277-nfsv2-filestore/nfsv2.pcap b/tests/issue-3277-nfsv2-filestore/nfsv2.pcap new file mode 100644 index 000000000..8575554ee Binary files /dev/null and b/tests/issue-3277-nfsv2-filestore/nfsv2.pcap differ diff --git a/tests/issue-3277-nfsv2-filestore/test.rules b/tests/issue-3277-nfsv2-filestore/test.rules new file mode 100644 index 000000000..2d54ae4c5 --- /dev/null +++ b/tests/issue-3277-nfsv2-filestore/test.rules @@ -0,0 +1 @@ +alert nfs any any -> any any (msg:"FILE store in NFS"; filestore; sid:1; rev:1;) diff --git a/tests/issue-3277-nfsv2-filestore/test.yaml b/tests/issue-3277-nfsv2-filestore/test.yaml new file mode 100644 index 000000000..6c6b9650e --- /dev/null +++ b/tests/issue-3277-nfsv2-filestore/test.yaml @@ -0,0 +1,14 @@ +requires: + features: + - HAVE_LIBJANSSON + - RUST + +checks: + - filter: + count: 1 + match: + event_type: alert + app_proto: nfs + alert.signature_id: 1 + +