<div id="content">\r
<div id="preamble">\r
<div class="sectionbody">\r
-<img alt="snorty" src="data:image/png;base64,\r
-iVBORw0KGgoAAAANSUhEUgAAAX4AAADGCAIAAABaVnwHAAAMFWlDQ1BJQ0MgUHJvZmlsZQAASA2tV2dY
-U8kanlOSQEhCCURASuhNlF6l1wgKUgUbIQlJKCEEgoodWVRg7SKKFV0Bsa0FkLUgFkRZBHvfoKKirIsF
-Gyp3DkXdu3f/3fM8M+c977zzfd98M2eeGQAY7VypNB1VAyBDkiOLCvFnT0lIZFMeAAyoADLQBo5cXrbU
-LzIyHPzr8+4GQIjGq7aErX+V/e8Gdb4gmwcAEgmbk/nZvAyIjwCA1fOkshwASIQ901k5UgKvglhTBgOE
-eBeBhUO4nsDJQ7h1UBMTFQA1CgCUaFyuTAgAvQfy7FyeENph0CC2k/DFEojHQ+zNE3H5EM+DeExGRiaB
-qyC2TP7BjvAHzOUmf7PJ5Qq/4aGxwJ7QcaA4W5rOnTP48f+sMtLlMF+DjwGsadlp0WHwzYJ5m83jBkVD
-rA3xCpGAEz7M75bm+EcN88fFOZwYiDWh5ppIHho7jJ/J02L9INaD/Oe0zDBCD/OEakuSJ0VArAGxKS87
-AOae8IW65Ili4oc14XxBYBDEcBWhU2SZUSN6UXZu9AiflycKmDSiT+VOIOabAfVFXBlEg/GgZYL0EMKv
-MeT3SnMiiTgJX22S9EnDY0Efp8iCCQ3BfxJkD46XiE2UI4oJhTyMGVPLkcUQGjhGTC9FHMyBGMaG2Ylk
-oSO8rzR9cE3DvliMTB5F5MEU4hSBJJbIIcEX8bmBRG5hTrDNIBhwgQwIQDKQgG7ABuEgAAQO12zISyDH
-A5kgHRYZW3WkhfSE1EF6SLpOUpBuj3Cw57AOiAEf4iFbP/SHfDTIA39CqwKQPeIN18W9cU88HNa+sDjg
-brj7SFtbT13PCB6OVQj72g7b9h+OPhda/DKimynOl43g4T7J33r8M6Zg8BhmQDiisKux67b7PNL/+4jJ
-QeRAcig5mGyFLcMOY83YaawFO47VATZ2CqvHWrETBB6Oa8QLFzJEVogMZ4MwmEUBkA9+SUb8/S1L8m+K
-YQsMa4YziIK9JCANtom/eYgbjFr8DytyqEiGHlOhNuzbfAzHhZvD7Drj/rgXzDPMMc7CdYEt7gQz7of7
-wDlwhuz3Wfz7aGxBymC2cwfHkgaewHFk5Ahm58C1BAIypXNkYqEoh+0Hd0vBGDZHwhs7hu1gZ+8EiL2X
-0ADwhjW4pyKsi9+5rEYA3Ivg/0lse2xCBQDXBIBjTwBgvvvOmbyGvwHcK0+08+Sy3CEdTrxIgApU4V+h
-AwyACbCEGXEALsAT+IIgMAFEgBiQAGbANSwCGTDiWWAeWAwKQTFYBdaDTWAb2AmqwD5wCNSB4+A0OA8u
-gXZwHdwFCtAFXoBe8A70IwhCQegIE9FBDBEzxAZxQNwQbyQICUeikAQkCREiEkSOzEOWIMXIGmQTsgOp
-Rn5FjiGnkRakA7mNdCLdyGvkE4qhNFQT1UfN0XGoG+qHhqEx6HRUiGaheWgBugItQyvQvWgtehq9hF5H
-FegLtA8DmArGwowwW8wNC8AisEQsBZNhC7AirBSrwPZjDXAtXsUUWA/2ESfjTJyN28KZDMVjcR6ehS/A
-S/BNeBVei5/Fr+KdeC/+lUQn6ZFsSB4kDmkKSUiaRSoklZJ2k46SzsH/uYv0jkwms8gWZFe42hPIqeS5
-5BLyFvIBciO5g/yI3EehUHQoNhQvSgSFS8mhFFI2UvZSTlGuULooH5RUlAyVHJSClRKVJEr5SqVKe5RO
-Kl1ReqrUr6ymbKbsoRyhzFeeo7xSeZdyg/Jl5S7lfqo61YLqRY2hplIXU8uo+6nnqPeob1RUVIxV3FUm
-q4hVFqmUqRxUuaDSqfKRpkGzpgXQptHktBW0Sloj7TbtDZ1ON6f70hPpOfQV9Gr6GfoD+gcGkzGWwWHw
-GQsZ5YxaxhXGS1VlVTNVP9UZqnmqpaqHVS+r9qgpq5mrBahx1RaolasdU7up1qfOVLdXj1DPUC9R36Pe
-ov5Mg6JhrhGkwdco0NipcUbjERNjmjADmDzmEuYu5jlmlyZZ00KTo5mqWay5T7NNs1dLQ8tJK05rtla5
-1gktBQtjmbM4rHTWStYh1g3Wp1H6o/xGCUYtH7V/1JVR77VHa/tqC7SLtA9oX9f+pMPWCdJJ01mtU6dz
-XxfXtdadrDtLd6vuOd2e0ZqjPUfzRheNPjT6jh6qZ60XpTdXb6deq16fvoF+iL5Uf6P+Gf0eA5aBr0Gq
-wTqDkwbdhkxDb0Ox4TrDU4bP2VpsP3Y6u4x9lt1rpGcUaiQ32mHUZtRvbGEca5xvfMD4vgnVxM0kxWSd
-SZNJr6mh6UTTeaY1pnfMlM3czERmG8yazd6bW5jHmy81rzN/ZqFtwbHIs6ixuGdJt/SxzLKssLxmRbZy
-s0qz2mLVbo1aO1uLrMutL9ugNi42YpstNh1jSGPcx0jGVIy5aUuz9bPNta2x7RzLGhs+Nn9s3diX40zH
-JY5bPa553Fc7Z7t0u112d+017CfY59s32L92sHbgOZQ7XHOkOwY7LnSsd3zlZOMkcNrqdMuZ6TzRealz
-k/MXF1cXmct+l25XU9ck182uN9003SLdStwuuJPc/d0Xuh93/+jh4pHjccjjL09bzzTPPZ7PxluMF4zf
-Nf6Rl7EX12uHl8Kb7Z3kvd1b4WPkw/Wp8Hnoa+LL993t+9TPyi/Vb6/fS387f5n/Uf/3AR4B8wMaA7HA
-kMCiwLYgjaDYoE1BD4KNg4XBNcG9Ic4hc0MaQ0mhYaGrQ29y9Dk8TjWnd4LrhPkTzobRwqLDNoU9DLcO
-l4U3TEQnTpi4duK9SWaTJJPqIkAEJ2JtxP1Ii8isyN8mkydHTi6f/CTKPmpeVHM0M3pm9J7odzH+MStj
-7sZaxspjm+JU46bFVce9jw+MXxOvmDJuyvwplxJ0E8QJ9YmUxLjE3Yl9U4Omrp/aNc15WuG0G9Mtps+e
-3jJDd0b6jBMzVWdyZx5OIiXFJ+1J+syN4FZw+5I5yZuTe3kBvA28F3xf/jp+t8BLsEbwNMUrZU3KM6GX
-cK2wW+QjKhX1iAPEm8SvUkNTt6W+T4tIq0wbSI9PP5ChlJGUcUyiIUmTnM00yJyd2SG1kRZKFVkeWeuz
-emVhst3ZSPb07PocTXjIbZVbyn+Sd+Z655bnfpgVN+vwbPXZktmtc6znLJ/zNC8475e5+Fze3KZ5RvMW
-z+uc7zd/xwJkQfKCpoUmCwsWdi0KWVS1mLo4bfHv+Xb5a/LfLolf0lCgX7Co4NFPIT/VFDIKZYU3l3ou
-3bYMXyZe1rbccfnG5V+L+EUXi+2KS4s/l/BKLv5s/3PZzwMrUla0rXRZuXUVeZVk1Y3VPqur1qivyVvz
-aO3EtbXr2OuK1r1dP3N9S6lT6bYN1A3yDYqy8LL6jaYbV238vEm06Xq5f/mBzXqbl29+v4W/5cpW3637
-t+lvK972abt4+60dITtqK8wrSneSd+bufLIrblfzL26/VO/W3V28+0ulpFJRFVV1ttq1unqP3p6VNWiN
-vKZ777S97fsC99Xvt92/4wDrQPFBcFB+8PmvSb/eOBR2qOmw2+H9R8yObD7KPFpUi9TOqe2tE9Up6hPq
-O45NONbU4Nlw9Lexv1UeNzpefkLrxMqT1JMFJwdO5Z3qa5Q29pwWnn7UNLPp7pkpZ66dnXy27VzYuQvn
-g8+fafZrPnXB68LxFo+WYxfdLtZdcrlU2+rcevR359+Ptrm01V52vVzf7t7e0DG+4+QVnyunrwZePX+N
-c+3S9UnXO27E3rh1c9pNxS3+rWe302+/upN7p//uonuke0X31e6XPtB7UPGH1R8HFC6KE52Bna0Pox/e
-fcR79OJx9uPPXQVP6E9Knxo+rX7m8Ox4d3B3+/Opz7teSF/09xT+qf7n5peWL4/85ftXa++U3q5XslcD
-r0ve6LypfOv0tqkvsu/Bu4x3/e+LPuh8qPro9rH5U/ynp/2zPlM+l32x+tLwNezrvYGMgQEpV8YdPAtg
-sEZTUgB4XQnvRQnw7NAOAJUxdDcaVCBD9zmIkeFC0P+Fh+5PRAM8Q4BKXwBiFwEQ3gjAVljMIKbBN3HM
-j/EFqKPjtwIZ4slOcXQYBAhNBo8mHwYG3ugDQGkA4ItsYKB/y8DAl13w3H0bgMasoTsZoSbDc/x2eG8A
-oKWtZBHx/vH5D/IjYGjniSMUAAAACXBIWXMAABYlAAAWJQFJUiTwAAABnWlUWHRYTUw6Y29tLmFkb2Jl
-LnhtcAAAAAAAPHg6eG1wbWV0YSB4bWxuczp4PSJhZG9iZTpuczptZXRhLyIgeDp4bXB0az0iWE1QIENv
-cmUgNS4xLjIiPgogICA8cmRmOlJERiB4bWxuczpyZGY9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkvMDIv
-MjItcmRmLXN5bnRheC1ucyMiPgogICAgICA8cmRmOkRlc2NyaXB0aW9uIHJkZjphYm91dD0iIgogICAg
-ICAgICAgICB4bWxuczpleGlmPSJodHRwOi8vbnMuYWRvYmUuY29tL2V4aWYvMS4wLyI+CiAgICAgICAg
-IDxleGlmOlBpeGVsWERpbWVuc2lvbj4zODI8L2V4aWY6UGl4ZWxYRGltZW5zaW9uPgogICAgICAgICA8
-ZXhpZjpQaXhlbFlEaW1lbnNpb24+MTk4PC9leGlmOlBpeGVsWURpbWVuc2lvbj4KICAgICAgPC9yZGY6
-RGVzY3JpcHRpb24+CiAgIDwvcmRmOlJERj4KPC94OnhtcG1ldGE+ChfvoHgAAEAASURBVHgB7L3ndyNn
-luZJA++9IQh6b9NKJamqq7tne6b3zOnZb/tH7vfZPdNmuqpkSlJauqS38B4gvCG4v8BLIpF0IrOkzBQV
-SBxmEAzz4kbEE/e997nP7T46OuqSX7IFZAvIFviwFuj5sIeTjyZbQLaAbAHJAjL0yNeBbAHZAh/BAjL0
-fASjy4eULSBbQIYe+RqQLSBb4CNYQIaej2B0+ZCyBWQLyNAjXwOyBWQLfAQLyNDzEYwuH1K2gGwBGXrk
-a0C2gGyBj2ABGXo+gtHlQ8oWkC0gQ498DcgWkC3wESwgQ89HMLp8SNkCsgVk6JGvAdkCsgU+ggVk6PkI
-RpcPKVtAtoAMPfI1IFtAtsBHsIAMPR/B6PIhZQvIFpChR74GZAvIFvgIFpCh5yMYXT6kbAHZAjL0yNeA
-bAHZAh/BAjL0fASjy4eULSBbQCGb4ANbIJ/PR4LBtdXVb77+Wq1W//d/+ZeZ+TmD3qBUqT7wSOTDyRb4
-iBaQoedDGP/09PTk5KRaqRQKhVgsdrC/v7O7m0gmjUZjOp3KZ7NqlVqGng9xJuRjfDIWkKHnQ5wKcKdS
-LgM6O9vb6+vrS8vLh4eHuVyuz+PZ2962Wyx6g0Gn13+IocjHkC3waVhAhp5f9jxIzk61epzLRiPR/f29
-tbW19Tfr65ubyVSKAyt7e7c2N+02m29wyO78ZUci7122wCdlARl6ftnTAe6kksn93d3Xr15tbGzsHx7G
-4nHCPeKox/k8MGSxWR88ffrLjkPeu2yBT8wCMvTc7YTU6/VSqdSo19msu7tboVB091ydJazVasVCIZFI
-BI6Otre2VpaXj44Oj4+zPaenoy5X8/Q0lsuWa7VYIn4UDMVicX8up9PplErlTw5IRI5OGtKL/bTX72mN
-p1eh6O3tZWztz+UF2QKfoAVk6LnbSQF3AoRpslk2U6lUN4BFJpPZ3d3htb2zGwqHieycNqoGddeo2/vV
-5EKtcfpvy6+3IuF64ySTzRF4drvd/sFBs9n8kwMSkaNSqVgsFOu1Wnt9AtV6g16n02u0WjCx/bm8IFvg
-E7SAfIHe7aRwvwMTODLVWq2np4fY8HV+Siad3t3dPTjYPwwESsWSXq322swTPsfD4ZEvJ2aL1Xo0l8Hr
-CaZSmWx2Y2PdarFYbdZO6BHeTa1aLbN9qcyrwvytVqtIr3K5yFiK+FbtLwAU6vV6rV6n0Wh1Wi2wqNVq
-NdIv0uu6cbY3lxdkC3xIC8jQczdrkx3HlVlaWkqkUgABUxsA6MpdAAqsLPkmpbJBrR5xux+OjPz9/NyM
-3+8wWtL5wu8mpk+aXcVKLZ3NLL1+BUpMzkz7+v3tvQnvJp1MBA8Pg4FgMByKxOLJdLpQLPIn6cWEq9ls
-r89IxGyLUQFkg35/v8/n8Xp9/f239Kfau5IXZAv80haQoeduFgZQcGdCvCKR40KBjXt7utVKCX2q9eZJ
-823khWgLf9Kp1X0W66DTOTcw8GRs/MnYpN8hpbJ6exXzg0PFSuUwHi8FK+TdSbenkikRgRZxolwum0ql
-Y9FIC3oCwVCYwFA6k63WqkqFkoiOguAOaNPbw2ErxJ9OGl2nDRCJkcAYioSCPp/P6/WCPOzf4/VYLBaD
-0SR7QHc75fLav4wFZOj5W+0K7tiNavaSyldL1ZP27sAdjUrZb7c/Hh1/MDQ8Ozg45HLZjSaxAvOvIbc7
-XynvRiOlauUwkTjOF+PxOERnVhBxoj1eBwfxRIK5VbnMlEuCl+6uptmgNxpNRo3WqFAYVGq9RlNrNiOF
-fL5cOK0XWJWRsAUTvXgyub65ZTQYrBbz8PDQg8WHE1NTsgfUPkfywke0gAw9dzM+vgbxHRwHpjZiS7NO
-Nz/gM+v0qUK9XHsLPTgjQM+Aw/lkdHzGPwDQWDpIg0qFwqJQDDldj0dGy5VKtljM54+3NjeqlXKzeZpK
-pYgThYKBZDxRr1Q0KrVZqXRatFq1yqjVGPTvQI9Bo6k2m1Ggp1Jo1gtMx6LpUrpQLlYreFXxbC7SPMFH
-wnsiWJRnElgs+v1+m91OJOhuX15eW7bAz2cBGXruZkuVWu3g5XSGolGxpdts+28Ln80PDje6uptdb1Pa
-ZxMuldramuTg5lw+ks1g+N3YBEUWu/Hobirxw1+/e/3qZaVWx8EBIlTd3R6j0dPv77PZXWazTW+wGQ1W
-o1Gn1SgUSuiIV064iuVKMnscSqX3E/HdWHQ7Ek4c58ijhaKx4vc/kMjf399/8GDx6ee/IwZ0eUjyJ7IF
-PowFZOi5m53xerTC6+ntFVtqlWqv2THtGyCRdKssEokryDgtPo5WqfQ7HNmif35gsFStJuLxSr2u7FGo
-lUqHWuO1Wif6+oZdbqDHCfQwb9LrTXq9+sZCU1Jgxzg+2Yw/7uyz2Txm8348Fk5nCCPFolF8q1IhDyEI
-PGT8N/g+Ir9Wr9eqlSrcJTlCdLcLRV77pywgQ89PWein/l6t15PHx8ncsRvguR0hsNlonLYyU93dPcSi
-XVbrH6dm1T29f9lcP66UIf4AN8NOl9/p9NrseDpMuAAjlUKh6u1lpnbziFgBeCLRbjebJ32+3OTUTjj8
-7ebG8tHhXixGKIgYkIiGF/LHN/g+hKvJ4BPqBhBxsuQI0c1ml/96Vwv8xHV8193d+/WZ6BC1JX/U5uyd
-NJs4LLxJdN/89euNRrFazRcL2XwOzrLHZKVmtLtbSc6JjDtztVrXaaFSGff2jbo9xKQ9FutP+jhnR+wB
-wnq7FL1dLOBP1WrqE7XeZPJ04V2dOpyuU41apdX2KpQHsViuVAwEAz3dXXwFT5+PL3PBoxGMbRJ50WiY
-0rNYNGYymcAygBWVDzL3N39N+a+yBW5jARl6bmOlt+vA0PP29ZGxfo8YLbjDnb8dPloP7phV6n+eeWxU
-qIErVU+P02p9pNX6PR7wy6jRkLTSqzUa7vWf8nHEyMCdbr2uW6fp1mgAjuN0+qRaM4IUKlW3WuUw6n9n
-MtjsDrNe/4KSjsPDTKmI76MzGIeHhwlaX/BoBGN7Y/3NyxfP9w8OcvnC4MCg0WRiRml3OMCpt+aQl2QL
-vK8FZOi5m+V4+Nt42e0siC0bzZNCtcIbRs3N+8IzCiQSm6HQVjjsNZpIbHWxSb2rV6UEa4AAr91+8x6u
-+GvL32koe6vNk/zxcSoeSzH7SyQb1SriYyaj0eJyWoxGl6+P6gomd/gtBG62gsFk/jgYDK6urkipd5vV
-YDDAlIb/SI1INBLZ290l3bb+5g1MxlwBznQduQ8nuNOKc10xDPkj2QJ3tIAMPXczGJMU6qR4tZPr5Xo9
-ksvxxme5eV+VWjWcTiVyeVWvzqy1KHuV0uSocULAp4sg0XvNY4S/A+6Ectk3hwffLb3eCQSOqe2qNyhs
-dbuc0zMzi9PTT6enHP7+B3q9xW53mEzO1dVv19czHSxqq81Ohf3B3h5lrvt7u1AQCUgT7oFAVKpItGyS
-/S6X0+vz2d8DH2+2i/zX36QFZOi522kHcajP1BlIM8GV6YG+3Dhp5qsV3j8Z66FiK5xJpwp50uQOk1Wt
-UBGJkdDn5CzhdduhULoBVLUKOKo93aXmSTCTXt7eXt7aXNrcDCUS9ZNTXCqI0cZwKFUu9ygUUyMjfp9Z
-o4dcrVJDAmiehjKZ8tEhELO1ufVm7Q1F9oR1oE0fbG3lkkn9ScNGEMhgpGqjVq5IpMfDA7fbNb+42Gj4
-5Mr4254peb3rLSBDz/W2ueov3HXMXKTycAozVUo4OFetdfVnAnoyxcKox0u+XHs+Zbt67Rs+VSpPTcYu
-tTTjy5dKu8nky83N//zmm3A0ajAaxsfG1RotJakoAYE+/HRZLPkvv5R4RkqlyWodmhzPN+oSi7pcgkUN
-0+d///u/AzOpVLKnVndp9U/8g9NeL0wiIk1rwWAmm14LBgKhkOPggMIO0l5yZfwNJ0f+0y0tIEPPLQ11
-tho3MHMunVZHfSZV5ifZXPO0WWs0yF6xcN2+RG6LHHy6kGcW4zGa/Bbr+0CPyGRp1d0GHaWr+XJ5P5N+
-trWJy5PI57UGw/TEBAWjxIPDsSjR4t39vRyhn1SKsi9JXqi7W63T2pSK4dLQ07m5Wq1aqlfix8fr6280
-KlXvyYkPYOrzPxwanvcPuMxnNR+jLnc4nY5lc4ichUJBmNAej0dhMFz3ZeXPZQvcxgIy9NzGShfXIfvk
-dns8bk+pUmXCRb0CSXEWLq53/rvIbZHeorgB3uGQ2TJotiC3cf732/5/lsky6MlkMaXajcefra//x1/+
-ks3nx8fGZsfHHwI9Tgc85+3DA1weIJFMVufeQR98H5fL9fvPnqpVPalCvLR1jIBZl9Y47et7NDz61fTM
-eF+fWauDQcSGZoNhvM8XzeX4poV8gWCzw+4gJo2YdOdu5WXZAne1gAw9d7WYtD4cF4tVEthRhiPkkgo1
-6U2q67p9HZdKbwJHG+Eg+OQymGxanUWtuW7lmz5HiFClqPd0I8YBR/nF2trrN29iiYTFZJqfnPzdgweT
-/n67SfJWms2TEb8/EEZmI/HODlu+D/My/eBAoXg8tTUYSySJDzH5IkPHFNJjtXis1vYmBp1uzOPF69mJ
-RKj/2tvZdTmdY+Pj7vYa8oJsgfeygAw972M23AroLcxrCP3UTk/xLqTahFZtxJW7yxTyz3e3Xx8eNLq7
-id1CDr5ytVt+SHxnO5PB3/m3P/+ZSRBYsDgz82R6GtwxnleEwv8DGm0WMwtX7BYekEZjstqnB8bj0Wwk
-XWbaRbUXpRt5Uv4dL+hFkBvhBLAQzcVQtvd4XMgjdqwiL8oWeB8LXC1z9T57+i1tI6kgKyV2L+pcOAto
-X/CuX8XrIcpDVTpeA2FdyjjpekNtBIGVv8VaNUo3crlENks0x6DTLkxNfbYwP9rvw99pAw1kQrfNxpsF
-qWas2WSrXKmUKTBtKjBZO+nupoxrrG9gzOs3aHW1Rp04FCME11LHuc3QIW8WKId1msw+h8NmNoOz5OOj
-sVg2Ix2aoNXf8i3kbX/jFpC9nr/1Aqg36lBgeBNYubwvEeXZjURS+YKyu3fM4Zx0ueErX17zrp8Q5X44
-P2816L96/HhiaAho6NwDWXSkgnjr1EBP86ReRysjnM8jsKo/PTVptVa7TWgGHbnd7ap6xMaOi4XN4OF3
-W8vs7cuJhRG3D71Vp9XW53IdZFIIlQldIUhAMrO50+Dy8l0tIEPP3SzGox7WbzaXSyUT2UwGVXY+kYS8
-yuUrvQAR5XkTDLBg0mhHbY4xm93Q9nq6u0+lwG836afbjIMpHUqIVM/j4Ix2d/uh95lNM6Oj7g6aX7Fc
-TlB+FYuHgkEiPeg5M787DIV7lKrtWAwVxWGnc8DlMp6cEOc2m00Wi0mrUbNPBlIol7YjgYN493cbb6hI
-6z5V5cu1PruDWRgunlaDvk8Wp4lUu7+/X2Y23+aUyetcZwEZeq6zzNWfi75aR4cHlBkQ+ECYHVYh7B7e
-neqo7Y1FlOfV/m65Xh2y20es1s7cFrhzSs2n1FHnltCD/9IAKcZ9fUPdPc2TE4iNZqOxfTgWwJ0/P3v2
-anWVThgHoE8iUW3Uv0YHaGtrc3/fZDb/13/4B7vb3aCytKenCQhq1GqNmgAzsorJfO67zWVYApuhOD0z
-cqUXb0Lhmf6Bk65upo3iKDKzudPa8vJ7W0CGntuaTvg78Vh0a2NDqjbY30+mktVanUBK4+S0Vm+IdhHQ
-8IRQfKVWyxWL6FTQ8YaWW4gZ9qOeYzB25rZwNMAdqeL8dl5PF2236nWVRq03GHt1FzUGKRyla0UwHF5a
-W3u5tpZMZyD+UGqP5Ea5cdJTryFWpuvuRrKjJOkilk6RGwN/Wi19aF7BhBGh1VStirq8Um9sVBsRokLB
-YL5cIayOACtKQESO0MFnthWPxWghf1vbyevJFrhkARl6Lpnkmg+EvwPu/Ok///fy8nIoEu30dIiSADRo
-dLVlLvh1aX//1e5uLJNF/QsVnnFPn0Gas3S8erp7hNdzO+ihAqK3Vu+u1Vjo2MvZooQ7oRDFVvsH+/TP
-GR4cpFI0mUhQ7jo9Mz3q7TPWGypENUCiXC4IE1qjcbUYkpIIiNEID0it1bm8sI4s/fUmsaFMKkVJ6noo
-DKqiC00RCatRwUbkiD4bDVTo5Zdsgfe1gAw9P205/BpcHvRrJB2Jly8l3AkGqcDqs0qF5ugKooAjqtIP
-4jG/06VVq6EO7oQjP25vrR4dlKolu0E76+2b8fqI754dD6whvKJUdAM917TTuWJk1HydnHTXG81qlTIu
-afOObfFK4ul0IpM5OT1tyesoUPZgML4+7/To2ITPZzvtOqbaa38vETzqNZq8VpvO5cbHoa6LOA6MbJvN
-MTox3ddqyFMuFpNJauCTtN8hksVg8IwcNpu+9RV8Ph+dvq4YofyRbIHbWUCGnp+2E7hD4RIi7d/85S8v
-XjzH3wF3Zv1+ss5sHMvlUMAhirwaOBKpInLnB/H40sHB1+tvgqmYorcx6rI8HfAvePvMba9HYtao4QcC
-QD89gnfXaAI9+QINlJVGI3I87T8S8U4Xi9Xubp9/oEcdT8RjMI+mp2fmp2emBvwuk6mcyTKwPz9/fhCL
-Gs2WuZHRofNe74Si8Wh8Pv+DR48nJibYJ6QBug8CZ7xFBJ3kujThag2Y2n2ny9U+tLwgW+CuFpCh5yaL
-CX8HCRvcnLXV1dW11Wg4bFZrETD9bHjUZ7UReyGUcxSPJfP5rXCIfZFNR8kUSXYYenuxKIGgYZdjpq9/
-xO50G03ElaWwDrwgHBZw53ZKYBeHeHJyWio3CVETJO7tkcCrNV9DLxEFj3JHwBsu8vjQ0PToKMSc3tPT
-SLkUTKcC8VgkHqdavlIsNqu1Hug5p6cUpqFASL68z9eHctjFI8q/yxb4uS0gQ89NFj33d4LfffP18xcv
-wpGoQa39YnLq8eDworfPoTdQOAqn8Bu15jCZJKKcOD5eOTokgMOEizr1aqM26HB8NjzzeGjUqje281nE
-d6R51t39HTHWs4hPb6WrVDoFxWAJdUAYVOMDUm/lktPlXpiefjg5KVjOyUyGJstUY/Wq1C6na2hw0O/1
-GnoVx6Vyd/MUX0ZSIdLrFL3yJXHTJSH/7eeygHyd3WRJbuPA4eHKyvKrV68C+wdGhWrU6cTfeTwwSI7c
-qFQBPVDrJjzeTLl0XC6kClmSWeSANEoVXbcGnI75fv/DgZExZx+MYQlrqMnkDVJ0xGhuGsGVfxMRn2r9
-tFiWos3N0260B5UKicFst3scjgMdDbuUc+PjD6amR/okljNrweiB8titUiMWRhed6aEhtDuMKhWl9Hg9
-ZOWgZxNIPmnSTrkBEknZN/klW+AXs4AMPTeZNp1Mff/dX589+3Fja1vdPH06OvpkcPhx/4Dg5rRqORU0
-nPnDzKzeoF0P7UYy6UK1qVFo+qw2qi4XBoemPd4Ri41abzLcpypFD7FhXJ6f464m9N1VLDUbdWSYe/Q6
-QjUQfObHx0WVBpSfp7NzzLbo2yW+IdKoVrvD5y/xq6G359HwyLDVZuxoHMbnbEVUS1bkuemakP/2M1lA
-hp6rDUmiOp1KbWxsLC0t7e7sdlVrPqfzoX9Q+Dttbg4oYtPrF/v9erXCoetFhLBYaaqVmj6LbdTjmfMP
-+q1WnCOVQgnuiHxWZ07q6mPf8lOkBsWbGA+1EmjxkCw3GE77fBRYEaWaHhlxO+xIZIj90U7HabWcNOrm
-nl4EL4ZpK6jRkqqnDg3fR9PTUymVIpHwm7VVSIPU5dN3Aw18AtW8oDLfclDyarIFbmkBGXquNhS48+yH
-75/9+Gxze7terkx4vU8Gh4jvdHKRxZaUI/ChXaOZcTiJ70Av7O3pZcJFP2JohFqlCuGbU+XP6e90jljE
-fbokSnX1RK3u0WtNvb2zA4NM7uizDu60PSzaDfahEt/VXVGpFbW6pYei+zqbaxRKiI5BpXIvEYvGY4eH
-B06nq6/P5/X2ebxeOpRe6FfReXR5WbbAe1tAhp6LphNdqAKBwOvXS2tv1tDRctFV3df/eGBo0Gpr+zvt
-zZQ9vRY1b02XydL+8O1CT+8pEhkt/s7P5u+83bvUZwumD50tTmu1rlq92Wyq1CqnSs20jvj3KZTl85V7
-abPTONH19DaJOvXUJNxhQyZfavWYyw1nUNPdHcqkculMIHecTiToV+Fyu33BfvSbafWMS4WuswoPTvwg
-Hyb35Dq3rfz/e1hAhp6LRmO2Qmh5c30dVWOKMKnbHuvzPR0cfoeVc3Gj63+/I1/5+h399F9E9KeL+oZW
-VWqTSHZnUIk5WLMpeUmoKbYWxB5pzrU4PDzkctKnFF2elcDRdix6lE2TgMcC8AbxnpwOqr48NMOR5NFo
-neNw2ByoFco9uX76pMhrXGcBGXreWqaTtbwGhScShvOCxsWjgaEJMtWGd6o032523dJZVbrEu/lF/J3L
-x22FfqQ8VuvV9nc6V7yctSIszRsReGq7fFa7XqtDFNUcCQdTSYQ+SplMlC4a/BoIms2S9pjVZiNcLaCH
-voB4QrxbnZlxtGh+Qc2YikwZB5UoiO/rGYlzISXbKC3jVWu96sgKNSjg4Iuyf6rtOW6Lty05YxTBcmw5
-N9d5uj/lZRl63p4dweKh2y9dN1eWlyqUQVlt/2V0/IvhUaf+zlLEbRbPLavS347jYywREgI2rGbzomp0
-pM+LSkYsk0FmKJBMRpEHy2XD0dhBICjJo7WAhh/c9rQYpLQCb4gXy0AY5WD4RKI1q1avf2/PSJyLEj0J
-kXHN5TJJaEmIBaEWlKd8DCTCSKh2cFygEH1+etPDrgYc5W4ZH+PyeZ9jytDz1mqCxbO+9mZza4tr3Wk0
-Tff55umAbrNDUH673u2WpPguW92+Kv12u/2l1mK43d3IcfAW2syoZFDkxRSMtoVHicRuNBrPZUu1Wqlc
-AQsIqFfqNaQabVaLnZ7KTmcLeqRqDHwiTas5MqkxCXr0esaMMaAO4adAm6Zq7MpvgZ605OSckLFr0u+0
-QpK/CPYUj7PZTCpJDV06mzvOU6Jbwg1iD+yf41qtAKYZDHJ73Mjdc0SmhHxCcOrKo8gffiIWuPMd9YmM
-+5cYhmDxfP/D97CWtUr1w+HRz0bH3BYLuAOF585H/IBRnjuP7RYbCA1DenjN1gaK5QoKYfFc7jCVohQD
-MILBBJPguFLGFaEpeygaBVNaEy4F3hCzHo7AT5b5vLXcgyQQpacGgzRHu/L4FIsVCsdInSEJQPdUHB/p
-1ZpwUU0mzbmkj6UZF0EraZ8KBcfFD+NFLtFsNHi93rGx8amp6bmFBZcMPVda+ZP58D5DD9ct9Y8wdGit
-ycOT+DGX7QXLdz6N93f3YC3T76VaLvY7nLN9fbNen1Wn5466sNXtfpUe9B8oynO7Ad1pLYSHLLxbPgu3
-OpGgbKE4mE5RjQH0gDtSJ1WUYWEgghmNhtSMrI7lSplGnWr+dtGpOCiwBPRQ+04nZaZqV46EyhN0ZqmS
-B3pu6Cx05bZi/6FgKJWkYWoJVAKmbHa7mPpduYn84ce1wH2GHqGwEw4Gd3d39vcP6EhFP7wL5u5t3RLi
-aUwe/c36Ok2pDOouv90wYbddZvFc2Pw38itzMSJBSPUMq5RIzeMHMeHiXSiXM/l8Ol9IFwtM0BAPSRWL
-iIrhHyVSKSG1IUwktBxRcqSDu5BSu2w68A2nRvJ0WlHkyyvc8InYfyKVpl9YLp8v5FEHST39/Hfwkm7Y
-Sv7TR7TA/YQennj4OLFIZGtrCy9md3f34GC/BT15ZEDVShVEXRjG2F08LUnLIH9DJz+aUnWf1tCkMWtV
-PDEvs3g+4qn6mIduRYKk0LJK1UlewrUh9JIpFtMFCXqOS8VksRgt5BESoeUpJaynTUnqqFoHc6QpEq3K
-qK2/zqMhfZUn3tNiG931y5IRYx7WwMMtU7pfg7TNRM8/OEQQ+r2zbHcdg7z+nSxwP6FHcHOQMf3L119v
-7+xQGSDlSkplcAe3n0TIuLfP3kqWc08xn8qVS8hc4O3z1FVdHQO9k1V/KyszKUOVkXoLu9nMZBapRtjc
-6BmKCRcTMKZpmJ2Oz0ipYZRCtRLJ5fLVq5VVU4U8SiMEs1sTriu5AbcyLEfkMWMhRn50JALPBKRvtaW8
-0ge0wH2DHukZW63i74A7Pz57trS8jGYo9oTyQdSGDLDbahl0OIEeWwdPhxZUVr0+lDblCsVKDSmcaq5c
-Pcxk7IaMHSEJ5dVh0Q94mj7RQzF1kng914xORIhwQ5K5K6CHM4V8dZnerZVKsVZlOa/oVSl6tVLhmF7R
-06tTKHlOKPFPCSMTwxaRfqnrPFRJKfrG3IyMG2G8XA412mI7uoTPm83VpQ7xQalDPG2aZei55hR9zI/v
-G/SI+A7zLPwdcCeVTgvrmnX6+cHBB0PDD0dHB2kFcz7hEn+VXP1KJX2ciyRSG6Gj73c3D1P5r3d3q41T
-SD06iww973ONiggRBahupRIWILsga+X3eMQykBRPpQPJBLBBU0EpaF3I00mRXJXT6fZYrH690W2zWt1u
-qcW0VA3XKmGlJOVcn+i4XA6kMzsHB5JK/8HBhegS6YUIr3C4z+d7n9HL2/zCFrh30FOp0Czh8OBgd2+v
-7e+AOxN9fZ+NjX82PkHRANfylVaVbgZH2mY00J44mT/mcV7lwX19O+MrdyJ/+NYCrQgRlfF4LeJDoEeD
-n0I/DFyhYgG4CaSS/CRaxLoOi2VAiwaJVSpbtTn69QY3RRseF8wdq06nOYMeZbde362Sdiigx4UAY2vv
-tNnoDGyTi4cJBBGRhbdDkpc+GQvcN+ipVCo86Hja8dATRhb+Drjzd7Nzkz4fJUvXGZ+5g8tu02g1PJlp
-IwORBG0wqs+vW1/+/K4WYE6Ep7Mbj70MBRGWDUYiWeJrpycOo2nWPzjmHxjw9zudDoPRoGPWhWYr1GlN
-q1TiKkVHrUrlt1l7msMMg0JY9oaIfXtITOjKxPykBs0XGRXtdeSFj2iB+wY9POJ40PFqP+sseh2SXfg7
-4M51/o44ARLXVqsl0e6120XuhqyJThIM7aY0nBrxj3iefr2HxtPBmMLTYWIVjES3opGlSCiSzTaqNcrh
-3VYzBbpPRsamhoaBHqZXJByvS8B32kHZ26ukPYbDTqEsCbW/mozkK8my82I1EIfcAuhz0pB7w3ea7VNZ
-vm/Q07rgStIFd56jFZXZzLNu8Hcunw2Ru5H00inBIm1bqXZdoiNe3kr+5LIFLns6EBErJ3XC/E/Gx6eG
-hsbHRn0EdJAm0+kJ6YA7TL4u7+e6T4TvM+iw2wx6ItLt7BikZ5KavOV+YdeZ7uN+ft+gh/oguvjyD66g
-sCxl1GSvYOWCJre3tcjdnK1PV+ImHRykJ6ns+9zKhpLnIfWDhrUQTqV2AoHVUPAVCadsBo4PURu/0zHZ
-1/d0bHJ2dHQEpVZrJ1vo7RFgA5HG4nccnOs45cL3sVFtTyZLq4VBJHhDnEFiTLxglL/do7z0yVjgDnfj
-JzPmmwYCx4QgJa/1zS2x3uW+oDdtf+XfWj2zuhD9kn2fK+1z6UNwB0ZPhg5lgaNXB/vPYXXGo4SWqeAa
-Hh6eHRp6PDw85vG4LFaLCWLQtdE3cCdTksSkCTNfBz3i4BAIKdHgDVuabtR8CJOQ4lLKSqkjuzRA+YOP
-b4H7Bj2kcuHOj42NB4Ih+B0k12nO9yZwhFxpH/XVVDRrdbjlkkt/e6+eNRUKaQ6A78N/rWhCNwGF66I/
-Z0o9dznEx78Sfp4RiMhOjlrTTGaHmM7h4VrwaDMcoNjcYbUPDQwuzMw8oFXGwKDPZn0b02lZjJlRudKq
-uYOlUy4THqpQGtbVhTuj8nrPMlzYnJkvfiiB544ziI/T4lqrWRDfBH9HSo3ZbHz+83w3eS8/qwXuG/RA
-HkNLWAQLEHD44ccf6U7zb8uvD5Lxmf6Buf6Bef8ArEIqku4UUJBsLnwfhQKH/pSrv3Eioc9Vr1+XUs9V
-3+D9PxORHbD+zxtra8FALIu8Rpn+q/MD/V8+/nJufGrA3SLq6CAMvo3pYLFmby/EQgrieWbs8wqG9uIx
-WA59fX0L4+O0TrWL1hpIwSLD2Dxps3uuGyvQw4OGFwvXrSN//hEtcN+gR1xwXQMD+PyULxMsQOccruxB
-NlM7aVJwlCvkSWDhHNGMHEV06LN0nyIMhDIGCncstB+bF89Ky/eR+mfxyMX3wekh9XWV7yOB2q9Iqefi
-93zP36EjQw4MtSI7L/d2v9lcJ7KjVGtogzHutS9OTHz58OH44Mhbho7wdIjm1Os4OIlCIZxMHgSDh0dH
-R4eHoUQiViyigghSSXG7toPT8nqAqi6V5IDe8GKeReU6EmKy13ODlT7in+4b9AhTCt9HbzD0D/i5jvd3
-d0NHR+FIeD8a+WZj3aw3EANAiIdODA693qSTgtDEKYlGE3i4Tk1G7BlYwWM67eqWyLmEFK70fX7lSj3v
-dzmCO0v7+4AOkR1KseBkagyGifHxh5MTX02NT/b77Va7kb465wwd4elUm81cubwbCPx1dXVtdzcQDmez
-2ZN6TavXDQ0PTw8PfzU1PTMw4DjvJnb7sRHrQbeQNzmH228lr/nBLHA/oUf4PsQvnU6nx+02m+gQ0wvf
-LJQNUaUFfcdJl06LxWcyec0Wt9nitVqrVhti6ZpeherdrnicCUnhtB1ZAHskp4aVWtMtfJ+Oh6/kDvGA
-bvWf+Jv6i36w8/83HkhKZJ0WKqVoNr0VDj/b2nl9sL8WCBRrNRyO0cHBh/MLT6amaJ0ISVk6VMvTAXQw
-abVxguBGNJWi1HNte/uvKytHkQjhHpLlPofH5/EMD49MDw0vnEeFbh4pXAqozLwJNnGueX4QwGYMSKYi
-6XrztvJfP4oF7if0CFNyCaLUS5qDX6miRrgH4hkZEEoWqfcpo/aQSSfM5kGHi4wv6+DY2xQqfSuN/s7J
-UPZ28+TsyM1L907b9znpyN0yW/vb+qm/c9xP/hdwh0xWOBH7X9TqIk0SSSeOC3SaH/C6v3z46NH0NLSd
-AacLzo74KsLT6SbQplQcZ3NrR4ev1tZ+fPmKOqxULmcw6GcmJ+dGRxfpB+906vUGnFCqtzqjQteZhBgT
-Yj2cVhbAHR4tqKWaTWYuAC6D67aSP/+IFrjP0ANAtFQ7e+GzQm5G+g7GB+kpwjn0IbbrdE6jwWM0uZht
-aTQGhVKNfwOLpAVDnaeEG4zMuuTcXOn79Epzr7MXkSAQ6jzJcv7pPfy/JevVYJIVSSZf7m99s/5mLXCU
-Lze0Gt10/+D8xOTvHz6Es+Oz2020/eKFq4j1enro7o5oRiKe2zkKPF9bfbGy+mplJZZIEM6h1c7M0PBX
-CwsLg4O4oldbrbUfya/EFW298Hc4t+iiIOEqarhg9/T7fP7+fkJFQp716l3Jn35UC9xn6BGGRVFheWnp
-2bNnFJSKpyJKPVSxz/X5Zt0ev8Vq0ukMag1+Pm9aiV5xOqSsSrWVVbnC93knxQ7acW/8Bl7AODF7Mln/
-+vrli72dg0SsXG0YtYrZEf8/f/n3DydncTosJqO2ragh5Qc1XQBM4yQaT/zrX797trK6c3gYjpEEy53p
-KJlMs76+KY/XqNFea8LWfqTy0XNfBtzJwKFIvS2dIcY3ymtsDLmMa/cj/+FjW+A+Q4/QKqSL5traGt3T
-k+mUimQtYj0ez5OR0QWff6rVXYvc1s10Nc6RpEPOm/By5wn7zQBN55cWzJ1ELkurnB93tr/d3KActEeh
-dDpcEz7n5zMzX84vTgyNSJyd3l5mWCKyQ5mVxO08LiK5//LN2tc/Plva3GzLXJh02n67fdzrHeKMmM1s
-23nEs2WRETttSp0qcHHKZTwap81GlW8snYqnmWpVOSGgmNFooBC1398vCzNfYcZP5qP7DD1Cq1D0EQ2E
-Qs1GfdDp/LvJ6YcDQ2MOp9dkMqqRSf3pbhPS/UNPGyIU507+J3P6PsJABHNn9ejgP9ZWYCofJhLgjt/n
-Wxgb/Ye52YWRUZ/HK6IznZEdHgO0rljb2vrXb79+sbZ2EI6msll2Jb6AVW98PDpOXQX85usiO2JviNhG
-UsmjWGw3HIa39cenTxESQ6med6laE94TrSlojCPntj7CxXGXQ95P6CE6QwiACvaN9Terqys4PieVKrjz
-aGjoi7Hx+b5+J92hrny0XmU7aQ712+PpXLYEk6xitQr75s3BwfOd7R+3t48yKXCn3+N5PD39+czs06np
-Qbfrrb/DnEipJIBfQ0QplUIi+8fXr795/nxjf7/dc0Jko7xOx+L4BLEh0lKXeVWUU5RpVlGpZsrlWDod
-CIf4mS2VwDupbVezGYzFAjFmfBW1Sk0ZKWU06KLKua3LZ/CT+uR+Qg+4g1cu+oguvX5FCzm30YS/A+7M
-0DtcpyeZdYfT8Jvk6Vy2D7hzEIu93N35j6Wl1aNDmDuU6nL/gzv//Pnn+Duwbzr9HXCnR6WslUqhSGR5
-ff1PP3y/tL5+GImCO+2eEyIbNeQfmJqaGBkZvrKeC9yRmIrB0NLOzn4omEgmUDxdnJ4Z7eszaLXJbDYY
-CvOmNyGbk5IfGxunEaCc27p8Bj+pT+4n9FTpLSFpFR5KoeV43KhSE99hnnUHf0cEKfB3flM8nWuuTeHv
-HMRjz3d2vt/aeLm/F8ll9QRoWv7OF3PziyOjg263tHXLbqfn/g6aFSh4La+sPFt6/SMypsFg298RhzLq
-9RNDQ3MT4wM+3+X69Uq1ShA6EI+/CQTWj442Dw9pe2zQarxu99jg4KDHo+npKR4fowwXS8ThT9httlE0
-OMbGLUzcOsgQ13wt+eOPaYH7CT2kWumBs7m5mUxl1ArVrN9PXJn4zu39nXZ85zfF07nuShT+DrhDPmvl
-UPJ3wJ1BrDozg78D7lCXK7YVERnh74A726HQ85WVP/35z2ubG6mM1Gqi7e+I9Wll8cX8/O8WFuyWK7Lp
-4M6r1bUXGxs/bm9Fczk0CyeGh//p91/NTUzQ3tigUikaJ4VkOh6P0wQVZROH3To5OTk2Pi7ntq47lZ/O
-5/cNekSUhxnW7s723s4uGGTRame8PvJZxJVvFd8RzBFFi6HTii7/Fng6112RF/wdcEf4O4M+H7hzwd8h
-4d3NW9FbO+0Cd/Yj4WcrK399+fLV+rrQye48Cj1C0K4d8XpnEdDo72fqJP4qNHrydBPMpLb3939YWnm5
-ucVx4fIsTE3NjI0+WViYGh1l5eJxPpYIHUUjyUyGKbbTbvNB5/H7pbIvuetxp60/yeX7Bj0iypNKJnd2
-to8O90/qVcoX4e+QRyefdatTIDFH1F2CtPabTJ93Wun2/o6EO9zwSqlrTTFfwN8Bd/4Nf2d9vd0XpHPP
-QjP78fDIkNNJTWm7tkto9Gwf7n/38q/LGxu7wUQYpnOpODowIPlH8ws4SmI/mVLx1eEhb0LOcpSn07a/
-iuX7Bj21ajWdTETCoXA4DJnQoFZ7zBZ4g26DkTz6tafkQmRHpegsm7h2q3v9hzv5O8yz8HfAHfJZ+dJb
-fwfcuezvCPaN3WxaoGZifNxtsQotHuHvxDKZzcDRy/XVr1+92tzfT+WrJ6e98JKHBgZmJyfHh4YMSIvh
-3J6e0uB4/WCfABC9KBDHkKM8v67r8fq78df1Pc5HWy4Vg4eHR/sHGSb/p91us7XfZoevfDN/R47snNvv
-7f+393dEfId5Fv4OuLMZCD5bXr7B3xHsG7fdujg9PT85aT6vShf+DrjzP//ylxdvVkOxaDZfrdabhJ+n
-JycX56GgD1pbIhjStLpez2eze7s7wrd12P1ylOftyfs1LN036CmVysFAEMkXKnp4lg673GMeL8qEN/OV
-z5g7wtn5pSuwWk/sd8ovxIUiJnefQB2GqM9KZLMrhwfPd7dXj45uiO9IqC3yWd3dhWoVst/z1VXiO1f6
-O+KL6rU66kunKXUYHPC4nOTjO/2d71dWqO0S3B9i0uAUEejFqakHMzMel0sQlOl0RIetQCQSCkeKpRL6
-BCg8Dw6RZJOjPL8G1GmN8b5BDxdlMBwSLI8+o3HOPzDnH/zpXlofkLkD8lDtLVVmvPvqlqre766d+O5O
-fpbfmGpRn3UQj36/tf5idztTzN8mn0X1fyiTXdrZ/c9vvnnd0ff18pDsVgt17dSXUucleEA1hJwld0ny
-d8CdNvdH+Edeu+3p9NTjyUnruX8klY/t7y/v7sUzWQ19ZRcWHz1+4vH0yVyey9b+ZD+5P9AjOeEnJ6S0
-wtEYrLOe04bDoBuy2wn0aKVeWte8RJSH9hVMFz6Iv0Nvr9N6o+vkIvRIebTmaRc5NZyIj+T7nPk7udxW
-OEgqHX8nlE6edjW9duejyckL+ay2v9Ps6a7X6olUcnl7G/7Om42Ny/EdYX0IhFQ/oOODnkaLu2xE6RHc
-EfGdTn9HdJXQa/X4RzOjIxODgz6XsxcCestnzB0fr+1sb+zvVuoIAzmmp2cQFEOGWebyXHOVf4ofX39P
-foqjvWlMIreVO87F4vHj46xB3eU2aRxqlRH90+vv5HaU5wPUZ535O/VGd61BHfyFL4PM2Gm9W8qsvasN
-dGG1X/RX4e+AO//vy+fPdnaoz2qeNq165VS/6/94tPh0Zv5K/g64A5the2vrz3/6zx+XV1Kpty1AL4wW
-3CFqg34YOj7oaVDX3hnf6fR3xIZn/tHjJy6nhDtMSaUHDOVg6fT6+vre/j4ZeuhFEHkQ5Eaa8sLh5F8/
-ZQvcH+ip12u5XDaVSmePj6lmNpnNdohlNE6/2ZehFF0SkXmnIv2XOmGSrjB6QLg8J92XJlzSQUWbr55e
-SfaZIX3I6E/Lm4BNsx0OvNrbfgEtKhICd5xmw8xQP/XoCwRTLvGVCS0zyONCfm1z68dXr5ZWVvYPpPqs
-ywYUtVp9Lhf+DrqF6Ifp1Rpw5zp/B51JZnkDvv6Hs3Mktixms/BJiezEYvHNvb1dmM2FwujI6Pj4ONLx
-ZLguH1T+5FO2wP2BnmqlSs0E72q1quxVmbQWs9ai7L1KfuFjnZDmafeNrSykcQltoEb9tFWw+sGiP8Ij
-i2dS3268RgcjmEoKfwfc+Zc//MPTmQWPTRJ75CXyWYKvLJVNnJygg0E9OnWh7RiNWLPzp6jVmhgY+D3Q
-MzqKbuHN/o6ILk1PTEyMj6H71Za/oGLr69evvn75MhhPqLX6mbn5+YUF81VM6M6jy8ufoAXuD/QgGYVe
-VDqVgtqDH+4wWXlTRfETRse/wAEhldLT/KBeRsewGs1mtdVjk6JWFBTpM3Xa7DkFpwj9fKjoTwnR2HQG
-6a9XB3ub4VC+UkfCfWLI93hm9tH0PJ0kiAefDRlfDFhUKoBFKqogUKG/gw5GZz16x5eT1MHUyh6vzTw3
-NvbZ9PQ0bGOL5QZ/h923s1qP5mYpTzWZTOyQTcq1GvVcL9+8ebO722ie9lPJNT4+NDKCDEHnEeXlX4UF
-7g/0oAgDh5AXCxqVus9m543w4M2nQepmwySIe5zKx67TX9bL6EH3RwGmXOhjAe4kSkXGSYmZBD2MpDWq
-bgDxQ0V/0oXC9ztb321sbIVTmWKdjJ/P7fnD06++WFhwO90iDyUsSVBM0idtRV5iyeT/+ubbr3/8Ef2d
-y/VZYn1wx25Uzwx6/vvvnj6ZXXBbrTf7OyKr1e9y/vHRo68ePHScezQS7qQzm8HQ+u5uIplyOuwUiiIJ
-RpE6zSfEseSfvyIL3B/okYQy07A9MkCPQamy6Q28b2Iwi7N0eiqFLlkmQCF5QL9kjoloN2UGuDPn6S2E
-ouunp8lScS0SKlUrXqMecQ+XwYJgq9R5ivcvH/05Yy0n4i/2dl8fHEQzxzTyJK+0MDH5YGp2YnAUasKZ
-hg7jIQ8I6CgUEA4T6TRKg98vveYnul8iJ9V56Qv/xWI0Tg77CPE8pLDT5yPok8ofbwUP4SvDG7zsK1ES
-QRX7LFmr8YlBX5+U1Wq98hSjHhys7+xEY3EGMjIywioQeeTocqfNf0XL9wh6qtUkr0SCWI9CpaZSVK+g
-lURHu4jrT8uH8TK4FfGqpL7J+DKtBBe4kz9p7GXT/7GxFkhGbXrVjLfvHycWxxxeQBNysDTkXzj6I1jL
-a4eHpNL3YjF+7fd6JN7Ngwdjfb7O6ipRpSV0kROx2J+fPfv2+XOwQCheX7au8F86vSdwh0RkLBH79tm3
-3y4vw1e+7CuRLP/iq6+++uwzl9cjslpiz+QQVpaX36yuVMtFEOfBwwcLi4tydPmy2X8tn9wf6EEzuES5
-dKl00mhQi2hRq80aTbso8SfOR8v3kdaR5l5doqsESCH5HT/jiz2yQ7JCSpoItjwsdo/oM1jEnKtYCGQK
-mWJRq9CXayc+q83SkjTrjP5IrBbmhXQB+znG1slapn8WqfRSrWbRG8b7fI8np+bHxlxWy1mn8zP2kzTy
-Ck37IP4cHPy4tPRydRVdd9EH4rKd0OIZ9vU9npl7ND0nvKdKvR5Jplb39l4haLK/T51Ep6+kUavJZE2O
-jj6ZX5idnGpntaS+pvn8/lFgY3MzGotZLZbxMeTAxn39/XAILx9X/uRXYYH7Az2d5iZeS9zk9uo8nduC
-BHRVJ7f9S8V9pApvqbMFR+lt1I1dXYNmy+/GJkgewx5eCcRypRc4En8/PYvWx4Xoz88bk7rMWhbV5J+N
-T8z4/YJ3IywjslqiSgs638r29vdLS8tv3tC9r1gqv2O9jl/cdsc/ffn73z9YnPQPCO8pmk5/t7H+zera
-VihBXSj1WR2rd4E1D+fnv3z8eG542G+ztuN04A5HhPVDBwv0fhYXZ2XucqfdfqXL9xN68BR0yms62/zU
-iaKf6Hn/Cck1+flfkuPT6tXVI6VyGKrTZJ7r81frjXg2tx4K7uB91BsatYbM14TT7WnJDNHe4eeMSXWw
-eJYPdklsCdZyn938aHLi8dSU3+Vq989qs5ZPurtrlSqhlpcrq8+Xlg8CwWzu+Er76NRqh9E0NzT0lALR
-sXFwp+e06zh3zCYvNtaXtnei6Vyp+pZUKVg8Q/7+J4sLT+bnBtwcXXJnmJ0RwhNHXN7YpEKdNuoQl2Xu
-8pVm/3V9eD+h59M/B8yYpLhPq/BS39MzxIhb+XWLwfBXiVaT/s/11UTh+Hhiav60H7fIopbEpH+umNR1
-LJ7RfufnD+Yfzs7igAgbdrJ4BGsZDvEPL17Qtw8JQbHO5Z/gzlfT07+fmx/zeIS/A+7s7e2vrq29Wd+8
-7CsJFs/CzMzvFhfnx8fbteyix5Y44tbhIQ2sIUNPkqCXucuXjf5r++R+Qg/+QqleK9brZ0yZu5wVAjxS
-ORXvnzfQc2EMUtinFUjq7VJRPtHVNcQKvb3VRmMnFksWi/vJRA3Sc6+ixuyv/7TLSj2D1NpKQh9e55kv
-aRd3qvliczTz6e5QyO9EwkuHBxuhYLZYNej044P9yACODw9TIC4dQrwYJRDZwVp+sby8tbsbjcfP13jn
-fxGvmRoe/nxu/uHEpMdqI9xGJCuezazs7rze3DwKhzt9pbOOFC73w5mZp/Pz6DS77XZpjy2/jKDS2ubm
-q5XlPYkkXVsYmp+dne3v75ejy+8Y/df5y/2EHsGUgSzTjpXc4ex8wCr2s1G1oj+w4oa6ulLHLuoVYqUC
-YsP0lipWaunj1qSmp7vt+5xtdU1P1J/4pq2tsunMcjj4Yu9gL5YRMZchq/3Lx19++fCh3dq688/3Ilg8
-yGK0Wct/efYsdn2VlojXfDE392h2dsTXT6ZcsHj24vG/bm2IOvjzfUv/C5bz9MjIf/ns86cLC20WD8hD
-rZbgSX/38mUun+vzD8hZrU7T/dqX7w/0oFQFqxWWR69CUW3UY4V8LJ83XdXLWJpunJ7iGdVbhVRKxCog
-rvB4p5iLn79wFbvIK6FQw6WDipCSHoR4WAqFCnHRrq4Bh+OBf5BGd0tEVdKpfLnCaE2Crdvh+0iXHf4L
-vGcWfrLmq+VBSOsTQYf1BCXnOLcWDKwEA7FsHg1AtLiGBgbnxqdgLUNilnbOC6fsnMVzXC63Wcvktq6s
-0hLxGqHZ/GR2dtjvp6kWR6ZKa+3w4BkN0Q72j5KJ9rYtS3dbTcap4aGH0+TAxjtZPEVabsXiq9tb6DrT
-Y8tms8lZLXFa7s3P+wM9KkKbvJzOUDRaJomby0WOs/1w8C+lX8EdhBqYjuVqVU6kuUUCEjKGH6DLqMgr
-MX3g0BqVCljhyS9dTy3fx2W3/8PYuKbZzGTT2cIxNyrtH75dX0ehRlrnOt/nxpovCWpF7ViDhjH141ot
-XMy/CQe3I+F8pSKqyYmzDLjd17F4bsNaPovXTE5+Pjk57/dDROS4HI/T8b+++ea75aULFV5nrB+n46vF
-B188WHQ5HJ0sns5aLVmRRzr19+51j6BHpUKxxWq18vgtFQoHqUS/1TrlcJ4YjJJH0wqsiGqpbKkYyqRT
-pUKxUdNrNKN2BKvMMPh6hUphK67xS5xowRvGC9iLRsqVKjcnxBkVtfUCehihQmHQ60Ydzmw222+1BahI
-a+aprjqqJhi/zWRSKXrV3T1KS+/bGJbwfTpqvk5bpRiSzyLK8eFnE8BGJKiFPvlSYSeTWAsf7cWjqXyu
-p6fpdVgeTU0ix+Oxnmkks23L++tk8Ryi8X4da/ksXuN0PZqaosZ9wuej9ScGLBSL0Xjizfb26/X1y6xl
-KkJ9HvfUxMTC9PT40DAIKGrTBYsH34ojootBtIsyrjl0NmRFnl/iovx4+7w/0APiEH3kxUK6UuGR7tTp
-PusfqFlsbWawiAG9iYT+tL4WyMRVyq5Rt0en1ZqtVq1G3a3mvj6XqvgFTongDb/a2/vT6jKAMj8w+HBk
-hP4K5o7qRwJNjBYxaSSl+9LpYqVKK3HGglQggZLTk4ZJRaN41YUY1juZL8LkvIhHEx5m2gTinDSlStQW
-bRK4+XZz+dud7XZt+rjX/tXU+NNWNbm04XlteieLR3BqrmMti3jNzMjwPz1+giBGW9Mnlc1B//nu1etw
-QppnXejARZe+xQcPnz55Mjw6IhSXxdEFi0fwhjLZ7IDfD2t5dg6xSVmRR1jonvy8P9BD6yWX2+3xeOhY
-EG6eEM7gwb4aPtSqet0mq6pXWahW4pBiM6nNWGQnBXO34tMbDQa9WqtRqNW06KUq8uqz2o6VtP8s3KiW
-J9X+7CcXCpUK2auVwOF66FDR00tjQrVSdaHUA9jgE51KRX7aJnXROJPdknyfZEIFVdJg4uC0b/YYzZ2+
-TzvzJYZxeiLVvkvLjTNtoEbzhDlmIJtZDQZEVguN5CGfd2Z4GPpyn832dvwcQKHoZPG8WLmatcykqV2V
-Ts/1tqZPrVYvFouHweDLjfXl3Z1U7riTtQxUSVqFQ0OPELygDutccbmG0nu5vBsM0qf09doaSKfR6sbG
-x+Ss1ttTc4+WrrnZfoXfkAAzD0b6HVstZppB1RsnR6nkv2+8TpazT4emtUrNdjy2FY2sh0OVRoPJxZPR
-sUdjI6Mer8NoMWi0hHuv+9IiVtKppszU4D24zvlqZTMe3c8kVKrTYaft6cTY4vBwp8vTHkBvTy8zQd4K
-Yt6tFy4DjoPg+2RLBT5DYOOC79PenAXhB50ttP4A7hzmslupdCBVEFmtPrdlcebB4sxDi+mdzp8iq0VS
-H+3Bm1k8l6vSxRjAnb29/ZX19ZW9fVEXJj4XP0V06enDh0+mpyf9/cbzYghwh24WP6ytff3Dj/uHB4pe
-xfDgILgjdxPttN69Wb72fvvVfUMx4fL29aEuhWrPUSiULhZWQ/Vyo15r9GpU2v1EPEwQpVh0mExT/X6g
-hzsfDYerv2mL/3LmOJCNglzTykmdrUw85e417uSzKA7wWiz9Zs2Exzvp871zdOFbSUe5gkXNHwnXEKWq
-NGpk41wmo0bRo3L3aXpN7UjWO1+kXZXWosgQWadhHvXxK6FQNFeoN3uMRn2/1zszOjk+OCx1thLeE80m
-AABAAElEQVQv/LjzrFaxUNg+OFzd2NjZ37/M4sExwuXprEof7+9HW0P0lhAsnldbW4exGFVp7YFxjkQ0
-GtbyZwvzo/0+e0uLR7CWUbZdXn/zcmVl92AfMuHszOgC64yOyX0m2ga8Twv3B3rEWSHH9eWXv+/u6S3+
-x/8+PDzg8V6pxcPpslqhrJ+e2Aymx6NjcwODgM6Qy3Wlx3F2dlv8F8o6W7+2VLs6EIGA0Hso6dj1hi9G
-Rue9XpNOYzcaPe8yaIRv1ZofnZ4wOapUeHfOUxiJ8H0imfSP+296umsOrdaqkVqMndW4nw394n8ioxfL
-Zn/c2UL5tN1hYmp0bMLP3S9pJJ9tI2XZNKI2nZaf368s/3VlhYWLe8Tn6unWqJSdVelC00f0lriOxSNw
-5+Hc7N8/fUp/G9s5Z1qwlvd39579+MPK2lqlVOz3+ylff/zkqagRJZJ9eQzyJ79qC9w36DEYjRNTU6j2
-bm5ukSCiuDGZL2WKZRQ5B53OiT7v0/Hx+UE4s25L+1F/4QQKf6fWIAMPcab9x1bwtv1bi0/Mb0zTWpSg
-21CfaYU65nKz0duEesf+WjydVh7q9JR6rlQ+ny7ka4268C8o6TIZjYAI5Qt0Ad6JNgwq9bDVq1fpvGbz
-zT2dmWAmCvn9VHI7GgmkkkxFPTb75PAwPSH6HM6zWi0xklaWTdSm7x4Flje3yDQhRdg5TLF8uSpdaPoU
-yuWdYHB5d/fN0WEni6eTtfz5wsLM6KivxZlu+zsbW1uimwWzPI/bPYck89zcyOgotelyn4nL9r8Hn9w3
-6EGwDtk6xOuQsMtm0pQL0R6H5zO4888PHj0ZGxtyeZwWi/4GXTvh74A7raKqm87xHWvcCScJcuDVcaUO
-5WZ6vISz6XAmzYLwLzxOB+VLOEEUT9HqB29uJ5b5zrDf1a34Sjl2M/Tg+W0k4muxaCJfAHcIhLltlofj
-4/QdvtLv66wUvy6rdbkqXRgKzbDvl5e/XXodSiQ7s1oiC3aZtSz8HXDnf/7pP5+vrMD9sdrtn3/x5dPP
-PvP1++W+Wjddfr/yv9036JEuZbQK02mSLOLUoPgH7jwcGv5sbHxhaPhqj0OsKqItok9Wh79z3SmWVm80
-pHz87aYD+AVnFJ72HsURWzxjqVNFA+pfnXhwvFigoU+mWGD+IlT7UEdfXFisVWtUb7M1vg9dgVeCQZ1K
-4291dhYVXu0diwV2LzlK5dJGLMKbsAvBabvNBud4wu+nYoNI9tkmrSgPtVpsgl+1urmx9OYNIZ7LWjyX
-q9KFpg8tAHOl0m4kQjeuDRpPH+fFbFH4O/SimJuY+N2DB8yzBGu509/5/tUrCXeiUb3ROD4+sbD4QGbx
-XDiV9+/X+wY9BJif/fD98+cvXr1+HQhKajKDNvvfTU5TSD1KkEWvv9rjaJ1Y6UZt8e4kFswtXmdsGqAH
-Ec/3ikW8PaJ0XNTppfw3eai9TCZdLAmvQaj2PX70aHh4BC00xqXTaPB90uk0ySNaypCkY/pzscKrNX4R
-5UF3efOcu6w3GNjPxNiEz+m6zF2mVos6D9Hlan1z8zifv2yGy1XpYh1wZyUQeL67w4Sr01cS/g648z/+
-8R+fzM/3ec60B1Hvz6TSnf4OuPP0CUSfJ/ShkBWXL1v+nn1yf6CnWqnwuN7Z3n758uXSkoQ75VLZSkG2
-t+/RyOjcwJDTbLnodJyfTMEzLlPQXakqT0+tCqWGwqiffIksEpBRF7VU53TEm/k+4A1ujvB0OnjG4A5I
-IfJQpKLSxSK/M9sym01o8uEFwFriOzZw5xr1aCIBLhxXKofJ5OvgkUGjNimVRqXqQrZLRHkO0yl4BhCd
-iF5bTSaIPHMjIy7LuQKh+JoiykNUKJXaDQT2jgLReAzs67SB8Hfmh4epDhVV6cLfaX2h00z+eG13Z3lr
-i7EJX6nT3/ny0SNwZ3x4iGoJCRCrVfJZ4I7wd/ZDYaVaMzA4tPjgAVwft9crKy53Wv5eLt8f6JGmCcvL
-z1+8WF5ZFYow4M784OCT8fExv99lt12HO5xXwTNGQy9XLJpVqkW3V2NAPvB2L1FBfmMVVeeOuFHbFVWd
-POOTVmVZZx5KRHkMOi1EGL1BT7RVaTSOTU1BL9za2cXrASYEy1nVdTpisnj0UBDfyXZdjvJ4LObHw8MP
-BgYt7TLRjsFl8vkXm5vP1jciqXRnpEasIvwdcOezxcUhv5+ZoPicb0StViadWdtY7/SVbu/vgDsT4+OP
-HtLvT2Ytd5yPe714T6Ann89Ho9Fl6oxevz4KBHLHee5bh8n4YGgYl4f8sf6ct3bhbHIb0yDhIB5HFz2T
-L/AYV1qtlHpdWO2mX/Ff3u2cxbTlrH7q8mZM5To8HdGDlFu3RoSlUopkksuhg/VQoDM3VKlU4hRxx2LQ
-tc1mi02tJoiOYBa9N4j7MDNjZZtWt+lDVd7QznZJAHchytPTixwiYa8Rl8tnw7F721eLii0pQ3fazOSy
-y0R5NjYudJjo9HeezMyCOxS7t78cw0BxeePocO/oSPhKt/d34C73KJT+vj6qJR4sLvqpOz3PuLf3Ly/c
-SwvcE+iJBIMH+/tLy8s8dYEh4S+4rZaHo6PXMYbF6QR3vltff76zTT8Gyhf+cXrWa7Jo27flrc/5O1VU
-vT1Svy1iQO++pDY4xHQ6KqrE30Vfit1s8uvN18/3dpkctT0OFtCs+fbbb08aJ3q9AehhEzQLmZWggB+M
-cMunWIcy/R8PD1RKZTvbdTnKY9RomHtO9vVbjCbBwRFHFzqEFJ12Q19OZ6j0FDbsHPt1/o5YJ5nPS4rL
-b94Ek9JgmCdSEOe0228T35Fwx+dbmJ/7/PPPp2dmZNzpNPv9Xr4n0HN0dBQ4gsAc4lbkhKlVSopCKfX2
-OezvMIZbJ1Mo5hQqUH6ybwKB7zbeUNJJyLbPai21ZDTe55S32cPoB4r6KVFB3rEvqRTjvKJKwFK9VVdF
-Hy5Cy/g73+/t0vkzV6mTleNuR9+PurNm/WR/Z9eEfvMiE0Ev7AFkiYZGRhLJpPPly3A4XKXtaqGwFg6i
-ZzzqcNkNRmq7UDuEyyOiPPFclvSTx2ajY97owIDJYBAcnLOhtSq2KicnzFgDkUgwHBY2FHwi6rzsVsv8
-4PCXC4toNl/wdwR3mVr81zvbyzs7qJpB5jQbtH1u9/TY2O8WHzxZmB8fujq+s310dNrVQ7v0+bn5R48e
-US1BMKvDWh9zkewbLZX4ySAInzHVRQQKVw6bfMxh3a9j3xPo2d/bi0Qi5fJZdwSlFBWBgmciPHL5fAnF
-nO1I4Lut5Vf7e1uhZIQgT7V6s8rP5f1c98lZ/VT3W9nzszVpZMPsrOMl8lmrkRCdP9+EAlST03GY4vVB
-h5OsHMVNlJui/hHKZEORSDgU8vl8IvXDzz5+8XrDrXQSgwc6LVodQRzix9R2dUZ5hCdCaGZoeHhoZJiw
-UccQukTFVrFcenN4uLa/fyYMdM5XphcgPbmeTs8sDg2jFd+O74g9CAXCUDK5s38g4muCr/xobu6//v73
-i5OT7nMVnsv5LHDHZrVMjo///u/+jtkWeu+do/q4y+BOKpkst/KJStTmkDLR6WVy4897Uu4J9BD4YJ7V
-OCfjMN2AVFKt1QulEnp3xDt5doE4ODXHpVIidxxJp7ajweVgYC+ZiB0f5ytlpgmFSnUnHrPp9HaNlgcc
-PD0NEoI86e76rGt7QO+eK+IvxJLxdMoIldWq+XIhfJyjnpO6KuobRHyHY+k1CrNeh6C6WavLsU42Wa1W
-KMjkfiCai+vE45cEkN1uHxwYiITDzLyS5TIMoEA6uR4J2A1arae/WKvsp6J7ySg5bxCPGRBSRj6vB91l
-5JPfHRfyjL35Uml9d+fNzvZxocAYmLGSCxv0eoAPegHSk4t42Tu859YuKtUq3J9AKMxPeAwS7lAct7Dw
-xYMHCABBO4RJFEmlGHkum41Gokvr61SlC51DdIrAYarV4SgFQ8FwJMxpYlIpXtier0mcC7YElILGCfG3
-d1C7/RUQPGITIVDJBXCn9fH+GBtPLArW6OBGAhH6OE5xsVAEeviEo7B/AFerh9KgxZXG8vzKMNEbwgNl
-DzhH5VIJn5GfN4yzPeD2gqQQpVYroXjS71Wl0ur0fGW+AuPBXNi2vebfsiCOwrCxEl+tPU72iS+Hndvf
-haP/LQe667b3BHoufG3mIGR/CIUEI1G/yUJ6ixPA8zyQTBDTeRMMbIXD+XpVj4SnzZMrAVINXAMKFFYO
-D9mWveGPTDldbkm24p2c0YUD3elXEX/JVisRVN9T0fXQ7m48Rh059ZwkqoRvwsHa+6yf1HLl7HE5ywIO
-f+uKl/JcYgWupNGxsUQiIUV80mk+lLJdhxta5Wm/0YxERjgT5V2uV0Smqc/ppF7/HS5P+0hdXaTq1zel
-KA8LIlIG7vy33//hs7k5epAiafa2zqtjK27Rg719omwg41ld6MLC//nHP86PjFgUqlgo9OrwcC8STiaS
-KAogVwhCoessvqk4R6+WlnDoTGYTjHPCQ0PDIyN8q/FxSkbxMgRLq7V/ZP6l83L5hT4cW+DQoVtQyOdh
-dd1+fZIKQAye4+7uDhP2WCyaPZaUIasMrj3h6ukRsy3uTLoPDvr9w8NDFLX29ffjewIZlXIZh3SZLwKP
-rHjtOC+PHAyj5BDnHAEmm93WPzio0ekwaTAQoM8qiYXLm7zHJ+IoPr8fq/Loao+TXaEnzCS3/V0+MKHh
-nkAP9xR1WzzPeYLgv/AggloSTiZf7u7SlVRAD4nzaDZLp4dw/rhIMMhuHR4aApIcrhAck2QqwwNBUnuI
-x7RqVbFaSWSzfWYqxFWEb6XONT0KnCCElNunXygr8wkKOzhH7c+BmBMS6Gg/w01mKM2T+gkLdfT3AJhM
-uRIrl8KFzFE2nT5pdJlNNqPZ3GhQ8JFKJXnwEkDJFUs70ahK0R1MJwu1KleP3WY1mdE11HMbiAPxIfcb
-t/Tr5WXxrRnzbizmMpjiw3li3PHjnKgC02kMSD4Pu9ykwM66ibbHSvfTk5N6uUxJPxCQSMa7u5oem3kI
-MtTM3JcLC7OjY6DV5a3EDpim7QUCRIiIWwt/h6mW1+Xizl3d24cf1IKeCN2oU+kUQve4b2hAalVtG9bz
-uRSCkfhZPPvtNjvgRAyLMq7BoUGPpw+wev16af3NmnRL198hGbW/AQpNuJOACA/wVCp1y/U5IjvkTIE4
-QNXu7m4wcBSNRY+Pj6k1YYeMszNPwEVFw0JYDpFQsAWhCe5kqI/UDOaPYZPtvHrJtbZzwzjbA24vcKuj
-59uCHiUYFInHDAYjqMeQnj9/ThSvvebfssD+mZtzbdcgrVWrr16+ANqgxbNP9DFBz0QiOTk1NTc/D9uW
-2eXfcqw7bXtPoIeHJc6kxWyMqZQ8tbh4sEIsl/vXlaUf9nZAD+lSO2mg8Gdx2PuGhr6YItXjt9ttfJ7N
-ZIhP04l3d3tnf3+PK2ktEDiIxb5Ra6x6jdOkMeh03Uq9UWPwGoyGjnODNwEYEBKmubvyXFiH45LjKTbq
-RIiZ7OTL6FxUmFvhvxAMThxXitUGamBao8HucS3S5XN4hH0AeVy4f/3224PDA0ZPD+L/r1IF5XBkkDHz
-evtGhoYYbWdNExduW58Il0F6Vteb1HaFM8VQLg8YpYu1QlVqpMrMcdLlmXS5jXQ9vfSi9CSbz+OYHBeK
-FKXRc2d+1P/PX/79o+l533kXrUsbnX3ARHU7GgodZ+yUmE1M4O+AO5Fk8i+7ey9fvSLXnmXCC1ETD4KK
-k66mSa82qFHCf7s/qkcYZKV2wrcGn0qVKnHutdWV0ZERWoxyJ+OIbfH84Ixew3ggQ+dLJCyRCDsFFG65
-Pg+Rg/29VDq9vbMbiUbB/XIZkkCFowCCGlXvhXGWqyfYlkklIS3GyVGQqc8fH7tcTghW29s7a+vrZDpu
-GOfb73y+xFMET1CKYdOxUquBr4BynVaj4yG6u7eXzmTOV/yb/mcGzfY80kLBIF8wCNW2XGLiyIfofzPP
-5bscBYM82AhpWVUdinF/02F/euOOq+CnV/501xgYGIAgvBBeYPqdyWRLZcl34NlFvVO1VqW/sDSX1utM
-Tie4Mzk5RVyz3bEbh9nb50Ov0+lwEAuhq/dxnmusnKtWi5VSrquiKheb3Xm9Whc/hx48KR7s+Dt0Cpag
-h2duhzdEtID5Wgt6ishfCehh3lRpnpwqSRmZEDPzeD3tyYXRaMDNdjjsOPoEx8X4KR/Hw7d7+xHxoxR2
-bm7OZrO3Z1ucCY5JKtrpcvZ5PYd2B/cDUS1aeqYK5YN0Cm8uyd0k9TRv6jRq9tLvdmvV5xVb4ky2NJgJ
-PMVgJ2bSOGdOs2FmqP+L+YUv5xcnhkZA1HdyYR3nn+9YPjnJEk07aUJ5nJuenp2YYP7KhIWADr1JKfXI
-ZBJGXY9R2+uy9Rq1CqNOa9Ao9BoUYN96iAgEFCvNQqWRL9WyhUYydxyNHMejaGenASNGj1NVKubsxl6z
-vteo61UrpW3rJ6eVajNbPIllGtyoADfPD3SZaJsB+lxeP1dsBhN11sd5ASm4CQt5bsliMpUMhEKVUl6n
-6bJoeozSOFVGneryOEvVRupYlc7X0vkKkk+HySgRGaLPLocThyIQDPL0qlVyPrvSzINIIbU1ufASY+Zn
-x+foIvDIOM2XTuK5rqjkO2rIjXDK8BBVPdV+J3u7tKOO7a9bLFeb6XyD75svNfHIoeljn2g0woSLpwv3
-CC8msASzsB02MZrMR0eHfB2rVYae64x6zefe/n4qgLgVF44WjvYPkkkpoABAsDo3IU4BCRTm0m6PF98B
-+7Jm24NgQZJVNRhwoYvFQjaTjcfjqUQik0oeZ4mTgkOlUrlKUUKkkBcTLoCJW52yC2UrDKAgUPvuhKsh
-xbmleRY/uX+4iYjXuDzuljLfDBMlIKMdUgVQWCbieGH8hDS9Xi8QCYeQEV6ZA2JDIIx5SqlSBXr4vkAe
-eTGGk8wXMAIXllKjsdJtwuNSvev1CEYP92MgnYrn0jp1F7jzL3/4hyfTCz6Pl/sAl/Aae3eBO0HC282m
-yeGwuVz/7Q9/wLF/s7OzurVFL/ZWT+QcuDPlV0/5NZP9mn6HymZS6tS9BLM6JzLEjnFoQMz0cX0zWPtm
-tbIVrGaK9LGIFb//gYcHjgm48/mUbnFEO+nX2E1SyjJfPgmnaku75X9/lRfB2EqlTGEJWU4WLq+/dlj9
-f/58vLRXxiDgFL4twI25eH40G3WnRT3k7hnrU94wTsyIU3mUqP64UWA/G4Eqs8Kl168IPDNxy0voV/Q7
-lP/XF+bFEZ3ZAERehAwxZlDmgklTx43NYGU/WgunGrmCVLkH3OMhTvr1//cfTbODVziqF/Zw+ddQqtYe
-JwRXYjo8evFxeJghhGTQGxgzmRlFNo3nztMTBbvA4VGtUll48PDy3n6hT+6J18MknIwDty5SL16Xm8AC
-gZV2m612GM/mcAI0nb4DZuVXBRLNBoNglYAzhB7TyWSGN9UB2SyR1wvhQ65alS0NALE5Ez0ptFQsEmgg
-y8bVzK98zn1LvJaTrWwl+OtUpZ+g7YM8oBEfjbAfTx7+Ks4r1xehigvjJ+iI6CKBQCbk14UApWmXfyAU
-Cu8dHopdoQC9G4+yTOAK1GOBWBXOPOEwrj+xTvsnTMIaoaVymRH3ez20wXgwOXutv9PykqQv1tPN10To
-Go9p2Ndv0eu8bje3zdr29o9U7YZCzXph2N074tXPD2tmBiTosRpojsbESkKZZlNSdMaL8doVRq10i1Zq
-hLdOHKZqqUIislk+qiVyRe5nMU6zSwPu/HHBMOnX2k3SFZvJN3YjCm5j/TopKmktfBApkh0Os+Cz9LbX
-txiQykV6rQuPSewNLxhnh1PD89+i7x3u1w67lUOenkGXYtClMmgV9RPIlacMQ63qshsV7AHHDeVuNg8l
-lVqVdFpzxa6DWB3CA7bgc74SJ91u0jwY1f1h3sBX07TiWewHB6Rca/IzV+zRKiWcZSSqDmBKHUO5ohGA
-5B3nilKFHgANGo71qT+b1D2ZuNTLSXyNG3+uH1X2IjVFb41zRfiGSDy3ABczlx/ePU9ZnCCWSTIS3nHY
-pXgTOb7oNVPaGw/1/n+8J9CDAbiNgRWHyw2IEL/gahDyptwn7eQlnkX7br/OZiACtzoAQXCO/dSQVyVc
-/G5yl+usDTE8QHjSkuj5/q/fbW1tk1kTkCTyRDwVcaE5llTsSQZteYmL1GQyMdQLgHJ5/AhcaDRohBE9
-v/bRxwrAE84RyCu+keD4sMyC+ITwIRVb1+W2xDrIM3tmHhL94kK8zt8RXhIEO2LCUmQ6k+mt1Z6OjDBE
-hN9XdndXN7ck3GnUR7y6f36sezim8TuVDrMS9yeWqX+zml89KB/FMWeP3aTCO/jvn+uN/RIaMkPhdh30
-qD6bOsHcqEomOpQRuVfxd8AdIECM9vJPEYUBelgw9qna64M7gBouFRM64QOyLQtatYKo1uKo9n98YZwb
-Uus1MK6kic9moPr9ZvUwRk6g7rb2/O7M29LaWwEqm1Hx2aSeNkPBRFeuUMY7q1Sl4Hcr4cB8UPLs+CJ8
-HTFCECecquODBBO1YuWE2aLbqnRalI4WgIp1+p2qES/enDqYzMWzkgI3sz+8MNCQUYl17vqzWDk9iDYP
-Ys1Spctl0XJ5QEyi7T0XMw9CrmYepUSaifhoNVqP1ws//oZr7K5Hv+X69wd6AHjJf1EoSP3c8stfuRoQ
-gCvBq/1XLkqwhmwrIWOmXrx4yBEbRPUYl0esJh0dqOAaPJ+kkJW3UlTlcAz1+aiBAnqI5lK3EQsE3qws
-4/DPLy52HuX9xg8w4RbRn4Jri6MzL4Dgw7s9eBbgKFEacmWWiiKy7lPepxBjhh1Ov8POA5DnYefm0nLL
-35Fq0ygx4cYiBsTjEm1mrXa4z4ee2fL6+uu1VejkjWph0K19NKb9cla/OKLhPoS8Q9xhN1x9tln8cbMU
-SAA93Xajmuf/4ojSa+vVqnuYhfWquk26Hqe5x2Z8GwziUDp1t9Pc67Ephb9zcWDEfQiTtyKyZGqYHV9Y
-P1M4CSVrwWRN8tBaPiCPBIJNLrNibkj71azhyxndRAv+Qsn6RqD2fLvy7VqJ0QIBPrvEq8AH6XOo7dLj
-o4uh+tSq5HHT71LtR6vHZZKYkoer0XWz8oBLaTEo/v/2zvWpjTQ741x0v0sgEAibm/F97PHOONnMzmQr
-X1KbfEnlS/69VOUPyKcktZvdqq3abFI7mfXY2MY25o6EBLqABOiGuOT39oHmRS0wHo/NEFqlwu3W2293
-v919+rzPec5zxN+R49ys7jPXm1rC4EIZ2mc0Jgb342EnJsz0pGiZiDrzZWrMVrmFOjuZrKvZeqG883Su
-miupS4ntNlAkZdQ4fumcv1u1/SzTtMoek0Euvbmenc5mGhvbB7y8kGe6fn2Y99fC/HytCPeoyuuKFxUE
-ImYG0NzBDYL7e8Ytf3zPm119vIX/P6bn440Rdgcoer2QTy8tpUEUMyjwFbe3N5l2cYM2Faa0t1OvVbaY
-mW2haCFH4nG6BqOxR8Ojf/3Zg2vxOHF2NNLJF0Oo9Ol331XqtQFK5X1w6oD4aH196MT7Jc7FI33OocDi
-wIfr4uE5OIC2A2nwhE6z1ov4O9gdSgZJKQ6M6RD84z2wnp5iOvV8isTdp8AffeGur+95vrnvHR9wyft/
-db35v9OV/3m1/Wy+jt2pNrDXB0SL0oXuxbV6stcx2INbpNwZIFgAEb7mKWBHrsV5pB0+t8UaHh2eYDf8
-jwVre3BWkBS+JsgiVTTuj/j+8Rehx7e8TPqkp0J5D6TpDy+r6byyOzzJ27WDmZW9wZ69L26eGFK3syMe
-7ohHOjKKTaU+EX8XZvTzMWcEl0j7SJ9/elNdZyLeRB+yk2kav3OCavKoh/q0rThmsKTV9d3vpmsYO35h
-xvoPX4EieRlSbLTZFrvz799WJuerxc0dSKXmeoHVDzrgkSoiEiAmtygkj0IxTxteVKTpcrMqRlghDwYE
-JkmMmJm72cMnWLBNz1mDzPUiMEy0BbZYCrHhhUX+zWSzRFU7oJng8qjcCNUD7k7M5Q6Eu73dTqJahrAp
-PogCmPf3dvzOrt5Yf9jj28Zp2mk8mZ/r8npgu/AKwna8cw54xiGKjxaJRgC5eo04F2RYa3u8Mz44VnyO
-fzVY157urnggwErIbVa+sspo51XMF6KL4jY5pEYo72cab1crqdzay/n56dlZgA+8wETU/XDMDcTTFzl8
-/8ub/9lcA7vDIyF7B/Eh+rarvahZDzgH5sqXsJc0gwE01OtM9jq9bu2w5bejv4Ld8D8e7nCka2zAzZc4
-mvxO+Gwu25zNNLfrh7vG3WA69uVN3xc3veLvqBhTbW8pt/M6VRd/R/wj6D14E3XKCZw8Tvw4rCRPurk6
-4O0EpeYbMKArdo1xYbaV3WhOrzRAXrBl0ic/jfQ7B3ud1/sOJ9F0zqwQegG2iZcYLk9j96BRxuvBnzpk
-UVbr+z+/42vsuPePppyyFdPYp7PVP75U1Y0YUjll/nKVcY56Yt6hZHJkZIQpFW9I4hXMufiJEDuwOF8i
-ovg+QIFE1iFwAEGaPXyCBdv0nDXI2B0g5zevX/3xD3+YfjtN2FvNtvZ2Ix4vMapkJNofDPmNcg67B/tk
-YFJ+J10orKwXkVUm0gQ9p7pTK2znHq2OfXXzQW8wemswScrCi+Vl4vcqjlYotCA+Zx3N6b9Z41x6W4yO
-gquazbYgTtDjvZ0YoD0L+laHyxgdRFThumCD1GzyhAmAAPhk+s33hLRWMkBroCdDvZ6Rfg+OjLyu6UTH
-HfT+Pe6uwR6X3hI4FliE0BUPrbSkE9oke1waC1HvQy3zEPJgy4IyK0MK1TZBZevee8PdX9/38O0NHZon
-7M50qvZ6qZovKRthGhrl3USUg8OC/rH26XF2AeL0R13mbEtQHhyokqqJctynYE9Mkcwoe1s0St9d22XZ
-Kl9urm7UsTuYSL2Z4Iy9sQi0R6je4Mq8or766muAvOUl9K+zf/7+CZyAyvZWoi/+s5998ehnFGq5kRgc
-1Dv52Mu26Wk/woLv4O9gd56gt/rkzxBMmGijo86sBGYwAhTDPXH0cXxOF68rakhAI0QF+VpP72ppI7Ne
-zJY21krlaqP2cmmpUqt3HrjuDo30hyNUASNCzzSbCQIJinunFQJrf1zt13JvkX8ADxg+HsLUPDx8zKa8
-Szdr1U3wVz/i0K0zFzCgfkMiB8MkmM7hhpgZTA0hdupDC4Va9XrAO5OUFIzO/MICVbqolkNOVmGj5HUc
-DPY4RvpdfdHDCZT002geFDZ5hzNEJx6PSm2fKEzQe+yjLa41phbr6UITGyTv7ZDPMZbAluHFnAowc0i4
-GNI+7HcC2WL7/G7mkcrvKGzuZjegC6m9C3LEFO/esGsiSTDL9Iz22PX8an0TJ8DAg+TImeUB3+jTPfE1
-Nqt7a6XDPnnImcFFAsrugEaZlCUxo6k8mXrH/g7dYsIDXuo7dpuQjWp5hEaBFkYiqN2iLuXltZcz/GJa
-upzdGF+unYnC4RjiHq5tQIbCiHUTwcRz4QOOw17ondk3Ls9DRN1GR0E/wRap1MJ9Eo6EA6GQK5WCiiJt
-Pn/4iJ/6KGcbPLc8ngzQh/21TU/78WOqBb7DPAt/B7uzkl3F7qCz9WB45Jt7pDUNIn/jgxxN0TsebIxI
-Y8d3sE/W+L3rw4DQxFnIF5skFzy9PJ1JTaXWytUn6fWNv33wUXgT3FLM54Fa4AFnM2nDvT82PfVmkxTZ
-tc0yxHnkRFpOmIdWGR3DSxdMh4g7/+U2J5IFdG+K3vOQ7zWbsGxfLSw8ffX62ydPZhcWqNIF9YB4XzzY
-PZFUX2Yf+i5Adjge/c0vvy6t7fzLb4uErs3GTI5ypSYeAXiQvLfjEc+dYd/ZsS3ZXNpHgu6huFs8Kavf
-EfIp5GhswAloLTiUbGv1tmS9iqwd+lCHRsrqoWARgMwTUQ/g8Yk+G5AYFbxdPfLgTutTR6N4+Kk7Mjo6
-SkyKUOnvf/975vkYCGvsDNAau8OEq26kd7DV3Xv37qMta6CHhocKQ9obiUQCwRAQMldT+dd+Pwjjoy++
-ZKYPFMBKvY0c4Sf7a5ue9kMN8EYOAMmZs3OzvN55cgYi0bF4/6ORscc3JkYTCTbDc4E7Q7pGKp9jgTXk
-Mke5fWAY+XzO/gSvGq/Hw6tyIbeWXlesikQ4SvgJ6o3Lp1hecC7MiFj74zjfWuJc3HNghwhpZDNZ6I46
-4rNdq86lF5PxWBQ+N+E/AlXavAk7cWwqMDdgOgZXBfgKl0f5QUeeTpkiGevry5nM87l5lAzhK5MOah5g
-wOvEleArVB1zPbtydqugEu6PIODiodSaXXOrAhwdtgU6I68CUhSeBx5Hb9hBWAc7clpsy9wFC7getB+I
-Oohby2yr0iC6DL0Fssyh34GvAQw0kSRcdSIOVWscEN4Sb0v65NQNNFohMsne4+me7qGIf4TpAYrCOYoG
-T/SJ9VzO7y7nlBmVPuWsYXXDrtT71NGoYCR489bN2zdviQMCDijn1R+B+HPIFZLetmv7AFgKw6od4CVh
-rR4+ePDF48cwLaSB9a/EsBA8sP50IWts09N+2IHfAOKIWAEMyxubhAlK8PINHBWQwdxM8v5fmH86P0dF
-UDoCsQt6PSSIT/QPjPUnRoglxHoQ/Xq2OP90YW6tXPrP5095Dlig9mlLJnr74zjfWmbyQhS6cWOiWFCZ
-UECI5qblzdLkq2dhd+cNsMTEgMJujnJQzTaHC2DKwhs0nCCeFt3TmZqdef36NUzl3EaJFE/ELvTNlY/Q
-jn2jnuGQC9fAhELFQxHGE6w2sxNCvVAQAOIZ8PfltljbK5KOxLYUX1J9rEiQrMcxgW0k0TdZY9idNr6M
-7qFIS1y8tr6eFQ+Ss7b6L3rLRFB5r8lrQyspok9Kf8p6XrLfUuXg2Xxzcp7skP1kTDF3MDoy25IGP/2/
-tulpf41ASyCMkEZM7Fzeb8R0gl4fX8QDZRsmMsA6c6vZKXKNC3m8G7m9+sKR1Y1SuVZ3ut0s3xkaIqGe
-tIrX6XSqUNisqdm/y+lQkx+8HnP63v5AzrVWTZrgDUai4zcm0BhsQXzIL19Ip6lufufGoj8CQJXwe9xs
-ovs++m4gPUKlxASUt7dVhtT2NlmOeDpTM29JNTxSX3bwZlYsWDXbgqF8AF+OLAerh8I0BPYgb+mXix3Z
-9WNAlDd6bw9pp/EQtTEMziR02/m5uezaKqgsWR3X+7qvxwmrH/tk+kG2LAc8KhNifMCpx7bmsw2+uBXi
-cehIkGwusS3C//nynhl946fTfBndQ5EeAIxafD0rxiQt8bmG+90Tg24Y0kxkmbtt1PagCL1cbCysIdjS
-6fEFyddLJocY2Fw+xz0FCcd6Xgw125LvtpyDrKhIUlC6eMdB1MD5lX1dir+26TnvZYLpRVIo2g0tIWHC
-6szG+YpzxF+FLtcbwCsLpY3PR0a+Gh3/gtKDaLJ4A2TSF7e2jdxoct1bEd/zHsop7U5DfEBY8TjepHO/
-+36y2un42ukYQYjr9BQt7A4VspYyK9QvnkPpPZtZQ00D+kcZuf1DXSHQUPAFzPHCwjx5CZz1KQfVAXEG
-1nJfRJ0srTgSpi20P+jsotDoHQOhEH7T/Nzs737zG6XZVd/xufeYmMD0NSNlp/Uv6624jO7LyCtBR4Jk
-K4ltTaeOWT+y/vy+jNXXs2JM0mevwXhSkbWwyu0A0ppZUTlr0CwXsjUUWZgtiz4BgXCSORlYzHpi4Cy8
-iXcY9xKULohdQDlYc9nXpfhrm572l4kpjNfvJ2QAGTQSDgEbU7tiqZifWcsGAz50DiidDMaciERvJZMg
-JIOxGDZlG0LPniKJbtXr1bW1kiKL7pAwfrs/MdbXD7djBkUYRCR2VdIwFCHcZIQvKL/T/iDec60gPkz7
-b9+6rVyV7CroDC9JvpA+ssXS99PTe0bSUa5YJN2EORozRM6U/eDb4d4TVWGmiYIEGhoLyF+Bc6VSqNgQ
-iFXGoqOTbENJvh0eHgZcgGewt8tpNfdw8hoqNE6wBqqubi+AfiRbIlfaB/FZXOtc3VDTBJxJRQ1voA3S
-ZQRnwgg7ILoDGYo1bHUtDsvxGGc5bTDEo9ExFKsvg8fRggRJb7CBef754pTp/fs8nQS2jNjWoc9l9WXw
-8oRkTPjf6ut5nJ2JKAEyB1aGqBYWaizhuh7vdnSR4rAzn+0gLv56uYHpAa+pNR3oFty+fXt8bBx5XBIH
-V1cRvC6SZ9YT9JyBN0Ep74/3Dg1y95En80m5yPpw/bBl2/S0HzdeILxG9NrtUvGKDCM2IGoz0t9PoJ1y
-F6OJfgwNdwo1f7MbG0gdQuqZyWaK21vknr7ca+7vlLNj439z5xHlT6FPwABCD8haZ6L9cbzPWkF8kkPX
-UDsm6/2P//WHRl3hJjw2dCNZTuj4LS0tItueGBhEJATZPYBwflXc1hUE4akusYkJRbuHb4nZlqFiw3sY
-+yV1JtBXox4G4lJEbclgoENll+uN9a0a2dJkV5LlRLZBy4GL73P7uuPFguP5fB2QAumitzMzitu2tYki
-HzIm5c0ymm0MGnnbkaDXjFW1dNXyXyuGUtpWPB3dlzkNMRG+MpRlFvRuz8PTiQSMvPzriGyc8F4NLpLz
-/qh3Y3uXs8a7IZpOpIyZILOk795Wt6pd61t78HEI58Eb3Otwh0IR9IkeP348PDKyWS4jXcZ8XXhS1tiZ
-jjeFglF8zzu3bkueoH4KP/1l2/S0v0Y8xrxGkKp48OAB4XNcHFTjyNV+Qc0ZhxMV38LWBu+akDcQC4YS
-0VgyGgPWyTMlqVZmV7P4PvgRZLJnizV8IPYxEBsY6um/mUxS6CCPS7KxMTs75/P6RsbGcEB47X/4RF0Q
-H9KUKVVKtsJmuYSA4loeKWqVT4/5KJWbeDTU9JpNpRL9CdjPeHSCTeqmR4BeQbgYB9PTicfjCNHfGB/H
-9HDYmGYI2cCipJVkc/lSRalJgGLg2vCqJ0nShF04ffF9ekIoHHXA1vG4dl4tNxbXykvLZB8RTKw2ULsp
-b2J68BrJ29ZjVeJxiAHFg+DZVn6Et7s/4hztd0HSRvRBMBRh9Fl9mdMQEzLgFWJiMInkPuD4VRZYxDFg
-ZI2dwdPh7MYGXGMJN53r9xBxOkg3ZPgNxBzObg9mHzcQ0wOrG4mPFwtkSOznS9wbauKJ3ezvizGGFKO/
-dfsOtxwqtel0Cuvv6lY8KWvsTMebIj2BsRs3xsbHUV7Qj+FSLNum56zLhETO47/8eTzel4jHJ6nyNTWV
-LhYr9Z23meXr8RDFzm8nx6/19Me48kZOE2xDjE5PKEzwCxphpd7ACeIme7WS73K9+Nl47a/GJ2CLgQFt
-7u4SPptbWICvSHwdRkbfj4QRir8GSYwT48ifPZuEHGDm0+O84AcxP8JPYUbGhKvLmHBBdlahPFBgZk98
-jnIEsDtIJounA+GVbH58JRKdYYiwI4wmyr65XB74GfUsMo9AWDYru7zP/+ZhyJ9ohR6MJAZvNOgc6W/+
-+a3jP77rmM02SXYnWIYvhnFEHdnqoQh6Ai7DGdGD0Hb4K57Fneu7qHONDyoMRa6l1ZexIkGCtljZwJIF
-1ob7Y+HpEP5vi0YJfgQnmwWMzuiAG7YhntHUIrPRg+k02STNal1RHMVfQ+ntF7/4xRdfPibRAaA9n8vh
-PaOFcB68iYR0VKj4Iil/1n38k/zNNj1nXRbMBDcEUxLU+vBKcADmFymZVUrB3quuU6S4UG4M9RTQPI4E
-/My/eFDpbg2BMfAcIx/nEGfB1HQtIS7x6PpIbyh8l2yaamVyawuJmVdTU6FQcHgUgnT/WYdy7t/EX+vr
-T0CNRRUBfw2XChvHvsxo1G69UasfSmroHYuPQ1qGElNAUQHZunCEsMvY6Kjp6eiYAuODOvpN+GyLi4BE
-xWJhaY34ncpkJIRXrhxgDshHFz+FHaF6Q84k/kIsSJZ/J/EdYKj57HZ6pVzIK4oQZhHWnxmrYvSwEZKp
-hCAhuavX4i4YLpgSvix/MeHjCcceEVxjR9Je92V4vM9g6CznqD3b1LOfiG2RNWb4Gid4NDpP5whdcrag
-UYIxzWXq5Oin8ir9qg+j4yeNtiMa7IoGu0FtcuW90hZYe0ehvI/eBl0xnsh3DV0bYsSxOagsrq2uQhmP
-hc+KnUlWOleH2wYVKtRg9Ot4KZZt0/Puy4T0N5XOY33xiTt3iPm8mJxcWpjfKOaW8uXs+pTLMYM+BoEG
-FAslUg50WkDhWT3oh4838x38jsVMZjqVupUcfDA4xJyEahlLhTyBDAKjIB7vPo73aSG+jzINySQeEL4V
-Ns6MRsnkxdqf+DgUzBlKIl19jdcpd3ZYKPpHno6+leyFqqGs7Iv3oi2dTi+itofqFeozn43sENBBZw8P
-BUthbsikhoj7LSVVEYj4O/71vxuAIBgdGmA7dA9FfJO3K43/+G5zPtuEHPTlzQ5ogQMGLU58KPIIhLKI
-gbP6Mudn6MjhGUhNm6wxnX0j3spp8TLszm+fbhPUp8OI3/lsdvfxLT8xPqSL/umXwb+66yaxi2nXH6eU
-MiE4nHJCDaUx2PNgZ5kMAo3K9AQHHC08KT12JlXMeCtwdbBZvDPM4b0sC7bpefeV4pVCpXPoJ0CzffE+
-1JX74nGmBmh3iorzJoEho5IEBLzD7hA+RBaQ6UxnJzQZ0BPmFNDwFtZWkYS7OTC4u5tElytfZnUJq4Rt
-evdxvE8L8X14o1LzIBgKcRj4Vtg40oKYCSoFB/LGgSWMhAlD5ZUtugOUZ4nFBhByHgStHsL0WHUdiUOp
-zMMKlcSUZ0cP0E8gIlLUFFVzdIGQK0RtD9UrwFS0YZlcMDPCQ8FSiNYfjy7KD+Ap/Hdjq/m7p2j6qDws
-1ht5CcccYslUWlprvFlWkaCBWGey143UoYyE+FD6qOABEWLTfZnzM3TEl7FmjYkvYyh+gQqriRLm7Ix4
-2eQ8R9sgD54D83v2C+Uun8fxzWdkyXdhhWEqZYpOl6N7LrufXSdbXQUIUe1CCQop3QIaFtT/qmz6XHvx
-sLtFpUgSPiQvjOJgyUG4h0NcXChd+iBcluVLedAXMrg8mbxecCIAOFD5kifQVHEGuOH1JY+iHB4eATMd
-YteUmEM0nLQDoBTSSvPlPvK8BmI9NwcHUQ4ju50NxQp8pPPiMMCSmNMZSgkI1Blq4NgOw96Rz6HyFY0S
-d0DOOD4Q/HCXfNCNfaTlt2p6YHdePn9OFIbnBFlYjhloiKg8I4BcFaEWWDmMBCe1tLbPxDOdrxPrYWbU
-olAjvg8yxiwcjhi855P5UCpR8yhT6TyDo0d/pP15EBNpKb6MNWtMsBs9r92KRkkPVowJKSTqbQAMm26m
-4VUxU0MN1kHRC1QEeQdgx1Xlwmp1bXWtvLXd1bk72MPsrFWlCK/HzAszUDZwNpWVfp6R+Qm2sU3PeS+K
-xI94yfCVbbhXTBVnYszqiTP8CPmVB5hnHtId4oZv375dJR8sm6U2FlkUFM8AGBqIxuKhcLq4rkDdI2/p
-vEfzPu1AqcCwBUsCkcGxJz2NNBHo2nQDo5oqKOcp7KuSKhAGWV9/OTVFjTrRG2o5EOJiRtq88mLgB6Nh
-jNfgdYOboDR4gv+iVG92Ub1Bxvbw5K0eip6p1LKjtv/Voz/S4DwMHWkpvow1a0ziZdNpNSuUqN/542Xk
-w/k96suCfFRGGzm53Yakt8FgUtWvjCRkAGaKRvBmQKNjNIFq6rHqkGyL5ND8KvxstFb3e6M+5L3xTHlJ
-HHZ92f6xTc8Pv2KCdEB7xxUiQqQeuqPAEJ0SOeKWwmAx4XJ6vG9n52oU+atsw/oh3g78Sy6Yn9LK1rIp
-P/yI3r2l+G4cGFiyPPPMxfDYZc519vbYHcwWBUSnXr2afPECT4c3dssm+H0tk0fYg7B4woFmi9afIBdE
-gihrI51YPRQ9U6llR23/qyMy0uA8DB1peX5fRkejZFsrxnRan3pLpJ0hEAoXGS9mHaEVI7YVsqgOSW/4
-dG+WdwgjspB0u+PUAOvrc5+sMiItL8Vf2/T88MvEYwyYwuedXZBrSU55xqgsvlFBYeXwiVWPPb3g658r
-Uemd+3l3A/HdsDU/ICICuINKLFXeVzIrxWKOODTvfxPBweHD0+GFXCR+v38oIYw/p6YJBbgzuyzoxyfI
-BdAMC7Jez4eSWJVkKrE5GhH4RPrmLcvS/kOUdDidlqwx6VOPlwkepDOn5TDUuZzEmGS9tU9dZ2d3vzMW
-CVGbiWI1sMJRv4Q7xiyYabqpOiT9HOFNOytFsr26/D5/HFIWLIdwxOlsZW+2jMxP9r+26fkUlwbEhBuF
-lCXyMI2IBvMR6t7VEUvF6yH/60dJIv3YZ4IqvlKnXlqqVapH/Bc3ZDlJI5DHg+nAt2+qqxt7nBTHIyfL
-X744hfoR6siFrFfexFHuu3gHLZUk9M1blq3tDcS6Tfa5db/SlZWno3sokLNMJo41+9yKMZ3Wp66zA7Km
-iJ29cWayxeL6/OKi1PM4LXYm/GypbW+tRtsyID/9/9qm51NcI6BcSMZklnd2dWN0uNVIyKAg+vbOTigS
-hrMnhKBPcSgfsA+SzyAHAUgAsRtcXjeVJx6O+xJR9eJFpCJbVHDXc5UVr7w5VlJfwdF9QBq6z009ixOm
-R2fKAH9gy/TKE9ZKEmcfuPgdeuUJK3IkPej7lTVHvkwrT8fqy2AcAYNg/bRUnrBiTKf1qaNXwPhUd0Ro
-qa4AZgjheeqgtjC55Qh1fjbgDh40MA+I/iWNbclJ2aZHxuHj/gVbAXLmw4LsCbgH0KfcbCSSQ5QPBXn5
-uEfwY/ROFScKIq6XyiRlhA08Artza8grVaVgMBPJsu5H/CNrvEbHZaxtTvMjrP3LGmt7K3IkLfX9yhqJ
-bbXxNSzVLE6rPHH+PnX0aiAJF5zEvoENdE7ElzylApceOwv1KHUelN4vlzqP9cLZpsc6Jh9rjSA7VKjI
-lUo4BfmtMp7A9dFRZJUvRYgUryeL05Nbo3LTYIgadajPeKkhhS/AkJWr+1tVuDwHcAMNno6i/LCA99FS
-VeIIuUBu5pApQ4ZXSxurH3H2VbG2f9/Ylp41JihPodx8tVx/g6TGkdgY5qxt5QldAVqO08r9kT4FvRKd
-HWhQ8DZjsdj0q1fIGBB4PDt2BldzZ69TbTV0TZHszwEynj1oF/urbXo+xfiTnQQdBuZLd2dHo7lDDipm
-CFpeoIfUwRtkD14K0wOZYCmV4kuqOvyflnoS+puZxwxwh5FlwcoPtjJlrG2sfsTZ18na/kNiW4LypPLN
-FwuYHhVRkr1/eJ+CXkEAM3V2vP4A+bfIBpBDNxRtr84juWYSEYtGwmgGoLVynvjG2YN2sb/apufjjj+v
-fWLSqP0RviA85AVVbh7MZjMOl8sbCl8bHrk+PMxs/8PT1j/uaRi9k4uPABB58Abt2BH2Haogy66VuWmq
-wlWqlJTBTkbRBmUJkBGgaKkqIW9+Kmo+X2i8WKxTlZQ19KZziAmTgQSLHyGZSj5va8BeP1m9vV73ghwx
-1CrwIxxauU59Q5bZNe4JWNWDUTdUYzMLjMzy6fTO01lVudyoh3XY8vyVJ6z+i45GkV6HDhSRB7fbVW80
-shAW8hSEblpjZ3pEjKFiK9JN431xJu8t53Lp/mubno97yYQLA/NwdnZmdSUddrqp/5AqFvyRCHlh9x4+
-TCQGL1cOjiAjRlTuBCPAWpOTdO3b19yPb/m+vOWXqhLiTVDR/M9vd0RXWHrTOcTYHbIWpIKVZCpBOSTX
-BDmztpdKby8BtbbNWClMYmSAgHU8LhV0QxMD/vTEoO+b+6oSKYnmcoTYnX/7dpuqoYTqpDcsVAvTWtaf
-Fi+zcn90NMrvDzHPJhMCebb19Y2VbFZUioI+b0vVdj0i5vcH2eqyIIOnXQVzvW16zKH4KAsQhzMrK/Pz
-c5TxKhSKnp4e8hNcgUBsIHH73n2EdYh8XZY4BeQjKEigVIRv8G6kUqjJ6wGvoZjndt1LuApPgb/UUbh9
-3UVpc2o2IAaLOCHoCbMYvImXS6reFs+VlUMMBRG1Qz1TiQtD8kej1t706JUnxIcisMaCimTldikL4fN0
-+wxJHaXyY+S7fznhwxPaqu5getDioqDw+KCbNvky1bUOjxC7QzCboqByW7x/vOysyhMIHYzdGEeGubpd
-gcyzsbEhKkVnV54A3EG7jvLEl32qJUNqm56PYnHMToF4nk9SjvzZWi6/YWQ8UZjt1r17d+9/RiIYXPhL
-dBtBPsLZAaQAqqBQJ2lNvaFOMzMLlwF9wuE+15cTTYBkkrMMdQs2UfTChWyD+hCgtqAnzGLwJniqMRBW
-DrHuR0imEoNJfYZGbdMcVX1BrzwhPhS/4tFg/pAfxVT2hp292uxEMsh/+cAD7IKyLfWzqAVGiO20I5R9
-vW+8zMr90dGoK1V5Qr9Y+rJtevTR+DGXlS9dLL55/XpycpIcLqU753ZHUNIdG7v34CEF27A7l2vGjr+G
-3UwPDiLrUNzceTpXZbwKmwd9EcwR5QJVgWDYkWj0MEWC+MOnUu9AZ4eHHMYNpodoEahtcVOpZMlYG6gQ
-tUlVb2BArMTl+X4WEZ/jTCVW8sLHTtVQmF5v8OtW7TiKT+HQ72eqCFAgfwMEi1dA++VUqlqrvE03MHy9
-YbwwVdCKTHeOkPwpY26I2aFMiMqoQlB1ZqVJvrt5hFu1blgzEVcHkQHJCzHcqD3SPr6fqVC8UA6ev1NL
-jdlMQ8eY5CcMImeqJ8lIS0GvYpHoIFUktcoT1nGQftiKiqyXuvKEOVYtC7bpaRmQH+2/2J3vvv0TNZOf
-PnuWyWYoe47Ewdff/PXnnz8i4Zg6s5fI35FBoZQlRXIpk1X507eFfAbWMkIW8RcNVGkwNJEAHkSHx3WA
-gA6Iyc4usfaOXKkTciBTG4wFTyOxLSAP3Tfhvzyiq+u7303XwGLYEV4P8HOpolpKphIrSZdTU7ytxpOZ
-3cx6jcmdeZ0Iq0MpwqfYP3CMXLv2q1/9ip9+/etfz868JST0ZKZJ+74wmasulC44QpI5+TDXK1UQ9CCF
-FUmzfaNyedM8QswOmsc0Q32xoWAmxL32OF8OlSkb8LnqwviwbTrPzPFY1xEjhc81ndr/59/shP3Hxykt
-DzrcsahSX0Nnh6Q/s/IEEiYt46D3T2VEMyJGAgWjcbj7y/yPbXp+zKsHqExSJf4OBSEW5udnZ6hAsUqO
-FoAiL+SbNyceP/4LhLu4ey6d3WGYKKHLweMFbFeq02/dzCUXcvXFXN3laKD/EAl0xCOwltV4Yn2wCKXt
-g1wZSAVLtEdMB2w1GA0MXA9ALGhUK7iBqo4FAZ4yXg+QyrErQQ/Qu3n+BwcGyJGEwYgiPQATQSJVWmP9
-REu1P5RxvN54TwyR/s8ePIQ7jkwACBqTXPSQXizWnF0NQGLcsZYjxCmr1rs4QowU8SPzCIeSQ/fu3lU6
-1nk4WBuGw7WfNpLRZHfmX2EtwxSlEDaeC7QDiBQE3RBgLGyeAKekZU9MeY6is0PcU1QESOCiNGvbcZAd
-BQP+ZKKfKiA9vT2X8c4xh0tfsE2PPhofuozdIZiVSafn5mZBl3F8iIbyPFChDS4G9SGJp6J5eEnfWtz0
-0El4sJENQTIV3YzFpUVCM5uVOu7DRqUjs97hMF7zZGtRrYx3NZOgg4Mu3tjGOIyBrUJiIt996sULJqHo
-Q7fVaeUyMBnB7+D57+vrR7HYj0itUemMp7rtRUJyiOgPFCnMeizW86u/+3sGHIhtGtHoVIp5Ex7TVr2z
-5QiZcO3udRJHI4NcP0JKSLNfLuLUy+eZdAov5rT9igfHxJlsLLL22Rfa+22PUFoixD8xcVN0dpQAc4Aq
-ikrhCPG2tlvJSlJwFfnFFwAAAj9JREFUHn7+CJcTx/OMZpfrJ9v0/JjXC6+nVqlgfZYXl5AxpGtumqGh
-JA/c7bt3eSp+zJ198r54t/OMqUxXSrM2GquZDCldHR0lpOQxMad9wIA8XU6SHuPxXiUvf/8+ydnFfH5l
-JYNUx2lbYZ0x09TAQEkIbSHAbSOydgzxtGyI6lAEWcgYAUQfz6djYoIGebjX2VWnY1WQmmobNWrVDZbR
-73HoR4iFDfgD7Jec8rP3iy9DAy8oXjiMfWJfLQdm/ldagpf19JCsHsWCUy8E547Sz2pIz/yoRNPEAC8w
-j+eyqvNYz69zeXnZutZeY4+APQL2CHzUEXiHuf2o+7Y7t0fAHoErOwK26bmyl94+cXsELnIEbNNzkaNv
-79segSs7ArbpubKX3j5xewQucgRs03ORo2/v2x6BKzsCtum5spfePnF7BC5yBGzTc5Gjb+/bHoErOwK2
-6bmyl94+cXsELnIEbNNzkaNv79segSs7ArbpubKX3j5xewQucgRs03ORo2/v2x6BKzsCtum5spfePnF7
-BC5yBGzTc5Gjb+/bHoErOwK26bmyl94+cXsELnIEbNNzkaNv79segSs7ArbpubKX3j5xewQucgRs03OR
-o2/v2x6BKzsCtum5spfePnF7BC5yBGzTc5Gjb+/bHoErOwK26bmyl94+cXsELnIEbNNzkaNv79segSs7
-ArbpubKX3j5xewQucgRs03ORo2/v2x6BKzsCtum5spfePnF7BC5yBGzTc5Gjb+/bHoErOwL/BxO3tcAh
-GzKXAAAAAElFTkSuQmCC
-" />\r
+<div class="imageblock">\r
+<div class="content">\r
+<img src="./snorty.png" alt="Snorty" width="480" />\r
+</div>\r
+</div>\r
<div class="literalblock">\r
<div class="content">\r
<pre><code> ,,_ -*> Snort++ <*-\r
-o" )~ Version 3.0.0-a4 (Build 227) from 2.9.8-383\r
+o" )~ Version 3.0.0-a4 (Build 234) from 2.9.8-383\r
'''' By Martin Roesch & The Snort Team\r
http://snort.org/contact#team\r
- Copyright (C) 2014-2016 Cisco and/or its affiliates. All rights reserved.\r
+ Copyright (C) 2014-2017 Cisco and/or its affiliates. All rights reserved.\r
Copyright (C) 1998-2013 Sourcefire, Inc., et al.</code></pre>\r
</div></div>\r
<div id="toc">\r
packets it reassembles and normalizes the content so that a set of rules\r
can be evaluated to detect the presence of any significant conditions that\r
merit further action. A rough processing flow is as follows:</p></div>\r
-<img alt="snort2x" src="data:image/png;base64,\r
-iVBORw0KGgoAAAANSUhEUgAAAp0AAAA6CAIAAAB9MXUWAAAAA3NCSVQICAjb4U/gAAAACXBIWXMAAAfQ
-AAAH0AG5i+efAAAXWUlEQVR4nO3deVQTxx8A8MlyVbEgooAQKQIiVEFJlcNftaUtR9+rRxEPqj4Elcqj
-iPoUxYO2EbSiYkFtrQqiaNV699FnqUXFowiiQChQKCJRQMCjHqVACMnvj7HbGDawhN1sgt/PX3Gd7H4z
-TOa72Z2ZRXLAkLa2NvTKCA8P12TdHj58mOtPzJmEhASN1XNZWRnXH1ejkpKSNFa3pEuXLnH9uTVn//79
-mq9hoM/1370P6tevH9chsKijo0MikXByaD09PUNDQ04OzQmpVNre3q754xIEYWRkpPnjalJ7e7tUKuUw
-gD5fyZzX8KsM8jrDTExMnj59ynUULDp48GBISAgnhw4JCUlNTeXk0JyIj49fv3695o87duzYmzdvav64
-mrR27dqNGzdyGICfn9+5c+c4DIBtERERu3fv5jqKVxTBdQAAAAAAYAzkdQAAAKDvgLwOAAAA9B2Q1wEA
-AIC+A/I6AAAA0Hd0NR5eJpNdu3YtPz9fJBJp1YwFa2vrN99809vb29nZmetYAAAA6AC5XH716tXCwsLC
-wkKuJut2gSAIR0dHFxeXCRMm8Pn83uyKOq+3t7enp6dv2LDh3r17vdk726ZMmSIUCseMGcN1IAAAALRU
-a2trWlraV199peUZDTMwMJg3b15sbKyjo6N6e6DI648ePfL398cTWN966y0fH59x48Zpz3ogcrm8pqbm
-xo0bJ0+e/PHHHzMzMzdv3rxixQqu4wIAAKB1ampqAgICKioqEEICgeCdd94ZP378a6+9xnVcyjo6OsrK
-ykQi0enTp9PS0jIyMvbs2TN//nw1dqWc12tqavz9/SsrK0eMGJGUlPTRRx8xEC87mpubY2Njd+7cuXLl
-yoaGhi1btvB4PK6DAgAAoC1yc3OnTZvW1NTk5ua2efPmgIAAriPq3sOHD1evXp2amhoaGlpeXr5p0yaC
-6NlIuJdK//33376+vpWVld7e3tevX9fmpI4QMjY2TklJOXPmTL9+/bZt27Zp0yauIwIAAKAtKioq/Pz8
-mpqapk+fnpubqxNJHSE0ePDgffv2HT169LXXXktMTPz88897uoeX8vpnn31WVVXl4eFx+fLlQYMGMRcn
-i6ZMmfLLL78QBPH555/n5uZyHQ4AAADuNTc3BwUF/f3335988snx48f79+/PdUQ9M2vWrOzsbH19/Y0b
-N/788889eu9/ef3cuXMHDhwwNTU9cuSIvr4urRv/9ttvx8XFSaXSOXPmaNW4fQAAAJyIjo7+/fff3d3d
-U1NTdfQW7YQJE7Zt2yaTyYKCghobG+m/8UVe7+joiI6ORgilpKTY29uzEiOb1q9fLxAI7ty5s2PHDq5j
-AQAAwCWRSLR//35jY+Off/5ZC4fI0bdkyRJfX9/m5ub4+Hj673qR148cOfLnn3+6urrOnTuXnfDYRRDE
-1q1bEUJbtmxpaWnhOhygS3j/srKyCgkJefToEdcRAQB6JS4uTiaTLVmyxMLCgutYeuvbb781MDDYs2eP
-WCym+ZYXeR2fC6xbt66n4+60h4+Pz8SJE+/fv5+WlsZ1LEDHyOVyuVx+8+bNlpaWJUuWcB0OAEB9v//+
-+9mzZwcOHLhy5UquY2GAg4NDWFiYRCJJSEig+RYCIVRQUFBRUWFnZzdjxgw2w2NdTEwMQujQoUNcBwJ0
-ko2Nzc6dO7OyshBCPB5v+/btw4YNw2e6MpksPj5++PDhgwYNCgsLa25u5jpYAAC17777DiEUGRlpZmbG
-dSzMWLduHY/HO3bsGM2r0QRC6OTJkwihmTNn6ujgApKfn9/AgQPz8vJqa2u5jgXovJycnLy8PJlMhhD6
-+uuvL126dOHChdu3b7e3t8fFxXEdHQCAQkdHx4kTJxBCc+bM4ToWxvD5/EmTJj179uzcuXN0yhMIoVOn
-TiGEAgMD2Q2NfYaGhh999JFcLj99+jTXsQDdU19fHx0d7evri/+ZnJxsbW2NX+/du3fXrl3Dhw83MzPb
-unUrPhUGAGibnJychoYGNzc3FxcXrmNh0qxZsxBCR48epVOYEIvFlZWVlpaWHh4eLAemCdOmTUMInT9/
-nutAgC7B4+bc3d319PRSUlLwRltbW7KAWCx2dnYmh9eRq0yTY+44CBoA0Ame6q3r95Q7mz59OkIoKytL
-Lpd3W5goLi5GCHl5eWmyb2LvWPjsBH8oxv3www906lRraW36efjwYUNDA4cB4HFzjY2Nhw4dGjJkCN6o
-WF22trZ37tyR/6ujo0PxjTrUKtLT07kOoY9ra2ujP24Z9Eh1dfXjx4+7LnPr1i2EkJeXl0YiUsZeH2th
-YeHo6Pjs2bPbt293W5goKipCCPWZR6INGzZs0KBBd+/e7fbPrwahUDh69OijR4/ie66AKQ8ePLC2tg4M
-DMStUQtFREQsWrSovLxcIpGUlJTMnj2b64jUFBERMWHCBDw2ELChra3Nzs7O19f36tWrXMfS11RVVVla
-WoaGhlZVVVEWkMvlhYWFCCGBQKDZ0JSxkeDd3d3RvycuXXvxe71HeV2T833VqB38WVj6yV5WVhYcHOzq
-6spIdsfVSBCEqampu7v76tWrHzx4wEicOgePihAIBNqZ3aOioqZMmRIYGGhiYjJnzpzg4GCuI1IfXiib
-jeyuRnvuTfentdefEEK//vrrxIkTNZzdtblCmCKVStPT011cXCizu1gsfvz4sZ2dHf110IcOHdra2qq0
-8cmTJ25ubn/99ZfacXZ7DU+NPxY+WaGV1/Gdwp4+51Wb5/viz8Lqc3YZzO5yuVwmk9XX16elpbW0tIwd
-O7ampoahMHUPJ9md8huotJEgiKioqPLy8tbWVpFINHXqVM3Exh6Wsju0Z0WcZPdXgarsfvfuXYSQk5MT
-/V29/fbb+/fvV9q4e/duT09PbZsmhz8X/oxdI54+fYoQGjhwoBqHUZzvW1lZGRQUZG5ubmpqGhgY+PDh
-Q1xGKpXGxcW98cYbZmZm27ZtU9rDzZs3+Xx+cnIy5fxgfEbT03FJ+LPgz8UqBrO7sbGxu7t7cnLyggUL
-1q9fjzdS1gllfba1tS1dutTKysrKymrp0qVtbW14u0QiiYyMNDc3t7Ky2rJlC3k4LZ+NreW/3fsSlrI7
-zfbc+QuuqmV2bvbqdQ6c4Da7q+oc2traIiIicOeQmJio/dXYWefsjn9h9yidxcbGJiUlKXbgEolk165d
-K1euVJWVFFe2UNXHKtYnU60Xn2c8efKk25IELmRqakp/75RmzJgRGRlZW1t79+5dGxub2NhYvH3z5s1X
-rly5cOFCdXW10rTyzMzMDz/8cNeuXdHR0ZTzg/Fvpp6OS8Kfhc6HZwSZ3X/44Yfe723hwoW//vorfk1Z
-J5T1mZCQUFpaWlBQUFBQIBKJNm7ciLdv3LixsrJSJBIVFBQoTnzUidnYitkdBiKxiszu165dY3bPXbfn
-zl9wVS2zc7NXr3PgEJndS0pKNHlcVZ1DfHy8WCwuKSm5detWdna2JkNilmJ2r6ysRP/mP5oEAoG9vb3i
-zNUjR454eHg4OTmpao2KK1uo6mMVMdV68fkKrdRmZGREEERHR4ecNjKgurq62bNnz549W6nA06dP+Xw+
-fu3o6FhSUtJ5Dzt37rS2ts7Pz8dbnJ2d//jjD/y6oaHhjTfeUDoWfTt37kQI4ft8zKJT9f369aNfmZ0/
-nUQiMTAw6KJOKOvT3t6+tLQUvy4pKXFwcMCvHRwcFLeTh1NV23QcOHCAjertulbxWe20adPox9kHbNiw
-gfGqptOGHR0d1QtYjfas9BZVLVNVN6JenHK5fM2aNSz1EjQr2dPTU+3gVaGsEFWdg729fXl5OX5dWlra
-m8qktHjxYsZruNtft7hAeHh4j0K9ePHi+PHjyX+6urrm5eXJVbfYmpoasrCqPlaxPplqvdXV1QghZ2fn
-bkuq+TxWXH0WFha+vr7bt29HCBUUFKxataqwsBBfCdHT08Mla2trKW/eJyUlhYSEjB8/Hv8Tzw8m/5fm
-d6MLBEEw/rRZiUQiZ/nHwf379wcPHoxfU9YJZX3W19eTT+FzdHSsq6vDr+vq6hS3k+V7X9vMVq9cLpdI
-JN0W08VLhb2np6dHfpt6j7wM2wUG67nb9qxEVRlV3UgvMVu3JA1XctdUdQ719fXDhw/Hr9l7hiezNSyT
-ydrb27st1tMO7d1339XT07t48aKPj09WVpa5uTmeL62qNSqubKGqj1XEbOul03KIgQMHymSy58+f92jX
-+KRAcb7v7NmzQ0JCqqqqpFLpo0ePyAm+w4YNo5yTkJOTc/z4cfKGhKr5wWq0fnyZ4osvvmhl2ptvvqnq
-oK6urkeOHEEIGRgY9OakZN++fR988AF+TVknlPVpbW2NT+UQQlVVVTY2Nvi1jY0NuV1x1qOq2qZvwYIF
-DFZsFzfRCYKYOXPmV199hXp4ea3P+PLLLxms6i6eWTlx4kQ8gOj1119nKvhu27PSF1xVy6Rs9r1PjYmJ
-iQzWLdbU1NTFEQMCAr755huk7pAmNajqHKytre/cuYNfkwUYt3fvXgbrNjMzU9WBDAwMFi5cmJiYiBBS
-Y7RTbGwsfu/WrVtXrVqFN9LJSqr6WEVMtV6c2ui0HALfje79KLPm5mYTExNjY2OxWBweHk5unz9/flRU
-VHV19V9//bVs2TJyO5/Pz8nJSU1N3bRpE1I9P3jw4MHl5eU9igR/lt6PGKDJ1dX1+PHjRUVFvVmI959/
-/iksLFy6dGlqaqpQKMQbKeuEsj6Dg4Ojo6Nra2tra2ujo6PJWViffPLJsmXL6urq6urqli5dSh5OJ2Zj
-44xeXFx87NgxPp/PdTh92cSJE7Ozsy9fvuzp6cnIDum3Z6UvuKqWSdns1egcOBQQEJCbm3vu3Lkufh6w
-QVXnEBwcvHz58vr6+vr6+uXLl2syJGbhjF5RUbF37148YlyNwVWTJ0+ura3NyMh48OBBQEAA3kinn1TV
-xypiqvXSz+v/LdBG/yo/orox8NNPP40cOdLAwMDW1havxIm3SySSNWvW8Pl8MzOzpKQkpT3cv3/fxcVF
-KBR2dHSkpKQ4OzsbGRm5urqeOXMGF9i2bRv+GPTDW7RoEULowIED9N9C06hRoxSrDmd08m46vvhmYmJC
-f4d4Pzweb8CAAWPGjImJiWlsbCT/l7JOKOuzpaUlKirK0tLS0tIyKiqqpaUFb29tbV28eLGZmZmFhQU+
-G+1izzTh++s9vYPVtbKyMsWKxRld8Y7U4cOHEUJhYWEMHlT74fvrCQkJDO5T6fc6zujk/+I/hEAgUG/n
-arRnpS+4qpZJ2ezV6BxI+P46uSsGdf6NhDM6WeDSpUt4I+OH7ty9y1V3Di0tLeHh4bhzEAqF5DAIpuD7
-6/v372dwn0qzNnBGr66uJgvk5OQghHx9fdXYeUZGhr6+/qFDh8gtlK1Rqb2p6mMVizHVevHgvuDg4G5L
-vlh19uTJk/T3ruV8fHwQQhcvXmR8z2ReV8romBp5XRexmtc7Z3QM8jpTyLyulNGxXuZ1HaKZvK6U0TH2
-8rraiouLhw8fzuw+Wc3rnTM6hu8s9GggsA7B17ZXr17dbUkCr87Wl2YJ45Xm3Nzc2Ng5edU9KCio94P7
-AEnxqvvo0aOZ2i2Px0tMTLS0tDQ3N//ss8/I0XlKk1BVzfGlXC2AclZrdna2QCDo16+fnZ3dvn37cEnK
-jZwjr7q/9957XMfSZ5FX3blaqJyOZcuWNTQ0iMXi5cuX4ydmaT/Fq+7kuD+SnZ2dubm5WCxmdRVUruCV
-5ugskUuwuuqq5uGV4W1tbemvI0jfl19+WVxcDBmdcUOGDLl//z6zGZ10/vz5W7duiUSiiooKfMKLKU5C
-VTXHl3K1AMpZrfPmzVu7du2TJ08uX758/fp1XJJyI7f27NkDGZ1VRkZG9+7d0/KMjtnZ2Y0fP97Dw8Pe
-3j4+Pp7rcLrn5OTU1NREmdFJ9BdR1zk9yOtjx45FCF2/fl2uI8s7dC0/Px8hhD8U46ZPn/5qTrVi2+DB
-gy0sLFjaeXJyso2NjY2Nzddff52RkaG4nXy8+uHDh5OTk/l8Pp/PT0lJwZf9EULp6ek7duxwcHAwMzPD
-8zmRimex6+vr19fXNzU12drakj/NKTdya968eVyH0McZGRnpyjDP6Ojoe/fuNTY27tmzp3///lyH0z07
-O7tuR43htJebm6uRiDSnsbHx9u3bpqamdCYlEra2tiNHjmxqasrLy9NAcGw7c+YMQsjX15frQIC2IL8G
-Dg4O5ORd9PIkVFVzfCknnlI+i/3MmTMXLlxwd3d3cnIil52i3AgAYA8ezX7ixAmuA2EY/kQBAQG05q8j
-9N/QObYjY1tbW1tmZiZBEB9//DHXsQBtQc4ura6uJifvopfnj6qa40s58ZRyVqtAIDh9+vSDBw+2b98e
-FhaGS1JuBACwZ9KkSUOHDi0pKVGaZaPrjh07hhCaNWsWncL/5fXjx4/r+qX4rKysp0+fenl5KXbf4BVH
-zi5dtmzZnDlzKMuomuNLOfGUclZrcHBwWVkZXgyLHH5BuREAwB49Pb0ZM2YghA4dOsR1LIy5d+/e1atX
-TUxMPvzwQzrlCYSQQCBwcXERi8X4jEB34emDc+fO5ToQoEXef/99gUDg6urq4OCAZzd1tm7dOhcXl3Hj
-xo0bN27UqFFr167F21euXDlhwoR33nnHwcGBvG5P+Sz2qVOnBgYGmpqarl+/nuxQKDcCAFgVHh7O4/G+
-+eabx48fcx0LM4RCoVwuDw4O7mK9yJfga4l4oNCoUaN69AAYrYIfG2VtbU0uvKBhMH+dPWrPX0dMP81C
-k9iYv941mL+uAVo4f50NbMxfpw/fil21ahUnR2dWZWWlvr6+kZGRWCym+ZYX1wZnzZo1cuTI0tLSgwcP
-MnuioRkymWzFihUIoZiYGLpnNAAAAPoioVBIEMSOHTsaGhq4jqW3IiIipFLpp59+qjjUt2sv8rqenh5e
-/HXJkiWUj2nRcl988UVRUZGDg0NkZCTXsQAAAODS6NGjFy5c+M8//wQEBLS0tHAdjvqSkpKys7MHDBhA
-3hyk47+xPH5+fmFhYc+fPw8ODpZKpSxEyJbLly8nJCQYGBh8//33jD+bFeg0uY4PBQUAqGf79u1ubm7F
-xcWhoaE62g9cuXIlJiaGIIiTJ0/2aIWPl8bopqSkODk5FRQU/O9//3v48CHTQbLi1KlT/v7+Mplsw4YN
-+Bk2AAAAXnH9+/c/ceKEiYnJsWPHPv74Y7zesw45fPiwr69vR0dHXFycn59fj977Ul43NjY+f/68i4tL
-fn6+p6fn6dOntfk05/nz55GRkUFBQa2tratXr46JieE6IgAAANpixIgR58+ft7KyOnv2rKenZ2ZmpjZn
-NFJTU1NoaOjcuXPb2trWrFmDV6ruEeWr1ra2tteuXfP3979x40ZgYOCYMWN8fHzGjRtnYGDAUMwMqKmp
-yc/PP3v2rFQqJQhi9+7dik98BwAAABBCHh4e+fn5/v7+paWlkydPdnNzmzRpkoeHh5GREdehKZPJZGVl
-ZcXFxZmZmTKZzNDQMC0tTdWSG12juBttZmb222+/ZWRkCIXC4uJirX0kDI/HCwwMFAqFSo9FBwAAALBh
-w4YVFRWlp6dv2rRJJBKJRCKuI+qGoaHh/PnzY2Nj7ezs1NsD9SgzfX390NDQ+fPnX79+/caNGyKRSKtG
-0g0dOnTUqFFeXl6d1+4GAAAAFBkaGoaHhy9atCgvL+/WrVtFRUXkI5u1B4/Hc3R0dHFx8fb2Hjp0aG92
-1dXocR6P5+3t7e3t3ZsDAAAAAJzj8XheXl7a//zc3oM1qwEAAIC+A/I6AAAA0HdAXgcAAAD6DsjrAAAA
-QN8BeR0AAADoO2A1dYY9e/ZMq9bwYRyHCzalp6fr6PMG1SOTyTg5bmFhYd9uw4i7uiVlZWX17UrmvIZf
-ZZDXmfQqPHWGx+Pp6+vr6elp8qAEQbwKdauE+JfGjoj/uBo7HIc0X7ekV6SSOaxh8H9ZpgkclhMrzwAA
-AABJRU5ErkJggg==
-" />\r
+<div class="imageblock">\r
+<div class="content">\r
+<img src="./snort2x.png" alt="Snort 2" width="480" />\r
+</div>\r
+</div>\r
<div class="paragraph"><p>The steps are:</p></div>\r
<div class="olist arabic"><ol class="arabic">\r
<li>\r
stateless packet decoding, TCP stream reassembly, and service specific\r
analysis in both cases. (Snort 3 provides hooks for arbitrary inspectors,\r
but they are not central to basic flow processing and are not shown.)</p></div>\r
-<img alt="snort3x" src="data:image/png;base64,\r
-iVBORw0KGgoAAAANSUhEUgAAAxcAAADGCAIAAAAvyOp8AAAAA3NCSVQICAjb4U/gAAAACXBIWXMAAAfQ
-AAAH0AG5i+efAAAgAElEQVR4nO3de1wUVf8H8LPLIvcQUFxBURRU5CZqiVlpaiJor4zHkPRXlJaigKJm
-iqaGqV28glj2aFlqTyqZWqGWPiZmYt5FBEWuCioIJojsctv5/XFqn21vLMPsDOx+3n/w2j07l++cnT37
-3e8MM4QBTk2ePJmYDQcHB567d8GCBUJvtJBSU1N57vA5c+YIvdF8k8vlPHcywzCrV68Werv5VlxczH8/
-l5WVCb3dvFq6dCn/nWxuJEK/y6ZJLBaLRCKhozAihmEUCoVQaxeJRGKxWKi1C0KhUDAMI9TazaTDm5qa
-hA0A/cwbCwsLoUMwLmFHDLOCLMoovvnmm8jISKGjMKLa2lo7Ozuh1r5mzZr58+cLtXZBREZG7tmzR6i1
-JyUlxcXFCbV23tja2spkMgEDWLx48cqVKwUMgB+enp5FRUUCBiCVSu/evStgADxYvXr1kiVLhI7CLJj+
-7x4AAAAAY0AWBQAAAMAGsigAAAAANpBFAQAAALCBLAoAAACAjWb+R6+4uPjChQsXL16sr6/nJyBDiESi
-3r17+/r6BgUF2draCh0OAAAANKOuri4zMzMnJycnJ6ctXPBCk6urq4+PT1BQkJubm4Gz6MyiMjIy3nvv
-vePHj3MUm1E4OzsvWLAgLi5OwP+6BwAAAD1qa2s///zzNWvWtJdrTISFhS1dujQ4OLjZKbVkUU1NTW++
-+ebOnTsJIU5OTs8880xwcLC1tTX3YbKlUCiys7OvXLly8eLFhISE5OTkY8eO9e/fX+i4AAAA4B8yMzND
-QkLu3btHCPH29n7yyScDAwMlkrZ4ucrbt2/n5OScPn360KFDhw4dioyM/Prrrzt06KBnFvXNqK2tjYiI
-SEtLs7OzW7Bgwfz58+3t7Y0Zc6ucPXs2Jibm/PnzwcHB+/bte+GFF4SOCAAAAP7y3Xffvf766zKZbNCg
-QStXrhw7dqzQETWvqqpq/fr1GzZs2L17d0lJyf79+zt16qRr4n+cXc4wzLhx49LS0lxdXdPT05cvX96W
-UyhCyFNPPZWRkfHGG288evRo/PjxmZmZQkcEAAAAhBCyb9++V155RSaTxcTE/PHHH+0ihSKEODo6JiYm
-ZmRk9OzZ89SpU88995yeuxr8I4tav379iRMnXF1ds7OzBw0aZPxQOSCRSLZv3x4VFVVfXz9hwoSqqiqh
-IwIAADB3N2/enDp1KiFk/vz5KSkp7e7ehb6+vpmZmT4+Pjk5OTNmzNA12f+yqKysrISEBJFI9NVXX7m4
-uPASJGe2bt06ZMiQwsLCWbNmCR0LAACAWaurqwsNDa2urn711VfXrl0rdDgsOTg47N+/38HBYefOndu2
-bdM6zf+yqLlz5zY0NMyZMyc0NJSvCDljaWm5b98+e3v7//znP2fPnhU6HAAAAPP1+eef5+fne3l56Uo+
-2ou+ffv++9//JoQsWrSourpac4K/sqjTp08fO3bMycnp/fff5zM+Drm7u8fHxxNCVqxYIXQsAAAAZurx
-48erV68mhCQlJZnANR0jIyNHjhxZWVm5fv16zVf/yqJo5jFnzhxHR0deo+NUfHy8g4PDoUOHrl69KnQs
-AAAA5mjTpk1lZWXDhg0LCwsTOhZurFy5khCybt26P//8U+0lMSGkpKTkl19+sbe3X7BggQDRccfFxSU6
-OpphmC1btggdCwAAgNlhGIYeAktMTBQ6Fs4MHTo0NDS0pqbmm2++UXtJTAj5/vvvGYYJCwszgcrblClT
-CCH79+9XKBRCxwIAAGBezp49W1hY6OHhMXLkSKFj4dIbb7xBCNmzZ49au5gQsm/fPkLIv/71L96j4l5g
-YKCXl9fdu3czMjKEjgUAAMC87N69mxASEREhEomEjoVL48ePt7OzO3369O3bt1XbxQ8fPvztt9+sra3H
-jx8vVHDcCg8PJ4T89NNPQgcCAABgXg4ePEgImTRpktCBcMzW1vbFF19UKBQ//PCDarv4ypUrDMMEBQXx
-eTjPqCnqs88+Swi5ePGiMRau9R8d25e2/PvABLq3fUGH86O8vFzoEMyCQqFoamoSOgpT1uyIUVFRUVhY
-+MQTTwwcOJCfkDQZ7ztuxIgRhJDz58+rNoqvXLlCCAkMDDTSWvlHt4VuF+cSEhImTJhw6dIlYywcNm3a
-NGrUqJMnTwodiLlYu3btmDFjfv/9d6EDMUhb/gGgX2pq6rBhw3755RehAzFxDQ0NUqn0o48+qqmpEToW
-0zRmzJi4uLjS0lJdE9AvxwEDBojFYl3T8IbzEYOmhmo1GvHly5cJIQMGDGhRZJRUKo2KiqqsrOQ2UM3V
-tWj67t27u7i4lJWV0TtIc4thmIMHDw4aNIjDXIp2plgsdnR0DAoKWrRo0f379zlZcnt0/Pjx4cOHGymX
-qqqqSkhI6NOnj62trbOz84QJE/773/+S9vz13HpHjx595plnuM2ldPVzKzEM0/qFCOX06dMhISFGyqXY
-jSGt2e3b7EemoqIiISHB09OT51yqzXYIt+rq6lJSUry8vHTlUjTDaFEhqmvXrnK5XK3x4cOHAQEBmpcV
-aBH9IwaLt8zf39/S0jInJ0c1YPHNmzcJIf37929pcAzDXLhwQSaTzZ49u6WhGBvdnNzcXCMtn/NcimEY
-hUJx586dL7/8UiaTDRgwoKioqPWLbb+MlEtNmjSpsrIyLS3t4cOHN27cmDx58gcffMDh8tsvbnMp9LMu
-xsulMIaoEiqXMhNyuVxXLnX9+nVCiL+/v+FLe+aZZ7Zv367WuGXLliFDhjg5ObU+Wg5ZW1t7e3s3NDTk
-5+crG8U012N34zx3d/eUlJSff/6ZEJKbmztx4kQXFxdHR8fw8PCKigo6TWNj47Jly3r06OHk5LRu3Tq1
-JVy4cKFbt25JSUmEEIVCsXLlSk9PT2dn56lTpz5+/Jj8nS3SX1qGB0Y35+HDhyw2ynCc51J2dnZBQUFJ
-SUnTpk1bunQpbdTaLURHx9bV1cXHx0ulUqlUGh8fX1dXRwipr6+PiYlxcXGRSqVr1qxRXaOuhbcRnOdS
-J0+eXLNmjbe3d4cOHTp37hwREXHixAnNfUwkEm3YsKF79+60KK2rl3Tt8yKR6LPPPuvVq5eVlZWfn9+p
-U6e++uqrPn362NjYDB06lI4ybRNXuZTWfia6e1LZ4SKRqHPnzqo/QB88eNClSxfaonyDtO78bXxnVmW8
-XMrwMURzt9c6mdauZjcs80/wXErrgEzbZ86cScfkTz75pI13oy5acyn6Ue3UqZPhy0lISFi/fr3qxYnq
-6+s3b968YMGCZkcMOkTr+o7TM2Kw3ofppqmOUeKqqipCSMeOHVu0IE2vvPJKTExMSUnJrVu33N3dExIS
-aPvHH3/822+/HT9+vKCgoKSkRHWWn376KTQ0dPPmzXPmzCGEbNy48cSJE8ePH8/Pz29oaFi2bBn5uyJH
-S1+GB0OvwG7sLIoyxjG+t95669ixY/Sx1m4hOjp21apV165dO3/+/Pnz5zMzM+k1+FevXp2bm5uZmXn+
-/PnDhw+rrkjXwtsUDnOpESNGTJ8+/ffff5fJZMpGrftYenr6H3/8QT/YunpJ1z5PCElLSzt69OiDBw8m
-T54cFha2f//+I0eOVFRUvPjii9HR0a3cCmNrfS6ltZ+J3v2NdjjDMBMnTqSX7KP+/e9/T548We0nqdad
-v13szKqMeoyv2TFEc7fXOpnWrmY3LAtFNZfiObfWOiATQlauXFlcXHz16tWLFy9ycrBbQGq5FP3abVFG
-MXDgwF69etErLlHffvvtU0891adPn2ZHDDpE6/mOozR3Y9b7MN001exC5ODg8OjRo5qaGjs7OwOXIhKJ
-6Irv3Lkzf/58us2qE1RXV/v6+tJrKnh7e+/fv9/Pz09tCSkpKatXrz5w4MCTTz5JG318fA4cONC3b19C
-SFlZ2ZAhQ2hFWrk6w8XHxyclJQ0ePJgujUNnz56lx0B1cXV1LS8v//bbbyMjIw1cpuYGNjQ02NnZ1dfX
-E93dorVje/fu/eOPP9IDmllZWRMmTMjLy/Py8vrhhx+Ujf7+/srV6Vp4s2pra+3s7CwtLSMiIgzcTENk
-ZWXp/7cADw+PW7durV27lu54LVVdXb127doffvjhxo0bbm5u4eHh7733nqOjo9pbIBKJioqKevToQZ8a
-0kuq+7xIJLpz507Xrl3J3x119+5dqVRKn3bq1Km2tralkUdGRu7Zs+fZZ5/18PBgseG6XLlyJSsrS88E
-dH9OTk6Oi4szfLG6+lnPZ1zZ4devXw8JCcnPz5dIJI2Njd7e3unp6XSrlW+T1p2f9c6sZGtrK5PJIiMj
-LSwsWjRjs3Jzc8+dO6dngk6dOlVUVCxZsoTeaKKl2I0hanNpnUxrV2tdo+E8PT2LioomTJhg+JeOgRQK
-hdqXkRpnZ2da3eT8rFmtHaJ1QKbtaWlp/fr1I4RkZ2f7+vpyno+uXr16yZIlfn5+3P7r2KFDh/Scq2Rh
-YeHo6PjgwYPMzMwWHdQ7ceLEu+++e/bsWfo0ICBg27ZtTz31lCEjBiFE13ec/hGD3T4cFRW1Y8eOHTt2
-vPbaa381KY9ZMAZTLs7V1XXKlCnl5eUMw5w7d27kyJHKn4wWFhZ0Ymtra5lMprmEXr16JSQkqDba2Nio
-xioWi5UTGx4btWjRopZ2Dbc+//zzFvWnWktxcXHXrl31d4vWjlVtlMlk1tbWmo2qq9O18GYJe7jkvffe
-M7x7tVIoFFlZWVFRUePGjWM03gLyz0+Erl7Stc9rLk3PUwMJe/GVFStWsIiZ0ehnPZ9x1Q4PDQ3dvXs3
-wzDffvvt5MmTNbtO687PemfWtQT+RUVFtTRmtZ5RMmQMUZtL62Rau1rrGg3Xs2dP/vpUGxsbmxZ95RlC
-a4doHZBpu1wuV7a3pjN1WbVqlYA9nJWV1dKAg4ODjx8/zjDMkSNHRowYQRsNHDF0fccRvSMGYdXtM2bM
-IP/8ipc4Ojr++eefVVVVLSrBMRoZXGRk5LJly1JTUx0dHauqqpQnWnXv3j0vL0/zp0x6evrzzz/v5OSk
-vHmfh4fHkSNHND9gLI4Z02taTJs2bfTo0S2dV78vvvhCWSfX5Orq6ubmdvny5SeeeKI1a9m2bZsycl3d
-orVj3dzcCgoKaEqel5fn7u5OCHF3d1c2qp4Tp2fhBrKxsfnyyy/ZzavVgQMHNK+vrySVSn18fH799dfW
-H4AWiUS+vr4bN25UFjk0J1A+1tVLuvZ544mPjx8yZAiHC0xNTf3+++91verk5OTt7X327FnWHa7Wz3r2
-N9UOj4+Pf//99ydNmpSUlPTpp59qTqx152/lzqy0c+dOiUTSyoWo+eWXXzTPn1Wyt7cPCAg4ffp0t27d
-uFqjIWOI2m6vdTJdA3jrT+VJSUnh/CPT0NDw+uuv63pVLBaHhYX99NNPtPzM7aq10jog0/bCwkJaiyoo
-KDBeAOHh4a+88gqHC1y0aFFxcbGuV729vRmGycvLU54BZriEhIRPPvnk+eefX7t27cKFC2mjgSOGnu84
-SutuzG4foNnFP77iPT09CSFFRUWG52JEWwYnlUr3798vl8vz8/PpzWRo+6pVq0aMGJGfn//gwYP4+HjV
-JZSWlvbt23f16tW0cePGjaNHj87Ozq6rq8vMzJw0aRJt79y5c3Z2douyRXo3vf/85z8tmssQM2fO1Nqz
-np6eW7dura+vnzx5MiHk22+/NXyZyr56/PjxxYsX58yZQz9jtFFXt2jt2CVLlowePfr27du3b98eOXIk
-rdksXbp0zJgxJSUlJSUldGBVrlrXwptFa1EODg6Gb6YhdB3OkEql69evf/z4Mc25165dy275w4cP37Nn
-z7179+rr6wsKCmbMmBEaGspo7GNqe7iuXtK1zxOj1aJSU1NZzKuH8gRkNW5ubklJSTKZjJ6zmJyc3KLF
-6upnXT2p2Se+vr6bNm0aPXq0aqP+UYX1zqxEf/gqiwQcSklJ0drPLi4uq1atqq6upmfMLFmyhN3y2Y0h
-aru91sm0drXmvC1CvxSLi4vZza6H5j/MU2KxeOLEiZmZmWVlZXQ84XzVWj/XWgdk2h4aGlpaWlpaWhoS
-EsJuTNCP1qKWLl3K7WJ1XRQpODj4yJEjDMPQr5hjx461dMkKhcLPz2/Hjh2BgYHKRgNHDF3fcfpHDHb7
-cGhoKCGEbuxfa6GdQq9gbiCtb3laWlrfvn0tLS09PDySk5OV09TX1y9evLhbt25OTk7r169XW8Ldu3d9
-fHzo8YKmpqbk5OR+/fpZWVn5+/sfOHCATrNu3Tr6U9jwCMeNG0cISUtLM3wWA2lmUcr8iU7ALosihIhE
-Int7+8DAwHfffbesrEz5qq5u0dqxMpksLi6uS5cuXbp0iYuLozVMuVweHR3t5OTk6ur6ySefqPakroU3
-i7csSpk/0QlamUX997//ffnll52cnKytrT09PWNiYiorKxmNfUxtZ9PVS7r2edKesyhl/kQnYJdF6epn
-XT2p2Sdbt24Vi8U///yzaqP+UYX1zqzEZxalzJ/oBK3PoliMIWq7vdbJtHa15rwtwmcWpcyf6ARGzaLU
-MDoGZNo+ffp0OiavWLHC0tKS83h4y6KU+RM1ceJEQsh3333HYuG0DLxr1y5li4Ejhq7vOP0jBrt9eOjQ
-oYSQM2fOKFsITdxUe8EEDBo0iBBC/+WHW6pZlFr+RLHIotojHrIotfyJamUW1X7xkEWp5U8UuyyqneIn
-i1LLn6hWZlHtCz9ZlFr+RBkvi2LtypUrnp6enC+WhyxKLX+i6FekCY8Y9JT2vLw8ZYvY19eXEJKZmamZ
-SrdTjY2N165dE4vFLb2UqOFo/nTjxo233nrL0tLSSGsxWzR/ys/Pnzt3Lp+3dzRbNH/Kz8+fPXu2tbW1
-0OGYLJo/FRYWLl682MHBQehwTBbNny5fvpyamtqi/xTj09y5c+/du1dcXDxv3rwJEyYIHU7L0PwpIyOD
-Ho5UFRAQQP6+D4zpqaysLC4udnBwoKdCURKaWtL7wJiGGzduyOVyb29ve3t7zhfu4eGxdevWqKgoJE/G
-0Llz5/Xr10dHRwv+31JmQiqVJiUlTZ8+HcmTUTk7O69atWr27NnGGJRA1cSJExMTE433E5orPXv2fPLJ
-J+vr61966SV2l7cQxJNPPvnRRx9pJk9KWu80ZzK03iVQQi8mYUpZFN0WI91fWfBrKJi26dOnCx2CeZk1
-a5bQIZiFV199VegQzIKVlVVqaqrQURhkzpw59HB5+6J6RVyt/P39JRLJtWvX5HK56f02u3DhAtG4S6DY
-19fX2to6JyeHXjDQBNALAQcHBwsdCAAAgBmxsbEJCgpqbGw8evSo0LFw79ChQ4SQp59+WrVR3KFDh5de
-eolhGD2XjWlH6uvrf/zxR0JIuzvSDAAA0N7RK1Tt3r1b6EA4VlpaeurUKVtb27CwMNV2MSGEXurGNLKo
-48eP//nnnwMGDOjdu7fQsQAAAJiXiIgIkUj0448/qt1Gs71LTU1VKBTjx49XO7tRTAgZN26cjY3NqVOn
-9N8hrl3Ytm0bIYResgIAAAD41KNHj6FDhz569GjHjh1Cx8KZpqYmeh8FzTvkigkhtra2b731lkKhSExM
-FCA67mRlZe3fv59ujtCxAAAAmKN33nmHELJy5UpdV5Nvd3bu3Hnz5s0+ffq8+OKLai/99d967777rpWV
-1e7du+kdp9upDz74QKFQzJgxo0uXLkLHAgAAYI4mTJgwePDgkpISrffBbHfq6+uXLVtGCElMTNS8yeZf
-WVS3bt2mTZvW1NRE//IdIxd++umn1NRUa2tr5Y0MAQAAgGcikYheBGv58uU5OTlCh9NaCxYsuH37tr+/
-f0REhOar/7ty1IoVK7p163by5Ml2dAUwpTt37kydOpVhmA8//BCFKAAAAAGFhIS88cYbNTU1EydOpHcM
-a6dSU1OTk5OtrKy2b9+uerFNpf81ubi47Nq1y8LC4oMPPkhLS+MxyNZ6+PDhuHHj7t+/HxYW1h6vYwYA
-AGBiNm/e7O/vn52dPW7cuJqaGqHDYePUqVNTp04lhGzcuJHen1fTPxKr4cOHp6SkNDU1vfjii+3lcGZx
-cfGgQYMuX77s5eW1d+9ekUgkdEQAAADmztbW9rvvvrOzs0tPTx80aNCtW7eEjqhltm/fPmLEiJqamsmT
-J0dHR+uaTL08FR0dvWnTJpFIFBMTM2DAgGPHjjEMY+RQWSooKHjnnXf69etXUFAwcODAU6dO2dnZCR0U
-AAAAEEJInz59rl275ufnl5ub26dPn9jY2OvXrwsdVDMYhjl06FBAQMDUqVMVCsX777+/a9cuPdOrn21O
-CImNje3evftrr7125cqVF154QSQSDRs2rE3dfJdhmN9//72hoYEQIhKJYmNj165da2VlJXRcAAAA8D89
-evQ4d+7cggULNv9NIpE8/fTTFhYWQoemxe3bt/Pz82nxyMHB4YsvvqCXYtdDSxZFCHnppZfu37//6aef
-7tq169KlS6dOneI+2FazsLAICwtbt26dt7e30LEAAACAFtbW1ps2bZo/f/7ChQvT09PLyspOnjwpdFA6
-iUSiwYMHT506ddq0aR06dGh2eu1ZFCHEyspq7ty5c+fOVSgUGRkZbe3yB15eXm5ubkJHAQAAAM3r2bPn
-nj17CCGNjY0ZGRlt82QhV1fXvn37tugEa51ZlJJYLB42bFgrogIAAAAghBCJRPLss88KHQVntFz8AAAA
-AACahSwKAAAAgA1kUQAAAABsIIsCAAAAYKP5s8uBhcuXLzs6OgodhRHJ5XIB1379+vXDhw8LGAD/7t69
-K+Das7OzzaHDFQqFsAHk5+ebQz/LZDJhA6irqzP5fs7NzRU6BHOBLMooPv74448//ljoKEzWtm3btm3b
-JnQUZmTLli1btmwROgrTt3v37t27dwsdhen7888/w8LChI4CTASyKI4FBQVVV1cLHQVPbGxseF6jj4/P
-+PHjWc9+8uTJ6urq4cOHOzg4cBgVb7p27crzGn19fVl3+NGjR+vq6saMGWPIlevaDq23bTc2Ly8v1v2c
-np7+6NGjESNG2NvbcxuVUfE/ehBCrKysWjOAtDt9+vQROgTTJ2qbV74CMIbAwMDMzMysrCxfX1+hYzF9
-Xbp0KS8vr6iocHFxEToWUxYQEHD16tVr1671799f6FgAzA7OLgcAAABgA1kUAAAAABvIogAAAADYQBYF
-AAAAwAayKAAAAAA2kEUBAAAAsIEsCgAAAIANZFEAAAAAbCCLAgAAAGADWRQAAAAAG8iiAAAAANhAFgUA
-AADABrIoAAAAADaQRQEAAACwgSwKAAAAgA1kUQAA7d7Dhw+FDgHAHCGLArPzzTffCB0CAMcuX74sdAgA
-5ghZFJidW7duCR2CWWhqahI6BLPQsWNHoUMAMF/IosCMTJkyRegQzEhtba3QIZiFwMBAoUMAMF/IosCM
-dO/eXegQzI6FhYXQIQAAGAuyKAAwIhsbG6FDAAAwFmRRAAAAAGwgiwIAAABgQyJ0AAAAYKiGhobCwkLV
-FnqlqPLy8tzcXNX2Pn368BoZgFlCFgWmLC8vr7GxUfn0zp07hJDq6urr16+rTtazZ09ra2u+gwNoOQsL
-i/Dw8GvXrqm1JyYmJiYmKp+Gh4fv27eP39AAzJGIYRihYwAwlrfffnvbtm36p/Hw8Lh582aHDh34Ccl8
-2NraymQyuVxuZWUldCwmZe/evZMmTdIzgUgkunTpEq6AAMADnBcFpmzx4sWWlpbNToMUCtqRiRMn+vr6
-6png5ZdfRgoFwA/UosDE6S9HoRDFlfLy8vLyctWWwYMH19XVXbhwQbV7XVxcunbtynt0pkZPOQqFKAA+
-IYsCE1dYWNi3b9+Ghgatr27ZsmXGjBk8h2SSzpw5M3To0GYnO3z48NixY3mIx7QpFIqAgADNs6MIzogC
-4BeO6IGJ8/T0jIqK0vqSh4fHm2++yXM8pio4OLjZ9MiQacAQYrF42bJlmu0ikUhrOwAYCbIoMH26zo7C
-GVHcWr58eSsnAMNpPTsKZ0QB8AxZFJg+reUoFKI4p7/UhEIUtzTLUShEAfAPWRSYBc1yFApRxqCn2oRC
-FOfUylEoRAHwD1kUmAW1chQKUUaiq+CEQpQxqJajUIgCEASyKDAXquUoFKKMR2vNCYUoI1GWo1CIAhAE
-7gBjajIzM+VyudBRtFFhYWEHDx6USqV+fn5nz54VOhzTJBaLhw4dmpGRoWzx8/NzdnZGhxvJ5MmT33vv
-vfDwcPRwm9WxY0fc1tBU4XpRpsbLyys/P1/oKAAA4C+hoaGHDh0SOgowChzRAwAAAGADWRQAAAAAGzgv
-ytQMGjRIKpUKHQVoV1RUVFpa2rt3b3N4j7KzsxsbGwMCAvhcaW5u7v379wkhPj4+zs7OfK7afFRVVWVl
-ZRFCnJ2dfXx8hA6nHejfv7/QIYCx4LwoAJ6UlZX16tWrtrbWTG6BfObMmaqqqpCQEN7WeP36dT8/v6am
-JkLIwIEDz58/LxKJeFu7+RgxYkR6ejohRCQSnTt3btCgQUJHBCAYHNED4MmaNWtqa2sJIbdu3fryyy+F
-DsfogoOD+UyhCCEffPABTaEIIRcvXvzxxx/5XLuZOHHiBE2hCCEMwyQmJgobD4CwUIsC4IOyEEWfmkk5
-ik+qhSgK5ShjUBaiKJSjwMyhFgXAB2UhijKTchSfVAtRFMpRnFMtRFEoR4GZQy0KwOjUClEUylEc0ixE
-UShHcUutEEWhHAXmDLUoAKNTK0RRKEdxSLMQRaEcxSHNQhSFchSYM9SiAIxLayGKQjmKE7oKURTKUVzR
-WoiiUI4Cs4VaFIBxaS1EUShHcUJXIYpCOYoTugpRFMpRYLZQiwIwIj2FKArlqFbSX4iiUI5qPT2FKArl
-KDBPuHY5gBHpKURRtBwVHR3NW0gm5tdff33hhReUT2tqak6dOuXg4DBs2DDVybKzs5Ws66MAAAx5SURB
-VH19fXmPzkQUFhba2NiMHTtW2XLmzJmHDx8GBwd37NhR2XjixAlkUWBuUIsCMJbGxsaIiAi5XK5sycnJ
-KSoq6t+/f48ePZSNnTt3/vrrr4UI0ATRbMnf3z8zM1PoWEzZsGHDTp8+nZGRERwcLHQsAEJCLQrAWCQS
-yffff6/aEh8fn5SUNHPmzNjYWKGiAgAAruDscgAAAAA2kEUBAAAAsIEsCgAAAIANZFEAAAAAbCCLAgAA
-AGADWRQAf2QymdAhmDj0MD/QzwAUsigA/mRnZwsdgolDD/MjJydH6BAA2gRkUQB8s7GxEToEE4ce5oet
-ra3QIQAIDFkUAN98fHyEDsHE9e/fX+gQzAL2ZABkUQAAAABsIIsCAAAAYANZFAAAAAAbyKIAAAAA2EAW
-BQAAAMCGROgAAExWfX19TU2NaktjYyMhpLq6+sGDB8pGiUTyxBNP8B0cAAC0GrIoAGOpqKjo3bu3XC5X
-aw8NDVV9unDhwo8++ojHuEzKgwcPGIZRPqVpa11dXWVlpepkjo6OEgmGO5Zqa2vVLlZO+7yystLS0lLZ
-aG1tbWdnx3dwAIISqQ5AAMCtOXPmJCcn65nA3t6+sLCwU6dOvIVkYiIiIlJTU/VP4+bmlp+fb21tzU9I
-pueXX34JCQlpdrJ9+/aFh4fzEA9A24HzogCMaOHChfq/vGNiYpBCtcayZcvE4mbGsUWLFiGFao0xY8Y8
-/fTT+qcJDAx8+eWX+YkHoO1AFgVgRG5ubtOnT9f1qr29/TvvvMNnPKbHz8/vX//6l54J3Nzc3n77bd7i
-MVXLly/XP8GyZctEIhE/wQC0HciiAIxLTzkKhShO6C9HoRDFCf3lKBSiwGwhiwIwLl3lKBSiuKKnHIVC
-FIf0lKNQiAKzhSwKwOi0lqNQiOKQrnIUClEc0lWOQiEKzBmyKACj0yxHoRDFLa3lKBSiOKe1HIVCFJgz
-ZFEAfFArR6EQxTnNchQKUZzTLEehEAVmDlkUAB9Uy1EoRBmDWjkKhSgjUStHoRAFZg5X3YT2rbi4uL3s
-w2VlZcOHD6+rq4uOjl64cCGLJdjb26OCpUdWVlZgYKBCoSCEJCcnx8XFCR2RaRo2bNjp06cJIYGBgZcu
-XUIWBeYMWRS0bzY2Npq3WDFVUVFRX331Fc8rraysrK6u5nmlrMXGxh46dMjV1TU9Pd3KyorFEnr27Ml/
-WlBfX19aWsrzSln77bffoqKiCCGfffaZIdc01+Ti4oJ7R4JpwI2lwBT06tVL6BAM0tTUVF1d7eTk1NIZ
-a2pqysvLjRFSs1asWKH/JjZtUHl5uY+PD7t55XI5u/SrNW7cuBEQEMDzSltv5syZ7GZMSUmJiYnhNhgA
-QSCLAlOQk5PToUMHoaMwCMMwLEodu3bteu2114wRj4E6d+7s6OgoYACGq6iocHFxYdHJ+fn5wtbmrays
-unfvLmAAhqutrVUoFPb29i2d8f79+1VVVcYICUAQyKIAeNVOTyJZvnx5eykesMtTCSG2trYymYzzeAzX
-r1+/y5cvCxhAi7Dr52bvzw3QvuB/9ADApLTTPLXdQT8DEGRRAAAAAOwgiwIAAABgA1kUAAAAABvIogAA
-AADYQBYFAAAAwAayKAAAAAA2kEUBAAAAsIEsCgAAAIANZFEAAAAAbCCLAgAAAGADWRQAAAAAG8iiAAAA
-ANhAFgUAAADABrIoAAAAADaQRQEAAACwgSwKAAAAgA1kUQAAAABsIIsCAAAAYANZFACYDpFIpPYAdEEX
-AbQesigwd2vWrJFIJGvWrOFqgapfTiKRSCQSicViR0fHoKCgRYsW3b9/n6sVtSP4wgYAk4QsCsyaQqH4
-7LPPNmzYsGXLFoVCYYxVMAyjUCju3Lnz5ZdfymSyAQMGFBUVGWNFbYfonwghDMMIHZS5yMrKCgsLc3Bw
-cHBwCAsLu3r1qvIl5LIAnEMWBWbt8OHDTk5OcXFxLi4uR44cUbaLRKJPPvmkS5cuLi4usbGx9fX1+tub
-ZWdnFxQUlJSUNG3atKVLl3K/JW0Mo0LoWMxIXl7eyJEjR48effPmzZs3b77wwgujRo3Ky8sTOi4Ak4Us
-Cszap59+GhsbSwiZNWvW5s2bVV86evToxYsXMzMzb9y48eGHHzbbbqC33nrr2LFjrY+8fVE7yrlhw4bu
-3buLxWJCiEKhWLlypaenp7Oz89SpUx8/fkwI8fLyunbtGp3+66+/pg+uXbvm5eVFH+fm5k6cONHFxcXR
-0TE8PLyiooLX7Wmr3n///VmzZs2bN08qlUql0rlz586cOTMxMZH8/RYoq4PUli1bevbsaWNjM3To0Kys
-LNqo9R0hGm8cABBkUWDOCgoKzp079+qrrxJCIiMjz507V1hYqHw1KSnJ3d3d3d1948aNO3fubLbdQF27
-dq2srOQk/vYrPT39jz/+oIdQN27ceOLEiePHj+fn5zc0NCxbtowQEhIScvLkSUJISUlJXFzco0eP6Fxj
-x46lS3jllVdiYmJKSkpu3brl7u6ekJAg3Na0IceOHXvttddUW15//XWatdOioFp18Oeffz5x4kRFRUVo
-aGh0dDRt1PqOUKpvHAAQ8s/CO0C7Y21tTQipq6tjMe8777yj9nFYsGABfYkQIpPJ6GOZTGZtba2/XZXq
-x0rzI1ZcXNy1a9eWhkrTtaioqJbO2HqzZ88mhKSkpBg+i+Ygo9YnRUVFyqf9+vW7fv06fXzv3r0ePXow
-DHPw4MFJkyYxDPPRRx917tx569atDMNERET88MMPmqurqqrq1q2bcuFqDwxnY2NDCJHL5S2dsfUyMzMJ
-IYGBga1cjoWFhXL/pGprayUSCX1MNI603r17lz5+/PixjY0Nfaz1HWE03jh2WOxOAG0ZalFgpuRy+ddf
-f11YWKj8MBQUFHz11VdyuZxOUFBQoHzg7u6unFFXu4G2bds2evToVoff1qmOMpqvenh4KB8XFxf369eP
-HmmSSqW3b98mhIwcOTIjI4MQ8s0332zfvn379u2EkDNnzowcOZLOdf78+VGjRjk7O4tEIkdHx7t37/Kx
-VW2ei4tLaWmpasudO3c6deqka3qpVEof2NraymQy+ljrO0KpvnEAQHBED8zW7t27hwwZ0rNnT2WLp6fn
-4MGD9+zZQ5/OnTu3tLS0tLR07ty5U6ZMUU6mq12/2traS5cuxcfHf/HFFytWrOBuO9ol1VNzPDw8VHPZ
-pqYmQoi9vX2vXr327t1rY2Mzbty4xsbGgwcP9u7d287Ojs4VGRkZFRWVl5fX2NhYWVlJ54JRo0apHWXe
-sWPHqFGj6GMD/0dP6zvSoiUAmA9kUWCmNm/ePGvWLLXGmTNnKs8xHzVq1MCBA/39/Xv37r148WLlNLra
-daHXi+rSpcubb75pZWV16dIl1dQNZs6c+fbbb+fk5NTX11+9ejUyMpK2jx07dt68ef/3f/9HCJkyZUps
-bKzypChCyOPHj5944gk7O7vi4uLp06cLE3rbs3z58s2bN2/YsOHevXv37t3bsGHDp59+qjyxqVOnTjk5
-Oc0uRNc7AgBaGPuQIYBRtea8KD10fTSE+si0u/Oi9LSovdrU1JScnNyvXz8rKyt/f/8DBw7Q9kuXLkkk
-kvLycoZhysrKJBLJ5cuXlXOlpaX17dvX0tLSw8MjOTmZaJwOxeKdMoHzohiGuXLlytixY+3s7Ozs7EJC
-QlQ7bd26dR07dtTVRcqnut4RTnZ+nBcFJkbCd9YGAKaO0XGCudZXxWJxXFxcXFyc2iwDBgxoaGigj11d
-XZWPqbCwsLCwMOVT5ezKhWvGYCYCAgIOHz6s9aV58+bNmzdP+VSti5RPdb0jZtulAHrgiB4AAAAAG8ii
-ALTQ9bMbP8cBAEAJWRQAAAAAG8iiAAAAANhAFgUAAADABrIoAAAAADaQRQEAAACwgSwKAAAAgA1kUQAA
-AABsIIsCAAAAYANZFAAAAAAbyKIAAAAA2EAWBQAAAMAGsigAAAAANpBFAQAAALCBLAoAAACADWRRAAAA
-AGwgiwIAAABgA1kUAAAAABvIogAAAADYQBYFAAAAwIZE6AAAOPD5559LJKa8M589e1boEAAAQJ0pf/GA
-+Zg9e7bQIZi4kydPCh2C0TU2NgobQEVFxebNm4WNwdgyMzOFDgGAS8iioH2bOXNmQ0OD0FHwZMiQIUKt
-eu/evXv37hVq7WaitLQ0NjZW6CgAoAWQRUH7tn79eqFDMHHPPfccwzBCR8EfCwsL/lfq4uISFxfH/3qF
-EhAQIHQIANz4fwd4GWtRXdapAAAAAElFTkSuQmCC
-" />\r
+<div class="imageblock">\r
+<div class="content">\r
+<img src="./snort3x.png" alt="Snort 3" width="480" />\r
+</div>\r
+</div>\r
<div class="paragraph"><p>However, Snort 3 also provides a more flexible mechanism than callback\r
functions. By using inspection events, it is possible for an inspector to\r
supply data that other inspectors can process. This is known as the\r
<div class="ulist"><ul>\r
<li>\r
<p>\r
-lzma >= 5.1.2 from <a href="http://tukaani.org/xz/">http://tukaani.org/xz/</a> for decompression of SWF and\r
- PDF files\r
+asciidoc from <a href="http://www.methods.co.nz/asciidoc/">http://www.methods.co.nz/asciidoc/</a> to build the HTML\r
+ manual\r
</p>\r
</li>\r
<li>\r
<p>\r
-hyperscan from <a href="https://github.com/01org/hyperscan">https://github.com/01org/hyperscan</a> to build new and improved\r
- regex and (coming soon) fast pattern support\r
+cpputest from <a href="http://cpputest.github.io">http://cpputest.github.io</a> to run additional unit tests with\r
+ make check\r
</p>\r
</li>\r
<li>\r
<p>\r
-cpputest from <a href="http://cpputest.github.io">http://cpputest.github.io</a> to run additional unit tests with\r
- make check\r
+dblatex from <a href="http://dblatex.sourceforge.net">http://dblatex.sourceforge.net</a> to build the pdf manual (in\r
+ addition to asciidoc)\r
</p>\r
</li>\r
<li>\r
<p>\r
-asciidoc from <a href="http://www.methods.co.nz/asciidoc/">http://www.methods.co.nz/asciidoc/</a> to build the HTML\r
- manual\r
+flatbuffers from <a href="https://google.github.io/flatbuffers/">https://google.github.io/flatbuffers/</a> for enabling the\r
+ flatbuffers serialization format\r
</p>\r
</li>\r
<li>\r
<p>\r
-dblatex from <a href="http://dblatex.sourceforge.net">http://dblatex.sourceforge.net</a> to build the pdf manual (in\r
- addition to asciidoc)\r
+hyperscan >= 4.4.0 from <a href="https://github.com/01org/hyperscan">https://github.com/01org/hyperscan</a> to build new\r
+ the regex and sd_pattern rule options and hyperscan search engine\r
</p>\r
</li>\r
<li>\r
<p>\r
-w3m from <a href="http://sourceforge.net/projects/w3m/">http://sourceforge.net/projects/w3m/</a> to build the plain text\r
- manual\r
+lzma >= 5.1.2 from <a href="http://tukaani.org/xz/">http://tukaani.org/xz/</a> for decompression of SWF and\r
+ PDF files\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+safec from <a href="https://sourceforge.net/projects/safeclib/">https://sourceforge.net/projects/safeclib/</a> for runtime bounds\r
+ checks on certain legacy C-library calls\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-safec from <a href="https://sourceforge.net/projects/safeclib/">https://sourceforge.net/projects/safeclib/</a> for runtime bounds\r
- checks on certain legacy C-library calls.\r
+w3m from <a href="http://sourceforge.net/projects/w3m/">http://sourceforge.net/projects/w3m/</a> to build the plain text\r
+ manual\r
</p>\r
</li>\r
</ul></div>\r
configuration.</p></div>\r
</div>\r
<div class="sect2">\r
+<h3 id="_byte_rule_options">Byte rule options</h3>\r
+<div class="sect3">\r
+<h4 id="_byte_test">byte_test</h4>\r
+<div class="paragraph"><p>This rule option tests a byte field against a specific value (with\r
+operator). Capable of testing binary values or converting\r
+representative byte strings to their binary equivalent and testing them.</p></div>\r
+<div class="paragraph"><p>Snort uses the C operators for each of these operators. If the &\r
+operator is used, then it would be the same as using</p></div>\r
+<div class="listingblock">\r
+<div class="content"><!-- Generator: GNU source-highlight 3.1.6\r
+by Lorenzo Bettini\r
+http://www.lorenzobettini.it\r
+http://www.gnu.org/software/src-highlite -->\r
+<pre><tt><span style="font-weight: bold"><span style="color: #0000FF">if</span></span> <span style="color: #990000">(</span>data <span style="color: #990000">&</span> value<span style="color: #990000">)</span> <span style="color: #FF0000">{</span> <span style="font-weight: bold"><span style="color: #000000">do_something</span></span><span style="color: #990000">();</span> <span style="color: #FF0000">}</span></tt></pre></div></div>\r
+<div class="paragraph"><p>Note:\r
+The bitmask option applies bitwise AND operator on the bytes\r
+converted. The result will be right-shifted by the number of bits\r
+equal to the number of trailing zeros in the mask.\r
+This applies for the other rule options as well.</p></div>\r
+<div class="sect4">\r
+<h5 id="_examples">Examples</h5>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>alert tcp (byte_test:2, =, 568, 0, bitmask 0x3FF0;)</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>This example extracts 2 bytes at offset 0, performs bitwise and with\r
+bitmask 0x3FF0, shifts the result by 4 bits and compares to 568.</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>alert udp (byte_test:4, =, 1234, 0, string, dec;\r
+ msg:"got 1234!";)</code></pre>\r
+</div></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>alert udp (byte_test:8, =, 0xdeadbeef, 0, string, hex;\r
+ msg:"got DEADBEEF!";)</code></pre>\r
+</div></div>\r
+</div>\r
+</div>\r
+<div class="sect3">\r
+<h4 id="_byte_jump">byte_jump</h4>\r
+<div class="paragraph"><p>The byte_jump rule option allows rules to be written for length\r
+encoded protocols trivially. By having an option that reads the\r
+length of a portion of data, then skips that far forward in the\r
+packet, rules can be written that skip over specific portions of\r
+length-encoded protocols and perform detection in very specific\r
+locations.</p></div>\r
+<div class="sect4">\r
+<h5 id="_examples_2">Examples</h5>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>alert tcp (content:"Begin";\r
+ byte_jump:0, 0, from_end, post_offset -6;\r
+ content:"end..", distance 0, within 5;\r
+ msg:"Content match from end of the payload";)</code></pre>\r
+</div></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>alert tcp (content:"catalog";\r
+ byte_jump:2, 1, relative, post_offset 2, bitmask 0x03f0;\r
+ byte_test:2, =, 968, 0, relative;\r
+ msg:"Bitmask applied on the 2 bytes extracted for byte_jump";)</code></pre>\r
+</div></div>\r
+</div>\r
+</div>\r
+<div class="sect3">\r
+<h4 id="_byte_extract">byte_extract</h4>\r
+<div class="paragraph"><p>The byte_extract keyword is another useful option for writing rules\r
+against length-encoded protocols. It reads in some number of bytes\r
+from the packet payload and saves it to a variable. These variables\r
+can be referenced later in the rule, instead of using hard-coded values.</p></div>\r
+<div class="sect4">\r
+<h5 id="_other_options_which_use_byte_extract_variables">Other options which use byte_extract variables</h5>\r
+<div class="paragraph"><p>A byte_extract rule option detects nothing by itself. Its use is in\r
+extracting packet data for use in other rule options.</p></div>\r
+<div class="paragraph"><p>Here is a list of places where byte_extract variables can be used:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+content/uricontent: offset, depth, distance, within\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+byte_test: offset, value\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+byte_jump: offset\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+isdataat: offset\r
+</p>\r
+</li>\r
+</ul></div>\r
+</div>\r
+<div class="sect4">\r
+<h5 id="_examples_3">Examples</h5>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>alert tcp (byte_extract:1, 0, str_offset;\r
+ byte_extract:1, 1, str_depth;\r
+ content:"bad stuff", offset str_offset, depth str_depth;\r
+ msg:"Bad Stuff detected within field";)</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>This example uses two variables.</p></div>\r
+<div class="paragraph"><p>The first variable keeps the offset of a string, read from a byte at offset 0.\r
+The second variable keeps the depth of a string, read from a byte at offset 1.\r
+These values are used to constrain a pattern match to a smaller area.</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>alert tcp (content:"|04 63 34 35|", offset 4, depth 4;\r
+ byte_extract: 2, 0, var_match, relative, bitmask 0x03ff;\r
+ byte_test: 2, =, var_match, 2, relative;\r
+ msg:"Test value match, after applying bitmask on bytes extracted";)</code></pre>\r
+</div></div>\r
+</div>\r
+</div>\r
+<div class="sect3">\r
+<h4 id="_byte_math">byte_math</h4>\r
+<div class="paragraph"><p>Perform a mathematical operation on an extracted value and a specified\r
+value or existing variable, and store the outcome in a new resulting\r
+variable. These resulting variables can be referenced later in the\r
+rule, at the same places as byte_extract variables.</p></div>\r
+<div class="paragraph"><p>The syntax for this rule option is different. The order of the options\r
+is critical for the other rule options and can’t be changed. For\r
+example, the first option is the number of bytes to extract.\r
+Here the name of the option is explicitly written, for example : bytes 2.\r
+The order is not important.</p></div>\r
+<div class="admonitionblock">\r
+<table><tr>\r
+<td class="icon">\r
+<img src="./images/icons/note.png" alt="Note" />\r
+</td>\r
+<td class="content">Byte_math operations are performed on unsigned 32-bit values. When\r
+ writing a rule it should be taken into consideration to avoid wrap around.</td>\r
+</tr></table>\r
+</div>\r
+<div class="sect4">\r
+<h5 id="_examples_4">Examples</h5>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>alert tcp ( byte_math: bytes 2, offset 0, oper *, rvalue 10, result area;\r
+ byte_test:2,>,area,16;)</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>At the zero offset of the payload, extract 2 bytes and apply multiplication operation with\r
+value 10. Store result in variable area. The area variable is given as\r
+input to byte_test value option.</p></div>\r
+<div class="paragraph"><p>Let’s consider 2 bytes of extracted data is 5. The rvalue is 10.\r
+Result variable area is 50 ( 5 * 10 ).\r
+Area variable can be used in either byte_test offset/value options.</p></div>\r
+</div>\r
+</div>\r
+<div class="sect3">\r
+<h4 id="_testing_numerical_values">Testing Numerical Values</h4>\r
+<div class="paragraph"><p>The rule options byte_test and byte_jump were written to support\r
+writing rules for protocols that have length encoded data. RPC was\r
+the protocol that spawned the requirement for these two rule options,\r
+as RPC uses simple length based encoding for passing data.</p></div>\r
+<div class="paragraph"><p>In order to understand why byte test and byte jump are useful, let’s\r
+go through an exploit attempt against the sadmind service.</p></div>\r
+<div class="paragraph"><p>This is the payload of the exploit:</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>89 09 9c e2 00 00 00 00 00 00 00 02 00 01 87 88 ................\r
+00 00 00 0a 00 00 00 01 00 00 00 01 00 00 00 20 ...............\r
+40 28 3a 10 00 00 00 0a 4d 45 54 41 53 50 4c 4f @(:.....metasplo\r
+49 54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 it..............\r
+00 00 00 00 00 00 00 00 40 28 3a 14 00 07 45 df ........@(:...e.\r
+00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\r
+00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 ................\r
+00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 04 ................\r
+7f 00 00 01 00 01 87 88 00 00 00 0a 00 00 00 04 ................\r
+7f 00 00 01 00 01 87 88 00 00 00 0a 00 00 00 11 ................\r
+00 00 00 1e 00 00 00 00 00 00 00 00 00 00 00 00 ................\r
+00 00 00 00 00 00 00 3b 4d 45 54 41 53 50 4c 4f .......;metasplo\r
+49 54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 it..............\r
+00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\r
+00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\r
+00 00 00 00 00 00 00 06 73 79 73 74 65 6d 00 00 ........system..\r
+00 00 00 15 2e 2e 2f 2e 2e 2f 2e 2e 2f 2e 2e 2f ....../../../../\r
+2e 2e 2f 62 69 6e 2f 73 68 00 00 00 00 00 04 1e ../bin/sh.......</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>Let’s break this up, describe each of the fields, and figure out how to write a\r
+rule to catch this exploit.</p></div>\r
+<div class="paragraph"><p>There are a few things to note with RPC:</p></div>\r
+<div class="paragraph"><p>Numbers are written as uint32s, taking four bytes. The number 26 would\r
+show up as 0x0000001a.</p></div>\r
+<div class="paragraph"><p>Strings are written as a uint32 specifying the length of the string, the\r
+string, and then null bytes to pad the length of the string to end on a 4-byte\r
+boundary. The string <em>bob</em> would show up as 0x00000003626f6200.</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>89 09 9c e2 - the request id, a random uint32, unique to each request\r
+00 00 00 00 - rpc type (call = 0, response = 1)\r
+00 00 00 02 - rpc version (2)\r
+00 01 87 88 - rpc program (0x00018788 = 100232 = sadmind)\r
+00 00 00 0a - rpc program version (0x0000000a = 10)\r
+00 00 00 01 - rpc procedure (0x00000001 = 1)\r
+00 00 00 01 - credential flavor (1 = auth_unix)\r
+00 00 00 20 - length of auth_unix data (0x20 = 32)</code></pre>\r
+</div></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>## the next 32 bytes are the auth_unix data\r
+40 28 3a 10 - unix timestamp (0x40283a10 = 1076378128 = feb 10 01:55:28 2004 gmt)\r
+00 00 00 0a - length of the client machine name (0x0a = 10)\r
+4d 45 54 41 53 50 4c 4f 49 54 00 00 - metasploit</code></pre>\r
+</div></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>00 00 00 00 - uid of requesting user (0)\r
+00 00 00 00 - gid of requesting user (0)\r
+00 00 00 00 - extra group ids (0)</code></pre>\r
+</div></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>00 00 00 00 - verifier flavor (0 = auth_null, aka none)\r
+00 00 00 00 - length of verifier (0, aka none)</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>The rest of the packet is the request that gets passed to procedure 1 of\r
+sadmind.</p></div>\r
+<div class="paragraph"><p>However, we know the vulnerability is that sadmind trusts the uid coming from\r
+the client. sadmind runs any request where the client’s uid is 0 as root. As\r
+such, we have decoded enough of the request to write our rule.</p></div>\r
+<div class="paragraph"><p>First, we need to make sure that our packet is an RPC call.</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>content:"|00 00 00 00|", offset 4, depth 4;</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>Then, we need to make sure that our packet is a call to sadmind.</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>content:"|00 01 87 88|", offset 12, depth 4;</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>Then, we need to make sure that our packet is a call to the procedure 1, the\r
+vulnerable procedure.</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>content:"|00 00 00 01|", offset 20, depth 4;</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>Then, we need to make sure that our packet has auth_unix credentials.</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>content:"|00 00 00 01|", offset 24, depth 4;</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>We don’t care about the hostname, but we want to skip over it and check a\r
+number value after the hostname. This is where byte_test is useful. Starting\r
+at the length of the hostname, the data we have is:</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>00 00 00 0a 4d 45 54 41 53 50 4c 4f 49 54 00 00\r
+00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\r
+00 00 00 00</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>We want to read 4 bytes, turn it into a number, and jump that many bytes\r
+forward, making sure to account for the padding that RPC requires on strings.\r
+If we do that, we are now at:</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\r
+00 00 00 00</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>which happens to be the exact location of the uid, the value we want to check.</p></div>\r
+<div class="paragraph"><p>In English, we want to read 4 bytes, 36 bytes from the beginning of the packet,\r
+and turn those 4 bytes into an integer and jump that many bytes forward,\r
+aligning on the 4-byte boundary. To do that in a Snort rule, we use:</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>byte_jump:4,36,align;</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>then we want to look for the uid of 0.</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>content:"|00 00 00 00|", within 4;</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>Now that we have all the detection capabilities for our rule, let’s put them\r
+all together.</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>content:"|00 00 00 00|", offset 4, depth 4;\r
+content:"|00 01 87 88|", offset 12, depth 4;\r
+content:"|00 00 00 01|", offset 20, depth 4;\r
+content:"|00 00 00 01|", offset 24, depth 4;\r
+byte_jump:4,36,align;\r
+content:"|00 00 00 00|", within 4;</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>The 3rd and fourth string match are right next to each other, so we should\r
+combine those patterns. We end up with:</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>content:"|00 00 00 00|", offset 4, depth 4;\r
+content:"|00 01 87 88|", offset 12, depth 4;\r
+content:"|00 00 00 01 00 00 00 01|", offset 20, depth 8;\r
+byte_jump:4,36,align;\r
+content:"|00 00 00 00|", within 4;</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>If the sadmind service was vulnerable to a buffer overflow when reading the\r
+client’s hostname, instead of reading the length of the hostname and jumping\r
+that many bytes forward, we would check the length of the hostname to make sure\r
+it is not too large.</p></div>\r
+<div class="paragraph"><p>To do that, we would read 4 bytes, starting 36 bytes into the packet, turn it\r
+into a number, and then make sure it is not too large (let’s say bigger than\r
+200 bytes). In Snort, we do:</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>byte_test:4,>,200,36;</code></pre>\r
+</div></div>\r
+<div class="paragraph"><p>Our full rule would be:</p></div>\r
+<div class="literalblock">\r
+<div class="content">\r
+<pre><code>content:"|00 00 00 00|", offset 4, depth 4;\r
+content:"|00 01 87 88|", offset 12, depth 4;\r
+content:"|00 00 00 01 00 00 00 01|", offset 20, depth 8;\r
+byte_test:4,>,200,36;</code></pre>\r
+</div></div>\r
+</div>\r
+</div>\r
+<div class="sect2">\r
<h3 id="_dce_inspectors">DCE Inspectors</h3>\r
<div class="paragraph"><p>The main purpose of these inspector are to perform SMB desegmentation and\r
DCE/RPC defragmentation to avoid rule evasion using these techniques.</p></div>\r
</div>\r
<div class="sect3">\r
<h4 id="_tcp">TCP</h4>\r
-<div class="paragraph"><p>dce_tcp inspector supports defragementation, reassembling, and policy that is\r
+<div class="paragraph"><p>dce_tcp inspector supports defragmentation, reassembling, and policy that is\r
similar to SMB.</p></div>\r
</div>\r
<div class="sect3">\r
<h4 id="_udp">UDP</h4>\r
-<div class="paragraph"><p>dce_udp is a very simple inspector that only supports defragementation</p></div>\r
+<div class="paragraph"><p>dce_udp is a very simple inspector that only supports defragmentation</p></div>\r
</div>\r
<div class="sect3">\r
<h4 id="_rule_options">Rule Options</h4>\r
magic = { { content = "| 47 49 46 38 39 61 |",offset = 0 } } },</code></pre>\r
</div></div>\r
<div class="paragraph"><p>The previous two rules define GIF format, because two file magics are\r
-different. File magics are specifed by content and offset, which look\r
+different. File magics are specified by content and offset, which look\r
at content at particular file offset to identify the file type. In this\r
case, two magics look at the beginning of the file. You can use character\r
if it is printable or hex value in between "|".</p></div>\r
messaging subsystems.</p></div>\r
<div class="sect3">\r
<h4 id="_ha">HA</h4>\r
-<div class="paragraph"><p>HighAvailability (or HA) is a Snort module that provides state coherancy\r
+<div class="paragraph"><p>HighAvailability (or HA) is a Snort module that provides state coherency\r
between two partner snort instances. It uses SideChannel for messaging.</p></div>\r
<div class="paragraph"><p>There can be multiple types of HA within Snort and Snort plugins. HA\r
implements an extensible architecture to enable plugins to subscribe to the\r
The TcpConnector is duplex while the FileConnector is simplex.</p></div>\r
<div class="paragraph"><p>All subtypes of Connector have a <em>direction</em> configuration element and a\r
<em>connector</em> element. The <em>connector</em> string is the key used to identify the\r
-element for sidechannel configiration. The <em>direction</em> element may have a\r
+element for sidechannel configuration. The <em>direction</em> element may have a\r
default value, for instance TcpConnector’s are <em>duplex</em>.</p></div>\r
<div class="paragraph"><p>There are currently two implementations of Connectors:</p></div>\r
<div class="ulist"><ul>\r
<div class="ulist"><ul>\r
<li>\r
<p>\r
-name = string - used as part of the messsage file name\r
+name = string - used as part of the message file name\r
</p>\r
</li>\r
<li>\r
<div class="paragraph"><p>The SideChannel configuration mostly serves to map a port number to a Connector\r
or set of connectors. Each port mapping can have at most one transmit plus\r
one receive connector or one duplex connector. Multiple SideChannel’s\r
-may be configured and instatiated to support multiple applications.</p></div>\r
-<div class="paragraph"><p>An example SideChannel configuration along with the corresponing Connector\r
+may be configured and instantiated to support multiple applications.</p></div>\r
+<div class="paragraph"><p>An example SideChannel configuration along with the corresponding Connector\r
configuration:</p></div>\r
<div class="literalblock">\r
<div class="content">\r
is on by default and you should not turn it off unless you have no interest\r
in URI paths.</p></div>\r
<div class="paragraph"><p>backslash_to_slash is a tweak to path simplification for servers that allow\r
-directories to be separated by backslashs:</p></div>\r
+directories to be separated by backslashes:</p></div>\r
<div class="literalblock">\r
<div class="content">\r
<pre><code>/this/is/the/normal/way/to/write/a/path</code></pre>\r
cookie headers Cookie and Set-Cookie. http_raw_header includes the\r
unmodified header names and values as they appeared in the original\r
message. http_header is the same except percent encodings are removed and\r
-pathes are simplified exactly as if the headers were a URI.</p></div>\r
+paths are simplified exactly as if the headers were a URI.</p></div>\r
<div class="paragraph"><p>In most cases specifying individual headers creates a more efficient and\r
accurate rule. It is recommended that new rules be written using individual\r
headers whenever possible.</p></div>\r
<div class="paragraph"><p>These are the unmodified first header line of the HTTP request and response\r
messages respectively. These rule options are a safety valve in case you\r
need to do something you cannot otherwise do. In most cases it is better to\r
-use a rule option for a specifc part of the first header line. For a\r
+use a rule option for a specific part of the first header line. For a\r
request message those are http_method, http_raw_uri, and http_version. For\r
a response message those are http_version, http_stat_code, and\r
http_stat_msg.</p></div>\r
<pre><code>perf_monitor = { cpu = true }</code></pre>\r
</div></div>\r
</div>\r
+<div class="sect3">\r
+<h4 id="_formatters">Formatters</h4>\r
+<div class="paragraph"><p>Performance monitor allows statistics to be output in a few formats. Along with\r
+human readable text (as seen at shutdown) and csv formats, a Flatbuffers binary\r
+format is also available if Flatbuffers is present at build. A utility for\r
+accessing the statistics generated in this format has been included for\r
+convenience (see fbstreamer in tools). This tool generates a YAML array of\r
+records found, allowing the data to be read by humans or passed into other\r
+analysis tools. For information on working directly with the Flatbuffers file\r
+format used by Performance monitor, see the developer notes for Performance\r
+monitor or the code provided for fbstreamer.</p></div>\r
+</div>\r
</div>\r
<div class="sect2">\r
<h3 id="_sensitive_data_filtering">Sensitive Data Filtering</h3>\r
<strong>116:472</strong> (decode) too many protocols present\r
</p>\r
</li>\r
+<li>\r
+<p>\r
+<strong>116:473</strong> (decode) ether type out of range\r
+</p>\r
+</li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
</li>\r
<li>\r
<p>\r
+int <strong>detection.offload_limit</strong> = 99999: minimum sizeof PDU to offload fast pattern search (defaults to disabled) { 0: }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+int <strong>detection.offload_threads</strong> = 0: maximum number of simultaneous offloads (defaults to disabled) { 0: }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
bool <strong>detection.pcre_enable</strong> = true: disable pcre pattern matching\r
</p>\r
</li>\r
int <strong>detection.pcre_match_limit_recursion</strong> = 1500: limit pcre stack consumption, -1 = max, 0 = off { -1:10000 }\r
</p>\r
</li>\r
+<li>\r
+<p>\r
+int <strong>detection.trace</strong>: mask for enabling debug traces in module\r
+</p>\r
+</li>\r
</ul></div>\r
<div class="paragraph"><p>Peg counts:</p></div>\r
<div class="ulist"><ul>\r
</li>\r
<li>\r
<p>\r
+<strong>detection.offloads</strong>: fast pattern searches that were offloaded\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>detection.alerts</strong>: alerts not including IP reputation\r
</p>\r
</li>\r
bool <strong>output.verbose</strong> = false: be verbose (same as -v)\r
</p>\r
</li>\r
+<li>\r
+<p>\r
+bool <strong>output.wide_hex_dump</strong> = false: output 20 bytes per lines instead of 16 when dumping buffers\r
+</p>\r
+</li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
</li>\r
<li>\r
<p>\r
-dynamic <strong>search_engine.search_method</strong> = ac_bnfa: set fast pattern algorithm - choose available search engine { ac_banded | ac_bnfa | ac_full | ac_sparse | ac_sparse_bands | ac_std | hyperscan }\r
+dynamic <strong>search_engine.search_method</strong> = ac_bnfa: set fast pattern algorithm - choose available search engine { ac_banded | ac_bnfa | ac_full | ac_sparse | ac_sparse_bands | ac_std | hyperscan | lowmem }\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
+string <strong>snort.--control-socket</strong>: <file> to create unix socket\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
implied <strong>snort.--create-pidfile</strong>: create PID file, even when not in Daemon mode\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-implied <strong>snort.--piglet</strong>: enable piglet test harness mode\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
implied <strong>snort.--show-plugins</strong>: list module and plugin versions\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-string <strong>snort.--catch-test</strong>: comma separated list of cat unit test tags or <em>all</em>\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
implied <strong>snort.--version</strong>: show version number (same as -V)\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
+<strong>snort.reload_daq</strong>(): reload daq module\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>snort.reload_hosts</strong>(filename): load a new hosts table\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
+<strong>snort.daq_reloads</strong>: number of times daq configuration was reloaded\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>snort.attribute_table_reloads</strong>: number of times hosts table was reloaded\r
</p>\r
</li>\r
</div>\r
<div class="sect2">\r
<h3 id="_gtp">gtp</h3>\r
-<div class="paragraph"><p>What: support for general-packet-radio-service tunnelling protocol</p></div>\r
+<div class="paragraph"><p>What: support for general-packet-radio-service tunneling protocol</p></div>\r
<div class="paragraph"><p>Type: codec</p></div>\r
<div class="paragraph"><p>Rules:</p></div>\r
<div class="ulist"><ul>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
+<h3 id="_llc">llc</h3>\r
+<div class="paragraph"><p>What: support for logical link control</p></div>\r
+<div class="paragraph"><p>Type: codec</p></div>\r
+<div class="paragraph"><p>Rules:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+<strong>116:131</strong> (llc) bad LLC header\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>116:132</strong> (llc) bad extra LLC info\r
+</p>\r
+</li>\r
+</ul></div>\r
+</div>\r
+<div class="sect2">\r
<h3 id="_mpls">mpls</h3>\r
<div class="paragraph"><p>What: support for multiprotocol label switching</p></div>\r
<div class="paragraph"><p>Type: codec</p></div>\r
<strong>116:130</strong> (vlan) bad VLAN frame\r
</p>\r
</li>\r
-<li>\r
-<p>\r
-<strong>116:131</strong> (vlan) bad LLC header\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>116:132</strong> (vlan) bad extra LLC info\r
-</p>\r
-</li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
bool <strong>appid.session_log_filter.log_all_sessions</strong> = false: enable logging for all appid sessions\r
</p>\r
</li>\r
+<li>\r
+<p>\r
+bool <strong>appid.log_all_sessions</strong> = false: enable logging of all appid sessions\r
+</p>\r
+</li>\r
</ul></div>\r
<div class="paragraph"><p>Peg counts:</p></div>\r
<div class="ulist"><ul>\r
</li>\r
<li>\r
<p>\r
-<strong>dce_smb.client_segs_reassembled</strong>: total smb client segments reassembled\r
+<strong>dce_smb.smb_client_segs_reassembled</strong>: total smb client segments reassembled\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>dce_smb.server_segs_reassembled</strong>: total smb server segments reassembled\r
+<strong>dce_smb.smb_server_segs_reassembled</strong>: total smb server segments reassembled\r
</p>\r
</li>\r
<li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
-<h3 id="_http_global">http_global</h3>\r
-<div class="paragraph"><p>What: http inspector global configuration and client rules for use with http_server</p></div>\r
-<div class="paragraph"><p>Type: inspector</p></div>\r
-<div class="paragraph"><p>Configuration:</p></div>\r
-<div class="ulist"><ul>\r
-<li>\r
-<p>\r
-int <strong>http_global.compress_depth</strong> = 65535: maximum amount of packet payload to decompress { 1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.decode.b64_decode_depth</strong> = 0: single packet decode depth { -1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.decode.bitenc_decode_depth</strong> = 0: single packet decode depth { -1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.decode.max_mime_mem</strong> = 838860: single packet decode depth { 3276: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.decode.qp_decode_depth</strong> = 0: single packet decode depth { -1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.decode.uu_decode_depth</strong> = 0: single packet decode depth { -1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.decompress_depth</strong> = 65535: maximum amount of decompressed data to process { 1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_global.detect_anomalous_servers</strong> = false: inspect non-configured ports for HTTP - bad idea\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.max_gzip_mem</strong> = 0: disregard - not implemented { 0: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.memcap</strong> = 0: disregard - not implemented { 0: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_global.proxy_alert</strong> = false: alert on proxy usage for servers without allow_proxy_use\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.unicode_map.code_page</strong> = 1252: select code page in map file { 0: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-string <strong>http_global.unicode_map.map_file</strong>: unicode map file\r
-</p>\r
-</li>\r
-</ul></div>\r
-<div class="paragraph"><p>Rules:</p></div>\r
-<div class="ulist"><ul>\r
-<li>\r
-<p>\r
-<strong>319:1</strong> (http_global) ascii encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:2</strong> (http_global) double decoding attack\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:3</strong> (http_global) u encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:4</strong> (http_global) bare byte unicode encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:5</strong> (http_global) base36 encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:6</strong> (http_global) UTF-8 encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:7</strong> (http_global) IIS unicode codepoint encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:8</strong> (http_global) multi_slash encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:9</strong> (http_global) IIS backslash evasion\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:10</strong> (http_global) self directory traversal\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:11</strong> (http_global) directory traversal\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:12</strong> (http_global) apache whitespace (tab)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:13</strong> (http_global) non-RFC http delimiter\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:14</strong> (http_global) non-RFC defined char\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:15</strong> (http_global) oversize request-URI directory\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:16</strong> (http_global) oversize chunk encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:17</strong> (http_global) unauthorized proxy use detected\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:18</strong> (http_global) webroot directory traversal\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:19</strong> (http_global) long header\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:20</strong> (http_global) max header fields\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:21</strong> (http_global) multiple content length\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:22</strong> (http_global) chunk size mismatch detected\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:23</strong> (http_global) invalid ip in true-client-IP/XFF header\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:24</strong> (http_global) multiple host hdrs detected\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:25</strong> (http_global) hostname exceeds 255 characters\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:26</strong> (http_global) header parsing space saturation\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:27</strong> (http_global) client consecutive small chunk sizes\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:28</strong> (http_global) post w/o content-length or chunks\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:29</strong> (http_global) multiple true IPs in a session\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:30</strong> (http_global) both true-client-IP and XFF hdrs present\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:31</strong> (http_global) unknown method\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:32</strong> (http_global) simple request\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:33</strong> (http_global) unescaped space in http URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:34</strong> (http_global) too many pipelined requests\r
-</p>\r
-</li>\r
-</ul></div>\r
-<div class="paragraph"><p>Peg counts:</p></div>\r
-<div class="ulist"><ul>\r
-<li>\r
-<p>\r
-<strong>http_global.packets</strong>: total packets processed\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.gets</strong>: GET requests\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.posts</strong>: POST requests\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.request_headers</strong>: total requests\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.response_headers</strong>: total responses\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.request_cookies</strong>: requests with Cookie\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.response_cookies</strong>: responses with Set-Cookie\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.post_params</strong>: POST parameters extracted\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.unicode</strong>: unicode normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.double_unicode</strong>: double unicode normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.non_ascii</strong>: non-ascii normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.paths_with_traversal</strong>: directory traversal (../) normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.paths_with_double_slash</strong>: double slash (//) normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.paths_with_relative</strong>: relative directory (./) normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.gzip_packets</strong>: packets with gzip compression\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.compressed_bytes</strong>: total comparessed bytes processed\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.decompressed_bytes</strong>: total bytes decompressed\r
-</p>\r
-</li>\r
-</ul></div>\r
-</div>\r
-<div class="sect2">\r
<h3 id="_http_inspect">http_inspect</h3>\r
<div class="paragraph"><p>What: HTTP inspector</p></div>\r
<div class="paragraph"><p>Type: inspector</p></div>\r
bool <strong>http_inspect.simplify_path</strong> = true: reduce URI directory path to simplest form\r
</p>\r
</li>\r
-<li>\r
-<p>\r
-bool <strong>http_inspect.test_input</strong> = false: read HTTP messages from text file\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_inspect.test_output</strong> = false: print out HTTP section data\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_inspect.print_amount</strong> = 1200: number of characters to print from a Field { 1:1000000 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_inspect.print_hex</strong> = false: nonprinting characters printed in [HH] format instead of using an asterisk\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_inspect.show_pegs</strong> = true: display peg counts with test output\r
-</p>\r
-</li>\r
</ul></div>\r
<div class="paragraph"><p>Rules:</p></div>\r
<div class="ulist"><ul>\r
</li>\r
<li>\r
<p>\r
-<strong>119:7</strong> (http_inspect) IIS unicode codepoint encoding\r
+<strong>119:7</strong> (http_inspect) unicode map code point encoding in URI\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>119:9</strong> (http_inspect) IIS backslash evasion\r
+<strong>119:9</strong> (http_inspect) backslash used in URI path\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>119:13</strong> (http_inspect) non-RFC http delimiter\r
+<strong>119:13</strong> (http_inspect) HTTP header line terminated by LF without a CR\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>119:26</strong> (http_inspect) header parsing space saturation\r
+<strong>119:26</strong> (http_inspect) too much whitespace in header (not implemented yet)\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>119:37</strong> (http_inspect) no content-length or transfer-encoding in HTTP response\r
+<strong>119:37</strong> (http_inspect) unused event number—should not appear\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>119:42</strong> (http_inspect) invalid content-length or chunk size\r
+<strong>119:42</strong> (http_inspect) unused event number—should not appear\r
</p>\r
</li>\r
<li>\r
<strong>119:80</strong> (http_inspect) PDF/SWF decompression of server response too big\r
</p>\r
</li>\r
+<li>\r
+<p>\r
+<strong>119:81</strong> (http_inspect) nonprinting character in HTTP message header name\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>119:82</strong> (http_inspect) bad Content-Length value in HTTP header\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>119:83</strong> (http_inspect) HTTP header line wrapped\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>119:84</strong> (http_inspect) HTTP header line terminated by CR without a LF\r
+</p>\r
+</li>\r
</ul></div>\r
<div class="paragraph"><p>Peg counts:</p></div>\r
<div class="ulist"><ul>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
-<h3 id="_http_server">http_server</h3>\r
-<div class="paragraph"><p>What: http inspection and server rules; also configure http_global</p></div>\r
-<div class="paragraph"><p>Type: inspector</p></div>\r
-<div class="paragraph"><p>Configuration:</p></div>\r
-<div class="ulist"><ul>\r
-<li>\r
-<p>\r
-bool <strong>http_server.allow_proxy_use</strong> = false: don’t alert on proxy use for this server\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.decompress_pdf</strong> = false: enable decompression of the compressed portions of PDF files\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.decompress_swf</strong> = false: enable decompression of SWF (Adobe Flash content)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.enable_cookies</strong> = true: extract cookies\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.enable_xff</strong> = false: log True-Client-IP and X-Forwarded-For headers with unified2 alerts as extra data\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.extended_ascii_uri</strong> = false: allow extended ASCII codes in the request URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.extended_response_inspection</strong> = true: extract response headers\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-string <strong>http_server.http_methods</strong> = GET POST PUT SEARCH MKCOL COPY MOVE LOCK UNLOCK NOTIFY POLL BCOPY BDELETE BMOVE LINK UNLINK OPTIONS HEAD DELETE TRACE TRACK CONNECT SOURCE SUBSCRIBE UNSUBSCRIBE PROPFIND PROPPATCH BPROPFIND BPROPPATCH RPC_CONNECT PROXY_SUCCESS BITS_POST CCM_POST SMS_POST RPC_IN_DATA RPC_OUT_DATA RPC_ECHO_DATA: request methods allowed in addition to GET and POST\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.inspect_gzip</strong> = true: enable gzip decompression of compressed bodies\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.inspect_uri_only</strong> = false: disable all detection except for uricontent\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.log_hostname</strong> = false: enable logging of Hostname with unified2 alerts as extra data\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.log_uri</strong> = false: enable logging of URI with unified2 alerts as extra data\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.no_pipeline_req</strong> = false: don’t inspect pipelined requests after first (still does general detection)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bit_list <strong>http_server.non_rfc_chars</strong> = 0x00 0x01 0x02 0x03 0x04 0x05 0x06 0x07: alert on given non-RFC chars being present in the URI { 255 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.normalize_cookies</strong> = false: normalize cookies similar to URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.normalize_headers</strong> = false: normalize headers other than cookie similar to URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.oversize_dir_length</strong> = 500: alert if a URL has a directory longer than this limit { 0: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.apache_whitespace</strong> = false: don’t alert if tab is used in lieu of space characters\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.ascii</strong> = false: enable decoding ASCII like %2f to /\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.bare_byte</strong> = false: decode non-standard, non-ASCII character encodings\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.chunk_length</strong> = 500000: alert on chunk lengths greater than specified { 1: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.client_flow_depth</strong> = 0: raw request payload to inspect { -1:1460 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.directory</strong> = false: normalize . and .. sequences out of URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.double_decode</strong> = false: iis specific extra decoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.iis_backslash</strong> = false: normalize directory slashes\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.iis_delimiter</strong> = false: allow use of non-standard delimiter\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.iis_unicode</strong> = false: enable unicode code point mapping using unicode_map settings\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.iis_unicode_map.code_page</strong> = 1252: select code page in map file { 0: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-string <strong>http_server.profile.iis_unicode_map.map_file</strong>: unicode map file\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.max_header_length</strong> = 750: maximum allowed client request header field { 0:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.max_headers</strong> = 100: maximum allowed client request headers { 0:1024 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.max_spaces</strong> = 200: maximum allowed whitespaces when folding { 0:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.multi_slash</strong> = false: normalize out consecutive slashes in URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.non_strict</strong> = true: allows HTTP 0.9 processing\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.max_javascript_whitespaces</strong> = 200: maximum number of consecutive whitespaces { 0: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.normalize_utf</strong> = true: normalize response bodies with UTF content-types\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.normalize_javascript</strong> = true: normalize javascript between <script> tags\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.post_depth</strong> = 65495: amount of POST data to inspect { -1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-enum <strong>http_server.profile.profile_type</strong> = default: set defaults appropriate for selected server { default | apache | iis | iis_40 | iis_50 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.server_flow_depth</strong> = 0: response payload to inspect; includes headers with extended_response_inspection { -1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.u_encode</strong> = true: decode %uXXXX character sequences\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.utf_8</strong> = false: decode UTF-8 unicode sequences in URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.webroot</strong> = false: alert on directory traversals past the top level (web server root)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bit_list <strong>http_server.profile.whitespace_chars</strong>: allowed white space characters { 255 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.small_chunk_count</strong> = 5: alert if more than this limit of consecutive chunks are below small_chunk_length { 0:255 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.small_chunk_length</strong> = 10: alert if more than small_chunk_count consecutive chunks below this limit { 0:255 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.tab_uri_delimiter</strong> = false: whether a tab not preceded by a space is considered a delimiter or part of URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.unlimited_decompress</strong> = true: decompress across multiple packets\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.xff_headers</strong> = false: not implemented\r
-</p>\r
-</li>\r
-</ul></div>\r
-<div class="paragraph"><p>Rules:</p></div>\r
-<div class="ulist"><ul>\r
-<li>\r
-<p>\r
-<strong>320:1</strong> (http_server) anomalous http server on undefined HTTP port\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:2</strong> (http_server) invalid status code in HTTP response\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:3</strong> (http_server) no content-length or transfer-encoding in HTTP response\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:4</strong> (http_server) HTTP response has UTF charset which failed to normalize\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:5</strong> (http_server) HTTP response has UTF-7 charset\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:6</strong> (http_server) HTTP response gzip decompression failed\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:7</strong> (http_server) server consecutive small chunk sizes\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:8</strong> (http_server) invalid content-length or chunk size\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:9</strong> (http_server) javascript obfuscation levels exceeds 1\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:10</strong> (http_server) javascript whitespaces exceeds max allowed\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:11</strong> (http_server) multiple encodings within javascript obfuscated data\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:12</strong> (http_server) HTTP response SWF file zlib decompression failure\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:13</strong> (http_server) HTTP response SWF file LZMA decompression failure\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:14</strong> (http_server) HTTP response PDF file deflate decompression failure\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:15</strong> (http_server) HTTP response PDF file unsupported compression type\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:16</strong> (http_server) HTTP response PDF file cascaded compression\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:17</strong> (http_server) HTTP response PDF file parse failure\r
-</p>\r
-</li>\r
-</ul></div>\r
-</div>\r
-<div class="sect2">\r
<h3 id="_imap">imap</h3>\r
<div class="paragraph"><p>What: imap inspection</p></div>\r
<div class="paragraph"><p>Type: inspector</p></div>\r
</li>\r
<li>\r
<p>\r
-<strong>normalizer.tcp_paddding</strong>: packets with padding cleared\r
+<strong>normalizer.tcp_padding</strong>: packets with padding cleared\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>normalizer.test_tcp_paddding</strong>: test packets with padding cleared\r
+<strong>normalizer.test_tcp_padding</strong>: test packets with padding cleared\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>normalizer.tcp_trim_win</strong>: data trimed to window\r
+<strong>normalizer.tcp_trim_win</strong>: data trimmed to window\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>normalizer.test_tcp_trim_win</strong>: test data trimed to window\r
+<strong>normalizer.test_tcp_trim_win</strong>: test data trimmed to window\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-enum <strong>perf_monitor.format</strong> = csv: output format for stats { csv | text }\r
+enum <strong>perf_monitor.format</strong> = csv: output format for stats { csv | text | flatbuffers }\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-int <strong>sip.max_sessions</strong> = 10000: maximum number of sessions that can be allocated { 1024:4194303 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
int <strong>sip.max_to_len</strong> = 256: maximum to field size { 0:65535 }\r
</p>\r
</li>\r
<div class="ulist"><ul>\r
<li>\r
<p>\r
-<strong>140:1</strong> (sip) maximum sessions reached\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>140:2</strong> (sip) empty request URI\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.1xx</strong>: 1xx\r
+<strong>sip.code_1xx</strong>: 1xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.2xx</strong>: 2xx\r
+<strong>sip.code_2xx</strong>: 2xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.3xx</strong>: 3xx\r
+<strong>sip.code_3xx</strong>: 3xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.4xx</strong>: 4xx\r
+<strong>sip.code_4xx</strong>: 4xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.5xx</strong>: 5xx\r
+<strong>sip.code_5xx</strong>: 5xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.6xx</strong>: 6xx\r
+<strong>sip.code_6xx</strong>: 6xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.7xx</strong>: 7xx\r
+<strong>sip.code_7xx</strong>: 7xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.8xx</strong>: 8xx\r
+<strong>sip.code_8xx</strong>: 8xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.9xx</strong>: 9xx\r
+<strong>sip.code_9xx</strong>: 9xx\r
</p>\r
</li>\r
</ul></div>\r
</li>\r
<li>\r
<p>\r
-<strong>stream_tcp.3way_trackers</strong>: tcp session tracking started on ack\r
+<strong>stream_tcp.three_way_trackers</strong>: tcp session tracking started on ack\r
</p>\r
</li>\r
<li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
-<h3 id="_byte_extract">byte_extract</h3>\r
+<h3 id="_byte_extract_2">byte_extract</h3>\r
<div class="paragraph"><p>What: rule option to convert data to an integer variable</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
<div class="paragraph"><p>Configuration:</p></div>\r
implied <strong>byte_extract.dec</strong>: convert from decimal string\r
</p>\r
</li>\r
+<li>\r
+<p>\r
+int <strong>byte_extract.bitmask</strong>: applies as an AND to the extracted value before storage in <em>name</em> { 0x1:0xFFFFFFFF }\r
+</p>\r
+</li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
-<h3 id="_byte_jump">byte_jump</h3>\r
+<h3 id="_byte_jump_2">byte_jump</h3>\r
<div class="paragraph"><p>What: rule option to move the detection cursor</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
<div class="paragraph"><p>Configuration:</p></div>\r
<div class="ulist"><ul>\r
<li>\r
<p>\r
-int <strong>byte_jump.~count</strong>: number of bytes to pick up from the buffer { 1:10 }\r
+int <strong>byte_jump.~count</strong>: number of bytes to pick up from the buffer { 0:10 }\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
+implied <strong>byte_jump.from_end</strong>: jump backward from end of buffer\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
int <strong>byte_jump.multiplier</strong> = 1: scale extracted value by given amount { 1:65535 }\r
</p>\r
</li>\r
implied <strong>byte_jump.dec</strong>: convert from decimal string\r
</p>\r
</li>\r
+<li>\r
+<p>\r
+int <strong>byte_jump.bitmask</strong>: applies as an AND prior to evaluation { 0x1:0xFFFFFFFF }\r
+</p>\r
+</li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
-<h3 id="_byte_test">byte_test</h3>\r
+<h3 id="_byte_math_2">byte_math</h3>\r
+<div class="paragraph"><p>What: rule option to perform mathematical operations on extracted value and a specified value or existing variable</p></div>\r
+<div class="paragraph"><p>Type: ips_option</p></div>\r
+<div class="paragraph"><p>Configuration:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+int <strong>byte_math.bytes</strong>: number of bytes to pick up from the buffer { 1:10 }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+string <strong>byte_math.offset</strong>: number of bytes into the buffer to start processing\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+enum <strong>byte_math.oper</strong>: mathematical operation to perform { +|-|*|/|<<|>> }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+string <strong>byte_math.rvalue</strong>: value to use mathematical operation against\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+string <strong>byte_math.result</strong>: name of the variable to store the result\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>byte_math.relative</strong>: offset from cursor instead of start of buffer\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+enum <strong>byte_math.endian</strong>: specify big/little endian { big|little }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>byte_math.dce</strong>: dcerpc2 determines endianness\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+enum <strong>byte_math.string</strong>: convert extracted string to dec/hex/oct { hex|dec|oct }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+int <strong>byte_math.bitmask</strong>: applies as bitwise AND to the extracted value before storage in <em>name</em> { 0x1:0xFFFFFFFF }\r
+</p>\r
+</li>\r
+</ul></div>\r
+</div>\r
+<div class="sect2">\r
+<h3 id="_byte_test_2">byte_test</h3>\r
<div class="paragraph"><p>What: rule option to convert data to integer and compare</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
<div class="paragraph"><p>Configuration:</p></div>\r
implied <strong>byte_test.dec</strong>: convert from decimal string\r
</p>\r
</li>\r
+<li>\r
+<p>\r
+int <strong>byte_test.bitmask</strong>: applies as an AND prior to evaluation { 0x1:0xFFFFFFFF }\r
+</p>\r
+</li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
<h3 id="_http_cookie">http_cookie</h3>\r
<div class="paragraph"><p>What: rule option to set the detection cursor to the HTTP cookie</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
+<div class="paragraph"><p>Configuration:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+implied <strong>http_cookie.request</strong>: match against the cookie from the request message even when examining the response\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_cookie.with_body</strong>: parts of this rule examine HTTP message body\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_cookie.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
+</p>\r
+</li>\r
+</ul></div>\r
</div>\r
<div class="sect2">\r
<h3 id="_http_header">http_header</h3>\r
-<div class="paragraph"><p>What: rule option to set the detection cursor to the normalized header(s)</p></div>\r
+<div class="paragraph"><p>What: rule option to set the detection cursor to the normalized headers</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
<div class="paragraph"><p>Configuration:</p></div>\r
<div class="ulist"><ul>\r
<li>\r
<p>\r
-string <strong>http_header.~name</strong>: restrict to given header\r
+string <strong>http_header.field</strong>: restrict to given header. Header name is case insensitive.\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_header.request</strong>: match against the headers from the request message even when examining the response\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_header.with_body</strong>: parts of this rule examine HTTP message body\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_header.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
</p>\r
</li>\r
</ul></div>\r
<h3 id="_http_method_2">http_method</h3>\r
<div class="paragraph"><p>What: rule option to set the detection cursor to the HTTP request method</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
+<div class="paragraph"><p>Configuration:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+implied <strong>http_method.with_body</strong>: parts of this rule examine HTTP message body\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_method.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
+</p>\r
+</li>\r
+</ul></div>\r
</div>\r
<div class="sect2">\r
<h3 id="_http_raw_cookie">http_raw_cookie</h3>\r
<div class="paragraph"><p>What: rule option to set the detection cursor to the unnormalized cookie</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
+<div class="paragraph"><p>Configuration:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_cookie.request</strong>: match against the cookie from the request message even when examining the response\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_cookie.with_body</strong>: parts of this rule examine HTTP message body\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_cookie.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
+</p>\r
+</li>\r
+</ul></div>\r
</div>\r
<div class="sect2">\r
<h3 id="_http_raw_header">http_raw_header</h3>\r
<div class="paragraph"><p>What: rule option to set the detection cursor to the unnormalized headers</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
+<div class="paragraph"><p>Configuration:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_header.request</strong>: match against the headers from the request message even when examining the response\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_header.with_body</strong>: parts of this rule examine HTTP message body\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_header.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
+</p>\r
+</li>\r
+</ul></div>\r
</div>\r
<div class="sect2">\r
<h3 id="_http_raw_request">http_raw_request</h3>\r
<h3 id="_http_raw_uri">http_raw_uri</h3>\r
<div class="paragraph"><p>What: rule option to set the detection cursor to the unnormalized URI</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
+<div class="paragraph"><p>Configuration:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_uri.with_body</strong>: parts of this rule examine HTTP message body\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_uri.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_uri.scheme</strong>: match against scheme section of URI only\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_uri.host</strong>: match against host section of URI only\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_uri.port</strong>: match against port section of URI only\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_uri.path</strong>: match against path section of URI only\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_uri.query</strong>: match against query section of URI only\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_uri.fragment</strong>: match against fragment section of URI only\r
+</p>\r
+</li>\r
+</ul></div>\r
</div>\r
<div class="sect2">\r
<h3 id="_http_stat_code_2">http_stat_code</h3>\r
<div class="paragraph"><p>What: rule option to set the detection cursor to the HTTP status code</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
+<div class="paragraph"><p>Configuration:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+implied <strong>http_stat_code.with_body</strong>: parts of this rule examine HTTP message body\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_stat_code.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
+</p>\r
+</li>\r
+</ul></div>\r
</div>\r
<div class="sect2">\r
<h3 id="_http_stat_msg_2">http_stat_msg</h3>\r
<div class="paragraph"><p>What: rule option to set the detection cursor to the HTTP status message</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
+<div class="paragraph"><p>Configuration:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+implied <strong>http_stat_msg.with_body</strong>: parts of this rule examine HTTP message body\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_stat_msg.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
+</p>\r
+</li>\r
+</ul></div>\r
</div>\r
<div class="sect2">\r
<h3 id="_http_trailer">http_trailer</h3>\r
<h3 id="_http_uri">http_uri</h3>\r
<div class="paragraph"><p>What: rule option to set the detection cursor to the normalized URI buffer</p></div>\r
<div class="paragraph"><p>Type: ips_option</p></div>\r
+<div class="paragraph"><p>Configuration:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+implied <strong>http_uri.with_body</strong>: parts of this rule examine HTTP message body\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_uri.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_uri.scheme</strong>: match against scheme section of URI only\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_uri.host</strong>: match against host section of URI only\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_uri.port</strong>: match against port section of URI only\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_uri.path</strong>: match against path section of URI only\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_uri.query</strong>: match against query section of URI only\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_uri.fragment</strong>: match against fragment section of URI only\r
+</p>\r
+</li>\r
+</ul></div>\r
</div>\r
<div class="sect2">\r
<h3 id="_http_version_2">http_version</h3>\r
</li>\r
<li>\r
<p>\r
-implied <strong>regex.nocase</strong>: case insensitive match\r
+implied <strong>regex.dotall</strong>: matching a . will not exclude newlines\r
</p>\r
</li>\r
<li>\r
<p>\r
-implied <strong>regex.dotall</strong>: matching a . will not exclude newlines\r
+implied <strong>regex.fast_pattern</strong>: use this content in the fast pattern matcher instead of the content selected by default\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>regex.nocase</strong>: case insensitive match\r
</p>\r
</li>\r
<li>\r
</li>\r
</ul></div>\r
<div class="sect2">\r
+<h3 id="_features_new_to_snort_3">Features New to Snort 3</h3>\r
+<div class="paragraph"><p>Some things Snort++ can do today that Snort can not do:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+regex fast patterns, not just literals\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+FlatBuffers perf monitor logs\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+LuaJIT scriptable rule options and loggers\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+pub/sub inspection events (currently used by sip and http to appid)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+JIT buffer stuffers (notably with new http_inspect)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+C-style comments in rules\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+#begin … #end comment blocks in rules\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+rule remarks (comment is part of rule, not just in it)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+process raw files (eg read a PDF and do file processing)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+process raw payload (eg bridge 2 sockets and do inspection)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+fast pattern offload to separate thread (experimental)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+track all memory allocated\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+add or override any config item on command line\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+set CPU affinity\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+pause and resume commands\r
+</p>\r
+</li>\r
+</ul></div>\r
+</div>\r
+<div class="sect2">\r
+<h3 id="_features_improved_over_snort_2">Features Improved over Snort 2</h3>\r
+<div class="paragraph"><p>Some things Snort++ can do today that Snort can not do as well:</p></div>\r
+<div class="ulist"><ul>\r
+<li>\r
+<p>\r
+Hyperscan search engine plugin\r
+ (Intel provides patch for Snort 2)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+fast pattern sensitive data\r
+ (Snort 2 requires a slow, extra search)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+multiple packet threads with one config\r
+ (Snort 2 requires multiple processes)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+wizard automatically detects service for first flow\r
+ (Snort 2 appid detects for next flow)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+nested policy binding\r
+ (Snort 2 has just one level)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+decode arbitrary layers\r
+ (Snort 2 supports only 2 IP layers)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+process PDU buffers\r
+ (Snort 2 only processes packets)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+fully stateful http_inspect with 83 builtin alerts\r
+ (Snort 2 is only partly stateful with 33 builtin alerts)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+output all semantic errors before quitting\r
+ (Snort 2 stops at first one)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+alert service (eg http) and alert file rules\r
+ (Snort 2 must use metadata:service)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+elided rule headers omit nets and/or ports\r
+ (Snort 2 requires explicit <em>any</em>)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+dump builtin rule stubs\r
+ (Snort 2 can only dump SO stubs)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+rule sticky buffers\r
+ (Snort 2 buffers must be repeated)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+http_header:name supported to restrict to single field\r
+ (Snort 2 searches all headers)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+fully equivalent SO rules\r
+ (Snort 2 has some limitations with SO processing)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+text-based SO rule implementation\r
+ (Snort 2 requires tedious, nested C structs)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+extensible module-based tracing\r
+ (Snort 2 has a fixed set of flags)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+over 200 plugins, no need to change core source code\r
+ (Snort 2 only supports preprocessors and outputs)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+use consistent conf syntax\r
+ (Snort 2 defines lists different ways in different places, etc.)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+use consistent rule syntax\r
+ (Snort 2 has semicolon separated suboptions, etc.)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+arbitrary whitespace and comments in conf and rules\r
+ (Snort 2 requires newline escapes)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+properly parse rules\r
+ (Snort 2 can actually completely ignore stuff)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+optional warnings output, can be fatal\r
+ (Snort 2 warnings are not optional or fatal)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+define and use arbitrary variables and functions in config with Lua\r
+ (Snort 2 has variables just for rule headers)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+text-based command line shell\r
+ (Snort 2 has binary control socket)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+generate text and HTML user guide in addition to PDF\r
+ (Snort 2 just has PDF and Talos provides HTML)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+generate developer’s guide\r
+ (Snort 2’s is manually written)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+extensive command line help, eg every config item, rule option, and peg count\r
+ (Snort 2 only has command line args)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+cmake builds\r
+ (Snort 2 only does automake)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+read rules from separate file or stdin\r
+ (Snort 2 requires rules directly in or included in conf)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+simple, clean, uniform startup and shutdown output\r
+ (Snort 2 is heavy and inconsistent)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+better modularity 346K/1534 = 226 lines/file, max=2700\r
+ (Snort 2 has 440K/1021 = 431 lines/file, max=13K)\r
+</p>\r
+</li>\r
+</ul></div>\r
+</div>\r
+<div class="sect2">\r
<h3 id="_build_options">Build Options</h3>\r
<div class="ulist"><ul>\r
<li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
-<h3 id="_http_profiles">HTTP Profiles</h3>\r
-<div class="paragraph"><p>This section describes the changes to the Http Inspect config option "profile".</p></div>\r
-<div class="paragraph"><p>Snort 2 allows users to select pre-defined HTTP server profiles using the\r
-config option "profile". The user can choose one of five predefined profiles.\r
-When defined, this option will set defaults for other config options within\r
-Http Inspect.</p></div>\r
-<div class="paragraph"><p>With Snort 3, the user has the flexibility of defining and fine tuning custom\r
-profiles along with the five predefined profiles.</p></div>\r
-<div class="paragraph"><p>Snort 2 conf</p></div>\r
-<div class="literalblock">\r
-<div class="content">\r
-<pre><code>preprocessor http_inspect_server: server default \\r
- profile apache ports { 80 3128 } max_headers 200</code></pre>\r
-</div></div>\r
-<div class="paragraph"><p>Snort 3 conf</p></div>\r
-<div class="literalblock">\r
-<div class="content">\r
-<pre><code>http_inspect = { profile = http_profile_apache }\r
-http_inspect.profile.max_headers = 200</code></pre>\r
-</div></div>\r
-<div class="literalblock">\r
-<div class="content">\r
-<pre><code>binder =\r
-{\r
- {\r
- when = { proto = 'tcp', ports = '80 3128', },\r
- use = { type = 'http_inspect' },\r
- },\r
-}</code></pre>\r
-</div></div>\r
-<div class="admonitionblock">\r
-<table><tr>\r
-<td class="icon">\r
-<img src="./images/icons/note.png" alt="Note" />\r
-</td>\r
-<td class="content">The "profile" option now that points to a table "http_profile_apache"\r
-which is defined in "snort_defaults.lua" (as follows).</td>\r
-</tr></table>\r
-</div>\r
-<div class="literalblock">\r
-<div class="content">\r
-<pre><code>http_profile_apache =\r
-{\r
- profile_type = 'apache',\r
- server_flow_depth = 300,\r
- client_flow_depth = 300,\r
- post_depth = -1,\r
- chunk_length = 500000,\r
- ascii = true,\r
- multi_slash = true,\r
- directory = true,\r
- webroot = true,\r
- utf_8 = true,\r
- apache_whitespace = true,\r
- non_strict = true,\r
- normalize_utf = true,\r
- normalize_javascript = false,\r
- max_header_length = 0,\r
- max_headers = 0,\r
- max_spaces = 200,\r
- max_javascript_whitespaces = 200,\r
- whitespace_chars ='0x9 0xb 0xc 0xd'\r
-}</code></pre>\r
-</div></div>\r
-<div class="admonitionblock">\r
-<table><tr>\r
-<td class="icon">\r
-<img src="./images/icons/note.png" alt="Note" />\r
-</td>\r
-<td class="content">The config option "max_headers" is set to 0 in the profile, but\r
-overwritten by "http_inspect.profile.max_headers = 200".</td>\r
-</tr></table>\r
-</div>\r
-<div class="paragraph"><p>Conversion</p></div>\r
-<div class="paragraph"><p>snort2lua can convert the existing snort.conf with the "profile" option to\r
-Snort 3 compatible "profile". Please refer to the snort2Lua post for more\r
-details.</p></div>\r
-<div class="paragraph"><p>Examples</p></div>\r
-<div class="literalblock">\r
-<div class="content">\r
-<pre><code>"profile all" ==> "profile = http_profile_default"\r
-"profile apache" ==> "profile = http_profile_apache"\r
-"profile iis" ==> "profile = http_profile_iis"\r
-"profile iis_40" ==> "profile = http_profile_iis_40"\r
-"profile iis_50" ==> "profile = http_profile_iis_50"</code></pre>\r
-</div></div>\r
-<div class="paragraph"><p>Defining custom profiles</p></div>\r
-<div class="paragraph"><p>The complete set of Http Inspect config options that a custom profile can\r
-configure can be found by running the following command:</p></div>\r
-<div class="literalblock">\r
-<div class="content">\r
-<pre><code>snort --help-config http_inspect | grep http_inspect.profile</code></pre>\r
-</div></div>\r
-</div>\r
-<div class="sect2">\r
-<h3 id="_sdf_preprocessor">SDF Preprocessor</h3>\r
+<h3 id="_sensitive_data">Sensitive Data</h3>\r
<div class="paragraph"><p>The Snort 2.X SDF Preprocessor is gone, replaced by ips option <code>sd_pattern</code>.\r
The sd_pattern rule option is synonymous with the sd_pattern option used\r
for gid:138 rules, but has a different syntax. A major difference in syntax\r
<div class="paragraph"><p>One of the major differences between Snort 2 and Snort 3 is the\r
configuration. Snort 2 configuration files are written in Snort-specific\r
syntax while Snort 3 configuration files are written in Lua. Snort2Lua is\r
-a program specifically designed to convert Snort 2 configuration files\r
+a program specifically designed to convert valid Snort 2 configuration files\r
into Lua files that Snort 3 can understand.</p></div>\r
<div class="paragraph"><p>Snort2Lua reads your legacy Snort conf file(s) and generates Snort 3 Lua\r
-and rules files. When running this program, the only mandatory option is\r
+and rules files. When running this program, the only mandatory option is\r
to provide Snort2Lua with a Snort 2 configuration file. The default\r
output file file is snort.lua, the default error file will be snort.rej,\r
and the default rule file is the output file (default is snort.lua). When\r
manually adjust or comment the file name. Additionally, if the exit code is\r
not zero, some of the information may not be successfully converted. Check\r
the error file for all of the conversion problems.</p></div>\r
-<div class="paragraph"><p>Those errors can occur for a multitude of reasons and are not necessarily\r
-bad. For instance, Snort2Lua will only convert preprocessors that are\r
-currently supported. Therefore, any unsupported preprocessors or\r
-configuration options including DCERP, SIP, and SMTP, will cause an error\r
-in Snort2Lua since Snort 3 does not support those preprocessors.\r
-Additionally, any rule options associated with those preprocessors are also\r
-not supported. Finally, Snort2Lua expects a valid Snort 2 configuration.\r
+<div class="paragraph"><p>Those errors can occur for a multitude of reasons and are not\r
+necessarily bad. Snort2Lua expects a valid Snort 2 configuration.\r
Therefore, if the configuration is invalid or has questionable syntax,\r
Snort2Lua may fail to parse the configuration file or create an invalid\r
Snort 3 configuration file.</p></div>\r
</li>\r
<li>\r
<p>\r
-<strong>-q</strong> quiet mode. Only output valid confiration information to the\r
- <out_file>\r
+<strong>-q</strong> quiet mode. Only output valid configuration information to\r
+ the <out_file>\r
</p>\r
</li>\r
<li>\r
<li>\r
<p>\r
<strong>-s</strong> when parsing <include_file>, write <include_file>'s rules to\r
- <rule_file>. Meaningles if <em>-i</em> provided\r
+ <rule_file>. Meaningless if <em>-i</em> provided\r
</p>\r
</li>\r
<li>\r
<p>\r
<strong>-t</strong> when parsing <include_file>, write <include_file>'s\r
- information, excluding rules, to <out_file>. Meaningles if\r
+ information, excluding rules, to <out_file>. Meaningless if\r
<em>-i</em> provided\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>--ohi</strong> Use Old Http Inspect format\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>--output-file=<out_file></strong>\r
Same as <em>-o</em>. output the new Snort++ lua configuration to\r
<out_file>\r
</li>\r
<li>\r
<p>\r
-<strong>--quiet</strong> Same as <em>-q</em>. quiet mode. Only output valid confiration\r
+<strong>--quiet</strong> Same as <em>-q</em>. quiet mode. Only output valid configuration\r
information to the <out_file>\r
</p>\r
</li>\r
<p>\r
Snort2Lua currently does not handle variables well. First, that means\r
variables will not always be parsed correctly. Second, sometimes a\r
-variables value will be outoput in the lua file rather than a variable\r
+variables value will be output in the lua file rather than a variable\r
For instance, if Snort2Lua attempted to convert the line\r
-<em>include $RULE_PATH/example.rule</em>, the output may ouput\r
+<em>include $RULE_PATH/example.rule</em>, the output may output\r
<em>include /etc/rules/example.rule</em> instead.\r
</p>\r
</li>\r
<p>\r
If a rule’s action is a custom ruletype, that rule action will be silently\r
converted to the rultype’s <em>type</em>. No warnings or errors are currently\r
-emmitted. Additionally, the custom ruletypes outputs will be silently\r
+emitted. Additionally, the custom ruletypes outputs will be silently\r
discarded.\r
</p>\r
</li>\r
multiple error returns. The C-style use of zero for success and -1 for\r
error is less readable and often leads to messy code that either ignores\r
the various errors anyway or needlessly and ineffectively tries to do\r
- something aobut them. Generally that code is not updated if new errors\r
+ something about them. Generally that code is not updated if new errors\r
are added.\r
</p>\r
</li>\r
support.\r
</p>\r
</li>\r
+<li>\r
+<p>\r
+<strong>--enable-tsc-clock</strong>: use the TSC register on x86 systems for improved\r
+ performance of latency and profiler features.\r
+</p>\r
+</li>\r
</ul></div>\r
<div class="paragraph"><p>These options are built only if the required libraries and headers are\r
present. There is no need to explicitly enable.</p></div>\r
<div class="ulist"><ul>\r
<li>\r
<p>\r
-<strong>lzma</strong>: for decompression of SWF and PDF files.\r
+<strong>flatbuffers</strong>: for an alternative perf_monitor logging format.\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>openssl</strong>: for SHA and MD5 file signatures and the protected_content rule\r
- option.\r
+<strong>hyperscan</strong> >= 4.4.0: for the regex and sd_pattern rule options and the hyperscan\r
+ search engine.\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-hyperscan for the regex rule option and hyperscan search engine.\r
+<strong>lzma</strong>: for decompression of SWF and PDF files.\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>safec</strong>: for additional runtime error checking of some memory copy operations.\r
</p>\r
</li>\r
</ul></div>\r
</p>\r
</li>\r
</ul></div>\r
-<div class="paragraph"><p>These can be use for pcap, luajit, pcre, dnet, daq, lzma, openssl,\r
-intel-soft-cpm, and hyperscan packages. For more information on these\r
-libraries see the Getting Started section of the manual.</p></div>\r
+<div class="paragraph"><p>These can be used for pcap, luajit, pcre, dnet, daq, lzma, openssl,\r
+intel-soft-cpm, flatbuffers, and hyperscan packages. For more information on\r
+these libraries see the Getting Started section of the manual.</p></div>\r
</div>\r
<div class="sect2">\r
<h3 id="_environment_variables">Environment Variables</h3>\r
<div class="ulist"><ul>\r
<li>\r
<p>\r
-<strong>--alert-before-pass</strong> process alert, drop, sdrop, or reject before pass; default is pass before alert, drop,…\r
+<strong>-?</strong> <option prefix> output matching command line option quick help (same as --help-options) (optional)\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>--bpf</strong> <filter options> are standard BPF options, as seen in TCPDump\r
+<strong>-C</strong> print out payloads with character data only (no hex)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--c2x</strong> output hex for given char (see also --x2c)\r
+<strong>-c</strong> <conf> use this configuration\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--catch-test</strong> comma separated list of cat unit test tags or <em>all</em>\r
+<strong>-D</strong> run Snort in background (daemon) mode\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-c</strong> <conf> use this configuration\r
+<strong>-d</strong> dump the Application Layer\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-C</strong> print out payloads with character data only (no hex)\r
+<strong>-e</strong> display the second layer header info\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--create-pidfile</strong> create PID file, even when not in Daemon mode\r
+<strong>-f</strong> turn off fflush() calls after binary log writes\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--daq-dir</strong> <dir> tell snort where to find desired DAQ\r
+<strong>-G</strong> <0xid> (same as --logid) (0:65535)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--daq-list</strong> list packet acquisition modules available in optional dir, default is static modules only\r
+<strong>-g</strong> <gname> run snort gid as <gname> group (or gid) after initialization\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--daq</strong> <type> select packet acquisition module (default is pcap)\r
+<strong>-H</strong> make hash tables deterministic\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--daq-var</strong> <name=value> specify extra DAQ configuration variable\r
+<strong>-i</strong> <iface>… list of interfaces\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-d</strong> dump the Application Layer\r
+<strong>-j</strong> <port> to listen for telnet connections\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--dirty-pig</strong> don’t flush packets on shutdown\r
+<strong>-k</strong> <mode> checksum mode; default is all (all|noip|notcp|noudp|noicmp|none)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-D</strong> run Snort in background (daemon) mode\r
+<strong>-L</strong> <mode> logging mode (none, dump, pcap, or log_*)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--dump-builtin-rules</strong> [<module prefix>] output stub rules for selected modules\r
+<strong>-l</strong> <logdir> log to this directory instead of current directory\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--dump-defaults</strong> [<module prefix>] output module defaults in Lua format (optional)\r
+<strong>-M</strong> log messages to syslog (not alerts)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--dump-dynamic-rules</strong> output stub rules for all loaded rules libraries\r
+<strong>-m</strong> <umask> set umask = <umask> (0:)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--dump-version</strong> output the version, the whole version, and only the version\r
+<strong>-n</strong> <count> stop after count packets (0:)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-e</strong> display the second layer header info\r
+<strong>-O</strong> obfuscate the logged IP addresses\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--enable-inline-test</strong> enable Inline-Test Mode Operation\r
+<strong>-Q</strong> enable inline mode operation\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-f</strong> turn off fflush() calls after binary log writes\r
+<strong>-q</strong> quiet mode - Don’t show banner and status report\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-G</strong> <0xid> (same as --logid) (0:65535)\r
+<strong>-R</strong> <rules> include this rules file in the default policy\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-g</strong> <gname> run snort gid as <gname> group (or gid) after initialization\r
+<strong>-r</strong> <pcap>… (same as --pcap-list)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--help-commands</strong> [<module prefix>] output matching commands (optional)\r
+<strong>-S</strong> <x=v> set config variable x equal to value v\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--help-config</strong> [<module prefix>] output matching config options (optional)\r
+<strong>-s</strong> <snap> (same as --snaplen); default is 1514 (68:65535)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--help-counts</strong> [<module prefix>] output matching peg counts (optional)\r
+<strong>-T</strong> test and report on the current Snort configuration\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--help</strong> list command line options\r
+<strong>-t</strong> <dir> chroots process to <dir> after initialization\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--help-module</strong> <module> output description of given module\r
+<strong>-U</strong> use UTC for timestamps\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--help-modules</strong> list all available modules with brief help\r
+<strong>-u</strong> <uname> run snort as <uname> or <uid> after initialization\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--help-options</strong> <option prefix> output matching command line option quick help (same as -?) (optional)\r
+<strong>-V</strong> (same as --version)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--help-plugins</strong> list all available plugins with brief help\r
+<strong>-v</strong> be verbose\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--help-signals</strong> dump available control signals\r
+<strong>-W</strong> lists available interfaces\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-H</strong> make hash tables deterministic\r
+<strong>-X</strong> dump the raw packet data starting at the link layer\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--id-subdir</strong> create/use instance subdirectories in logdir instead of instance filename prefix\r
+<strong>-x</strong> same as --pedantic\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--id-zero</strong> use id prefix / subdirectory even with one packet thread\r
+<strong>-y</strong> include year in timestamp in the alert and log files\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-i</strong> <iface>… list of interfaces\r
+<strong>-z</strong> <count> maximum number of packet threads (same as --max-packet-threads); 0 gets the number of CPU cores reported by the system; default is 1 (0:)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-j</strong> <port> to listen for telnet connections\r
+<strong>--alert-before-pass</strong> process alert, drop, sdrop, or reject before pass; default is pass before alert, drop,…\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-k</strong> <mode> checksum mode; default is all (all|noip|notcp|noudp|noicmp|none)\r
+<strong>--bpf</strong> <filter options> are standard BPF options, as seen in TCPDump\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--c2x</strong> output hex for given char (see also --x2c)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--control-socket</strong> <file> to create unix socket\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--create-pidfile</strong> create PID file, even when not in Daemon mode\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--daq</strong> <type> select packet acquisition module (default is pcap)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--daq-dir</strong> <dir> tell snort where to find desired DAQ\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--daq-list</strong> list packet acquisition modules available in optional dir, default is static modules only\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--daq-var</strong> <name=value> specify extra DAQ configuration variable\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--dirty-pig</strong> don’t flush packets on shutdown\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--dump-builtin-rules</strong> [<module prefix>] output stub rules for selected modules\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--dump-dynamic-rules</strong> output stub rules for all loaded rules libraries\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--dump-defaults</strong> [<module prefix>] output module defaults in Lua format (optional)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--dump-version</strong> output the version, the whole version, and only the version\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--enable-inline-test</strong> enable Inline-Test Mode Operation\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--help</strong> list command line options\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--help-commands</strong> [<module prefix>] output matching commands (optional)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--help-config</strong> [<module prefix>] output matching config options (optional)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--help-counts</strong> [<module prefix>] output matching peg counts (optional)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--help-module</strong> <module> output description of given module\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--help-modules</strong> list all available modules with brief help\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--help-options</strong> <option prefix> output matching command line option quick help (same as -?) (optional)\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--help-plugins</strong> list all available plugins with brief help\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--help-signals</strong> dump available control signals\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--id-subdir</strong> create/use instance subdirectories in logdir instead of instance filename prefix\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>--id-zero</strong> use id prefix / subdirectory even with one packet thread\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>-l</strong> <logdir> log to this directory instead of current directory\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-L</strong> <mode> logging mode (none, dump, pcap, or log_*)\r
+<strong>--lua</strong> <chunk> extend/override conf with chunk; may be repeated\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>--lua</strong> <chunk> extend/override conf with chunk; may be repeated\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>--markup</strong> output help in asciidoc compatible format\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>-M</strong> log messages to syslog (not alerts)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-m</strong> <umask> set umask = <umask> (0:)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-n</strong> <count> stop after count packets (0:)\r
+<strong>--nostamps</strong> don’t include timestamps in log file names\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>--nostamps</strong> don’t include timestamps in log file names\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-O</strong> obfuscate the logged IP addresses\r
+<strong>--pause</strong> wait for resume/quit command before processing packets/terminating\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-?</strong> <option prefix> output matching command line option quick help (same as --help-options) (optional)\r
+<strong>--pcap-file</strong> <file> file that contains a list of pcaps to read - read mode is implied\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--pause</strong> wait for resume/quit command before processing packets/terminating\r
+<strong>--pcap-list</strong> <list> a space separated list of pcaps to read - read mode is implied\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>--pcap-file</strong> <file> file that contains a list of pcaps to read - read mode is implied\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>--pcap-filter</strong> <filter> filter to apply when getting pcaps from file or directory\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>--pcap-list</strong> <list> a space separated list of pcaps to read - read mode is implied\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>--pcap-loop</strong> <count> read all pcaps <count> times; 0 will read until Snort is terminated (-1:)\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>--piglet</strong> enable piglet test harness mode\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>--plugin-path</strong> <path> where to find plugins\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>-Q</strong> enable inline mode operation\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-q</strong> quiet mode - Don’t show banner and status report\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-r</strong> <pcap>… (same as --pcap-list)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-R</strong> <rules> include this rules file in the default policy\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>--rule</strong> <rules> to be added to configuration; may be repeated\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>-s</strong> <snap> (same as --snaplen); default is 1514 (68:65535)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>--stdin-rules</strong> read rules from stdin until EOF or a line starting with END is read\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-S</strong> <x=v> set config variable x equal to value v\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-t</strong> <dir> chroots process to <dir> after initialization\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>--treat-drop-as-alert</strong> converts drop, sdrop, and reject rules into alert rules during startup\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>-T</strong> test and report on the current Snort configuration\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-u</strong> <uname> run snort as <uname> or <uid> after initialization\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-U</strong> use UTC for timestamps\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-v</strong> be verbose\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>--version</strong> show version number (same as -V)\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>-V</strong> (same as --version)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>--warn-all</strong> enable all warnings\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>-W</strong> lists available interfaces\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>--x2c</strong> output ASCII char for given hex (see also --c2x)\r
</p>\r
</li>\r
<strong>--x2s</strong> output ASCII string for given byte code (see also --x2c)\r
</p>\r
</li>\r
-<li>\r
-<p>\r
-<strong>-X</strong> dump the raw packet data starting at the link layer\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-x</strong> same as --pedantic\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-y</strong> include year in timestamp in the alert and log files\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>-z</strong> <count> maximum number of packet threads (same as --max-packet-threads); 0 gets the number of CPU cores reported by the system; default is 1 (0:)\r
-</p>\r
-</li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
</li>\r
<li>\r
<p>\r
+bool <strong>appid.log_all_sessions</strong> = false: enable logging of all appid sessions\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
bool <strong>appid.log_stats</strong> = false: enable logging of appid statistics\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
+int <strong>byte_extract.bitmask</strong>: applies as an AND to the extracted value before storage in <em>name</em> { 0x1:0xFFFFFFFF }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
int <strong>byte_extract.~count</strong>: number of bytes to pick up from the buffer { 1:10 }\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-int <strong>byte_jump.~count</strong>: number of bytes to pick up from the buffer { 1:10 }\r
+int <strong>byte_jump.bitmask</strong>: applies as an AND prior to evaluation { 0x1:0xFFFFFFFF }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+int <strong>byte_jump.~count</strong>: number of bytes to pick up from the buffer { 0:10 }\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
+implied <strong>byte_jump.from_end</strong>: jump backward from end of buffer\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
implied <strong>byte_jump.hex</strong>: convert from hex string\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
+int <strong>byte_math.bitmask</strong>: applies as bitwise AND to the extracted value before storage in <em>name</em> { 0x1:0xFFFFFFFF }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+int <strong>byte_math.bytes</strong>: number of bytes to pick up from the buffer { 1:10 }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>byte_math.dce</strong>: dcerpc2 determines endianness\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+enum <strong>byte_math.endian</strong>: specify big/little endian { big|little }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+string <strong>byte_math.offset</strong>: number of bytes into the buffer to start processing\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+enum <strong>byte_math.oper</strong>: mathematical operation to perform { +|-|*|/|<<|>> }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>byte_math.relative</strong>: offset from cursor instead of start of buffer\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+string <strong>byte_math.result</strong>: name of the variable to store the result\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+string <strong>byte_math.rvalue</strong>: value to use mathematical operation against\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+enum <strong>byte_math.string</strong>: convert extracted string to dec/hex/oct { hex|dec|oct }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
implied <strong>byte_test.big</strong>: big endian\r
</p>\r
</li>\r
<li>\r
<p>\r
+int <strong>byte_test.bitmask</strong>: applies as an AND prior to evaluation { 0x1:0xFFFFFFFF }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
string <strong>byte_test.~compare</strong>: variable name or value to test the converted result against\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
+int <strong>detection.offload_limit</strong> = 99999: minimum sizeof PDU to offload fast pattern search (defaults to disabled) { 0: }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+int <strong>detection.offload_threads</strong> = 0: maximum number of simultaneous offloads (defaults to disabled) { 0: }\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
bool <strong>detection.pcre_enable</strong> = true: disable pcre pattern matching\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
+int <strong>detection.trace</strong>: mask for enabling debug traces in module\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
bool <strong>dnp3.check_crc</strong> = false: validate checksums in DNP3 link layer frames\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-int <strong>http_global.compress_depth</strong> = 65535: maximum amount of packet payload to decompress { 1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.decode.b64_decode_depth</strong> = 0: single packet decode depth { -1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.decode.bitenc_decode_depth</strong> = 0: single packet decode depth { -1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.decode.max_mime_mem</strong> = 838860: single packet decode depth { 3276: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.decode.qp_decode_depth</strong> = 0: single packet decode depth { -1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_global.decode.uu_decode_depth</strong> = 0: single packet decode depth { -1:65535 }\r
+implied <strong>http_cookie.request</strong>: match against the cookie from the request message even when examining the response\r
</p>\r
</li>\r
<li>\r
<p>\r
-int <strong>http_global.decompress_depth</strong> = 65535: maximum amount of decompressed data to process { 1:65535 }\r
+implied <strong>http_cookie.with_body</strong>: parts of this rule examine HTTP message body\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_global.detect_anomalous_servers</strong> = false: inspect non-configured ports for HTTP - bad idea\r
+implied <strong>http_cookie.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
</p>\r
</li>\r
<li>\r
<p>\r
-int <strong>http_global.max_gzip_mem</strong> = 0: disregard - not implemented { 0: }\r
+string <strong>http_header.field</strong>: restrict to given header. Header name is case insensitive.\r
</p>\r
</li>\r
<li>\r
<p>\r
-int <strong>http_global.memcap</strong> = 0: disregard - not implemented { 0: }\r
+implied <strong>http_header.request</strong>: match against the headers from the request message even when examining the response\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_global.proxy_alert</strong> = false: alert on proxy usage for servers without allow_proxy_use\r
+implied <strong>http_header.with_body</strong>: parts of this rule examine HTTP message body\r
</p>\r
</li>\r
<li>\r
<p>\r
-int <strong>http_global.unicode_map.code_page</strong> = 1252: select code page in map file { 0: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-string <strong>http_global.unicode_map.map_file</strong>: unicode map file\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-string <strong>http_header.~name</strong>: restrict to given header\r
+implied <strong>http_header.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-int <strong>http_inspect.print_amount</strong> = 1200: number of characters to print from a Field { 1:1000000 }\r
+int <strong>http_inspect.request_depth</strong> = -1: maximum request message body bytes to examine (-1 no limit) { -1: }\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_inspect.print_hex</strong> = false: nonprinting characters printed in [HH] format instead of using an asterisk\r
+int <strong>http_inspect.response_depth</strong> = -1: maximum response message body bytes to examine (-1 no limit) { -1: }\r
</p>\r
</li>\r
<li>\r
<p>\r
-int <strong>http_inspect.request_depth</strong> = -1: maximum request message body bytes to examine (-1 no limit) { -1: }\r
+bool <strong>http_inspect.simplify_path</strong> = true: reduce URI directory path to simplest form\r
</p>\r
</li>\r
<li>\r
<p>\r
-int <strong>http_inspect.response_depth</strong> = -1: maximum response message body bytes to examine (-1 no limit) { -1: }\r
+bool <strong>http_inspect.unzip</strong> = true: decompress gzip and deflate message bodies\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_inspect.show_pegs</strong> = true: display peg counts with test output\r
+bool <strong>http_inspect.utf8_bare_byte</strong> = false: when doing UTF-8 character normalization include bytes that were not percent encoded\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_inspect.simplify_path</strong> = true: reduce URI directory path to simplest form\r
+bool <strong>http_inspect.utf8</strong> = true: normalize 2-byte and 3-byte UTF-8 characters to a single byte\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_inspect.test_input</strong> = false: read HTTP messages from text file\r
+implied <strong>http_method.with_body</strong>: parts of this rule examine HTTP message body\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_inspect.test_output</strong> = false: print out HTTP section data\r
+implied <strong>http_method.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_inspect.unzip</strong> = true: decompress gzip and deflate message bodies\r
+implied <strong>http_raw_cookie.request</strong>: match against the cookie from the request message even when examining the response\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_inspect.utf8_bare_byte</strong> = false: when doing UTF-8 character normalization include bytes that were not percent encoded\r
+implied <strong>http_raw_cookie.with_body</strong>: parts of this rule examine HTTP message body\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_inspect.utf8</strong> = true: normalize 2-byte and 3-byte UTF-8 characters to a single byte\r
+implied <strong>http_raw_cookie.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_header.request</strong>: match against the headers from the request message even when examining the response\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_header.with_body</strong>: parts of this rule examine HTTP message body\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+implied <strong>http_raw_header.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.allow_proxy_use</strong> = false: don’t alert on proxy use for this server\r
+implied <strong>http_raw_uri.fragment</strong>: match against fragment section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.decompress_pdf</strong> = false: enable decompression of the compressed portions of PDF files\r
+implied <strong>http_raw_uri.host</strong>: match against host section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.decompress_swf</strong> = false: enable decompression of SWF (Adobe Flash content)\r
+implied <strong>http_raw_uri.path</strong>: match against path section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.enable_cookies</strong> = true: extract cookies\r
+implied <strong>http_raw_uri.port</strong>: match against port section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.enable_xff</strong> = false: log True-Client-IP and X-Forwarded-For headers with unified2 alerts as extra data\r
+implied <strong>http_raw_uri.query</strong>: match against query section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.extended_ascii_uri</strong> = false: allow extended ASCII codes in the request URI\r
+implied <strong>http_raw_uri.scheme</strong>: match against scheme section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.extended_response_inspection</strong> = true: extract response headers\r
+implied <strong>http_raw_uri.with_body</strong>: parts of this rule examine HTTP message body\r
</p>\r
</li>\r
<li>\r
<p>\r
-string <strong>http_server.http_methods</strong> = GET POST PUT SEARCH MKCOL COPY MOVE LOCK UNLOCK NOTIFY POLL BCOPY BDELETE BMOVE LINK UNLINK OPTIONS HEAD DELETE TRACE TRACK CONNECT SOURCE SUBSCRIBE UNSUBSCRIBE PROPFIND PROPPATCH BPROPFIND BPROPPATCH RPC_CONNECT PROXY_SUCCESS BITS_POST CCM_POST SMS_POST RPC_IN_DATA RPC_OUT_DATA RPC_ECHO_DATA: request methods allowed in addition to GET and POST\r
+implied <strong>http_raw_uri.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.inspect_gzip</strong> = true: enable gzip decompression of compressed bodies\r
+implied <strong>http_stat_code.with_body</strong>: parts of this rule examine HTTP message body\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.inspect_uri_only</strong> = false: disable all detection except for uricontent\r
+implied <strong>http_stat_code.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.log_hostname</strong> = false: enable logging of Hostname with unified2 alerts as extra data\r
+implied <strong>http_stat_msg.with_body</strong>: parts of this rule examine HTTP message body\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.log_uri</strong> = false: enable logging of URI with unified2 alerts as extra data\r
+implied <strong>http_stat_msg.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
</p>\r
</li>\r
<li>\r
<p>\r
-bit_list <strong>http_server.non_rfc_chars</strong> = 0x00 0x01 0x02 0x03 0x04 0x05 0x06 0x07: alert on given non-RFC chars being present in the URI { 255 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.no_pipeline_req</strong> = false: don’t inspect pipelined requests after first (still does general detection)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.normalize_cookies</strong> = false: normalize cookies similar to URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.normalize_headers</strong> = false: normalize headers other than cookie similar to URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.oversize_dir_length</strong> = 500: alert if a URL has a directory longer than this limit { 0: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.apache_whitespace</strong> = false: don’t alert if tab is used in lieu of space characters\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.ascii</strong> = false: enable decoding ASCII like %2f to /\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.bare_byte</strong> = false: decode non-standard, non-ASCII character encodings\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.chunk_length</strong> = 500000: alert on chunk lengths greater than specified { 1: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.client_flow_depth</strong> = 0: raw request payload to inspect { -1:1460 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.directory</strong> = false: normalize . and .. sequences out of URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.double_decode</strong> = false: iis specific extra decoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.iis_backslash</strong> = false: normalize directory slashes\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.iis_delimiter</strong> = false: allow use of non-standard delimiter\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.iis_unicode</strong> = false: enable unicode code point mapping using unicode_map settings\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.iis_unicode_map.code_page</strong> = 1252: select code page in map file { 0: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-string <strong>http_server.profile.iis_unicode_map.map_file</strong>: unicode map file\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.max_header_length</strong> = 750: maximum allowed client request header field { 0:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.max_headers</strong> = 100: maximum allowed client request headers { 0:1024 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.max_javascript_whitespaces</strong> = 200: maximum number of consecutive whitespaces { 0: }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.max_spaces</strong> = 200: maximum allowed whitespaces when folding { 0:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.multi_slash</strong> = false: normalize out consecutive slashes in URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.non_strict</strong> = true: allows HTTP 0.9 processing\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.normalize_javascript</strong> = true: normalize javascript between <script> tags\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.normalize_utf</strong> = true: normalize response bodies with UTF content-types\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.post_depth</strong> = 65495: amount of POST data to inspect { -1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-enum <strong>http_server.profile.profile_type</strong> = default: set defaults appropriate for selected server { default | apache | iis | iis_40 | iis_50 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-int <strong>http_server.profile.server_flow_depth</strong> = 0: response payload to inspect; includes headers with extended_response_inspection { -1:65535 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-bool <strong>http_server.profile.u_encode</strong> = true: decode %uXXXX character sequences\r
+string <strong>http_trailer.field</strong>: restrict to given trailer\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.profile.utf_8</strong> = false: decode UTF-8 unicode sequences in URI\r
+implied <strong>http_trailer.request</strong>: match against the trailers from the request message even when examining the response\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.profile.webroot</strong> = false: alert on directory traversals past the top level (web server root)\r
+implied <strong>http_trailer.with_body</strong>: parts of this rule examine HTTP message body (must be combined with request)\r
</p>\r
</li>\r
<li>\r
<p>\r
-bit_list <strong>http_server.profile.whitespace_chars</strong>: allowed white space characters { 255 }\r
+implied <strong>http_trailer.with_header</strong>: parts of this rule examine HTTP response message headers (must be combined with request)\r
</p>\r
</li>\r
<li>\r
<p>\r
-int <strong>http_server.small_chunk_count</strong> = 5: alert if more than this limit of consecutive chunks are below small_chunk_length { 0:255 }\r
+implied <strong>http_uri.fragment</strong>: match against fragment section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-int <strong>http_server.small_chunk_length</strong> = 10: alert if more than small_chunk_count consecutive chunks below this limit { 0:255 }\r
+implied <strong>http_uri.host</strong>: match against host section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.tab_uri_delimiter</strong> = false: whether a tab not preceded by a space is considered a delimiter or part of URI\r
+implied <strong>http_uri.path</strong>: match against path section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.unlimited_decompress</strong> = true: decompress across multiple packets\r
+implied <strong>http_uri.port</strong>: match against port section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-bool <strong>http_server.xff_headers</strong> = false: not implemented\r
+implied <strong>http_uri.query</strong>: match against query section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-string <strong>http_trailer.field</strong>: restrict to given trailer\r
+implied <strong>http_uri.scheme</strong>: match against scheme section of URI only\r
</p>\r
</li>\r
<li>\r
<p>\r
-implied <strong>http_trailer.request</strong>: match against the trailers from the request message even when examining the response\r
+implied <strong>http_uri.with_body</strong>: parts of this rule examine HTTP message body\r
</p>\r
</li>\r
<li>\r
<p>\r
-implied <strong>http_trailer.with_body</strong>: parts of this rule examine HTTP message body (must be combined with request)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-implied <strong>http_trailer.with_header</strong>: parts of this rule examine HTTP response message headers (must be combined with request)\r
+implied <strong>http_uri.with_trailer</strong>: parts of this rule examine HTTP message trailers\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
+bool <strong>output.wide_hex_dump</strong> = false: output 20 bytes per lines instead of 16 when dumping buffers\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
bool <strong>packet_capture.enable</strong> = false: initially enable packet dumping\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-enum <strong>perf_monitor.format</strong> = csv: output format for stats { csv | text }\r
+enum <strong>perf_monitor.format</strong> = csv: output format for stats { csv | text | flatbuffers }\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
+implied <strong>regex.fast_pattern</strong>: use this content in the fast pattern matcher instead of the content selected by default\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
implied <strong>regex.multiline</strong>: ^ and $ anchors match any newlines in data\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-int <strong>sip.max_sessions</strong> = 10000: maximum number of sessions that can be allocated { 1024:4194303 }\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
int <strong>sip.max_to_len</strong> = 256: maximum to field size { 0:65535 }\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-string <strong>snort.--catch-test</strong>: comma separated list of cat unit test tags or <em>all</em>\r
+string <strong>snort.-c</strong>: <conf> use this configuration\r
</p>\r
</li>\r
<li>\r
<p>\r
-string <strong>snort.-c</strong>: <conf> use this configuration\r
+string <strong>snort.--control-socket</strong>: <file> to create unix socket\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-implied <strong>snort.--piglet</strong>: enable piglet test harness mode\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
string <strong>snort.--plugin-path</strong>: <path> where to find plugins\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>dce_smb.client_segs_reassembled</strong>: total smb client segments reassembled\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>dce_smb.events</strong>: total events\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>dce_smb.server_segs_reassembled</strong>: total smb server segments reassembled\r
+<strong>dce_smb.sessions</strong>: total smb sessions\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>dce_smb.sessions</strong>: total smb sessions\r
+<strong>dce_smb.shutdowns</strong>: total connection-oriented shutdowns\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>dce_smb.shutdowns</strong>: total connection-oriented shutdowns\r
+<strong>dce_smb.smb_client_segs_reassembled</strong>: total smb client segments reassembled\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>dce_smb.smb_server_segs_reassembled</strong>: total smb server segments reassembled\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
+<strong>detection.offloads</strong>: fast pattern searches that were offloaded\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>detection.passed</strong>: passed packets\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>http_global.compressed_bytes</strong>: total comparessed bytes processed\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.decompressed_bytes</strong>: total bytes decompressed\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.double_unicode</strong>: double unicode normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.gets</strong>: GET requests\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.gzip_packets</strong>: packets with gzip compression\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.non_ascii</strong>: non-ascii normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.packets</strong>: total packets processed\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.paths_with_double_slash</strong>: double slash (//) normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.paths_with_relative</strong>: relative directory (./) normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.paths_with_traversal</strong>: directory traversal (../) normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.post_params</strong>: POST parameters extracted\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.posts</strong>: POST requests\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.request_cookies</strong>: requests with Cookie\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.request_headers</strong>: total requests\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.response_cookies</strong>: responses with Set-Cookie\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.response_headers</strong>: total responses\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_global.unicode</strong>: unicode normalizations\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>http_inspect.chunked</strong>: chunked message bodies\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>normalizer.tcp_paddding</strong>: packets with padding cleared\r
+<strong>normalizer.tcp_padding</strong>: packets with padding cleared\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>normalizer.tcp_trim_win</strong>: data trimed to window\r
+<strong>normalizer.tcp_trim_win</strong>: data trimmed to window\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>normalizer.test_tcp_paddding</strong>: test packets with padding cleared\r
+<strong>normalizer.test_tcp_padding</strong>: test packets with padding cleared\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>normalizer.test_tcp_trim_win</strong>: test data trimed to window\r
+<strong>normalizer.test_tcp_trim_win</strong>: test data trimmed to window\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.1xx</strong>: 1xx\r
+<strong>sip.ack</strong>: ack\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.2xx</strong>: 2xx\r
+<strong>sip.bye</strong>: bye\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.3xx</strong>: 3xx\r
+<strong>sip.cancel</strong>: cancel\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.4xx</strong>: 4xx\r
+<strong>sip.code_1xx</strong>: 1xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.5xx</strong>: 5xx\r
+<strong>sip.code_2xx</strong>: 2xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.6xx</strong>: 6xx\r
+<strong>sip.code_3xx</strong>: 3xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.7xx</strong>: 7xx\r
+<strong>sip.code_4xx</strong>: 4xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.8xx</strong>: 8xx\r
+<strong>sip.code_5xx</strong>: 5xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.9xx</strong>: 9xx\r
+<strong>sip.code_6xx</strong>: 6xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.ack</strong>: ack\r
+<strong>sip.code_7xx</strong>: 7xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.bye</strong>: bye\r
+<strong>sip.code_8xx</strong>: 8xx\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>sip.cancel</strong>: cancel\r
+<strong>sip.code_9xx</strong>: 9xx\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
+<strong>snort.daq_reloads</strong>: number of times daq configuration was reloaded\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>snort.local_commands</strong>: total local commands processed\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>stream_tcp.3way_trackers</strong>: tcp session tracking started on ack\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>stream_tcp.client_cleanups</strong>: number of times data from server was flushed when session released\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
+<strong>stream_tcp.three_way_trackers</strong>: tcp session tracking started on ack\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>stream_tcp.timeouts</strong>: tcp session timeouts\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
+<strong>116</strong>: llc\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>116</strong>: mpls\r
</p>\r
</li>\r
<strong>256</strong>: dpx\r
</p>\r
</li>\r
-<li>\r
-<p>\r
-<strong>319</strong>: http_global\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320</strong>: http_server\r
-</p>\r
-</li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
</li>\r
<li>\r
<p>\r
-<strong>116:131</strong> (vlan) bad LLC header\r
+<strong>116:131</strong> (llc) bad LLC header\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>116:132</strong> (vlan) bad extra LLC info\r
+<strong>116:132</strong> (llc) bad extra LLC info\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
+<strong>116:473</strong> (decode) ether type out of range\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>119:1</strong> (http_inspect) ascii encoding\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>119:7</strong> (http_inspect) IIS unicode codepoint encoding\r
+<strong>119:7</strong> (http_inspect) unicode map code point encoding in URI\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>119:9</strong> (http_inspect) IIS backslash evasion\r
+<strong>119:9</strong> (http_inspect) backslash used in URI path\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>119:13</strong> (http_inspect) non-RFC http delimiter\r
+<strong>119:13</strong> (http_inspect) HTTP header line terminated by LF without a CR\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>119:26</strong> (http_inspect) header parsing space saturation\r
+<strong>119:26</strong> (http_inspect) too much whitespace in header (not implemented yet)\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>119:37</strong> (http_inspect) no content-length or transfer-encoding in HTTP response\r
+<strong>119:37</strong> (http_inspect) unused event number—should not appear\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>119:42</strong> (http_inspect) invalid content-length or chunk size\r
+<strong>119:42</strong> (http_inspect) unused event number—should not appear\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
+<strong>119:81</strong> (http_inspect) nonprinting character in HTTP message header name\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>119:82</strong> (http_inspect) bad Content-Length value in HTTP header\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>119:83</strong> (http_inspect) HTTP header line wrapped\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>119:84</strong> (http_inspect) HTTP header line terminated by CR without a LF\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>122:1</strong> (port_scan) TCP portscan\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>140:1</strong> (sip) maximum sessions reached\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>140:2</strong> (sip) empty request URI\r
</p>\r
</li>\r
<strong>256:1</strong> (dpx) too much data sent to port\r
</p>\r
</li>\r
-<li>\r
-<p>\r
-<strong>319:1</strong> (http_global) ascii encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:2</strong> (http_global) double decoding attack\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:3</strong> (http_global) u encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:4</strong> (http_global) bare byte unicode encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:5</strong> (http_global) base36 encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:6</strong> (http_global) UTF-8 encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:7</strong> (http_global) IIS unicode codepoint encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:8</strong> (http_global) multi_slash encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:9</strong> (http_global) IIS backslash evasion\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:10</strong> (http_global) self directory traversal\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:11</strong> (http_global) directory traversal\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:12</strong> (http_global) apache whitespace (tab)\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:13</strong> (http_global) non-RFC http delimiter\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:14</strong> (http_global) non-RFC defined char\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:15</strong> (http_global) oversize request-URI directory\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:16</strong> (http_global) oversize chunk encoding\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:17</strong> (http_global) unauthorized proxy use detected\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:18</strong> (http_global) webroot directory traversal\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:19</strong> (http_global) long header\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:20</strong> (http_global) max header fields\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:21</strong> (http_global) multiple content length\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:22</strong> (http_global) chunk size mismatch detected\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:23</strong> (http_global) invalid ip in true-client-IP/XFF header\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:24</strong> (http_global) multiple host hdrs detected\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:25</strong> (http_global) hostname exceeds 255 characters\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:26</strong> (http_global) header parsing space saturation\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:27</strong> (http_global) client consecutive small chunk sizes\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:28</strong> (http_global) post w/o content-length or chunks\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:29</strong> (http_global) multiple true IPs in a session\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:30</strong> (http_global) both true-client-IP and XFF hdrs present\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:31</strong> (http_global) unknown method\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:32</strong> (http_global) simple request\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:33</strong> (http_global) unescaped space in http URI\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>319:34</strong> (http_global) too many pipelined requests\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:1</strong> (http_server) anomalous http server on undefined HTTP port\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:2</strong> (http_server) invalid status code in HTTP response\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:3</strong> (http_server) no content-length or transfer-encoding in HTTP response\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:4</strong> (http_server) HTTP response has UTF charset which failed to normalize\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:5</strong> (http_server) HTTP response has UTF-7 charset\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:6</strong> (http_server) HTTP response gzip decompression failed\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:7</strong> (http_server) server consecutive small chunk sizes\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:8</strong> (http_server) invalid content-length or chunk size\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:9</strong> (http_server) javascript obfuscation levels exceeds 1\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:10</strong> (http_server) javascript whitespaces exceeds max allowed\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:11</strong> (http_server) multiple encodings within javascript obfuscated data\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:12</strong> (http_server) HTTP response SWF file zlib decompression failure\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:13</strong> (http_server) HTTP response SWF file LZMA decompression failure\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:14</strong> (http_server) HTTP response PDF file deflate decompression failure\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:15</strong> (http_server) HTTP response PDF file unsupported compression type\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:16</strong> (http_server) HTTP response PDF file cascaded compression\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>320:17</strong> (http_server) HTTP response PDF file parse failure\r
-</p>\r
-</li>\r
</ul></div>\r
</div>\r
<div class="sect2">\r
<div class="ulist"><ul>\r
<li>\r
<p>\r
-<strong>packet_capture.disable</strong>(): stop packet dump\r
+<strong>packet_capture.enable</strong>(filter): dump raw packets\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>packet_capture.enable</strong>(filter): dump raw packets\r
+<strong>packet_capture.disable</strong>(): stop packet dump\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>snort.detach</strong>(): exit shell w/o shutdown\r
+<strong>snort.show_plugins</strong>(): show available plugins\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>snort.help</strong>(): this output\r
+<strong>snort.rotate_stats</strong>(): roll perfmonitor log files\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>snort.pause</strong>(): suspend packet processing\r
+<strong>snort.reload_config</strong>(filename): load new configuration\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>snort.quit</strong>(): shutdown and dump-stats\r
+<strong>snort.reload_daq</strong>(): reload daq module\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>snort.reload_config</strong>(filename): load new configuration\r
+<strong>snort.reload_hosts</strong>(filename): load a new hosts table\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>snort.reload_hosts</strong>(filename): load a new hosts table\r
+<strong>snort.pause</strong>(): suspend packet processing\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>snort.rotate_stats</strong>(): roll perfmonitor log files\r
+<strong>snort.detach</strong>(): exit shell w/o shutdown\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>snort.show_plugins</strong>(): show available plugins\r
+<strong>snort.quit</strong>(): shutdown and dump-stats\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
+<strong>snort.help</strong>(): this output\r
</p>\r
</li>\r
</ul></div>\r
<div class="ulist"><ul>\r
<li>\r
<p>\r
-<strong>hosts</strong>(23): reload hosts file\r
+<strong>term</strong>(15): shutdown normally\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>reload</strong>(1): reload config file\r
+<strong>stats</strong>(10): dump stats to stdout\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>stats</strong>(10): dump stats to stdout\r
+<strong>reload</strong>(1): reload config file\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>term</strong>(15): shutdown normally\r
+<strong>hosts</strong>(23): reload hosts file\r
</p>\r
</li>\r
</ul></div>\r
change -> dynamicengine ==> 'snort.--plugin_path=<path>'\r
change -> dynamicpreprocessor ==> 'snort.--plugin_path=<path>'\r
change -> dynamicsidechannel ==> 'snort.--plugin_path=<path>'\r
-change -> alertfile: 'config alertfile:' ==> 'alert_fast.file'\r
-change -> alertfile: 'config alertfile:' ==> 'alert_full.file'\r
change -> attribute_table: 'STREAM_POLICY' ==> 'hosts: tcp_policy'\r
change -> attribute_table: 'filename <file_name>' ==> 'hosts[]'\r
change -> config ' addressspace_agnostic' ==> ' packets. address_space_agnostic'\r
change -> config ' checksum_mode' ==> ' network. checksum_eval'\r
-change -> config ' daq' ==> ' daq. type'\r
-change -> config ' daq_dir' ==> ' daq. dir'\r
-change -> config ' daq_mode' ==> ' daq. mode'\r
-change -> config ' daq_var' ==> ' daq. var'\r
+change -> config ' daq' ==> ' daq. module'\r
+change -> config ' daq_dir' ==> ' daq. module_dirs, true'\r
+change -> config ' daq_var' ==> ' daq. variables, true'\r
change -> config ' detection_filter' ==> ' alerts. detection_filter_memcap'\r
change -> config ' enable_deep_teredo_inspection' ==> ' udp. deep_teredo_inspection'\r
change -> config ' event_filter' ==> ' alerts. event_filter_memcap'\r
change -> config ' rate_filter' ==> ' alerts. rate_filter_memcap'\r
change -> config ' react' ==> ' react. page'\r
change -> config ' threshold' ==> ' alerts. event_filter_memcap'\r
+change -> csv: 'csv' ==> 'fields'\r
change -> csv: 'dgmlen' ==> 'dgm_len'\r
change -> csv: 'dst' ==> 'dst_addr'\r
change -> csv: 'dstport' ==> 'dst_port'\r
change -> csv: 'icmpid' ==> 'icmp_id'\r
change -> csv: 'icmpseq' ==> 'icmp_seq'\r
change -> csv: 'icmptype' ==> 'icmp_type'\r
+change -> csv: 'id' ==> 'ip_id'\r
change -> csv: 'iplen' ==> 'ip_len'\r
change -> csv: 'sig_generator' ==> 'gid'\r
change -> csv: 'sig_id' ==> 'sid'\r
change -> csv: 'tcpseq' ==> 'tcp_seq'\r
change -> csv: 'tcpwindow' ==> 'tcp_win'\r
change -> csv: 'udplength' ==> 'udp_len'\r
-change -> detection: 'ac' ==> 'ac_full_q'\r
+change -> detection: 'ac' ==> 'ac_full'\r
change -> detection: 'ac-banded' ==> 'ac_banded'\r
-change -> detection: 'ac-bnfa' ==> 'ac_bnfa_q'\r
+change -> detection: 'ac-bnfa' ==> 'ac_bnfa'\r
change -> detection: 'ac-bnfa-nq' ==> 'ac_bnfa'\r
-change -> detection: 'ac-bnfa-q' ==> 'ac_bnfa_q'\r
+change -> detection: 'ac-bnfa-q' ==> 'ac_bnfa'\r
change -> detection: 'ac-nq' ==> 'ac_full'\r
-change -> detection: 'ac-q' ==> 'ac_full_q'\r
+change -> detection: 'ac-q' ==> 'ac_full'\r
change -> detection: 'ac-sparsebands' ==> 'ac_sparse_bands'\r
-change -> detection: 'ac-split' ==> 'ac_full_q'\r
+change -> detection: 'ac-split' ==> 'ac_full'\r
change -> detection: 'ac-split' ==> 'split_any_any'\r
change -> detection: 'ac-std' ==> 'ac_std'\r
change -> detection: 'acs' ==> 'ac_sparse'\r
change -> detection: 'bleedover-port-limit' ==> 'bleedover_port_limit'\r
+change -> detection: 'debug-print-fast-pattern' ==> 'show_fast_patterns'\r
change -> detection: 'intel-cpm' ==> 'intel_cpm'\r
-change -> detection: 'lowmem' ==> 'lowmem_q'\r
change -> detection: 'lowmem-nq' ==> 'lowmem'\r
-change -> detection: 'lowmem-q' ==> 'lowmem_q'\r
+change -> detection: 'lowmem-q' ==> 'lowmem'\r
change -> detection: 'max-pattern-len' ==> 'max_pattern_len'\r
+change -> detection: 'no_stream_inserts' ==> 'inspect_stream_inserts'\r
change -> detection: 'search-method' ==> 'search_method'\r
change -> detection: 'search-optimize' ==> 'search_optimize'\r
change -> detection: 'split-any-any' ==> 'split_any_any'\r
+change -> dnp3: 'ports' ==> 'bindings'\r
change -> dns: 'ports' ==> 'bindings'\r
change -> event_filter: 'gen_id' ==> 'gid'\r
change -> event_filter: 'sig_id' ==> 'sid'\r
change -> ftp_telnet_protocol: 'alt_max_param_len' ==> 'cmd_validity'\r
change -> ftp_telnet_protocol: 'data_chan' ==> 'ignore_data_chan'\r
change -> ftp_telnet_protocol: 'ports' ==> 'bindings'\r
-change -> gtp: 'ports' ==> 'gtp_ports'\r
-change -> http_inspect: 'http_inspect' ==> 'http_global'\r
-change -> http_inspect_server: 'apache_whitespace' ==> 'profile.apache_whitespace'\r
-change -> http_inspect_server: 'ascii' ==> 'profile.ascii'\r
-change -> http_inspect_server: 'bare_byte' ==> 'profile.bare_byte'\r
-change -> http_inspect_server: 'chunk_length' ==> 'profile.chunk_length'\r
-change -> http_inspect_server: 'client_flow_depth' ==> 'profile.client_flow_depth'\r
-change -> http_inspect_server: 'directory' ==> 'profile.directory'\r
-change -> http_inspect_server: 'double_decode' ==> 'profile.double_decode'\r
-change -> http_inspect_server: 'enable_cookie' ==> 'enable_cookies'\r
-change -> http_inspect_server: 'flow_depth' ==> 'server_flow_depth'\r
+change -> gtp: 'ports' ==> 'bindings'\r
+change -> http_inspect_server: 'bare_byte' ==> 'utf8_bare_byte'\r
+change -> http_inspect_server: 'client_flow_depth' ==> 'request_depth'\r
+change -> http_inspect_server: 'double_decode' ==> 'iis_double_decode'\r
change -> http_inspect_server: 'http_inspect_server' ==> 'http_inspect'\r
-change -> http_inspect_server: 'iis_backslash' ==> 'profile.iis_backslash'\r
-change -> http_inspect_server: 'iis_delimiter' ==> 'profile.iis_delimiter'\r
-change -> http_inspect_server: 'iis_unicode' ==> 'profile.iis_unicode'\r
-change -> http_inspect_server: 'max_header_length' ==> 'profile.max_header_length'\r
-change -> http_inspect_server: 'max_headers' ==> 'profile.max_headers'\r
-change -> http_inspect_server: 'max_spaces' ==> 'profile.max_spaces'\r
-change -> http_inspect_server: 'multi_slash' ==> 'profile.multi_slash'\r
-change -> http_inspect_server: 'non_rfc_char' ==> 'non_rfc_chars'\r
-change -> http_inspect_server: 'non_strict' ==> 'profile.non_strict'\r
-change -> http_inspect_server: 'normalize_utf' ==> 'profile.normalize_utf'\r
+change -> http_inspect_server: 'iis_backslash' ==> 'backslash_to_slash'\r
+change -> http_inspect_server: 'inspect_gzip' ==> 'unzip'\r
+change -> http_inspect_server: 'non_rfc_char' ==> 'bad_characters'\r
change -> http_inspect_server: 'ports' ==> 'bindings'\r
-change -> http_inspect_server: 'u_encode' ==> 'profile.u_encode'\r
-change -> http_inspect_server: 'utf_8' ==> 'profile.utf_8'\r
-change -> http_inspect_server: 'webroot' ==> 'profile.webroot'\r
-change -> http_inspect_server: 'whitespace_chars' ==> 'profile.whitespace_chars'\r
+change -> http_inspect_server: 'u_encode' ==> 'percent_u'\r
+change -> http_inspect_server: 'utf_8' ==> 'utf8'\r
change -> imap: 'ports' ==> 'bindings'\r
+change -> modbus: 'ports' ==> 'bindings'\r
change -> paf_max: 'paf_max [0:63780]' ==> 'max_pdu [1460:63780]'\r
-change -> perfmonitor: 'accumulate' ==> 'reset = false'\r
-change -> perfmonitor: 'flow-file' ==> 'flow_file = true'\r
+change -> perfmonitor: 'console' ==> 'format = 'text''\r
+change -> perfmonitor: 'console' ==> 'output = 'console''\r
+change -> perfmonitor: 'file' ==> 'format = 'csv''\r
+change -> perfmonitor: 'file' ==> 'output = 'file''\r
+change -> perfmonitor: 'flow-file' ==> 'format = 'csv''\r
+change -> perfmonitor: 'flow-file' ==> 'output = 'file''\r
change -> perfmonitor: 'flow-ip' ==> 'flow_ip'\r
-change -> perfmonitor: 'flow-ip-file' ==> 'flow_ip_file = true'\r
+change -> perfmonitor: 'flow-ip-file' ==> 'format = 'csv''\r
+change -> perfmonitor: 'flow-ip-file' ==> 'output = 'file''\r
change -> perfmonitor: 'flow-ip-memcap' ==> 'flow_ip_memcap'\r
change -> perfmonitor: 'flow-ports' ==> 'flow_ports'\r
change -> perfmonitor: 'pktcnt' ==> 'packets'\r
-change -> perfmonitor: 'snortfile' ==> 'file = true'\r
+change -> perfmonitor: 'snortfile' ==> 'format = 'csv''\r
+change -> perfmonitor: 'snortfile' ==> 'output = 'file''\r
change -> perfmonitor: 'time' ==> 'seconds'\r
change -> policy_mode: 'inline_test' ==> 'inline-test'\r
change -> pop: 'ports' ==> 'bindings'\r
-change -> ppm: 'max-pkt-time' ==> 'max_pkt_time'\r
-change -> ppm: 'max-rule-time' ==> 'max_rule_time'\r
-change -> ppm: 'pkt-log' ==> 'pkt_log'\r
-change -> ppm: 'rule-log' ==> 'rule_log'\r
-change -> ppm: 'suspend-timeout' ==> 'suspend_timeout'\r
+change -> ppm: ''both'' ==> ''alert_and_log''\r
+change -> ppm: 'fastpath-expensive-packets' ==> 'packet.fastpath'\r
+change -> ppm: 'max-pkt-time' ==> 'packet.max_time'\r
+change -> ppm: 'max-rule-time' ==> 'rule.max_time'\r
+change -> ppm: 'pkt-log' ==> 'packet.action'\r
+change -> ppm: 'ppm' ==> 'latency'\r
+change -> ppm: 'rule-log' ==> 'rule.action'\r
+change -> ppm: 'suspend-expensive-rules' ==> 'rule.suspend'\r
+change -> ppm: 'suspend-timeout' ==> 'max_suspend_time'\r
+change -> ppm: 'threshold' ==> 'rule.suspend_threshold'\r
change -> preprocessor 'normalize_ icmp4' ==> 'normalize. icmp4'\r
change -> preprocessor 'normalize_ icmp6' ==> 'normalize. icmp6'\r
change -> preprocessor 'normalize_ ip6' ==> 'normalize. ip6'\r
change -> profile: 'print' ==> 'count'\r
+change -> profile: 'sort avg_ticks' ==> 'sort = avg_check'\r
+change -> profile: 'sort total_ticks' ==> 'sort = total_time'\r
change -> rate_filter: 'gen_id' ==> 'gid'\r
change -> rate_filter: 'sig_id' ==> 'sid'\r
change -> rule_state: 'disabled' ==> 'enable'\r
deleted -> attribute_table: '<STREAM_POLICY>noack</STREAM_POLICY>'\r
deleted -> attribute_table: '<STREAM_POLICY>unknown</STREAM_POLICY>'\r
deleted -> config ' cs_dir'\r
+deleted -> config ' daq_mode'\r
+deleted -> config ' decode_data_link'\r
deleted -> config ' disable_attribute_reload_thread'\r
deleted -> config ' disable_decode_alerts'\r
deleted -> config ' disable_decode_drops'\r
+deleted -> config ' disable_inline_init_failopen'\r
deleted -> config ' disable_ipopt_alerts'\r
deleted -> config ' disable_ipopt_drops'\r
deleted -> config ' disable_tcpopt_alerts'\r
deleted -> config ' include_vlan_in_alerts'\r
deleted -> config ' interface'\r
deleted -> config ' layer2resets'\r
+deleted -> config ' nolog'\r
deleted -> config ' policy_version'\r
deleted -> config ' so_rule_memcap'\r
deleted -> csv: '<filename> can no longer be specific'\r
deleted -> csv: 'default'\r
deleted -> csv: 'trheader'\r
deleted -> detection: 'mwm'\r
+deleted -> dnp3: 'disabled'\r
+deleted -> dnp3: 'memcap'\r
deleted -> dns: 'enable_experimental_types'\r
deleted -> dns: 'enable_obsolete_types'\r
deleted -> dns: 'enable_rdata_overflow'\r
+deleted -> event_trace: 'file'\r
deleted -> fast: '<filename> can no longer be specific'\r
deleted -> frag3_engine: 'detect_anomalies'\r
deleted -> frag3_global: 'disabled'\r
deleted -> ftp_telnet_protocol: 'detect_anomalies'\r
deleted -> full: '<filename> can no longer be specific'\r
+deleted -> http_inspect: 'detect_anomalous_servers'\r
deleted -> http_inspect: 'disabled'\r
+deleted -> http_inspect: 'proxy_alert'\r
+deleted -> http_inspect_server: 'allow_proxy_use'\r
+deleted -> http_inspect_server: 'enable_cookie'\r
+deleted -> http_inspect_server: 'enable_xff'\r
+deleted -> http_inspect_server: 'extended_ascii_uri'\r
+deleted -> http_inspect_server: 'extended_response_inspection'\r
+deleted -> http_inspect_server: 'iis_unicode_map not allowed in sever'\r
+deleted -> http_inspect_server: 'inspect_uri_only'\r
+deleted -> http_inspect_server: 'log_hostname'\r
+deleted -> http_inspect_server: 'log_uri'\r
deleted -> http_inspect_server: 'no_alerts'\r
+deleted -> http_inspect_server: 'no_pipeline_req'\r
+deleted -> http_inspect_server: 'non_strict'\r
+deleted -> http_inspect_server: 'normalize_cookies'\r
+deleted -> http_inspect_server: 'normalize_headers'\r
+deleted -> http_inspect_server: 'small_chunk_length'\r
+deleted -> http_inspect_server: 'tab_uri_delimiter'\r
+deleted -> http_inspect_server: 'unlimited_decompress'\r
deleted -> imap: 'disabled'\r
deleted -> imap: 'max_mime_mem'\r
deleted -> imap: 'memcap'\r
+deleted -> perfmonitor: 'accumulate'\r
deleted -> perfmonitor: 'atexitonly'\r
deleted -> perfmonitor: 'atexitonly: base-stats'\r
deleted -> perfmonitor: 'atexitonly: events-stats'\r
deleted -> perfmonitor: 'atexitonly: flow-ip-stats'\r
deleted -> perfmonitor: 'atexitonly: flow-stats'\r
+deleted -> perfmonitor: 'atexitonly: reset'\r
+deleted -> perfmonitor: 'events'\r
+deleted -> perfmonitor: 'max'\r
deleted -> pop: 'disabled'\r
deleted -> pop: 'max_mime_mem'\r
deleted -> pop: 'memcap'\r
deleted -> ppm: 'debug-pkts'\r
deleted -> react: 'block'\r
deleted -> react: 'warn'\r
+deleted -> reputation: 'shared_mem'\r
+deleted -> reputation: 'shared_refresh'\r
deleted -> rpc_decode: 'alert_fragments'\r
deleted -> rpc_decode: 'no_alert_incomplete'\r
deleted -> rpc_decode: 'no_alert_large_fragments'\r
deleted -> sfportscan: 'disabled'\r
deleted -> sfportscan: 'logfile'\r
deleted -> sip: 'disabled'\r
+deleted -> sip: 'max_sessions'\r
deleted -> smtp: 'alert_unknown_cmds'\r
deleted -> smtp: 'disabled'\r
deleted -> smtp: 'enable_mime_decoding'\r
deleted -> ssl: 'noinspect_encrypted'\r
deleted -> stream5_global: 'disabled'\r
deleted -> stream5_global: 'flush_on_alert'\r
+deleted -> stream5_global: 'memcap'\r
deleted -> stream5_global: 'no_midstream_drop_alerts'\r
deleted -> stream5_tcp: 'check_session_hijacking'\r
deleted -> stream5_tcp: 'detect_anomalies'\r
deleted -> stream5_tcp: 'dont_store_large_packets'\r
+deleted -> stream5_tcp: 'ignore_ports'\r
+deleted -> stream5_tcp: 'log_asymmetric_traffic'\r
deleted -> stream5_tcp: 'policy noack'\r
deleted -> stream5_tcp: 'policy unknown'\r
deleted -> tcpdump: '<filename> can no longer be specific'\r
</li>\r
<li>\r
<p>\r
+<strong>byte_math</strong> (ips_option): rule option to perform mathematical operations on extracted value and a specified value or existing variable\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>byte_test</strong> (ips_option): rule option to convert data to integer and compare\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>gtp</strong> (codec): support for general-packet-radio-service tunnelling protocol\r
+<strong>gtp</strong> (codec): support for general-packet-radio-service tunneling protocol\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>http_global</strong> (inspector): http inspector global configuration and client rules for use with http_server\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>http_header</strong> (ips_option): rule option to set the detection cursor to the normalized header(s)\r
+<strong>http_header</strong> (ips_option): rule option to set the detection cursor to the normalized headers\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>http_server</strong> (inspector): http inspection and server rules; also configure http_global\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>http_stat_code</strong> (ips_option): rule option to set the detection cursor to the HTTP status code\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
+<strong>llc</strong> (codec): support for logical link control\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>log_codecs</strong> (logger): log protocols in packet by layer\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>codec::gtp</strong>: support for general-packet-radio-service tunnelling protocol\r
+<strong>codec::gtp</strong>: support for general-packet-radio-service tunneling protocol\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>inspector::http_global</strong>: shared HTTP inspector settings\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>inspector::http_inspect</strong>: the new HTTP inspector!\r
</p>\r
</li>\r
<li>\r
<p>\r
-<strong>inspector::http_server</strong>: main HTTP inspector module\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>inspector::imap</strong>: imap inspection\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
+<strong>ips_option::byte_math</strong>: rule option to perform mathematical operations on extracted value and a specified value or existing variable\r
+</p>\r
+</li>\r
+<li>\r
+<p>\r
<strong>ips_option::byte_test</strong>: rule option to convert data to integer and compare\r
</p>\r
</li>\r
</li>\r
<li>\r
<p>\r
-<strong>ips_option::http_header</strong>: rule option to set the detection cursor to the normalized header(s)\r
+<strong>ips_option::http_header</strong>: rule option to set the detection cursor to the normalized headers\r
</p>\r
</li>\r
<li>\r
</li>\r
<li>\r
<p>\r
-<strong>piglet::pp_codec</strong>: Codec piglet\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>piglet::pp_inspector</strong>: Inspector piglet\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>piglet::pp_ips_action</strong>: Ips action piglet\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>piglet::pp_ips_option</strong>: Ips option piglet\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>piglet::pp_logger</strong>: Logger piglet\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>piglet::pp_search_engine</strong>: Search engine piglet\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>piglet::pp_so_rule</strong>: SO rule piglet\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
-<strong>piglet::pp_test</strong>: Test piglet\r
-</p>\r
-</li>\r
-<li>\r
-<p>\r
<strong>search_engine::ac_banded</strong>: Aho-Corasick Banded (high memory, moderate performance)\r
</p>\r
</li>\r
<div id="footnotes"><hr /></div>\r
<div id="footer">\r
<div id="footer-text">\r
-Last updated 2017-03-01 10:06:34 EST\r
+Last updated 2017-06-01 07:44:30 EDT\r
</div>\r
</div>\r
</body>\r
5.1. AppId
5.2. Binder
- 5.3. DCE Inspectors
- 5.4. File Processing
- 5.5. High Availability
- 5.6. HTTP Inspector
- 5.7. Performance Monitor
- 5.8. Sensitive Data Filtering
- 5.9. Wizard
+ 5.3. Byte rule options
+ 5.4. DCE Inspectors
+ 5.5. File Processing
+ 5.6. High Availability
+ 5.7. HTTP Inspector
+ 5.8. Performance Monitor
+ 5.9. Sensitive Data Filtering
+ 5.10. Wizard
6. Basic Modules
7.14. igmp
7.15. ipv4
7.16. ipv6
- 7.17. mpls
- 7.18. pgm
- 7.19. pppoe
- 7.20. tcp
- 7.21. token_ring
- 7.22. udp
- 7.23. vlan
- 7.24. wlan
+ 7.17. llc
+ 7.18. mpls
+ 7.19. pgm
+ 7.20. pppoe
+ 7.21. tcp
+ 7.22. token_ring
+ 7.23. udp
+ 7.24. vlan
+ 7.25. wlan
8. Connector Modules
9.17. ftp_data
9.18. ftp_server
9.19. gtp_inspect
- 9.20. http_global
- 9.21. http_inspect
- 9.22. http_server
- 9.23. imap
- 9.24. modbus
- 9.25. normalizer
- 9.26. packet_capture
- 9.27. perf_monitor
- 9.28. pop
- 9.29. port_scan
- 9.30. port_scan_global
- 9.31. reputation
- 9.32. rpc_decode
- 9.33. sip
- 9.34. smtp
- 9.35. ssh
- 9.36. ssl
- 9.37. stream
- 9.38. stream_file
- 9.39. stream_icmp
- 9.40. stream_ip
- 9.41. stream_tcp
- 9.42. stream_udp
- 9.43. stream_user
- 9.44. telnet
- 9.45. wizard
+ 9.20. http_inspect
+ 9.21. imap
+ 9.22. modbus
+ 9.23. normalizer
+ 9.24. packet_capture
+ 9.25. perf_monitor
+ 9.26. pop
+ 9.27. port_scan
+ 9.28. port_scan_global
+ 9.29. reputation
+ 9.30. rpc_decode
+ 9.31. sip
+ 9.32. smtp
+ 9.33. ssh
+ 9.34. ssl
+ 9.35. stream
+ 9.36. stream_file
+ 9.37. stream_icmp
+ 9.38. stream_ip
+ 9.39. stream_tcp
+ 9.40. stream_udp
+ 9.41. stream_user
+ 9.42. telnet
+ 9.43. wizard
10. IPS Action Modules
11.5. bufferlen
11.6. byte_extract
11.7. byte_jump
- 11.8. byte_test
- 11.9. classtype
- 11.10. content
- 11.11. cvs
- 11.12. dce_iface
- 11.13. dce_opnum
- 11.14. dce_stub_data
- 11.15. detection_filter
- 11.16. dnp3_data
- 11.17. dnp3_func
- 11.18. dnp3_ind
- 11.19. dnp3_obj
- 11.20. dsize
- 11.21. file_data
- 11.22. file_type
- 11.23. flags
- 11.24. flow
- 11.25. flowbits
- 11.26. fragbits
- 11.27. fragoffset
- 11.28. gid
- 11.29. gtp_info
- 11.30. gtp_type
- 11.31. gtp_version
- 11.32. http_client_body
- 11.33. http_cookie
- 11.34. http_header
- 11.35. http_method
- 11.36. http_raw_cookie
- 11.37. http_raw_header
- 11.38. http_raw_request
- 11.39. http_raw_status
- 11.40. http_raw_trailer
- 11.41. http_raw_uri
- 11.42. http_stat_code
- 11.43. http_stat_msg
- 11.44. http_trailer
- 11.45. http_uri
- 11.46. http_version
- 11.47. icmp_id
- 11.48. icmp_seq
- 11.49. icode
- 11.50. id
- 11.51. ip_proto
- 11.52. ipopts
- 11.53. isdataat
- 11.54. itype
- 11.55. md5
- 11.56. metadata
- 11.57. modbus_data
- 11.58. modbus_func
- 11.59. modbus_unit
- 11.60. msg
- 11.61. pcre
- 11.62. pkt_data
- 11.63. pkt_num
- 11.64. priority
- 11.65. raw_data
- 11.66. reference
- 11.67. regex
- 11.68. rem
- 11.69. replace
- 11.70. rev
- 11.71. rpc
- 11.72. sd_pattern
- 11.73. seq
- 11.74. session
- 11.75. sha256
- 11.76. sha512
- 11.77. sid
- 11.78. sip_body
- 11.79. sip_header
- 11.80. sip_method
- 11.81. sip_stat_code
- 11.82. so
- 11.83. soid
- 11.84. ssl_state
- 11.85. ssl_version
- 11.86. stream_reassemble
- 11.87. stream_size
- 11.88. tag
- 11.89. tos
- 11.90. ttl
- 11.91. urg
- 11.92. window
+ 11.8. byte_math
+ 11.9. byte_test
+ 11.10. classtype
+ 11.11. content
+ 11.12. cvs
+ 11.13. dce_iface
+ 11.14. dce_opnum
+ 11.15. dce_stub_data
+ 11.16. detection_filter
+ 11.17. dnp3_data
+ 11.18. dnp3_func
+ 11.19. dnp3_ind
+ 11.20. dnp3_obj
+ 11.21. dsize
+ 11.22. file_data
+ 11.23. file_type
+ 11.24. flags
+ 11.25. flow
+ 11.26. flowbits
+ 11.27. fragbits
+ 11.28. fragoffset
+ 11.29. gid
+ 11.30. gtp_info
+ 11.31. gtp_type
+ 11.32. gtp_version
+ 11.33. http_client_body
+ 11.34. http_cookie
+ 11.35. http_header
+ 11.36. http_method
+ 11.37. http_raw_cookie
+ 11.38. http_raw_header
+ 11.39. http_raw_request
+ 11.40. http_raw_status
+ 11.41. http_raw_trailer
+ 11.42. http_raw_uri
+ 11.43. http_stat_code
+ 11.44. http_stat_msg
+ 11.45. http_trailer
+ 11.46. http_uri
+ 11.47. http_version
+ 11.48. icmp_id
+ 11.49. icmp_seq
+ 11.50. icode
+ 11.51. id
+ 11.52. ip_proto
+ 11.53. ipopts
+ 11.54. isdataat
+ 11.55. itype
+ 11.56. md5
+ 11.57. metadata
+ 11.58. modbus_data
+ 11.59. modbus_func
+ 11.60. modbus_unit
+ 11.61. msg
+ 11.62. pcre
+ 11.63. pkt_data
+ 11.64. pkt_num
+ 11.65. priority
+ 11.66. raw_data
+ 11.67. reference
+ 11.68. regex
+ 11.69. rem
+ 11.70. replace
+ 11.71. rev
+ 11.72. rpc
+ 11.73. sd_pattern
+ 11.74. seq
+ 11.75. session
+ 11.76. sha256
+ 11.77. sha512
+ 11.78. sid
+ 11.79. sip_body
+ 11.80. sip_header
+ 11.81. sip_method
+ 11.82. sip_stat_code
+ 11.83. so
+ 11.84. soid
+ 11.85. ssl_state
+ 11.86. ssl_version
+ 11.87. stream_reassemble
+ 11.88. stream_size
+ 11.89. tag
+ 11.90. tos
+ 11.91. ttl
+ 11.92. urg
+ 11.93. window
12. Search Engine Modules
13. SO Rule Modules
16. Snort 3 vs Snort 2
- 16.1. Build Options
- 16.2. Command Line
- 16.3. Conf File
- 16.4. Rules
- 16.5. Output
- 16.6. HTTP Profiles
- 16.7. SDF Preprocessor
+ 16.1. Features New to Snort 3
+ 16.2. Features Improved over Snort 2
+ 16.3. Build Options
+ 16.4. Command Line
+ 16.5. Conf File
+ 16.6. Rules
+ 16.7. Output
+ 16.8. Sensitive Data
17. Snort2Lua
Snorty
,,_ -*> Snort++ <*-
-o" )~ Version 3.0.0-a4 (Build 227) from 2.9.8-383
+o" )~ Version 3.0.0-a4 (Build 234) from 2.9.8-383
'''' By Martin Roesch & The Snort Team
http://snort.org/contact#team
- Copyright (C) 2014-2016 Cisco and/or its affiliates. All rights reserved.
+ Copyright (C) 2014-2017 Cisco and/or its affiliates. All rights reserved.
Copyright (C) 1998-2013 Sourcefire, Inc., et al.
Optional:
- * lzma >= 5.1.2 from http://tukaani.org/xz/ for decompression of
- SWF and PDF files
- * hyperscan from https://github.com/01org/hyperscan to build new
- and improved regex and (coming soon) fast pattern support
- * cpputest from http://cpputest.github.io to run additional unit
- tests with make check
* asciidoc from http://www.methods.co.nz/asciidoc/ to build the
HTML manual
+ * cpputest from http://cpputest.github.io to run additional unit
+ tests with make check
* dblatex from http://dblatex.sourceforge.net to build the pdf
manual (in addition to asciidoc)
- * w3m from http://sourceforge.net/projects/w3m/ to build the plain
- text manual
+ * flatbuffers from https://google.github.io/flatbuffers/ for
+ enabling the flatbuffers serialization format
+ * hyperscan >= 4.4.0 from https://github.com/01org/hyperscan to
+ build new the regex and sd_pattern rule options and hyperscan
+ search engine
+ * lzma >= 5.1.2 from http://tukaani.org/xz/ for decompression of
+ SWF and PDF files
+ * safec from https://sourceforge.net/projects/safeclib/ for runtime
+ bounds checks on certain legacy C-library calls
* source-highlight from http://www.gnu.org/software/src-highlite/
to generate the dev guide
- * safec from https://sourceforge.net/projects/safeclib/ for runtime
- bounds checks on certain legacy C-library calls.
+ * w3m from http://sourceforge.net/projects/w3m/ to build the plain
+ text manual
3.2. Building
action, config file, or inspector configuration.
-5.3. DCE Inspectors
+5.3. Byte rule options
+
+--------------
+
+5.3.1. byte_test
+
+This rule option tests a byte field against a specific value (with
+operator). Capable of testing binary values or converting
+representative byte strings to their binary equivalent and testing
+them.
+
+Snort uses the C operators for each of these operators. If the &
+operator is used, then it would be the same as using
+
+if (data & value) { do_something(); }
+
+Note: The bitmask option applies bitwise AND operator on the bytes
+converted. The result will be right-shifted by the number of bits
+equal to the number of trailing zeros in the mask. This applies for
+the other rule options as well.
+
+5.3.1.1. Examples
+
+alert tcp (byte_test:2, =, 568, 0, bitmask 0x3FF0;)
+
+This example extracts 2 bytes at offset 0, performs bitwise and with
+bitmask 0x3FF0, shifts the result by 4 bits and compares to 568.
+
+alert udp (byte_test:4, =, 1234, 0, string, dec;
+ msg:"got 1234!";)
+
+alert udp (byte_test:8, =, 0xdeadbeef, 0, string, hex;
+ msg:"got DEADBEEF!";)
+
+5.3.2. byte_jump
+
+The byte_jump rule option allows rules to be written for length
+encoded protocols trivially. By having an option that reads the
+length of a portion of data, then skips that far forward in the
+packet, rules can be written that skip over specific portions of
+length-encoded protocols and perform detection in very specific
+locations.
+
+5.3.2.1. Examples
+
+alert tcp (content:"Begin";
+ byte_jump:0, 0, from_end, post_offset -6;
+ content:"end..", distance 0, within 5;
+ msg:"Content match from end of the payload";)
+
+alert tcp (content:"catalog";
+ byte_jump:2, 1, relative, post_offset 2, bitmask 0x03f0;
+ byte_test:2, =, 968, 0, relative;
+ msg:"Bitmask applied on the 2 bytes extracted for byte_jump";)
+
+5.3.3. byte_extract
+
+The byte_extract keyword is another useful option for writing rules
+against length-encoded protocols. It reads in some number of bytes
+from the packet payload and saves it to a variable. These variables
+can be referenced later in the rule, instead of using hard-coded
+values.
+
+5.3.3.1. Other options which use byte_extract variables
+
+A byte_extract rule option detects nothing by itself. Its use is in
+extracting packet data for use in other rule options.
+
+Here is a list of places where byte_extract variables can be used:
+
+ * content/uricontent: offset, depth, distance, within
+ * byte_test: offset, value
+ * byte_jump: offset
+ * isdataat: offset
+
+5.3.3.2. Examples
+
+alert tcp (byte_extract:1, 0, str_offset;
+ byte_extract:1, 1, str_depth;
+ content:"bad stuff", offset str_offset, depth str_depth;
+ msg:"Bad Stuff detected within field";)
+
+This example uses two variables.
+
+The first variable keeps the offset of a string, read from a byte at
+offset 0. The second variable keeps the depth of a string, read from
+a byte at offset 1. These values are used to constrain a pattern
+match to a smaller area.
+
+alert tcp (content:"|04 63 34 35|", offset 4, depth 4;
+ byte_extract: 2, 0, var_match, relative, bitmask 0x03ff;
+ byte_test: 2, =, var_match, 2, relative;
+ msg:"Test value match, after applying bitmask on bytes extracted";)
+
+5.3.4. byte_math
+
+Perform a mathematical operation on an extracted value and a
+specified value or existing variable, and store the outcome in a new
+resulting variable. These resulting variables can be referenced later
+in the rule, at the same places as byte_extract variables.
+
+The syntax for this rule option is different. The order of the
+options is critical for the other rule options and can’t be changed.
+For example, the first option is the number of bytes to extract. Here
+the name of the option is explicitly written, for example : bytes 2.
+The order is not important.
+
+Note
+
+Byte_math operations are performed on unsigned 32-bit values. When
+writing a rule it should be taken into consideration to avoid wrap
+around.
+
+5.3.4.1. Examples
+
+alert tcp ( byte_math: bytes 2, offset 0, oper *, rvalue 10, result area;
+ byte_test:2,>,area,16;)
+
+At the zero offset of the payload, extract 2 bytes and apply
+multiplication operation with value 10. Store result in variable
+area. The area variable is given as input to byte_test value option.
+
+Let’s consider 2 bytes of extracted data is 5. The rvalue is 10.
+Result variable area is 50 ( 5 * 10 ). Area variable can be used in
+either byte_test offset/value options.
+
+5.3.5. Testing Numerical Values
+
+The rule options byte_test and byte_jump were written to support
+writing rules for protocols that have length encoded data. RPC was
+the protocol that spawned the requirement for these two rule options,
+as RPC uses simple length based encoding for passing data.
+
+In order to understand why byte test and byte jump are useful, let’s
+go through an exploit attempt against the sadmind service.
+
+This is the payload of the exploit:
+
+89 09 9c e2 00 00 00 00 00 00 00 02 00 01 87 88 ................
+00 00 00 0a 00 00 00 01 00 00 00 01 00 00 00 20 ...............
+40 28 3a 10 00 00 00 0a 4d 45 54 41 53 50 4c 4f @(:.....metasplo
+49 54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 it..............
+00 00 00 00 00 00 00 00 40 28 3a 14 00 07 45 df ........@(:...e.
+00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
+00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 ................
+00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 04 ................
+7f 00 00 01 00 01 87 88 00 00 00 0a 00 00 00 04 ................
+7f 00 00 01 00 01 87 88 00 00 00 0a 00 00 00 11 ................
+00 00 00 1e 00 00 00 00 00 00 00 00 00 00 00 00 ................
+00 00 00 00 00 00 00 3b 4d 45 54 41 53 50 4c 4f .......;metasplo
+49 54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 it..............
+00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
+00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
+00 00 00 00 00 00 00 06 73 79 73 74 65 6d 00 00 ........system..
+00 00 00 15 2e 2e 2f 2e 2e 2f 2e 2e 2f 2e 2e 2f ....../../../../
+2e 2e 2f 62 69 6e 2f 73 68 00 00 00 00 00 04 1e ../bin/sh.......
+
+Let’s break this up, describe each of the fields, and figure out how
+to write a rule to catch this exploit.
+
+There are a few things to note with RPC:
+
+Numbers are written as uint32s, taking four bytes. The number 26
+would show up as 0x0000001a.
+
+Strings are written as a uint32 specifying the length of the string,
+the string, and then null bytes to pad the length of the string to
+end on a 4-byte boundary. The string bob would show up as
+0x00000003626f6200.
+
+89 09 9c e2 - the request id, a random uint32, unique to each request
+00 00 00 00 - rpc type (call = 0, response = 1)
+00 00 00 02 - rpc version (2)
+00 01 87 88 - rpc program (0x00018788 = 100232 = sadmind)
+00 00 00 0a - rpc program version (0x0000000a = 10)
+00 00 00 01 - rpc procedure (0x00000001 = 1)
+00 00 00 01 - credential flavor (1 = auth_unix)
+00 00 00 20 - length of auth_unix data (0x20 = 32)
+
+## the next 32 bytes are the auth_unix data
+40 28 3a 10 - unix timestamp (0x40283a10 = 1076378128 = feb 10 01:55:28 2004 gmt)
+00 00 00 0a - length of the client machine name (0x0a = 10)
+4d 45 54 41 53 50 4c 4f 49 54 00 00 - metasploit
+
+00 00 00 00 - uid of requesting user (0)
+00 00 00 00 - gid of requesting user (0)
+00 00 00 00 - extra group ids (0)
+
+00 00 00 00 - verifier flavor (0 = auth_null, aka none)
+00 00 00 00 - length of verifier (0, aka none)
+
+The rest of the packet is the request that gets passed to procedure 1
+of sadmind.
+
+However, we know the vulnerability is that sadmind trusts the uid
+coming from the client. sadmind runs any request where the client’s
+uid is 0 as root. As such, we have decoded enough of the request to
+write our rule.
+
+First, we need to make sure that our packet is an RPC call.
+
+content:"|00 00 00 00|", offset 4, depth 4;
+
+Then, we need to make sure that our packet is a call to sadmind.
+
+content:"|00 01 87 88|", offset 12, depth 4;
+
+Then, we need to make sure that our packet is a call to the procedure
+1, the vulnerable procedure.
+
+content:"|00 00 00 01|", offset 20, depth 4;
+
+Then, we need to make sure that our packet has auth_unix credentials.
+
+content:"|00 00 00 01|", offset 24, depth 4;
+
+We don’t care about the hostname, but we want to skip over it and
+check a number value after the hostname. This is where byte_test is
+useful. Starting at the length of the hostname, the data we have is:
+
+00 00 00 0a 4d 45 54 41 53 50 4c 4f 49 54 00 00
+00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+00 00 00 00
+
+We want to read 4 bytes, turn it into a number, and jump that many
+bytes forward, making sure to account for the padding that RPC
+requires on strings. If we do that, we are now at:
+
+00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+00 00 00 00
+
+which happens to be the exact location of the uid, the value we want
+to check.
+
+In English, we want to read 4 bytes, 36 bytes from the beginning of
+the packet, and turn those 4 bytes into an integer and jump that many
+bytes forward, aligning on the 4-byte boundary. To do that in a Snort
+rule, we use:
+
+byte_jump:4,36,align;
+
+then we want to look for the uid of 0.
+
+content:"|00 00 00 00|", within 4;
+
+Now that we have all the detection capabilities for our rule, let’s
+put them all together.
+
+content:"|00 00 00 00|", offset 4, depth 4;
+content:"|00 01 87 88|", offset 12, depth 4;
+content:"|00 00 00 01|", offset 20, depth 4;
+content:"|00 00 00 01|", offset 24, depth 4;
+byte_jump:4,36,align;
+content:"|00 00 00 00|", within 4;
+
+The 3rd and fourth string match are right next to each other, so we
+should combine those patterns. We end up with:
+
+content:"|00 00 00 00|", offset 4, depth 4;
+content:"|00 01 87 88|", offset 12, depth 4;
+content:"|00 00 00 01 00 00 00 01|", offset 20, depth 8;
+byte_jump:4,36,align;
+content:"|00 00 00 00|", within 4;
+
+If the sadmind service was vulnerable to a buffer overflow when
+reading the client’s hostname, instead of reading the length of the
+hostname and jumping that many bytes forward, we would check the
+length of the hostname to make sure it is not too large.
+
+To do that, we would read 4 bytes, starting 36 bytes into the packet,
+turn it into a number, and then make sure it is not too large (let’s
+say bigger than 200 bytes). In Snort, we do:
+
+byte_test:4,>,200,36;
+
+Our full rule would be:
+
+content:"|00 00 00 00|", offset 4, depth 4;
+content:"|00 01 87 88|", offset 12, depth 4;
+content:"|00 00 00 01 00 00 00 01|", offset 20, depth 8;
+byte_test:4,>,200,36;
+
+
+5.4. DCE Inspectors
--------------
and DCE/RPC defragmentation to avoid rule evasion using these
techniques.
-5.3.1. Overview
+5.4.1. Overview
The following transports are supported for DCE/RPC: SMB, TCP, and
UDP. New rule options have been implemented to improve performance,
address/port mapping is handled by the binder. Autodetect
functionality is replaced by wizard curses.
-5.3.2. Quick Guide
+5.4.2. Quick Guide
A typical dcerpce configuration looks like this:
In this example, it defines smb, tcp and udp inspectors based on
port. All the configurations are default.
-5.3.3. Target Based
+5.4.3. Target Based
There are enough important differences between Windows and Samba
versions that a target based approach has been implemented. Some
* Samba-3.0.22
* Samba-3.0.20
-5.3.4. Reassembling
+5.4.4. Reassembling
Both SMB inspector and TCP inspector support reassemble. Reassemble
threshold specifies a minimum number of bytes in the DCE/RPC
argument to this option will, in effect, disable this option. Default
is disabled.
-5.3.5. SMB
+5.4.5. SMB
SMB inspector is one of the most complex inspectors. In addition to
supporting rule options and lots of inspector rule events, it also
supports file processing for both SMB version 1, 2, and 3.
-5.3.5.1. Finger Print Policy
+5.4.5.1. Finger Print Policy
In the initial phase of an SMB session, the client needs to
authenticate with a SessionSetupAndX. Both the request and response
inspector to dynamically set the policy for a session which allows
for better protection against Windows and Samba specific evasions.
-5.3.5.2. File Inspection
+5.4.5.2. File Inspection
SMB inspector supports file inspection. A typical configuration looks
like this:
unlimited. Default is "off", i.e. no SMB file inspection is done in
the inspector.
-5.3.6. TCP
+5.4.6. TCP
-dce_tcp inspector supports defragementation, reassembling, and policy
+dce_tcp inspector supports defragmentation, reassembling, and policy
that is similar to SMB.
-5.3.7. UDP
+5.4.7. UDP
-dce_udp is a very simple inspector that only supports
-defragementation
+dce_udp is a very simple inspector that only supports defragmentation
-5.3.8. Rule Options
+5.4.8. Rule Options
New rule options are supported by enabling the dcerpc2 inspectors:
* byte_test: dce
* byte_jump: dce
-5.3.8.1. dce_iface
+5.4.8.1. dce_iface
For DCE/RPC based rules it has been necessary to set flow-bits based
on a client bind to a service to avoid false positives. It is
fast_pattern rule option, it will unequivocally be used over the
above mentioned patterns.
-5.3.8.2. dce_opnum
+5.4.8.2. dce_opnum
The opnum represents a specific function call to an interface. After
is has been determined that a client has bound to a specific
specified with this option. This option matches if any one of the
opnums specified match the opnum of the DCE/RPC request.
-5.3.8.3. dce_stub_data
+5.4.8.3. dce_stub_data
Since most DCE/RPC based rules had to do protocol decoding only to
get to the DCE/RPC stub data, i.e. the remote procedure call or
start of the stub data buffer. To leave the stub data buffer and
return to the main payload buffer, use the "pkt_data" rule option.
-5.3.8.4. byte_test and byte_jump
+5.4.8.4. byte_test and byte_jump
A DCE/RPC request can specify whether numbers are represented in big
or little endian. These rule options will take as a new argument
"hex", "dec", "oct" and "from_beginning"
-5.4. File Processing
+5.5. File Processing
--------------
will provide file type identification, file signature creation, and
file capture capabilities to help users deal with those challenges.
-5.4.1. Overview
+5.5.1. Overview
There are two parts of file services: file APIs and file policy. File
APIs provides all the file inspection functionalities, such as file
* Supported protocols: HTTP, SMTP, IMAP, POP3, FTP, and SMB.
* Supported file signature calculation: SHA256
-5.4.2. Quick Guide
+5.5.2. Quick Guide
A very simple configuration has been included in lua/snort.lua file.
A typical file configuration looks like this:
* At last, enable file_log to get detailed information about file
event
-5.4.3. Pre-packaged File Magic Rules
+5.5.3. Pre-packaged File Magic Rules
A set of file magic rules is packaged with Snort. They can be located
at "lua/file_magic.lua". To use this feature, it is recommended that
magic = { { content = "| 47 49 46 38 39 61 |",offset = 0 } } },
The previous two rules define GIF format, because two file magics are
-different. File magics are specifed by content and offset, which look
-at content at particular file offset to identify the file type. In
-this case, two magics look at the beginning of the file. You can use
-character if it is printable or hex value in between "|".
+different. File magics are specified by content and offset, which
+look at content at particular file offset to identify the file type.
+In this case, two magics look at the beginning of the file. You can
+use character if it is printable or hex value in between "|".
-5.4.4. File Policy
+5.5.4. File Policy
You can enabled file type, file signature, or file capture by
configuring file_id. In addition, you can enable trace to see file
* For all file types identified, they will be logged with
signature, and also captured onto log folder.
-5.4.5. File Capture
+5.5.5. File Capture
File can be captured and stored to log folder. We use SHA as file
name instead of actual file name to avoid conflicts. You can capture
The above rule will enable PDF file capture.
-5.4.6. File Events
+5.5.6. File Events
File inspect preprocessor also works as a dynamic output plugin for
file events. It logs basic information about file. The log file is in
[Size: 1039328]
-5.5. High Availability
+5.6. High Availability
--------------
High Availability includes the HA flow synchronization and the
SideChannel messaging subsystems.
-5.5.1. HA
+5.6.1. HA
HighAvailability (or HA) is a Snort module that provides state
-coherancy between two partner snort instances. It uses SideChannel
+coherency between two partner snort instances. It uses SideChannel
for messaging.
There can be multiple types of HA within Snort and Snort plugins. HA
messages while the ancillary module content is only present when
requested via a status change request.
-5.5.2. Connector
+5.6.2. Connector
Connectors are a set of modules that are used to exchange
message-oriented data among Snort threads and the external world. A
Connectors are a Snort plugin type.
-5.5.2.1. Connector (parent plugin class)
+5.6.2.1. Connector (parent plugin class)
Connectors may either be a simplex channel and perform unidirectional
communications. Or may be duplex and perform bidirectional
All subtypes of Connector have a direction configuration element and
a connector element. The connector string is the key used to identify
-the element for sidechannel configiration. The direction element may
+the element for sidechannel configuration. The direction element may
have a default value, for instance TcpConnector’s are duplex.
There are currently two implementations of Connectors:
* FileConnector - Write messages to files and read messages from
files.
-5.5.2.2. TcpConnector
+5.6.2.2. TcpConnector
TcpConnector is a subclass of Connector and implements a DUPLEX type
Connector, able to send and receive messages over a tcp session.
},
}
-5.5.2.3. FileConnector
+5.6.2.3. FileConnector
FileConnector implements a Connector that can either read from files
or write to files. FileConnector’s are simplex and must be configured
FileConnector configuration adds two additional element:
- * name = string - used as part of the messsage file name
+ * name = string - used as part of the message file name
* format = text or binary - FileConnector supports two file types
The configured name string is used to construct the actual names as
},
}
-5.5.3. Side Channel
+5.6.3. Side Channel
SideChannel is a Snort module that uses Connectors to implement a
messaging infrastructure that is used to communicate between Snort
The SideChannel configuration mostly serves to map a port number to a
Connector or set of connectors. Each port mapping can have at most
one transmit plus one receive connector or one duplex connector.
-Multiple SideChannel’s may be configured and instatiated to support
+Multiple SideChannel’s may be configured and instantiated to support
multiple applications.
-An example SideChannel configuration along with the corresponing
+An example SideChannel configuration along with the corresponding
Connector configuration:
side_channel =
}
-5.6. HTTP Inspector
+5.7. HTTP Inspector
--------------
One of the major undertakings for Snort 3 is developing a completely
new HTTP inspector.
-5.6.1. Overview
+5.7.1. Overview
You can configure it by adding:
to be a date then normalization means put that date in a standard
format.
-5.6.2. Configuration
+5.7.2. Configuration
Configuration can be as simple as adding:
that provide extra features, tweak how things are done, or conserve
resources by doing less.
-5.6.2.1. request_depth and response_depth
+5.7.2.1. request_depth and response_depth
These replace the flow depth parameters used by the old HTTP
inspector but they work differently.
These limits have no effect on how much data is forwarded to file
processing.
-5.6.2.2. gzip
+5.7.2.2. gzip
http_inspect by default decompresses deflate and gzip message bodies
before inspecting them. This feature can be turned off by unzip =
meaningful inspection of message bodies will be possible. Effectively
HTTP processing would be limited to the headers.
-5.6.2.3. normalize_utf
+5.7.2.3. normalize_utf
http_inspect will decode utf-8, utf-7, utf-16le, utf-16be, utf-32le,
and utf-32be in response message bodies based on the Content-Type
header. This feature is on by default: normalize_utf = false will
deactivate it.
-5.6.2.4. decompress_pdf
+5.7.2.4. decompress_pdf
decompress_pdf = true will enable decompression of compressed
portions of PDF files encountered in a response body. http_inspect
content is decompressed and made available through the file data rule
option.
-5.6.2.5. decompress_swf
+5.7.2.5. decompress_swf
decompress_swf = true will enable decompression of compressed SWF
(Adobe Flash content) files encountered in a response body. The
through the file data rule option. The compressed SWF file signature
is converted to FWS to indicate an uncompressed file.
-5.6.2.6. normalize_javascript
+5.7.2.6. normalize_javascript
normalize_javascript = true will enable normalization of JavaScript
within the HTTP response body. http_inspect looks for JavaScript by
replaces consecutive whitespaces with a single space and normalizes
the plus by concatenating the strings.
-5.6.2.7. URI processing
+5.7.2.7. URI processing
Normalization and inspection of the URI in the HTTP request message
is a key aspect of what http_inspect does. The best way to normalize
you have no interest in URI paths.
backslash_to_slash is a tweak to path simplification for servers that
-allow directories to be separated by backslashs:
+allow directories to be separated by backslashes:
/this/is/the/normal/way/to/write/a/path
such a server then set backslash_to_slash = true and all the
backslashes will be replaced with slashes during normalization.
-5.6.3. Detection rules
+5.7.3. Detection rules
http_inspect parses HTTP messages into their components and makes
them available to the detection engine through rule options. Let’s
In addition to the headers there are rule options for virtually every
part of the HTTP message.
-5.6.3.1. http_uri and http_raw_uri
+5.7.3.1. http_uri and http_raw_uri
These provide the URI of the request message. The raw form is exactly
as it appeared in the message and the normalized form is determined
Nothing here is intended to conflict with the technical language of
the HTTP RFCs and the implementation follows the RFCs.
-5.6.3.2. http_header and http_raw_header
+5.7.3.2. http_header and http_raw_header
These cover all the header lines except the first one. You may
specify an individual header by name using the field option as shown
the cookie headers Cookie and Set-Cookie. http_raw_header includes
the unmodified header names and values as they appeared in the
original message. http_header is the same except percent encodings
-are removed and pathes are simplified exactly as if the headers were
-a URI.
+are removed and paths are simplified exactly as if the headers were a
+URI.
In most cases specifying individual headers creates a more efficient
and accurate rule. It is recommended that new rules be written using
individual headers whenever possible.
-5.6.3.3. http_trailer and http_raw_trailer
+5.7.3.3. http_trailer and http_raw_trailer
HTTP permits header lines to appear after a chunked body ends.
Typically they contain information about the message content that was
rule to inspect both kinds of headers you need to write two rules,
one using header and one using trailer.
-5.6.3.4. http_cookie and http_raw_cookie
+5.7.3.4. http_cookie and http_raw_cookie
These provide the value of the Cookie header for a request message
and the Set-Cookie for a response message. If multiple cookies are
Normalization for http_cookie is the same URI-style normalization
applied to http_header when no specific header is specified.
-5.6.3.5. http_client_body
+5.7.3.5. http_client_body
This is the body of a request message such as POST or PUT.
Normalization for http_client_body is the same URI-like normalization
applied to http_header when no specific header is specified.
-5.6.3.6. http_method
+5.7.3.6. http_method
The method field of a request message. Common values are "GET",
"POST", "OPTIONS", "HEAD", "DELETE", "PUT", "TRACE", and "CONNECT".
-5.6.3.7. http_stat_code
+5.7.3.7. http_stat_code
The status code field of a response message. This is normally a
3-digit number between 100 and 599. In this example it is 200.
HTTP/1.1 200 OK
-5.6.3.8. http_stat_msg
+5.7.3.8. http_stat_msg
The reason phrase field of a response message. This is the
human-readable text following the status code. "OK" in the previous
example.
-5.6.3.9. http_version
+5.7.3.9. http_version
The protocol version information that appears on the first line of an
HTTP message. This is usually "HTTP/1.0" or "HTTP/1.1".
-5.6.3.10. http_raw_request and http_raw_status
+5.7.3.10. http_raw_request and http_raw_status
These are the unmodified first header line of the HTTP request and
response messages respectively. These rule options are a safety valve
in case you need to do something you cannot otherwise do. In most
-cases it is better to use a rule option for a specifc part of the
+cases it is better to use a rule option for a specific part of the
first header line. For a request message those are http_method,
http_raw_uri, and http_version. For a response message those are
http_version, http_stat_code, and http_stat_msg.
-5.6.3.11. file_data and packet data
+5.7.3.11. file_data and packet data
file_data contains the normalized message body. This is the
normalization described above under gzip, normalize_utf,
The unnormalized message body is available in the packet data. If
gzip is configured the packet data will be unzipped.
-5.6.4. Timing issues and combining rule options
+5.7.4. Timing issues and combining rule options
HTTP inspector is stateful. That means it is aware of a bigger
picture than the packet in front of it. It knows what all the pieces
cannot.
-5.7. Performance Monitor
+5.8. Performance Monitor
--------------
being dropped without hitting a rule? perf_monitor! Why is a sensor
leaking water? Not perf_monitor, check with stream…
-5.7.1. Overview
+5.8.1. Overview
The Snort performance monitor is the built-in utility for monitoring
system and traffic statistics. All statistics are separated by
processing thread. perf_monitor supports several trackers for
monitoring such data:
-5.7.2. Base Tracker
+5.8.2. Base Tracker
The base tracker is used to gather running statistics about Snort and
its running modules. All Snort modules gather, at the very least,
Note: Event stats from prior Snorts are now located within base
statistics.
-5.7.3. Flow Tracker
+5.8.3. Flow Tracker
Flow tracks statistics regarding traffic and L3/L4 protocol
distributions. This data can be used to build a profile of traffic
perf_monitor = { flow = true }
-5.7.4. FlowIP Tracker
+5.8.4. FlowIP Tracker
FlowIP provides statistics for individual hosts within a network.
This data can be used for identifying communication habits, such as
perf_monitor = { flow_ip = true }
-5.7.5. CPU Tracker
+5.8.5. CPU Tracker
This tracker monitors the CPU and wall time spent by a given
processing thread.
perf_monitor = { cpu = true }
+5.8.6. Formatters
+
+Performance monitor allows statistics to be output in a few formats.
+Along with human readable text (as seen at shutdown) and csv formats,
+a Flatbuffers binary format is also available if Flatbuffers is
+present at build. A utility for accessing the statistics generated in
+this format has been included for convenience (see fbstreamer in
+tools). This tool generates a YAML array of records found, allowing
+the data to be read by humans or passed into other analysis tools.
+For information on working directly with the Flatbuffers file format
+used by Performance monitor, see the developer notes for Performance
+monitor or the code provided for fbstreamer.
-5.8. Sensitive Data Filtering
+
+5.9. Sensitive Data Filtering
--------------
addresses. A rich regular expression syntax is available for defining
your own PII.
-5.8.1. Hyperscan
+5.9.1. Hyperscan
The sd_pattern rule option is powered by the open source Hyperscan
library from Intel. It provides a regex grammar which is mostly PCRE
compatible. To learn more about Hyperscan see http://01org.github.io/
hyperscan/dev-reference/
-5.8.2. Syntax
+5.9.2. Syntax
Snort provides sd_pattern as IPS rule option with no additional
inspector overhead. The Rule option takes the following syntax.
sd_pattern: "<pattern>"[, threshold <count>];
-5.8.2.1. Pattern
+5.9.2.1. Pattern
Pattern is the most important and is the only required parameter to
sd_pattern. It supports 3 built in patterns which are configured by
Note: This is just an example, this pattern is not suitable to detect
many correctly formatted emails.
-5.8.2.2. Threshold
+5.9.2.2. Threshold
Threshold is an optional parameter allowing you to change built in
default value (default value is 1). The following two instances are
literal" to qualify as a positive match. That is, if the string only
occurred 299 times in a packet, you will not see an event.
-5.8.2.3. Obfuscating Credit Cards and Social Security Numbers
+5.9.2.3. Obfuscating Credit Cards and Social Security Numbers
Snort provides discreet logging for the built in patterns
"credit_card", "us_social" and "us_social_nodashes". Enabling
obfuscate_pii = true
}
-5.8.3. Example
+5.9.3. Example
A complete Snort IPS rule
58 58 58 58 58 58 58 58 58 58 58 58 39 32 39 34 XXXXXXXXXXXX9294
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
-5.8.4. Caveats
+5.9.4. Caveats
1. Snort currently requires setting the fast pattern engine to use
"hyperscan" in order for sd_pattern ips option to function
(This is a known bug).
-5.9. Wizard
+5.10. Wizard
--------------
* 116:151 (decode) same src/dst IP
* 116:449 (decode) unassigned/reserved IP protocol
* 116:472 (decode) too many protocols present
+ * 116:473 (decode) ether type out of range
6.7. detection
Configuration:
* int detection.asn1 = 256: maximum decode nodes { 1: }
+ * int detection.offload_limit = 99999: minimum sizeof PDU to
+ offload fast pattern search (defaults to disabled) { 0: }
+ * int detection.offload_threads = 0: maximum number of simultaneous
+ offloads (defaults to disabled) { 0: }
* bool detection.pcre_enable = true: disable pcre pattern matching
* int detection.pcre_match_limit = 1500: limit pcre backtracking,
-1 = max, 0 = off { -1:1000000 }
* int detection.pcre_match_limit_recursion = 1500: limit pcre stack
consumption, -1 = max, 0 = off { -1:10000 }
+ * int detection.trace: mask for enabling debug traces in module
Peg counts:
* detection.header_searches: fast pattern searches in header buffer
* detection.body_searches: fast pattern searches in body buffer
* detection.file_searches: fast pattern searches in file buffer
+ * detection.offloads: fast pattern searches that were offloaded
* detection.alerts: alerts not including IP reputation
* detection.total_alerts: alerts including IP reputation
* detection.logged: logged packets
* int output.tagged_packet_limit = 256: maximum number of packets
tagged for non-packet metrics { 0: }
* bool output.verbose = false: be verbose (same as -v)
+ * bool output.wide_hex_dump = false: output 20 bytes per lines
+ instead of 16 when dumping buffers
6.19. packets
detection
* dynamic search_engine.search_method = ac_bnfa: set fast pattern
algorithm - choose available search engine { ac_banded | ac_bnfa
- | ac_full | ac_sparse | ac_sparse_bands | ac_std | hyperscan }
+ | ac_full | ac_sparse | ac_sparse_bands | ac_std | hyperscan |
+ lowmem }
* bool search_engine.search_optimize = true: tweak state machine
construction for better performance
* bool search_engine.show_fast_patterns = false: print fast pattern
* string snort.--bpf: <filter options> are standard BPF options, as
seen in TCPDump
* string snort.--c2x: output hex for given char (see also --x2c)
+ * string snort.--control-socket: <file> to create unix socket
* implied snort.--create-pidfile: create PID file, even when not in
Daemon mode
* string snort.--daq: <type> select packet acquisition module
* string snort.--script-path: <path> to a luajit script or
directory containing luajit scripts
* implied snort.--shell: enable the interactive command line
- * implied snort.--piglet: enable piglet test harness mode
* implied snort.--show-plugins: list module and plugin versions
* int snort.--skip: <n> skip 1st n packets { 0: }
* int snort.--snaplen = 1514: <snap> set snaplen of packet (same as
reject rules into alert rules during startup
* implied snort.--treat-drop-as-ignore: use drop, sdrop, and reject
rules to ignore session traffic when not inline
- * string snort.--catch-test: comma separated list of cat unit test
- tags or all
* implied snort.--version: show version number (same as -V)
* implied snort.--warn-all: enable all warnings
* implied snort.--warn-conf: warn about configuration issues
* snort.dump_stats(): show summary statistics
* snort.rotate_stats(): roll perfmonitor log files
* snort.reload_config(filename): load new configuration
+ * snort.reload_daq(): reload daq module
* snort.reload_hosts(filename): load a new hosts table
* snort.pause(): suspend packet processing
* snort.resume(): continue packet processing
* snort.remote_commands: total remote commands processed
* snort.signals: total signals processed
* snort.conf_reloads: number of times configuration was reloaded
+ * snort.daq_reloads: number of times daq configuration was reloaded
* snort.attribute_table_reloads: number of times hosts table was
reloaded
* snort.attribute_table_hosts: total number of hosts in table
--------------
-What: support for general-packet-radio-service tunnelling protocol
+What: support for general-packet-radio-service tunneling protocol
Type: codec
* 116:456 (ipv6) too many IPv6 extension headers
-7.17. mpls
+7.17. llc
+
+--------------
+
+What: support for logical link control
+
+Type: codec
+
+Rules:
+
+ * 116:131 (llc) bad LLC header
+ * 116:132 (llc) bad extra LLC info
+
+
+7.18. mpls
--------------
* mpls.total_bytes: total mpls labeled bytes processed
-7.18. pgm
+7.19. pgm
--------------
* 116:454 (pgm) PGM nak list overflow attempt
-7.19. pppoe
+7.20. pppoe
--------------
* 116:120 (pppoe) bad PPPOE frame detected
-7.20. tcp
+7.21. tcp
--------------
* tcp.bad_tcp6_checksum: nonzero tcp over ipv6 checksums
-7.21. token_ring
+7.22. token_ring
--------------
* 116:143 (token_ring) bad Token Ring MR header
-7.22. udp
+7.23. udp
--------------
* udp.bad_udp6_checksum: nonzero udp over ipv6 checksums
-7.23. vlan
+7.24. vlan
--------------
Rules:
* 116:130 (vlan) bad VLAN frame
- * 116:131 (vlan) bad LLC header
- * 116:132 (vlan) bad extra LLC info
-7.24. wlan
+7.25. wlan
--------------
* string appid.session_log_filter.protocol: ip protocol
* bool appid.session_log_filter.log_all_sessions = false: enable
logging for all appid sessions
+ * bool appid.log_all_sessions = false: enable logging of all appid
+ sessions
Peg counts:
* dce_smb.sessions: total smb sessions
* dce_smb.packets: total smb packets
* dce_smb.ignored_bytes: total ignored bytes
- * dce_smb.client_segs_reassembled: total smb client segments
+ * dce_smb.smb_client_segs_reassembled: total smb client segments
reassembled
- * dce_smb.server_segs_reassembled: total smb server segments
+ * dce_smb.smb_server_segs_reassembled: total smb server segments
reassembled
* dce_smb.max_outstanding_requests: total smb maximum outstanding
requests
* gtp_inspect.unknown_infos: unknown information elements
-9.20. http_global
-
---------------
-
-What: http inspector global configuration and client rules for use
-with http_server
-
-Type: inspector
-
-Configuration:
-
- * int http_global.compress_depth = 65535: maximum amount of packet
- payload to decompress { 1:65535 }
- * int http_global.decode.b64_decode_depth = 0: single packet decode
- depth { -1:65535 }
- * int http_global.decode.bitenc_decode_depth = 0: single packet
- decode depth { -1:65535 }
- * int http_global.decode.max_mime_mem = 838860: single packet
- decode depth { 3276: }
- * int http_global.decode.qp_decode_depth = 0: single packet decode
- depth { -1:65535 }
- * int http_global.decode.uu_decode_depth = 0: single packet decode
- depth { -1:65535 }
- * int http_global.decompress_depth = 65535: maximum amount of
- decompressed data to process { 1:65535 }
- * bool http_global.detect_anomalous_servers = false: inspect
- non-configured ports for HTTP - bad idea
- * int http_global.max_gzip_mem = 0: disregard - not implemented {
- 0: }
- * int http_global.memcap = 0: disregard - not implemented { 0: }
- * bool http_global.proxy_alert = false: alert on proxy usage for
- servers without allow_proxy_use
- * int http_global.unicode_map.code_page = 1252: select code page in
- map file { 0: }
- * string http_global.unicode_map.map_file: unicode map file
-
-Rules:
-
- * 319:1 (http_global) ascii encoding
- * 319:2 (http_global) double decoding attack
- * 319:3 (http_global) u encoding
- * 319:4 (http_global) bare byte unicode encoding
- * 319:5 (http_global) base36 encoding
- * 319:6 (http_global) UTF-8 encoding
- * 319:7 (http_global) IIS unicode codepoint encoding
- * 319:8 (http_global) multi_slash encoding
- * 319:9 (http_global) IIS backslash evasion
- * 319:10 (http_global) self directory traversal
- * 319:11 (http_global) directory traversal
- * 319:12 (http_global) apache whitespace (tab)
- * 319:13 (http_global) non-RFC http delimiter
- * 319:14 (http_global) non-RFC defined char
- * 319:15 (http_global) oversize request-URI directory
- * 319:16 (http_global) oversize chunk encoding
- * 319:17 (http_global) unauthorized proxy use detected
- * 319:18 (http_global) webroot directory traversal
- * 319:19 (http_global) long header
- * 319:20 (http_global) max header fields
- * 319:21 (http_global) multiple content length
- * 319:22 (http_global) chunk size mismatch detected
- * 319:23 (http_global) invalid ip in true-client-IP/XFF header
- * 319:24 (http_global) multiple host hdrs detected
- * 319:25 (http_global) hostname exceeds 255 characters
- * 319:26 (http_global) header parsing space saturation
- * 319:27 (http_global) client consecutive small chunk sizes
- * 319:28 (http_global) post w/o content-length or chunks
- * 319:29 (http_global) multiple true IPs in a session
- * 319:30 (http_global) both true-client-IP and XFF hdrs present
- * 319:31 (http_global) unknown method
- * 319:32 (http_global) simple request
- * 319:33 (http_global) unescaped space in http URI
- * 319:34 (http_global) too many pipelined requests
-
-Peg counts:
-
- * http_global.packets: total packets processed
- * http_global.gets: GET requests
- * http_global.posts: POST requests
- * http_global.request_headers: total requests
- * http_global.response_headers: total responses
- * http_global.request_cookies: requests with Cookie
- * http_global.response_cookies: responses with Set-Cookie
- * http_global.post_params: POST parameters extracted
- * http_global.unicode: unicode normalizations
- * http_global.double_unicode: double unicode normalizations
- * http_global.non_ascii: non-ascii normalizations
- * http_global.paths_with_traversal: directory traversal (../)
- normalizations
- * http_global.paths_with_double_slash: double slash (//)
- normalizations
- * http_global.paths_with_relative: relative directory (./)
- normalizations
- * http_global.gzip_packets: packets with gzip compression
- * http_global.compressed_bytes: total comparessed bytes processed
- * http_global.decompressed_bytes: total bytes decompressed
-
-
-9.21. http_inspect
+9.20. http_inspect
--------------
normalizing URIs
* bool http_inspect.simplify_path = true: reduce URI directory path
to simplest form
- * bool http_inspect.test_input = false: read HTTP messages from
- text file
- * bool http_inspect.test_output = false: print out HTTP section
- data
- * int http_inspect.print_amount = 1200: number of characters to
- print from a Field { 1:1000000 }
- * bool http_inspect.print_hex = false: nonprinting characters
- printed in [HH] format instead of using an asterisk
- * bool http_inspect.show_pegs = true: display peg counts with test
- output
Rules:
* 119:4 (http_inspect) bare byte unicode encoding
* 119:5 (http_inspect) obsolete event—should not appear
* 119:6 (http_inspect) UTF-8 encoding
- * 119:7 (http_inspect) IIS unicode codepoint encoding
+ * 119:7 (http_inspect) unicode map code point encoding in URI
* 119:8 (http_inspect) multi_slash encoding
- * 119:9 (http_inspect) IIS backslash evasion
+ * 119:9 (http_inspect) backslash used in URI path
* 119:10 (http_inspect) self directory traversal
* 119:11 (http_inspect) directory traversal
* 119:12 (http_inspect) apache whitespace (tab)
- * 119:13 (http_inspect) non-RFC http delimiter
+ * 119:13 (http_inspect) HTTP header line terminated by LF without a
+ CR
* 119:14 (http_inspect) non-RFC defined char
* 119:15 (http_inspect) oversize request-uri directory
* 119:16 (http_inspect) oversize chunk encoding
* 119:23 (http_inspect) invalid IP in true-client-IP/XFF header
* 119:24 (http_inspect) multiple host hdrs detected
* 119:25 (http_inspect) hostname exceeds 255 characters
- * 119:26 (http_inspect) header parsing space saturation
+ * 119:26 (http_inspect) too much whitespace in header (not
+ implemented yet)
* 119:27 (http_inspect) client consecutive small chunk sizes
* 119:28 (http_inspect) post w/o content-length or chunks
* 119:29 (http_inspect) multiple true ips in a session
* 119:35 (http_inspect) anomalous http server on undefined HTTP
port
* 119:36 (http_inspect) invalid status code in HTTP response
- * 119:37 (http_inspect) no content-length or transfer-encoding in
- HTTP response
+ * 119:37 (http_inspect) unused event number—should not appear
* 119:38 (http_inspect) HTTP response has UTF charset which failed
to normalize
* 119:39 (http_inspect) HTTP response has UTF-7 charset
* 119:40 (http_inspect) HTTP response gzip decompression failed
* 119:41 (http_inspect) server consecutive small chunk sizes
- * 119:42 (http_inspect) invalid content-length or chunk size
+ * 119:42 (http_inspect) unused event number—should not appear
* 119:43 (http_inspect) javascript obfuscation levels exceeds 1
* 119:44 (http_inspect) javascript whitespaces exceeds max allowed
* 119:45 (http_inspect) multiple encodings within javascript
* 119:79 (http_inspect) server response before client request
* 119:80 (http_inspect) PDF/SWF decompression of server response
too big
+ * 119:81 (http_inspect) nonprinting character in HTTP message
+ header name
+ * 119:82 (http_inspect) bad Content-Length value in HTTP header
+ * 119:83 (http_inspect) HTTP header line wrapped
+ * 119:84 (http_inspect) HTTP header line terminated by CR without a
+ LF
Peg counts:
* http_inspect.uri_coding: URIs with character coding problems
-9.22. http_server
-
---------------
-
-What: http inspection and server rules; also configure http_global
-
-Type: inspector
-
-Configuration:
-
- * bool http_server.allow_proxy_use = false: don’t alert on proxy
- use for this server
- * bool http_server.decompress_pdf = false: enable decompression of
- the compressed portions of PDF files
- * bool http_server.decompress_swf = false: enable decompression of
- SWF (Adobe Flash content)
- * bool http_server.enable_cookies = true: extract cookies
- * bool http_server.enable_xff = false: log True-Client-IP and
- X-Forwarded-For headers with unified2 alerts as extra data
- * bool http_server.extended_ascii_uri = false: allow extended ASCII
- codes in the request URI
- * bool http_server.extended_response_inspection = true: extract
- response headers
- * string http_server.http_methods = GET POST PUT SEARCH MKCOL COPY
- MOVE LOCK UNLOCK NOTIFY POLL BCOPY BDELETE BMOVE LINK UNLINK
- OPTIONS HEAD DELETE TRACE TRACK CONNECT SOURCE SUBSCRIBE
- UNSUBSCRIBE PROPFIND PROPPATCH BPROPFIND BPROPPATCH RPC_CONNECT
- PROXY_SUCCESS BITS_POST CCM_POST SMS_POST RPC_IN_DATA
- RPC_OUT_DATA RPC_ECHO_DATA: request methods allowed in addition
- to GET and POST
- * bool http_server.inspect_gzip = true: enable gzip decompression
- of compressed bodies
- * bool http_server.inspect_uri_only = false: disable all detection
- except for uricontent
- * bool http_server.log_hostname = false: enable logging of Hostname
- with unified2 alerts as extra data
- * bool http_server.log_uri = false: enable logging of URI with
- unified2 alerts as extra data
- * bool http_server.no_pipeline_req = false: don’t inspect pipelined
- requests after first (still does general detection)
- * bit_list http_server.non_rfc_chars = 0x00 0x01 0x02 0x03 0x04
- 0x05 0x06 0x07: alert on given non-RFC chars being present in the
- URI { 255 }
- * bool http_server.normalize_cookies = false: normalize cookies
- similar to URI
- * bool http_server.normalize_headers = false: normalize headers
- other than cookie similar to URI
- * int http_server.oversize_dir_length = 500: alert if a URL has a
- directory longer than this limit { 0: }
- * bool http_server.profile.apache_whitespace = false: don’t alert
- if tab is used in lieu of space characters
- * bool http_server.profile.ascii = false: enable decoding ASCII
- like %2f to /
- * bool http_server.profile.bare_byte = false: decode non-standard,
- non-ASCII character encodings
- * int http_server.profile.chunk_length = 500000: alert on chunk
- lengths greater than specified { 1: }
- * int http_server.profile.client_flow_depth = 0: raw request
- payload to inspect { -1:1460 }
- * bool http_server.profile.directory = false: normalize . and ..
- sequences out of URI
- * bool http_server.profile.double_decode = false: iis specific
- extra decoding
- * bool http_server.profile.iis_backslash = false: normalize
- directory slashes
- * bool http_server.profile.iis_delimiter = false: allow use of
- non-standard delimiter
- * bool http_server.profile.iis_unicode = false: enable unicode code
- point mapping using unicode_map settings
- * int http_server.profile.iis_unicode_map.code_page = 1252: select
- code page in map file { 0: }
- * string http_server.profile.iis_unicode_map.map_file: unicode map
- file
- * int http_server.profile.max_header_length = 750: maximum allowed
- client request header field { 0:65535 }
- * int http_server.profile.max_headers = 100: maximum allowed client
- request headers { 0:1024 }
- * int http_server.profile.max_spaces = 200: maximum allowed
- whitespaces when folding { 0:65535 }
- * bool http_server.profile.multi_slash = false: normalize out
- consecutive slashes in URI
- * bool http_server.profile.non_strict = true: allows HTTP 0.9
- processing
- * int http_server.profile.max_javascript_whitespaces = 200: maximum
- number of consecutive whitespaces { 0: }
- * bool http_server.profile.normalize_utf = true: normalize response
- bodies with UTF content-types
- * bool http_server.profile.normalize_javascript = true: normalize
- javascript between <script> tags
- * int http_server.profile.post_depth = 65495: amount of POST data
- to inspect { -1:65535 }
- * enum http_server.profile.profile_type = default: set defaults
- appropriate for selected server { default | apache | iis | iis_40
- | iis_50 }
- * int http_server.profile.server_flow_depth = 0: response payload
- to inspect; includes headers with extended_response_inspection {
- -1:65535 }
- * bool http_server.profile.u_encode = true: decode %uXXXX character
- sequences
- * bool http_server.profile.utf_8 = false: decode UTF-8 unicode
- sequences in URI
- * bool http_server.profile.webroot = false: alert on directory
- traversals past the top level (web server root)
- * bit_list http_server.profile.whitespace_chars: allowed white
- space characters { 255 }
- * int http_server.small_chunk_count = 5: alert if more than this
- limit of consecutive chunks are below small_chunk_length { 0:255
- }
- * int http_server.small_chunk_length = 10: alert if more than
- small_chunk_count consecutive chunks below this limit { 0:255 }
- * bool http_server.tab_uri_delimiter = false: whether a tab not
- preceded by a space is considered a delimiter or part of URI
- * bool http_server.unlimited_decompress = true: decompress across
- multiple packets
- * bool http_server.xff_headers = false: not implemented
-
-Rules:
-
- * 320:1 (http_server) anomalous http server on undefined HTTP port
- * 320:2 (http_server) invalid status code in HTTP response
- * 320:3 (http_server) no content-length or transfer-encoding in
- HTTP response
- * 320:4 (http_server) HTTP response has UTF charset which failed to
- normalize
- * 320:5 (http_server) HTTP response has UTF-7 charset
- * 320:6 (http_server) HTTP response gzip decompression failed
- * 320:7 (http_server) server consecutive small chunk sizes
- * 320:8 (http_server) invalid content-length or chunk size
- * 320:9 (http_server) javascript obfuscation levels exceeds 1
- * 320:10 (http_server) javascript whitespaces exceeds max allowed
- * 320:11 (http_server) multiple encodings within javascript
- obfuscated data
- * 320:12 (http_server) HTTP response SWF file zlib decompression
- failure
- * 320:13 (http_server) HTTP response SWF file LZMA decompression
- failure
- * 320:14 (http_server) HTTP response PDF file deflate decompression
- failure
- * 320:15 (http_server) HTTP response PDF file unsupported
- compression type
- * 320:16 (http_server) HTTP response PDF file cascaded compression
- * 320:17 (http_server) HTTP response PDF file parse failure
-
-
-9.23. imap
+9.21. imap
--------------
* imap.non_encoded_bytes: total non-encoded extracted bytes
-9.24. modbus
+9.22. modbus
--------------
* modbus.frames: total Modbus messages
-9.25. normalizer
+9.23. normalizer
--------------
from non-SYN packets
* normalizer.tcp_options: packets with options cleared
* normalizer.test_tcp_options: test packets with options cleared
- * normalizer.tcp_paddding: packets with padding cleared
- * normalizer.test_tcp_paddding: test packets with padding cleared
+ * normalizer.tcp_padding: packets with padding cleared
+ * normalizer.test_tcp_padding: test packets with padding cleared
* normalizer.tcp_reserved: packets with reserved bits cleared
* normalizer.test_tcp_reserved: test packets with reserved bits
cleared
* normalizer.test_tcp_trim_syn: test tcp segments trimmed on SYN
* normalizer.tcp_trim_rst: RST packets with data trimmed
* normalizer.test_tcp_trim_rst: test RST packets with data trimmed
- * normalizer.tcp_trim_win: data trimed to window
- * normalizer.test_tcp_trim_win: test data trimed to window
+ * normalizer.tcp_trim_win: data trimmed to window
+ * normalizer.test_tcp_trim_win: test data trimmed to window
* normalizer.tcp_trim_mss: data trimmed to MSS
* normalizer.test_tcp_trim_mss: test data trimmed to MSS
* normalizer.tcp_ecn_session: ECN bits cleared
* normalizer.test_tcp_block: test blocked segments
-9.26. packet_capture
+9.24. packet_capture
--------------
filter
-9.27. perf_monitor
+9.25. perf_monitor
--------------
* string perf_monitor.modules[].pegs: list of statistics to track
or empty for all counters
* enum perf_monitor.format = csv: output format for stats { csv |
- text }
+ text | flatbuffers }
* bool perf_monitor.summary = false: output summary at shutdown
Peg counts:
* perf_monitor.packets: total packets
-9.28. pop
+9.26. pop
--------------
* pop.non_encoded_bytes: total non-encoded extracted bytes
-9.29. port_scan
+9.27. port_scan
--------------
* 122:27 (port_scan) open port
-9.30. port_scan_global
+9.28. port_scan_global
--------------
* port_scan_global.packets: total packets
-9.31. reputation
+9.29. reputation
--------------
* reputation.memory_allocated: total memory allocated
-9.32. rpc_decode
+9.30. rpc_decode
--------------
* rpc_decode.packets: total packets
-9.33. sip
+9.31. sip
--------------
* int sip.max_from_len = 256: maximum from field size { 0:65535 }
* int sip.max_requestName_len = 20: maximum request name field size
{ 0:65535 }
- * int sip.max_sessions = 10000: maximum number of sessions that can
- be allocated { 1024:4194303 }
* int sip.max_to_len = 256: maximum to field size { 0:65535 }
* int sip.max_uri_len = 256: maximum request uri field size {
0:65535 }
Rules:
- * 140:1 (sip) maximum sessions reached
* 140:2 (sip) empty request URI
* 140:3 (sip) URI is too long
* 140:4 (sip) empty call-Id
* sip.notify: notify
* sip.prack: prack
* sip.total_responses: total responses
- * sip.1xx: 1xx
- * sip.2xx: 2xx
- * sip.3xx: 3xx
- * sip.4xx: 4xx
- * sip.5xx: 5xx
- * sip.6xx: 6xx
- * sip.7xx: 7xx
- * sip.8xx: 8xx
- * sip.9xx: 9xx
+ * sip.code_1xx: 1xx
+ * sip.code_2xx: 2xx
+ * sip.code_3xx: 3xx
+ * sip.code_4xx: 4xx
+ * sip.code_5xx: 5xx
+ * sip.code_6xx: 6xx
+ * sip.code_7xx: 7xx
+ * sip.code_8xx: 8xx
+ * sip.code_9xx: 9xx
-9.34. smtp
+9.32. smtp
--------------
* smtp.non_encoded_bytes: total non-encoded extracted bytes
-9.35. ssh
+9.33. ssh
--------------
* ssh.packets: total packets
-9.36. ssl
+9.34. ssl
--------------
* ssl.detection_disabled: total detection disabled
-9.37. stream
+9.35. stream
--------------
sync
-9.38. stream_file
+9.36. stream_file
--------------
* bool stream_file.upload = false: indicate file transfer direction
-9.39. stream_icmp
+9.37. stream_icmp
--------------
* stream_icmp.prunes: icmp session prunes
-9.40. stream_ip
+9.38. stream_ip
--------------
* stream_ip.fragmented_bytes: total fragmented bytes
-9.41. stream_tcp
+9.39. stream_tcp
--------------
* stream_tcp.syn_trackers: tcp session tracking started on syn
* stream_tcp.syn_ack_trackers: tcp session tracking started on
syn-ack
- * stream_tcp.3way_trackers: tcp session tracking started on ack
+ * stream_tcp.three_way_trackers: tcp session tracking started on
+ ack
* stream_tcp.data_trackers: tcp session tracking started on data
* stream_tcp.segs_queued: total segments queued
* stream_tcp.segs_released: total segments released
* stream_tcp.closing: number of sessions currently closing
-9.42. stream_udp
+9.40. stream_udp
--------------
* stream_udp.prunes: udp session prunes
-9.43. stream_user
+9.41. stream_user
--------------
* int stream_user.trace: mask for enabling debug traces in module
-9.44. telnet
+9.42. telnet
--------------
* telnet.packets: total packets
-9.45. wizard
+9.43. wizard
--------------
* implied byte_extract.hex: convert from hex string
* implied byte_extract.oct: convert from octal string
* implied byte_extract.dec: convert from decimal string
+ * int byte_extract.bitmask: applies as an AND to the extracted
+ value before storage in name { 0x1:0xFFFFFFFF }
11.7. byte_jump
Configuration:
* int byte_jump.~count: number of bytes to pick up from the buffer
- { 1:10 }
+ { 0:10 }
* string byte_jump.~offset: variable name or number of bytes into
the buffer to start processing
* implied byte_jump.relative: offset from cursor instead of start
of buffer
* implied byte_jump.from_beginning: jump from start of buffer
instead of cursor
+ * implied byte_jump.from_end: jump backward from end of buffer
* int byte_jump.multiplier = 1: scale extracted value by given
amount { 1:65535 }
* int byte_jump.align = 0: round the number of converted bytes up
* implied byte_jump.hex: convert from hex string
* implied byte_jump.oct: convert from octal string
* implied byte_jump.dec: convert from decimal string
+ * int byte_jump.bitmask: applies as an AND prior to evaluation {
+ 0x1:0xFFFFFFFF }
-11.8. byte_test
+11.8. byte_math
+
+--------------
+
+What: rule option to perform mathematical operations on extracted
+value and a specified value or existing variable
+
+Type: ips_option
+
+Configuration:
+
+ * int byte_math.bytes: number of bytes to pick up from the buffer {
+ 1:10 }
+ * string byte_math.offset: number of bytes into the buffer to start
+ processing
+ * enum byte_math.oper: mathematical operation to perform { +|-|*|/|
+ <<|>> }
+ * string byte_math.rvalue: value to use mathematical operation
+ against
+ * string byte_math.result: name of the variable to store the result
+ * implied byte_math.relative: offset from cursor instead of start
+ of buffer
+ * enum byte_math.endian: specify big/little endian { big|little }
+ * implied byte_math.dce: dcerpc2 determines endianness
+ * enum byte_math.string: convert extracted string to dec/hex/oct {
+ hex|dec|oct }
+ * int byte_math.bitmask: applies as bitwise AND to the extracted
+ value before storage in name { 0x1:0xFFFFFFFF }
+
+
+11.9. byte_test
--------------
* implied byte_test.hex: convert from hex string
* implied byte_test.oct: convert from octal string
* implied byte_test.dec: convert from decimal string
+ * int byte_test.bitmask: applies as an AND prior to evaluation {
+ 0x1:0xFFFFFFFF }
-11.9. classtype
+11.10. classtype
--------------
* string classtype.~: classification for this rule
-11.10. content
+11.11. content
--------------
from cursor
-11.11. cvs
+11.12. cvs
--------------
* implied cvs.invalid-entry: looks for an invalid Entry string
-11.12. dce_iface
+11.13. dce_iface
--------------
* implied dce_iface.any_frag: match on any fragment
-11.13. dce_opnum
+11.14. dce_opnum
--------------
list
-11.14. dce_stub_data
+11.15. dce_stub_data
--------------
Type: ips_option
-11.15. detection_filter
+11.16. detection_filter
--------------
1: }
-11.16. dnp3_data
+11.17. dnp3_data
--------------
Type: ips_option
-11.17. dnp3_func
+11.18. dnp3_func
--------------
* string dnp3_func.~: match dnp3 function code or name
-11.18. dnp3_ind
+11.19. dnp3_ind
--------------
* string dnp3_ind.~: match given dnp3 indicator flags
-11.19. dnp3_obj
+11.20. dnp3_obj
--------------
}
-11.20. dsize
+11.21. dsize
--------------
max | <max | >min
-11.21. file_data
+11.22. file_data
--------------
Type: ips_option
-11.22. file_type
+11.23. file_type
--------------
* string file_type.~: list of file type IDs to match
-11.23. flags
+11.24. flags
--------------
* string flags.~mask_flags: these flags are don’t cares
-11.24. flow
+11.25. flow
--------------
* implied flow.only_frag: match on defragmented packets only
-11.25. flowbits
+11.26. flowbits
--------------
* string flowbits.~arg2: group if arg1 is bits
-11.26. fragbits
+11.27. fragbits
--------------
* string fragbits.~flags: these flags are tested
-11.27. fragoffset
+11.28. fragoffset
--------------
value | min<>max | <max | >min
-11.28. gid
+11.29. gid
--------------
* int gid.~: generator id { 1: }
-11.29. gtp_info
+11.30. gtp_info
--------------
* string gtp_info.~: info element to match
-11.30. gtp_type
+11.31. gtp_type
--------------
* string gtp_type.~: list of types to match
-11.31. gtp_version
+11.32. gtp_version
--------------
* int gtp_version.~: version to match { 0:2 }
-11.32. http_client_body
+11.33. http_client_body
--------------
Type: ips_option
-11.33. http_cookie
+11.34. http_cookie
--------------
Type: ips_option
+Configuration:
+
+ * implied http_cookie.request: match against the cookie from the
+ request message even when examining the response
+ * implied http_cookie.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_cookie.with_trailer: parts of this rule examine HTTP
+ message trailers
+
-11.34. http_header
+11.35. http_header
--------------
What: rule option to set the detection cursor to the normalized
-header(s)
+headers
Type: ips_option
Configuration:
- * string http_header.~name: restrict to given header
+ * string http_header.field: restrict to given header. Header name
+ is case insensitive.
+ * implied http_header.request: match against the headers from the
+ request message even when examining the response
+ * implied http_header.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_header.with_trailer: parts of this rule examine HTTP
+ message trailers
-11.35. http_method
+11.36. http_method
--------------
Type: ips_option
+Configuration:
+
+ * implied http_method.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_method.with_trailer: parts of this rule examine HTTP
+ message trailers
-11.36. http_raw_cookie
+
+11.37. http_raw_cookie
--------------
Type: ips_option
+Configuration:
-11.37. http_raw_header
+ * implied http_raw_cookie.request: match against the cookie from
+ the request message even when examining the response
+ * implied http_raw_cookie.with_body: parts of this rule examine
+ HTTP message body
+ * implied http_raw_cookie.with_trailer: parts of this rule examine
+ HTTP message trailers
+
+
+11.38. http_raw_header
--------------
Type: ips_option
+Configuration:
-11.38. http_raw_request
+ * implied http_raw_header.request: match against the headers from
+ the request message even when examining the response
+ * implied http_raw_header.with_body: parts of this rule examine
+ HTTP message body
+ * implied http_raw_header.with_trailer: parts of this rule examine
+ HTTP message trailers
+
+
+11.39. http_raw_request
--------------
HTTP message trailers
-11.39. http_raw_status
+11.40. http_raw_status
--------------
HTTP message trailers
-11.40. http_raw_trailer
+11.41. http_raw_trailer
--------------
HTTP response message body (must be combined with request)
-11.41. http_raw_uri
+11.42. http_raw_uri
--------------
Type: ips_option
+Configuration:
-11.42. http_stat_code
+ * implied http_raw_uri.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_raw_uri.with_trailer: parts of this rule examine
+ HTTP message trailers
+ * implied http_raw_uri.scheme: match against scheme section of URI
+ only
+ * implied http_raw_uri.host: match against host section of URI only
+ * implied http_raw_uri.port: match against port section of URI only
+ * implied http_raw_uri.path: match against path section of URI only
+ * implied http_raw_uri.query: match against query section of URI
+ only
+ * implied http_raw_uri.fragment: match against fragment section of
+ URI only
+
+
+11.43. http_stat_code
--------------
Type: ips_option
+Configuration:
+
+ * implied http_stat_code.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_stat_code.with_trailer: parts of this rule examine
+ HTTP message trailers
+
-11.43. http_stat_msg
+11.44. http_stat_msg
--------------
Type: ips_option
+Configuration:
+
+ * implied http_stat_msg.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_stat_msg.with_trailer: parts of this rule examine
+ HTTP message trailers
+
-11.44. http_trailer
+11.45. http_trailer
--------------
message body (must be combined with request)
-11.45. http_uri
+11.46. http_uri
--------------
Type: ips_option
+Configuration:
+
+ * implied http_uri.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_uri.with_trailer: parts of this rule examine HTTP
+ message trailers
+ * implied http_uri.scheme: match against scheme section of URI only
+ * implied http_uri.host: match against host section of URI only
+ * implied http_uri.port: match against port section of URI only
+ * implied http_uri.path: match against path section of URI only
+ * implied http_uri.query: match against query section of URI only
+ * implied http_uri.fragment: match against fragment section of URI
+ only
+
-11.46. http_version
+11.47. http_version
--------------
HTTP message trailers
-11.47. icmp_id
+11.48. icmp_id
--------------
>min
-11.48. icmp_seq
+11.49. icmp_seq
--------------
min<>max | <max | >min
-11.49. icode
+11.50. icode
--------------
| >min
-11.50. id
+11.51. id
--------------
min
-11.51. ip_proto
+11.52. ip_proto
--------------
* string ip_proto.~proto: [!|>|<] name or number
-11.52. ipopts
+11.53. ipopts
--------------
lsrre|ssrr|satid|any }
-11.53. isdataat
+11.54. isdataat
--------------
buffer
-11.54. itype
+11.55. itype
--------------
| >min
-11.55. md5
+11.56. md5
--------------
of buffer
-11.56. metadata
+11.57. metadata
--------------
* string metadata.*: additional parameters not used by snort
-11.57. modbus_data
+11.58. modbus_data
--------------
Type: ips_option
-11.58. modbus_func
+11.59. modbus_func
--------------
* string modbus_func.~: function code to match
-11.59. modbus_unit
+11.60. modbus_unit
--------------
* int modbus_unit.~: modbus unit ID { 0:255 }
-11.60. msg
+11.61. msg
--------------
* string msg.~: message describing rule
-11.61. pcre
+11.62. pcre
--------------
* string pcre.~re: Snort regular expression
-11.62. pkt_data
+11.63. pkt_data
--------------
Type: ips_option
-11.63. pkt_num
+11.64. pkt_num
--------------
* string pkt_num.~range: check if packet number is in given range
-11.64. priority
+11.65. priority
--------------
1: }
-11.65. raw_data
+11.66. raw_data
--------------
Type: ips_option
-11.66. reference
+11.67. reference
--------------
* string reference.~id: reference id
-11.67. regex
+11.68. regex
--------------
Configuration:
* string regex.~re: hyperscan regular expression
- * implied regex.nocase: case insensitive match
* implied regex.dotall: matching a . will not exclude newlines
+ * implied regex.fast_pattern: use this content in the fast pattern
+ matcher instead of the content selected by default
+ * implied regex.nocase: case insensitive match
* implied regex.multiline: ^ and $ anchors match any newlines in
data
* implied regex.relative: start search from end of last match
instead of start of buffer
-11.68. rem
+11.69. rem
--------------
* string rem.~: comment
-11.69. replace
+11.70. replace
--------------
* string replace.~: byte code to replace with
-11.70. rev
+11.71. rev
--------------
* int rev.~: revision { 1: }
-11.71. rpc
+11.72. rpc
--------------
* int rpc.proc: procedure number or * for any
-11.72. sd_pattern
+11.73. sd_pattern
--------------
* sd_pattern.terminated: hyperscan terminated
-11.73. seq
+11.74. seq
--------------
min<>max | <max | >min
-11.74. session
+11.75. session
--------------
* enum session.~mode: output format { printable|binary|all }
-11.75. sha256
+11.76. sha256
--------------
start of buffer
-11.76. sha512
+11.77. sha512
--------------
start of buffer
-11.77. sid
+11.78. sid
--------------
* int sid.~: signature id { 1: }
-11.78. sip_body
+11.79. sip_body
--------------
Type: ips_option
-11.79. sip_header
+11.80. sip_header
--------------
Type: ips_option
-11.80. sip_method
+11.81. sip_method
--------------
* string sip_method.*method: sip method
-11.81. sip_stat_code
+11.82. sip_stat_code
--------------
* int sip_stat_code.*code: stat code { 1:999 }
-11.82. so
+11.83. so
--------------
* string so.~func: name of eval function
-11.83. soid
+11.84. soid
--------------
* string soid.~: SO rule ID has <gid>|<sid> format, like 3|12345
-11.84. ssl_state
+11.85. ssl_state
--------------
unknown
-11.85. ssl_version
+11.86. ssl_version
--------------
tls1.2
-11.86. stream_reassemble
+11.87. stream_reassemble
--------------
remainder of the session
-11.87. stream_size
+11.88. stream_size
--------------
direction(s) { either|to_server|to_client|both }
-11.88. tag
+11.89. tag
--------------
* int tag.bytes: tag for this many bytes { 1: }
-11.89. tos
+11.90. tos
--------------
<max | >min
-11.90. ttl
+11.91. ttl
--------------
max | <max | >min
-11.91. urg
+11.92. urg
--------------
min
-11.92. window
+11.93. window
--------------
* all Snort 2 config options are grouped into Snort 3 modules
-16.1. Build Options
+16.1. Features New to Snort 3
+
+--------------
+
+Some things Snort++ can do today that Snort can not do:
+
+ * regex fast patterns, not just literals
+ * FlatBuffers perf monitor logs
+ * LuaJIT scriptable rule options and loggers
+ * pub/sub inspection events (currently used by sip and http to
+ appid)
+ * JIT buffer stuffers (notably with new http_inspect)
+ * C-style comments in rules
+ * #begin … #end comment blocks in rules
+ * rule remarks (comment is part of rule, not just in it)
+ * process raw files (eg read a PDF and do file processing)
+ * process raw payload (eg bridge 2 sockets and do inspection)
+ * fast pattern offload to separate thread (experimental)
+ * track all memory allocated
+ * add or override any config item on command line
+ * set CPU affinity
+ * pause and resume commands
+
+
+16.2. Features Improved over Snort 2
+
+--------------
+
+Some things Snort++ can do today that Snort can not do as well:
+
+ * Hyperscan search engine plugin (Intel provides patch for Snort 2)
+ * fast pattern sensitive data (Snort 2 requires a slow, extra
+ search)
+ * multiple packet threads with one config (Snort 2 requires
+ multiple processes)
+ * wizard automatically detects service for first flow (Snort 2
+ appid detects for next flow)
+ * nested policy binding (Snort 2 has just one level)
+ * decode arbitrary layers (Snort 2 supports only 2 IP layers)
+ * process PDU buffers (Snort 2 only processes packets)
+ * fully stateful http_inspect with 83 builtin alerts (Snort 2 is
+ only partly stateful with 33 builtin alerts)
+ * output all semantic errors before quitting (Snort 2 stops at
+ first one)
+ * alert service (eg http) and alert file rules (Snort 2 must use
+ metadata:service)
+ * elided rule headers omit nets and/or ports (Snort 2 requires
+ explicit any)
+ * dump builtin rule stubs (Snort 2 can only dump SO stubs)
+ * rule sticky buffers (Snort 2 buffers must be repeated)
+ * http_header:name supported to restrict to single field (Snort 2
+ searches all headers)
+ * fully equivalent SO rules (Snort 2 has some limitations with SO
+ processing)
+ * text-based SO rule implementation (Snort 2 requires tedious,
+ nested C structs)
+ * extensible module-based tracing (Snort 2 has a fixed set of
+ flags)
+ * over 200 plugins, no need to change core source code (Snort 2
+ only supports preprocessors and outputs)
+ * use consistent conf syntax (Snort 2 defines lists different ways
+ in different places, etc.)
+ * use consistent rule syntax (Snort 2 has semicolon separated
+ suboptions, etc.)
+ * arbitrary whitespace and comments in conf and rules (Snort 2
+ requires newline escapes)
+ * properly parse rules (Snort 2 can actually completely ignore
+ stuff)
+ * optional warnings output, can be fatal (Snort 2 warnings are not
+ optional or fatal)
+ * define and use arbitrary variables and functions in config with
+ Lua (Snort 2 has variables just for rule headers)
+ * text-based command line shell (Snort 2 has binary control socket)
+ * generate text and HTML user guide in addition to PDF (Snort 2
+ just has PDF and Talos provides HTML)
+ * generate developer’s guide (Snort 2’s is manually written)
+ * extensive command line help, eg every config item, rule option,
+ and peg count (Snort 2 only has command line args)
+ * cmake builds (Snort 2 only does automake)
+ * read rules from separate file or stdin (Snort 2 requires rules
+ directly in or included in conf)
+ * simple, clean, uniform startup and shutdown output (Snort 2 is
+ heavy and inconsistent)
+ * better modularity 346K/1534 = 226 lines/file, max=2700 (Snort 2
+ has 440K/1021 = 431 lines/file, max=13K)
+
+
+16.3. Build Options
--------------
* hardened --enable-inline-init-failopen / INLINE_FAILOPEN
-16.2. Command Line
+16.4. Command Line
--------------
* removed -b, -N, -Z and, --perfmon-file options
-16.3. Conf File
+16.5. Conf File
--------------
active.max_responses, min_interval
-16.4. Rules
+16.6. Rules
--------------
* #begin … #end comments
-16.5. Output
+16.7. Output
--------------
* alert_unified2 and log_unified2 have been deleted
-16.6. HTTP Profiles
-
---------------
-
-This section describes the changes to the Http Inspect config option
-"profile".
-
-Snort 2 allows users to select pre-defined HTTP server profiles using
-the config option "profile". The user can choose one of five
-predefined profiles. When defined, this option will set defaults for
-other config options within Http Inspect.
-
-With Snort 3, the user has the flexibility of defining and fine
-tuning custom profiles along with the five predefined profiles.
-
-Snort 2 conf
-
-preprocessor http_inspect_server: server default \
- profile apache ports { 80 3128 } max_headers 200
-
-Snort 3 conf
-
-http_inspect = { profile = http_profile_apache }
-http_inspect.profile.max_headers = 200
-
-binder =
-{
- {
- when = { proto = 'tcp', ports = '80 3128', },
- use = { type = 'http_inspect' },
- },
-}
-
-Note
-
-The "profile" option now that points to a table "http_profile_apache"
-which is defined in "snort_defaults.lua" (as follows).
-
-http_profile_apache =
-{
- profile_type = 'apache',
- server_flow_depth = 300,
- client_flow_depth = 300,
- post_depth = -1,
- chunk_length = 500000,
- ascii = true,
- multi_slash = true,
- directory = true,
- webroot = true,
- utf_8 = true,
- apache_whitespace = true,
- non_strict = true,
- normalize_utf = true,
- normalize_javascript = false,
- max_header_length = 0,
- max_headers = 0,
- max_spaces = 200,
- max_javascript_whitespaces = 200,
- whitespace_chars ='0x9 0xb 0xc 0xd'
-}
-
-Note
-
-The config option "max_headers" is set to 0 in the profile, but
-overwritten by "http_inspect.profile.max_headers = 200".
-
-Conversion
-
-snort2lua can convert the existing snort.conf with the "profile"
-option to Snort 3 compatible "profile". Please refer to the snort2Lua
-post for more details.
-
-Examples
-
-"profile all" ==> "profile = http_profile_default"
-"profile apache" ==> "profile = http_profile_apache"
-"profile iis" ==> "profile = http_profile_iis"
-"profile iis_40" ==> "profile = http_profile_iis_40"
-"profile iis_50" ==> "profile = http_profile_iis_50"
-
-Defining custom profiles
-
-The complete set of Http Inspect config options that a custom profile
-can configure can be found by running the following command:
-
-snort --help-config http_inspect | grep http_inspect.profile
-
-
-16.7. SDF Preprocessor
+16.8. Sensitive Data
--------------
One of the major differences between Snort 2 and Snort 3 is the
configuration. Snort 2 configuration files are written in
Snort-specific syntax while Snort 3 configuration files are written
-in Lua. Snort2Lua is a program specifically designed to convert Snort
-2 configuration files into Lua files that Snort 3 can understand.
+in Lua. Snort2Lua is a program specifically designed to convert valid
+Snort 2 configuration files into Lua files that Snort 3 can
+understand.
Snort2Lua reads your legacy Snort conf file(s) and generates Snort 3
Lua and rules files. When running this program, the only mandatory
Those errors can occur for a multitude of reasons and are not
necessarily bad. Snort2Lua expects a valid Snort 2 configuration.
-Therefore, if the configuration is invalid or has questionable syntax,
-Snort2Lua may fail to parse the configuration file or create an invalid
-Snort 3 configuration file.
+Therefore, if the configuration is invalid or has questionable
+syntax, Snort2Lua may fail to parse the configuration file or create
+an invalid Snort 3 configuration file.
There are a also few peculiarities of Snort2Lua that may be confusing
to a first time user. Specifically, aside from an initial
* -m add a remark to the end of every converted rule
* -o <out_file> output the new Snort++ lua configuration to
<out_file>
- * -q quiet mode. Only output valid confiration information to the
+ * -q quiet mode. Only output valid configuration information to the
<out_file>
* -r <rule_file> output any converted rule to <rule_file>
* -s when parsing <include_file>, write <include_file>'s rules to
- <rule_file>. Meaningles if -i provided
+ <rule_file>. Meaningless if -i provided
* -t when parsing <include_file>, write <include_file>'s
- information, excluding rules, to <out_file>. Meaningles if -i
+ information, excluding rules, to <out_file>. Meaningless if -i
provided
* -V Print the current Snort2Lua version
* --conf-file Same as -c. A Snort <snort_conf> file which will be
<error_file>
* --help Same as -h. this overview of snort2lua
* --markup print help in asciidoc compatible format
- * --ohi Use Old Http Inspect format
* --output-file=<out_file> Same as -o. output the new Snort++ lua
configuration to <out_file>
* --print-all Same as -a. default option. print all data
* --print-differences Same as -d. output the differences, and only
the differences, between the Snort and Snort++ configurations to
the <out_file>
- * --quiet Same as -q. quiet mode. Only output valid confiration
+ * --quiet Same as -q. quiet mode. Only output valid configuration
information to the <out_file>
* --remark same as -m. add a remark to the end of every converted
rule
longer have that variable in the Lua string.
* Snort2Lua currently does not handle variables well. First, that
means variables will not always be parsed correctly. Second,
- sometimes a variables value will be outoput in the lua file
- rather than a variable For instance, if Snort2Lua attempted to
- convert the line include $RULE_PATH/example.rule, the output may
- ouput include /etc/rules/example.rule instead.
+ sometimes a variables value will be output in the lua file rather
+ than a variable For instance, if Snort2Lua attempted to convert
+ the line include $RULE_PATH/example.rule, the output may output
+ include /etc/rules/example.rule instead.
* When Snort2Lua parses a ‘binding’ configuration file, the rules
and configuration will automatically be combined into the same
file. Also, the new files name will automatically become the old
specify or change that files name.
* If a rule’s action is a custom ruletype, that rule action will be
silently converted to the rultype’s type. No warnings or errors
- are currently emmitted. Additionally, the custom ruletypes
- outputs will be silently discarded.
+ are currently emitted. Additionally, the custom ruletypes outputs
+ will be silently discarded.
* If the original configuration contains a binding that points to
another file and the binding file contains an error, Snort2Lua
will output the number of rejects for the binding file in
for multiple error returns. The C-style use of zero for success
and -1 for error is less readable and often leads to messy code
that either ignores the various errors anyway or needlessly and
- ineffectively tries to do something aobut them. Generally that
+ ineffectively tries to do something about them. Generally that
code is not updated if new errors are added.
* --enable-shell: enable building local and remote command line
shell support.
+ * --enable-tsc-clock: use the TSC register on x86 systems for
+ improved performance of latency and profiler features.
These options are built only if the required libraries and headers
are present. There is no need to explicitly enable.
- * lzma: for decompression of SWF and PDF files.
- * openssl: for SHA and MD5 file signatures and the
- protected_content rule option.
+ * flatbuffers: for an alternative perf_monitor logging format.
+ * hyperscan >= 4.4.0: for the regex and sd_pattern rule options and
+ the hyperscan search engine.
* *intel-soft-cpm": an optional pattern matcher based on a library
from Intel.
- * hyperscan for the regex rule option and hyperscan search engine.
+ * lzma: for decompression of SWF and PDF files.
+ * safec: for additional runtime error checking of some memory copy
+ operations.
If you need to use headers and/or libraries in non-standard
locations, you can use these options:
* --with-pkg-libraries: specify the directory containing the
package libraries.
-These can be use for pcap, luajit, pcre, dnet, daq, lzma, openssl,
-intel-soft-cpm, and hyperscan packages. For more information on these
-libraries see the Getting Started section of the manual.
+These can be used for pcap, luajit, pcre, dnet, daq, lzma, openssl,
+intel-soft-cpm, flatbuffers, and hyperscan packages. For more
+information on these libraries see the Getting Started section of the
+manual.
20.2. Environment Variables
--------------
- * --alert-before-pass process alert, drop, sdrop, or reject before
- pass; default is pass before alert, drop,…
+ * -? <option prefix> output matching command line option quick help
+ (same as --help-options) (optional)
* -A <mode> set alert mode: none, cmg, or alert_*
* -B <mask> obfuscated IP addresses in alerts and packet dumps
using CIDR mask
+ * -C print out payloads with character data only (no hex)
+ * -c <conf> use this configuration
+ * -D run Snort in background (daemon) mode
+ * -d dump the Application Layer
+ * -e display the second layer header info
+ * -f turn off fflush() calls after binary log writes
+ * -G <0xid> (same as --logid) (0:65535)
+ * -g <gname> run snort gid as <gname> group (or gid) after
+ initialization
+ * -H make hash tables deterministic
+ * -i <iface>… list of interfaces
+ * -j <port> to listen for telnet connections
+ * -k <mode> checksum mode; default is all (all|noip|notcp|noudp|
+ noicmp|none)
+ * -L <mode> logging mode (none, dump, pcap, or log_*)
+ * -l <logdir> log to this directory instead of current directory
+ * -M log messages to syslog (not alerts)
+ * -m <umask> set umask = <umask> (0:)
+ * -n <count> stop after count packets (0:)
+ * -O obfuscate the logged IP addresses
+ * -Q enable inline mode operation
+ * -q quiet mode - Don’t show banner and status report
+ * -R <rules> include this rules file in the default policy
+ * -r <pcap>… (same as --pcap-list)
+ * -S <x=v> set config variable x equal to value v
+ * -s <snap> (same as --snaplen); default is 1514 (68:65535)
+ * -T test and report on the current Snort configuration
+ * -t <dir> chroots process to <dir> after initialization
+ * -U use UTC for timestamps
+ * -u <uname> run snort as <uname> or <uid> after initialization
+ * -V (same as --version)
+ * -v be verbose
+ * -W lists available interfaces
+ * -X dump the raw packet data starting at the link layer
+ * -x same as --pedantic
+ * -y include year in timestamp in the alert and log files
+ * -z <count> maximum number of packet threads (same as
+ --max-packet-threads); 0 gets the number of CPU cores reported by
+ the system; default is 1 (0:)
+ * --alert-before-pass process alert, drop, sdrop, or reject before
+ pass; default is pass before alert, drop,…
* --bpf <filter options> are standard BPF options, as seen in
TCPDump
* --c2x output hex for given char (see also --x2c)
- * --catch-test comma separated list of cat unit test tags or all
- * -c <conf> use this configuration
- * -C print out payloads with character data only (no hex)
+ * --control-socket <file> to create unix socket
* --create-pidfile create PID file, even when not in Daemon mode
+ * --daq <type> select packet acquisition module (default is pcap)
* --daq-dir <dir> tell snort where to find desired DAQ
* --daq-list list packet acquisition modules available in optional
dir, default is static modules only
- * --daq <type> select packet acquisition module (default is pcap)
* --daq-var <name=value> specify extra DAQ configuration variable
- * -d dump the Application Layer
* --dirty-pig don’t flush packets on shutdown
- * -D run Snort in background (daemon) mode
* --dump-builtin-rules [<module prefix>] output stub rules for
selected modules
- * --dump-defaults [<module prefix>] output module defaults in Lua
- format (optional)
* --dump-dynamic-rules output stub rules for all loaded rules
libraries
+ * --dump-defaults [<module prefix>] output module defaults in Lua
+ format (optional)
* --dump-version output the version, the whole version, and only
the version
- * -e display the second layer header info
* --enable-inline-test enable Inline-Test Mode Operation
- * -f turn off fflush() calls after binary log writes
- * -G <0xid> (same as --logid) (0:65535)
- * -g <gname> run snort gid as <gname> group (or gid) after
- initialization
+ * --help list command line options
* --help-commands [<module prefix>] output matching commands
(optional)
* --help-config [<module prefix>] output matching config options
(optional)
* --help-counts [<module prefix>] output matching peg counts
(optional)
- * --help list command line options
* --help-module <module> output description of given module
* --help-modules list all available modules with brief help
* --help-options <option prefix> output matching command line
option quick help (same as -?) (optional)
* --help-plugins list all available plugins with brief help
* --help-signals dump available control signals
- * -H make hash tables deterministic
* --id-subdir create/use instance subdirectories in logdir instead
of instance filename prefix
* --id-zero use id prefix / subdirectory even with one packet
thread
- * -i <iface>… list of interfaces
- * -j <port> to listen for telnet connections
- * -k <mode> checksum mode; default is all (all|noip|notcp|noudp|
- noicmp|none)
* --list-buffers output available inspection buffers
* --list-builtin <module prefix> output matching builtin rules
(optional)
* --list-modules [<module type>] list all known modules of given
type (optional)
* --list-plugins list all known plugins
- * -l <logdir> log to this directory instead of current directory
- * -L <mode> logging mode (none, dump, pcap, or log_*)
+ * --lua <chunk> extend/override conf with chunk; may be repeated
* --logid <0xid> log Identifier to uniquely id events for multiple
snorts (same as -G) (0:65535)
- * --lua <chunk> extend/override conf with chunk; may be repeated
* --markup output help in asciidoc compatible format
* --max-packet-threads <count> configure maximum number of packet
threads (same as -z) (0:)
- * -M log messages to syslog (not alerts)
- * -m <umask> set umask = <umask> (0:)
- * -n <count> stop after count packets (0:)
- * --nolock-pidfile do not try to lock Snort PID file
* --nostamps don’t include timestamps in log file names
- * -O obfuscate the logged IP addresses
- * -? <option prefix> output matching command line option quick help
- (same as --help-options) (optional)
+ * --nolock-pidfile do not try to lock Snort PID file
* --pause wait for resume/quit command before processing packets/
terminating
- * --pcap-dir <dir> a directory to recurse to look for pcaps - read
- mode is implied
* --pcap-file <file> file that contains a list of pcaps to read -
read mode is implied
- * --pcap-filter <filter> filter to apply when getting pcaps from
- file or directory
* --pcap-list <list> a space separated list of pcaps to read - read
mode is implied
+ * --pcap-dir <dir> a directory to recurse to look for pcaps - read
+ mode is implied
+ * --pcap-filter <filter> filter to apply when getting pcaps from
+ file or directory
* --pcap-loop <count> read all pcaps <count> times; 0 will read
until Snort is terminated (-1:)
* --pcap-no-filter reset to use no filter when getting pcaps from
between pcaps
* --pcap-show print a line saying what pcap is currently being read
* --pedantic warnings are fatal
- * --piglet enable piglet test harness mode
* --plugin-path <path> where to find plugins
* --process-all-events process all action groups
- * -Q enable inline mode operation
- * -q quiet mode - Don’t show banner and status report
- * -r <pcap>… (same as --pcap-list)
- * -R <rules> include this rules file in the default policy
* --rule <rules> to be added to configuration; may be repeated
* --rule-to-hex output so rule header to stdout for text rule on
stdin
* --show-plugins list module and plugin versions
* --skip <n> skip 1st n packets (0:)
* --snaplen <snap> set snaplen of packet (same as -s) (68:65535)
- * -s <snap> (same as --snaplen); default is 1514 (68:65535)
* --stdin-rules read rules from stdin until EOF or a line starting
with END is read
- * -S <x=v> set config variable x equal to value v
- * -t <dir> chroots process to <dir> after initialization
* --treat-drop-as-alert converts drop, sdrop, and reject rules into
alert rules during startup
* --treat-drop-as-ignore use drop, sdrop, and reject rules to
ignore session traffic when not inline
- * -T test and report on the current Snort configuration
- * -u <uname> run snort as <uname> or <uid> after initialization
- * -U use UTC for timestamps
- * -v be verbose
* --version show version number (same as -V)
- * -V (same as --version)
* --warn-all enable all warnings
* --warn-conf warn about configuration issues
* --warn-daq warn about DAQ issues, usually related to mode
scripts
* --warn-symbols warn about unknown symbols in your Lua config
* --warn-vars warn about variable definition and usage issues
- * -W lists available interfaces
* --x2c output ASCII char for given hex (see also --c2x)
* --x2s output ASCII string for given byte code (see also --x2c)
- * -X dump the raw packet data starting at the link layer
- * -x same as --pedantic
- * -y include year in timestamp in the alert and log files
- * -z <count> maximum number of packet threads (same as
- --max-packet-threads); 0 gets the number of CPU cores reported by
- the system; default is 1 (0:)
20.4. Configuration
information
* int appid.instance_id = 0: instance id - need more details for
what this is { 0: }
+ * bool appid.log_all_sessions = false: enable logging of all appid
+ sessions
* bool appid.log_stats = false: enable logging of appid statistics
* int appid.memcap = 0: disregard - not implemented { 0: }
* string appids.~: comma separated list of application names
* int byte_extract.align = 0: round the number of converted bytes
up to the next 2- or 4-byte boundary { 0:4 }
* implied byte_extract.big: big endian
+ * int byte_extract.bitmask: applies as an AND to the extracted
+ value before storage in name { 0x1:0xFFFFFFFF }
* int byte_extract.~count: number of bytes to pick up from the
buffer { 1:10 }
* implied byte_extract.dce: dcerpc2 determines endianness
* int byte_jump.align = 0: round the number of converted bytes up
to the next 2- or 4-byte boundary { 0:4 }
* implied byte_jump.big: big endian
+ * int byte_jump.bitmask: applies as an AND prior to evaluation {
+ 0x1:0xFFFFFFFF }
* int byte_jump.~count: number of bytes to pick up from the buffer
- { 1:10 }
+ { 0:10 }
* implied byte_jump.dce: dcerpc2 determines endianness
* implied byte_jump.dec: convert from decimal string
* implied byte_jump.from_beginning: jump from start of buffer
instead of cursor
+ * implied byte_jump.from_end: jump backward from end of buffer
* implied byte_jump.hex: convert from hex string
* implied byte_jump.little: little endian
* int byte_jump.multiplier = 1: scale extracted value by given
* implied byte_jump.relative: offset from cursor instead of start
of buffer
* implied byte_jump.string: convert from string
+ * int byte_math.bitmask: applies as bitwise AND to the extracted
+ value before storage in name { 0x1:0xFFFFFFFF }
+ * int byte_math.bytes: number of bytes to pick up from the buffer {
+ 1:10 }
+ * implied byte_math.dce: dcerpc2 determines endianness
+ * enum byte_math.endian: specify big/little endian { big|little }
+ * string byte_math.offset: number of bytes into the buffer to start
+ processing
+ * enum byte_math.oper: mathematical operation to perform { +|-|*|/|
+ <<|>> }
+ * implied byte_math.relative: offset from cursor instead of start
+ of buffer
+ * string byte_math.result: name of the variable to store the result
+ * string byte_math.rvalue: value to use mathematical operation
+ against
+ * enum byte_math.string: convert extracted string to dec/hex/oct {
+ hex|dec|oct }
* implied byte_test.big: big endian
+ * int byte_test.bitmask: applies as an AND prior to evaluation {
+ 0x1:0xFFFFFFFF }
* string byte_test.~compare: variable name or value to test the
converted result against
* int byte_test.~count: number of bytes to pick up from the buffer
1: }
* enum detection_filter.track: track hits by source or destination
IP address { by_src | by_dst }
+ * int detection.offload_limit = 99999: minimum sizeof PDU to
+ offload fast pattern search (defaults to disabled) { 0: }
+ * int detection.offload_threads = 0: maximum number of simultaneous
+ offloads (defaults to disabled) { 0: }
* bool detection.pcre_enable = true: disable pcre pattern matching
* int detection.pcre_match_limit = 1500: limit pcre backtracking,
-1 = max, 0 = off { -1:1000000 }
* int detection.pcre_match_limit_recursion = 1500: limit pcre stack
consumption, -1 = max, 0 = off { -1:10000 }
+ * int detection.trace: mask for enabling debug traces in module
* bool dnp3.check_crc = false: validate checksums in DNP3 link
layer frames
* string dnp3_func.~: match dnp3 function code or name
* enum host_tracker[].tcp_policy: tcp reassembly policy { first |
last | linux | old_linux | bsd | macos | solaris | irix | hpux11
| hpux10 | windows | win_2003 | vista | proxy }
- * int http_global.compress_depth = 65535: maximum amount of packet
- payload to decompress { 1:65535 }
- * int http_global.decode.b64_decode_depth = 0: single packet decode
- depth { -1:65535 }
- * int http_global.decode.bitenc_decode_depth = 0: single packet
- decode depth { -1:65535 }
- * int http_global.decode.max_mime_mem = 838860: single packet
- decode depth { 3276: }
- * int http_global.decode.qp_decode_depth = 0: single packet decode
- depth { -1:65535 }
- * int http_global.decode.uu_decode_depth = 0: single packet decode
- depth { -1:65535 }
- * int http_global.decompress_depth = 65535: maximum amount of
- decompressed data to process { 1:65535 }
- * bool http_global.detect_anomalous_servers = false: inspect
- non-configured ports for HTTP - bad idea
- * int http_global.max_gzip_mem = 0: disregard - not implemented {
- 0: }
- * int http_global.memcap = 0: disregard - not implemented { 0: }
- * bool http_global.proxy_alert = false: alert on proxy usage for
- servers without allow_proxy_use
- * int http_global.unicode_map.code_page = 1252: select code page in
- map file { 0: }
- * string http_global.unicode_map.map_file: unicode map file
- * string http_header.~name: restrict to given header
+ * implied http_cookie.request: match against the cookie from the
+ request message even when examining the response
+ * implied http_cookie.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_cookie.with_trailer: parts of this rule examine HTTP
+ message trailers
+ * string http_header.field: restrict to given header. Header name
+ is case insensitive.
+ * implied http_header.request: match against the headers from the
+ request message even when examining the response
+ * implied http_header.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_header.with_trailer: parts of this rule examine HTTP
+ message trailers
* bool http_inspect.backslash_to_slash = false: replace \ with /
when normalizing URIs
* bit_list http_inspect.bad_characters: alert when any of specified
encodings
* bool http_inspect.plus_to_space = true: replace + with <sp> when
normalizing URIs
- * int http_inspect.print_amount = 1200: number of characters to
- print from a Field { 1:1000000 }
- * bool http_inspect.print_hex = false: nonprinting characters
- printed in [HH] format instead of using an asterisk
* int http_inspect.request_depth = -1: maximum request message body
bytes to examine (-1 no limit) { -1: }
* int http_inspect.response_depth = -1: maximum response message
body bytes to examine (-1 no limit) { -1: }
- * bool http_inspect.show_pegs = true: display peg counts with test
- output
* bool http_inspect.simplify_path = true: reduce URI directory path
to simplest form
- * bool http_inspect.test_input = false: read HTTP messages from
- text file
- * bool http_inspect.test_output = false: print out HTTP section
- data
* bool http_inspect.unzip = true: decompress gzip and deflate
message bodies
* bool http_inspect.utf8_bare_byte = false: when doing UTF-8
encoded
* bool http_inspect.utf8 = true: normalize 2-byte and 3-byte UTF-8
characters to a single byte
+ * implied http_method.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_method.with_trailer: parts of this rule examine HTTP
+ message trailers
+ * implied http_raw_cookie.request: match against the cookie from
+ the request message even when examining the response
+ * implied http_raw_cookie.with_body: parts of this rule examine
+ HTTP message body
+ * implied http_raw_cookie.with_trailer: parts of this rule examine
+ HTTP message trailers
+ * implied http_raw_header.request: match against the headers from
+ the request message even when examining the response
+ * implied http_raw_header.with_body: parts of this rule examine
+ HTTP message body
+ * implied http_raw_header.with_trailer: parts of this rule examine
+ HTTP message trailers
* implied http_raw_request.with_body: parts of this rule examine
HTTP message body
* implied http_raw_request.with_trailer: parts of this rule examine
HTTP response message body (must be combined with request)
* implied http_raw_trailer.with_header: parts of this rule examine
HTTP response message headers (must be combined with request)
- * bool http_server.allow_proxy_use = false: don’t alert on proxy
- use for this server
- * bool http_server.decompress_pdf = false: enable decompression of
- the compressed portions of PDF files
- * bool http_server.decompress_swf = false: enable decompression of
- SWF (Adobe Flash content)
- * bool http_server.enable_cookies = true: extract cookies
- * bool http_server.enable_xff = false: log True-Client-IP and
- X-Forwarded-For headers with unified2 alerts as extra data
- * bool http_server.extended_ascii_uri = false: allow extended ASCII
- codes in the request URI
- * bool http_server.extended_response_inspection = true: extract
- response headers
- * string http_server.http_methods = GET POST PUT SEARCH MKCOL COPY
- MOVE LOCK UNLOCK NOTIFY POLL BCOPY BDELETE BMOVE LINK UNLINK
- OPTIONS HEAD DELETE TRACE TRACK CONNECT SOURCE SUBSCRIBE
- UNSUBSCRIBE PROPFIND PROPPATCH BPROPFIND BPROPPATCH RPC_CONNECT
- PROXY_SUCCESS BITS_POST CCM_POST SMS_POST RPC_IN_DATA
- RPC_OUT_DATA RPC_ECHO_DATA: request methods allowed in addition
- to GET and POST
- * bool http_server.inspect_gzip = true: enable gzip decompression
- of compressed bodies
- * bool http_server.inspect_uri_only = false: disable all detection
- except for uricontent
- * bool http_server.log_hostname = false: enable logging of Hostname
- with unified2 alerts as extra data
- * bool http_server.log_uri = false: enable logging of URI with
- unified2 alerts as extra data
- * bit_list http_server.non_rfc_chars = 0x00 0x01 0x02 0x03 0x04
- 0x05 0x06 0x07: alert on given non-RFC chars being present in the
- URI { 255 }
- * bool http_server.no_pipeline_req = false: don’t inspect pipelined
- requests after first (still does general detection)
- * bool http_server.normalize_cookies = false: normalize cookies
- similar to URI
- * bool http_server.normalize_headers = false: normalize headers
- other than cookie similar to URI
- * int http_server.oversize_dir_length = 500: alert if a URL has a
- directory longer than this limit { 0: }
- * bool http_server.profile.apache_whitespace = false: don’t alert
- if tab is used in lieu of space characters
- * bool http_server.profile.ascii = false: enable decoding ASCII
- like %2f to /
- * bool http_server.profile.bare_byte = false: decode non-standard,
- non-ASCII character encodings
- * int http_server.profile.chunk_length = 500000: alert on chunk
- lengths greater than specified { 1: }
- * int http_server.profile.client_flow_depth = 0: raw request
- payload to inspect { -1:1460 }
- * bool http_server.profile.directory = false: normalize . and ..
- sequences out of URI
- * bool http_server.profile.double_decode = false: iis specific
- extra decoding
- * bool http_server.profile.iis_backslash = false: normalize
- directory slashes
- * bool http_server.profile.iis_delimiter = false: allow use of
- non-standard delimiter
- * bool http_server.profile.iis_unicode = false: enable unicode code
- point mapping using unicode_map settings
- * int http_server.profile.iis_unicode_map.code_page = 1252: select
- code page in map file { 0: }
- * string http_server.profile.iis_unicode_map.map_file: unicode map
- file
- * int http_server.profile.max_header_length = 750: maximum allowed
- client request header field { 0:65535 }
- * int http_server.profile.max_headers = 100: maximum allowed client
- request headers { 0:1024 }
- * int http_server.profile.max_javascript_whitespaces = 200: maximum
- number of consecutive whitespaces { 0: }
- * int http_server.profile.max_spaces = 200: maximum allowed
- whitespaces when folding { 0:65535 }
- * bool http_server.profile.multi_slash = false: normalize out
- consecutive slashes in URI
- * bool http_server.profile.non_strict = true: allows HTTP 0.9
- processing
- * bool http_server.profile.normalize_javascript = true: normalize
- javascript between <script> tags
- * bool http_server.profile.normalize_utf = true: normalize response
- bodies with UTF content-types
- * int http_server.profile.post_depth = 65495: amount of POST data
- to inspect { -1:65535 }
- * enum http_server.profile.profile_type = default: set defaults
- appropriate for selected server { default | apache | iis | iis_40
- | iis_50 }
- * int http_server.profile.server_flow_depth = 0: response payload
- to inspect; includes headers with extended_response_inspection {
- -1:65535 }
- * bool http_server.profile.u_encode = true: decode %uXXXX character
- sequences
- * bool http_server.profile.utf_8 = false: decode UTF-8 unicode
- sequences in URI
- * bool http_server.profile.webroot = false: alert on directory
- traversals past the top level (web server root)
- * bit_list http_server.profile.whitespace_chars: allowed white
- space characters { 255 }
- * int http_server.small_chunk_count = 5: alert if more than this
- limit of consecutive chunks are below small_chunk_length { 0:255
- }
- * int http_server.small_chunk_length = 10: alert if more than
- small_chunk_count consecutive chunks below this limit { 0:255 }
- * bool http_server.tab_uri_delimiter = false: whether a tab not
- preceded by a space is considered a delimiter or part of URI
- * bool http_server.unlimited_decompress = true: decompress across
- multiple packets
- * bool http_server.xff_headers = false: not implemented
+ * implied http_raw_uri.fragment: match against fragment section of
+ URI only
+ * implied http_raw_uri.host: match against host section of URI only
+ * implied http_raw_uri.path: match against path section of URI only
+ * implied http_raw_uri.port: match against port section of URI only
+ * implied http_raw_uri.query: match against query section of URI
+ only
+ * implied http_raw_uri.scheme: match against scheme section of URI
+ only
+ * implied http_raw_uri.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_raw_uri.with_trailer: parts of this rule examine
+ HTTP message trailers
+ * implied http_stat_code.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_stat_code.with_trailer: parts of this rule examine
+ HTTP message trailers
+ * implied http_stat_msg.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_stat_msg.with_trailer: parts of this rule examine
+ HTTP message trailers
* string http_trailer.field: restrict to given trailer
* implied http_trailer.request: match against the trailers from the
request message even when examining the response
message body (must be combined with request)
* implied http_trailer.with_header: parts of this rule examine HTTP
response message headers (must be combined with request)
+ * implied http_uri.fragment: match against fragment section of URI
+ only
+ * implied http_uri.host: match against host section of URI only
+ * implied http_uri.path: match against path section of URI only
+ * implied http_uri.port: match against port section of URI only
+ * implied http_uri.query: match against query section of URI only
+ * implied http_uri.scheme: match against scheme section of URI only
+ * implied http_uri.with_body: parts of this rule examine HTTP
+ message body
+ * implied http_uri.with_trailer: parts of this rule examine HTTP
+ message trailers
* implied http_version.request: match against the version from the
request message even when examining the response
* implied http_version.with_body: parts of this rule examine HTTP
* int output.tagged_packet_limit = 256: maximum number of packets
tagged for non-packet metrics { 0: }
* bool output.verbose = false: be verbose (same as -v)
+ * bool output.wide_hex_dump = false: output 20 bytes per lines
+ instead of 16 when dumping buffers
* bool packet_capture.enable = false: initially enable packet
dumping
* string packet_capture.filter: bpf filter to use for packet dump
* int perf_monitor.flow_ports = 1023: maximum ports to track {
0:65535 }
* enum perf_monitor.format = csv: output format for stats { csv |
- text }
+ text | flatbuffers }
* int perf_monitor.max_file_size = 1073741824: files will be rolled
over if they exceed this size { 4096: }
* string perf_monitor.modules[].name: name of the module
* string references[].name: name used with reference rule option
* string references[].url: where this reference is defined
* implied regex.dotall: matching a . will not exclude newlines
+ * implied regex.fast_pattern: use this content in the fast pattern
+ matcher instead of the content selected by default
* implied regex.multiline: ^ and $ anchors match any newlines in
data
* implied regex.nocase: case insensitive match
* int sip.max_from_len = 256: maximum from field size { 0:65535 }
* int sip.max_requestName_len = 20: maximum request name field size
{ 0:65535 }
- * int sip.max_sessions = 10000: maximum number of sessions that can
- be allocated { 1024:4194303 }
* int sip.max_to_len = 256: maximum to field size { 0:65535 }
* int sip.max_uri_len = 256: maximum request uri field size {
0:65535 }
* string snort.--bpf: <filter options> are standard BPF options, as
seen in TCPDump
* string snort.--c2x: output hex for given char (see also --x2c)
- * string snort.--catch-test: comma separated list of cat unit test
- tags or all
* string snort.-c: <conf> use this configuration
+ * string snort.--control-socket: <file> to create unix socket
* implied snort.-C: print out payloads with character data only (no
hex)
* implied snort.--create-pidfile: create PID file, even when not in
* implied snort.--pcap-show: print a line saying what pcap is
currently being read
* implied snort.--pedantic: warnings are fatal
- * implied snort.--piglet: enable piglet test harness mode
* string snort.--plugin-path: <path> where to find plugins
* implied snort.--process-all-events: process all action groups
* implied snort.-Q: enable inline mode operation
minimum fragment size
* dce_smb.client_segs_reassembled: total connection-oriented client
segments reassembled
- * dce_smb.client_segs_reassembled: total smb client segments
- reassembled
* dce_smb.events: total events
* dce_smb.faults: total connection-oriented faults
* dce_smb.files_processed: total smb files processed
minimum fragment size
* dce_smb.server_segs_reassembled: total connection-oriented server
segments reassembled
- * dce_smb.server_segs_reassembled: total smb server segments
- reassembled
* dce_smb.sessions: total smb sessions
* dce_smb.shutdowns: total connection-oriented shutdowns
+ * dce_smb.smb_client_segs_reassembled: total smb client segments
+ reassembled
+ * dce_smb.smb_server_segs_reassembled: total smb server segments
+ reassembled
* dce_smb.smbv2_close: total number of SMBv2 close packets seen
* dce_smb.smbv2_create: total number of SMBv2 create packets seen
* dce_smb.smbv2_read: total number of SMBv2 read packets seen
* detection.logged: logged packets
* detection.log_limit: events queued but not logged
* detection.match_limit: fast pattern matches not processed
+ * detection.offloads: fast pattern searches that were offloaded
* detection.passed: passed packets
* detection.pkt_searches: fast pattern searches in packet data
* detection.queue_limit: events not queued because queue full
* host_tracker.service_adds: host service adds
* host_tracker.service_finds: host service finds
* host_tracker.service_removes: host service removes
- * http_global.compressed_bytes: total comparessed bytes processed
- * http_global.decompressed_bytes: total bytes decompressed
- * http_global.double_unicode: double unicode normalizations
- * http_global.gets: GET requests
- * http_global.gzip_packets: packets with gzip compression
- * http_global.non_ascii: non-ascii normalizations
- * http_global.packets: total packets processed
- * http_global.paths_with_double_slash: double slash (//)
- normalizations
- * http_global.paths_with_relative: relative directory (./)
- normalizations
- * http_global.paths_with_traversal: directory traversal (../)
- normalizations
- * http_global.post_params: POST parameters extracted
- * http_global.posts: POST requests
- * http_global.request_cookies: requests with Cookie
- * http_global.request_headers: total requests
- * http_global.response_cookies: responses with Set-Cookie
- * http_global.response_headers: total responses
- * http_global.unicode: unicode normalizations
* http_inspect.chunked: chunked message bodies
* http_inspect.connect_requests: CONNECT requests inspected
* http_inspect.delete_requests: DELETE requests inspected
* normalizer.tcp_ips_data: normalized segments
* normalizer.tcp_nonce: packets with nonce bit cleared
* normalizer.tcp_options: packets with options cleared
- * normalizer.tcp_paddding: packets with padding cleared
+ * normalizer.tcp_padding: packets with padding cleared
* normalizer.tcp_req_pay: cleared urgent pointer and urgent flag
when there is no payload
* normalizer.tcp_req_urg: cleared urgent pointer when urgent flag
* normalizer.tcp_trim_mss: data trimmed to MSS
* normalizer.tcp_trim_rst: RST packets with data trimmed
* normalizer.tcp_trim_syn: tcp segments trimmed on SYN
- * normalizer.tcp_trim_win: data trimed to window
+ * normalizer.tcp_trim_win: data trimmed to window
* normalizer.tcp_ts_ecr: timestamp cleared on non-ACKs
* normalizer.tcp_ts_nop: timestamp options cleared
* normalizer.tcp_urgent_ptr: packets without data with urgent
* normalizer.test_tcp_ips_data: test normalized segments
* normalizer.test_tcp_nonce: test packets with nonce bit cleared
* normalizer.test_tcp_options: test packets with options cleared
- * normalizer.test_tcp_paddding: test packets with padding cleared
+ * normalizer.test_tcp_padding: test packets with padding cleared
* normalizer.test_tcp_req_pay: test cleared urgent pointer and
urgent flag when there is no payload
* normalizer.test_tcp_req_urg: test cleared urgent pointer when
* normalizer.test_tcp_trim_mss: test data trimmed to MSS
* normalizer.test_tcp_trim_rst: test RST packets with data trimmed
* normalizer.test_tcp_trim_syn: test tcp segments trimmed on SYN
- * normalizer.test_tcp_trim_win: test data trimed to window
+ * normalizer.test_tcp_trim_win: test data trimmed to window
* normalizer.test_tcp_ts_ecr: test timestamp cleared on non-ACKs
* normalizer.test_tcp_ts_nop: test timestamp options cleared
* normalizer.test_tcp_urgent_ptr: test packets without data with
to overflow
* search_engine.total_inserts: total fast pattern hits
* search_engine.total_unique: total unique fast pattern hits
- * sip.1xx: 1xx
- * sip.2xx: 2xx
- * sip.3xx: 3xx
- * sip.4xx: 4xx
- * sip.5xx: 5xx
- * sip.6xx: 6xx
- * sip.7xx: 7xx
- * sip.8xx: 8xx
- * sip.9xx: 9xx
* sip.ack: ack
* sip.bye: bye
* sip.cancel: cancel
+ * sip.code_1xx: 1xx
+ * sip.code_2xx: 2xx
+ * sip.code_3xx: 3xx
+ * sip.code_4xx: 4xx
+ * sip.code_5xx: 5xx
+ * sip.code_6xx: 6xx
+ * sip.code_7xx: 7xx
+ * sip.code_8xx: 8xx
+ * sip.code_9xx: 9xx
* sip.dialogs: total dialogs
* sip.events: events generated
* sip.ignored_channels: total channels ignored
* snort.attribute_table_reloads: number of times hosts table was
reloaded
* snort.conf_reloads: number of times configuration was reloaded
+ * snort.daq_reloads: number of times daq configuration was reloaded
* snort.local_commands: total local commands processed
* snort.remote_commands: total remote commands processed
* snort.signals: total signals processed
* stream_ip.trackers_completed: datagram trackers completed
* stream_ip.trackers_freed: datagram trackers released
* stream.ip_uni_prunes: ip uni sessions pruned
- * stream_tcp.3way_trackers: tcp session tracking started on ack
* stream_tcp.client_cleanups: number of times data from server was
flushed when session released
* stream_tcp.closing: number of sessions currently closing
* stream_tcp.syn_ack_trackers: tcp session tracking started on
syn-ack
* stream_tcp.syn_trackers: tcp session tracking started on syn
+ * stream_tcp.three_way_trackers: tcp session tracking started on
+ ack
* stream_tcp.timeouts: tcp session timeouts
* stream.tcp_total_prunes: total tcp sessions pruned
* stream.tcp_uni_prunes: tcp uni sessions pruned
* 116: igmp
* 116: ipv4
* 116: ipv6
+ * 116: llc
* 116: mpls
* 116: pgm
* 116: pppoe
* 144: modbus
* 145: dnp3
* 256: dpx
- * 319: http_global
- * 320: http_server
20.7. Builtin Rules
* 116:112 (eapol) EAP header truncated
* 116:120 (pppoe) bad PPPOE frame detected
* 116:130 (vlan) bad VLAN frame
- * 116:131 (vlan) bad LLC header
- * 116:132 (vlan) bad extra LLC info
+ * 116:131 (llc) bad LLC header
+ * 116:132 (llc) bad extra LLC info
* 116:133 (wlan) bad 802.11 LLC header
* 116:134 (wlan) bad 802.11 extra LLC info
* 116:140 (token_ring) bad Token Ring header
* 116:470 (ciscometadata) invalid Cisco Metadata option type
* 116:471 (ciscometadata) invalid Cisco Metadata SGT
* 116:472 (decode) too many protocols present
+ * 116:473 (decode) ether type out of range
* 119:1 (http_inspect) ascii encoding
* 119:2 (http_inspect) double decoding attack
* 119:3 (http_inspect) u encoding
* 119:4 (http_inspect) bare byte unicode encoding
* 119:5 (http_inspect) obsolete event—should not appear
* 119:6 (http_inspect) UTF-8 encoding
- * 119:7 (http_inspect) IIS unicode codepoint encoding
+ * 119:7 (http_inspect) unicode map code point encoding in URI
* 119:8 (http_inspect) multi_slash encoding
- * 119:9 (http_inspect) IIS backslash evasion
+ * 119:9 (http_inspect) backslash used in URI path
* 119:10 (http_inspect) self directory traversal
* 119:11 (http_inspect) directory traversal
* 119:12 (http_inspect) apache whitespace (tab)
- * 119:13 (http_inspect) non-RFC http delimiter
+ * 119:13 (http_inspect) HTTP header line terminated by LF without a
+ CR
* 119:14 (http_inspect) non-RFC defined char
* 119:15 (http_inspect) oversize request-uri directory
* 119:16 (http_inspect) oversize chunk encoding
* 119:23 (http_inspect) invalid IP in true-client-IP/XFF header
* 119:24 (http_inspect) multiple host hdrs detected
* 119:25 (http_inspect) hostname exceeds 255 characters
- * 119:26 (http_inspect) header parsing space saturation
+ * 119:26 (http_inspect) too much whitespace in header (not
+ implemented yet)
* 119:27 (http_inspect) client consecutive small chunk sizes
* 119:28 (http_inspect) post w/o content-length or chunks
* 119:29 (http_inspect) multiple true ips in a session
* 119:35 (http_inspect) anomalous http server on undefined HTTP
port
* 119:36 (http_inspect) invalid status code in HTTP response
- * 119:37 (http_inspect) no content-length or transfer-encoding in
- HTTP response
+ * 119:37 (http_inspect) unused event number—should not appear
* 119:38 (http_inspect) HTTP response has UTF charset which failed
to normalize
* 119:39 (http_inspect) HTTP response has UTF-7 charset
* 119:40 (http_inspect) HTTP response gzip decompression failed
* 119:41 (http_inspect) server consecutive small chunk sizes
- * 119:42 (http_inspect) invalid content-length or chunk size
+ * 119:42 (http_inspect) unused event number—should not appear
* 119:43 (http_inspect) javascript obfuscation levels exceeds 1
* 119:44 (http_inspect) javascript whitespaces exceeds max allowed
* 119:45 (http_inspect) multiple encodings within javascript
* 119:79 (http_inspect) server response before client request
* 119:80 (http_inspect) PDF/SWF decompression of server response
too big
+ * 119:81 (http_inspect) nonprinting character in HTTP message
+ header name
+ * 119:82 (http_inspect) bad Content-Length value in HTTP header
+ * 119:83 (http_inspect) HTTP header line wrapped
+ * 119:84 (http_inspect) HTTP header line terminated by CR without a
+ LF
* 122:1 (port_scan) TCP portscan
* 122:2 (port_scan) TCP decoy portscan
* 122:3 (port_scan) TCP portsweep
* 137:2 (ssl) invalid server HELLO without client HELLO detected
* 137:3 (ssl) heartbeat read overrun attempt detected
* 137:4 (ssl) large heartbeat response detected
- * 140:1 (sip) maximum sessions reached
* 140:2 (sip) empty request URI
* 140:3 (sip) URI is too long
* 140:4 (sip) empty call-Id
* 145:6 (dnp3) DNP3 application-layer fragment uses a reserved
function code
* 256:1 (dpx) too much data sent to port
- * 319:1 (http_global) ascii encoding
- * 319:2 (http_global) double decoding attack
- * 319:3 (http_global) u encoding
- * 319:4 (http_global) bare byte unicode encoding
- * 319:5 (http_global) base36 encoding
- * 319:6 (http_global) UTF-8 encoding
- * 319:7 (http_global) IIS unicode codepoint encoding
- * 319:8 (http_global) multi_slash encoding
- * 319:9 (http_global) IIS backslash evasion
- * 319:10 (http_global) self directory traversal
- * 319:11 (http_global) directory traversal
- * 319:12 (http_global) apache whitespace (tab)
- * 319:13 (http_global) non-RFC http delimiter
- * 319:14 (http_global) non-RFC defined char
- * 319:15 (http_global) oversize request-URI directory
- * 319:16 (http_global) oversize chunk encoding
- * 319:17 (http_global) unauthorized proxy use detected
- * 319:18 (http_global) webroot directory traversal
- * 319:19 (http_global) long header
- * 319:20 (http_global) max header fields
- * 319:21 (http_global) multiple content length
- * 319:22 (http_global) chunk size mismatch detected
- * 319:23 (http_global) invalid ip in true-client-IP/XFF header
- * 319:24 (http_global) multiple host hdrs detected
- * 319:25 (http_global) hostname exceeds 255 characters
- * 319:26 (http_global) header parsing space saturation
- * 319:27 (http_global) client consecutive small chunk sizes
- * 319:28 (http_global) post w/o content-length or chunks
- * 319:29 (http_global) multiple true IPs in a session
- * 319:30 (http_global) both true-client-IP and XFF hdrs present
- * 319:31 (http_global) unknown method
- * 319:32 (http_global) simple request
- * 319:33 (http_global) unescaped space in http URI
- * 319:34 (http_global) too many pipelined requests
- * 320:1 (http_server) anomalous http server on undefined HTTP port
- * 320:2 (http_server) invalid status code in HTTP response
- * 320:3 (http_server) no content-length or transfer-encoding in
- HTTP response
- * 320:4 (http_server) HTTP response has UTF charset which failed to
- normalize
- * 320:5 (http_server) HTTP response has UTF-7 charset
- * 320:6 (http_server) HTTP response gzip decompression failed
- * 320:7 (http_server) server consecutive small chunk sizes
- * 320:8 (http_server) invalid content-length or chunk size
- * 320:9 (http_server) javascript obfuscation levels exceeds 1
- * 320:10 (http_server) javascript whitespaces exceeds max allowed
- * 320:11 (http_server) multiple encodings within javascript
- obfuscated data
- * 320:12 (http_server) HTTP response SWF file zlib decompression
- failure
- * 320:13 (http_server) HTTP response SWF file LZMA decompression
- failure
- * 320:14 (http_server) HTTP response PDF file deflate decompression
- failure
- * 320:15 (http_server) HTTP response PDF file unsupported
- compression type
- * 320:16 (http_server) HTTP response PDF file cascaded compression
- * 320:17 (http_server) HTTP response PDF file parse failure
20.8. Command Set
--------------
- * packet_capture.disable(): stop packet dump
* packet_capture.enable(filter): dump raw packets
- * snort.detach(): exit shell w/o shutdown
+ * packet_capture.disable(): stop packet dump
+ * snort.show_plugins(): show available plugins
* snort.dump_stats(): show summary statistics
- * snort.help(): this output
- * snort.pause(): suspend packet processing
- * snort.quit(): shutdown and dump-stats
+ * snort.rotate_stats(): roll perfmonitor log files
* snort.reload_config(filename): load new configuration
+ * snort.reload_daq(): reload daq module
* snort.reload_hosts(filename): load a new hosts table
+ * snort.pause(): suspend packet processing
* snort.resume(): continue packet processing
- * snort.rotate_stats(): roll perfmonitor log files
- * snort.show_plugins(): show available plugins
+ * snort.detach(): exit shell w/o shutdown
+ * snort.quit(): shutdown and dump-stats
+ * snort.help(): this output
20.9. Signals
Signal numbers are for the system that generated this documentation
and are not applicable elsewhere.
- * hosts(23): reload hosts file
+ * term(15): shutdown normally
* int(2): shutdown normally
* quit(3): shutdown as if started with --dirty-pig
- * reload(1): reload config file
- * rotate(12): rotate stats files
* stats(10): dump stats to stdout
- * term(15): shutdown normally
+ * rotate(12): rotate stats files
+ * reload(1): reload config file
+ * hosts(23): reload hosts file
20.10. Configuration Changes
change -> dynamicengine ==> 'snort.--plugin_path=<path>'
change -> dynamicpreprocessor ==> 'snort.--plugin_path=<path>'
change -> dynamicsidechannel ==> 'snort.--plugin_path=<path>'
-change -> alertfile: 'config alertfile:' ==> 'alert_fast.file'
-change -> alertfile: 'config alertfile:' ==> 'alert_full.file'
change -> attribute_table: 'STREAM_POLICY' ==> 'hosts: tcp_policy'
change -> attribute_table: 'filename <file_name>' ==> 'hosts[]'
change -> config ' addressspace_agnostic' ==> ' packets. address_space_agnostic'
change -> config ' checksum_mode' ==> ' network. checksum_eval'
-change -> config ' daq' ==> ' daq. type'
-change -> config ' daq_dir' ==> ' daq. dir'
-change -> config ' daq_mode' ==> ' daq. mode'
-change -> config ' daq_var' ==> ' daq. var'
+change -> config ' daq' ==> ' daq. module'
+change -> config ' daq_dir' ==> ' daq. module_dirs, true'
+change -> config ' daq_var' ==> ' daq. variables, true'
change -> config ' detection_filter' ==> ' alerts. detection_filter_memcap'
change -> config ' enable_deep_teredo_inspection' ==> ' udp. deep_teredo_inspection'
change -> config ' event_filter' ==> ' alerts. event_filter_memcap'
change -> config ' rate_filter' ==> ' alerts. rate_filter_memcap'
change -> config ' react' ==> ' react. page'
change -> config ' threshold' ==> ' alerts. event_filter_memcap'
+change -> csv: 'csv' ==> 'fields'
change -> csv: 'dgmlen' ==> 'dgm_len'
change -> csv: 'dst' ==> 'dst_addr'
change -> csv: 'dstport' ==> 'dst_port'
change -> csv: 'icmpid' ==> 'icmp_id'
change -> csv: 'icmpseq' ==> 'icmp_seq'
change -> csv: 'icmptype' ==> 'icmp_type'
+change -> csv: 'id' ==> 'ip_id'
change -> csv: 'iplen' ==> 'ip_len'
change -> csv: 'sig_generator' ==> 'gid'
change -> csv: 'sig_id' ==> 'sid'
change -> csv: 'tcpseq' ==> 'tcp_seq'
change -> csv: 'tcpwindow' ==> 'tcp_win'
change -> csv: 'udplength' ==> 'udp_len'
-change -> detection: 'ac' ==> 'ac_full_q'
+change -> detection: 'ac' ==> 'ac_full'
change -> detection: 'ac-banded' ==> 'ac_banded'
-change -> detection: 'ac-bnfa' ==> 'ac_bnfa_q'
+change -> detection: 'ac-bnfa' ==> 'ac_bnfa'
change -> detection: 'ac-bnfa-nq' ==> 'ac_bnfa'
-change -> detection: 'ac-bnfa-q' ==> 'ac_bnfa_q'
+change -> detection: 'ac-bnfa-q' ==> 'ac_bnfa'
change -> detection: 'ac-nq' ==> 'ac_full'
-change -> detection: 'ac-q' ==> 'ac_full_q'
+change -> detection: 'ac-q' ==> 'ac_full'
change -> detection: 'ac-sparsebands' ==> 'ac_sparse_bands'
-change -> detection: 'ac-split' ==> 'ac_full_q'
+change -> detection: 'ac-split' ==> 'ac_full'
change -> detection: 'ac-split' ==> 'split_any_any'
change -> detection: 'ac-std' ==> 'ac_std'
change -> detection: 'acs' ==> 'ac_sparse'
change -> detection: 'bleedover-port-limit' ==> 'bleedover_port_limit'
+change -> detection: 'debug-print-fast-pattern' ==> 'show_fast_patterns'
change -> detection: 'intel-cpm' ==> 'intel_cpm'
-change -> detection: 'lowmem' ==> 'lowmem_q'
change -> detection: 'lowmem-nq' ==> 'lowmem'
-change -> detection: 'lowmem-q' ==> 'lowmem_q'
+change -> detection: 'lowmem-q' ==> 'lowmem'
change -> detection: 'max-pattern-len' ==> 'max_pattern_len'
+change -> detection: 'no_stream_inserts' ==> 'inspect_stream_inserts'
change -> detection: 'search-method' ==> 'search_method'
change -> detection: 'search-optimize' ==> 'search_optimize'
change -> detection: 'split-any-any' ==> 'split_any_any'
+change -> dnp3: 'ports' ==> 'bindings'
change -> dns: 'ports' ==> 'bindings'
change -> event_filter: 'gen_id' ==> 'gid'
change -> event_filter: 'sig_id' ==> 'sid'
change -> ftp_telnet_protocol: 'alt_max_param_len' ==> 'cmd_validity'
change -> ftp_telnet_protocol: 'data_chan' ==> 'ignore_data_chan'
change -> ftp_telnet_protocol: 'ports' ==> 'bindings'
-change -> gtp: 'ports' ==> 'gtp_ports'
-change -> http_inspect: 'http_inspect' ==> 'http_global'
-change -> http_inspect_server: 'apache_whitespace' ==> 'profile.apache_whitespace'
-change -> http_inspect_server: 'ascii' ==> 'profile.ascii'
-change -> http_inspect_server: 'bare_byte' ==> 'profile.bare_byte'
-change -> http_inspect_server: 'chunk_length' ==> 'profile.chunk_length'
-change -> http_inspect_server: 'client_flow_depth' ==> 'profile.client_flow_depth'
-change -> http_inspect_server: 'directory' ==> 'profile.directory'
-change -> http_inspect_server: 'double_decode' ==> 'profile.double_decode'
-change -> http_inspect_server: 'enable_cookie' ==> 'enable_cookies'
-change -> http_inspect_server: 'flow_depth' ==> 'server_flow_depth'
+change -> gtp: 'ports' ==> 'bindings'
+change -> http_inspect_server: 'bare_byte' ==> 'utf8_bare_byte'
+change -> http_inspect_server: 'client_flow_depth' ==> 'request_depth'
+change -> http_inspect_server: 'double_decode' ==> 'iis_double_decode'
change -> http_inspect_server: 'http_inspect_server' ==> 'http_inspect'
-change -> http_inspect_server: 'iis_backslash' ==> 'profile.iis_backslash'
-change -> http_inspect_server: 'iis_delimiter' ==> 'profile.iis_delimiter'
-change -> http_inspect_server: 'iis_unicode' ==> 'profile.iis_unicode'
-change -> http_inspect_server: 'max_header_length' ==> 'profile.max_header_length'
-change -> http_inspect_server: 'max_headers' ==> 'profile.max_headers'
-change -> http_inspect_server: 'max_spaces' ==> 'profile.max_spaces'
-change -> http_inspect_server: 'multi_slash' ==> 'profile.multi_slash'
-change -> http_inspect_server: 'non_rfc_char' ==> 'non_rfc_chars'
-change -> http_inspect_server: 'non_strict' ==> 'profile.non_strict'
-change -> http_inspect_server: 'normalize_utf' ==> 'profile.normalize_utf'
+change -> http_inspect_server: 'iis_backslash' ==> 'backslash_to_slash'
+change -> http_inspect_server: 'inspect_gzip' ==> 'unzip'
+change -> http_inspect_server: 'non_rfc_char' ==> 'bad_characters'
change -> http_inspect_server: 'ports' ==> 'bindings'
-change -> http_inspect_server: 'u_encode' ==> 'profile.u_encode'
-change -> http_inspect_server: 'utf_8' ==> 'profile.utf_8'
-change -> http_inspect_server: 'webroot' ==> 'profile.webroot'
-change -> http_inspect_server: 'whitespace_chars' ==> 'profile.whitespace_chars'
+change -> http_inspect_server: 'u_encode' ==> 'percent_u'
+change -> http_inspect_server: 'utf_8' ==> 'utf8'
change -> imap: 'ports' ==> 'bindings'
+change -> modbus: 'ports' ==> 'bindings'
change -> paf_max: 'paf_max [0:63780]' ==> 'max_pdu [1460:63780]'
-change -> perfmonitor: 'accumulate' ==> 'reset = false'
-change -> perfmonitor: 'flow-file' ==> 'flow_file = true'
+change -> perfmonitor: 'console' ==> 'format = 'text''
+change -> perfmonitor: 'console' ==> 'output = 'console''
+change -> perfmonitor: 'file' ==> 'format = 'csv''
+change -> perfmonitor: 'file' ==> 'output = 'file''
+change -> perfmonitor: 'flow-file' ==> 'format = 'csv''
+change -> perfmonitor: 'flow-file' ==> 'output = 'file''
change -> perfmonitor: 'flow-ip' ==> 'flow_ip'
-change -> perfmonitor: 'flow-ip-file' ==> 'flow_ip_file = true'
+change -> perfmonitor: 'flow-ip-file' ==> 'format = 'csv''
+change -> perfmonitor: 'flow-ip-file' ==> 'output = 'file''
change -> perfmonitor: 'flow-ip-memcap' ==> 'flow_ip_memcap'
change -> perfmonitor: 'flow-ports' ==> 'flow_ports'
change -> perfmonitor: 'pktcnt' ==> 'packets'
-change -> perfmonitor: 'snortfile' ==> 'file = true'
+change -> perfmonitor: 'snortfile' ==> 'format = 'csv''
+change -> perfmonitor: 'snortfile' ==> 'output = 'file''
change -> perfmonitor: 'time' ==> 'seconds'
change -> policy_mode: 'inline_test' ==> 'inline-test'
change -> pop: 'ports' ==> 'bindings'
-change -> ppm: 'max-pkt-time' ==> 'max_pkt_time'
-change -> ppm: 'max-rule-time' ==> 'max_rule_time'
-change -> ppm: 'pkt-log' ==> 'pkt_log'
-change -> ppm: 'rule-log' ==> 'rule_log'
-change -> ppm: 'suspend-timeout' ==> 'suspend_timeout'
+change -> ppm: ''both'' ==> ''alert_and_log''
+change -> ppm: 'fastpath-expensive-packets' ==> 'packet.fastpath'
+change -> ppm: 'max-pkt-time' ==> 'packet.max_time'
+change -> ppm: 'max-rule-time' ==> 'rule.max_time'
+change -> ppm: 'pkt-log' ==> 'packet.action'
+change -> ppm: 'ppm' ==> 'latency'
+change -> ppm: 'rule-log' ==> 'rule.action'
+change -> ppm: 'suspend-expensive-rules' ==> 'rule.suspend'
+change -> ppm: 'suspend-timeout' ==> 'max_suspend_time'
+change -> ppm: 'threshold' ==> 'rule.suspend_threshold'
change -> preprocessor 'normalize_ icmp4' ==> 'normalize. icmp4'
change -> preprocessor 'normalize_ icmp6' ==> 'normalize. icmp6'
change -> preprocessor 'normalize_ ip6' ==> 'normalize. ip6'
change -> profile: 'print' ==> 'count'
+change -> profile: 'sort avg_ticks' ==> 'sort = avg_check'
+change -> profile: 'sort total_ticks' ==> 'sort = total_time'
change -> rate_filter: 'gen_id' ==> 'gid'
change -> rate_filter: 'sig_id' ==> 'sid'
change -> rule_state: 'disabled' ==> 'enable'
deleted -> attribute_table: '<STREAM_POLICY>noack</STREAM_POLICY>'
deleted -> attribute_table: '<STREAM_POLICY>unknown</STREAM_POLICY>'
deleted -> config ' cs_dir'
+deleted -> config ' daq_mode'
+deleted -> config ' decode_data_link'
deleted -> config ' disable_attribute_reload_thread'
deleted -> config ' disable_decode_alerts'
deleted -> config ' disable_decode_drops'
+deleted -> config ' disable_inline_init_failopen'
deleted -> config ' disable_ipopt_alerts'
deleted -> config ' disable_ipopt_drops'
deleted -> config ' disable_tcpopt_alerts'
deleted -> config ' include_vlan_in_alerts'
deleted -> config ' interface'
deleted -> config ' layer2resets'
+deleted -> config ' nolog'
deleted -> config ' policy_version'
deleted -> config ' so_rule_memcap'
deleted -> csv: '<filename> can no longer be specific'
deleted -> csv: 'default'
deleted -> csv: 'trheader'
deleted -> detection: 'mwm'
+deleted -> dnp3: 'disabled'
+deleted -> dnp3: 'memcap'
deleted -> dns: 'enable_experimental_types'
deleted -> dns: 'enable_obsolete_types'
deleted -> dns: 'enable_rdata_overflow'
+deleted -> event_trace: 'file'
deleted -> fast: '<filename> can no longer be specific'
deleted -> frag3_engine: 'detect_anomalies'
deleted -> frag3_global: 'disabled'
deleted -> ftp_telnet_protocol: 'detect_anomalies'
deleted -> full: '<filename> can no longer be specific'
+deleted -> http_inspect: 'detect_anomalous_servers'
deleted -> http_inspect: 'disabled'
+deleted -> http_inspect: 'proxy_alert'
+deleted -> http_inspect_server: 'allow_proxy_use'
+deleted -> http_inspect_server: 'enable_cookie'
+deleted -> http_inspect_server: 'enable_xff'
+deleted -> http_inspect_server: 'extended_ascii_uri'
+deleted -> http_inspect_server: 'extended_response_inspection'
+deleted -> http_inspect_server: 'iis_unicode_map not allowed in sever'
+deleted -> http_inspect_server: 'inspect_uri_only'
+deleted -> http_inspect_server: 'log_hostname'
+deleted -> http_inspect_server: 'log_uri'
deleted -> http_inspect_server: 'no_alerts'
+deleted -> http_inspect_server: 'no_pipeline_req'
+deleted -> http_inspect_server: 'non_strict'
+deleted -> http_inspect_server: 'normalize_cookies'
+deleted -> http_inspect_server: 'normalize_headers'
+deleted -> http_inspect_server: 'small_chunk_length'
+deleted -> http_inspect_server: 'tab_uri_delimiter'
+deleted -> http_inspect_server: 'unlimited_decompress'
deleted -> imap: 'disabled'
deleted -> imap: 'max_mime_mem'
deleted -> imap: 'memcap'
+deleted -> perfmonitor: 'accumulate'
deleted -> perfmonitor: 'atexitonly'
deleted -> perfmonitor: 'atexitonly: base-stats'
deleted -> perfmonitor: 'atexitonly: events-stats'
deleted -> perfmonitor: 'atexitonly: flow-ip-stats'
deleted -> perfmonitor: 'atexitonly: flow-stats'
+deleted -> perfmonitor: 'atexitonly: reset'
+deleted -> perfmonitor: 'events'
+deleted -> perfmonitor: 'max'
deleted -> pop: 'disabled'
deleted -> pop: 'max_mime_mem'
deleted -> pop: 'memcap'
deleted -> ppm: 'debug-pkts'
deleted -> react: 'block'
deleted -> react: 'warn'
+deleted -> reputation: 'shared_mem'
+deleted -> reputation: 'shared_refresh'
deleted -> rpc_decode: 'alert_fragments'
deleted -> rpc_decode: 'no_alert_incomplete'
deleted -> rpc_decode: 'no_alert_large_fragments'
deleted -> sfportscan: 'disabled'
deleted -> sfportscan: 'logfile'
deleted -> sip: 'disabled'
+deleted -> sip: 'max_sessions'
deleted -> smtp: 'alert_unknown_cmds'
deleted -> smtp: 'disabled'
deleted -> smtp: 'enable_mime_decoding'
deleted -> ssl: 'noinspect_encrypted'
deleted -> stream5_global: 'disabled'
deleted -> stream5_global: 'flush_on_alert'
+deleted -> stream5_global: 'memcap'
deleted -> stream5_global: 'no_midstream_drop_alerts'
deleted -> stream5_tcp: 'check_session_hijacking'
deleted -> stream5_tcp: 'detect_anomalies'
deleted -> stream5_tcp: 'dont_store_large_packets'
+deleted -> stream5_tcp: 'ignore_ports'
+deleted -> stream5_tcp: 'log_asymmetric_traffic'
deleted -> stream5_tcp: 'policy noack'
deleted -> stream5_tcp: 'policy unknown'
deleted -> tcpdump: '<filename> can no longer be specific'
* byte_extract (ips_option): rule option to convert data to an
integer variable
* byte_jump (ips_option): rule option to move the detection cursor
+ * byte_math (ips_option): rule option to perform mathematical
+ operations on extracted value and a specified value or existing
+ variable
* byte_test (ips_option): rule option to convert data to integer
and compare
* ciscometadata (codec): support for cisco metadata
be configured
* gid (ips_option): rule option specifying rule generator
* gre (codec): support for generic routing encapsulation
- * gtp (codec): support for general-packet-radio-service tunnelling
+ * gtp (codec): support for general-packet-radio-service tunneling
protocol
* gtp_info (ips_option): rule option to check gtp info element
* gtp_inspect (inspector): gtp control channel inspection
cursor to the request body
* http_cookie (ips_option): rule option to set the detection cursor
to the HTTP cookie
- * http_global (inspector): http inspector global configuration and
- client rules for use with http_server
* http_header (ips_option): rule option to set the detection cursor
- to the normalized header(s)
+ to the normalized headers
* http_inspect (inspector): HTTP inspector
* http_method (ips_option): rule option to set the detection cursor
to the HTTP request method
cursor to the unnormalized trailers
* http_raw_uri (ips_option): rule option to set the detection
cursor to the unnormalized URI
- * http_server (inspector): http inspection and server rules; also
- configure http_global
* http_stat_code (ips_option): rule option to set the detection
cursor to the HTTP status code
* http_stat_msg (ips_option): rule option to set the detection
payload data
* itype (ips_option): rule option to check ICMP type
* latency (basic): packet and rule latency monitoring and control
+ * llc (codec): support for logical link control
* log_codecs (logger): log protocols in packet by layer
* log_hext (logger): output payload suitable for daq hext
* log_pcap (logger): log packet in pcap format
* codec::eth: support for ethernet protocol (DLT 1) (DLT 51)
* codec::fabricpath: support for fabricpath
* codec::gre: support for generic routing encapsulation
- * codec::gtp: support for general-packet-radio-service tunnelling
+ * codec::gtp: support for general-packet-radio-service tunneling
protocol
* codec::icmp4: support for Internet control message protocol v4
* codec::icmp4_ip: support for IP in ICMPv4
* inspector::ftp_data: FTP data channel handler
* inspector::ftp_server: FTP inspector server module
* inspector::gtp_inspect: gtp control channel inspection
- * inspector::http_global: shared HTTP inspector settings
* inspector::http_inspect: the new HTTP inspector!
- * inspector::http_server: main HTTP inspector module
* inspector::imap: imap inspection
* inspector::modbus: modbus inspection
* inspector::normalizer: packet scrubbing for inline mode
* ips_option::byte_extract: rule option to convert data to an
integer variable
* ips_option::byte_jump: rule option to move the detection cursor
+ * ips_option::byte_math: rule option to perform mathematical
+ operations on extracted value and a specified value or existing
+ variable
* ips_option::byte_test: rule option to convert data to integer and
compare
* ips_option::classtype: general rule option for rule
* ips_option::http_cookie: rule option to set the detection cursor
to the HTTP cookie
* ips_option::http_header: rule option to set the detection cursor
- to the normalized header(s)
+ to the normalized headers
* ips_option::http_method: rule option to set the detection cursor
to the HTTP request method
* ips_option::http_raw_cookie: rule option to set the detection
* logger::log_null: disable logging of packets
* logger::log_pcap: log packet in pcap format
* logger::unified2: output event and packet in unified2 format file
- * piglet::pp_codec: Codec piglet
- * piglet::pp_inspector: Inspector piglet
- * piglet::pp_ips_action: Ips action piglet
- * piglet::pp_ips_option: Ips option piglet
- * piglet::pp_logger: Logger piglet
- * piglet::pp_search_engine: Search engine piglet
- * piglet::pp_so_rule: SO rule piglet
- * piglet::pp_test: Test piglet
* search_engine::ac_banded: Aho-Corasick Banded (high memory,
moderate performance)
* search_engine::ac_bnfa: Aho-Corasick Binary NFA (low memory, high