]>
git.ipfire.org Git - thirdparty/snort3.git/log
Russ Combs [Thu, 16 Jul 2015 18:44:00 +0000 (14:44 -0400)]
fix system specific build issue
huica [Thu, 16 Jul 2015 13:28:59 +0000 (09:28 -0400)]
Merge branch 'master' of ssh://huica@chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into fileclass2
Russ Combs [Thu, 16 Jul 2015 13:13:47 +0000 (09:13 -0400)]
fix broken cmake
huica [Thu, 16 Jul 2015 13:04:11 +0000 (09:04 -0400)]
Merge branch 'master' of
ssh://huica@chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into
fileclass2
Conflicts:
src/file_api/file_capture.h
src/service_inspectors/smtp/smtp_config.h
Russ Combs [Thu, 16 Jul 2015 13:03:35 +0000 (09:03 -0400)]
Squashed commit of the following:
commit
eec3e7b2bdb059d5443926b092907a43e843eb36
Author: davis mcpherson <davis.mcpherson@gmail.com>
Date: Thu Jul 16 05:30:16 2015 -0400
initial draft and updates to stream component dev notes
Russ Combs [Thu, 16 Jul 2015 12:55:22 +0000 (08:55 -0400)]
update documentation
Russ Combs [Thu, 16 Jul 2015 02:27:40 +0000 (22:27 -0400)]
Squashed commit of the following:
additional header cleanup; add/remove config.h; consistent author lines; and other scrubbing
fuchsia -> green and additional css tweaks via sed
cleanup and formatting of dev_notes.txt
dev notes and header scrubbing for helpers/ and protocols/
remove dead file
removed hard limit on number of rules; converted sfrim to use vector
Additional dev guide updates.
davis: dev guide updates
hui: update sip dev notes
parser cleanup
some C++ification of structs
update events dev notes
Bhagya: dev guide updates
ed - dev guide updates
added dev_guide.sh to doc/
remove doxygen markup
packet_io dev notes tweaks
spell check updates
Ed: dev guide updates
carter: dev guide updates
Merge branch 'devdoc_file' from hui
dev notes for src/search_engines/
wizard dev notes
src/network_inspectors/binder/ dev notes
dev notes for src/managers/
dev notes for src/main/
dev notes for src/framework/
dev notes for src/flow/
src/detection/ dev guide updates
dev notes for src/ports
commit
7cddb3d668f7eafce0c7c78787673932d5f45906
Author: Tom Peters <thopeter@cisco.com>
Date: Tue Jul 14 14:17:18 2015 -0400
NHI Guide
commit
3fd9e703ffb27353e435cfaad3f5909b85ef02ff
Author: huica <huica@cisco.com>
Date: Mon Jul 13 16:47:57 2015 -0400
update documents for sfip, sfrt, and target-based
commit
1a1be2c9191a5743fd8318894586131f1b785a3b
Author: Bhagyashree Bantwal <bbantwal@cisco.com>
Date: Mon Jul 13 13:27:45 2015 -0400
dev guide update
commit
aec8ca50dbdd72cec9cd7e7150d2d49e481fb811
Author: Tom Peters <thopeter@cisco.com>
Date: Mon Jul 13 11:47:41 2015 -0400
Developer's Guide
commit
ed093eb5857e9a94aa612c652d19ec2e5ae7924f
Author: huica <huica@cisco.com>
Date: Fri Jul 10 17:26:15 2015 -0400
file API document updated
huica [Wed, 15 Jul 2015 20:47:28 +0000 (16:47 -0400)]
file mime separation
huica [Wed, 15 Jul 2015 14:05:57 +0000 (10:05 -0400)]
Merge branch 'master' of ssh://huica@chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into fileclass2
Russ Combs [Fri, 10 Jul 2015 00:45:42 +0000 (20:45 -0400)]
fix cmake parallel build of docs
Russ Combs [Thu, 9 Jul 2015 20:07:23 +0000 (16:07 -0400)]
remove redundant chunked
Russ Combs [Thu, 9 Jul 2015 19:47:41 +0000 (15:47 -0400)]
ensure all docs built sequentially to avoid xml issue
Russ Combs [Thu, 9 Jul 2015 18:11:10 +0000 (14:11 -0400)]
fix cmake build of docs
Tom Peters [Wed, 8 Jul 2015 15:12:32 +0000 (11:12 -0400)]
Merge branch 'master' of /nfs/home/rucombs/Snort++
huica [Tue, 7 Jul 2015 19:42:23 +0000 (15:42 -0400)]
Merge branch 'master' of ssh://huica@chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into fileclass2
Russ Combs [Tue, 7 Jul 2015 17:01:04 +0000 (13:01 -0400)]
Squashed commit of the following:
commit
0f4301235ab202cd9f7bb555d409c7c21ee030dd
Author: Russ Combs <rucombs@cisco.com>
Date: Tue Jul 7 12:59:47 2015 -0400
Squashed commit of the following:
commit
8c11ee5abd9cf2f695c8d74fca6cf610c6b69d55
Author: Joel Cornett <joel.cornett@gmail.com>
Date: Mon Jul 6 13:10:03 2015 -0400
fixed warning for unused variable
manual merge of updates from feature/piglet branch
removed unused lua helper sources
fix warnings on clang/osx
commit
406b779dfe76e95f0bf00c825c0b6a16d06e8af4
Author: Russ Combs <rucombs@cisco.com>
Date: Fri Jul 3 08:10:19 2015 -0400
uncrustification
add copyright
TODO -> FIXIT
commit
47cadb98e8f2d694f85eefc7997c08c76e51b81a
Author: Russ Combs <rucombs@cisco.com>
Date: Fri Jul 3 08:10:19 2015 -0400
Squashed commit of the following:
commit
e7b52fed1a6069927e8a38d291545af3615a999b
Author: Joel Cornett <joel.cornett@gmail.com>
Date: Thu Jun 4 19:48:25 2015 -0400
piglet test harness
Russ Combs [Tue, 7 Jul 2015 15:58:11 +0000 (11:58 -0400)]
update cmake to a2
Russ Combs [Tue, 7 Jul 2015 15:55:37 +0000 (11:55 -0400)]
Squashed commit of the following:
remove dead code
make smtp packet processing flag thread local
bump configured version from a1 to a2
Russ Combs [Mon, 6 Jul 2015 15:48:04 +0000 (11:48 -0400)]
build 160 - alpha 2
Tom Peters [Mon, 6 Jul 2015 15:02:44 +0000 (11:02 -0400)]
Merge branch 'master' of /nfs/home/rucombs/Snort++
huica [Mon, 6 Jul 2015 13:47:47 +0000 (09:47 -0400)]
Merge branch 'master' of ssh://huica@chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into fileclass2
huica [Mon, 6 Jul 2015 13:47:25 +0000 (09:47 -0400)]
enable file capture
Russ Combs [Mon, 6 Jul 2015 11:35:54 +0000 (07:35 -0400)]
update make foo for prior commit
Russ Combs [Mon, 6 Jul 2015 11:23:40 +0000 (07:23 -0400)]
Squashed commit of the following:
commit
0c99294e56f953f9cd4e5d50fe7d0177edf0df17
Author: Russ Combs <rucombs@cisco.com>
Date: Sat Jul 4 15:26:34 2015 -0400
remove dead code
Russ Combs [Sat, 4 Jul 2015 11:42:35 +0000 (07:42 -0400)]
fix Snort++ markup
Russ Combs [Sat, 4 Jul 2015 03:05:37 +0000 (23:05 -0400)]
add bugs list to manual
Russ Combs [Fri, 3 Jul 2015 20:38:38 +0000 (16:38 -0400)]
allow file_data searches for service rules for now; mic cleanup
russ [Fri, 3 Jul 2015 11:49:43 +0000 (07:49 -0400)]
fix tcp bindings for pdus; fix smtp leak
Russ Combs [Fri, 3 Jul 2015 02:46:57 +0000 (22:46 -0400)]
fix smtp command init
Russ Combs [Thu, 2 Jul 2015 22:02:48 +0000 (18:02 -0400)]
fix sip leaks, valgrind issues, and usage
Tom Peters [Thu, 2 Jul 2015 19:59:04 +0000 (15:59 -0400)]
Merge branch 'master' of /nfs/home/rucombs/Snort++
Tom Peters [Thu, 2 Jul 2015 19:58:43 +0000 (15:58 -0400)]
test tool upgrade
Russ Combs [Thu, 2 Jul 2015 19:07:38 +0000 (15:07 -0400)]
fix sip stats and misc static analysis issues
Russ Combs [Thu, 2 Jul 2015 16:51:16 +0000 (12:51 -0400)]
grumble
Russ Combs [Thu, 2 Jul 2015 16:45:25 +0000 (12:45 -0400)]
rename user pkt to pdu
Russ Combs [Thu, 2 Jul 2015 16:27:56 +0000 (12:27 -0400)]
add inspector packet filtering before eval
huica [Thu, 2 Jul 2015 15:48:12 +0000 (11:48 -0400)]
Merge branch 'master' of ssh://huica@chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into fileclass2
Russ Combs [Thu, 2 Jul 2015 15:28:05 +0000 (11:28 -0400)]
fix mime decoding
huica [Thu, 2 Jul 2015 13:31:53 +0000 (09:31 -0400)]
Merge branch 'master' of
ssh://huica@chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into
fileclass2
Conflicts:
src/file_api/file_service.cc
src/file_api/file_stats.cc
src/file_api/libs/file_identifier.h
Russ Combs [Thu, 2 Jul 2015 02:10:37 +0000 (22:10 -0400)]
fix decode sizes
Russ Combs [Wed, 1 Jul 2015 23:10:15 +0000 (19:10 -0400)]
add sip lib into the mix
Russ Combs [Wed, 1 Jul 2015 22:01:18 +0000 (18:01 -0400)]
Squashed commit of the following:
commit
510940569cf8f66668e7265ee004c7fa4127ee00
Author: Russ Combs <rucombs@cisco.com>
Date: Thu Jun 25 23:33:05 2015 -0400
fixed duplicate patterns in file_magic.lua
warn about rules with no fast pattern
run fast patterns according to packet type
tweak shutdown output
add slow search count; match alert service ports
binder sets service from gadget if not set
allow abbreviated rule headers
split file / user protos
eliminate need for MAX_PROTOCOL_ORDINAL; vectorize sopg_table_t
warn if file rule has no file_data fp
add legacy mode warning
split raw vs cooked counts
limit detection of service file data
default to not inspect stream inserts
valgrind cleanup for smtp and misc
fix up mail leaks
fix cmake build on linux w/o asciidoc
Russ Combs [Wed, 1 Jul 2015 21:58:08 +0000 (17:58 -0400)]
fix dns inspector type
Russ Combs [Wed, 1 Jul 2015 21:32:06 +0000 (17:32 -0400)]
fix cmake build
Russ Combs [Wed, 1 Jul 2015 21:23:57 +0000 (17:23 -0400)]
compiler cleanup
huica [Wed, 1 Jul 2015 21:08:17 +0000 (17:08 -0400)]
Merge branch 'master' of ssh://huica@chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into fileclass2
Russ Combs [Wed, 1 Jul 2015 21:01:22 +0000 (17:01 -0400)]
build 159
Russ Combs [Wed, 1 Jul 2015 20:57:38 +0000 (16:57 -0400)]
Squashed commit of the following:
commit
4666c3666bb94dee5404f584fb55e69927a35c6e
Author: Bhagyashree Bantwal <bbantwal@cisco.com>
Date: Wed Jul 1 16:39:49 2015 -0400
sip inspector
huica [Wed, 1 Jul 2015 18:59:48 +0000 (14:59 -0400)]
Merge branch 'master' of ssh://huica@chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into fileclass2
Russ Combs [Wed, 1 Jul 2015 17:40:00 +0000 (13:40 -0400)]
Squashed commit of the following:
commit
2013351aa4e456f3bd910dcf08ba7289b6fa9b45
Author: Tom Peters <thopeter@cisco.com>
Date: Tue Jun 30 14:57:43 2015 -0400
File processing complete
commit
be3c57506fe6e654da94e962150a7114ac99ec56
Author: Tom Peters <thopeter@cisco.com>
Date: Fri Jun 26 13:55:35 2015 -0400
File processing stage 2 - MIME but not unexpected close processing
huica [Tue, 30 Jun 2015 17:31:25 +0000 (13:31 -0400)]
code update based on comments
huica [Fri, 26 Jun 2015 19:14:22 +0000 (15:14 -0400)]
code clean up
huica [Fri, 26 Jun 2015 19:06:21 +0000 (15:06 -0400)]
Fixed warnings
huica [Fri, 26 Jun 2015 15:31:44 +0000 (11:31 -0400)]
valgrind fix
huica [Thu, 25 Jun 2015 21:32:59 +0000 (17:32 -0400)]
update file id
huica [Thu, 25 Jun 2015 19:51:42 +0000 (15:51 -0400)]
remove all file verdict stuff
huica [Thu, 25 Jun 2015 19:48:35 +0000 (15:48 -0400)]
Merge branch 'master' of ssh://huica@chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into fileclass2
Russ Combs [Thu, 25 Jun 2015 16:16:08 +0000 (12:16 -0400)]
backout raw packet optimization for now
huica [Thu, 25 Jun 2015 13:25:31 +0000 (09:25 -0400)]
Merge branch 'master' of ssh://huica@chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into fileclass2
huica [Thu, 25 Jun 2015 13:25:23 +0000 (09:25 -0400)]
file class
Russ Combs [Thu, 25 Jun 2015 12:29:48 +0000 (08:29 -0400)]
Squashed commit of the following:
commit
8d98226a3ae26ce92fbbdc1a93eb04f5fca838d2
Author: Tom Peters <thopeter@cisco.com>
Date: Wed Jun 24 11:35:10 2015 -0400
File processing stage 1 - no MIME
Russ Combs [Thu, 25 Jun 2015 12:19:46 +0000 (08:19 -0400)]
Squashed commit of the following:
commit
50f7258a3f0fa9c2561fa0322fd20cca239982b9
Author: Russ Combs <rucombs@cisco.com>
Date: Wed Jun 17 14:13:12 2015 -0400
refactoring port group init and start up output
standardize / generalize fp buffers
dont search raw packets unless necessary
add log_hext.width
tweak style guide
fix hosts table parsing
eliminate g_alt_data; refactor mpse calls; add stats for mpse calls
convert rtn/otn proto from eth/ip proto to protocol ref
convert ips_ip_proto to plugin
added svc_anyany port group for alert services
rename sftarget_protocol_reference.* to snort_protocols.*
get alert service rules basically working
Russ Combs [Mon, 22 Jun 2015 15:45:56 +0000 (11:45 -0400)]
Squashed commit of the following:
commit
6763e931ecd25c3e7b68fec434f340919cb58169
Author: huica <huica@cisco.com>
Date: Mon Jun 22 08:27:12 2015 -0400
replace packet pointer with flow
Russ Combs [Mon, 22 Jun 2015 11:11:59 +0000 (07:11 -0400)]
Squashed commit of the following:
commit
4a1634abbe8a08ad62384edf76d6c71549f00a93
Author: Tom Peters <thopeter@cisco.com>
Date: Thu Jun 18 17:30:00 2015 -0400
first step toward flow depth
Russ Combs [Fri, 19 Jun 2015 21:04:55 +0000 (17:04 -0400)]
build 158
Russ Combs [Wed, 17 Jun 2015 19:12:33 +0000 (15:12 -0400)]
Squashed commit of the following:
commit
a0384e473768fac2ddc09d1e20a11ba3cac194cb
Author: Russ Combs <rucombs@cisco.com>
Date: Tue Jun 16 17:41:02 2015 -0400
cleanup cache config
Russ Combs [Wed, 17 Jun 2015 12:06:49 +0000 (08:06 -0400)]
Squashed commit of the following:
commit
24647b3ee562d18ac38a6ed8f46ca07eb9ce9edb
Author: Tom Peters <thopeter@cisco.com>
Date: Mon Jun 15 15:32:50 2015 -0400
white space after chunk length
Russ Combs [Tue, 16 Jun 2015 15:21:12 +0000 (11:21 -0400)]
Squashed commit of the following:
commit
9305b4efbfef9657155bb19accf09fcfa64d4878
Author: Bhagyashree Bantwal <bbantwal@cisco.com>
Date: Tue Jun 16 11:07:24 2015 -0400
ssl assertion change
Russ Combs [Tue, 16 Jun 2015 13:47:03 +0000 (09:47 -0400)]
Squashed commit of the following:
commit
2d448adbcb476c2d7e80ca6aafc0dbcf21165633
Author: Russ Combs <rucombs@cisco.com>
Date: Thu Jun 11 15:24:32 2015 -0400
refactor of fpcreate
refactor sfportobject into ports/*
delete flowbits_size, refactor bitop foo
rename PortList to PortBitSet etc. to avoid confusion
fix flowbit group
Russ Combs [Fri, 12 Jun 2015 16:18:16 +0000 (12:18 -0400)]
Squashed commit of the following:
commit
7e0e4e1ef73e850d46d333e665ac91829554a0e5
Author: Tom Peters <thopeter@cisco.com>
Date: Wed Jun 3 13:48:43 2015 -0400
NHI Updates
Russ Combs [Thu, 11 Jun 2015 19:56:29 +0000 (15:56 -0400)]
build 157
Russ Combs [Thu, 11 Jun 2015 19:27:40 +0000 (15:27 -0400)]
Squashed commit of the following:
commit
f0852f3da95431b5706963c66463a05b529dbdaa
Author: Bhagyashree Bantwal <bbantwal@cisco.com>
Date: Mon Jun 8 10:30:38 2015 -0400
port ssl preprocessor from snort
Russ Combs [Wed, 10 Jun 2015 22:56:37 +0000 (18:56 -0400)]
Squashed commit of the following:
commit
b8189b26b8a153c6be4e75a6e48c74c4b4a12c86
Author: Russ Combs <rucombs@cisco.com>
Date: Fri Jun 5 19:37:15 2015 -0400
update active module
drop rules drop a single packet, block rules blacklist flow
add reset action for completeness
remove daq patch cruft
fixup rule lists
fixup fast logging
updated snort2lua
Russ Combs [Wed, 10 Jun 2015 21:17:45 +0000 (17:17 -0400)]
only call splitter finish is scan was called
Russ Combs [Thu, 4 Jun 2015 21:25:39 +0000 (17:25 -0400)]
oops - forgot to clear the flush policy
Russ Combs [Thu, 4 Jun 2015 15:35:22 +0000 (11:35 -0400)]
build 156, update change log, fix paf abort handling
Russ Combs [Wed, 3 Jun 2015 21:22:21 +0000 (17:22 -0400)]
new_http_inspect switch to bitset for event tracking
Russ Combs [Wed, 3 Jun 2015 20:39:02 +0000 (16:39 -0400)]
stream sequencing fixes
Russ Combs [Tue, 2 Jun 2015 16:55:56 +0000 (12:55 -0400)]
fix mime decoding
Russ Combs [Sun, 31 May 2015 13:55:45 +0000 (09:55 -0400)]
add plugin load warnings, update manual
Russ Combs [Sat, 30 May 2015 15:12:23 +0000 (11:12 -0400)]
build 155; file fixup
Russ Combs [Sat, 30 May 2015 13:19:32 +0000 (09:19 -0400)]
update usage from blog
Russ Combs [Fri, 29 May 2015 14:55:24 +0000 (10:55 -0400)]
actually add file magic
Russ Combs [Fri, 29 May 2015 14:46:51 +0000 (10:46 -0400)]
add file magic lua
Russ Combs [Fri, 29 May 2015 11:56:10 +0000 (07:56 -0400)]
xcode analyzer cleanup
Russ Combs [Thu, 28 May 2015 14:04:57 +0000 (10:04 -0400)]
update change log, remove debug foo
Russ Combs [Thu, 28 May 2015 13:12:29 +0000 (09:12 -0400)]
build 154
Russ Combs [Wed, 27 May 2015 21:05:09 +0000 (17:05 -0400)]
fixup some borked copyrights
Russ Combs [Wed, 27 May 2015 20:46:03 +0000 (16:46 -0400)]
commit
3a05fa04a9716d0365e4b00752bbcb46458b847f
Author: huica <huica@cisco.com>
Date: Wed May 27 15:43:44 2015 -0400
file capture merge
Russ Combs [Wed, 27 May 2015 19:08:32 +0000 (15:08 -0400)]
Squashed commit of the following:
commit
4eac8870ac2220666d8da50dd3531143bebdf0f9
Author: Russ Combs <rucombs@cisco.com>
Date: Wed May 27 15:06:52 2015 -0400
-- stream_tcp reassembles payload only
-- remove obsolete REG_TEST logging
-- change max_dsize to const
-- refactor encode_format*()
-- rewrite alert_csv with default suitable for reg tests and debugging
-- dump 20 hex bytes per line instead of 16
-- fix final_flush packet
-- add raw mode hext DAQ and logger; fix dns inspector typo for tcp checks
-- document raw hext mode
-- cleanup flush flags vs dir
-- add alert_csv.separator, delete alert_test
-- tweak log config; rename daq/log user to hext
-- cleanup logging
-- stream_tcp refactoring and cleanup
Russ Combs [Fri, 22 May 2015 15:58:03 +0000 (11:58 -0400)]
tom: new_http_inspect parsing and event handling updates
Russ Combs [Fri, 22 May 2015 13:35:25 +0000 (09:35 -0400)]
build 153
Russ Combs [Tue, 19 May 2015 15:10:48 +0000 (11:10 -0400)]
tom: new_http_inspect start line parsing updates
Russ Combs [Mon, 18 May 2015 16:06:10 +0000 (12:06 -0400)]
Russ
-- use buckets for user seglist
-- add -L u2
-- fix u2 to output data only packets
Russ Combs [Sat, 16 May 2015 01:19:58 +0000 (21:19 -0400)]
russ:
-- added socket codec in extras
-- added DAQs for socket, user, and file in extras
-- added stream_user for use with proxy type traffic from socket and user
DAQs
-- added stream_file for use with file DAQ for file type, signature, and
inspection
-- refactor Session, StreamApi, and PAF
-- pulled DAQ README into manual
-- fix double loading of stream plugins
-- fix cmake build issues
Russ Combs [Fri, 15 May 2015 14:52:42 +0000 (10:52 -0400)]
build 152
Russ Combs [Fri, 15 May 2015 14:51:46 +0000 (10:51 -0400)]
carter - fixed config error for inspection of rebuilt packets
Russ Combs [Fri, 15 May 2015 14:48:11 +0000 (10:48 -0400)]
bhagya - ported smtp preprocessor from Snort
Russ Combs [Wed, 13 May 2015 11:50:34 +0000 (07:50 -0400)]
tom: static analysis fix for new_http_inspect
Russ Combs [Fri, 8 May 2015 11:46:18 +0000 (07:46 -0400)]
bump build