]> git.ipfire.org Git - thirdparty/snort3.git/log
thirdparty/snort3.git
10 years agotom: new_http_inspect aborts on obvious non-HTTP ttraffic
Russ Combs [Fri, 8 May 2015 11:27:55 +0000 (07:27 -0400)] 
tom: new_http_inspect aborts on obvious non-HTTP ttraffic

10 years agotom:
Russ Combs [Thu, 7 May 2015 15:05:21 +0000 (11:05 -0400)] 
tom:
    eliminate chunk aggregation from reassemble()
-- static buffer for body sections
-- update during chunk reassembly mods
-- new chunk splitting is working
-- skip on chunk scan side
-- reassemble side chunk skip
-- complete space optimization changes

10 years agodoc tweaks
Russ Combs [Sat, 2 May 2015 00:48:18 +0000 (20:48 -0400)] 
doc tweaks

10 years agoruss:
Russ Combs [Thu, 30 Apr 2015 20:30:25 +0000 (16:30 -0400)] 
russ:
-- fix http inspect use of decompress_swf and decompress_pdf
-- ensure that autotools and cmake install the same files in the same dirs
-- add doc/online_manual.sh to generate an all-in-1 html manual with
   embedded images

10 years agofix packaging foo
Russ Combs [Thu, 30 Apr 2015 02:06:04 +0000 (22:06 -0400)] 
fix packaging foo

10 years agoforgot change log
Russ Combs [Thu, 30 Apr 2015 00:44:26 +0000 (20:44 -0400)] 
forgot change log

10 years agofixed xcode static analysis issues
Russ Combs [Thu, 30 Apr 2015 00:43:52 +0000 (20:43 -0400)] 
fixed xcode static analysis issues

10 years agoruss:
Russ Combs [Wed, 29 Apr 2015 21:41:24 +0000 (17:41 -0400)] 
russ:
add packet processing to manual
update default manuals
update base version to 297-177

10 years agoruss - cleanup some comments; build 150
Russ Combs [Wed, 29 Apr 2015 20:54:07 +0000 (16:54 -0400)] 
russ - cleanup some comments; build 150

10 years agoSquashed commit of the following:
Russ Combs [Wed, 29 Apr 2015 20:03:12 +0000 (16:03 -0400)] 
Squashed commit of the following:

russ:
-- ensure unknown sources are analyzed
-- change daq.var to daq.vars to support multiple params, reported by Sancho Panza
-- fixed urg option
-- fix hi mpse search
-- additional refactoring and cleanup

10 years agobhagya - pop and imap inspectors ported
Russ Combs [Wed, 29 Apr 2015 17:36:48 +0000 (13:36 -0400)] 
bhagya - pop and imap inspectors ported

10 years agofixed build issue with exta/; bump build to 149
Russ Combs [Tue, 28 Apr 2015 19:07:25 +0000 (15:07 -0400)] 
fixed build issue with exta/; bump build to 149

10 years agobuild 148
Russ Combs [Tue, 28 Apr 2015 16:18:22 +0000 (12:18 -0400)] 
build 148

10 years agodont just validate when no -r or -i for non-pcap DAQ; reported by Sancho Panza
Russ Combs [Tue, 28 Apr 2015 15:51:58 +0000 (11:51 -0400)] 
dont just validate when no -r or -i for non-pcap DAQ; reported by Sancho Panza

10 years agoruss - refactor of snort and snort_config modules
Russ Combs [Tue, 28 Apr 2015 15:20:07 +0000 (11:20 -0400)] 
russ - refactor of snort and snort_config modules

10 years agohui - file type ID updates and refactoring
Russ Combs [Tue, 28 Apr 2015 14:46:41 +0000 (10:46 -0400)] 
hui - file type ID updates and refactoring

10 years agoadded publish-subscribe handling of data events and data_log example
Russ Combs [Mon, 27 Apr 2015 19:13:56 +0000 (15:13 -0400)] 
added publish-subscribe handling of data events and data_log example

10 years agobuild 147
Russ Combs [Thu, 23 Apr 2015 16:53:27 +0000 (12:53 -0400)] 
build 147

10 years agochange PT_DATA to IT_PASSIVE; supports named instances, reload, and consumers
Russ Combs [Wed, 22 Apr 2015 21:48:52 +0000 (17:48 -0400)] 
change PT_DATA to IT_PASSIVE; supports named instances, reload, and consumers

10 years agoadded snort_manual.text; add flow pointer to splitter finish
Russ Combs [Thu, 16 Apr 2015 19:01:09 +0000 (15:01 -0400)] 
added snort_manual.text; add flow pointer to splitter finish

10 years agobuild 145
Russ Combs [Fri, 10 Apr 2015 13:10:19 +0000 (09:10 -0400)] 
build 145

10 years agonhttp clear() and related changes
Russ Combs [Fri, 10 Apr 2015 12:44:00 +0000 (08:44 -0400)] 
nhttp clear() and related changes

10 years agoensure inspector::clear called only after eval
Russ Combs [Fri, 10 Apr 2015 12:38:44 +0000 (08:38 -0400)] 
ensure inspector::clear called only after eval

10 years agostream and splitter changes for new http - change log
Russ Combs [Tue, 7 Apr 2015 21:06:03 +0000 (17:06 -0400)] 
stream and splitter changes for new http - change log

10 years agostream and splitter changes for new http
Russ Combs [Tue, 7 Apr 2015 21:05:28 +0000 (17:05 -0400)] 
stream and splitter changes for new http

10 years agonew http refactoring and cleanup
Russ Combs [Tue, 7 Apr 2015 18:43:58 +0000 (14:43 -0400)] 
new http refactoring and cleanup

10 years agomerge in new http changes: events from splitter plus additional refactoring and cleanup
Russ Combs [Wed, 1 Apr 2015 18:06:59 +0000 (14:06 -0400)] 
merge in new http changes: events from splitter plus additional refactoring and cleanup

10 years agofix dns assertion; remove unused variables
Russ Combs [Wed, 1 Apr 2015 17:52:53 +0000 (13:52 -0400)] 
fix dns assertion; remove unused variables

10 years agoupdated autotools generation of api_options.h; bumped build to 144
Russ Combs [Tue, 31 Mar 2015 13:03:36 +0000 (09:03 -0400)] 
updated autotools generation of api_options.h; bumped build to 144

10 years agoported dns preprocessor
Russ Combs [Mon, 30 Mar 2015 16:14:59 +0000 (12:14 -0400)] 
ported dns preprocessor

10 years agobuild 143 final
Russ Combs [Thu, 26 Mar 2015 16:34:48 +0000 (12:34 -0400)] 
build 143 final

10 years agomissed ssh updates
russ [Thu, 26 Mar 2015 16:32:49 +0000 (12:32 -0400)] 
missed ssh updates

10 years agoadded ssh inspector
Russ Combs [Thu, 26 Mar 2015 15:26:37 +0000 (11:26 -0400)] 
added ssh inspector

10 years agoadd duplicate service warning; set service ahead of session
Russ Combs [Thu, 26 Mar 2015 12:07:28 +0000 (08:07 -0400)] 
add duplicate service warning; set service ahead of session

10 years agoapply service from hosts when inspector already bound to flow
Russ Combs [Wed, 25 Mar 2015 21:25:29 +0000 (17:25 -0400)] 
apply service from hosts when inspector already bound to flow

10 years agoensure direction and service are set regardless of flow state
Russ Combs [Wed, 25 Mar 2015 19:02:20 +0000 (15:02 -0400)] 
ensure direction and service are set regardless of flow state

10 years agoenable active for react / reject only if used in configuration
Russ Combs [Sat, 21 Mar 2015 12:41:30 +0000 (08:41 -0400)] 
enable active for react / reject only if used in configuration

10 years agofixed use of bound ip and tcp policy if not set in hosts
Russ Combs [Fri, 20 Mar 2015 21:06:53 +0000 (17:06 -0400)] 
fixed use of bound ip and tcp policy if not set in hosts

10 years agoeliminate dedicated nhttp chunk buffer; minor nhttp cleanup in StreamSplitter
Russ Combs [Thu, 19 Mar 2015 18:29:16 +0000 (14:29 -0400)] 
eliminate dedicated nhttp chunk buffer; minor nhttp cleanup in StreamSplitter

10 years agofixed host lookup issue
Russ Combs [Thu, 19 Mar 2015 13:08:24 +0000 (09:08 -0400)] 
fixed host lookup issue

10 years agomisc snort2lua updates
russ [Wed, 18 Mar 2015 22:55:56 +0000 (18:55 -0400)] 
misc snort2lua updates

10 years agoapply module defaults; bump build to 142
Russ Combs [Wed, 18 Mar 2015 17:32:10 +0000 (13:32 -0400)] 
apply module defaults; bump build to 142

10 years agofix static analysis issues reported by xcode
Russ Combs [Wed, 18 Mar 2015 16:38:43 +0000 (12:38 -0400)] 
fix static analysis issues reported by xcode

10 years agoall parse warnings are optional; fix ip and tcp policy defines
Russ Combs [Mon, 16 Mar 2015 17:46:52 +0000 (13:46 -0400)] 
all parse warnings are optional; fix ip and tcp policy defines

10 years agofixed ip and icmp flow init of client/server ip
Russ Combs [Mon, 16 Mar 2015 15:37:16 +0000 (11:37 -0400)] 
fixed ip and icmp flow init of client/server ip

10 years agofix usage typo
Russ Combs [Thu, 12 Mar 2015 12:46:08 +0000 (08:46 -0400)] 
fix usage typo

10 years agoadded logging examples to usage
Russ Combs [Thu, 12 Mar 2015 12:31:41 +0000 (08:31 -0400)] 
added logging examples to usage

10 years agoadded build foo for lzma, refactored configure.ac, bumped build #
Russ Combs [Wed, 11 Mar 2015 16:42:18 +0000 (12:42 -0400)] 
added build foo for lzma, refactored configure.ac, bumped build #

10 years agofixed generation of api_options.h
Russ Combs [Wed, 11 Mar 2015 00:33:44 +0000 (20:33 -0400)] 
fixed generation of api_options.h

10 years agoupdate change log
Russ Combs [Wed, 11 Mar 2015 00:01:05 +0000 (20:01 -0400)] 
update change log

10 years agoenhancements for checking compatibility of external plugins
Russ Combs [Wed, 11 Mar 2015 00:00:09 +0000 (20:00 -0400)] 
enhancements for checking compatibility of external plugins

10 years agoadded doc/usage.txt
Russ Combs [Mon, 9 Mar 2015 15:20:57 +0000 (11:20 -0400)] 
added doc/usage.txt

10 years agofix typo
Russ Combs [Fri, 27 Feb 2015 18:50:46 +0000 (13:50 -0500)] 
fix typo

10 years agofix make distcheck cleanup for extras
Russ Combs [Fri, 27 Feb 2015 18:45:52 +0000 (13:45 -0500)] 
fix make distcheck cleanup for extras

10 years agoupdated documentation
Russ Combs [Fri, 27 Feb 2015 18:15:55 +0000 (13:15 -0500)] 
updated documentation

10 years agouncrustify, see crusty.cfg
Russ Combs [Fri, 27 Feb 2015 14:54:24 +0000 (09:54 -0500)] 
uncrustify, see crusty.cfg

10 years agofixed change log date
Russ Combs [Thu, 26 Feb 2015 16:59:15 +0000 (11:59 -0500)] 
fixed change log date

10 years agobump build #
Russ Combs [Thu, 26 Feb 2015 16:41:41 +0000 (11:41 -0500)] 
bump build #

10 years agoadditional http_inspect cleanup
Russ Combs [Wed, 25 Feb 2015 14:43:19 +0000 (09:43 -0500)] 
additional http_inspect cleanup

10 years agodocumented gotcha regarding rule variable definitions in Lua
Russ Combs [Wed, 25 Feb 2015 14:39:29 +0000 (09:39 -0500)] 
documented gotcha regarding rule variable definitions in Lua

10 years agominor changes related to comments and a reg test problem
Tom Peters [Tue, 24 Feb 2015 22:25:58 +0000 (17:25 -0500)] 
minor changes related to comments and a reg test problem

10 years agominor changes to http
Tom Peters [Tue, 24 Feb 2015 18:15:20 +0000 (13:15 -0500)] 
minor changes to http

10 years agostrip unneeded mstring.h includes
Russ Combs [Sat, 21 Feb 2015 19:07:38 +0000 (14:07 -0500)] 
strip unneeded mstring.h includes

10 years agorefactor file_decomp (missed files)
Russ Combs [Sat, 21 Feb 2015 18:54:43 +0000 (13:54 -0500)] 
refactor file_decomp (missed files)

10 years agorefactor file_decomp
Russ Combs [Sat, 21 Feb 2015 18:53:58 +0000 (13:53 -0500)] 
refactor file_decomp

10 years agosync 297 http xff, swf, and pdf updates
Russ Combs [Sat, 21 Feb 2015 17:42:55 +0000 (12:42 -0500)] 
sync 297 http xff, swf, and pdf updates

10 years agobump build to 138
Russ Combs [Fri, 20 Feb 2015 20:34:12 +0000 (15:34 -0500)] 
bump build to 138

10 years agosync ftp with 297; replace stream event callbacks with FlowData virtuals
Russ Combs [Thu, 12 Feb 2015 21:28:36 +0000 (16:28 -0500)] 
sync ftp with 297; replace stream event callbacks with FlowData virtuals

10 years agobump build to 137
Russ Combs [Thu, 12 Feb 2015 15:58:07 +0000 (10:58 -0500)] 
bump build to 137

10 years agoremove deleted files from ignore set
Russ Combs [Tue, 10 Feb 2015 17:18:23 +0000 (12:18 -0500)] 
remove deleted files from ignore set

10 years agoupdated manual from blog posts and emails
Russ Combs [Tue, 10 Feb 2015 14:33:55 +0000 (09:33 -0500)] 
updated manual from blog posts and emails

10 years agofix merge error
Russ Combs [Mon, 9 Feb 2015 20:31:08 +0000 (15:31 -0500)] 
fix merge error

10 years agonormalization fixups, refactoring, renaming
Russ Combs [Mon, 9 Feb 2015 20:25:54 +0000 (15:25 -0500)] 
normalization fixups, refactoring, renaming

10 years agofixed icmp4 encoding
Russ Combs [Mon, 9 Feb 2015 19:39:58 +0000 (14:39 -0500)] 
fixed icmp4 encoding

10 years agorefactored codec methods
Russ Combs [Mon, 9 Feb 2015 17:40:27 +0000 (12:40 -0500)] 
refactored codec methods

10 years ago297 sync of active and codecs
Russ Combs [Mon, 9 Feb 2015 14:27:30 +0000 (09:27 -0500)] 
297 sync of active and codecs

10 years agobump build #
Russ Combs [Thu, 5 Feb 2015 16:34:42 +0000 (11:34 -0500)] 
bump build #

10 years agofix up encoders
russ [Thu, 5 Feb 2015 11:54:10 +0000 (06:54 -0500)] 
fix up encoders

10 years agofix typo
russ [Wed, 4 Feb 2015 22:07:52 +0000 (17:07 -0500)] 
fix typo

10 years agosync stream with 297
Russ Combs [Wed, 4 Feb 2015 22:02:03 +0000 (17:02 -0500)] 
sync stream with 297

10 years agofix encoder check for ip6 extensions
Russ Combs [Wed, 4 Feb 2015 21:59:59 +0000 (16:59 -0500)] 
fix encoder check for ip6 extensions

10 years agopolicy mode default is based on run mode
rcombs [Wed, 4 Feb 2015 14:27:40 +0000 (09:27 -0500)] 
policy mode default is based on run mode

10 years agosync normalize with 297
Russ Combs [Wed, 4 Feb 2015 13:54:31 +0000 (08:54 -0500)] 
sync normalize with 297

10 years agobumped build, updated default snort manuals
Russ Combs [Thu, 29 Jan 2015 17:09:56 +0000 (12:09 -0500)] 
bumped build, updated default snort manuals

10 years agofix freebsd build error
Russ Combs [Thu, 29 Jan 2015 13:53:07 +0000 (08:53 -0500)] 
fix freebsd build error

10 years agofix default hi profile name
Russ Combs [Wed, 28 Jan 2015 18:17:22 +0000 (13:17 -0500)] 
fix default hi profile name

10 years agodeleted double define
Russ Combs [Tue, 27 Jan 2015 00:10:09 +0000 (19:10 -0500)] 
deleted double define

10 years agofix merge
Russ Combs [Mon, 26 Jan 2015 23:01:29 +0000 (18:01 -0500)] 
fix merge

10 years agobump build
Russ Combs [Mon, 26 Jan 2015 22:36:50 +0000 (17:36 -0500)] 
bump build

10 years agosync Mpse to 297, add SearchTool
Russ Combs [Mon, 26 Jan 2015 22:36:17 +0000 (17:36 -0500)] 
sync Mpse to 297, add SearchTool

10 years agoupdate change log
Russ Combs [Mon, 26 Jan 2015 21:43:37 +0000 (16:43 -0500)] 
update change log

10 years ago297 sync for tag, hash, perfmon, etc.
Russ Combs [Mon, 26 Jan 2015 20:02:11 +0000 (15:02 -0500)] 
297 sync for tag, hash, perfmon, etc.

10 years agofix year
Russ Combs [Mon, 26 Jan 2015 17:06:25 +0000 (12:06 -0500)] 
fix year

10 years agofix typo
Russ Combs [Fri, 23 Jan 2015 00:52:55 +0000 (19:52 -0500)] 
fix typo

10 years agosnort2lua default port bindings
Russ Combs [Thu, 22 Jan 2015 21:55:46 +0000 (16:55 -0500)] 
snort2lua default port bindings

10 years agoadd md5, sha256, and sha512 rule options based on snort 2.x protected_content
Russ Combs [Thu, 22 Jan 2015 15:06:59 +0000 (10:06 -0500)] 
add md5, sha256, and sha512 rule options based on snort 2.x protected_content

10 years agoupdate change log
Russ Combs [Tue, 20 Jan 2015 21:36:37 +0000 (16:36 -0500)] 
update change log

10 years agoupdate build
Russ Combs [Tue, 20 Jan 2015 21:27:17 +0000 (16:27 -0500)] 
update build

10 years agofixes for LFS
Russ Combs [Tue, 20 Jan 2015 15:05:49 +0000 (10:05 -0500)] 
fixes for LFS

10 years agoreformat comment
Russ Combs [Thu, 15 Jan 2015 23:59:42 +0000 (18:59 -0500)] 
reformat comment