]> git.ipfire.org Git - thirdparty/snort3.git/log
thirdparty/snort3.git
10 years agochange log
rcombs [Thu, 13 Nov 2014 21:36:40 +0000 (16:36 -0500)] 
change log

10 years agoMerge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs
rcombs [Thu, 13 Nov 2014 21:33:35 +0000 (16:33 -0500)] 
Merge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs

10 years agolegacy paf_max implementation
rcombs [Thu, 13 Nov 2014 21:33:21 +0000 (16:33 -0500)] 
legacy paf_max implementation

10 years agotweaking frag. FragStart had the wrong start point
Josh [Thu, 13 Nov 2014 18:06:16 +0000 (12:06 -0600)] 
tweaking frag.  FragStart had the wrong start point

10 years agoupdating ZERO_FRAG alert - Codecs still consider a Zero Frag a valid packet
Josh [Thu, 13 Nov 2014 17:51:58 +0000 (11:51 -0600)] 
updating ZERO_FRAG alert - Codecs still consider a Zero Frag a valid packet

10 years agoMerge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort...
Josh [Thu, 13 Nov 2014 14:44:39 +0000 (08:44 -0600)] 
Merge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into codecs

10 years agoMerge branch 'codecs' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/jrosenba/codecs...
Josh [Thu, 13 Nov 2014 14:44:12 +0000 (08:44 -0600)] 
Merge branch 'codecs' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/jrosenba/codecs into codecs

10 years agoMerge branch 'master' of /nfs/home/rucombs/Snort++
Tom Peters [Thu, 13 Nov 2014 14:40:18 +0000 (09:40 -0500)] 
Merge branch 'master' of /nfs/home/rucombs/Snort++

10 years agoMerge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs
rcombs [Thu, 13 Nov 2014 00:54:44 +0000 (19:54 -0500)] 
Merge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs

10 years agofixing byte_jump
Josh [Thu, 13 Nov 2014 00:38:36 +0000 (18:38 -0600)] 
fixing byte_jump

10 years agosuspend active when purging caches
rcombs [Wed, 12 Nov 2014 22:51:38 +0000 (17:51 -0500)] 
suspend active when purging caches

10 years agochange log
rcombs [Wed, 12 Nov 2014 21:56:57 +0000 (16:56 -0500)] 
change log

10 years agoMerge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs
rcombs [Wed, 12 Nov 2014 21:54:47 +0000 (16:54 -0500)] 
Merge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs

10 years agofixing bit and little endian mixup in byte_* ips_options
Josh [Wed, 12 Nov 2014 21:53:48 +0000 (15:53 -0600)] 
fixing bit and little endian mixup in byte_* ips_options

10 years agofixed inspectors reinit
rcombs [Wed, 12 Nov 2014 20:48:18 +0000 (15:48 -0500)] 
fixed inspectors reinit

10 years agoMerge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort...
Josh [Wed, 12 Nov 2014 19:03:35 +0000 (13:03 -0600)] 
Merge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into codecs

10 years agoupdating Frags handling of IP options and copying IP headers
Josh [Wed, 12 Nov 2014 19:02:40 +0000 (13:02 -0600)] 
updating Frags handling of IP options and copying IP headers

10 years agoMerge branch 'master' of /nfs/home/rucombs/Snort++
Tom Peters [Wed, 12 Nov 2014 18:37:34 +0000 (13:37 -0500)] 
Merge branch 'master' of /nfs/home/rucombs/Snort++

10 years agoflush available data for atom splitter
Russ Combs [Wed, 12 Nov 2014 18:06:42 +0000 (13:06 -0500)] 
flush available data for atom splitter

10 years agoMerge branch 'master' of /nfs/home/rucombs/Snort++
Tom Peters [Wed, 12 Nov 2014 15:48:04 +0000 (10:48 -0500)] 
Merge branch 'master' of /nfs/home/rucombs/Snort++

10 years agoMerge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort...
Josh [Wed, 12 Nov 2014 15:09:38 +0000 (09:09 -0600)] 
Merge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into codecs

10 years agoMerge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/jrosenba/codecs...
Josh [Wed, 12 Nov 2014 15:09:35 +0000 (09:09 -0600)] 
Merge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/jrosenba/codecs into codecs

10 years agofixed byte_test endian
Russ Combs [Wed, 12 Nov 2014 12:33:07 +0000 (07:33 -0500)] 
fixed byte_test endian

10 years agofixed byte_test compare value
Russ Combs [Wed, 12 Nov 2014 12:10:46 +0000 (07:10 -0500)] 
fixed byte_test compare value

10 years agochange log
rcombs [Tue, 11 Nov 2014 22:51:13 +0000 (17:51 -0500)] 
change log

10 years agoupdating ip_proto_next for fragmented packet
Josh [Tue, 11 Nov 2014 22:35:37 +0000 (16:35 -0600)] 
updating ip_proto_next for fragmented packet

10 years agofixed white-/black-list enforcement
rcombs [Tue, 11 Nov 2014 21:24:44 +0000 (16:24 -0500)] 
fixed white-/black-list enforcement

10 years agoMerge branch 'master' of /nfs/home/rucombs/Snort++
Tom Peters [Tue, 11 Nov 2014 19:23:49 +0000 (14:23 -0500)] 
Merge branch 'master' of /nfs/home/rucombs/Snort++

10 years agofixed legacy hi scanner events
rcombs [Tue, 11 Nov 2014 18:33:15 +0000 (13:33 -0500)] 
fixed legacy hi scanner events

10 years agosuppress repeated 129:20 on same session
Russ Combs [Tue, 11 Nov 2014 17:31:56 +0000 (12:31 -0500)] 
suppress repeated 129:20 on same session

10 years agoMerge branch 'master' of /nfs/home/rucombs/Snort++
Tom Peters [Tue, 11 Nov 2014 15:20:45 +0000 (10:20 -0500)] 
Merge branch 'master' of /nfs/home/rucombs/Snort++

10 years agochange log update
Russ Combs [Tue, 11 Nov 2014 11:43:42 +0000 (06:43 -0500)] 
change log update

10 years agoMerge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs
Russ Combs [Tue, 11 Nov 2014 11:41:59 +0000 (06:41 -0500)] 
Merge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs

10 years agofixed Inspector::tterm() calls
Russ Combs [Tue, 11 Nov 2014 11:25:48 +0000 (06:25 -0500)] 
fixed Inspector::tterm() calls

10 years agoSnort2Lua: clearing badbit before using seekg(). Fixing frag3_engine bug
Josh [Mon, 10 Nov 2014 20:22:32 +0000 (14:22 -0600)] 
Snort2Lua:  clearing badbit before using seekg().  Fixing frag3_engine bug

10 years agoMerge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort...
Josh [Mon, 10 Nov 2014 19:22:35 +0000 (13:22 -0600)] 
Merge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into codecs

10 years agoMerge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort...
Josh [Mon, 10 Nov 2014 17:21:58 +0000 (11:21 -0600)] 
Merge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into codecs

10 years agoMerge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/jrosenba/codecs...
Josh [Mon, 10 Nov 2014 17:21:51 +0000 (11:21 -0600)] 
Merge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/jrosenba/codecs into codecs

10 years agoMerge branch 'master' of /nfs/home/rucombs/Snort++
Tom Peters [Mon, 10 Nov 2014 15:26:17 +0000 (10:26 -0500)] 
Merge branch 'master' of /nfs/home/rucombs/Snort++

10 years agopatched around shutdown issue after reload
Russ Combs [Mon, 10 Nov 2014 13:42:11 +0000 (08:42 -0500)] 
patched around shutdown issue after reload

10 years agofixed udp session timeout counting
Russ Combs [Mon, 10 Nov 2014 12:25:49 +0000 (07:25 -0500)] 
fixed udp session timeout counting

10 years agofix flow_con and icmp counts
Russ Combs [Mon, 10 Nov 2014 11:27:40 +0000 (06:27 -0500)] 
fix flow_con and icmp counts

10 years agosupport \xFF style chars in content strings
Russ Combs [Mon, 10 Nov 2014 00:43:13 +0000 (19:43 -0500)] 
support \xFF style chars in content strings

10 years agofixed !content
Russ Combs [Sun, 9 Nov 2014 13:15:58 +0000 (08:15 -0500)] 
fixed !content

10 years agofixed fp_only and non-op range check parsing
Russ Combs [Sun, 9 Nov 2014 12:59:32 +0000 (07:59 -0500)] 
fixed fp_only and non-op range check parsing

10 years agofixed prune count capture
Russ Combs [Sun, 9 Nov 2014 12:02:58 +0000 (07:02 -0500)] 
fixed prune count capture

10 years agoensure fp_offset/length are applied correctly; add printf style escaptes to content...
Russ Combs [Sat, 8 Nov 2014 20:37:02 +0000 (15:37 -0500)] 
ensure fp_offset/length are applied correctly; add printf style escaptes to content strings

10 years ago127
Russ Combs [Sat, 8 Nov 2014 11:06:02 +0000 (06:06 -0500)] 
127

10 years agoMerge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs
Russ Combs [Sat, 8 Nov 2014 10:18:05 +0000 (05:18 -0500)] 
Merge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs

10 years agopcre sticky buffer tweak
Josh [Fri, 7 Nov 2014 22:27:48 +0000 (16:27 -0600)] 
pcre sticky buffer tweak

10 years agorange check fix
Russ Combs [Fri, 7 Nov 2014 22:47:34 +0000 (17:47 -0500)] 
range check fix

10 years ago3.0.0
Russ Combs [Fri, 7 Nov 2014 22:46:34 +0000 (17:46 -0500)] 
3.0.0

10 years agofixed RangeCheck
rcombs [Fri, 7 Nov 2014 22:44:15 +0000 (17:44 -0500)] 
fixed RangeCheck

10 years agoSnort2Lua: updating sticky buffers.
Josh [Fri, 7 Nov 2014 22:15:40 +0000 (16:15 -0600)] 
Snort2Lua: updating sticky buffers.

10 years agoSnort2Lua: fixing frag3 binder
Josh [Fri, 7 Nov 2014 20:17:36 +0000 (14:17 -0600)] 
Snort2Lua: fixing frag3 binder

10 years agoMerge branch 'master' of /nfs/home/rucombs/Snort++
Tom Peters [Fri, 7 Nov 2014 19:48:46 +0000 (14:48 -0500)] 
Merge branch 'master' of /nfs/home/rucombs/Snort++

10 years agodefault non-RFC chars
Tom Peters [Fri, 7 Nov 2014 19:48:27 +0000 (14:48 -0500)] 
default non-RFC chars

10 years agoMerge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs
Russ Combs [Fri, 7 Nov 2014 19:28:13 +0000 (14:28 -0500)] 
Merge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs

10 years agoadded stream_tcp.segs_split
Russ Combs [Fri, 7 Nov 2014 19:26:45 +0000 (14:26 -0500)] 
added stream_tcp.segs_split

10 years agoMerge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort...
Josh [Fri, 7 Nov 2014 16:10:43 +0000 (10:10 -0600)] 
Merge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into codecs

10 years agoSnort2Lua: add pkt_data sticky buffer for pcre and content if no other buffer is...
Josh [Fri, 7 Nov 2014 16:06:52 +0000 (10:06 -0600)] 
Snort2Lua:  add pkt_data sticky buffer for pcre and content if no other buffer is specified

10 years agoadding REG_TEST space after TcpOptions
Josh [Thu, 6 Nov 2014 23:58:41 +0000 (17:58 -0600)] 
adding REG_TEST space after TcpOptions

10 years agoAdding REG_TEST for UDP
Josh [Thu, 6 Nov 2014 23:54:38 +0000 (17:54 -0600)] 
Adding REG_TEST for UDP

10 years agoMerge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs
Russ Combs [Thu, 6 Nov 2014 23:39:36 +0000 (18:39 -0500)] 
Merge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs

10 years agofixed static flush points
rcombs [Thu, 6 Nov 2014 23:37:29 +0000 (18:37 -0500)] 
fixed static flush points

10 years agofixed misformed binder init
rcombs [Thu, 6 Nov 2014 22:25:53 +0000 (17:25 -0500)] 
fixed misformed binder init

10 years agoSnort2Lua fix - correctly parse a variable that does not start with '$'
Josh [Thu, 6 Nov 2014 21:19:33 +0000 (15:19 -0600)] 
Snort2Lua fix - correctly parse a variable that does not start with '$'

10 years agoMerge branch 'codecs' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/jrosenba/codecs...
Josh [Thu, 6 Nov 2014 21:16:30 +0000 (15:16 -0600)] 
Merge branch 'codecs' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/jrosenba/codecs into codecs

10 years agoMerge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort...
Josh [Thu, 6 Nov 2014 20:32:58 +0000 (14:32 -0600)] 
Merge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into codecs

10 years agofixing Codec IPv4 alert and an incorrectly set codec Flag
Josh [Thu, 6 Nov 2014 20:30:24 +0000 (14:30 -0600)] 
fixing Codec IPv4 alert and an incorrectly set codec Flag

10 years agoMerge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort...
Josh [Thu, 6 Nov 2014 20:28:16 +0000 (14:28 -0600)] 
Merge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into codecs

10 years agoregining log_test REG_TEST statement - TCP options printed for reassemble FRAG packet
Josh [Thu, 6 Nov 2014 17:51:03 +0000 (11:51 -0600)] 
regining log_test REG_TEST statement - TCP options printed for reassemble FRAG packet

10 years agofixed stream_ip defaults
rcombs [Thu, 6 Nov 2014 17:39:29 +0000 (12:39 -0500)] 
fixed stream_ip defaults

10 years agofixing Packet's get_next_ip_proto function
Josh [Thu, 6 Nov 2014 17:04:43 +0000 (11:04 -0600)] 
fixing Packet's get_next_ip_proto function

10 years agofixing IPv6 Unordered extension alert for Fragments
Josh [Thu, 6 Nov 2014 16:10:35 +0000 (10:10 -0600)] 
fixing IPv6 Unordered extension alert for Fragments

10 years agoupdating Snort2Lua content keyword. Now parses comma seperated 'content' options
Josh [Thu, 6 Nov 2014 15:56:59 +0000 (09:56 -0600)] 
updating Snort2Lua content keyword. Now parses comma seperated 'content' options

10 years agoIPv6 Frag fixes ... more to come
Josh [Thu, 6 Nov 2014 15:26:28 +0000 (09:26 -0600)] 
IPv6 Frag fixes ... more to come

10 years agoupdate
Russ Combs [Thu, 6 Nov 2014 13:24:32 +0000 (08:24 -0500)] 
update

10 years ago--c2x and --x2c
rcombs [Thu, 6 Nov 2014 13:19:57 +0000 (08:19 -0500)] 
--c2x and --x2c

10 years agoFIXIT-M comments
Russ Combs [Thu, 6 Nov 2014 10:35:47 +0000 (05:35 -0500)] 
FIXIT-M comments

10 years agoadded hi event squelch
Russ Combs [Thu, 6 Nov 2014 02:37:38 +0000 (21:37 -0500)] 
added hi event squelch

10 years agochange log
Russ Combs [Wed, 5 Nov 2014 20:05:42 +0000 (15:05 -0500)] 
change log

10 years agoMerge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs
Russ Combs [Wed, 5 Nov 2014 20:05:05 +0000 (15:05 -0500)] 
Merge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs

10 years agoprelim support for /* comments */ in text rules
Russ Combs [Wed, 5 Nov 2014 20:04:04 +0000 (15:04 -0500)] 
prelim support for /* comments */ in text rules

10 years agomore bug fixes. Invalid pointer arithmetic and adding another REG_TEST for frag...
Josh [Tue, 4 Nov 2014 23:28:49 +0000 (17:28 -0600)] 
more bug fixes.  Invalid pointer arithmetic and adding another REG_TEST for frag options

10 years agofixing warning from last commit
Josh [Tue, 4 Nov 2014 21:45:39 +0000 (15:45 -0600)] 
fixing warning from last commit

10 years agotweaking a Packet function so it makes logical sense
Josh [Tue, 4 Nov 2014 21:44:43 +0000 (15:44 -0600)] 
tweaking a Packet function so it makes logical sense

10 years agoMerge branch 'master' of /nfs/home/rucombs/Snort++
Tom Peters [Tue, 4 Nov 2014 21:36:23 +0000 (16:36 -0500)] 
Merge branch 'master' of /nfs/home/rucombs/Snort++

10 years agolatest from Josh
Russ Combs [Tue, 4 Nov 2014 20:56:17 +0000 (15:56 -0500)] 
latest from Josh

10 years agoMerge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs
Russ Combs [Tue, 4 Nov 2014 20:55:35 +0000 (15:55 -0500)] 
Merge branch 'master' of 10.6.12.29:/nfs/home/jrosenba/codecs

10 years agofixed boyer-moore init and removed content byte extract var cruft
Russ Combs [Tue, 4 Nov 2014 20:55:21 +0000 (15:55 -0500)] 
fixed boyer-moore init and removed content byte extract var cruft

10 years agoSnort2Lua tweak
Josh [Tue, 4 Nov 2014 17:10:04 +0000 (11:10 -0600)] 
Snort2Lua tweak

10 years agoBegin printing outer layers for Rebuilt frag packets
Josh [Tue, 4 Nov 2014 16:13:43 +0000 (10:13 -0600)] 
Begin printing outer layers for Rebuilt frag packets

10 years agoMerge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort...
Josh [Tue, 4 Nov 2014 15:51:49 +0000 (09:51 -0600)] 
Merge branch 'master' of ssh://chivas64dev.cm.sourcefire.com/nfs/home/rucombs/Snort++ into codecs

10 years agoAdjusting ProcessPacket() signature. Now sets appropriate flag flags after decode
Josh [Tue, 4 Nov 2014 15:40:35 +0000 (09:40 -0600)] 
Adjusting ProcessPacket() signature.  Now sets appropriate flag flags after decode

10 years agoWill now log approproiate protocol name for outer IP layers.
Josh [Tue, 4 Nov 2014 14:54:41 +0000 (08:54 -0600)] 
Will now log approproiate protocol name for outer IP layers.

10 years agofiglet foo
rcombs [Tue, 4 Nov 2014 00:59:33 +0000 (19:59 -0500)] 
figlet foo

10 years agofixed splitter foo
rcombs [Tue, 4 Nov 2014 00:45:13 +0000 (19:45 -0500)] 
fixed splitter foo

10 years agofixed norm conf init; block rule parsing
rcombs [Tue, 4 Nov 2014 00:01:50 +0000 (19:01 -0500)] 
fixed norm conf init; block rule parsing

10 years agominor IPv6 logging tweak
Josh [Mon, 3 Nov 2014 21:11:06 +0000 (15:11 -0600)] 
minor IPv6 logging tweak