Feature #258
closedkeyword 'ssl_state'
Description
unknown rule keyword 'ssl_state'
Example:
[9838] 20/12/2010 -- 11:50:19 - (detect-parse.c:655) <Error> (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(100)] - unknown rule keyword 'ssl_state'.
[9838] 20/12/2010 -- 11:50:19 - (detect.c:526) <Error> (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - Error parsing signature "alert tcp $EXTERNAL_NET 443 -> $HOME_NET any (msg:"WEB-CLIENT Windows schannel security package"; flow:established, to_client; ssl_state:server_hello; content:"|16 03 00|"; content:"|0C|"; within:1; distance:2; byte_jump:2,3,relative,big; byte_jump:2,0,relative,big; content:"|00 00|"; within:2; reference:cve,2007-2218; reference:url,www.microsoft.com/technet/security/bulletin/MS07-031.mspx; classtype:attempted-user; sid:11947; rev:5;)" from file /etc/suricata/rules/web-client.rules at line 180
Updated by Victor Julien almost 14 years ago
- Assignee set to Victor Julien
- Target version set to 1.1beta2
Will be tasked to a OISF dev.
Updated by Victor Julien over 13 years ago
This is now supported in our git repository.
Updated by Victor Julien over 13 years ago
- Status changed from New to Closed
- % Done changed from 0 to 100