Project

General

Profile

Actions

Bug #293

closed

Some debug messages does not support filter

Added by Eric Leblond over 13 years ago. Updated almost 13 years ago.

Status:
Closed
Priority:
Low
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

There is some debug messages that does not get filtered by SC_LOG_OP_FILTER.

For example, when suricata is launched with:

SC_LOG_LEVEL=debug SC_LOG_OP_FILTER="FIN packet received" /home/eric/builds/suricata/bin/suricata -c ~eric/builds/suricata/etc/suricata.yaml -r benches/nmap-fin.pcap

We see a lot of uri in the output:
.php?&&reader_version=
/download/Antivirus_
.exe

The code responsible for this output is in src/detect-uricontent.c at source:/src/detect-uricontent.c@047b19d2715f1cba98d8c5de8174466256bc7f64#L311. A printf is used where a filtered printf should be used.

Actions #1

Updated by Victor Julien about 13 years ago

  • Assignee set to Eric Leblond
  • Target version set to 1.1beta3
  • Estimated time set to 4.00 h
Actions #2

Updated by Victor Julien about 13 years ago

  • Status changed from New to Assigned
Actions #3

Updated by Victor Julien about 13 years ago

  • Target version changed from 1.1beta3 to 1.2
Actions #4

Updated by Eric Leblond almost 13 years ago

  • % Done changed from 0 to 80
Actions #5

Updated by Victor Julien almost 13 years ago

  • Status changed from Assigned to Closed
  • Target version changed from 1.2 to 1.2rc1
  • % Done changed from 80 to 100

Patches applied, thanks Eric!

Actions

Also available in: Atom PDF