Bug #5220
closed
detect/base64_data: fast_pattern shouldn't be allowed
Added by Jason Taylor about 3 years ago.
Updated 19 days ago.
Description
It seems that specifying a fast_pattern in base64_data is ignored both from an error/warning standpoint and from an actual fast_pattern assignment by suricata. It seems suricata should warn/fail on fast_pattern assignment in base64_data.
rule example:
alert http $HOME_NET any -> $EXTERNAL_NET any (flow:established,to_server; http.method; content:"POST"; http.request_body; base64_decode:bytes 28; base64_data; content:"something"; fast_pattern; classtype:bad-unknown; sid:123; rev:1;)
suricata.log:
[52155] 29/3/2022 -- 20:20:41 - (detect-engine-loader.c:354) <Info> (SigLoadSignatures) -- 1 rule files processed. 1 rules successfully loaded, 0 rules failed
rules_fast_pattern.log:
== Sid: 123 ==
alert http $HOME_NET any -> $EXTERNAL_NET any (flow:established,to_server; http.method; content:"POST"; http.request_body; base64_decode:bytes 28; base64_data; content:"something"; fast_pattern; classtype:bad-unknown; sid:123; rev:1;)
Fast Pattern analysis:
Fast pattern matcher: http request method (http_method)
Flags: None
Fast pattern set: no
Fast pattern only set: no
Fast pattern chop set: no
Original content: POST
Final content: POST
suricata version:
This is Suricata version 7.0.0-dev (99b344336 2022-03-25)
- Description updated (diff)
- Target version changed from TBD to 7.0.0-beta1
- Label Needs backport to 6.0 added
- Status changed from New to Assigned
- Assignee changed from OISF Dev to Shivani Bhardwaj
- Target version changed from 7.0.0-beta1 to 6.0.5
- Label deleted (
Needs backport to 6.0)
- Assignee changed from Shivani Bhardwaj to OISF Dev
- Target version changed from 6.0.5 to 7.0.0-beta1
- Label Needs backport to 6.0 added
- Copied to Bug #5242: fast_pattern specification in base64_data shouldn't be allowed (6.0.x backport) added
- Related to Feature #5245: allow fast_pattern on base64_data strings added
- Label deleted (
Needs backport to 6.0)
- Target version changed from 7.0.0-beta1 to 8.0.0-beta1
- Assignee changed from OISF Dev to Shivani Bhardwaj
- Related to Task #6443: Suricon 2023 brainstorm added
This ticket is about the parser allowing the setting, but then not acting on it. #5245 is about adding proper support. As I think that is non-trivial and might not happen at all, it would be good to fix this issue independent of #5245.
- Status changed from Assigned to In Progress
- Status changed from In Progress to In Review
- Label Needs backport to 7.0 added
- Label deleted (
Needs backport to 7.0)
- Status changed from In Review to Closed
- Subject changed from fast_pattern specification in base64_data shouldn't be allowed to detect/base64_data: fast_pattern shouldn't be allowed
Also available in: Atom
PDF