Actions
Feature #524
closeddetect double encoding in URI
Effort:
Difficulty:
Label:
Description
Update libhtp/suricata to detect double encoding in URI path and query string.
Updated by Victor Julien about 12 years ago
I think the least performance impacting way would be in the current libhtp decode routines. It would be best if we can do it w/o doing a separate pass over the data.
Updated by Victor Julien about 12 years ago
- Target version changed from 1.4 to 1.4beta2
Updated by Victor Julien about 12 years ago
- Target version changed from 1.4beta2 to 1.4beta3
Updated by Victor Julien almost 12 years ago
- Target version changed from 1.4beta3 to 1.4rc1
Updated by Victor Julien almost 12 years ago
- Status changed from New to Assigned
- Assignee changed from OISF Dev to Victor Julien
Talking to libhtp upstream for determining the best strategy here.
Updated by Victor Julien almost 12 years ago
- Target version changed from 1.4rc1 to 2.0rc2
Updated by Victor Julien almost 11 years ago
- Target version changed from 2.0rc2 to 3.0RC2
Updated by Victor Julien almost 9 years ago
- Target version changed from 3.0RC2 to 70
Updated by Victor Julien over 7 years ago
- Status changed from Assigned to New
- Assignee changed from Victor Julien to OISF Dev
- Target version changed from 70 to TBD
Updated by Victor Julien over 5 years ago
- Assignee changed from OISF Dev to Philippe Antoine
- Target version changed from TBD to 70
- Parent task deleted (
#775)
Updated by Philippe Antoine over 5 years ago
What is expected here ? ie what do you mean by "detect" ?
Should we trigger an http event ? Or should we double decode the URI if necessary ? (and keep raw uri as is already done)
Updated by Victor Julien over 5 years ago
I think the idea is/was that double decoding is possibly used as an evasion technique, so we want to be able to decode it and indeed match on the fact that its double decoded. So a http event indeed.
Updated by Victor Julien over 5 years ago
- Status changed from Assigned to Closed
- Target version changed from 70 to 5.0rc1
Actions