rmkml rmkml
- Login: rmkml
- Email: rmkml@yahoo.fr
- Registered on: 01/05/2010
- Last sign in: 05/21/2015
Issues
open | closed | Total | |
---|---|---|---|
Assigned issues | 0 | 0 | 0 |
Reported issues | 1 | 54 | 55 |
Activity
03/14/2015
- 08:33 AM Suricata Bug #1416 (Closed): request feature: urilen <> inclusive please
- Hi,
First Thx Suricata team and all,
I'm recently tested urilen on snort and urilen <> is inclusive but not on ...
01/28/2015
- 03:31 PM Suricata Bug #1370 (New): sctp fp on suricata engine
- Hello,
I'm continue Suricata testing and 1) found a fp with this (simplified) sig on joigned sctp pcap file:
al...
08/19/2014
- 10:39 AM Suricata Feature #1265 (Closed): Replace response on Suricata dns decoder when dns error please
- Hello,
When I start this test: (only for example)
perl -e 'print "\x00\x00\x01\x00\x00\x01\x00\x00\x00\x00\x00\x0...
02/04/2014
- 09:44 AM Suricata Bug #1098 (Closed): http_raw_uri with relative pcre parsing issue
- Hi,
Suricata v2.0 beta 2 fire if you use relative uri pcre like this:
alert tcp any any -> any 80 (msg:"Testin...
11/27/2013
- 03:14 AM Suricata Bug #1045 (Closed): Suricata smtp flowbits FN
- Hi,
During my testing, I'm found a FN when smtp and flowbits are used.
Created a PoC especially for this:
1)...
10/04/2013
- 03:14 AM Suricata Bug #990 (Closed): FP on Suricata dns ttl 0
- Hi,
Congratulations for new Suricata v1.4.6 version !
ok I'm found a FP with joigned pcap and this old sig plea...
07/09/2013
- 08:11 AM Suricata Bug #856: FP on new Suricata git dns decoder
- $ mkdir suricata_git7jul2013
$ cd suricata_git7jul2013
suricata_git7jul2013]$ git clone git://phalanx.openinfosecfo...
07/06/2013
- 06:45 AM Suricata Bug #856: FP on new Suricata git dns decoder
- Joigned pcap file.
- 06:44 AM Suricata Bug #856 (Closed): FP on new Suricata git dns decoder
- Hi,
Congrats for hard work on new git (yesterday) dns decoder,
but I have FP with it :
Joigned pcap file,
s...
03/10/2013
- 09:48 AM Suricata Bug #771 (Closed): curious ip proto break fast.log
- Hi,
I have a curious "break" on fast.log with theses lines on /etc/protocols :
sscopmce 128 SSCOPMCE
...
Also available in: Atom