Skip to content

Commit

Permalink
tests: add frame gap logging tests
Browse files Browse the repository at this point in the history
  • Loading branch information
victorjulien committed Nov 24, 2023
1 parent 10e130a commit 97984c5
Show file tree
Hide file tree
Showing 7 changed files with 45 additions and 0 deletions.
7 changes: 7 additions & 0 deletions tests/http-gap-simple-frames/test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -75,3 +75,10 @@ checks:
frame.length: 40
frame.direction: toserver
frame.tx_id: 0
- filter:
min-version: 8
count: 1
match:
event_type: alert
alert.signature_id: 3
frame.payload_printable: "HTTP/1.0 200 OK\r\nDate: Mon, 31 Aug 2009 20:25:50 GMT\r\nServer: Apache\r\nConnection: close\r\nContent-Type: text/html\r\nContent-Length: 12\r\n\r\nHello World!\r\nHTTP/1.0 200 OK\r\nServer: Apache\r\nConnection: close\r\nContent-Type: text/html\r\nContent-Length: 70\r\n\r\nAAAAAAAAAAAAAA[14 bytes missing]AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHTTP/1.0 200 OK\r\nServer: Apache\r\nConnection: close\r\nContent-Type: text/html\r\nContent-Length: 12\r\n\r\nHello People\r\n"
Binary file not shown.
1 change: 1 addition & 0 deletions tests/smb2-frames-gap-payload-logging-02/test.rules
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
alert smb any any -> any any (frame:smb2.data; content:"wnwk"; sid:1;)
22 changes: 22 additions & 0 deletions tests/smb2-frames-gap-payload-logging-02/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
requires:
min-version: 8

args:
- --set stream.midstream=true
- -k none

checks:
- filter:
count: 1
match:
event_type: alert
alert.signature_id: 1
frame.length: 5872
frame.payload_printable: "..P.............wnwkphzdzzgxsqssxeyhtmudoapczaxhmtuwvztbwfczmzazvbfnobpbzbfcxoylfpzwpvtsjbdatwyhapqxqmhohmqlxjscgdmkoaeyfcgsrlizsckadtnboiuqffqqlfvhaojrlxfimwoxliietldPR\n7KuXaYTT442H/RDrQbQgOcIhX1PGQLXEX95dXJLq7wUtZkH7cofHcuuIReOQWtVj8gi1+chn3ZUb\nGiV+D1JN2qbo9MexbC4NJiFbSv+eJh1Vb5ZfcA9XnbEwmczGVlL58n1/K5pDG63KhC2qf1sj5Bsy\nlFck1cz7quBJgJ+3hQ8YfZ46KYA2NveP6aw8Rfys3pkXfIWEVCktBASLsAypLErwnQhFMIA/ipcV\nU9HrDnM4mRgfcgNgM4eGcm7Xleysh69mQceIqWuIW2RfNEnMjIZ6jbqBnUx2AaYDQbzl+uHs9EEI\nmT3poVDaFxPCr8VZJx/+hUvNjgP9Mrv+QxtPmaDWyuMeb9oOvrccVayoTryuNZscXwqqLwj54444\nrCZvsfJ4WeIk+rVu6Iwi0n479n85hdC4CtpBN/bAb0MHyQ+Y2ppi068nlj7hbwxJbIYsfgrF/5rw\nabFpSPR6Nj+BwHi1X7qEn1leh2QYW0SUCk8DlbBAY/gs6+meo+c1THEmat8TDqUKLOyIBdrrQoYD\nH22q1d4IWCeMKir6uTMDiKUZ8MMULxw5g0F9YDOxKhnA4Pw2CSczn0OrcuYLshFRRulNcKeX7AYx\noJI32tBO9acvkRlI404MKFgpBiJD4yLAk1Ly2dpWe7xKVg1jCBy76+4whX72slRRl7843hdqYl5E\nBEFJIUXqK0EYjhURypMhNhqlz4fdwljUlPtPj1qHXg/YHLl9Gg2ZchLNsrhwKSJwpoTEStehFq/L\nWVg14hFsjnA4wS0kcDU3RGTd6A2PoLK1VJOvsY5Ux7NcGvWuIFjDdKxPYvEsTIO5zlDjZCCfO0Ms\n5/QS9Nmq7B6Z4kjVwDqgSy0+D/ODJcLtiyNT++l7E1YVlsmxRp2sZfjaWAOvuhHtoflRIltddtv+\nc8Wn7oOL2rfpmFITG1N1UNOHTtnYGORVF4pNSV56YaAfaWBJ+54ST7pWOMSw8dcR93O9iQm5oN4z\nWexCA3eNHRv2xNULo4Mhp8ISiPYAX742tpDBsB/c1PySbsWzSUkJ9JkhyBx/4vwfSmRoBiYLW7PD\nHr30YXIAh2ZTTsx5Nmpagu0V3Z8jhfF24wmgD9gMsgsrJcK2oxHnVTGOBavSUlxLla65u10xOEd7\nhybM2+aX72EB/jAmiCvC1X/7723Ur9kqYyGvq5MYidS6WlbSjGAxmycap5Wp1Z/6FpPKl3e9bo8u\nRThMMpTmu5VfmYazAqs3nJLfNc7rzwIczy/uW8bvm700HP/Jar1tGZlsKzT1rToTErpBENd8yctO\nAuiKAQkMOei2sJQVe4Kpozon+RR8GWIu+rVnBDjTYGZXtHAUyZ3weqnY65V1fZ/dsj4TP71J6EHY\nK8Teiru4fp06TUiYNTTF4edkKhu+w0TfItswoJtLVZGioSOeNbRHbX2E5dwAy92xJOBInA9s4ega\nBq7pD9xkCl+hT3k14W5PhkRNY5aAVpY6KlRo5Y7TMjTbm3esGTkxWRVOPYaifbgd/dxGECdZRd4a\nfUt8tliKhdXEXB8KrTBznTWEdkQHljOcvBJgd7alm5w1mfudOzo0PL4u5QU8T45TpEEL3HpaGMw8\nWtCQeGcSMwg+af8XwjAF6yHasYPK/QiBSgV4n55yH1z6i/9ALhG255TNjHg8dKmTjwsBgrhIUM8Z\nqRGiJALjazgIzy1q30dXTWW1khpLeM1zYgb1x0uRUytdUQaDKa51C8WtjPlN90IPkmdNnqbWMQQs\nzm887tTN0ZWBmLyKUnNlkxu51/nRWtIUoe715+sy2MOIGCSz1KPBw7q90iMvzbVesYOI9aYGFQgB\n249k/O9v+7/WCrAdXFLwGBIoYb79JPfSz4itXLE1392G9E1vutl6mVt3tinOh5Kcf6ohyox1b3Qz\nGAIJsW0ksTs2vld9+RiygD/qn001XjvceEUisRiCntc+SuH10wA0K0W1hOTNAz4yh7uk0y39bP4q\nEqPZLQtb4ta0xTrgK/mbQ0oLCZrqOpnx6FdEqqEIKPgvMahiZ9EZau2IYpK9tIlrJwhRsOdBC/Cy\nG7BoxHS7DxdjDw8q73+eo9SkAvdXjmV1ym8ugAxMrTO+oHVJz+STBYB3Bh0ym7DkkuSGYuQSqH9a\nwbM++e5yBi/pASRRaTQRYQGEaIt8wMN+aizVZlA+Yimtu8V6p1keL/P1nMwCKlJq/6DBD4RUQGk/\n88fUwuDo6yEzvGGi1/2VGQ179N30tfaFzGxKZWytq91Wez5v4nji9MYZzP12ohOAao8KgSToneoU\nrjUG471y0EF1rdALMWUNpA1VyP19SO7ywnBqU3moXliQ7HSpb5B4U466GAWQuA3zGF1ERFD4GPyC\n4D5HUe6ZRtEn5BvLQyBcNQW99Pm6K7Rrlja2ORB3xMDJk9xq33eT7DU3xtov9oAM/sXPOgYjvPt6\nKqVe2dKMtzdZEjbgrBhOnZgTEYSUwSFgHEO21ZMwL0EXzHG9h1mxvZaaeho7vWZSvziYaNSMiEZ2\nDvo5NxNdsegPG9ugurz6K9beGCMDxsdN6nU1hFYJYV0RHI1Ib8GoQ16X2ww4oAG4Mul+p0AbL8e+\nT1PQsp2gkYfFyrcy9HyXJVF7DX1XwqjcbJGyf+Om[3044 bytes missing]"
- filter:
count: 1
match:
event_type: alert
alert.signature_id: 1
frame.length: 4112
frame.payload_printable.__len: 4095
Binary file not shown.
1 change: 1 addition & 0 deletions tests/smb2-frames-gap-payload-logging/test.rules
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
alert smb any any -> any any (frame:smb2.data; content:"wnwk"; sid:1;)
14 changes: 14 additions & 0 deletions tests/smb2-frames-gap-payload-logging/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
requires:
min-version: 8

args:
- --set stream.midstream=true
- -k none

checks:
- filter:
count: 1
match:
event_type: alert
alert.signature_id: 1
frame.payload_printable: "..P.............wnwkphzdzzgxsqssxeyhtmudoapczaxhmtuwvztbwfczmzazvbfnobpbzbfcxoylfpzwpvtsjbdatwyhapqxqmhohmqlxjscgdmkoaeyfcgsrlizsckadtnboiuqffqqlfvhaojrlxfimwoxliietldPR\n7KuXaYTT442H/RDrQbQgOcIhX1PGQLXEX95dXJLq7wUtZkH7cofHcuuIReOQWtVj8gi1+chn3ZUb\nGiV+D1JN2qbo9MexbC4NJiFbSv+eJh1Vb5ZfcA9XnbEwmczGVlL58n1/K5pDG63KhC2qf1sj5Bsy\nlFck1cz7quBJgJ+3hQ8YfZ46KYA2NveP6aw8Rfys3pkXfIWEVCktBASLsAypLErwnQhFMIA/ipcV\nU9HrDnM4mRgfcgNgM4eGcm7Xleysh69mQceIqWuIW2RfNEnMjIZ6jbqBnUx2AaYDQbzl+uHs9EEI\nmT3poVDaFxPCr8VZJx/+hUvNjgP9Mrv+QxtPmaDWyuMeb9oOvrccVayoTryuNZscXwqqLwj54444\nrCZvsfJ4WeIk+rVu6Iwi0n479n85hdC4CtpBN/bAb0MHyQ+Y2ppi068nlj7hbwxJbIYsfgrF/5rw\nabFpSPR6Nj+BwHi1X7qEn1leh2QYW0SUCk8DlbBAY/gs6+meo+c1THEmat8TDqUKLOyIBdrrQoYD\nH22q1d4IWCeMKir6uTMDiKUZ8MMULxw5g0F9YDOxKhnA4Pw2CSczn0OrcuYLshFRRulNcKeX7AYx\noJI32tBO9acvkRlI404MKFgpBiJD4yLAk1Ly2dpWe7xKVg1jCBy76+4whX72slRRl7843hdqYl5E\nBEFJIUXqK0EYjhURypMhNhqlz4fdwljUlPtPj1qHXg/YHLl9Gg2ZchLNsrhwKSJwpoTEStehFq/L\nWVg14hFsjnA4wS0kcDU3RGTd6A2PoLK1VJOvsY5Ux7NcGvWuIFjDdKxPYvEsTIO5zlDjZCCfO0Ms\n5/QS9Nmq7B6Z4kjVwDqgSy0+D/ODJcLtiyNT++l7E1YVlsmxRp2sZfjaWAOvuhHtoflRIltddtv+\nc8Wn7oOL2rfpmFITG1N1UNOHTtnYGORVF4pNSV56YaAfaWBJ+54ST7pWOMSw8dcR93O9iQm5oN4z\nWexCA3eNHRv2xNULo4Mhp8ISiPYAX742tpDBsB/c1PySbsWzSUkJ9JkhyBx/4vwfSmRoBiYLW7PD\nHr30YXIAh2ZTTsx5Nmpagu0V3Z8jhfF24wmgD9gMsgsrJcK2oxHnVTGOBavSUlxLla65u10xOEd7\nhybM2+aX72EB/jAmiCvC1X/7723Ur9kqYyGvq5MYidS6WlbSjGAxmycap5Wp1Z/6FpPKl3e9bo8u\nRThMMpTmu5VfmYazAqs3nJLfNc7rzwIczy/uW8bvm700HP/Jar1tGZlsKzT1rToTErpBENd8yctO\nAuiKAQkMOei2sJQVe4Kpozon+RR8GWIu+rVnBDjTYGZXtHAUyZ3weqnY65V1fZ/dsj4TP71J6EHY\nK8Teiru4fp06TUiYNTTF4edkKhu+w0TfItswoJtLVZGioSOeNbRHbX2E5dwAy92xJOBInA9s4ega\nBq7pD9xkCl+hT3k14W5PhkRNY5aAVpY6KlRo5Y7TMjTbm3esGTkxWRVOPYaifbgd/dxGECdZRd4a\nfUt8tliKhdXEXB8KrTBznTWEdkQHljOcvBJgd7alm5w1mfudOzo0PL4u5QU8T45TpEEL3HpaGMw8\nWtCQeGcSMwg+af8XwjAF6yHasYPK/QiBSgV4n55yH1z6i/9ALhG255TNjHg8dKmTjwsBgrhIUM8Z\nqRGiJALjazgIzy1q30dXTWW1khpLeM1zYgb1x0uRUytdUQaDKa51C8WtjPlN90IPkmdNnqbWMQQs\nzm887tTN0ZWBmLyKUnNlkxu51/nRWtIUoe715+sy2MOIGCSz1KPBw7q90iMvzbVesYOI9aYGFQgB\n249k/O9v+7/WCrAdXFLwGBIoYb79JPfSz4itXLE1392G9E1vutl6mVt3tinOh5Kcf6ohyox1b3Qz\nGAIJsW0ksTs2vld9+RiygD/qn001XjvceEUisRiCntc+SuH10wA0K0W1hOTNAz4yh7uk0y39bP4q\nEqPZLQtb4ta0xTrgK/mbQ0oLCZrqOpnx6FdEqqEIKPgvMahiZ9EZau2IYpK9tIlrJwhRsOdBC/Cy\nG7BoxHS7DxdjDw8q73+eo9SkAvdXjmV1ym8ugAxMrTO+oHVJz+STBYB3Bh0ym7DkkuSGYuQSqH9a\nwbM++e5yBi/pASRRaTQRYQGEaIt8wMN+aizVZlA+Yimtu8V6p1keL/P1nMwCKlJq/6DBD4RUQGk/\n88fUwuDo6yEzvGGi1/2VGQ179N30tfaFzGxKZWytq91Wez5v4nji9MYZzP12ohOAao8KgSToneoU\nrjUG471y0EF1rdALMWUNpA1VyP19SO7ywnBqU3moXliQ7HSpb5B4U466GAWQuA3zGF1ERFD4GPyC\n4D5HUe6ZRtEn5BvLQyBcNQW99Pm6K7Rrlja2ORB3xMDJk9xq33eT7DU3xtov9oAM/sXPOgYjvPt6\nKqVe2dKMtzdZEjbgrBhOnZgTEYSUwSFgHEO21ZMwL0EXzHG9h1mxvZaaeho7vWZSvziYaNSMiEZ2\nDvo5NxNdsegPG9ugurz6K9beGCMDxsdN6nU1hFYJYV0RHI1Ib8GoQ16X2ww4oAG4Mul+p0AbL8e+\nT1PQsp2gkYfFyrcy9HyXJVF7DX1XwqjcbJGyf+Om[2896 bytes missing]hksrgtlgguzfewezyeyvyriypgzndkroppwevfmbpfbnfgjszsncitdidoqdkvnhzxvsgertefksqsgadbmaohyhptxitynjxjxnhrewjjnegphkzymixsybpquiytjohrgthwfedgxbkshmecka"

0 comments on commit 97984c5

Please sign in to comment.