[Snort-users] byte_test only on reassembled stream?

Duane Howard duane.security at ...11827...
Fri Dec 11 14:04:25 EST 2015

I currently have a rule that looks for something like:

flow:established,from_server; byte_test:1,&,0x82,2;

I have a payload that is a UDP fragment that is tripping this up where the
bytes in the inspected position are 0x87 but on the fully reassembled
stream (and what Snort logs in the pseudopacket) is 0x84.

I'm really only interested in the value from the reassembled part of this,
and not the bits in the data section of the initial fragment, is this
working as intended? Is there a way to accomplish what I want (only match
on the pseudo packet/reassembled byte stream?).

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20151211/f30c25da/attachment.html>

More information about the Snort-users mailing list