Hi,
I am trying to detect some byte in my pcap CVE-2015-5254_ActiveMQ_Deserialization.pcapng (7.7 KB) ,but suricata can’t detect keyword(1a) in my pcap,
even use such loose rules:
alert ip any any <> any any (msg:"111"; content:"|1a|";sid:10082; rev:1;)
alert tcp any any <> any any (msg:"111"; content:"|1a|";sid:10083; rev:1;)
alert tcp any any -> any any (msg:"111"; content:"|1a|";sid:10084; rev:1;)
after run suricata , no alart appear.
┌──(hans㉿kali-xps)-[~/suricata-rules]
└─$ rm logs/*
┌──(hans㉿kali-xps)-[~/suricata-rules]
└─$ cat 1.rules
alert ip any any <> any any (msg:"111"; content:"|1a|";sid:10082; rev:1;)
alert tcp any any <> any any (msg:"111"; content:"|1a|";sid:10083; rev:1;)
alert tcp any any -> any any (msg:"111"; content:"|1a|";sid:10084; rev:1;)┌──(hans㉿kali-xps)-[~/suricata-rules]
└─$ pwd
/home/hans/suricata-rules
┌──(hans㉿kali-xps)-[~/suricata-rules]
└─$ suricata -r pcap/CVE-2015-5254_ActiveMQ_Deserialization.pcapng -S ~/suricata-rules/1.rules -l ~/suricata-rules/logs/ -k none
10/3/2021 -- 23:28:14 - <Notice> - This is Suricata version 6.0.1 RELEASE running in USER mode
10/3/2021 -- 23:28:14 - <Notice> - all 5 packet processing threads, 4 management threads initialized, engine started.
10/3/2021 -- 23:28:14 - <Notice> - Signal Received. Stopping engine.
10/3/2021 -- 23:28:14 - <Notice> - Pcap-file module read 1 files, 37 packets, 6147 bytes
┌──(hans㉿kali-xps)-[~/suricata-rules]
└─$ cat logs/fast.log
┌──(hans㉿kali-xps)-[~/suricata-rules]
└─$
It’s CVE-2015-5254 ActiveMQ Deserialization
Anyone can help me,thanks.