another issue:
‘http.uri’ doesn’t work!
alert http any any → any any (msg:“test2”; http.uri; content:"/…/conf/config.properties";sid:80000;)
my suricata version 6.0.1 RELEASE
my suricata.yaml :
stream:
midstream: yes
memcap: 64mb
checksum-validation: no
inline: auto
reassembly:
memcap: 256mb
depth: 1mb
toserver-chunk-size: 1024
toclient-chunk-size: 1024
randomize-chunk-size: yes
my command:
suricata -r ./lanproxy-cve-2021-3019-lfi.pcap -v -c ./suricata.yaml
but this rule can produce an alert :
lanproxy-cve-2021-3019-lfi.pcap (9.1 KB)
alert http any any → any any (msg:“test2”; content:"/…/conf/config.properties";sid:80000;)