hello.i have a question about suricata-4.1.2 ftp extraction.
my signature example: alert ftp-data any any -> any any (msg:“FTP store password”; filestore; sid:3; rev:1;)
suricata.yaml
please forgive me for my bad english.i want using suricata extracte file for ftp protocol.but i couldn’t capture anything.I want to determine the cause of the problem.
Thank you very much.I check it and found i use ftp active model default.
I try the passive model when you tips me.And i capture those FTP files.
But why i couldn’t extracte files when active FTP ?
Could I think that 4.1.8 supported the active FTP ?
If I use the 5.0.3. i have to rewrite too many source code.
Because i develop some industrial control protocol parsers in 4.1.2.
It will be also required as soon as 4.1.x is EOL. So we highly recommend that you update it to the current master code base and ideally in Rust. We would welcome new protocol additions especially from that area since we see more and more people asking for those.