Dion
(Dion)
1
Hello,
I try use ipopts : ssrr in my rules. But I get alert any case when set any IP flag in packet.
What version of Suricata are you using?
What platform and release (Linux x.y, Macos 10.x, …)?
Can you provide the rule?
Dion
(Dion)
3
Suricata version: 6.0.4
Platform: Linux
Rule: alert ip any any -> any any (ipopts: ssrr; msg: "issue"; rev: 1; sid:1;)
Dion
(Dion)
4
Do you have some updates? =)
Can you also provide the pcap?
Dion
(Dion)
6
Dion
(Dion)
7
Do you have some updates? =)
Thanks for bringing this to our attention. There may be an issue with how this is handled so I created Bug #6864: Detect: ipopts keyword misfires - Suricata - Open Information Security Foundation to track it.
1 Like
I’ve prepared a PR with the changes – if you’re able to build with my PR, let me know if this works for you