dpd.sig rejection syntax

TQ <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CAM2MKSqTN2066cnkikYJ5L8Rxg2S-gLUuuGvGRP1VwzR=UCLKg@mail.gmail.com>
Hello All,

There are two protocols, A and B which use <STX> and <ETX> to encapsulate
their data.  Both protocols operate over 20+ ports, and the only difference
is that protocol B starts with lowercase 's' after \x02.  I've looked over
the dpd.sig files on Zeek GitHub but didn't find anything for rejection.
I've tried adding (!s), [!s] after \x02, but protocol A stops logging... so
I know there's a syntax issue.

##! Match for <STX>...<ETX>
signature dpd_02_03_client {
ip-proto == tcp
payload /\x02.{0,1500}\x03/
tcp-state originator
enable "A"
}

##! Match for <STX>...<ETX>
signature dpd_02_03_server {
ip-proto == tcp
payload /\x02.{0,1500}\x03/
tcp-state responder
enable " A"
}

Thanks,

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.