Re: Question about http_inspect

Asim Jamshed <[email protected]>
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <CANwh_8bBGxKHFBM00vKBP18q0JZe9CrfvnRwm3nX+FAtNe55LQ@mail.gmail.com>
Thanks! I was previously looking at this link:

http://manual.snort.org/node90.html

The explanation was a bit confusing here. So, this means
that http_inspect uses stream5 for help in reassembling requests
and responses.. right? Can you please help me in pointing out
which function does the reassembling task for this purpose?

Thanks,
--Asim


On Tue, Sep 22, 2015 at 12:14 AM, Russ <[email protected]> wrote:

> Looking at the code will likely lead to some confusion.  http_inspect was
> originally stateless, but it has morphed over the years to become more and
> more stateful.  It does analyze reassembled requests and responses,
> supports normalizations on headers and body, and can even extract files.
> This is generally like what is done for ftp and smtp, etc.
>
> What version of the manual are you looking at?  What section?  We'll get
> that updated.
>
> Thanks
> Russ
>
>
> On 9/21/15 6:44 AM, Asim Jamshed wrote:
>
> Thanks. That makes sense. I will take a look at the code.
> I just wanted to make sure whether HttpInspect module
> takes care of those scenarios when the HTTP header is
> split across multiple segments (maybe due to a very long
> cookie value). I know this condition is very rare but just
> wanted to verify what HttpInspect would do in this case.
>
> --Asim
>
> On Mon, Sep 21, 2015 at 6:58 PM, Rahul Burman (rahburma) <
> <[email protected]>[email protected]> wrote:
>
>> It is not really required as the response codes and headers are available
>> in the first response packet itself.
>>
>> You can actually go through the code under HttpInspect module. I believe
>> it is well explained there.
>>
>>
>>
>> [image: http://www.cisco.com/web/europe/images/email/signature/logo05.jpg]
>>
>> *Rahul Burman*
>> ENGINEER.SOFTWARE ENGINEERING
>> [email protected]
>> Phone: *+91 80 4365 7902 <%2B91%2080%204365%207902>*
>>
>> *Cisco Systems Limited*
>> SEZ, Embassy Tech Village,Panathur Varthur Hobli, Bangalore East Taluk
>> BANGALORE
>> KARNATAKA
>> 560 037
>> IN
>> Cisco.com <http://www.cisco.com>
>>
>>
>>
>>
>>
>> [image: Think before you print.]Think before you print.
>>
>> This email may contain confidential and privileged material for the sole
>> use of the intended recipient. Any review, use, distribution or disclosure
>> by others is strictly prohibited. If you are not the intended recipient (or
>> authorized to receive for the recipient), please contact the sender by
>> reply email and delete all copies of this message.
>>
>> For corporate legal information go to:
>> <http://www.cisco.com/web/about/doing_business/legal/cri/index.html>
>> http://www.cisco.com/web/about/doing_business/legal/cri/index.html
>>
>>
>>
>>
>>
>> *From:* Asim Jamshed [mailto:[email protected]]
>> *Sent:* Monday, September 21, 2015 3:14 PM
>> *To:* Rahul Burman (rahburma)
>> *Cc:* [email protected]
>> *Subject:* Re: Question about http_inspect
>>
>>
>>
>> Thanks. Can you please elaborate on why it cannot do stateful inspection
>> on server response?
>>
>>
>>
>> --Asim
>>
>> On Monday, September 21, 2015, Rahul Burman (rahburma) <
>> [email protected]> wrote:
>>
>> HttpInspect module is stateless while inspecting the server responses.
>> There is a provision to do both stateless and stateful traffic inspection.
>>
>> Regards
>> Rahul
>>
>> -----Original Message-----
>> From: Asim Jamshed [mailto:[email protected]]
>> Sent: Sunday, September 20, 2015 4:55 PM
>> To: [email protected]
>> Subject: [Snort-devel] Question about http_inspect
>>
>> Hi,
>>
>> I was going through the Snort manual and it says that the http inspect
>> module is stateless (analyzes flows on a per-packet basis). Is that right?
>> I was wondering why it can use stream5 module and perform stateful
>> management like ftp, telnet and smtp protocols?
>>
>> Thanks,
>> --Asim
>>
>>
>> ------------------------------------------------------------------------------
>> _______________________________________________
>> Snort-devel mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/snort-devel
>> Archive:
>> http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel
>>
>> Please visit http://blog.snort.org for the latest news about Snort!
>>
>
>
>
> ------------------------------------------------------------------------------
>
>
>
> _______________________________________________
> Snort-devel mailing [email protected]://lists.sourceforge.net/lists/listinfo/snort-devel
> Archive:http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel
>
> Please visit http://blog.snort.org for the latest news about Snort!
>
>
>

------------------------------------------------------------------------------

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/snort-devel
Archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel

Please visit http://blog.snort.org for the latest news about Snort!
(unnamed) (image/jpeg, 2.1 KB) - not displayed
(unnamed) (image/png, 901 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.