Re: Snort crashes with lightSPD rules and hyperscan_literals enabled
"Nihal Desai \(nihdesai\) via Snort-users" <[email protected]> Wed, 17 May 2023 06:14:14 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <BL0PR11MB312142CD8EDB21EBB0DB88E2D57E9@BL0PR11MB3121.namprd11.prod.outlook.com> |
Hello Yarava, Thank you for reporting the issue. Have you tried testing with latest/newer build? We believe this issue is fixed in 3.1.46.0 version. Thanks! -- V/r Nihal N. Desai From: Snort-users <[email protected]> on behalf of Yarava, Saikumar via Snort-users <[email protected]> Date: Monday, May 15, 2023 at 8:53 AM To: snort-users <[email protected]> Subject: [Snort-users] Snort crashes with lightSPD rules and hyperscan_literals enabled Hi, We are seeing snort crash when ran with lightspd rules and hyperscan_literals variable enabled in snort configuration. Details for the same are provided below. Stacktrace: #0 0x0000562779ca5d49 in snort::SnortConfig::post_setup (this=this@entry=0x56277beb9300) at /opt/intel/saiky/http_ngfw/snort3/src/main/snort_config.cc:339 339 if ( s and s->setup(this) ) (gdb) bt #0 0x0000562779ca5d49 in snort::SnortConfig::post_setup (this=this@entry=0x56277beb9300) at /opt/intel/saiky/http_ngfw/snort3/src/main/snort_config.cc:339 #1 0x0000562779ca25a3 in snort::Snort::init (argc=argc@entry=25, argv=argv@entry=0x7ffd72159ab8) at /opt/intel/saiky/http_ngfw/snort3/src/main/snort.cc:208 #2 0x0000562779ca2b01 in snort::Snort::setup (argc=25, argv=0x7ffd72159ab8) at /opt/intel/saiky/http_ngfw/snort3/src/main/snort.cc:386 #3 0x0000562779be5f23 in main (argc=25, argv=0x7ffd72159ab8) at /opt/intel/saiky/http_ngfw/snort3/src/main.cc:1136 Versions: snort3_version:"3.1.36.0" lightspd package link: https://www.snort.org/downloads/registered/Talos_LightSPD.tar.gz Steps to reproduce the issue: * Download and install snort 3.1.36.0 on ubuntu 22.04 * Download lightspd package and unzip it. * Link to download: https://www.snort.org/downloads/registered/Talos_LightSPD.tar.gz * Enable hyperscan_literals variable in conf file lightspd/policies/common/policy_logic.lua -- all policies include('baseconfig.lua') detection.global_default_rule_state = false detection.hyperscan_literals = true detection.pcre_to_regex = true detection.pcre_match_limit = 3500 detection.pcre_match_limit_recursion = 3500 * Run snort with balanced policy (Issue is seen with any policy) * snort -A none -c lightspd/policies/3.1.0.0-0/balanced-security-and-connectivity.lua -R lightspd/rules/3.0.0.0/includes.rules -r entmix_stripped.pcap We are able to narrowed down the issue. The crash is seen only with following 3 rules present in rules file, when hyperscan_literals variable enabled in conf file. Could you please check this issue. * lightspd/rules/3.0.0.0/ snort3-malware-cnc.rules * alert http ( msg:"MALWARE-CNC Win.Trojan.Prometei variant outbound connection"; flow:to_server; http_uri:path; content:"/k.php",fast_pattern,nocase; http_param:"B",nocase; content:"_AMD64",nocase; metadata:impact_flag red,policy max-det ect-ips drop,policy security-ips drop; reference:url,blog.talosintelligence.com/prometei-botnet-and-its-quest-for-monero; classtype:trojan-activity; gid:1; sid:61429; rev:1; ) * lightspd/rules/3.0.0.0/ snort3-server-webapp.rules * alert http ( msg:"SERVER-WEBAPP Forta GoAnywhere MFT remote code execution attempt"; flow:to_server,established; http_uri; content:"/goanywhere/lic/accept",fast_pattern,nocase; http_param:"bundle"; content:"Jh88_jqGQWSbZmiCc1DErQhwOhCTL kYm",depth 32; metadata:policy max-detect-ips drop,policy security-ips drop; reference:cve,2023-0669; classtype:attempted-admin; gid:1; sid:300442; rev:1; ) * 5791 # alert http ( msg:"SERVER-WEBAPP Forta GoAnywhere MFT remote code execution attempt"; flow:to_server,established; http_uri; content:"/goanywhere/lic/accept",fast_pattern,nocase; http_param:"bundle"; content:"_ejELN_Z2eeHN2I455gixeLf7eWn7 bzd",depth 32; metadata:policy max-detect-ips drop,policy security-ips drop; reference:cve,2023-0669; classtype:attempted-admin; gid:1; sid:300443; rev:1; ) No Crash seen in following scenarios * Enable hyperscan_literals and comment out above 3 rules. * Disable hyperscan_literals and uncomment above 3 rules. Crash seen only when hyperscan_literals enabled with above rules present in rules file. Regards, Sai. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette