Re: How to support keyword 'pkt_data' in snort rules
"Viktor Chyzhovych -X \(vchyzhov - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]> Mon, 26 Jan 2026 15:13:21 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <LV8PR11MB8769CEA8BABB0E5032432D2CCF93A@LV8PR11MB8769.namprd11.prod.outlook.com> |
--===============1597600876669623937== Content-Language: en-GB Content-Type: multipart/alternative; boundary="_000_LV8PR11MB8769CEA8BABB0E5032432D2CCF93ALV8PR11MB8769namp_" --_000_LV8PR11MB8769CEA8BABB0E5032432D2CCF93ALV8PR11MB8769namp_ Content-Type: text/plain; charset="gb2312" Content-Transfer-Encoding: base64 SGVsbG8gV3UsDQoNClRoYW5rIHlvdSBmb3IgcmVhY2hpbmcgb3V0IHRvIHRoZSBTbm9ydC4NCg0K UmVnYXJkaW5nIHlvdXIgcXVlc3Rpb25zIHdlIHdhbnQgdG8gZXhwbGFpbiBhbmQgZ2l2ZSBzb21l IHJlY29tbWVuZGF0aW9ucy4NCg0KRm9yIGNvbmZpZ3VyYXRpb24gY2hlY2sgeW91IG5lZWQgdXNl IHRoZSBuZXh0IG9wdGlvbiAiLS1kdW1wLWNvbmZpZy10ZXh0IGluc3RlYWQgb2YgIi0taGVscC1j b25maWciIGJlY2F1c2Ugb2Y6DQoNCi0taGVscC1jb25maWcgLSBTaG93cyBhdmFpbGFibGUgY29u ZmlndXJhdGlvbiBvcHRpb25zIGFuZCB0aGVpciBkZXNjcmlwdGlvbnMgKGhlbHAvZG9jdW1lbnRh dGlvbikuDQoNCi0tZHVtcC1jb25maWctdGV4dCAtIER1bXBzIHRoZSBhY3R1YWwgbG9hZGVkIGNv bmZpZ3VyYXRpb24gdmFsdWVzLg0KDQpEb2MgcGFnZTogaHR0cHM6Ly9naXRodWIuY29tL3Nub3J0 My9zbm9ydDMvYmxvYi9tYXN0ZXIvZG9jL3VzZXIvZHVtcF9jb25maWcudHh0DQoNCkFjY29yZGlu ZyB0byB5b3VyIHRyYWZmaWMsICIvaW5kZXgucGhwIiBpcyBwcmVzZW50IGluIHRoZSBVUkkgKGxp a2UgR0VUIC9pbmRleC5waHApLCBidXQgeW91ciBydWxlIHdvbid0IGRldGVjdCBpdCB0aGVyZS4g VGhlICJwa3RfZGF0YSIgb3B0aW9uIHNlYXJjaGVzIGluIHRoZSBtZXNzYWdlIGJvZHksIG5vdCBp biB0aGUgVVJJIGl0c2VsZi4gVGhpcyBtZWFucyB5b3VyIHJ1bGUgd2lsbCBvbmx5IHRyaWdnZXIg aWYgIi9pbmRleC5waHAiIGFsc28gYXBwZWFycyBpbiB0aGUgYm9keSBjb250ZW50LCB3aGljaCBp dCBkb2Vzbid0IGluIHlvdXIgY2FzZS4NClRoaXMgaGFwcGVucyBiZWNhdXNlIGlmIHlvdSB1c2Us IG1peGluZyAiaHR0cF9oZWFkZXIiIHdpdGggInBrdF9kYXRhIiAod2hpY2ggaW5zcGVjdHMgYm9k eSBjb250ZW50KSBjcmVhdGVzIGEgY29uZmxpY3QgaW4gaG93IHRoZSBydWxlIHByb2Nlc3NlcyB0 aGUgdHJhZmZpYy4NClRvIHJlc29sdmUgdGhpcywgZWl0aGVyIHVzZSAiaHR0cF91cmkiIGluc3Rl YWQgb2YgInBrdF9kYXRhIiB0byBpbnNwZWN0IHRoZSBVUkkgb3IgcmVtb3ZlIHRoZSAiaHR0cF9o ZWFkZXIiIG9wdGlvbiB0byBhdm9pZCBzZWN0aW9uIGNvbmZsaWN0cy4gQWxzbywgeW91IGNhbiBz cGxpdCBpbnRvIHNlcGFyYXRlIHJ1bGVzIGlmIHlvdSBpbnRlbmQgdG8gaW5zcGVjdCBib3RoIHNl Y3Rpb25zIGluZGVwZW5kZW50bHkuDQoNCkRvYyBwYWdlOiBodHRwczovL2RvY3Muc25vcnQub3Jn L3J1bGVzL29wdGlvbnMvcGF5bG9hZC9odHRwL3VyaQ0KDQpSZWNvbW1lbmRlZCBydWxlczoNCg0K YWxlcnQgaHR0cCBhbnkgYW55IC0+IGFueSAkSFRUUF9QT1JUUyAoIG1zZzoiY2hlY2sgcGt0X2Rh dGEtMyI7IGh0dHBfaGVhZGVyOyBjb250ZW50OiJBY2NlcHQtRW5jb2Rpbmc6IGd6aXAiOyBodHRw X3VyaTsgY29udGVudDoiL2luZGV4LnBocCI7IHNpZDoxMDAwMTAwMzsgcmV2OjE7ICkNCg0KQmVz dCByZWdhcmRzLA0KVmlrdG9yDQoNCg0KDQpHZXQgT3V0bG9vayBmb3IgTWFjIDxodHRwczovL2Fr YS5tcy9HZXRPdXRsb29rRm9yTWFjPg0KDQpGcm9tOiBTbm9ydC11c2VycyA8c25vcnQtdXNlcnMt Ym91bmNlc0BsaXN0cy5zbm9ydC5vcmc+IG9uIGJlaGFsZiBvZiDO4rOsIHZpYSBTbm9ydC11c2Vy cyA8c25vcnQtdXNlcnNAbGlzdHMuc25vcnQub3JnPg0KRGF0ZTogVHVlc2RheSwgMTMgSmFudWFy eSAyMDI2IGF0IDIwOjI3DQpUbzogc25vcnQtdXNlcnNAbGlzdHMuc25vcnQub3JnIDxzbm9ydC11 c2Vyc0BsaXN0cy5zbm9ydC5vcmc+DQpTdWJqZWN0OiBbU25vcnQtdXNlcnNdIEhvdyB0byBzdXBw b3J0IGtleXdvcmQgJ3BrdF9kYXRhJyBpbiBzbm9ydCBydWxlcw0KDQpIaSBTbm9ydCBleHBlcnRz LA0KDQpJIGhhdmUgYSBxdWVzdGlvbiB3aGVuIHVzaW5nICdwa3RfZGF0YScga2V5d29yZCBpbiBz bm9ydCBydWxlcy4NCkFjY29yZGluZyB0byBodHRwczovL2RvY3Muc25vcnQub3JnL3J1bGVzL29w dGlvbnMvcGF5bG9hZC9wa3RfZGF0YSwgSSBuZWVkIHRvIHNldCAnc2VhcmNoX2VuZ2luZS5kZXRl Y3RfcmF3X3RjcCcgdG8gdHJ1ZSB0byBzdXBwb3J0ICdwa3RfZGF0YScgaW4gc29ucnQgcnVsZXMu DQpCdXQgYWZ0ZXIgSSBhZGRlZCB0aGlzIHNldHRpbmcgdG8gY29uZmlndXJhdGlvbiwgaXQgc2Vl bXMgbm90IHdvcmtpbmcuDQpQbHMgaGVscCB0byBjaGVjayB3aHkgdGhlIGNvbmZpZ3VyYXRpb24g bm90IGNoZW5nZWQgaW4gbXkgd29ya2luZyBlbnYsIFRoYW5rcw0KDQpUaGUgc25vcnQgdmVyc2lv biBpcyB2My43LjQuMC4gSGVyZSBpcyB3aGF0IEkgdHJpZWQ6DQooMSkgYWRkIGNoYW5nZSB0byBz bm9ydC5sdWEgZmlsZToNCiAgICBhZGQgImluY2x1ZGUoJ21heF9kYXRlY3QubHVhJykiIG9yICJz ZWFyY2hfZW5naW5lLmRldGVjdF9yYXdfdGNwID0gdHJ1ZSIgb3IgInNlYXJjaF9lbmdpbmUgPSB7 IGRldGVjdF9yYXdfdGNwID0gdHJ1ZSB9Ig0KKDIpIGFkZCBwYXJhbWV0ZXIgaW4gY29tbWFuZA0K ICAgIGFkZCAiLS1sdWEgJ3NlYXJjaF9lbmdpbmUuZGV0ZWN0X3Jhd190Y3AgPSB0cnVlJyIgb3Ig Ii0tdHdlYWtzIG1heF9kZXRlY3QiDQpBZnRlciBkb2luZyBhYm92ZSwgSSBjaGVja2VkIGNvbmZp Z3VyYXRpb24gYnkgdXNpbmcgIi0taGVscC1jb25maWcgc2VhcmNoX2VuZ2luZSB8Z3JlcCB0Y3Ai LCBhbmQgZ2V0IHRoZSBvdXRwdXQ6DQogICAgYm9vbCBzZWFyY2hfZW5naW5lLmRldGVjdF9yYXdf dGNwID0gZmFsc2U6IGRldGVjdCBvbiBUQ1AgcGF5bG9hZCBiZWZvcmUgcmVhc3NlbWJseQ0KDQpJ IGFsc28gY2hlY2tlZCB3aXRoIHNvbWUgc2ltcGxlIHBjYXAgd2l0aCBmb2xsb3dpbmcgc25vcnQg cnVsZXMsIGFuZCBzZWVtcyBubyBtYXR0ZXIgaG93IHRoZSBjb25maWd1cmF0aW9uIGNoYW5nZWQs IHRoZSAzcmQgcnVsZSh3aXRoICdwa3RfZGF0YScgaW4gcnVsZSkgbmV2ZXIgbWF0Y2hlZDoNCiAg ICBhbGVydCB0Y3AgYW55IGFueSAtPiBhbnkgJEhUVFBfUE9SVFMgKCBtc2c6ImNoZWNrIHBrdF9k YXRhLTEiOyBjb250ZW50OiIvaW5kZXgucGhwIjsgY29udGVudDoiQWNjZXB0LUVuY29kaW5nOiBn emlwIjsgc2lkOjEwMDAxMDAxOyByZXY6MTsgKQ0KICAgIGFsZXJ0IHRjcCBhbnkgYW55IC0+IGFu eSAkSFRUUF9QT1JUUyAoIG1zZzoiY2hlY2sgcGt0X2RhdGEtMiI7IGh0dHBfdXJpOyBjb250ZW50 OiIvaW5kZXgucGhwIjsgaHR0cF9oZWFkZXI7IGNvbnRlbnQ6IkFjY2VwdC1FbmNvZGluZzogZ3pp cCI7IHNpZDoxMDAwMTAwMjsgcmV2OjE7ICkNCiAgICBhbGVydCB0Y3AgYW55IGFueSAtPiBhbnkg JEhUVFBfUE9SVFMgKCBtc2c6ImNoZWNrIHBrdF9kYXRhLTMiOyBodHRwX2hlYWRlcjsgY29udGVu dDoiQWNjZXB0LUVuY29kaW5nOiBnemlwIjsgcGt0X2RhdGE7IGNvbnRlbnQ6Ii9pbmRleC5waHAi OyBzaWQ6MTAwMDEwMDM7IHJldjoxOyApDQpUaGUgcGNhcCBpcyBhdHRhY2hlZCB0byB0aGUgbWFp bC4NCg0KQmVzdCBSZWdhcmRzLA0KV3UgQ2hhbw0KDQoNCg0K --_000_LV8PR11MB8769CEA8BABB0E5032432D2CCF93ALV8PR11MB8769namp_ Content-Type: text/html; charset="gb2312" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dgb2312"> </head> <body> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> Hello Wu,</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> Thank you for reaching out to the Snort.</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> Regarding your questions we want to explain and give some recommendations.<= /div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> For configuration check you need use the next option "--dump-config-te= xt instead of "--help-config" because of:</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> --help-config - Shows available configuration options and their description= s (help/documentation).</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> --dump-config-text - Dumps the actual loaded configuration values.</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> Doc page: <u>https://github.com/snort3/snort3/blob/master/doc/user/dump_con= fig.txt</u></div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> According to your traffic, "/index.php" is present in the URI (li= ke GET /index.php), but your rule won't detect it there. The "pkt_data= " option searches in the message body, not in the URI itself. This mea= ns your rule will only trigger if "/index.php" also appears in the body content, which it doesn't in your case. </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> This happens because if you use, mixing "http_header" with "= pkt_data" (which inspects body content) creates a conflict in how the = rule processes the traffic.</div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> To resolve this, either use "http_uri" instead of "pkt_data&= quot; to inspect the URI or remove the "http_header" option to av= oid section conflicts. Also, you can split into separate rules if you inten= d to inspect both sections independently.</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> Doc page: <u>https://docs.snort.org/rules/options/payload/http/uri</u></div= > <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> Recommended rules:</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> alert http any any -> any $HTTP_PORTS ( msg:"check pkt_data-3"= ; http_header; content:"Accept-Encoding: gzip"; http_uri; content= :"/index.php"; sid:10001003; rev:1; )</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> Best regards,</div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> Viktor</div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"direction: ltr; font-family: Aptos, Arial, Helvetica, sans-se= rif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div id=3D"ms-outlook-mobile-signature"> <p style=3D"direction: ltr; margin: 0in 0in 0.0001pt; font-family: Aptos, s= ans-serif; font-size: 12pt;"> Get <a href=3D"https://aka.ms/GetOutlookForMac" data-outlook-id=3D"aff7c8ca= -f9a5-4de4-9e09-1c0cfceb23d2" style=3D"margin-top: 0px; margin-bottom: 0px;= "> Outlook for Mac </a></p> </div> <div id=3D"mail-editor-reference-message-container"> <div class=3D"ms-outlook-mobile-reference-message skipProofing" style=3D"di= rection: ltr;"> </div> <div class=3D"ms-outlook-mobile-reference-message skipProofing" style=3D"te= xt-align: left; padding: 3pt 0in 0in; border-width: 1pt medium medium; bord= er-style: solid none none; border-color: rgb(181, 196, 223) currentcolor cu= rrentcolor; font-family: Aptos; font-size: 12pt; color: black;"> <b>From: </b>Snort-users <[email protected]> on beh= alf of =CE=E2=B3=AC via Snort-users <[email protected]><br> <b>Date: </b>Tuesday, 13 January 2026 at 20:27<br> <b>To: </b>[email protected] <[email protected]><= br> <b>Subject: </b>[Snort-users] How to support keyword 'pkt_data' in snort ru= les<br> <br> </div> <div id=3D"spnEditorContent"> <div style=3D"margin: 0px;">Hi Snort experts,</div> <div style=3D"direction: ltr; margin: 0px;"><br> </div> <div style=3D"margin: 0px;">I have a question when using 'pkt_data' keyword= in snort rules.</div> <div style=3D"margin: 0px;">According to <a href=3D"https://docs.snort.org/= rules/options/payload/pkt_data" data-outlook-id=3D"31be8314-6898-467b-ab99-= 092c2dc05229"> https://docs.snort.org/rules/options/payload/pkt_data</a>, I need to set 's= earch_engine.detect_raw_tcp' to true to support 'pkt_data' in sonrt rules.&= nbsp;</div> <div style=3D"margin: 0px;">But after I added this setting to configuration= , it seems not working. </div> <div style=3D"margin: 0px;">Pls help to check why the configuration not che= nged in my working env, Thanks</div> <div style=3D"direction: ltr; margin: 0px;"><br> </div> <div style=3D"margin: 0px;">The snort version is v3.7.4.0. Here is what I t= ried:</div> <div style=3D"margin: 0px;">(1) add change to snort.lua file:</div> <div style=3D"margin: 0px;"> add "<i>include('max_datect.= lua')</i>" or "<i>search_engine.detect_raw_tcp =3D true</i>"= or "<i>search_engine =3D { detect_raw_tcp =3D true }</i>"</div> <div style=3D"margin: 0px;">(2) add parameter in command</div> <div style=3D"margin: 0px;"> add "<i>--lua 'search_engine= .detect_raw_tcp =3D true'</i>" or "<i>--tweaks max_detect</i>&quo= t;</div> <div style=3D"margin: 0px;">After doing above, I checked configuration by u= sing "<i>--help-config search_engine |grep tcp</i>", and get the = output:</div> <div style=3D"margin: 0px;"><span style=3D"background-color: rgb(255, 255, = 255);"> </span><span style=3D"background-color: rgb(255, 245, 102);">bool search_en= gine.detect_raw_tcp =3D <b>false</b>: detect on TCP payload before reassembly</span></div> <div style=3D"direction: ltr; margin: 0px;"><br> </div> <div style=3D"margin: 0px;">I also checked with some simple pcap with follo= wing snort rules, and seems no matter how the configuration changed, the 3r= d rule(with 'pkt_data' in rule) never matched:</div> <div style=3D"margin: 0px;"> alert tcp any any -> any $HTTP= _PORTS ( msg:"check pkt_data-1"; content:"/index.php"; = content:"Accept-Encoding: gzip"; sid:10001001; rev:1; )</div> <div style=3D"margin: 0px;"> alert tcp any any -> any $HTTP= _PORTS ( msg:"check pkt_data-2"; http_uri; content:"/index.p= hp"; http_header; content:"Accept-Encoding: gzip"; sid:10001= 002; rev:1; )</div> <div style=3D"margin: 0px;"> alert tcp any any -> any $HTTP= _PORTS ( msg:"check pkt_data-3"; http_header; content:"Accep= t-Encoding: gzip"; pkt_data; content:"/index.php"; sid:10001= 003; rev:1; )</div> <div style=3D"margin: 0px;">The pcap is attached to the mail.</div> <div style=3D"direction: ltr; margin: 0px;"><br> </div> </div> <div class=3D"ms-outlook-mobile-reference-message skipProofing" style=3D"li= ne-height: 1.7; margin: 0px; font-family: Arial; font-size: 14px; color: rg= b(0, 0, 0);"> Best Regards,</div> <div class=3D"ms-outlook-mobile-reference-message skipProofing" style=3D"li= ne-height: 1.7; margin: 0px; font-family: Arial; font-size: 14px; color: rg= b(0, 0, 0);"> Wu Chao</div> <pre><div class=3D"ms-outlook-mobile-reference-message skipProofing" style= =3D"line-height: 1.7; font-size: 14px; color: rgb(0, 0, 0);"><br>=0A= </div></pre> </div> </body> </html> --_000_LV8PR11MB8769CEA8BABB0E5032432D2CCF93ALV8PR11MB8769namp_-- --===============1597600876669623937== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============1597600876669623937==--