suricata/rules
Jason Ish c98c49d4ba dns: parse and alert on invalid opcodes
Accept DNS messages with an invalid opcode that are otherwise
valid. Such DNS message will create a parser event.

This is a change of behavior, previously an invalid opcode would cause
the DNS message to not be detected or parsed as DNS.

Issue: #5444
2023-01-24 10:44:49 +01:00
..
app-layer-events.rules app-layer: protocol change API 2017-05-08 10:43:36 +02:00
decoder-events.rules doc: fix typo lenght/length 2022-01-13 08:19:34 +01:00
dhcp-events.rules dhcp: add dhcp app-layer rules file 2018-06-16 06:42:28 -06:00
dnp3-events.rules rules: add missing classtypes for event.rules 2017-06-01 07:38:26 +02:00
dns-events.rules dns: parse and alert on invalid opcodes 2023-01-24 10:44:49 +01:00
files.rules rules: fix files.rules typo 2020-02-24 11:17:05 +01:00
http-events.rules protocol-change: sets event in case of failure 2022-08-23 13:50:36 +02:00
http2-events.rules http2: limits the number of active transactions per flow 2022-02-01 07:17:38 +01:00
ipsec-events.rules ike: set event for multiple server proposals 2021-05-04 10:36:54 +02:00
kerberos-events.rules Kerberos 5: rename weak crypto to weak encryption, and log it 2018-06-13 10:25:40 +02:00
Makefile.am quic: events and rules on them 2022-08-02 14:54:43 +02:00
modbus-events.rules rules: add missing classtypes for event.rules 2017-06-01 07:38:26 +02:00
mqtt-events.rules mqtt: raise event on parse error 2022-04-08 22:58:27 +02:00
nfs-events.rules nfs: limits the number of active transactions per flow 2022-02-16 14:24:37 +01:00
ntp-events.rules Add event rules for NTP events 2017-06-27 16:52:23 +02:00
quic-events.rules quic: events and rules on them 2022-08-02 14:54:43 +02:00
smb-events.rules smb: configurable max number of transactions per flow 2023-01-10 11:45:28 +01:00
smtp-events.rules protocol-change: sets event in case of failure 2022-08-23 13:50:36 +02:00
ssh-events.rules rules: add SSH decoder events rules 2020-05-22 08:40:01 +02:00
stream-events.rules stream/rules: disable depth rule by default 2022-10-04 10:48:56 +02:00
tls-events.rules rules/tls: sync with changes to the TLS events 2020-09-10 20:41:12 +02:00