From mboxrd@z Thu Jan 1 00:00:00 1970 From: Stefan Schantl To: development@lists.ipfire.org Subject: [PATCH] suricata: Disable sid 2210059. Date: Wed, 08 Dec 2021 18:18:05 +0100 Message-ID: <20211208171805.309048-1-stefan.schantl@ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============8094277548105948666==" List-Id: --===============8094277548105948666== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable This rule emits a massive logspam and temporary will be disabled until a better solution is found. Fixes #12738. Signed-off-by: Stefan Schantl --- lfs/suricata | 1 + src/patches/suricata-disable-sid-2210059.patch | 12 ++++++++++++ 2 files changed, 13 insertions(+) create mode 100644 src/patches/suricata-disable-sid-2210059.patch diff --git a/lfs/suricata b/lfs/suricata index 96c2b33fe..6a24a02ab 100644 --- a/lfs/suricata +++ b/lfs/suricata @@ -71,6 +71,7 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) @$(PREBUILD) @rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar zxf $(DIR_DL)/$(DL_FILE) cd $(DIR_APP) && patch -Np1 < $(DIR_SRC)/src/patches/suricata-5.0-stream-tc= p-Handle-retransmitted-SYN-with-TSval.patch + cd $(DIR_APP) && patch -Np1 < $(DIR_SRC)/src/patches/suricata-disable-sid-2= 210059.patch cd $(DIR_APP) && LDFLAGS=3D"$(LDFLAGS)" ./configure \ --prefix=3D/usr \ --sysconfdir=3D/etc \ diff --git a/src/patches/suricata-disable-sid-2210059.patch b/src/patches/sur= icata-disable-sid-2210059.patch new file mode 100644 index 000000000..54747dfd2 --- /dev/null +++ b/src/patches/suricata-disable-sid-2210059.patch @@ -0,0 +1,12 @@ +diff -Nur a/rules/stream-events.rules b/rules/stream-events.rules +--- a/rules/stream-events.rules 2021-11-17 16:55:12.000000000 +0100 ++++ b/rules/stream-events.rules 2021-12-08 18:12:39.850189502 +0100 +@@ -89,7 +89,7 @@ + # rule to alert if a stream has excessive retransmissions + alert tcp any any -> any any (msg:"SURICATA STREAM excessive retransmission= s"; flowbits:isnotset,tcp.retransmission.alerted; flowint:tcp.retransmission.= count,>=3D,10; flowbits:set,tcp.retransmission.alerted; classtype:protocol-co= mmand-decode; sid:2210054; rev:1;) + # Packet on wrong thread. Fires at most once per flow. +-alert tcp any any -> any any (msg:"SURICATA STREAM pkt seen on wrong thread= "; stream-event:wrong_thread; sid:2210059; rev:1;) ++#alert tcp any any -> any any (msg:"SURICATA STREAM pkt seen on wrong threa= d"; stream-event:wrong_thread; sid:2210059; rev:1;) +=20 + # Packet with FIN+SYN set + alert tcp any any -> any any (msg:"SURICATA STREAM FIN SYN reuse"; stream-e= vent:fin_syn; classtype:protocol-command-decode; sid:2210060; rev:1;) --=20 2.30.2 --===============8094277548105948666==--