43 #include "rust-bindings.h"
47 #define SSH_CONFIG_DEFAULT_HASSH false
49 #define SSH_CONFIG_DEFAULT_ENCRYPTION_BYPASS ENCRYPTION_HANDLING_TRACK_ONLY
51 static int SSHRegisterPatternsForProtocolDetection(
void)
54 IPPROTO_TCP,
ALPROTO_SSH,
"SSH-", 4, 0, STREAM_TOSERVER) < 0) {
58 IPPROTO_TCP,
ALPROTO_SSH,
"SSH-", 4, 0, STREAM_TOCLIENT) < 0) {
73 if (
p->
flow != NULL) {
77 if (FlowIsBypassed(
p->
flow)) {
81 return SCSshTxGetLogCondition(tx);
88 const char *proto_name =
"ssh";
92 if (SSHRegisterPatternsForProtocolDetection() < 0)
97 const char *strval = NULL;
100 }
else if (strcmp(strval,
"auto") == 0) {
115 if (encryption_node != NULL && encryption_node->
val != NULL) {
116 if (strcmp(encryption_node->
val,
"full") == 0) {
117 encryption_bypass = ENCRYPTION_HANDLING_FULL;
118 }
else if (strcmp(encryption_node->
val,
"track-only") == 0) {
119 encryption_bypass = ENCRYPTION_HANDLING_TRACK_ONLY;
120 }
else if (strcmp(encryption_node->
val,
"bypass") == 0) {
121 encryption_bypass = ENCRYPTION_HANDLING_BYPASS;
127 if (encryption_bypass) {
128 SCLogConfig(
"ssh: bypass on the start of encryption enabled");
129 SCSshEnableBypass(encryption_bypass);
134 SCRegisterSshParser();
150 static int SSHParserTestUtilCheck(
const char *protoexp,
const char *softexp,
void *tx, uint8_t
flags) {
153 const uint8_t *software = NULL;
157 printf(
"Version string not parsed correctly return: ");
161 printf(
"Version string not parsed correctly NULL: ");
165 if (p_len != strlen(protoexp)) {
166 printf(
"Version string not parsed correctly length: ");
169 if (memcmp(
protocol, protoexp, strlen(protoexp)) != 0) {
170 printf(
"Version string not parsed correctly: ");
174 if (softexp != NULL) {
175 if (SCSshTxGetSoftware(tx,
flags, &software, &s_len) != 1)
177 if (software == NULL)
179 if (s_len != strlen(softexp)) {
180 printf(
"Software string not parsed correctly length: ");
183 if (memcmp(software, softexp, strlen(softexp)) != 0) {
184 printf(
"Software string not parsed correctly: ");
192 static int SSHParserTest01(
void)
195 uint8_t sshbuf[] =
"SSH-2.0-MySSHClient-0.5.1\n";
196 uint32_t sshlen =
sizeof(sshbuf) - 1;
200 memset(&
f, 0,
sizeof(
f));
201 memset(&
ssn, 0,
sizeof(
ssn));
210 STREAM_TOSERVER | STREAM_EOF, sshbuf, sshlen);
216 void *tx = SCSshStateGetTx(ssh_state, 0);
218 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
219 FAIL_IF(SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOSERVER));
230 static int SSHParserTest02(
void)
234 uint8_t sshbuf[] =
"SSH-2.0-MySSHClient-0.5.1 some comments...\n";
235 uint32_t sshlen =
sizeof(sshbuf) - 1;
239 memset(&
f, 0,
sizeof(
f));
240 memset(&
ssn, 0,
sizeof(
ssn));
249 STREAM_TOSERVER | STREAM_EOF, sshbuf, sshlen);
251 printf(
"toclient chunk 1 returned %" PRId32
", expected 0: ", r);
256 if (ssh_state == NULL) {
257 printf(
"no ssh state: ");
260 void *tx = SCSshStateGetTx(ssh_state, 0);
262 if (SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex) {
263 printf(
"Client version string not parsed: ");
266 if (SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOSERVER))
281 static int SSHParserTest03(
void)
285 uint8_t sshbuf[] =
"SSH-2.0 some comments...\n";
286 uint32_t sshlen =
sizeof(sshbuf) - 1;
290 memset(&
f, 0,
sizeof(
f));
291 memset(&
ssn, 0,
sizeof(
ssn));
300 STREAM_TOSERVER | STREAM_EOF, sshbuf, sshlen);
302 printf(
"toclient chunk 1 returned %" PRId32
", expected != 0: ", r);
307 if (ssh_state == NULL) {
308 printf(
"no ssh state: ");
311 void *tx = SCSshStateGetTx(ssh_state, 0);
313 if (SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) == SshStateKex) {
314 printf(
"Client version string parsed? It's not a valid string: ");
317 const uint8_t *dummy = NULL;
318 uint32_t dummy_len = 0;
319 if (SCSshTxGetProtocol(tx, STREAM_TOSERVER, &dummy, &dummy_len) != 0)
321 if (SCSshTxGetSoftware(tx, STREAM_TOSERVER, &dummy, &dummy_len) != 0)
334 static int SSHParserTest04(
void)
338 uint8_t sshbuf[] =
"SSH-2.0-MySSHClient-0.5.1\n";
339 uint32_t sshlen =
sizeof(sshbuf) - 1;
343 memset(&
f, 0,
sizeof(
f));
344 memset(&
ssn, 0,
sizeof(
ssn));
353 STREAM_TOCLIENT | STREAM_EOF, sshbuf, sshlen);
355 printf(
"toserver chunk 1 returned %" PRId32
", expected 0: ", r);
360 if (ssh_state == NULL) {
361 printf(
"no ssh state: ");
364 void *tx = SCSshStateGetTx(ssh_state, 0);
366 if (SCSshTxGetAlStateProgress(tx, STREAM_TOCLIENT) != SshStateKex) {
367 printf(
"Client version string not parsed: ");
370 if (SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOCLIENT))
385 static int SSHParserTest05(
void)
389 uint8_t sshbuf[] =
"SSH-2.0-MySSHClient-0.5.1 some comments...\n";
390 uint32_t sshlen =
sizeof(sshbuf) - 1;
394 memset(&
f, 0,
sizeof(
f));
395 memset(&
ssn, 0,
sizeof(
ssn));
404 STREAM_TOCLIENT | STREAM_EOF, sshbuf, sshlen);
406 printf(
"toserver chunk 1 returned %" PRId32
", expected 0: ", r);
411 if (ssh_state == NULL) {
412 printf(
"no ssh state: ");
415 void *tx = SCSshStateGetTx(ssh_state, 0);
417 if (SCSshTxGetAlStateProgress(tx, STREAM_TOCLIENT) != SshStateKex) {
418 printf(
"Client version string not parsed: ");
421 if (SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOCLIENT))
435 static int SSHParserTest06(
void)
439 uint8_t sshbuf[] =
"SSH-2.0 some comments...\n";
440 uint32_t sshlen =
sizeof(sshbuf) - 1;
444 memset(&
f, 0,
sizeof(
f));
445 memset(&
ssn, 0,
sizeof(
ssn));
454 STREAM_TOCLIENT | STREAM_EOF, sshbuf, sshlen);
456 printf(
"toserver chunk 1 returned %" PRId32
", expected != 0: ", r);
462 if (ssh_state == NULL) {
463 printf(
"no ssh state: ");
466 void *tx = SCSshStateGetTx(ssh_state, 0);
468 if (SCSshTxGetAlStateProgress(tx, STREAM_TOCLIENT) == SshStateKex) {
469 printf(
"Client version string parsed? It's not a valid string: ");
472 const uint8_t *dummy = NULL;
473 uint32_t dummy_len = 0;
474 if (SCSshTxGetProtocol(tx, STREAM_TOCLIENT, &dummy, &dummy_len) != 0)
476 if (SCSshTxGetSoftware(tx, STREAM_TOCLIENT, &dummy, &dummy_len) != 0)
488 #define MAX_SSH_TEST_SIZE 512
490 static int SSHParserTest07(
void)
500 memset(&
tv, 0x00,
sizeof(
tv));
520 for (
int i=0; i<2; i++) {
522 seq += strlen(sshbufs[i]);
528 void *tx = SCSshStateGetTx(ssh_state, 0);
529 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
531 FAIL_IF(SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOSERVER));
541 static int SSHParserTest08(
void)
551 memset(&
tv, 0x00,
sizeof(
tv));
571 for (
int i=0; i<3; i++) {
573 seq += strlen(sshbufs[i]);
579 void *tx = SCSshStateGetTx(ssh_state, 0);
580 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
582 FAIL_IF(SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOSERVER));
591 static int SSHParserTest09(
void)
601 memset(&
tv, 0x00,
sizeof(
tv));
621 for (
int i=0; i<2; i++) {
623 seq += strlen(sshbufs[i]);
629 void *tx = SCSshStateGetTx(ssh_state, 0);
630 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOCLIENT) != SshStateKex);
632 FAIL_IF(SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOCLIENT));
642 static int SSHParserTest10(
void)
652 memset(&
tv, 0x00,
sizeof(
tv));
672 for (
int i=0; i<3; i++) {
674 seq += strlen(sshbufs[i]);
680 void *tx = SCSshStateGetTx(ssh_state, 0);
681 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOCLIENT) != SshStateKex);
683 FAIL_IF(SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOCLIENT));
693 static int SSHParserTest11(
void)
697 uint8_t sshbuf1[] =
"SSH-2.0-MySSHClient-0.5.1\r\n";
698 uint32_t sshlen1 =
sizeof(sshbuf1) - 1;
699 uint8_t sshbuf2[] = { 0x00, 0x00, 0x00, 0x03, 0x01, 21, 0x00};
700 uint32_t sshlen2 =
sizeof(sshbuf2);
704 memset(&
f, 0,
sizeof(
f));
705 memset(&
ssn, 0,
sizeof(
ssn));
714 STREAM_TOSERVER, sshbuf1, sshlen1);
716 printf(
"toserver chunk 1 returned %" PRId32
", expected 0: ", r);
722 printf(
"toserver chunk 2 returned %" PRId32
", expected 0: ", r);
727 if (ssh_state == NULL) {
728 printf(
"no ssh state: ");
731 void *tx = SCSshStateGetTx(ssh_state, 0);
732 if (SCSshTxGetFlags(tx, STREAM_TOSERVER) != SshStateSession) {
733 printf(
"Didn't detect the msg code of new keys (ciphered data starts): ");
736 if (SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOSERVER))
749 static int SSHParserTest12(
void)
753 uint8_t sshbuf1[] =
"SSH-2.0-MySSHClient-0.5.1\r\n";
754 uint32_t sshlen1 =
sizeof(sshbuf1) - 1;
755 uint8_t sshbuf2[] = { 0x00, 0x00, 0x00, 0x03,0x01, 17, 0x00};
756 uint32_t sshlen2 =
sizeof(sshbuf2);
757 uint8_t sshbuf3[] = { 0x00, 0x00, 0x00, 0x03,0x01, 21, 0x00};
758 uint32_t sshlen3 =
sizeof(sshbuf3);
762 memset(&
f, 0,
sizeof(
f));
763 memset(&
ssn, 0,
sizeof(
ssn));
772 STREAM_TOSERVER, sshbuf1, sshlen1);
774 printf(
"toserver chunk 1 returned %" PRId32
", expected 0: ", r);
780 printf(
"toserver chunk 2 returned %" PRId32
", expected 0: ", r);
786 printf(
"toserver chunk 3 returned %" PRId32
", expected 0: ", r);
791 if (ssh_state == NULL) {
792 printf(
"no ssh state: ");
795 void *tx = SCSshStateGetTx(ssh_state, 0);
796 if (SCSshTxGetFlags(tx, STREAM_TOSERVER) != SshStateSession) {
797 printf(
"Didn't detect the msg code of new keys (ciphered data starts): ");
800 if (SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOSERVER))
813 static int SSHParserTest13(
void)
821 uint8_t sshbuf1[] =
"SSH-2.0-MySSHClient-0.5.1\r\n";
822 uint8_t sshbuf2[] = { 0x00, 0x00, 0x00, 0x02, 0x01, 17};
823 uint8_t sshbuf3[] = { 0x00, 0x00, 0x00, 0x02, 0x01, 21};
825 uint8_t* sshbufs[3] = {sshbuf1, sshbuf2, sshbuf3};
826 uint32_t sshlens[3] = {
sizeof(sshbuf1) - 1,
sizeof(sshbuf2),
sizeof(sshbuf3)};
828 memset(&
tv, 0x00,
sizeof(
tv));
848 for (
int i=0; i<3; i++) {
856 void *tx = SCSshStateGetTx(ssh_state, 0);
857 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOSERVER) != SshStateSession);
859 FAIL_IF(SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOSERVER));
869 static int SSHParserTest14(
void)
877 uint8_t sshbuf1[] =
"SSH-2.0-MySSHClient-0.5.1\r\n";
878 uint8_t sshbuf2[] = { 0x00, 0x00, 0x00, 0x10, 0x01, 17, 0x00};
879 uint8_t sshbuf3[] = { 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08};
880 uint8_t sshbuf4[] = { 0x09, 0x10, 0x11, 0x12, 0x13, 0x00};
882 uint8_t sshbuf5[] = { 0x00, 0x00, 0x02, 0x01, 21};
884 uint8_t* sshbufs[5] = {sshbuf1, sshbuf2, sshbuf3, sshbuf4, sshbuf5};
885 uint32_t sshlens[5] = {
sizeof(sshbuf1) - 1,
sizeof(sshbuf2),
sizeof(sshbuf3),
sizeof(sshbuf4),
sizeof(sshbuf5)};
887 memset(&
tv, 0x00,
sizeof(
tv));
907 for (
int i=0; i<5; i++) {
915 void *tx = SCSshStateGetTx(ssh_state, 0);
916 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOSERVER) != SshStateSession);
918 FAIL_IF(SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOSERVER));
928 static int SSHParserTest15(
void)
936 uint8_t sshbuf1[] =
"SSH-2.0-MySSHClient-0.5.1\r\n";
937 uint8_t sshbuf2[] = { 0x00, 0x00, 0x00, 0x10, 0x01, 17, 0x00};
938 uint8_t sshbuf3[] = { 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08};
939 uint8_t sshbuf4[] = { 0x09, 0x10, 0x11, 0x12, 0x13, 0x00};
940 uint8_t sshbuf5[] = { 0x00, 0x00, 0x02, 0x01, 20, 0x00, 0x00, 0x00, 0x02, 0x01, 21};
942 uint8_t* sshbufs[5] = {sshbuf1, sshbuf2, sshbuf3, sshbuf4, sshbuf5};
943 uint32_t sshlens[5] = {
sizeof(sshbuf1) - 1,
sizeof(sshbuf2),
sizeof(sshbuf3),
sizeof(sshbuf4),
sizeof(sshbuf5)};
945 memset(&
tv, 0x00,
sizeof(
tv));
965 for (
int i=0; i<5; i++) {
973 void *tx = SCSshStateGetTx(ssh_state, 0);
974 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOSERVER) != SshStateSession);
976 FAIL_IF(SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOSERVER));
986 static int SSHParserTest16(
void)
994 uint8_t sshbuf1[] =
"SSH-";
995 uint8_t sshbuf2[] =
"2.0-MySSHClient-0.5.1\r\n";
996 uint8_t sshbuf3[] = { 0x00, 0x00, 0x00, 0x03,0x01, 21, 0x00};
998 uint8_t* sshbufs[3] = {sshbuf1, sshbuf2, sshbuf3};
999 uint32_t sshlens[3] = {
sizeof(sshbuf1) - 1,
sizeof(sshbuf2) - 1,
sizeof(sshbuf3)};
1001 memset(&
tv, 0x00,
sizeof(
tv));
1009 f =
UTHBuildFlow(AF_INET,
"1.1.1.1",
"2.2.2.2", 1234, 2222);
1021 for (
int i=0; i<3; i++) {
1029 void *tx = SCSshStateGetTx(ssh_state, 0);
1030 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOCLIENT) != SshStateSession);
1032 FAIL_IF(SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOCLIENT));
1042 static int SSHParserTest17(
void)
1050 uint8_t sshbuf1[] =
"SSH-";
1051 uint8_t sshbuf2[] =
"2.0-MySSHClient-0.5.1\r\n";
1052 uint8_t sshbuf3[] = { 0x00, 0x00, 0x00, 0x03, 0x01, 17, 0x00};
1053 uint8_t sshbuf4[] = { 0x00, 0x00, 0x00, 0x03, 0x01, 21, 0x00};
1055 uint8_t* sshbufs[4] = {sshbuf1, sshbuf2, sshbuf3, sshbuf4};
1056 uint32_t sshlens[4] = {
sizeof(sshbuf1) - 1,
sizeof(sshbuf2) - 1,
sizeof(sshbuf3),
sizeof(sshbuf4)};
1058 memset(&
tv, 0x00,
sizeof(
tv));
1066 f =
UTHBuildFlow(AF_INET,
"1.1.1.1",
"2.2.2.2", 1234, 2222);
1078 for (
int i=0; i<4; i++) {
1086 void *tx = SCSshStateGetTx(ssh_state, 0);
1087 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOCLIENT) != SshStateSession);
1089 FAIL_IF(SSHParserTestUtilCheck(
"2.0",
"MySSHClient-0.5.1", tx, STREAM_TOCLIENT));
1099 static int SSHParserTest18(
void)
1107 uint8_t server1[] =
"SSH-2.0-OpenSSH_4.7p1 Debian-8ubuntu3\r\n";
1108 uint8_t sshbuf1[] =
"SSH-";
1109 uint8_t sshbuf2[] =
"2.0-MySSHClient-0.5.1\r\n";
1110 uint8_t server2[] = { 0x00, 0x00, 0x00, 0x03, 0x01, 21, 0x00 };
1111 uint8_t sshbuf3[] = { 0x00, 0x00, 0x00, 0x03, 0x01, 21, 0x00 };
1114 memset(&
tv, 0x00,
sizeof(
tv));
1122 uint8_t* sshbufs[5] = {server1, sshbuf1, sshbuf2, server2, sshbuf3};
1123 uint32_t sshlens[5] = {
sizeof(server1) - 1,
sizeof(sshbuf1) - 1,
sizeof(sshbuf2) -1,
sizeof(server2) - 1,
sizeof(sshbuf3)};
1124 bool sshdirs[5] = {
true,
false,
false,
true,
false};
1126 f =
UTHBuildFlow(AF_INET,
"1.1.1.1",
"2.2.2.2", 1234, 2222);
1137 uint32_t seqcli = 2;
1138 uint32_t seqsrv = 2;
1139 for (
int i=0; i<5; i++) {
1142 seqsrv += sshlens[i];
1146 seqcli += sshlens[i];
1153 void *tx = SCSshStateGetTx(ssh_state, 0);
1154 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOCLIENT) != SshStateSession);
1166 static int SSHParserTest19(
void)
1174 uint8_t sshbuf1[] =
"SSH-";
1175 uint8_t sshbuf2[] =
"2.0-";
1176 uint8_t sshbuf3[] =
"abcdefghijklmnopqrstuvwxyz"
1177 "abcdefghijklmnopqrstuvwxyz"
1178 "abcdefghijklmnopqrstuvwxyz"
1179 "abcdefghijklmnopqrstuvwxyz"
1180 "abcdefghijklmnopqrstuvwxyz"
1181 "abcdefghijklmnopqrstuvwxyz"
1182 "abcdefghijklmnopqrstuvwxyz"
1183 "abcdefghijklmnopqrstuvwxyz"
1184 "abcdefghijklmnopqrstuvwxyz"
1186 uint8_t sshbuf4[] = { 0x00, 0x00, 0x00, 0x03, 0x01, 21, 0x00};
1188 uint8_t* sshbufs[4] = {sshbuf1, sshbuf2, sshbuf3, sshbuf4};
1189 uint32_t sshlens[4] = {
sizeof(sshbuf1) - 1,
sizeof(sshbuf2) - 1,
sizeof(sshbuf3) - 1,
sizeof(sshbuf4)};
1191 memset(&
tv, 0x00,
sizeof(
tv));
1199 f =
UTHBuildFlow(AF_INET,
"1.1.1.1",
"2.2.2.2", 1234, 2222);
1211 for (
int i=0; i<4; i++) {
1219 void *tx = SCSshStateGetTx(ssh_state, 0);
1220 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOCLIENT) != SshStateSession);
1222 sshbuf3[
sizeof(sshbuf3) - 2] = 0;
1223 FAIL_IF(SSHParserTestUtilCheck(
"2.0", (
char *)sshbuf3, tx, STREAM_TOCLIENT));
1234 static int SSHParserTest20(
void)
1242 uint8_t sshbuf1[] =
"SSH-";
1243 uint8_t sshbuf2[] =
"2.0-";
1244 uint8_t sshbuf3[] =
"abcdefghijklmnopqrstuvwxyz"
1245 "abcdefghijklmnopqrstuvwxyz"
1246 "abcdefghijklmnopqrstuvwxyz"
1247 "abcdefghijklmnopqrstuvwxyz"
1248 "abcdefghijklmnopqrstuvwxyz"
1249 "abcdefghijklmnopqrstuvwxyz"
1250 "abcdefghijklmnopqrstuvwxyz"
1251 "abcdefghijklmnopqrstuvwxyz"
1252 "abcdefghijklmnopqrstuvwxyz"
1254 uint8_t sshbuf4[] = {
'a',
'b',
'c',
'd',
'e',
'f',
'\r',
1255 0x00, 0x00, 0x00, 0x06, 0x01, 21, 0x00, 0x00, 0x00};
1257 uint8_t* sshbufs[4] = {sshbuf1, sshbuf2, sshbuf3, sshbuf4};
1258 uint32_t sshlens[4] = {
sizeof(sshbuf1) - 1,
sizeof(sshbuf2) - 1,
sizeof(sshbuf3) - 1,
sizeof(sshbuf4) - 1};
1260 memset(&
tv, 0x00,
sizeof(
tv));
1268 f =
UTHBuildFlow(AF_INET,
"1.1.1.1",
"2.2.2.2", 1234, 2222);
1280 for (
int i=0; i<4; i++) {
1288 void *tx = SCSshStateGetTx(ssh_state, 0);
1289 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOCLIENT) != SshStateSession);
1291 FAIL_IF(SSHParserTestUtilCheck(
"2.0", NULL, tx, STREAM_TOCLIENT));
1302 static int SSHParserTest21(
void)
1310 uint8_t sshbuf1[] =
"SSH-";
1311 uint8_t sshbuf2[] =
"2.0-";
1312 uint8_t sshbuf3[] =
"abcdefghijklmnopqrstuvwxyz"
1313 "abcdefghijklmnopqrstuvwxyz"
1314 "abcdefghijklmnopqrstuvwxyz"
1315 "abcdefghijklmnopqrstuvwxyz"
1316 "abcdefghijklmnopqrstuvwxyz"
1317 "abcdefghijklmnopqrstuvwxyz"
1318 "abcdefghijklmnopqrstuvwxyz"
1319 "abcdefghijklmnopqrstuvwxyz"
1320 "abcdefghijklmnopqrstuvwxy";
1321 uint8_t sshbuf4[] = {
'l',
'i',
'b',
's',
's',
'h',
'\r',
1322 0x00, 0x00, 0x00, 0x06, 0x01, 21, 0x00, 0x00, 0x00};
1324 uint8_t* sshbufs[4] = {sshbuf1, sshbuf2, sshbuf3, sshbuf4};
1325 uint32_t sshlens[4] = {
sizeof(sshbuf1) - 1,
sizeof(sshbuf2) - 1,
sizeof(sshbuf3) - 1,
sizeof(sshbuf4)};
1327 memset(&
tv, 0x00,
sizeof(
tv));
1335 f =
UTHBuildFlow(AF_INET,
"1.1.1.1",
"2.2.2.2", 1234, 2222);
1347 for (
int i=0; i<4; i++) {
1355 void *tx = SCSshStateGetTx(ssh_state, 0);
1356 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOCLIENT) != SshStateSession);
1358 FAIL_IF(SSHParserTestUtilCheck(
"2.0", NULL, tx, STREAM_TOCLIENT));
1369 static int SSHParserTest22(
void)
1377 uint8_t sshbuf1[] =
"SSH-";
1378 uint8_t sshbuf2[] =
"2.0-";
1379 uint8_t sshbuf3[] = {
1380 'l',
'i',
'b',
's',
's',
'h',
'\r',
1382 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17,
1383 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00,
1384 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00,
1387 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17,
1388 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00,
1389 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00,
1392 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17,
1393 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00,
1394 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00,
1397 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17,
1398 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00,
1399 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00,
1402 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17,
1403 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00,
1404 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00,
1407 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17,
1408 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00,
1409 0x00, 0x00, 0x06, 0x01, 17, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x01, 21, 0x00,
1413 uint8_t *sshbufs[3] = { sshbuf1, sshbuf2, sshbuf3 };
1414 uint32_t sshlens[3] = {
sizeof(sshbuf1) - 1,
sizeof(sshbuf2) - 1,
sizeof(sshbuf3) - 1 };
1416 memset(&
tv, 0x00,
sizeof(
tv));
1424 f =
UTHBuildFlow(AF_INET,
"1.1.1.1",
"2.2.2.2", 1234, 2222);
1436 for (
int i = 0; i < 3; i++) {
1446 void *tx = SCSshStateGetTx(ssh_state, 0);
1447 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOCLIENT) != SshStateSession);
1449 FAIL_IF(SSHParserTestUtilCheck(
"2.0",
"libssh", tx, STREAM_TOCLIENT));
1459 static int SSHParserTest23(
void)
1463 uint8_t sshbuf[] =
"SSH-2.0\r-MySSHClient-0.5.1\n";
1464 uint32_t sshlen =
sizeof(sshbuf) - 1;
1468 memset(&
f, 0,
sizeof(
f));
1469 memset(&
ssn, 0,
sizeof(
ssn));
1478 STREAM_TOSERVER | STREAM_EOF, sshbuf, sshlen);
1480 printf(
"toclient chunk 1 returned 0 expected non null: ");
1494 static int SSHParserTest24(
void)
1498 uint8_t sshbuf[] =
"SSH-2.0-\rMySSHClient-0.5.1\n";
1499 uint32_t sshlen =
sizeof(sshbuf) - 1;
1503 memset(&
f, 0,
sizeof(
f));
1504 memset(&
ssn, 0,
sizeof(
ssn));
1513 STREAM_TOSERVER | STREAM_EOF, sshbuf, sshlen);
1515 printf(
"toclient chunk 1 returned %" PRId32
", expected 0: ", r);
1520 if (ssh_state == NULL) {
1521 printf(
"no ssh state: ");
1524 void *tx = SCSshStateGetTx(ssh_state, 0);
1525 if (SCSshTxGetFlags(tx, STREAM_TOSERVER) != SshStateKex) {
1526 printf(
"Didn't detect the msg code of new keys (ciphered data starts): ");
1529 if (SSHParserTestUtilCheck(
"2.0", NULL, tx, STREAM_TOSERVER))
1542 static int SSHParserTest25(
void)
1545 uint8_t sshbuf[] =
"\n";
1546 uint32_t sshlen =
sizeof(sshbuf) - 1;
1551 memset(&
f, 0,
sizeof(
f));
1552 memset(&
ssn, 0,
sizeof(
ssn));
1561 STREAM_TOSERVER | STREAM_EOF, sshbuf, sshlen);
1566 void *tx = SCSshStateGetTx(ssh_state, 0);
1567 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOSERVER) == SshStateKex);
1568 const uint8_t *dummy = NULL;
1569 uint32_t dummy_len = 0;
1570 FAIL_IF(SCSshTxGetSoftware(tx, STREAM_TOCLIENT, &dummy, &dummy_len) != 0);
1581 static int SSHParserTest26(
void)
1585 IPPROTO_TCP,
ALPROTO_SSH,
"request_banner", STREAM_TOSERVER) != SshStateBanner);
1587 IPPROTO_TCP,
ALPROTO_SSH,
"request_kex", STREAM_TOSERVER) != SshStateKex);
1589 STREAM_TOSERVER) != SshStateSession);
1591 STREAM_TOCLIENT) != SshStateBanner);
1593 STREAM_TOCLIENT) != SshStateSession);
1598 IPPROTO_TCP,
ALPROTO_SSH,
"request_in_progress", STREAM_TOSERVER) != -1);
1600 IPPROTO_TCP,
ALPROTO_SSH,
"request_banner_done", STREAM_TOSERVER) != -1);
1602 IPPROTO_TCP,
ALPROTO_SSH,
"request_finished", STREAM_TOSERVER) != -1);
1604 IPPROTO_TCP,
ALPROTO_SSH,
"response_finished", STREAM_TOCLIENT) != -1);
1608 IPPROTO_TCP,
ALPROTO_SSH,
"request_done", STREAM_TOSERVER) != -1);
1610 IPPROTO_TCP,
ALPROTO_SSH,
"response_done", STREAM_TOCLIENT) != -1);
1615 IPPROTO_TCP,
ALPROTO_SSH,
"request_nosuchstate", STREAM_TOSERVER) != -1);
1617 IPPROTO_TCP,
ALPROTO_SSH,
"request_banner_wait_eol", STREAM_TOSERVER) != -1);
1619 IPPROTO_TCP,
ALPROTO_SSH,
"response_banner", STREAM_TOSERVER) != -1);
1623 IPPROTO_TCP,
ALPROTO_SSH, SshStateBanner, STREAM_TOSERVER),
1624 "request_banner") != 0);
1626 IPPROTO_TCP,
ALPROTO_SSH, SshStateKex, STREAM_TOSERVER),
1627 "request_kex") != 0);
1629 IPPROTO_TCP,
ALPROTO_SSH, SshStateSession, STREAM_TOSERVER),
1630 "request_session") != 0);
1634 IPPROTO_TCP,
ALPROTO_SSH, SshStateDone, STREAM_TOSERVER) != NULL);
1636 IPPROTO_TCP,
ALPROTO_SSH, SshStateDone, STREAM_TOCLIENT) != NULL);
1645 static int SSHParserTest27(
void)
1648 uint8_t sshbuf1[] =
"SSH-2.0-MySSHClient-0.5.1\r\n";
1649 uint32_t sshlen1 =
sizeof(sshbuf1) - 1;
1650 uint8_t sshbuf2[] = { 0x00, 0x00, 0x00, 0x03, 0x01, 21, 0x00 };
1651 uint32_t sshlen2 =
sizeof(sshbuf2);
1656 memset(&
f, 0,
sizeof(
f));
1657 memset(&
ssn, 0,
sizeof(
ssn));
1672 void *tx = SCSshStateGetTx(ssh_state, 0);
1673 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateSession);
1674 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOCLIENT) != SshStateBanner);
1688 static int SSHParserTest28(
void)
1691 uint8_t badbanner[] =
"SSH-bogus\r\n";
1692 uint32_t badbannerlen =
sizeof(badbanner) - 1;
1693 uint8_t banner[] =
"SSH-2.0-TestClient-1.0\r\n";
1694 uint32_t bannerlen =
sizeof(banner) - 1;
1695 uint8_t badrecord[] = { 0x00, 0x00, 0x00, 0x00, 0x08, 0x21, 0x00, 0x00 };
1696 uint32_t badrecordlen =
sizeof(badrecord);
1702 memset(&
f, 0,
sizeof(
f));
1703 memset(&
ssn, 0,
sizeof(
ssn));
1716 void *tx = SCSshStateGetTx(ssh_state, 0);
1717 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateBanner);
1718 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOCLIENT) != SshStateBanner);
1728 tx = SCSshStateGetTx(ssh_state, 0);
1729 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateBanner);
1730 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOCLIENT) != SshStateBanner);
1735 memset(&
f, 0,
sizeof(
f));
1736 memset(&
ssn, 0,
sizeof(
ssn));
1749 tx = SCSshStateGetTx(ssh_state, 0);
1750 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
1759 uint8_t newkeys[] = { 0x00, 0x00, 0x00, 0x03, 0x01, 21, 0x00 };
1763 tx = SCSshStateGetTx(ssh_state, 0);
1764 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
1780 static int SSHParserTest29(
void)
1786 uint8_t banner[] =
"SSH-2.0-Client-1.0\r\n";
1787 uint8_t seg2[] = { 0x00, 0x00, 0x00, 29, 0x00, 50, 0x61, 0x62, 0x63, 0x64, 0x65, 0x66, 0x67,
1789 uint8_t seg3[4] = { 0x6b, 0x6c, 0x6d, 0x6e };
1790 uint8_t seg4[13] = { 0x6f, 0x70, 0x71, 0x72, 0x73, 0x74, 0x75, 0x76, 0x77, 0x78, 0x79, 0x7a,
1792 uint8_t seg5[3] = { 0x7c, 0x7d, 0x7e };
1798 memset(&
f, 0,
sizeof(
f));
1799 memset(&
ssn, 0,
sizeof(
ssn));
1813 tx = SCSshStateGetTx(
f.
alstate, 0);
1814 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
1842 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
1857 static int SSHParserTest30(
void)
1862 uint8_t longbanner[300];
1864 uint8_t badrecord[] = { 0x00, 0x00, 0x00, 0x00, 0x08, 0x21, 0x00, 0x00 };
1867 memset(&
f, 0,
sizeof(
f));
1868 memset(&
ssn, 0,
sizeof(
ssn));
1882 memset(longbanner,
'A',
sizeof(longbanner));
1883 memcpy(longbanner,
"SSH-2.0-", 8);
1888 tx = SCSshStateGetTx(
f.
alstate, 0);
1889 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateBanner);
1895 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
1900 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
1901 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOCLIENT) != SshStateBanner);
1906 memset(&
ssn, 0,
sizeof(
ssn));
1907 memset(&
f, 0,
sizeof(
f));
1912 memset(junk,
'X',
sizeof(junk));
1916 tx = SCSshStateGetTx(
f.
alstate, 0);
1917 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateBanner);
1918 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOCLIENT) != SshStateBanner);
1937 static int SSHParserTest31(
void)
1940 uint8_t badbanner[] =
"SSH-bogus\r\n";
1941 uint32_t badbannerlen =
sizeof(badbanner) - 1;
1942 uint8_t banner[] =
"SSH-2.0-TestClient-1.0\r\n";
1943 uint32_t bannerlen =
sizeof(banner) - 1;
1949 memset(&
f, 0,
sizeof(
f));
1950 memset(&
ssn, 0,
sizeof(
ssn));
1963 void *tx = SCSshStateGetTx(ssh_state, 0);
1964 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateBanner);
1965 FAIL_IF(SCSshTxGetLogCondition(tx) !=
true);
1972 memset(&
f, 0,
sizeof(
f));
1973 memset(&
ssn, 0,
sizeof(
ssn));
1983 tx = SCSshStateGetTx(ssh_state, 0);
1984 FAIL_IF(SCSshTxGetLogCondition(tx) !=
false);
1992 memset(&
f, 0,
sizeof(
f));
1993 memset(&
ssn, 0,
sizeof(
ssn));
2005 tx = SCSshStateGetTx(ssh_state, 0);
2006 FAIL_IF(SCSshTxGetLogCondition(tx) !=
false);
2009 uint8_t badrecord[] = { 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 };
2013 FAIL_IF(SCSshTxGetLogCondition(tx) !=
true);
2025 static int SSHParserTest32(
void)
2033 uint8_t part1[] =
"SSH-2.0-TestClient-1.0";
2034 uint8_t part2[] =
"\r\n";
2035 uint32_t part1len =
sizeof(part1) - 1;
2036 uint32_t part2len =
sizeof(part2) - 1;
2038 memset(&
tv, 0x00,
sizeof(
tv));
2046 f =
UTHBuildFlow(AF_INET,
"1.1.1.1",
"2.2.2.2", 1234, 2222);
2057 uint32_t seqcli = 2;
2067 void *tx = SCSshStateGetTx(ssh_state, 0);
2079 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
2093 static int SSHParserTest33(
void)
2096 uint8_t badbanner[] =
"SSH-bogus\r\n";
2097 uint32_t badbannerlen =
sizeof(badbanner) - 1;
2098 uint8_t banner[] =
"SSH-2.0-TestClient-1.0\r\n";
2099 uint32_t bannerlen =
sizeof(banner) - 1;
2100 uint8_t newkeys[] = { 0x00, 0x00, 0x00, 0x03, 0x01, 21, 0x00 };
2101 uint32_t newkeyslen =
sizeof(newkeys);
2106 memset(&
f, 0,
sizeof(
f));
2107 memset(&
ssn, 0,
sizeof(
ssn));
2125 void *tx = SCSshStateGetTx(ssh_state, 0);
2126 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOSERVER) != SshStateBanner);
2127 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOCLIENT) != SshStateSession);
2145 static int SSHParserTest34(
void)
2153 uint8_t cli_banner[] =
"SSH-2.0-TestClient-1.0\r\n";
2154 uint32_t cli_bannerlen =
sizeof(cli_banner) - 1;
2155 uint8_t srv_banner[] =
"SSH-2.0-TestServer-1.0\r\n";
2156 uint32_t srv_bannerlen =
sizeof(srv_banner) - 1;
2157 uint8_t badrecord[] = { 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 };
2158 uint32_t badrecordlen =
sizeof(badrecord);
2159 uint8_t newkeys[] = { 0x00, 0x00, 0x00, 0x03, 0x01, 21, 0x00 };
2160 uint32_t newkeyslen =
sizeof(newkeys);
2162 memset(&
tv, 0x00,
sizeof(
tv));
2170 f =
UTHBuildFlow(AF_INET,
"1.1.1.1",
"2.2.2.2", 1234, 2222);
2182 uint32_t seqsrv = 2;
2184 &
tv, ra_ctx, &
ssn.
server, seqsrv, srv_banner, srv_bannerlen) == -1);
2185 seqsrv += srv_bannerlen;
2187 uint32_t seqcli = 2;
2191 &
tv, ra_ctx, &
ssn.
client, seqcli, cli_banner, cli_bannerlen) == -1);
2192 seqcli += cli_bannerlen;
2197 void *tx = SCSshStateGetTx(ssh_state, 0);
2198 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
2203 &
tv, ra_ctx, &
ssn.
client, seqcli, badrecord, badrecordlen) == -1);
2204 seqcli += badrecordlen;
2210 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
2223 &
tv, ra_ctx, &
ssn.
client, seqcli, newkeys, newkeyslen) == -1);
2224 seqcli += newkeyslen;
2228 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOSERVER) != SshStateKex);
2229 FAIL_IF(SCSshTxGetAlStateProgress(tx, STREAM_TOCLIENT) != SshStateBanner);
2248 static int SSHParserTest35(
void)
2251 uint8_t banner[] =
"SSH-2.0-TestClient-1.0\r\n";
2252 uint32_t bannerlen =
sizeof(banner) - 1;
2253 uint8_t newkeys[] = { 0x00, 0x00, 0x00, 0x03, 0x01, 21, 0x00 };
2254 uint8_t newkeys_hdr[6] = { 0x00, 0x00, 0x00, 0x03, 0x01, 21 };
2255 uint8_t newkeys_body[1] = { 0x00 };
2260 memset(&
f, 0,
sizeof(
f));
2261 memset(&
ssn, 0,
sizeof(
ssn));
2281 void *tx = SCSshStateGetTx(ssh_state, 0);
2282 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOCLIENT) != SshStateSession);
2289 tx = SCSshStateGetTx(ssh_state, 0);
2290 FAIL_IF(SCSshTxGetFlags(tx, STREAM_TOSERVER) != SshStateSession);
2303 SCSshEnableBypass(ENCRYPTION_HANDLING_BYPASS);
2304 memset(&
f, 0,
sizeof(
f));
2305 memset(&
ssn, 0,
sizeof(
ssn));
2322 SCSshEnableBypass(ENCRYPTION_HANDLING_TRACK_ONLY);
2341 UtRegisterTest(
"SSHParserTest07 - ToServer 2 chunks", SSHParserTest07);
2342 UtRegisterTest(
"SSHParserTest08 - ToServer 3 chunks", SSHParserTest08);
2343 UtRegisterTest(
"SSHParserTest09 - ToClient 2 chunks", SSHParserTest09);
2344 UtRegisterTest(
"SSHParserTest10 - ToClient 3 chunks", SSHParserTest10);
2345 UtRegisterTest(
"SSHParserTest11 - ToClient 4 chunks", SSHParserTest11);
2346 UtRegisterTest(
"SSHParserTest12 - ToClient 4 chunks", SSHParserTest12);
2347 UtRegisterTest(
"SSHParserTest13 - ToClient 4 chunks", SSHParserTest13);
2348 UtRegisterTest(
"SSHParserTest14 - ToClient 4 chunks", SSHParserTest14);
2360 UtRegisterTest(
"SSHParserTest26 - State name table", SSHParserTest26);
2361 UtRegisterTest(
"SSHParserTest27 - Per-direction session state", SSHParserTest27);
2362 UtRegisterTest(
"SSHParserTest28 - failure freezes the failing direction at its state",
2365 "SSHParserTest29 - stash and fragment deliveries mark the tx updated", SSHParserTest29);
2367 "SSHParserTest30 - long-banner continuation failure freezes at kex", SSHParserTest30);
2368 UtRegisterTest(
"SSHParserTest31 - failed flow admits the eve log condition", SSHParserTest31);
2369 UtRegisterTest(
"SSHParserTest32 - banner continuation marks the tx updated at parse entry",
2371 UtRegisterTest(
"SSHParserTest33 - failed peer does not arm no-inspection", SSHParserTest33);
2372 UtRegisterTest(
"SSHParserTest34 - failure ends the flow's app-layer parsing (engine path)",
2375 "SSHParserTest35 - split NewKeys arms the no-inspection/bypass flags", SSHParserTest35);