40 static void DetectAsn1RegisterTests(
void);
60 const DetectAsn1Data *ad = (
const DetectAsn1Data *)smd->
ctx;
61 Asn1 *asn1 = SCAsn1Decode(buffer, buffer_len,
offset, ad);
62 uint8_t ret = SCAsn1Checks(asn1, ad);
75 static DetectAsn1Data *DetectAsn1Parse(
const char *asn1str)
77 DetectAsn1Data *ad = SCAsn1DetectParse(asn1str);
80 SCLogError(
"Malformed asn1 argument: %s", asn1str);
99 DetectAsn1Data *ad = DetectAsn1Parse(asn1str);
105 DetectAsn1Free(
de_ctx, ad);
121 DetectAsn1Data *ad = (DetectAsn1Data *)ptr;
122 SCAsn1DetectFree(ad);
130 static int DetectAsn1TestReal01(
void)
132 uint8_t *buf = (uint8_t *)
"\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
133 "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
134 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
135 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
136 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
137 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
138 "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
139 "Jones""\xA0\x0A\x43\x08""19590717"
140 "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
141 "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
142 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
143 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
144 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
145 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
146 "\x61\x11\x1A\x05""Pablo""\x1A\x01""B""\x1A\x05""Jones"
147 "\xA0\x0A\x43\x08""19590717";
149 uint16_t buflen = strlen((
char *)buf) - 1;
152 uint8_t *buf2 = (uint8_t *)
"AA\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
153 "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
154 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
155 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
156 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
157 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
158 "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
159 "Jones""\xA0\x0A\x43\x08""19590717"
160 "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
161 "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
162 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
163 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
164 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
165 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
166 "\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05""Jones"
167 "\xA0\x0A\x43\x08""19590717";
169 uint16_t buflen2 = strlen((
char *)buf2) - 1;
179 sigs[0]=
"alert ip any any -> any any (msg:\"Testing id 1\"; "
180 "content:\"Pablo\"; asn1:absolute_offset 0, "
181 "oversize_length 130; sid:1;)";
182 sigs[1]=
"alert ip any any -> any any (msg:\"Testing id 2\"; "
183 "content:\"AA\"; asn1:relative_offset 0, "
184 "oversize_length 130; sid:2;)";
185 sigs[2]=
"alert ip any any -> any any (msg:\"Testing id 3\"; "
186 "content:\"lalala\"; asn1: oversize_length 2000; sid:3;)";
188 uint32_t sid[3] = {1, 2, 3};
189 uint32_t results[2][3] = {
204 static int DetectAsn1TestReal02(
void)
207 uint8_t *buf = (uint8_t *)
"\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
208 "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
209 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
210 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
211 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
212 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
213 "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
214 "Jones""\xA0\x0A\x43\x08""19590717"
215 "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
216 "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
217 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
218 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
219 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
220 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
221 "\x61\x11\x1A\x05""Pablo""\x1A\x01""B""\x1A\x05""Jones"
222 "\xA0\x0A\x43\x08""19590717";
224 uint16_t buflen = strlen((
char *)buf) - 1;
227 uint8_t *buf2 = (uint8_t *)
"AA\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
228 "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
229 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
230 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
231 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
232 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
233 "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
234 "Jones""\xA0\x0A\x43\x08""19590717"
235 "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
236 "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
237 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
238 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
239 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
240 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
241 "\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05""Jones"
242 "\xA0\x0A\x43\x08""19590717";
244 uint16_t buflen2 = strlen((
char *)buf2) - 1;
251 if (
p[0] == NULL ||
p[1] == NULL)
255 sigs[0]=
"alert ip any any -> any any (msg:\"Testing id 1\"; "
256 "content:\"Pablo\"; asn1:absolute_offset 0, "
257 "oversize_length 140; sid:1;)";
258 sigs[1]=
"alert ip any any -> any any (msg:\"Testing id 2\"; "
259 "content:\"AA\"; asn1:relative_offset 0, "
260 "oversize_length 140; sid:2;)";
261 sigs[2]=
"alert ip any any -> any any (msg:\"Testing id 3\"; "
262 "content:\"lalala\"; asn1: oversize_length 2000; sid:3;)";
264 uint32_t sid[3] = {1, 2, 3};
266 uint32_t results[2][3] = {
281 static int DetectAsn1TestReal03(
void)
284 uint8_t buf[261] =
"";
298 uint16_t buflen = 261;
301 uint8_t *buf2 = (uint8_t *)
"AA\x03\x01\xFF";
303 uint16_t buflen2 = 5;
310 if (
p[0] == NULL ||
p[1] == NULL)
315 sigs[0]=
"alert ip any any -> any any (msg:\"Testing id 1\"; "
316 "asn1:absolute_offset 0, double_overflow; sid:1;)";
318 sigs[1]=
"alert ip any any -> any any (msg:\"Testing id 2\"; "
319 "asn1:relative_offset 2, bitstring_overflow,"
320 "oversize_length 140; sid:2;)";
322 sigs[2]=
"alert ip any any -> any any (msg:\"Testing id 3\"; "
323 "asn1: oversize_length 2000; sid:3;)";
325 uint32_t sid[3] = {1, 2, 3};
327 uint32_t results[2][3] = {{1, 0, 0},
342 static int DetectAsn1TestReal04(
void)
345 uint8_t *buf = (uint8_t *)
"\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
346 "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
347 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
348 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
349 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
350 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
351 "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
352 "Jones""\xA0\x0A\x43\x08""19590717"
353 "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
354 "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
355 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
356 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
357 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
358 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
359 "\x61\x11\x1A\x05""Pablo""\x1A\x01""B""\x1A\x05""Jones"
360 "\xA0\x0A\x43\x08""19590717";
362 uint16_t buflen = strlen((
char *)buf) - 1;
365 uint8_t *buf2 = (uint8_t *)
"AA\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
366 "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
367 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
368 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
369 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
370 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
371 "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
372 "Jones""\xA0\x0A\x43\x08""19590717"
373 "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
374 "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
375 "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
376 "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
377 "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
378 "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
379 "\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05""Jones"
380 "\xA0\x0A\x43\x08""19590717";
382 uint16_t buflen2 = strlen((
char *)buf2) - 1;
389 if (
p[0] == NULL ||
p[1] == NULL)
393 sigs[0]=
"alert ip any any -> any any (msg:\"Testing id 1\"; "
394 "content:\"Pablo\"; asn1:absolute_offset 0, "
395 "oversize_length 140; sid:1;)";
396 sigs[1]=
"alert ip any any -> any any (msg:\"Testing id 2\"; "
397 "content:\"John\"; asn1:relative_offset -11, "
398 "oversize_length 140; sid:2;)";
399 sigs[2]=
"alert ip any any -> any any (msg:\"Testing id 3\"; "
400 "content:\"lalala\"; asn1: oversize_length 2000; sid:3;)";
402 uint32_t sid[3] = {1, 2, 3};
404 uint32_t results[2][3] = {
419 static void DetectAsn1RegisterTests(
void)