Go to the documentation of this file.
55 #define PARSE_REGEX "^\\s*([A-z0-9\\.]+|\"[A-z0-9\\.]+\")\\s*$"
60 Flow *, uint8_t,
void *,
void *,
64 static void DetectTlsVersionRegisterTests(
void);
71 static int g_tls_version_list_id = 0;
118 Flow *
f, uint8_t
flags,
void *state,
void *txv,
125 if (ssl_state == NULL) {
131 bool decoded =
false;
134 if (
flags & STREAM_TOCLIENT) {
141 }
else if (
flags & STREAM_TOSERVER) {
157 const uint8_t engine_progress =
165 if (progress < engine_progress)
170 if (((
version >> 8) & 0xff) == 0x7f) {
181 if (progress > engine_progress ||
204 pcre2_match_data *match = NULL;
206 if (ret < 1 || ret > 3) {
214 pcre2len =
sizeof(ver_ptr);
215 res = pcre2_substring_copy_bynumber(match, 1, (PCRE2_UCHAR8 *)ver_ptr, &pcre2len);
217 SCLogError(
"pcre2_substring_copy_bynumber failed");
229 if (tmp_str[0] ==
'"')
231 tmp_str[strlen(tmp_str) - 1] =
'\0';
235 if (strncmp(
"1.0", tmp_str, 3) == 0) {
236 temp = TLS_VERSION_10;
237 }
else if (strncmp(
"1.1", tmp_str, 3) == 0) {
238 temp = TLS_VERSION_11;
239 }
else if (strncmp(
"1.2", tmp_str, 3) == 0) {
240 temp = TLS_VERSION_12;
241 }
else if (strncmp(
"1.3", tmp_str, 3) == 0) {
242 temp = TLS_VERSION_13;
243 }
else if ((strncmp(
"0x", tmp_str, 2) == 0) && (strlen(
str) == 6)) {
244 temp = (uint16_t)strtol(tmp_str, NULL, 0);
256 pcre2_match_data_free(match);
261 pcre2_match_data_free(match);
264 DetectTlsVersionFree(
de_ctx, tls);
290 int list = g_tls_version_list_id;
306 DetectTlsVersionFree(
de_ctx, tls);
SSLv[2.0|3.[0|1|2|3]] state structure.
SigTableElmt * sigmatch_table
void(* Free)(DetectEngineCtx *, void *)
SSLStateConnp client_connp
struct SignatureHook_::@87::@88 app
SSLStateConnp server_connp
union SignatureHook_::@87 t
main detection engine ctx
int(* AppLayerTxMatch)(DetectEngineThreadCtx *, Flow *, uint8_t flags, void *alstate, void *txv, const Signature *, const SigMatchCtx *)
int DetectParsePcreExec(DetectParseRegex *parse_regex, pcre2_match_data **match, const char *str, int start_offset, int options)
int SCDetectSignatureSetAppProto(Signature *s, AppProto alproto)
#define SIG_FLAG_TOCLIENT
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
void DetectAppLayerInspectEngineRegister(const char *name, AppProto alproto, uint32_t dir, uint8_t progress, InspectEngineFuncPtr Callback, InspectionBufferGetDataPtr GetData)
Registers an app inspection engine.
void DetectBufferTypeSetRunAlways(const char *name)
@ SIGNATURE_HOOK_TYPE_APP
#define SIG_FLAG_TOSERVER
#define DETECT_TLS_VERSION_FLAG_RAW
void DetectTlsVersionRegister(void)
Registration function for keyword: tls.version.
void DetectSetupParseRegexes(const char *parse_str, DetectParseRegex *detect_parse)
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
void DetectEngineBufferTypeSetRunAlways(DetectEngineCtx *de_ctx, const int id)
int AppLayerParserGetStateProgress(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
get the progress value for a tx/protocol
SignatureInitData * init_data
Data structures and function prototypes for keeping state for the detection engine.
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
int DetectBufferTypeRegister(const char *name)
#define PARSE_REGEX
Regex for parsing "id" option, matching number or "number".
enum SignatureHookType type
uint8_t DetectEngineInspectGenericList(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const struct DetectEngineAppInspectionEngine_ *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
#define SCLogError(...)
Macro used to log ERROR messages.
uint8_t AppLayerParserGetTxEndState(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
get the end state (progress) for a transaction.
#define SIGMATCH_SUPPORT_FIREWALL
void DetectBufferTypeSetDescriptionByName(const char *name, const char *desc)
#define SIGMATCH_STATEFUL
AppProto alproto
application level protocol
void(* RegisterTests)(void)