suricata
detect-uricontent.c
Go to the documentation of this file.
1
/* Copyright (C) 2007-2022 Open Information Security Foundation
2
*
3
* You can copy, redistribute or modify this Program under the terms of
4
* the GNU General Public License version 2 as published by the Free
5
* Software Foundation.
6
*
7
* This program is distributed in the hope that it will be useful,
8
* but WITHOUT ANY WARRANTY; without even the implied warranty of
9
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10
* GNU General Public License for more details.
11
*
12
* You should have received a copy of the GNU General Public License
13
* version 2 along with this program; if not, write to the Free Software
14
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15
* 02110-1301, USA.
16
*/
17
18
/**
19
* \file
20
*
21
* \author Victor Julien <victor@inliniac.net>
22
* \author Gurvinder Singh <gurvindersinghdahiya@gmail.com>
23
*
24
* Simple uricontent match part of the detection engine.
25
*/
26
27
#include "
suricata-common.h
"
28
#include "
decode.h
"
29
#include "
detect.h
"
30
#include "
detect-content.h
"
31
#include "
detect-http-uri.h
"
32
#include "
detect-uricontent.h
"
33
#include "
detect-engine-mpm.h
"
34
#include "
detect-parse.h
"
35
#include "
detect-engine.h
"
36
#include "
detect-engine-state.h
"
37
#include "
flow.h
"
38
#include "
detect-flow.h
"
39
#include "
flow-var.h
"
40
#include "
flow-util.h
"
41
#include "
threads.h
"
42
43
#include "
stream-tcp.h
"
44
#include "
stream.h
"
45
#include "
app-layer.h
"
46
#include "
app-layer-parser.h
"
47
#include "
app-layer-protos.h
"
48
#include "
app-layer-htp.h
"
49
50
#include "
util-mpm.h
"
51
#include "
util-print.h
"
52
#include "
util-debug.h
"
53
#include "
util-unittest-helper.h
"
54
#include "
util-spm.h
"
55
#include "
conf.h
"
56
57
/* prototypes */
58
static
int
DetectUricontentSetup(
DetectEngineCtx
*,
Signature
*,
const
char
*);
59
static
void
DetectUricontentFree(
DetectEngineCtx
*
de_ctx
,
void
*);
60
61
/**
62
* \brief Registration function for uricontent: keyword
63
*/
64
void
DetectUricontentRegister
(
void
)
65
{
66
sigmatch_table
[
DETECT_URICONTENT
].
name
=
"uricontent"
;
67
sigmatch_table
[
DETECT_URICONTENT
].
desc
=
"legacy keyword to match on the request URI buffer"
;
68
// No url doc for this obsolete keyword
69
sigmatch_table
[
DETECT_URICONTENT
].
Match
= NULL;
70
sigmatch_table
[
DETECT_URICONTENT
].
Setup
= DetectUricontentSetup;
71
sigmatch_table
[
DETECT_URICONTENT
].
Free
= DetectUricontentFree;
72
sigmatch_table
[
DETECT_URICONTENT
].
flags
= (
SIGMATCH_QUOTES_MANDATORY
|
SIGMATCH_HANDLE_NEGATION
);
73
sigmatch_table
[
DETECT_URICONTENT
].
alternative
=
DETECT_HTTP_URI
;
74
}
75
76
/**
77
* \brief this function will Free memory associated with DetectContentData
78
*
79
* \param cd pointer to DetectUricontentData
80
*/
81
void
DetectUricontentFree(
DetectEngineCtx
*
de_ctx
,
void
*ptr)
82
{
83
SCEnter
();
84
DetectContentData
*cd = (
DetectContentData
*)ptr;
85
86
if
(cd == NULL)
87
SCReturn
;
88
89
SpmDestroyCtx
(cd->
spm_ctx
);
90
SCFree
(cd);
91
92
SCReturn
;
93
}
94
95
/**
96
* \brief Creates a SigMatch for the uricontent keyword being sent as argument,
97
* and appends it to the Signature(s).
98
*
99
* \param de_ctx Pointer to the detection engine context
100
* \param s Pointer to signature for the current Signature being parsed
101
* from the rules
102
* \param contentstr Pointer to the string holding the keyword value
103
*
104
* \retval 0 on success, -1 on failure
105
*/
106
int
DetectUricontentSetup(
DetectEngineCtx
*
de_ctx
,
Signature
*s,
const
char
*contentstr)
107
{
108
SCEnter
();
109
110
const
char
*legacy = NULL;
111
if
(
SCConfGetNonNull
(
"legacy.uricontent"
, &legacy) == 1) {
112
if
(strcasecmp(
"disabled"
, legacy) == 0) {
113
SCLogError
(
"uricontent deprecated. To "
114
"use a rule with \"uricontent\", either set the "
115
"option - \"legacy.uricontent\" in the conf to "
116
"\"enabled\" OR replace uricontent with "
117
"\'content:%s; http_uri;\'."
,
118
contentstr);
119
goto
error;
120
}
else
if
(strcasecmp(
"enabled"
, legacy) == 0) {
121
;
122
}
else
{
123
SCLogError
(
"Invalid value found "
124
"for legacy.uricontent - \"%s\". Valid values are "
125
"\"enabled\" OR \"disabled\"."
,
126
legacy);
127
goto
error;
128
}
129
}
130
131
if
(
DetectContentSetup
(
de_ctx
, s, contentstr) < 0)
132
goto
error;
133
134
if
(
DetectHttpUriSetup
(
de_ctx
, s, NULL) < 0)
135
goto
error;
136
137
SCReturnInt
(0);
138
error:
139
SCReturnInt
(-1);
140
}
detect-content.h
detect-engine.h
SigTableElmt_::desc
const char * desc
Definition:
detect.h:1544
sigmatch_table
SigTableElmt * sigmatch_table
Definition:
detect-parse.c:78
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition:
detect.h:1529
flow-util.h
SigTableElmt_::name
const char * name
Definition:
detect.h:1542
stream-tcp.h
SigTableElmt_::flags
uint32_t flags
Definition:
detect.h:1533
threads.h
DetectEngineCtx_
main detection engine ctx
Definition:
detect.h:995
DetectContentData_
Definition:
detect-content.h:93
DetectUricontentRegister
void DetectUricontentRegister(void)
Registration function for uricontent: keyword.
Definition:
detect-uricontent.c:64
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition:
detect.h:1524
util-unittest-helper.h
DetectHttpUriSetup
int DetectHttpUriSetup(DetectEngineCtx *de_ctx, Signature *s, const char *str)
this function setups the http_uri modifier keyword used in the rule
Definition:
detect-http-uri.c:182
app-layer-htp.h
decode.h
util-debug.h
de_ctx
DetectEngineCtx * de_ctx
Definition:
fuzz_siginit.c:22
DetectContentSetup
int DetectContentSetup(DetectEngineCtx *de_ctx, Signature *s, const char *contentstr)
Function to setup a content pattern.
Definition:
detect-content.c:322
DETECT_URICONTENT
@ DETECT_URICONTENT
Definition:
detect-engine-register.h:79
util-print.h
SCEnter
#define SCEnter(...)
Definition:
util-debug.h:284
detect-engine-mpm.h
SCConfGetNonNull
int SCConfGetNonNull(const char *name, const char **vptr)
Retrieve the non-null value of a configuration node.
Definition:
conf.c:380
detect.h
detect-http-uri.h
SigTableElmt_::alternative
uint16_t alternative
Definition:
detect.h:1540
app-layer-parser.h
SCReturn
#define SCReturn
Definition:
util-debug.h:286
stream.h
conf.h
detect-engine-state.h
Data structures and function prototypes for keeping state for the detection engine.
SigTableElmt_::Match
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition:
detect.h:1504
SIGMATCH_QUOTES_MANDATORY
#define SIGMATCH_QUOTES_MANDATORY
Definition:
detect-engine-register.h:322
util-mpm.h
suricata-common.h
util-spm.h
detect-flow.h
DetectContentData_::spm_ctx
SpmCtx * spm_ctx
Definition:
detect-content.h:111
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition:
util-debug.h:274
SCFree
#define SCFree(p)
Definition:
util-mem.h:61
detect-parse.h
Signature_
Signature container.
Definition:
detect.h:692
app-layer-protos.h
detect-uricontent.h
flow.h
SpmDestroyCtx
void SpmDestroyCtx(SpmCtx *ctx)
Definition:
util-spm.c:192
SCReturnInt
#define SCReturnInt(x)
Definition:
util-debug.h:288
flow-var.h
SIGMATCH_HANDLE_NEGATION
#define SIGMATCH_HANDLE_NEGATION
Definition:
detect-engine-register.h:326
DETECT_HTTP_URI
@ DETECT_HTTP_URI
Definition:
detect-engine-register.h:186
app-layer.h
src
detect-uricontent.c
Generated on Thu Oct 8 2026 23:30:25 for suricata by
1.8.18