Skip to content

Commit

Permalink
websocket: adds check for data frame
Browse files Browse the repository at this point in the history
Ticket: 7051
  • Loading branch information
catenacyber authored and victorjulien committed Jun 7, 2024
1 parent 5856e16 commit b7bb81a
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 1 deletion.
3 changes: 2 additions & 1 deletion tests/websocket/test.rules
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
alert websocket any any -> any any (msg:"header frame"; flow:established,to_server; frame:websocket.header; content:"|81 88|"; sid:1;)
alert websocket any any -> any any (msg:"pdu frame"; flow:established,to_client; frame:websocket.pdu; content:"|81 15|version,hybi-draft-13"; sid:2;)
alert websocket any any -> any any (msg:"pdu frame"; flow:established,to_client; frame:websocket.pdu; content:"|81 15|version,hybi-draft-13"; startswith; endswith; sid:2;)
alert websocket any any -> any any (msg:"data frame"; flow:established,to_client; frame:websocket.data; content:"version,hybi-draft-13"; startswith; endswith; sid:21;)
alert websocket any any -> any any (msg:"ws opcode"; flow:established,to_client; websocket.opcode:text; sid:3;)
alert websocket any any -> any any (msg:"ws mask"; flow:established,to_server; websocket.mask:>0; sid:4;)
alert websocket any any -> any any (msg:"ws fin"; flow:established,to_server; websocket.flags:fin; sid:5;)
Expand Down
5 changes: 5 additions & 0 deletions tests/websocket/test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,11 @@ checks:
match:
event_type: alert
alert.signature_id: 2
- filter:
count: 1
match:
event_type: alert
alert.signature_id: 21
- filter:
count: 1
match:
Expand Down

0 comments on commit b7bb81a

Please sign in to comment.