Skip to content

Commit

Permalink
tests: add RST with unacked data file tests
Browse files Browse the repository at this point in the history
Add tests for bad handling of unacked data following a RST.
  • Loading branch information
victorjulien committed Dec 3, 2024
1 parent 2ea1528 commit b7cf987
Show file tree
Hide file tree
Showing 16 changed files with 2,359 additions and 0 deletions.
5 changes: 5 additions & 0 deletions tests/tcp-rst-unacked-stream-09/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
PCAP
====

Pcap from a pcap known as TLPW1 in the team. Originally from:
malware-traffic-analysis.net
Binary file not shown.
560 changes: 560 additions & 0 deletions tests/tcp-rst-unacked-stream-09/suricata.yaml

Large diffs are not rendered by default.

19 changes: 19 additions & 0 deletions tests/tcp-rst-unacked-stream-09/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
requires:
min-version: 8

checks:
- filter:
count: 1
match:
event_type: fileinfo
fileinfo.sha256: b95aa84c9ac4948c8565202e016933644c592c366525b2790857615ca7e6f665
- filter:
count: 1
match:
event_type: fileinfo
- filter:
count: 1
match:
event_type: stats
stats.app_layer.tx.http: 1
stats.app_layer.flow.http: 1
5 changes: 5 additions & 0 deletions tests/tcp-rst-unacked-stream-10/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
PCAP
====

Pcap from a pcap known as TLPW1 in the team. Originally from:
malware-traffic-analysis.net
Binary file not shown.
Loading

0 comments on commit b7cf987

Please sign in to comment.