diff --git a/tests/firewall/ruletype-firewall-200-sni-lte-prior-hook-bug/README.md b/tests/firewall/ruletype-firewall-200-sni-lte-prior-hook-bug/README.md new file mode 100644 index 0000000000..00e70bbbab --- /dev/null +++ b/tests/firewall/ruletype-firewall-200-sni-lte-prior-hook-bug/README.md @@ -0,0 +1,5 @@ +Test that auto-accept-prior-states (`<`) on a catch-all accept covers the prior app-layer hook when a lower-SID same-hook drop rule with a matching prefilter leads the candidate list. +Rules drop TLS SNI "www.google.com" (sid:200) and accept other SNI via `accept:flow tls: $EXTERNAL_NET any (flow:not_established; sid:1021;) +accept:hook tcp:all $HOME_NET any <> $EXTERNAL_NET any (flow:established; sid:1022;) +# drop a specific SNI; accept all other SNI via auto-accept-prior-states (<) +# note: no explicit accept:hook tls:client_in_progress (see README) +drop:flow tls:client_hello_done $HOME_NET any -> $EXTERNAL_NET any (tls.sni; content:"www.google.com"; endswith; nocase; msg:"Drop www.google.com by SNI"; alert; sid:200;) +accept:flow tls: $EXTERNAL_NET any (alert; sid:201;) diff --git a/tests/firewall/ruletype-firewall-200-sni-lte-prior-hook-bug/suricata.yaml b/tests/firewall/ruletype-firewall-200-sni-lte-prior-hook-bug/suricata.yaml new file mode 100644 index 0000000000..24e38b5ab9 --- /dev/null +++ b/tests/firewall/ruletype-firewall-200-sni-lte-prior-hook-bug/suricata.yaml @@ -0,0 +1,63 @@ +%YAML 1.1 +--- + +vars: + # more specific is better for alert accuracy and performance + address-groups: + HOME_NET: "[192.168.0.0/16,10.0.0.0/8,172.16.0.0/12]" + #HOME_NET: "[192.168.0.0/16]" + #HOME_NET: "[10.0.0.0/8]" + #HOME_NET: "[172.16.0.0/12]" + #HOME_NET: "any" + + EXTERNAL_NET: "!$HOME_NET" + #EXTERNAL_NET: "any" + + HTTP_SERVERS: "$HOME_NET" + SMTP_SERVERS: "$HOME_NET" + SQL_SERVERS: "$HOME_NET" + DNS_SERVERS: "$HOME_NET" + TELNET_SERVERS: "$HOME_NET" + AIM_SERVERS: "$EXTERNAL_NET" + DC_SERVERS: "$HOME_NET" + DNP3_SERVER: "$HOME_NET" + DNP3_CLIENT: "$HOME_NET" + MODBUS_CLIENT: "$HOME_NET" + MODBUS_SERVER: "$HOME_NET" + ENIP_CLIENT: "$HOME_NET" + ENIP_SERVER: "$HOME_NET" + + port-groups: + HTTP_PORTS: "80" + SHELLCODE_PORTS: "!80" + ORACLE_PORTS: 1521 + SSH_PORTS: 22 + DNP3_PORTS: 20000 + MODBUS_PORTS: 502 + FILE_DATA_PORTS: "[$HTTP_PORTS,110,143]" + FTP_PORTS: 21 + GENEVE_PORTS: 6081 + VXLAN_PORTS: 4789 + TEREDO_PORTS: 3544 + SIP_PORTS: "[5060, 5061]" + +# Global stats configuration +stats: + enabled: yes + interval: 8 + +# Configure the type of alert (and other) logging you would like. +outputs: + - eve-log: + enabled: yes + filetype: regular #regular|syslog|unix_dgram|unix_stream|redis + filename: eve.json + types: + - stats + - flow + - alert + - tls: + extended: yes # enable this for extended logging information + - drop: + alerts: yes # log alerts that caused drops + flows: all # start or all: 'start' logs only a single drop diff --git a/tests/firewall/ruletype-firewall-200-sni-lte-prior-hook-bug/test.yaml b/tests/firewall/ruletype-firewall-200-sni-lte-prior-hook-bug/test.yaml new file mode 100644 index 0000000000..3782c536a1 --- /dev/null +++ b/tests/firewall/ruletype-firewall-200-sni-lte-prior-hook-bug/test.yaml @@ -0,0 +1,29 @@ +# Asserts expected behaviour; currently FAILS (see README). +pcap: ../../tls/tls-client-hello-frag-01/dump_mtu300.pcap +requires: + min-version: 9 +args: + - --simulate-ips + - -k none +checks: +# sid:200 drops www.google.com by SNI, with alert +- filter: + count: 1 + match: + event_type: alert + alert.signature_id: 200 + alert.action: blocked + firewall.hook: "tls:client_hello_done" +- filter: + count: 1 + match: + event_type: flow + flow.action: "drop" + flow.alerted: true +# dropped by the rule, not the default app policy +- filter: + count: 1 + match: + event_type: stats + stats.firewall.drop_reason.rules: 1 + stats.firewall.drop_reason.default_app_policy: 0