From 83bda4083f9a40d4845332286c11c619446805df Mon Sep 17 00:00:00 2001 From: Jeff Lucovsky Date: Wed, 14 Aug 2024 10:11:48 -0400 Subject: [PATCH] smtp: add tests for issue 7126 Ensure the SMTP applayer parser doesn't generate an error message while parsing the SMTP frames. --- tests/bug-7126/README.md | 2 ++ tests/bug-7126/input.pcap | Bin 0 -> 16705 bytes tests/bug-7126/input.rules | 1 + tests/bug-7126/test.yaml | 13 +++++++++++++ 4 files changed, 16 insertions(+) create mode 100644 tests/bug-7126/README.md create mode 100644 tests/bug-7126/input.pcap create mode 100644 tests/bug-7126/input.rules create mode 100644 tests/bug-7126/test.yaml diff --git a/tests/bug-7126/README.md b/tests/bug-7126/README.md new file mode 100644 index 000000000..75406409d --- /dev/null +++ b/tests/bug-7126/README.md @@ -0,0 +1,2 @@ +This test is for bug 7126 and designed to insure the smtp applayer parser +doesn't generate an error message. diff --git a/tests/bug-7126/input.pcap b/tests/bug-7126/input.pcap new file mode 100644 index 0000000000000000000000000000000000000000..73ad48a78f5776eea3ca8d1475fd949e74970eb5 GIT binary patch literal 16705 zcmd6OdyFetTA%OiJlGyJ8IS_ALP95()o>@iW!KAg+0#8~x8Ln&`_b+8XmqDsRd!Xo zTve_rKNT$_E$~PFAczn}ixx7wclHJB%-)1ZVY4hE3nWTJ67d?)B0-cW2oNhCy2}FD z-F)Yi-7dQy_YOlyTGzMB)u+Dmo$q|-d;Gqye*H`T>SIp?o(!yio($ZAFXm4jy!Ot= z0)ZpA#-DmKAbj+X|D>4sH{bUUz9onJ1t4mYw?tf8EFTZ@uq*&tS^m{KT5FN7JM4Q4RzS z0tZijD2=IN>VXe@dFM}``+*&x{^lF?5&FU>*OXr-6b1wIAT@MnwHCjuXN>#La8|MHbB zUZ2IhzW#jRfBfA0Jc=(A?tKvW{4cn zA7YpYYO3SAh~`mQv=K|Q45H%+o=wm(6r|y2cL#`}h9wS>tU0|Qr1<=;ukQcM zCdEv?R7I1%VuuEbZ76!kwEG_CZs!@;1U&i*f&ckie?bKP&$a|^fxtgc1pexUz(05Y z;OpPbMy?ikUeR@Pn*sC+%Y_(L2*slzMtBt@3{N)-oeYYwJSzx9=x|FoEHul7a>g4_ zE7UTjLZwj2t-s$(RV$TDs_ETHAH7?RiM?(3gjEgXG%3s zAg|c(ziBH!Mg;$pTY~@mpFa14Vc5!t|MoK%g8vL`<>&BLew+LLz>ho|AfN56eD?bv zd>m8!m9r};K7Z@sfB4EK#d5MxLRs4!CiZmA7|$qgM=5h^DE7hD9>0tZtLd}-l>`x% z?mo|P-0n_2RcoTAnb>n}vDee2spv|e&<8zpY{;4$BIjl(YI;aAhcEB$9Hx^^#Pe`M zO34ODx~@oyHc{jRx-%5dO6+szGfOn&-5s?2(PY$MxmYYt zC%bAYeKa^mcdD4n^^iTgCkZV3(qpmw;!EoX$>H{&Z9c)%2_}jtI)c?~y_gR*9Zse1ZDLYYR0p@P~SBBx`K5C z>%ldDd8JUBL=$Y3jwO0Rmrn3Pluxj90t{^L)fd+b1#P)jcIZwGMAy@1FQTsd#QqKV+VDkJ@|7+Y%2Y$^8=^b5l?0mXGcO@=-*!aGQAIWqeF;hX zwxWwOMGh~2`woS?-(Q{Ymyom1(oB@0*@$n1xCCtt@Oa-8Is~8G=s7g zOP^D&nZQRTA&ah(7%Gk<_7zH#6VAAMu1IdeHP=f=2}$x%@2dOJNZ#yqv+YW4m{*U+ zmGFRXM*1g%v)19L7M|0ctll1!&*#-rX5athzEkI;qkOz?_xZl%f&KNgdoyLTy8y`%QBQx4;+k-}g&7Bmi*g#^=^vU7;#7C~;7Q@XPJr%<3 zqjEQTG;T!%t5rEOnR=l=IVvBk>S>AY&7%A~Er^*|YEZF*cGcl?=BY3Vmy#tq?;|%8 zj+$~cZ&&hlBkL;W$z06kPt*D1NKC6Ax)$4Kb?iRa8$?nvR*NwwP zba5V0edIK{aW0<38cu{g*6YrBS>ckcj?F~lTq@oyWX73+S!$(KDbHMy?}uYn ztevipQn7L)ovo$IK5`vF>F@9F?zE{Ku>{n6R!T-;Xc`;aYn5_F^@r3-*BqB<-n-FL zANyCU?BAZA7Q<{i=H%&yOPL~^JXFg`*XZEQiMcIbRA2*w6*J+n@yOyDQje?+!hGx`>7dU#D9jEJs zOg}hFAD2_%+$3tL_V7%K(W*R#cy;A(A=uT&wJKfa2AV3@EP-C+I>O0JC_3R@rz=(t z=dM^V?078c_VN>3j<{3SX{V3q^SE)6ZL6)|wBRGRuqVk8eL8gylX-^kp0WjLW|ce1 z-uP_fmd9zXKdk4u&Y+V|N{brTnNLp+O9M5NibqxMEanI;CgLL(EmZo#!VGtFqRHus zwQz&>X<;@J>hX3fch2OG>3M}~j5Jq@&*iGpVN-Fve0rFz)`Ep-j&F>MVIMhtbauSd z(;-z}+NlQ79h9sl%Mp%K*;ZjO9*kohr#!Nwh54{;ifY4J1p5m($3aQ&44GLcvdE02 zvTo0O9$!A5QCG%D+av~i~&AAdOR?pg5F6%H^ zN??y_H7a%@w)jP)Iy$t^(snSJJB~~bh>yGQbQ@$w<9-}R=;sijukzTftTPbc-})L( zg8pk`GYR^^@WcBb-GP|@xi9?0DhYZm4oT2wFvb526yJI}Kt9_s|I=?gcoWC`zxvW< z%>PlyyCI8!nEy*Vn=$_=bx%3ZXK3!MKh_#^s%<%)lW3odQkKG@$&y5iv=9~JTwII@ip;^b(u#n^44DK8{Y4jC{ZilsgQ^oR4|&3SCPs1= zFg{5`o}-4UOd#Db1}55rEMOjTE^Zw7_bQEzJ3O==?yOF9Aq|W! zwM34Lne%+HmMrxSo6S+iZ1*U>nv_ebV{l2Tx2R3Iva%mj)$%3L?d~*|0Su}G1FzJQ z%~T#SVfIxtHZ<3PBP+|uRTY%)+^c2k_lo%rgoct0;SLrS{(*(s$`qAN+cgbX=D-?W zC+L*qJ(4Eck4m2QqrK}-!`-!QyA27PsOSgl)c!WwyL9hm-xF7Dfvs(90?~*N048u4 zaRTUjx-=e$&H|Odn?Zz4zJzr6av<8n?Xjk%7!cDt?jvIH-JO&Pa~UqxoLeAp$PV4G zrHh&YF{~=uj^gg$hIE}0Ztw2YY{)%j9Ec`RcdQR~cS6nZ;B*xlLPsT!W@VN{5}>j6Wei`WFmpk(>+w-`-r6Et~u=Vb&WPZb$x z@hGcwJ(3KK^A2vQ&hO@kToB&f357zK<(E-Xcg(wJs^Vm2pkOT>A_vk0fUI1QuJex& zswjOp=o3)i1=1X3sdGn@L|vcb=MB?v6ocFdAynuA1z7Xgf=zIcV-6K0nX*EzrWgZ5 zT}2Ydj)F87O+^REiikywNs*+;KR4#a0OkM?y6e#;vT%Yoc#k<$ z8aOy_9p2C$$Urw?4fsF8Pm_pf2<*8aC{KQn9l1Kl3sk;ui#oC(g)*_>MfO-%mINIM zn-7rJ?oLlPr?3HcLET;8iZEc9E-)dfggYz+39|=C0dN5Ff~i!~P#l*qK~ZRT=M?|- z5N?4@>x(u>ZFgtO6nGfeAKdH@|C0E_`elFk@d^0De|VKY{KN;Jy?`^fJnR#JqqqKw zP>f$m@p+)Qgfm|#y!L7AVF4&a)uM;oB_&C*Tm^t6?05g&A3Ym*9UxQuxipXc)?br( zp4*xy^YA`!j_3KE3s3&#dxQ!zEVa7H3xDI_$VgsNAhfiWiIDdu%sU`(Z(Uc*g@U0(E$7=kL z8PzM9L0>y7M-;wp%;<7!);#K+a)-gwY?3#!yeJfM%<(4bI2fI{ou=Jor;HWU&Et_1 zbe*ZI97j8l!?szoU!skkmF`UI_K|L8AU2L3Pq|6AwJ-+pRCowACXyQ9|0YQ(7z=Bh zo9a7C(a?%ow!>sIxn`u*(A=sl=4ZkvDC>4SXVHfc9rW4x*ffjboXCyK5i>S!ochR( ztX4c7vx*(NJu4MOp&YMg3h8<2yl~XvV!>3sB@7mVUe7sBzE~N@j@SV+&I!3JKdTCK zy_24(wvSw|duGnXY%9pJi%x#tPPGL=3Aa0^^jWxh-kz(%^mIr|DmT|p3_%jRhpl?t zZjWonnZ=2gE~oo3Uu_2sjys2J{j|&R>GQKvvphadnMYwQpEFvMYW-YjmbhV=j*9$H zt)()}Q`(R!v(a(HQ8L4_$*0&_MGDQTehz^5!jc!Wa6i{-4#mj4I+L5NfgYZB!)}g0k7kV&pQrQV!`PyIURV_6 zLBkJk_AB;Ww8tgU?bVu{Y@|Ic@e6mxwMJ6?q`^&+&G0Z5lRKPJn51%WN~4`*WYU{N z7wN84=yFMJ6!&qbG-{P#vFe@_yB(JcCcD*nP9L30F|JaQxmH0qvtrSRb<#At;qD}} z(1erB`BW1}sktocR(eq@j(p^FZ4z~dX5Afu{+`#W$)RSC8&)xu>Pk$}bR&k|h?Tke z5CE#;`N>h!T!dXEo2(>{xOsn&ttr)ok6iR@_6R(ZX_-;l6o)ZusOGeAJAOQwPlU3g z7c|waHpl#YQZt;{oHrYNs5Fc+zT%g1?AAwY_NdF}ic_B&i;Z9al8?uQ*whw7Jk$b~2&BLWF+S!q z?d@`wpPB%UFWo ziMZZLd@gAvX(VwSQfHlElwo6RJTe{XAx;Qkh%-cUA%Hh&29^?HVrvz+vn;FaLvsRi zk3*7XL8gem-AiT~_n>@tFPAFc!x4HJBJ>;Z$^T8Vn(9_o^Wlg0Kl{rN^PjHsF;TgH z@QvTV6#qL={KKaL!@R zf$uPUE)|%s2syU)=>j0sm2*hNZ4;$T9d-xmxS~D_4MoF(;-a&G53aB_FPMZO+aS(e zgbympnYs)u2e8q5B7Bc=n(m|H1GmZ=z)gydii&M(&H(KV-N98;`yMHc0XxVmhOLbN zVgR5E5DxG9zyVYwBrAUOtl=tv9%OMHRYiMFk6au$;;<_&QP&k1n0#zG_?XGrN*@*T zXs-_!1Jwf@w}4&W@T6ggr~!#BMvAbY;XAZ`EWaN>6;8CQZBXw>>Ge=aoD*2{TqhSk z^wGcCvNq672Q?M|6UiD#lYBpLyze1(>>u2;0kA>k`9N2?V+q1OKxitQjZ`tl>lh&Dop4{|5`j&?X_G8(6lX@xcGc?KIdhO&Xx15IP0422fMk zyAzti*8|fQC9k!?|5O@-KPgo+pxp)@ki4q{SRR06+mfnilBokCc4%U?f)&ZOW(*|J zJ&;teMcQ~s_T0B21E5S#h8gR5TRvfPweaF!FUJ@2`Tc%zNJ(+Dz0g% za0+yNs`b&HDyavW(X*j%MwGYL2!M@B$#4vGw70(AKDmB&{JG*IkYt}MQ-y3}HCobo z&P_9r14y}wq#76(gp-L+vQUx$K$T&ESI$L^`<#X7<@(*U~&mcBMeHf zI5uu(_*B$g*v347?qGAKfRPWKgKp2k=EhgOc%`0Ap$Y#gK(^K#TmIP2jh6qXh~@v< zrseW6Odv z2*OP{5$O5b-PtJY__JUPg$rKWCG-LKDm&0==G6=#I-uj6KttCc9T9NR@LKoa!TpMz zKz+@n0MwQ#1^aKrhB)xXxab(_^N|P(%|pBh<>xCZUM$NqJPVaF7%lKH+ZFa5_Xu4s zZ9dL(S5!$aDj};ZHnYrP6G#9T`*&LZ@Kh9U8OG+pyNL+=iVa9Qt`g#MLuz}k?*OW8 zoAMY+G#E{fgt!;6@@eq!loSib{XWL_VQWn=rGRfE(!()?>JQWoOlgd-a2a5!MgWJK z=&+S*z(e4cp?%fCR6`+Pi$RWRj&&Ks-4^L!lmTI1vPR1LXc=Y!FQ9!xQr;wbND3L? zbjPb2#58l zfqP%VN!!)H`#52NkMcAZhBJ-hg2!?1-pI!dWW3Rj9|w5j9~A<4qaH8Td3226QG3_n z!E$Mj85ww^-$hX1J@Dvwz#I3Np@28|(NTam?$H5&H!g`SzXX>5hAiUiB#WqA&LV#H zJ0OereqR>RTV)X+y4jcfH1Q>WvFS^G_B&Qt#8>K@zT}bdiMN(VhbG>*$BIh4q3a;z z#(=~d?74TZ!o2d;-nUD>e#ywA!VquRR>1M-2*l6MV+J4IBkw-$@Sb}_$U!R1l-cVM zi~0E3%kB|$I4F>>@KFk-N$u5EhS*IIYpo5jfrWUO^ap^IUJtG-Q|Lioxrqr6 zl-^H4ofF@Mfp8709{4;7^l7M~F@VZ3w$yitOTcAg?2lAMw@5X(tGGDG!bHF!d43_K zDv*Of_y@&PFfI5u;U9|a1{=m<)<#f-{xM?V9g?em;6Ye9V!*jVIT%s|h@)_800-X6 zQNRU2CH_wE#k&w7$%?Lc-zjKG-rbQkNWv%z;u<7|ubH}g%^!Ampn#;zP?TXrF5VUB zP^cFXx;;e{dI+MfC=XZ?uy!rw-5ppDx}N;O0ivLz^e!|s;9qeBH>yy&HhX9Y`)OnU zk3xqiQ>iv;DY*8E|61%|@$ML$}c#N5fgwI-q$GI!S^sub-xDLX?78SOu&&8bHv*VtZ{- zm@pe*5igYcM)t>E+@M-dL`>O&Cg%5VcZ*u2U<-dx;l;hHAW@p7;>LKihe zQxNdrSP2#i#2jcg(0UpWf?!(oS~g%|M5Y3Nm!UzZLhLRR!%{UdXdfz|o_x<7Lu?2H zArK`Y6J(O2M4CLDsc4a9UdV^S!f&TD(6{V~3SVO>brpz`)?(r|r9`M>U-G|hw)~$Z zmjA1pmj8=iTxAj8^^r}>Z$tKsh0%q^i(sfw$EyKx+$Lx6_Ql$QB5;OxXQ>llG5xy- zi}QA8b46F}JJ~RzOP;)Z^Mf$2o1eOB{vo_CgE!r$nRj4IFBFY?5%YD`lj|qIm;?d5 zAd0?J9`bct=OO%FNdPzHfK|j2z&$;f0@gQkLwhgfVHanlkw>7tjY72oFGgW$U@d|p zvt_=}9k4Z6@u11>u7HBjv3VC_Zn%>qSOT19%to?SfZu>`-~b;t%s}KS+WH*yzo+50 zBNF&ap!A+zuhxp6>*Du~9GD(2jr6mCeZVOJKr=3ofG$A^zibEe4ZQJ~Ff`pD&*fs1 zjFJ}g;Q*+Dt>r2oSlSEBT~~pA84b=PQ73#%HE=2<+W`I{lkn3D)!=wjSMUEeIX+eYBb;PkqMDRdE+~9)M zsIg_k@U~y~F!ayjtVjfe3ZND!#s$e-T@#vs)~e^J)N&s;)XCc<*wpo41P)kViq0<_ zcwG!Lrzph#5?8tux(%&O8i)@LH%=n)ZiPVi;C;PpwO)po^iUJGQ9p(PvQg|!ST24S za#2vgK6I}+KHhNq7FcQ=Am9$oIiB)@U342OHpoH(FY4Ly+Ym!wum>A$5F>0h;IXio zSYvQ68;ArQxh9?qMw=pEpT`=2nb%b!7qX$%ft;`p7F(Gh&b`Y zlxa{?TLVW0?~V>o7YYvp2Tm5I25ufQRLaq0g(6Je@f-mn9caJ>;6ucOV7cKe7$jW) zjF4bQE5*V}?1`AUNhQcJybuZ;DtMm>GwPASPio$QzVLXYpYOsUV$1*S&)%3te1l{W z<;z*bFZLjdcyLt~@jXEC@4@S*__JM$xOMBnTiBPp^WQdo$uIU+zU1v+-SQ>a7{j_C z!qFz0JO(Upt-#n^1oP$;4g`dJU`&atXb93VKlOKRd|mx*tZ2XW(M?7BB@Ptr9gyV1?+dLI?VG>%LP7jBOz}H^ z;Hf|!q=-M;svAf=_#C0Q^_KRMB7mvC`GqCLWZ;J}#p70?>2aC|x~o+E5?%hm148%5 zwm6LwPQUHe!w*e2>0(a*{=axCU;vl+b7{|Cd;1Bp7vHtD7w^DcBwqgj?8SfbD85jT zK6oFvW#Rq!t6r>^px8r@I}^$y5PO=2x1Q45&jj{hX8gIdo;v~1IR5E>(%xE60tN?a QPX+?7_VCr$q&JNJ1L)>(v;Y7A literal 0 HcmV?d00001 diff --git a/tests/bug-7126/input.rules b/tests/bug-7126/input.rules new file mode 100644 index 000000000..0eac4f266 --- /dev/null +++ b/tests/bug-7126/input.rules @@ -0,0 +1 @@ +alert ip any any -> any any (msg:"Sample rule"; flow: established, to_server; file_data; content:"no-match"; sid:1;) diff --git a/tests/bug-7126/test.yaml b/tests/bug-7126/test.yaml new file mode 100644 index 000000000..93c23e4c8 --- /dev/null +++ b/tests/bug-7126/test.yaml @@ -0,0 +1,13 @@ +requires: + min-version: 8 + +args: + - --set logging.outputs.1.file.type=json + - -k none + +checks: + - filter: + count: 0 + filename: suricata.log + match: + engine.message: "Extra characters following numeric value"