back_orifice.cc (snort3-3.1.28.0) | : | back_orifice.cc (snort3-3.1.29.0) | ||
---|---|---|---|---|
skipping to change at line 162 | skipping to change at line 162 | |||
//------------------------------------------------------------------------- | //------------------------------------------------------------------------- | |||
#define GID_BO 105 | #define GID_BO 105 | |||
#define BO_TRAFFIC_DETECT 1 | #define BO_TRAFFIC_DETECT 1 | |||
#define BO_CLIENT_TRAFFIC_DETECT 2 | #define BO_CLIENT_TRAFFIC_DETECT 2 | |||
#define BO_SERVER_TRAFFIC_DETECT 3 | #define BO_SERVER_TRAFFIC_DETECT 3 | |||
#define BO_SNORT_BUFFER_ATTACK 4 | #define BO_SNORT_BUFFER_ATTACK 4 | |||
#define BO_TRAFFIC_DETECT_STR \ | #define BO_TRAFFIC_DETECT_STR \ | |||
"Back orifice traffic detected, unknown direction" | "Back Orifice traffic detected, unknown direction" | |||
#define BO_CLIENT_TRAFFIC_DETECT_STR \ | #define BO_CLIENT_TRAFFIC_DETECT_STR \ | |||
"Back orifice client traffic detected" | "Back Orifice client traffic detected" | |||
#define BO_SERVER_TRAFFIC_DETECT_STR \ | #define BO_SERVER_TRAFFIC_DETECT_STR \ | |||
"Back orifice server traffic detected" | "Back Orifice server traffic detected" | |||
#define BO_SNORT_BUFFER_ATTACK_STR \ | #define BO_SNORT_BUFFER_ATTACK_STR \ | |||
"Back orifice length field >= 1024 bytes" | "Back Orifice length field >= 1024 bytes" | |||
static const RuleMap bo_rules[] = | static const RuleMap bo_rules[] = | |||
{ | { | |||
{ BO_TRAFFIC_DETECT, BO_TRAFFIC_DETECT_STR }, | { BO_TRAFFIC_DETECT, BO_TRAFFIC_DETECT_STR }, | |||
{ BO_CLIENT_TRAFFIC_DETECT, BO_CLIENT_TRAFFIC_DETECT_STR }, | { BO_CLIENT_TRAFFIC_DETECT, BO_CLIENT_TRAFFIC_DETECT_STR }, | |||
{ BO_SERVER_TRAFFIC_DETECT, BO_SERVER_TRAFFIC_DETECT_STR }, | { BO_SERVER_TRAFFIC_DETECT, BO_SERVER_TRAFFIC_DETECT_STR }, | |||
{ BO_SNORT_BUFFER_ATTACK, BO_SNORT_BUFFER_ATTACK_STR }, | { BO_SNORT_BUFFER_ATTACK, BO_SNORT_BUFFER_ATTACK_STR }, | |||
{ 0, nullptr } | { 0, nullptr } | |||
}; | }; | |||
End of changes. 4 change blocks. | ||||
4 lines changed or deleted | 4 lines changed or added |