"Fossies" - the Fresh Open Source Software Archive  

Source code changes of the file "src/detection/detection_options.cc" between
snort3-3.1.36.0.tar.gz and snort3-3.1.38.0.tar.gz

About: Snort 3 is a network intrusion prevention and detection system (IDS/IPS) combining the benefits of signature, protocol and anomaly-based inspection.

detection_options.cc  (snort3-3.1.36.0):detection_options.cc  (snort3-3.1.38.0)
skipping to change at line 482 skipping to change at line 482
if ( !eval_data.flowbit_noalert ) if ( !eval_data.flowbit_noalert )
{ {
#ifdef DEBUG_MSGS #ifdef DEBUG_MSGS
const SigInfo& si = otn->sigInfo; const SigInfo& si = otn->sigInfo;
debug_logf(detection_trace, TRACE_RULE_EVAL, p, debug_logf(detection_trace, TRACE_RULE_EVAL, p,
"Matched rule gid:sid:rev %u:%u:%u\n", si.gid, si.si d, si.rev); "Matched rule gid:sid:rev %u:%u:%u\n", si.gid, si.si d, si.rev);
#endif #endif
fpAddMatch(p->context->otnx, otn); fpAddMatch(p->context->otnx, otn);
} }
result = rval = (int)IpsOption::MATCH; result = rval = (int)IpsOption::MATCH;
eval_data.leaf_reached = 1;
} }
} }
break; break;
case RULE_OPTION_TYPE_CONTENT: case RULE_OPTION_TYPE_CONTENT:
if ( node->evaluate ) if ( node->evaluate )
{ {
// This will be set in the fast pattern matcher if we found // This will be set in the fast pattern matcher if we found
// a content and the rule option specifies not that // a content and the rule option specifies not that
// content. Essentially we've already evaluated this rule // content. Essentially we've already evaluated this rule
 End of changes. 1 change blocks. 
0 lines changed or deleted 1 lines changed or added

Home  |  About  |  Features  |  All  |  Newest  |  Dox  |  Diffs  |  RSS Feeds  |  Screenshots  |  Comments  |  Imprint  |  Privacy  |  HTTP(S)