-
Notifications
You must be signed in to change notification settings - Fork 90
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
tests: add tests for smb.version keyword #1366
Conversation
Signed-off-by: jason taylor <[email protected]>
Thanks @jmtaylor90 are you also picking up OISF/suricata#7336 back ? |
Requires OISF/suricata#9415 apparently |
It does, what is the way to cross reference the PRs? |
I copy the link of the S-V PR in the suricata one (and GitHub makes it appear in the S-V PR) If you are interested, we use labels on S-V PRs, basically it is :
|
TEST | ||
==== | ||
|
||
Test smb.version keyword |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Could you please add an indication of where the pcap used here comes from? :)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
In this case I obtained it from the original submitters branch, it appears to be a capture from a local network they had access to. I am not sure how to denote that. How would you like that documented?
https://github.com/zer1t0/suricata-verify/tree/test/smb_version
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fair enough for me
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sorry for the late reply. A note with something along those lines - even if just - 'sample traffic from a local network' works, IMHO. :)
continued in #1380 |
Ticket
If your pull request is related to a Suricata ticket, please provide
the full URL to the ticket here so this pull request can monitor
changes to the ticket status:
Redmine ticket:
https://redmine.openinfosecfoundation.org/issues/5075