Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RCE attack - risk detection technique #1359

Open
v-crypto opened this issue Oct 25, 2021 · 2 comments
Open

RCE attack - risk detection technique #1359

v-crypto opened this issue Oct 25, 2021 · 2 comments
Labels

Comments

@v-crypto
Copy link

v-crypto commented Oct 25, 2021

Hi I am new to nDPI and have enjoyed using the features of nDPI. While i was learning about it I got struct by a query where i cant find any answer regarding it please help me to resolve my query

Branch : 4.0-stable

So my questions are
1.Is URL information is updated only during HTTP response?
2. If so with provided WebattackRCE.pcap there are only get requests no response information
3. when i used this pcap to verify the results nDPI couldn't identify risk as "RCE Injection" as there were no response packets to fill out url info for risk detection.
4. But in WebattackRCE.pcap.out file (in dev branch) i am able to view risk as "RCE Injection"

Could anyone correct me if I my understanding is wrong or correct.

@lucaderi
Copy link
Member

This was contributed code that might be imperfect. I see sometimes false positives. I would appreciate if you could fix the issues you have noticed.

@IvanNardi
Copy link
Collaborator

@v-crypto, keep in mind that to have RCE detection you need to have PCRE support, via --with-pcre flag

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants