Coverage Report

Created: 2026-09-06 07:25

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/suricata8/src/detect-http-uri.c
Line
Count
Source
1
/* Copyright (C) 2007-2018 Open Information Security Foundation
2
 *
3
 * You can copy, redistribute or modify this Program under the terms of
4
 * the GNU General Public License version 2 as published by the Free
5
 * Software Foundation.
6
 *
7
 * This program is distributed in the hope that it will be useful,
8
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
9
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
10
 * GNU General Public License for more details.
11
 *
12
 * You should have received a copy of the GNU General Public License
13
 * version 2 along with this program; if not, write to the Free Software
14
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15
 * 02110-1301, USA.
16
 */
17
18
/**
19
 * \ingroup httplayer
20
 *
21
 * @{
22
 */
23
24
25
/**
26
 * \file
27
 *
28
 * \author Gerardo Iglesias  <iglesiasg@gmail.com>
29
 * \author Victor Julien <victor@inliniac.net>
30
 */
31
32
#include "suricata-common.h"
33
#include "threads.h"
34
#include "decode.h"
35
#include "detect.h"
36
37
#include "detect-parse.h"
38
#include "detect-engine.h"
39
#include "detect-engine-buffer.h"
40
#include "detect-engine-mpm.h"
41
#include "detect-engine-prefilter.h"
42
#include "detect-content.h"
43
#include "detect-pcre.h"
44
#include "detect-urilen.h"
45
46
#include "flow.h"
47
#include "flow-var.h"
48
49
#include "util-debug.h"
50
#include "util-unittest.h"
51
#include "util-spm.h"
52
#include "util-print.h"
53
54
#include "app-layer.h"
55
56
#include "app-layer-htp.h"
57
#include "detect-http-uri.h"
58
#include "stream-tcp.h"
59
60
#ifdef UNITTESTS
61
static void DetectHttpUriRegisterTests(void);
62
#endif
63
static void DetectHttpUriSetupCallback(const DetectEngineCtx *de_ctx, Signature *s);
64
static InspectionBuffer *GetData(DetectEngineThreadCtx *det_ctx,
65
        const DetectEngineTransforms *transforms,
66
        Flow *_f, const uint8_t _flow_flags,
67
        void *txv, const int list_id);
68
static InspectionBuffer *GetData2(DetectEngineThreadCtx *det_ctx,
69
        const DetectEngineTransforms *transforms, Flow *_f, const uint8_t _flow_flags, void *txv,
70
        const int list_id);
71
static int DetectHttpUriSetupSticky(DetectEngineCtx *de_ctx, Signature *s, const char *str);
72
static int DetectHttpRawUriSetup(DetectEngineCtx *, Signature *, const char *);
73
static void DetectHttpRawUriSetupCallback(const DetectEngineCtx *de_ctx, Signature *s);
74
static InspectionBuffer *GetRawData(DetectEngineThreadCtx *det_ctx,
75
        const DetectEngineTransforms *transforms,
76
        Flow *_f, const uint8_t _flow_flags,
77
        void *txv, const int list_id);
78
static int DetectHttpRawUriSetupSticky(DetectEngineCtx *de_ctx, Signature *s, const char *str);
79
80
static int g_http_raw_uri_buffer_id = 0;
81
static int g_http_uri_buffer_id = 0;
82
83
/**
84
 * \brief Registration function for keywords: http_uri and http.uri
85
 */
86
void DetectHttpUriRegister (void)
87
79
{
88
    /* http_uri content modifier */
89
79
    sigmatch_table[DETECT_HTTP_URI_CM].name = "http_uri";
90
79
    sigmatch_table[DETECT_HTTP_URI_CM].desc =
91
79
            "content modifier to match specifically and only on the HTTP uri-buffer";
92
79
    sigmatch_table[DETECT_HTTP_URI_CM].url = "/rules/http-keywords.html#http-uri-and-http-uri-raw";
93
79
    sigmatch_table[DETECT_HTTP_URI_CM].Setup = DetectHttpUriSetup;
94
#ifdef UNITTESTS
95
    sigmatch_table[DETECT_HTTP_URI_CM].RegisterTests = DetectHttpUriRegisterTests;
96
#endif
97
79
    sigmatch_table[DETECT_HTTP_URI_CM].flags |= SIGMATCH_NOOPT | SIGMATCH_INFO_CONTENT_MODIFIER;
98
79
    sigmatch_table[DETECT_HTTP_URI_CM].alternative = DETECT_HTTP_URI;
99
100
    /* http.uri sticky buffer */
101
79
    sigmatch_table[DETECT_HTTP_URI].name = "http.uri";
102
79
    sigmatch_table[DETECT_HTTP_URI].alias = "http.uri.normalized";
103
79
    sigmatch_table[DETECT_HTTP_URI].desc = "sticky buffer to match specifically and only on the normalized HTTP URI buffer";
104
79
    sigmatch_table[DETECT_HTTP_URI].url = "/rules/http-keywords.html#http-uri-and-http-uri-raw";
105
79
    sigmatch_table[DETECT_HTTP_URI].Setup = DetectHttpUriSetupSticky;
106
79
    sigmatch_table[DETECT_HTTP_URI].flags |= SIGMATCH_NOOPT|SIGMATCH_INFO_STICKY_BUFFER;
107
108
79
    DetectAppLayerInspectEngineRegister("http_uri", ALPROTO_HTTP1, SIG_FLAG_TOSERVER,
109
79
            HTP_REQUEST_PROGRESS_LINE, DetectEngineInspectBufferGeneric, GetData);
110
111
79
    DetectAppLayerMpmRegister("http_uri", SIG_FLAG_TOSERVER, 2, PrefilterGenericMpmRegister,
112
79
            GetData, ALPROTO_HTTP1, HTP_REQUEST_PROGRESS_LINE);
113
114
79
    DetectAppLayerInspectEngineRegister("http_uri", ALPROTO_HTTP2, SIG_FLAG_TOSERVER,
115
79
            HTTP2StateOpen, DetectEngineInspectBufferGeneric, GetData2);
116
117
79
    DetectAppLayerMpmRegister("http_uri", SIG_FLAG_TOSERVER, 2, PrefilterGenericMpmRegister,
118
79
            GetData2, ALPROTO_HTTP2, HTTP2StateOpen);
119
120
79
    DetectBufferTypeSetDescriptionByName("http_uri",
121
79
            "http request uri");
122
123
79
    DetectBufferTypeRegisterSetupCallback("http_uri",
124
79
            DetectHttpUriSetupCallback);
125
126
79
    DetectBufferTypeRegisterValidateCallback("http_uri", DetectUrilenValidateContent);
127
128
79
    g_http_uri_buffer_id = DetectBufferTypeGetByName("http_uri");
129
130
    /* http_raw_uri content modifier */
131
79
    sigmatch_table[DETECT_HTTP_RAW_URI].name = "http_raw_uri";
132
79
    sigmatch_table[DETECT_HTTP_RAW_URI].desc = "content modifier to match on the raw HTTP uri";
133
79
    sigmatch_table[DETECT_HTTP_RAW_URI].url = "/rules/http-keywords.html#http_uri-and-http_raw-uri";
134
79
    sigmatch_table[DETECT_HTTP_RAW_URI].Setup = DetectHttpRawUriSetup;
135
79
    sigmatch_table[DETECT_HTTP_RAW_URI].flags |= SIGMATCH_NOOPT | SIGMATCH_INFO_CONTENT_MODIFIER;
136
79
    sigmatch_table[DETECT_HTTP_RAW_URI].alternative = DETECT_HTTP_URI_RAW;
137
138
    /* http.uri.raw sticky buffer */
139
79
    sigmatch_table[DETECT_HTTP_URI_RAW].name = "http.uri.raw";
140
79
    sigmatch_table[DETECT_HTTP_URI_RAW].desc = "sticky buffer to match specifically and only on the raw HTTP URI buffer";
141
79
    sigmatch_table[DETECT_HTTP_URI_RAW].url = "/rules/http-keywords.html#http-uri-and-http-raw-uri";
142
79
    sigmatch_table[DETECT_HTTP_URI_RAW].Setup = DetectHttpRawUriSetupSticky;
143
79
    sigmatch_table[DETECT_HTTP_URI_RAW].flags |= SIGMATCH_NOOPT|SIGMATCH_INFO_STICKY_BUFFER;
144
145
79
    DetectAppLayerInspectEngineRegister("http_raw_uri", ALPROTO_HTTP1, SIG_FLAG_TOSERVER,
146
79
            HTP_REQUEST_PROGRESS_LINE, DetectEngineInspectBufferGeneric, GetRawData);
147
148
79
    DetectAppLayerMpmRegister("http_raw_uri", SIG_FLAG_TOSERVER, 2, PrefilterGenericMpmRegister,
149
79
            GetRawData, ALPROTO_HTTP1, HTP_REQUEST_PROGRESS_LINE);
150
151
    // no difference between raw and decoded uri for HTTP2
152
79
    DetectAppLayerInspectEngineRegister("http_raw_uri", ALPROTO_HTTP2, SIG_FLAG_TOSERVER,
153
79
            HTTP2StateOpen, DetectEngineInspectBufferGeneric, GetData2);
154
155
79
    DetectAppLayerMpmRegister("http_raw_uri", SIG_FLAG_TOSERVER, 2, PrefilterGenericMpmRegister,
156
79
            GetData2, ALPROTO_HTTP2, HTTP2StateOpen);
157
158
79
    DetectBufferTypeSetDescriptionByName("http_raw_uri",
159
79
            "raw http uri");
160
161
79
    DetectBufferTypeRegisterSetupCallback("http_raw_uri",
162
79
            DetectHttpRawUriSetupCallback);
163
164
79
    DetectBufferTypeRegisterValidateCallback("http_raw_uri", DetectUrilenValidateContent);
165
166
79
    g_http_raw_uri_buffer_id = DetectBufferTypeGetByName("http_raw_uri");
167
79
}
168
169
/**
170
 * \brief this function setups the http_uri modifier keyword used in the rule
171
 *
172
 * \param de_ctx   Pointer to the Detection Engine Context
173
 * \param s        Pointer to the Signature to which the current keyword belongs
174
 * \param str      Should hold an empty string always
175
 *
176
 * \retval  0 On success
177
 * \retval -1 On failure
178
 */
179
180
int DetectHttpUriSetup(DetectEngineCtx *de_ctx, Signature *s, const char *str)
181
23.8k
{
182
23.8k
    return DetectEngineContentModifierBufferSetup(
183
23.8k
            de_ctx, s, str, DETECT_HTTP_URI_CM, g_http_uri_buffer_id, ALPROTO_HTTP1);
184
23.8k
}
185
186
static void DetectHttpUriSetupCallback(const DetectEngineCtx *de_ctx,
187
                                       Signature *s)
188
54.2k
{
189
54.2k
    SCLogDebug("callback invoked by %u", s->id);
190
54.2k
    DetectUrilenApplyToContent(s, g_http_uri_buffer_id);
191
54.2k
}
192
193
/**
194
 * \brief this function setup the http.uri keyword used in the rule
195
 *
196
 * \param de_ctx   Pointer to the Detection Engine Context
197
 * \param s        Pointer to the Signature to which the current keyword belongs
198
 * \param str      Should hold an empty string always
199
 *
200
 * \retval 0       On success
201
 */
202
static int DetectHttpUriSetupSticky(DetectEngineCtx *de_ctx, Signature *s, const char *str)
203
43.3k
{
204
43.3k
    if (SCDetectBufferSetActiveList(de_ctx, s, g_http_uri_buffer_id) < 0)
205
490
        return -1;
206
42.8k
    if (SCDetectSignatureSetAppProto(s, ALPROTO_HTTP) < 0)
207
1.27k
        return -1;
208
41.5k
    return 0;
209
42.8k
}
210
211
static InspectionBuffer *GetData(DetectEngineThreadCtx *det_ctx,
212
        const DetectEngineTransforms *transforms, Flow *_f,
213
        const uint8_t _flow_flags, void *txv, const int list_id)
214
3.17k
{
215
3.17k
    SCEnter();
216
217
3.17k
    InspectionBuffer *buffer = InspectionBufferGet(det_ctx, list_id);
218
3.17k
    if (!buffer->initialized) {
219
2.93k
        htp_tx_t *tx = (htp_tx_t *)txv;
220
2.93k
        bstr *request_uri_normalized = (bstr *)htp_tx_normalized_uri(tx);
221
2.93k
        if (request_uri_normalized == NULL)
222
2.02k
            return NULL;
223
224
912
        const uint32_t data_len = (uint32_t)bstr_len(request_uri_normalized);
225
912
        const uint8_t *data = bstr_ptr(request_uri_normalized);
226
227
912
        InspectionBufferSetupAndApplyTransforms(
228
912
                det_ctx, list_id, buffer, data, data_len, transforms);
229
912
    }
230
231
1.15k
    return buffer;
232
3.17k
}
233
234
static InspectionBuffer *GetData2(DetectEngineThreadCtx *det_ctx,
235
        const DetectEngineTransforms *transforms, Flow *_f, const uint8_t _flow_flags, void *txv,
236
        const int list_id)
237
840
{
238
840
    SCEnter();
239
240
840
    InspectionBuffer *buffer = InspectionBufferGet(det_ctx, list_id);
241
840
    if (!buffer->initialized) {
242
583
        uint32_t b_len = 0;
243
583
        const uint8_t *b = NULL;
244
245
583
        if (SCHttp2TxGetUri(txv, &b, &b_len) != 1)
246
39
            return NULL;
247
544
        if (b == NULL || b_len == 0)
248
2
            return NULL;
249
250
542
        InspectionBufferSetupAndApplyTransforms(det_ctx, list_id, buffer, b, b_len, transforms);
251
542
    }
252
253
799
    return buffer;
254
840
}
255
256
/**
257
 * \brief Sets up the http_raw_uri modifier keyword.
258
 *
259
 * \param de_ctx Pointer to the Detection Engine Context.
260
 * \param s      Pointer to the Signature to which the current keyword belongs.
261
 * \param arg    Should hold an empty string always.
262
 *
263
 * \retval  0 On success.
264
 * \retval -1 On failure.
265
 */
266
static int DetectHttpRawUriSetup(DetectEngineCtx *de_ctx, Signature *s, const char *arg)
267
164
{
268
164
    return DetectEngineContentModifierBufferSetup(
269
164
            de_ctx, s, arg, DETECT_HTTP_RAW_URI, g_http_raw_uri_buffer_id, ALPROTO_HTTP1);
270
164
}
271
272
static void DetectHttpRawUriSetupCallback(const DetectEngineCtx *de_ctx,
273
                                          Signature *s)
274
1.36k
{
275
1.36k
    SCLogDebug("callback invoked by %u", s->id);
276
1.36k
    DetectUrilenApplyToContent(s, g_http_raw_uri_buffer_id);
277
1.36k
}
278
279
/**
280
 * \brief this function setup the http.uri.raw keyword used in the rule
281
 *
282
 * \param de_ctx   Pointer to the Detection Engine Context
283
 * \param s        Pointer to the Signature to which the current keyword belongs
284
 * \param str      Should hold an empty string always
285
 *
286
 * \retval 0       On success
287
 */
288
static int DetectHttpRawUriSetupSticky(DetectEngineCtx *de_ctx, Signature *s, const char *str)
289
541
{
290
541
    if (SCDetectBufferSetActiveList(de_ctx, s, g_http_raw_uri_buffer_id) < 0)
291
1
        return -1;
292
540
    if (SCDetectSignatureSetAppProto(s, ALPROTO_HTTP) < 0)
293
1
        return -1;
294
539
    return 0;
295
540
}
296
297
static InspectionBuffer *GetRawData(DetectEngineThreadCtx *det_ctx,
298
        const DetectEngineTransforms *transforms, Flow *_f,
299
        const uint8_t _flow_flags, void *txv, const int list_id)
300
2.23k
{
301
2.23k
    SCEnter();
302
303
2.23k
    InspectionBuffer *buffer = InspectionBufferGet(det_ctx, list_id);
304
2.23k
    if (!buffer->initialized) {
305
2.22k
        htp_tx_t *tx = (htp_tx_t *)txv;
306
2.22k
        if (unlikely(htp_tx_request_uri(tx) == NULL)) {
307
444
            return NULL;
308
444
        }
309
1.78k
        const uint32_t data_len = (uint32_t)bstr_len(htp_tx_request_uri(tx));
310
1.78k
        const uint8_t *data = bstr_ptr(htp_tx_request_uri(tx));
311
312
1.78k
        InspectionBufferSetupAndApplyTransforms(
313
1.78k
                det_ctx, list_id, buffer, data, data_len, transforms);
314
1.78k
    }
315
316
1.78k
    return buffer;
317
2.23k
}
318
319
#ifdef UNITTESTS /* UNITTESTS */
320
#include "tests/detect-http-uri.c"
321
#endif /* UNITTESTS */
322
323
/**
324
 * @}
325
 */