<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Arg Name and Arg Value regex matching in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/arg-name-and-arg-value-regex-matching/m-p/512004#M90283</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It should be matching the arg name regex first.  The alert though could be showing you the last matches of the packet hence only the Arg Value Regex.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Arg Name Regex matches a space or tab, these could have come earlier in the stream or in the packet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Mar 2006 03:28:35 GMT</pubDate>
    <dc:creator>jlimbo</dc:creator>
    <dc:date>2006-03-15T03:28:35Z</dc:date>
    <item>
      <title>Arg Name and Arg Value regex matching</title>
      <link>https://community.cisco.com/t5/network-security/arg-name-and-arg-value-regex-matching/m-p/512003#M90282</link>
      <description>&lt;P&gt;Signature 5045-0 (WWW xterm Remote Shell Access) fired an alarm with "log pair packets" enabled.  I cannot provide the trace for confidentiality reasons. Here are the regex from that signature:&lt;/P&gt;&lt;P&gt;Arg Name Regex: term([ \t]|(%(20|09)))&lt;/P&gt;&lt;P&gt;Arg Value Regex: [-]display&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only the very 1st packet matched the Arg Value Regex (contained the string "-display").  It did not match the Arg Name Regex.  How is this possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do these particular regex's basically match anywhere in the HTTP stream and in any order?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:55:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/arg-name-and-arg-value-regex-matching/m-p/512003#M90282</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2019-03-10T09:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Arg Name and Arg Value regex matching</title>
      <link>https://community.cisco.com/t5/network-security/arg-name-and-arg-value-regex-matching/m-p/512004#M90283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It should be matching the arg name regex first.  The alert though could be showing you the last matches of the packet hence only the Arg Value Regex.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Arg Name Regex matches a space or tab, these could have come earlier in the stream or in the packet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Mar 2006 03:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/arg-name-and-arg-value-regex-matching/m-p/512004#M90283</guid>
      <dc:creator>jlimbo</dc:creator>
      <dc:date>2006-03-15T03:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: Arg Name and Arg Value regex matching</title>
      <link>https://community.cisco.com/t5/network-security/arg-name-and-arg-value-regex-matching/m-p/512005#M90284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shouldn't the ip logging process have the whole stream, or at least all relevant parts that match the regex?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's assume it doesn't, and I'm missing the first regex match.  I'm just trying to understand how these particular regex's work.  They will match query params and anywhere in the HTTP message-body (for an HTTP post for example). The order does matter, but for example a file upload of a text file with the following contents will trigger(i've tested and it does):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;long term health insurance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The quick brown fox jumped over the fence&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;non-display&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just want to make sure that is that the expected behavior?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Mar 2006 15:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/arg-name-and-arg-value-regex-matching/m-p/512005#M90284</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-03-15T15:22:21Z</dc:date>
    </item>
  </channel>
</rss>

