mirror of
https://github.com/zeek/zeek.git
synced 2025-10-08 09:38:19 +00:00
FileAnalysis: add custom libmagic database.
- It's derived from the magic database of libmagic 5.14, but with most everything not related to mime types removed. - The custom database is always used by default for mime detection, but the more verbose file type detection will fall back on the default libmagic installation's database. The result is: mime type strings are now guaranteed to be consistent across platforms, but the verbose file type descriptions are not. - The custom database gets installed in $prefix/share/bro/magic, and should even be extensible if files with new patterns are added inside the directory. - The search path for the mime magic database can be controlled via BROMAGIC environment variable. - Remove mime_desc field from ftp.log. - Stop using the mime/file type canonifier with unit tests. - libmagic >= 5.04 is now a requirement.
This commit is contained in:
parent
b8c98b8bf7
commit
037d582b0e
106 changed files with 2951 additions and 174 deletions
|
@ -1,7 +1,7 @@
|
|||
FILE_NEW
|
||||
7gZBKVUgy4l, 0, 0
|
||||
FILE_TYPE
|
||||
mime type is set
|
||||
MIME_TYPE
|
||||
application/pdf
|
||||
FILE_OVER_NEW_CONNECTION
|
||||
FILE_STATE_REMOVE
|
||||
7gZBKVUgy4l, 555523, 0
|
||||
|
|
|
@ -1,7 +1,7 @@
|
|||
FILE_NEW
|
||||
oDwT1BbzjM1, 0, 0
|
||||
FILE_TYPE
|
||||
mime type is set
|
||||
MIME_TYPE
|
||||
application/x-dosexec
|
||||
FILE_STATE_REMOVE
|
||||
oDwT1BbzjM1, 1022920, 0
|
||||
[orig_h=192.168.72.14, orig_p=3254/tcp, resp_h=65.54.95.206, resp_p=80/tcp]
|
||||
|
@ -9,8 +9,8 @@ total bytes: 1022920
|
|||
source: HTTP
|
||||
FILE_NEW
|
||||
oDwT1BbzjM1, 0, 0
|
||||
FILE_TYPE
|
||||
mime type is set
|
||||
MIME_TYPE
|
||||
application/octet-stream
|
||||
FILE_TIMEOUT
|
||||
FILE_STATE_REMOVE
|
||||
oDwT1BbzjM1, 206024, 0
|
||||
|
|
|
@ -1,7 +1,7 @@
|
|||
FILE_NEW
|
||||
uHS14uhRKGe, 0, 0
|
||||
FILE_TYPE
|
||||
mime type is set
|
||||
MIME_TYPE
|
||||
application/octet-stream
|
||||
FILE_OVER_NEW_CONNECTION
|
||||
FILE_STATE_REMOVE
|
||||
uHS14uhRKGe, 498702, 0
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue