mirror of
https://github.com/zeek/zeek.git
synced 2025-10-06 00:28:21 +00:00
Bringing the DPD POP3 signature back.
This also avoids the need for updating the external test suite.
This commit is contained in:
parent
cb09bd6358
commit
06287966a1
4 changed files with 19 additions and 2 deletions
|
@ -41,6 +41,7 @@
|
||||||
@load base/protocols/http
|
@load base/protocols/http
|
||||||
@load base/protocols/irc
|
@load base/protocols/irc
|
||||||
@load base/protocols/modbus
|
@load base/protocols/modbus
|
||||||
|
@load base/protocols/pop3
|
||||||
@load base/protocols/smtp
|
@load base/protocols/smtp
|
||||||
@load base/protocols/socks
|
@load base/protocols/socks
|
||||||
@load base/protocols/ssh
|
@load base/protocols/ssh
|
||||||
|
|
2
scripts/base/protocols/pop3/__load__.bro
Normal file
2
scripts/base/protocols/pop3/__load__.bro
Normal file
|
@ -0,0 +1,2 @@
|
||||||
|
|
||||||
|
@load-sigs ./dpd.sig
|
13
scripts/base/protocols/pop3/dpd.sig
Normal file
13
scripts/base/protocols/pop3/dpd.sig
Normal file
|
@ -0,0 +1,13 @@
|
||||||
|
signature dpd_pop3_server {
|
||||||
|
ip-proto == tcp
|
||||||
|
payload /^\+OK/
|
||||||
|
requires-reverse-signature dpd_pop3_client
|
||||||
|
enable "pop3"
|
||||||
|
tcp-state responder
|
||||||
|
}
|
||||||
|
|
||||||
|
signature dpd_pop3_client {
|
||||||
|
ip-proto == tcp
|
||||||
|
payload /(|.*[\r\n])[[:space:]]*([uU][sS][eE][rR][[:space:]]|[aA][pP][oO][pP][[:space:]]|[cC][aA][pP][aA]|[aA][uU][tT][hH])/
|
||||||
|
tcp-state originator
|
||||||
|
}
|
|
@ -3,7 +3,7 @@
|
||||||
#empty_field (empty)
|
#empty_field (empty)
|
||||||
#unset_field -
|
#unset_field -
|
||||||
#path loaded_scripts
|
#path loaded_scripts
|
||||||
#open 2013-07-10-03-19-58
|
#open 2013-07-10-21-18-31
|
||||||
#fields name
|
#fields name
|
||||||
#types string
|
#types string
|
||||||
scripts/base/init-bare.bro
|
scripts/base/init-bare.bro
|
||||||
|
@ -178,6 +178,7 @@ scripts/base/init-default.bro
|
||||||
scripts/base/protocols/modbus/__load__.bro
|
scripts/base/protocols/modbus/__load__.bro
|
||||||
scripts/base/protocols/modbus/consts.bro
|
scripts/base/protocols/modbus/consts.bro
|
||||||
scripts/base/protocols/modbus/main.bro
|
scripts/base/protocols/modbus/main.bro
|
||||||
|
scripts/base/protocols/pop3/__load__.bro
|
||||||
scripts/base/protocols/smtp/__load__.bro
|
scripts/base/protocols/smtp/__load__.bro
|
||||||
scripts/base/protocols/smtp/main.bro
|
scripts/base/protocols/smtp/main.bro
|
||||||
scripts/base/protocols/smtp/entities.bro
|
scripts/base/protocols/smtp/entities.bro
|
||||||
|
@ -194,4 +195,4 @@ scripts/base/init-default.bro
|
||||||
scripts/base/protocols/tunnels/__load__.bro
|
scripts/base/protocols/tunnels/__load__.bro
|
||||||
scripts/base/misc/find-checksum-offloading.bro
|
scripts/base/misc/find-checksum-offloading.bro
|
||||||
scripts/policy/misc/loaded-scripts.bro
|
scripts/policy/misc/loaded-scripts.bro
|
||||||
#close 2013-07-10-03-19-58
|
#close 2013-07-10-21-18-31
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue