mirror of
https://github.com/zeek/zeek.git
synced 2025-10-14 04:28:20 +00:00
Moved DPD signatures into script specific directories.
- This caused us to lose signatures for POP3 and Bittorrent. These will need discovered in the repository again when we add scripts for those analyzers.
This commit is contained in:
parent
841604bebe
commit
39444b5af7
19 changed files with 181 additions and 216 deletions
|
@ -1 +1,3 @@
|
|||
@load ./main
|
||||
@load ./main
|
||||
|
||||
@load-sigs ./dpd.sig
|
13
scripts/base/protocols/ssh/dpd.sig
Normal file
13
scripts/base/protocols/ssh/dpd.sig
Normal file
|
@ -0,0 +1,13 @@
|
|||
signature dpd_ssh_client {
|
||||
ip-proto == tcp
|
||||
payload /^[sS][sS][hH]-/
|
||||
requires-reverse-signature dpd_ssh_server
|
||||
enable "ssh"
|
||||
tcp-state originator
|
||||
}
|
||||
|
||||
signature dpd_ssh_server {
|
||||
ip-proto == tcp
|
||||
payload /^[sS][sS][hH]-/
|
||||
tcp-state responder
|
||||
}
|
Loading…
Add table
Add a link
Reference in a new issue