mirror of
https://github.com/zeek/zeek.git
synced 2025-10-09 18:18:19 +00:00
add signature for dtls client hello
This commit is contained in:
parent
90bc5add6e
commit
58ed2eb9ae
2 changed files with 10 additions and 1 deletions
|
@ -13,3 +13,10 @@ signature dpd_ssl_client {
|
|||
payload /^(\x16\x03[\x00\x01\x02\x03]..\x01...\x03[\x00\x01\x02\x03]|...?\x01[\x00\x03][\x00\x01\x02\x03]).*/
|
||||
tcp-state originator
|
||||
}
|
||||
|
||||
signature dpd_dtls_client {
|
||||
ip-proto == udp
|
||||
# Client hello.
|
||||
payload /^\x16\xfe[\xff\xfd]\x00\x00\x00\x00\x00\x00\x00...\x01...........\xfe[\xff\xfd].*/
|
||||
enable "dtls"
|
||||
}
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue