Add RDP over UDP analyzer

This commit is contained in:
Anthony Kasza 2020-03-22 14:43:54 -06:00 committed by Jon Siwek
parent c42ebfa1cf
commit 60644bc85f
15 changed files with 512 additions and 7 deletions

View file

@ -10,3 +10,12 @@ signature dpd_rdp_server {
ip-proto == tcp
payload /(.{5}\xd0|.*McDn)/
}
signature dpd_rdpeudp_syn {
ip-proto == udp
payload-size <= 1232
payload-size >= 1132
payload /^\xff{4}.{2}.{1}\x01/
enable "rdpeudp"
}

View file

@ -85,13 +85,15 @@ redef record connection += {
rdp: Info &optional;
};
const ports = { 3389/tcp };
redef likely_server_ports += { ports };
const rdp_ports = { 3389/tcp };
const rdpeudp_ports = { 3389/udp };
redef likely_server_ports += { rdp_ports, rdpeudp_ports };
event zeek_init() &priority=5
{
Log::create_stream(RDP::LOG, [$columns=RDP::Info, $ev=log_rdp, $path="rdp"]);
Analyzer::register_for_ports(Analyzer::ANALYZER_RDP, ports);
Analyzer::register_for_ports(Analyzer::ANALYZER_RDP, rdp_ports);
Analyzer::register_for_ports(Analyzer::ANALYZER_RDP, rdpeudp_ports);
}
function write_log(c: connection)