mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00
Remove old, unmaintained p0f support.
Addresses GH-417
This commit is contained in:
parent
8f668ce82c
commit
632e83de57
12 changed files with 7 additions and 1978 deletions
|
@ -1844,9 +1844,6 @@ function add_signature_file(sold: string, snew: string): string
|
|||
## since that can search paths relative to the current script.
|
||||
global signature_files = "" &add_func = add_signature_file;
|
||||
|
||||
## ``p0f`` fingerprint file to use. Will be searched relative to ``ZEEKPATH``.
|
||||
const passive_fingerprint_file = "base/misc/p0f.fp" &redef;
|
||||
|
||||
## Definition of "secondary filters". A secondary filter is a BPF filter given
|
||||
## as index in this table. For each such filter, the corresponding event is
|
||||
## raised for all matching packets.
|
||||
|
@ -3991,30 +3988,6 @@ type software: record {
|
|||
version: software_version;
|
||||
};
|
||||
|
||||
## Quality of passive fingerprinting matches.
|
||||
##
|
||||
## .. zeek:see:: OS_version
|
||||
type OS_version_inference: enum {
|
||||
direct_inference, ##< TODO.
|
||||
generic_inference, ##< TODO.
|
||||
fuzzy_inference, ##< TODO.
|
||||
};
|
||||
|
||||
## Passive fingerprinting match.
|
||||
##
|
||||
## .. zeek:see:: OS_version_found
|
||||
type OS_version: record {
|
||||
genre: string; ##< Linux, Windows, AIX, ...
|
||||
detail: string; ##< Kernel version or such.
|
||||
dist: count; ##< How far is the host away from the sensor (TTL)?.
|
||||
match_type: OS_version_inference; ##< Quality of the match.
|
||||
};
|
||||
|
||||
## Defines for which subnets we should do passive fingerprinting.
|
||||
##
|
||||
## .. zeek:see:: OS_version_found
|
||||
global generate_OS_version_event: set[subnet] &redef;
|
||||
|
||||
# Type used to report load samples via :zeek:see:`load_sample`. For now, it's a
|
||||
# set of names (event names, source file names, and perhaps ``<source file, line
|
||||
# number>``), which were seen during the sample.
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue