Added plugin.unprocessed_packet_hook btest

This commit is contained in:
Tim Wojtulewicz 2021-11-11 14:36:32 -07:00
parent d0f8c50417
commit 6e8dae316b
8 changed files with 540 additions and 2 deletions

View file

@ -0,0 +1,132 @@
1529347003.888515 | HookUnprocessedPacket [ts=1529347003.888515 len=60]
packet_not_processed: ts=1529347003.888515
1529347003.889372 | HookUnprocessedPacket [ts=1529347003.889372 len=62]
packet_not_processed: ts=1529347003.889372
1529347003.890009 | HookUnprocessedPacket [ts=1529347003.890009 len=60]
packet_not_processed: ts=1529347003.890009
1529347003.890881 | HookUnprocessedPacket [ts=1529347003.890881 len=62]
packet_not_processed: ts=1529347003.890881
1529347003.891520 | HookUnprocessedPacket [ts=1529347003.89152 len=60]
packet_not_processed: ts=1529347003.891520
1529347003.892374 | HookUnprocessedPacket [ts=1529347003.892374 len=62]
packet_not_processed: ts=1529347003.892374
1529347003.893010 | HookUnprocessedPacket [ts=1529347003.89301 len=60]
packet_not_processed: ts=1529347003.893010
1529347003.893973 | HookUnprocessedPacket [ts=1529347003.893973 len=62]
packet_not_processed: ts=1529347003.893973
1529347003.894627 | HookUnprocessedPacket [ts=1529347003.894627 len=60]
packet_not_processed: ts=1529347003.894627
1529347003.895482 | HookUnprocessedPacket [ts=1529347003.895482 len=62]
packet_not_processed: ts=1529347003.895482
1529347003.896120 | HookUnprocessedPacket [ts=1529347003.89612 len=60]
packet_not_processed: ts=1529347003.896120
1529347003.896974 | HookUnprocessedPacket [ts=1529347003.896974 len=62]
packet_not_processed: ts=1529347003.896974
1529347003.897608 | HookUnprocessedPacket [ts=1529347003.897608 len=60]
packet_not_processed: ts=1529347003.897608
1529347003.898627 | HookUnprocessedPacket [ts=1529347003.898627 len=62]
packet_not_processed: ts=1529347003.898627
1529347003.899558 | HookUnprocessedPacket [ts=1529347003.899558 len=60]
packet_not_processed: ts=1529347003.899558
1529347003.900941 | HookUnprocessedPacket [ts=1529347003.900941 len=62]
packet_not_processed: ts=1529347003.900941
1529347003.901790 | HookUnprocessedPacket [ts=1529347003.90179 len=66]
packet_not_processed: ts=1529347003.901790
1529347003.902972 | HookUnprocessedPacket [ts=1529347003.902972 len=82]
packet_not_processed: ts=1529347003.902972
1529347003.903806 | HookUnprocessedPacket [ts=1529347003.903806 len=66]
packet_not_processed: ts=1529347003.903806
1529347003.904631 | HookUnprocessedPacket [ts=1529347003.904631 len=82]
packet_not_processed: ts=1529347003.904631
1529347003.905200 | HookUnprocessedPacket [ts=1529347003.9052 len=66]
packet_not_processed: ts=1529347003.905200
1529347003.905985 | HookUnprocessedPacket [ts=1529347003.905985 len=82]
packet_not_processed: ts=1529347003.905985
1529347003.906561 | HookUnprocessedPacket [ts=1529347003.906561 len=66]
packet_not_processed: ts=1529347003.906561
1529347003.907448 | HookUnprocessedPacket [ts=1529347003.907448 len=82]
packet_not_processed: ts=1529347003.907448
1529347003.908018 | HookUnprocessedPacket [ts=1529347003.908018 len=66]
packet_not_processed: ts=1529347003.908018
1529347003.908803 | HookUnprocessedPacket [ts=1529347003.908803 len=82]
packet_not_processed: ts=1529347003.908803
1529347003.909373 | HookUnprocessedPacket [ts=1529347003.909373 len=66]
packet_not_processed: ts=1529347003.909373
1529347003.910163 | HookUnprocessedPacket [ts=1529347003.910163 len=82]
packet_not_processed: ts=1529347003.910163
1529347003.910733 | HookUnprocessedPacket [ts=1529347003.910733 len=66]
packet_not_processed: ts=1529347003.910733
1529347003.911522 | HookUnprocessedPacket [ts=1529347003.911522 len=82]
packet_not_processed: ts=1529347003.911522
1529347003.912089 | HookUnprocessedPacket [ts=1529347003.912089 len=66]
packet_not_processed: ts=1529347003.912089
1529347003.912976 | HookUnprocessedPacket [ts=1529347003.912976 len=82]
packet_not_processed: ts=1529347003.912976
1529347003.913490 | HookUnprocessedPacket [ts=1529347003.91349 len=60]
packet_not_processed: ts=1529347003.913490
1529347003.914244 | HookUnprocessedPacket [ts=1529347003.914244 len=60]
packet_not_processed: ts=1529347003.914244
1529347003.914754 | HookUnprocessedPacket [ts=1529347003.914754 len=60]
packet_not_processed: ts=1529347003.914754
1529347003.915493 | HookUnprocessedPacket [ts=1529347003.915493 len=60]
packet_not_processed: ts=1529347003.915493
1529347003.916000 | HookUnprocessedPacket [ts=1529347003.916 len=60]
packet_not_processed: ts=1529347003.916000
1529347003.916730 | HookUnprocessedPacket [ts=1529347003.91673 len=60]
packet_not_processed: ts=1529347003.916730
1529347003.917240 | HookUnprocessedPacket [ts=1529347003.91724 len=60]
packet_not_processed: ts=1529347003.917240
1529347003.917969 | HookUnprocessedPacket [ts=1529347003.917969 len=60]
packet_not_processed: ts=1529347003.917969
1529347003.918497 | HookUnprocessedPacket [ts=1529347003.918497 len=60]
packet_not_processed: ts=1529347003.918497
1529347003.919336 | HookUnprocessedPacket [ts=1529347003.919336 len=60]
packet_not_processed: ts=1529347003.919336
1529347003.919847 | HookUnprocessedPacket [ts=1529347003.919847 len=60]
packet_not_processed: ts=1529347003.919847
1529347003.920577 | HookUnprocessedPacket [ts=1529347003.920577 len=60]
packet_not_processed: ts=1529347003.920577
1529347003.921087 | HookUnprocessedPacket [ts=1529347003.921087 len=60]
packet_not_processed: ts=1529347003.921087
1529347003.921815 | HookUnprocessedPacket [ts=1529347003.921815 len=60]
packet_not_processed: ts=1529347003.921815
1529347003.922337 | HookUnprocessedPacket [ts=1529347003.922337 len=60]
packet_not_processed: ts=1529347003.922337
1529347003.923067 | HookUnprocessedPacket [ts=1529347003.923067 len=60]
packet_not_processed: ts=1529347003.923067
1529347003.923524 | HookUnprocessedPacket [ts=1529347003.923524 len=60]
packet_not_processed: ts=1529347003.923524
1529347003.924192 | HookUnprocessedPacket [ts=1529347003.924192 len=70]
packet_not_processed: ts=1529347003.924192
1529347003.924644 | HookUnprocessedPacket [ts=1529347003.924644 len=60]
packet_not_processed: ts=1529347003.924644
1529347003.925420 | HookUnprocessedPacket [ts=1529347003.92542 len=70]
packet_not_processed: ts=1529347003.925420
1529347003.925870 | HookUnprocessedPacket [ts=1529347003.92587 len=60]
packet_not_processed: ts=1529347003.925870
1529347003.926550 | HookUnprocessedPacket [ts=1529347003.92655 len=70]
packet_not_processed: ts=1529347003.926550
1529347003.926999 | HookUnprocessedPacket [ts=1529347003.926999 len=60]
packet_not_processed: ts=1529347003.926999
1529347003.927662 | HookUnprocessedPacket [ts=1529347003.927662 len=70]
packet_not_processed: ts=1529347003.927662
1529347003.928108 | HookUnprocessedPacket [ts=1529347003.928108 len=60]
packet_not_processed: ts=1529347003.928108
1529347003.928773 | HookUnprocessedPacket [ts=1529347003.928773 len=70]
packet_not_processed: ts=1529347003.928773
1529347003.929220 | HookUnprocessedPacket [ts=1529347003.92922 len=60]
packet_not_processed: ts=1529347003.929220
1529347003.929885 | HookUnprocessedPacket [ts=1529347003.929885 len=70]
packet_not_processed: ts=1529347003.929885
1529347003.930352 | HookUnprocessedPacket [ts=1529347003.930352 len=60]
packet_not_processed: ts=1529347003.930352
1529347003.931118 | HookUnprocessedPacket [ts=1529347003.931118 len=70]
packet_not_processed: ts=1529347003.931118
1529347003.931567 | HookUnprocessedPacket [ts=1529347003.931567 len=60]
packet_not_processed: ts=1529347003.931567
1529347003.932231 | HookUnprocessedPacket [ts=1529347003.932231 len=70]
packet_not_processed: ts=1529347003.932231
1529347003.932477 | HookUnprocessedPacket [ts=1529347003.932477 len=60]
packet_not_processed: ts=1529347003.932477
1529347003.932971 | HookUnprocessedPacket [ts=1529347003.932971 len=60]
packet_not_processed: ts=1529347003.932971

View file

@ -0,0 +1,336 @@
00000000 d4 c3 b2 a1 02 00 04 00 00 00 00 00 00 00 00 00 |................|
00000010 00 24 00 00 01 00 00 00 bb fb 27 5b c3 8e 0d 00 |.$........'[....|
00000020 3c 00 00 00 3c 00 00 00 a7 ab 16 9f 39 00 d4 f1 |<...<.......9...|
00000030 20 a6 03 c3 08 00 45 00 00 20 00 01 00 00 40 84 | .....E.. ....@.|
00000040 74 4f 01 01 01 06 02 02 02 02 de ad be ef 00 00 |tO..............|
00000050 00 00 4e 61 be 7a 00 00 00 00 00 00 00 00 00 00 |..Na.z..........|
00000060 00 00 00 00 bb fb 27 5b 1c 92 0d 00 3e 00 00 00 |......'[....>...|
00000070 3e 00 00 00 8c 71 c7 b1 fd 00 39 ad 7d 5e 0d c4 |>....q....9.}^..|
00000080 89 03 00 00 a7 ab 16 9f 39 c1 d4 f1 20 a6 03 c3 |........9... ...|
00000090 08 00 45 00 00 20 00 01 00 00 40 84 74 4f 01 01 |..E.. ....@.tO..|
000000a0 01 06 02 02 02 02 de ad be ef 00 00 00 00 4e 61 |..............Na|
000000b0 be 7a bb fb 27 5b 99 94 0d 00 3c 00 00 00 3c 00 |.z..'[....<...<.|
000000c0 00 00 5a 71 7a 02 7d 01 15 b2 9a 53 00 c1 08 00 |..Zqz.}....S....|
000000d0 45 00 00 20 00 01 00 00 40 84 74 51 01 01 01 04 |E.. ....@.tQ....|
000000e0 02 02 02 02 de ad be ef 00 00 00 00 4e 61 be 7a |............Na.z|
000000f0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 bb fb |................|
00000100 27 5b 01 98 0d 00 3e 00 00 00 3e 00 00 00 ea b8 |'[....>...>.....|
00000110 ac 2b 4f 01 68 be ce d7 aa 97 89 03 00 00 5a 71 |.+O.h.........Zq|
00000120 7a 02 7d e3 15 b2 9a 53 00 c1 08 00 45 00 00 20 |z.}....S....E.. |
00000130 00 01 00 00 40 84 74 51 01 01 01 04 02 02 02 02 |....@.tQ........|
00000140 de ad be ef 00 00 00 00 4e 61 be 7a bb fb 27 5b |........Na.z..'[|
00000150 80 9a 0d 00 3c 00 00 00 3c 00 00 00 07 21 7a b4 |....<...<....!z.|
00000160 15 02 de e3 dd 85 00 77 08 00 45 00 00 20 00 01 |.......w..E.. ..|
00000170 00 00 40 84 74 47 01 01 01 0e 02 02 02 02 de ad |..@.tG..........|
00000180 be ef 00 00 00 00 4e 61 be 7a 00 00 00 00 00 00 |......Na.z......|
00000190 00 00 00 00 00 00 00 00 bb fb 27 5b d6 9d 0d 00 |..........'[....|
000001a0 3e 00 00 00 3e 00 00 00 1b ad 85 88 cf 02 f6 df |>...>...........|
000001b0 33 01 f7 de 89 03 00 00 07 21 7a b4 15 1e de e3 |3........!z.....|
000001c0 dd 85 00 77 08 00 45 00 00 20 00 01 00 00 40 84 |...w..E.. ....@.|
000001d0 74 47 01 01 01 0e 02 02 02 02 de ad be ef 00 00 |tG..............|
000001e0 00 00 4e 61 be 7a bb fb 27 5b 52 a0 0d 00 3c 00 |..Na.z..'[R...<.|
000001f0 00 00 3c 00 00 00 dd d2 34 28 20 03 5a 52 ca 2e |..<.....4( .ZR..|
00000200 98 e5 08 00 45 00 00 20 00 01 00 00 40 84 74 49 |....E.. ....@.tI|
00000210 01 01 01 0c 02 02 02 02 de ad be ef 00 00 00 00 |................|
00000220 4e 61 be 7a 00 00 00 00 00 00 00 00 00 00 00 00 |Na.z............|
00000230 00 00 bb fb 27 5b 15 a4 0d 00 3e 00 00 00 3e 00 |....'[....>...>.|
00000240 00 00 1b 1a cb fc 0c 03 77 45 7b 36 65 7a 89 03 |........wE{6ez..|
00000250 00 00 dd d2 34 28 20 92 5a 52 ca 2e 98 e5 08 00 |....4( .ZR......|
00000260 45 00 00 20 00 01 00 00 40 84 74 49 01 01 01 0c |E.. ....@.tI....|
00000270 02 02 02 02 de ad be ef 00 00 00 00 4e 61 be 7a |............Na.z|
00000280 bb fb 27 5b a3 a6 0d 00 3c 00 00 00 3c 00 00 00 |..'[....<...<...|
00000290 fb 21 a9 34 94 04 45 62 50 d6 35 a0 08 00 45 00 |.!.4..EbP.5...E.|
000002a0 00 20 00 01 00 00 40 84 74 55 01 01 01 00 02 02 |. ....@.tU......|
000002b0 02 02 de ad be ef 00 00 00 00 4e 61 be 7a 00 00 |..........Na.z..|
000002c0 00 00 00 00 00 00 00 00 00 00 00 00 bb fb 27 5b |..............'[|
000002d0 fa a9 0d 00 3e 00 00 00 3e 00 00 00 7e b9 2f de |....>...>...~./.|
000002e0 88 04 86 c5 f7 b1 99 a6 89 03 00 00 fb 21 a9 34 |.............!.4|
000002f0 94 74 45 62 50 d6 35 a0 08 00 45 00 00 20 00 01 |.tEbP.5...E.. ..|
00000300 00 00 40 84 74 55 01 01 01 00 02 02 02 02 de ad |..@.tU..........|
00000310 be ef 00 00 00 00 4e 61 be 7a bb fb 27 5b 78 ac |......Na.z..'[x.|
00000320 0d 00 3c 00 00 00 3c 00 00 00 7f 3c 8f ef 67 05 |..<...<....<..g.|
00000330 b5 44 ab 5c 51 6e 08 00 45 00 00 20 00 01 00 00 |.D.\Qn..E.. ....|
00000340 40 84 74 53 01 01 01 02 02 02 02 02 de ad be ef |@.tS............|
00000350 00 00 00 00 4e 61 be 7a 00 00 00 00 00 00 00 00 |....Na.z........|
00000360 00 00 00 00 00 00 bb fb 27 5b ce af 0d 00 3e 00 |........'[....>.|
00000370 00 00 3e 00 00 00 f9 b4 40 06 3a 05 29 2c 74 fa |..>.....@.:.),t.|
00000380 8a a9 89 03 00 00 7f 3c 8f ef 67 cb b5 44 ab 5c |.......<..g..D.\|
00000390 51 6e 08 00 45 00 00 20 00 01 00 00 40 84 74 53 |Qn..E.. ....@.tS|
000003a0 01 01 01 02 02 02 02 02 de ad be ef 00 00 00 00 |................|
000003b0 4e 61 be 7a bb fb 27 5b 48 b2 0d 00 3c 00 00 00 |Na.z..'[H...<...|
000003c0 3c 00 00 00 b4 92 07 fa 3d 06 80 46 5d bd b8 6a |<.......=..F]..j|
000003d0 08 00 45 00 00 20 00 01 00 00 40 84 74 4d 01 01 |..E.. ....@.tM..|
000003e0 01 08 02 02 02 02 de ad be ef 00 00 00 00 4e 61 |..............Na|
000003f0 be 7a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |.z..............|
00000400 bb fb 27 5b 43 b6 0d 00 3e 00 00 00 3e 00 00 00 |..'[C...>...>...|
00000410 47 1f c4 81 7f 06 ec ba a9 51 3c 0a 89 03 00 00 |G........Q<.....|
00000420 b4 92 07 fa 3d 82 80 46 5d bd b8 6a 08 00 45 00 |....=..F]..j..E.|
00000430 00 20 00 01 00 00 40 84 74 4d 01 01 01 08 02 02 |. ....@.tM......|
00000440 02 02 de ad be ef 00 00 00 00 4e 61 be 7a bb fb |..........Na.z..|
00000450 27 5b e6 b9 0d 00 3c 00 00 00 3c 00 00 00 01 1a |'[....<...<.....|
00000460 72 65 2d 07 e7 43 32 3e 5e fb 08 00 45 00 00 20 |re-..C2>^...E.. |
00000470 00 01 00 00 40 84 74 4b 01 01 01 0a 02 02 02 02 |....@.tK........|
00000480 de ad be ef 00 00 00 00 4e 61 be 7a 00 00 00 00 |........Na.z....|
00000490 00 00 00 00 00 00 00 00 00 00 bb fb 27 5b 4d bf |............'[M.|
000004a0 0d 00 3e 00 00 00 3e 00 00 00 7e 86 23 7f 61 07 |..>...>...~.#.a.|
000004b0 bb 5f a0 46 c4 4f 89 03 00 00 01 1a 72 65 2d 80 |._.F.O......re-.|
000004c0 e7 43 32 3e 5e fb 08 00 45 00 00 20 00 01 00 00 |.C2>^...E.. ....|
000004d0 40 84 74 4b 01 01 01 0a 02 02 02 02 de ad be ef |@.tK............|
000004e0 00 00 00 00 4e 61 be 7a bb fb 27 5b 9e c2 0d 00 |....Na.z..'[....|
000004f0 42 00 00 00 42 00 00 00 6a 1f e4 d6 dd 00 f2 8f |B...B...j.......|
00000500 23 41 61 f0 86 dd 60 00 00 00 00 0c 84 40 12 34 |#Aa...`......@.4|
00000510 00 00 00 00 00 00 00 00 00 00 00 00 00 0e 56 78 |..............Vx|
00000520 00 00 00 00 00 00 00 00 00 00 00 00 00 00 de ad |................|
00000530 be ef 00 00 00 00 4e 61 be 7a bb fb 27 5b 3c c7 |......Na.z..'[<.|
00000540 0d 00 52 00 00 00 52 00 00 00 66 0b 62 a8 88 00 |..R...R...f.b...|
00000550 0a ad 9a a9 1e 97 89 03 00 00 6a 1f e4 d6 dd ef |..........j.....|
00000560 f2 8f 23 41 61 f0 86 dd 60 00 00 00 00 0c 84 40 |..#Aa...`......@|
00000570 12 34 00 00 00 00 00 00 00 00 00 00 00 00 00 0e |.4..............|
00000580 56 78 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |Vx..............|
00000590 de ad be ef 00 00 00 00 4e 61 be 7a bb fb 27 5b |........Na.z..'[|
000005a0 7e ca 0d 00 42 00 00 00 42 00 00 00 85 60 e6 6b |~...B...B....`.k|
000005b0 83 01 7b 41 63 96 85 e6 86 dd 60 00 00 00 00 0c |..{Ac.....`.....|
000005c0 84 40 12 34 00 00 00 00 00 00 00 00 00 00 00 00 |.@.4............|
000005d0 00 0c 56 78 00 00 00 00 00 00 00 00 00 00 00 00 |..Vx............|
000005e0 00 00 de ad be ef 00 00 00 00 4e 61 be 7a bb fb |..........Na.z..|
000005f0 27 5b b7 cd 0d 00 52 00 00 00 52 00 00 00 5d 0e |'[....R...R...].|
00000600 08 a3 7b 01 80 1f c3 9d d1 d9 89 03 00 00 85 60 |..{............`|
00000610 e6 6b 83 14 7b 41 63 96 85 e6 86 dd 60 00 00 00 |.k..{Ac.....`...|
00000620 00 0c 84 40 12 34 00 00 00 00 00 00 00 00 00 00 |...@.4..........|
00000630 00 00 00 0c 56 78 00 00 00 00 00 00 00 00 00 00 |....Vx..........|
00000640 00 00 00 00 de ad be ef 00 00 00 00 4e 61 be 7a |............Na.z|
00000650 bb fb 27 5b f0 cf 0d 00 42 00 00 00 42 00 00 00 |..'[....B...B...|
00000660 ae 24 47 01 9e 02 62 c6 11 c1 8c fd 86 dd 60 00 |.$G...b.......`.|
00000670 00 00 00 0c 84 40 12 34 00 00 00 00 00 00 00 00 |.....@.4........|
00000680 00 00 00 00 00 06 56 78 00 00 00 00 00 00 00 00 |......Vx........|
00000690 00 00 00 00 00 00 de ad be ef 00 00 00 00 4e 61 |..............Na|
000006a0 be 7a bb fb 27 5b 01 d3 0d 00 52 00 00 00 52 00 |.z..'[....R...R.|
000006b0 00 00 7d 31 25 ee cc 02 78 1b aa d2 29 67 89 03 |..}1%...x...)g..|
000006c0 00 00 ae 24 47 01 9e 88 62 c6 11 c1 8c fd 86 dd |...$G...b.......|
000006d0 60 00 00 00 00 0c 84 40 12 34 00 00 00 00 00 00 |`......@.4......|
000006e0 00 00 00 00 00 00 00 06 56 78 00 00 00 00 00 00 |........Vx......|
000006f0 00 00 00 00 00 00 00 00 de ad be ef 00 00 00 00 |................|
00000700 4e 61 be 7a bb fb 27 5b 41 d5 0d 00 42 00 00 00 |Na.z..'[A...B...|
00000710 42 00 00 00 10 ea 0a 20 67 03 38 aa ef 53 9c 1d |B...... g.8..S..|
00000720 86 dd 60 00 00 00 00 0c 84 40 12 34 00 00 00 00 |..`......@.4....|
00000730 00 00 00 00 00 00 00 00 00 04 56 78 00 00 00 00 |..........Vx....|
00000740 00 00 00 00 00 00 00 00 00 00 de ad be ef 00 00 |................|
00000750 00 00 4e 61 be 7a bb fb 27 5b b8 d8 0d 00 52 00 |..Na.z..'[....R.|
00000760 00 00 52 00 00 00 99 81 5f e9 cb 03 53 02 b0 7f |..R....._...S...|
00000770 97 d7 89 03 00 00 10 ea 0a 20 67 c0 38 aa ef 53 |......... g.8..S|
00000780 9c 1d 86 dd 60 00 00 00 00 0c 84 40 12 34 00 00 |....`......@.4..|
00000790 00 00 00 00 00 00 00 00 00 00 00 04 56 78 00 00 |............Vx..|
000007a0 00 00 00 00 00 00 00 00 00 00 00 00 de ad be ef |................|
000007b0 00 00 00 00 4e 61 be 7a bb fb 27 5b f2 da 0d 00 |....Na.z..'[....|
000007c0 42 00 00 00 42 00 00 00 58 dd f8 44 97 04 e3 17 |B...B...X..D....|
000007d0 e3 dc 91 fe 86 dd 60 00 00 00 00 0c 84 40 12 34 |......`......@.4|
000007e0 00 00 00 00 00 00 00 00 00 00 00 00 00 08 56 78 |..............Vx|
000007f0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 de ad |................|
00000800 be ef 00 00 00 00 4e 61 be 7a bb fb 27 5b 03 de |......Na.z..'[..|
00000810 0d 00 52 00 00 00 52 00 00 00 6d 78 c2 70 5f 04 |..R...R...mx.p_.|
00000820 8e cc 87 4b e6 5e 89 03 00 00 58 dd f8 44 97 76 |...K.^....X..D.v|
00000830 e3 17 e3 dc 91 fe 86 dd 60 00 00 00 00 0c 84 40 |........`......@|
00000840 12 34 00 00 00 00 00 00 00 00 00 00 00 00 00 08 |.4..............|
00000850 56 78 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |Vx..............|
00000860 de ad be ef 00 00 00 00 4e 61 be 7a bb fb 27 5b |........Na.z..'[|
00000870 3d e0 0d 00 42 00 00 00 42 00 00 00 a3 e2 21 1b |=...B...B.....!.|
00000880 ef 05 35 29 8f 97 f9 aa 86 dd 60 00 00 00 00 0c |..5)......`.....|
00000890 84 40 12 34 00 00 00 00 00 00 00 00 00 00 00 00 |.@.4............|
000008a0 00 0a 56 78 00 00 00 00 00 00 00 00 00 00 00 00 |..Vx............|
000008b0 00 00 de ad be ef 00 00 00 00 4e 61 be 7a bb fb |..........Na.z..|
000008c0 27 5b 53 e3 0d 00 52 00 00 00 52 00 00 00 3c 97 |'[S...R...R...<.|
000008d0 50 ba a0 05 e8 79 60 77 c7 1c 89 03 00 00 a3 e2 |P....y`w........|
000008e0 21 1b ef 54 35 29 8f 97 f9 aa 86 dd 60 00 00 00 |!..T5)......`...|
000008f0 00 0c 84 40 12 34 00 00 00 00 00 00 00 00 00 00 |...@.4..........|
00000900 00 00 00 0a 56 78 00 00 00 00 00 00 00 00 00 00 |....Vx..........|
00000910 00 00 00 00 de ad be ef 00 00 00 00 4e 61 be 7a |............Na.z|
00000920 bb fb 27 5b 8d e5 0d 00 42 00 00 00 42 00 00 00 |..'[....B...B...|
00000930 c6 60 5c 89 df 06 53 9a 0b 1e 70 34 86 dd 60 00 |.`\...S...p4..`.|
00000940 00 00 00 0c 84 40 12 34 00 00 00 00 00 00 00 00 |.....@.4........|
00000950 00 00 00 00 00 00 56 78 00 00 00 00 00 00 00 00 |......Vx........|
00000960 00 00 00 00 00 00 de ad be ef 00 00 00 00 4e 61 |..............Na|
00000970 be 7a bb fb 27 5b a2 e8 0d 00 52 00 00 00 52 00 |.z..'[....R...R.|
00000980 00 00 a7 14 e8 32 79 06 dd 2e 86 a4 fb cf 89 03 |.....2y.........|
00000990 00 00 c6 60 5c 89 df 2e 53 9a 0b 1e 70 34 86 dd |...`\...S...p4..|
000009a0 60 00 00 00 00 0c 84 40 12 34 00 00 00 00 00 00 |`......@.4......|
000009b0 00 00 00 00 00 00 00 00 56 78 00 00 00 00 00 00 |........Vx......|
000009c0 00 00 00 00 00 00 00 00 de ad be ef 00 00 00 00 |................|
000009d0 4e 61 be 7a bb fb 27 5b d9 ea 0d 00 42 00 00 00 |Na.z..'[....B...|
000009e0 42 00 00 00 a3 2e 8a 05 ba 07 c7 5c 4e c5 56 78 |B..........\N.Vx|
000009f0 86 dd 60 00 00 00 00 0c 84 40 12 34 00 00 00 00 |..`......@.4....|
00000a00 00 00 00 00 00 00 00 00 00 02 56 78 00 00 00 00 |..........Vx....|
00000a10 00 00 00 00 00 00 00 00 00 00 de ad be ef 00 00 |................|
00000a20 00 00 4e 61 be 7a bb fb 27 5b 50 ee 0d 00 52 00 |..Na.z..'[P...R.|
00000a30 00 00 52 00 00 00 7a 28 70 6e 32 07 96 b4 35 f7 |..R...z(pn2...5.|
00000a40 d9 bc 89 03 00 00 a3 2e 8a 05 ba 7e c7 5c 4e c5 |...........~.\N.|
00000a50 56 78 86 dd 60 00 00 00 00 0c 84 40 12 34 00 00 |Vx..`......@.4..|
00000a60 00 00 00 00 00 00 00 00 00 00 00 02 56 78 00 00 |............Vx..|
00000a70 00 00 00 00 00 00 00 00 00 00 00 00 de ad be ef |................|
00000a80 00 00 00 00 4e 61 be 7a bb fb 27 5b 52 f0 0d 00 |....Na.z..'[R...|
00000a90 3c 00 00 00 3c 00 00 00 8b 82 9c 7f e6 00 ab 7a |<...<..........z|
00000aa0 ad 7e d6 79 08 00 45 00 00 14 00 01 00 00 40 63 |.~.y..E.......@c|
00000ab0 74 72 01 01 01 10 02 02 02 02 00 00 00 00 00 00 |tr..............|
00000ac0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000ad0 00 00 00 00 bb fb 27 5b 44 f3 0d 00 3c 00 00 00 |......'[D...<...|
00000ae0 3c 00 00 00 ef 44 46 03 42 00 59 3f 99 a4 bc 0e |<....DF.B.Y?....|
00000af0 89 03 00 00 8b 82 9c 7f e6 3e ab 7a ad 7e d6 79 |.........>.z.~.y|
00000b00 08 00 45 00 00 14 00 01 00 00 40 63 74 72 01 01 |..E.......@ctr..|
00000b10 01 10 02 02 02 02 00 00 00 00 00 00 00 00 00 00 |................|
00000b20 bb fb 27 5b 42 f5 0d 00 3c 00 00 00 3c 00 00 00 |..'[B...<...<...|
00000b30 99 75 1b 46 1f 01 06 e0 3c a2 29 15 08 00 45 00 |.u.F....<.)...E.|
00000b40 00 14 00 01 00 00 40 63 74 81 01 01 01 01 02 02 |......@ct.......|
00000b50 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000b60 00 00 00 00 00 00 00 00 00 00 00 00 bb fb 27 5b |..............'[|
00000b70 25 f8 0d 00 3c 00 00 00 3c 00 00 00 ae 12 1d 31 |%...<...<......1|
00000b80 ce 01 5a 59 6e 95 c5 ee 89 03 00 00 99 75 1b 46 |..ZYn........u.F|
00000b90 1f cb 06 e0 3c a2 29 15 08 00 45 00 00 14 00 01 |....<.)...E.....|
00000ba0 00 00 40 63 74 81 01 01 01 01 02 02 02 02 00 00 |..@ct...........|
00000bb0 00 00 00 00 00 00 00 00 bb fb 27 5b 20 fa 0d 00 |..........'[ ...|
00000bc0 3c 00 00 00 3c 00 00 00 6f 9d 5a 56 44 02 c8 e2 |<...<...o.ZVD...|
00000bd0 90 22 87 e6 08 00 45 00 00 14 00 01 00 00 40 63 |."....E.......@c|
00000be0 74 32 01 01 01 50 02 02 02 02 00 00 00 00 00 00 |t2...P..........|
00000bf0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000c00 00 00 00 00 bb fb 27 5b fa fc 0d 00 3c 00 00 00 |......'[....<...|
00000c10 3c 00 00 00 14 b4 40 74 94 02 1c d9 67 6b 01 6c |<.....@t....gk.l|
00000c20 89 03 00 00 6f 9d 5a 56 44 ef c8 e2 90 22 87 e6 |....o.ZVD...."..|
00000c30 08 00 45 00 00 14 00 01 00 00 40 63 74 32 01 01 |..E.......@ct2..|
00000c40 01 50 02 02 02 02 00 00 00 00 00 00 00 00 00 00 |.P..............|
00000c50 bb fb 27 5b f8 fe 0d 00 3c 00 00 00 3c 00 00 00 |..'[....<...<...|
00000c60 19 17 dc 5d 82 03 70 7a 3d 74 1e 09 08 00 45 00 |...]..pz=t....E.|
00000c70 00 14 00 01 00 00 40 63 74 41 01 01 01 41 02 02 |......@ctA...A..|
00000c80 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000c90 00 00 00 00 00 00 00 00 00 00 00 00 bb fb 27 5b |..............'[|
00000ca0 d1 01 0e 00 3c 00 00 00 3c 00 00 00 ab db 1f 05 |....<...<.......|
00000cb0 3b 03 59 38 d1 ad 79 77 89 03 00 00 19 17 dc 5d |;.Y8..yw.......]|
00000cc0 82 99 70 7a 3d 74 1e 09 08 00 45 00 00 14 00 01 |..pz=t....E.....|
00000cd0 00 00 40 63 74 41 01 01 01 41 02 02 02 02 00 00 |..@ctA...A......|
00000ce0 00 00 00 00 00 00 00 00 bb fb 27 5b e1 03 0e 00 |..........'[....|
00000cf0 3c 00 00 00 3c 00 00 00 67 cf d1 a1 51 04 5d 9b |<...<...g...Q.].|
00000d00 41 45 8a 91 08 00 45 00 00 14 00 01 00 00 40 63 |AE....E.......@c|
00000d10 74 82 01 01 01 00 02 02 02 02 00 00 00 00 00 00 |t...............|
00000d20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000d30 00 00 00 00 bb fb 27 5b 28 07 0e 00 3c 00 00 00 |......'[(...<...|
00000d40 3c 00 00 00 72 b8 f1 f8 c0 04 3d 5c 78 94 45 c5 |<...r.....=\x.E.|
00000d50 89 03 00 00 67 cf d1 a1 51 de 5d 9b 41 45 8a 91 |....g...Q.].AE..|
00000d60 08 00 45 00 00 14 00 01 00 00 40 63 74 82 01 01 |..E.......@ct...|
00000d70 01 00 02 02 02 02 00 00 00 00 00 00 00 00 00 00 |................|
00000d80 bb fb 27 5b 27 09 0e 00 3c 00 00 00 3c 00 00 00 |..'['...<...<...|
00000d90 50 f0 c4 dd d9 05 64 8b e6 7b 53 8a 08 00 45 00 |P.....d..{S...E.|
00000da0 00 14 00 01 00 00 40 63 74 71 01 01 01 11 02 02 |......@ctq......|
00000db0 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000dc0 00 00 00 00 00 00 00 00 00 00 00 00 bb fb 27 5b |..............'[|
00000dd0 01 0c 0e 00 3c 00 00 00 3c 00 00 00 25 62 c1 dc |....<...<...%b..|
00000de0 7c 05 ef fe 10 61 4f c1 89 03 00 00 50 f0 c4 dd ||....aO.....P...|
00000df0 d9 be 64 8b e6 7b 53 8a 08 00 45 00 00 14 00 01 |..d..{S...E.....|
00000e00 00 00 40 63 74 71 01 01 01 11 02 02 02 02 00 00 |..@ctq..........|
00000e10 00 00 00 00 00 00 00 00 bb fb 27 5b ff 0d 0e 00 |..........'[....|
00000e20 3c 00 00 00 3c 00 00 00 e1 ba 64 6d f5 06 b8 c2 |<...<.....dm....|
00000e30 37 58 6c b4 08 00 45 00 00 14 00 01 00 00 40 63 |7Xl...E.......@c|
00000e40 74 42 01 01 01 40 02 02 02 02 00 00 00 00 00 00 |tB...@..........|
00000e50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000e60 00 00 00 00 bb fb 27 5b d7 10 0e 00 3c 00 00 00 |......'[....<...|
00000e70 3c 00 00 00 86 bc 60 68 69 06 f6 6a 7f 52 74 db |<.....`hi..j.Rt.|
00000e80 89 03 00 00 e1 ba 64 6d f5 5c b8 c2 37 58 6c b4 |......dm.\..7Xl.|
00000e90 08 00 45 00 00 14 00 01 00 00 40 63 74 42 01 01 |..E.......@ctB..|
00000ea0 01 40 02 02 02 02 00 00 00 00 00 00 00 00 00 00 |.@..............|
00000eb0 bb fb 27 5b e1 12 0e 00 3c 00 00 00 3c 00 00 00 |..'[....<...<...|
00000ec0 f1 77 fe 53 2d 07 39 aa e2 64 19 65 08 00 45 00 |.w.S-.9..d.e..E.|
00000ed0 00 14 00 01 00 00 40 63 74 31 01 01 01 51 02 02 |......@ct1...Q..|
00000ee0 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000ef0 00 00 00 00 00 00 00 00 00 00 00 00 bb fb 27 5b |..............'[|
00000f00 bb 15 0e 00 3c 00 00 00 3c 00 00 00 8e 6d 08 31 |....<...<....m.1|
00000f10 4a 07 e9 8c 40 4c a0 e4 89 03 00 00 f1 77 fe 53 |J...@L.......w.S|
00000f20 2d 1a 39 aa e2 64 19 65 08 00 45 00 00 14 00 01 |-.9..d.e..E.....|
00000f30 00 00 40 63 74 31 01 01 01 51 02 02 02 02 00 00 |..@ct1...Q......|
00000f40 00 00 00 00 00 00 00 00 bb fb 27 5b 84 17 0e 00 |..........'[....|
00000f50 3c 00 00 00 3c 00 00 00 3c 93 ba 49 bb 00 27 7f |<...<...<..I..'.|
00000f60 43 b2 e8 77 86 dd 60 00 00 00 00 00 63 40 12 34 |C..w..`.....c@.4|
00000f70 00 00 00 00 00 00 00 00 00 00 00 00 00 50 56 78 |.............PVx|
00000f80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00000f90 00 00 00 00 bb fb 27 5b 20 1a 0e 00 46 00 00 00 |......'[ ...F...|
00000fa0 46 00 00 00 ce 55 2e 87 58 00 40 64 a3 18 fb f5 |F....U..X.@d....|
00000fb0 89 03 00 00 3c 93 ba 49 bb 2e 27 7f 43 b2 e8 77 |....<..I..'.C..w|
00000fc0 86 dd 60 00 00 00 00 00 63 40 12 34 00 00 00 00 |..`.....c@.4....|
00000fd0 00 00 00 00 00 00 00 00 00 50 56 78 00 00 00 00 |.........PVx....|
00000fe0 00 00 00 00 00 00 00 00 00 00 bb fb 27 5b e4 1b |............'[..|
00000ff0 0e 00 3c 00 00 00 3c 00 00 00 84 6b 01 8b 40 01 |..<...<....k..@.|
00001000 1a cd e6 65 f4 67 86 dd 60 00 00 00 00 00 63 40 |...e.g..`.....c@|
00001010 12 34 00 00 00 00 00 00 00 00 00 00 00 00 00 41 |.4.............A|
00001020 56 78 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |Vx..............|
00001030 00 00 00 00 00 00 bb fb 27 5b ec 1e 0e 00 46 00 |........'[....F.|
00001040 00 00 46 00 00 00 43 ba f0 04 50 01 4c ba 61 b3 |..F...C...P.L.a.|
00001050 79 cb 89 03 00 00 84 6b 01 8b 40 7b 1a cd e6 65 |y......k..@{...e|
00001060 f4 67 86 dd 60 00 00 00 00 00 63 40 12 34 00 00 |.g..`.....c@.4..|
00001070 00 00 00 00 00 00 00 00 00 00 00 41 56 78 00 00 |...........AVx..|
00001080 00 00 00 00 00 00 00 00 00 00 00 00 bb fb 27 5b |..............'[|
00001090 ae 20 0e 00 3c 00 00 00 3c 00 00 00 d1 3d fc f0 |. ..<...<....=..|
000010a0 83 02 73 8a 4e 03 a9 37 86 dd 60 00 00 00 00 00 |..s.N..7..`.....|
000010b0 63 40 12 34 00 00 00 00 00 00 00 00 00 00 00 00 |c@.4............|
000010c0 00 10 56 78 00 00 00 00 00 00 00 00 00 00 00 00 |..Vx............|
000010d0 00 00 00 00 00 00 00 00 bb fb 27 5b 56 23 0e 00 |..........'[V#..|
000010e0 46 00 00 00 46 00 00 00 a2 c9 b9 b3 a2 02 2a a7 |F...F.........*.|
000010f0 20 c3 02 71 89 03 00 00 d1 3d fc f0 83 5f 73 8a | ..q.....=..._s.|
00001100 4e 03 a9 37 86 dd 60 00 00 00 00 00 63 40 12 34 |N..7..`.....c@.4|
00001110 00 00 00 00 00 00 00 00 00 00 00 00 00 10 56 78 |..............Vx|
00001120 00 00 00 00 00 00 00 00 00 00 00 00 00 00 bb fb |................|
00001130 27 5b 17 25 0e 00 3c 00 00 00 3c 00 00 00 17 08 |'[.%..<...<.....|
00001140 c1 80 9d 03 07 e5 5e 46 ab 62 86 dd 60 00 00 00 |......^F.b..`...|
00001150 00 00 63 40 12 34 00 00 00 00 00 00 00 00 00 00 |..c@.4..........|
00001160 00 00 00 01 56 78 00 00 00 00 00 00 00 00 00 00 |....Vx..........|
00001170 00 00 00 00 00 00 00 00 00 00 bb fb 27 5b ae 27 |............'[.'|
00001180 0e 00 46 00 00 00 46 00 00 00 d6 45 44 fa 13 03 |..F...F....ED...|
00001190 db 88 79 13 f2 11 89 03 00 00 17 08 c1 80 9d 25 |..y............%|
000011a0 07 e5 5e 46 ab 62 86 dd 60 00 00 00 00 00 63 40 |..^F.b..`.....c@|
000011b0 12 34 00 00 00 00 00 00 00 00 00 00 00 00 00 01 |.4..............|
000011c0 56 78 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |Vx..............|
000011d0 bb fb 27 5b 6c 29 0e 00 3c 00 00 00 3c 00 00 00 |..'[l)..<...<...|
000011e0 77 60 23 a4 06 04 b3 b3 6b bf 90 b9 86 dd 60 00 |w`#.....k.....`.|
000011f0 00 00 00 00 63 40 12 34 00 00 00 00 00 00 00 00 |....c@.4........|
00001200 00 00 00 00 00 40 56 78 00 00 00 00 00 00 00 00 |.....@Vx........|
00001210 00 00 00 00 00 00 00 00 00 00 00 00 bb fb 27 5b |..............'[|
00001220 05 2c 0e 00 46 00 00 00 46 00 00 00 78 97 40 ef |.,..F...F...x.@.|
00001230 69 04 9a 6d b9 6b 9c ee 89 03 00 00 77 60 23 a4 |i..m.k......w`#.|
00001240 06 69 b3 b3 6b bf 90 b9 86 dd 60 00 00 00 00 00 |.i..k.....`.....|
00001250 63 40 12 34 00 00 00 00 00 00 00 00 00 00 00 00 |c@.4............|
00001260 00 40 56 78 00 00 00 00 00 00 00 00 00 00 00 00 |.@Vx............|
00001270 00 00 bb fb 27 5b c4 2d 0e 00 3c 00 00 00 3c 00 |....'[.-..<...<.|
00001280 00 00 f1 3e 40 44 93 05 e9 24 90 83 39 d8 86 dd |...>@D...$..9...|
00001290 60 00 00 00 00 00 63 40 12 34 00 00 00 00 00 00 |`.....c@.4......|
000012a0 00 00 00 00 00 00 00 51 56 78 00 00 00 00 00 00 |.......QVx......|
000012b0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 bb fb |................|
000012c0 27 5b 5d 30 0e 00 46 00 00 00 46 00 00 00 b6 1c |'[]0..F...F.....|
000012d0 f7 71 11 05 dd ef d6 e7 eb 55 89 03 00 00 f1 3e |.q.......U.....>|
000012e0 40 44 93 35 e9 24 90 83 39 d8 86 dd 60 00 00 00 |@D.5.$..9...`...|
000012f0 00 00 63 40 12 34 00 00 00 00 00 00 00 00 00 00 |..c@.4..........|
00001300 00 00 00 51 56 78 00 00 00 00 00 00 00 00 00 00 |...QVx..........|
00001310 00 00 00 00 bb fb 27 5b 30 32 0e 00 3c 00 00 00 |......'[02..<...|
00001320 3c 00 00 00 50 0c f8 a7 55 06 c5 21 3a fd a1 3d |<...P...U..!:..=|
00001330 86 dd 60 00 00 00 00 00 63 40 12 34 00 00 00 00 |..`.....c@.4....|
00001340 00 00 00 00 00 00 00 00 00 00 56 78 00 00 00 00 |..........Vx....|
00001350 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00001360 bb fb 27 5b 2e 35 0e 00 46 00 00 00 46 00 00 00 |..'[.5..F...F...|
00001370 0f ee ff c1 df 06 8e 51 01 4a 68 42 89 03 00 00 |.......Q.JhB....|
00001380 50 0c f8 a7 55 29 c5 21 3a fd a1 3d 86 dd 60 00 |P...U).!:..=..`.|
00001390 00 00 00 00 63 40 12 34 00 00 00 00 00 00 00 00 |....c@.4........|
000013a0 00 00 00 00 00 00 56 78 00 00 00 00 00 00 00 00 |......Vx........|
000013b0 00 00 00 00 00 00 bb fb 27 5b ef 36 0e 00 3c 00 |........'[.6..<.|
000013c0 00 00 3c 00 00 00 f3 63 6c 97 68 07 52 01 44 11 |..<....cl.h.R.D.|
000013d0 10 8b 86 dd 60 00 00 00 00 00 63 40 12 34 00 00 |....`.....c@.4..|
000013e0 00 00 00 00 00 00 00 00 00 00 00 11 56 78 00 00 |............Vx..|
000013f0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
00001400 00 00 bb fb 27 5b 87 39 0e 00 46 00 00 00 46 00 |....'[.9..F...F.|
00001410 00 00 37 94 7b 3c e5 07 50 3c 33 a0 2e 4f 89 03 |..7.{<..P<3..O..|
00001420 00 00 f3 63 6c 97 68 1d 52 01 44 11 10 8b 86 dd |...cl.h.R.D.....|
00001430 60 00 00 00 00 00 63 40 12 34 00 00 00 00 00 00 |`.....c@.4......|
00001440 00 00 00 00 00 00 00 11 56 78 00 00 00 00 00 00 |........Vx......|
00001450 00 00 00 00 00 00 00 00 bb fb 27 5b 7d 3a 0e 00 |..........'[}:..|
00001460 3c 00 00 00 3c 00 00 00 9f 29 3b cb 41 ff 94 59 |<...<....);.A..Y|
00001470 94 2c c3 ab 99 99 00 00 00 00 00 00 00 00 00 00 |.,..............|
00001480 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
*
000014a0 00 00 00 00 bb fb 27 5b 6b 3c 0e 00 3c 00 00 00 |......'[k<..<...|
000014b0 3c 00 00 00 af f1 a4 d6 e0 ff ee 26 30 bc 81 dc |<..........&0...|
000014c0 89 03 00 00 9f 29 3b cb 41 cf 94 59 94 2c c3 ab |.....);.A..Y.,..|
000014d0 99 99 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000014e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
000014f0

View file

@ -282,8 +282,6 @@ void Plugin::HookUnprocessedPacket(const zeek::Packet* packet)
d.Add(packet->time);
d.Add(" len=");
d.Add(packet->len);
d.Add(" header=");
d.AddN(reinterpret_cast<const char*>(packet->data), 10);
d.Add("]");
fprintf(stderr, "%.6f %-23s %s\n", zeek::run_state::network_time, "| HookUnprocessedPacket", d.Description());

View file

@ -0,0 +1,4 @@
event packet_not_processed(pkt: pcap_packet)
{
print fmt("packet_not_processed: ts=%d.%d", pkt$ts_sec, pkt$ts_usec);
}

View file

@ -0,0 +1,39 @@
#include "Plugin.h"
#include <Func.h>
#include <Event.h>
#include <Conn.h>
#include <Desc.h>
#include <threading/Formatter.h>
#include <RunState.h>
namespace btest::plugin::Demo_Unprocessed_Packet { Plugin plugin; }
using namespace btest::plugin::Demo_Unprocessed_Packet;
zeek::plugin::Configuration Plugin::Configure()
{
EnableHook(zeek::plugin::HOOK_UNPROCESSED_PACKET);
zeek::plugin::Configuration config;
config.name = "Demo::Unprocessed_Packet";
config.description = "Exercises all plugin hooks";
config.version.major = 1;
config.version.minor = 0;
config.version.patch = 0;
return config;
}
void Plugin::HookUnprocessedPacket(const zeek::Packet* packet)
{
zeek::ODesc d;
d.Add("[");
d.Add("ts=");
d.Add(packet->time);
d.Add(" len=");
d.Add(packet->len);
d.Add("]");
fprintf(stdout, "%.6f %-23s %s\n", zeek::run_state::network_time, "| HookUnprocessedPacket", d.Description());
}

View file

@ -0,0 +1,19 @@
#pragma once
#include <plugin/Plugin.h>
namespace btest::plugin::Demo_Unprocessed_Packet {
class Plugin : public zeek::plugin::Plugin
{
protected:
void HookUnprocessedPacket(const zeek::Packet* packet) override;
// Overridden from zeek::plugin::Plugin.
zeek::plugin::Configuration Configure() override;
};
extern Plugin plugin;
}

View file

@ -0,0 +1,10 @@
# @TEST-EXEC: ${DIST}/auxil/zeek-aux/plugin-support/init-plugin -u . Demo Unprocessed_Packet
# @TEST-EXEC: cp -r %DIR/unprocessed-packet-hook-plugin/* .
# @TEST-EXEC: ./configure --zeek-dist=${DIST} && make
# @TEST-EXEC: ZEEK_PLUGIN_ACTIVATE="Demo::Unprocessed_Packet" ZEEK_PLUGIN_PATH=`pwd` zeek -c unprocessed.pcap -b -r $TRACES/cisco-fabric-path.pcap %INPUT 2>&1 > output
# @TEST-EXEC: btest-diff output
# @TEST-EXEC: hexdump -C unprocessed.pcap > unprocessed.pcap.hex
# @TEST-EXEC: btest-diff unprocessed.pcap.hex
@unload base/misc/version
@load base/init-default