mirror of
https://github.com/zeek/zeek.git
synced 2025-10-13 03:58:20 +00:00
Add SNMP datagram parsing support.
This supports parsing of SNMPv1 (RFC 1157), SNMPv2 (RFC 1901/3416), and SNMPv2 (RFC 3412). An event is raised for each SNMP PDU type, though there's not currently any event handlers for them and not a default snmp.log either. However, simple presence of SNMP is currently visible now in conn.log service field and known_services.log.
This commit is contained in:
parent
ba81aa4387
commit
a0c06a957b
38 changed files with 2345 additions and 8 deletions
18
testing/btest/Baseline/scripts.base.protocols.snmp.v2/out1
Normal file
18
testing/btest/Baseline/scripts.base.protocols.snmp.v2/out1
Normal file
|
@ -0,0 +1,18 @@
|
|||
snmp_get_request
|
||||
[orig_h=10.10.1.159, orig_p=51217/udp, resp_h=10.10.3.109, resp_p=161/udp]
|
||||
is_orig: T
|
||||
[community=public]
|
||||
request_id: 895734538
|
||||
error_stat: 0
|
||||
error_idx: 0
|
||||
oid: 1.3.6.1.2.1.2.2.1.17.1
|
||||
value (tag=0x05): <unspecified>
|
||||
snmp_response
|
||||
[orig_h=10.10.1.159, orig_p=51217/udp, resp_h=10.10.3.109, resp_p=161/udp]
|
||||
is_orig: F
|
||||
[community=public]
|
||||
request_id: 895734538
|
||||
error_stat: 0
|
||||
error_idx: 0
|
||||
oid: 1.3.6.1.2.1.2.2.1.17.1
|
||||
value (tag=0x41): 854387
|
18
testing/btest/Baseline/scripts.base.protocols.snmp.v2/out2
Normal file
18
testing/btest/Baseline/scripts.base.protocols.snmp.v2/out2
Normal file
|
@ -0,0 +1,18 @@
|
|||
snmp_get_bulk_request
|
||||
[orig_h=127.0.0.1, orig_p=28456/udp, resp_h=127.0.0.1, resp_p=161/udp]
|
||||
is_orig: T
|
||||
[community=]
|
||||
request_id: 1817072941
|
||||
non_repeaters: 0
|
||||
max_repititions: 0
|
||||
oid: 1.3.6.1.2.1.1.5.0
|
||||
value (tag=0x05): <unspecified>
|
||||
snmp_response
|
||||
[orig_h=127.0.0.1, orig_p=28456/udp, resp_h=127.0.0.1, resp_p=161/udp]
|
||||
is_orig: F
|
||||
[community=]
|
||||
request_id: 1817072941
|
||||
error_stat: 0
|
||||
error_idx: 0
|
||||
oid: 1.3.6.1.2.1.1.5.0
|
||||
value (tag=0x05): <unspecified>
|
72
testing/btest/Baseline/scripts.base.protocols.snmp.v2/out3
Normal file
72
testing/btest/Baseline/scripts.base.protocols.snmp.v2/out3
Normal file
|
@ -0,0 +1,72 @@
|
|||
snmp_get_request
|
||||
[orig_h=10.144.246.184, orig_p=33938/udp, resp_h=10.144.246.161, resp_p=161/udp]
|
||||
is_orig: T
|
||||
[community=[R0_C@cti!]]
|
||||
request_id: 722681733
|
||||
error_stat: 0
|
||||
error_idx: 0
|
||||
oid: 0.1
|
||||
value (tag=0x05): <unspecified>
|
||||
snmp_response
|
||||
[orig_h=10.144.246.184, orig_p=33938/udp, resp_h=10.144.246.161, resp_p=161/udp]
|
||||
is_orig: F
|
||||
[community=[R0_C@cti!]]
|
||||
request_id: 722681733
|
||||
error_stat: 0
|
||||
error_idx: 0
|
||||
oid: 1.0.8802.1.1.1.1.1.1.0
|
||||
value (tag=0x02): 2
|
||||
snmp_get_request
|
||||
[orig_h=10.144.246.184, orig_p=43824/udp, resp_h=10.144.246.161, resp_p=161/udp]
|
||||
is_orig: T
|
||||
[community=[R0_C@cti!]]
|
||||
request_id: 555232471
|
||||
error_stat: 0
|
||||
error_idx: 0
|
||||
oid: 1.3.6.1.2.1.1.3.0
|
||||
value (tag=0x05): <unspecified>
|
||||
snmp_response
|
||||
[orig_h=10.144.246.184, orig_p=43824/udp, resp_h=10.144.246.161, resp_p=161/udp]
|
||||
is_orig: F
|
||||
[community=[R0_C@cti!]]
|
||||
request_id: 555232471
|
||||
error_stat: 0
|
||||
error_idx: 0
|
||||
oid: 1.3.6.1.2.1.1.3.0
|
||||
value (tag=0x43): 76705700
|
||||
snmp_get_request
|
||||
[orig_h=10.144.246.184, orig_p=40807/udp, resp_h=10.144.246.161, resp_p=161/udp]
|
||||
is_orig: T
|
||||
[community=[R0_C@cti!]]
|
||||
request_id: 349867006
|
||||
error_stat: 0
|
||||
error_idx: 0
|
||||
oid: 1.3.6.1.2.1.31.1.1.1.10.1
|
||||
value (tag=0x05): <unspecified>
|
||||
snmp_response
|
||||
[orig_h=10.144.246.184, orig_p=40807/udp, resp_h=10.144.246.161, resp_p=161/udp]
|
||||
is_orig: F
|
||||
[community=[R0_C@cti!]]
|
||||
request_id: 349867006
|
||||
error_stat: 0
|
||||
error_idx: 0
|
||||
oid: 1.3.6.1.2.1.31.1.1.1.10.1
|
||||
value (tag=0x46): 2232821312
|
||||
snmp_get_request
|
||||
[orig_h=10.144.246.184, orig_p=54059/udp, resp_h=10.144.246.161, resp_p=161/udp]
|
||||
is_orig: T
|
||||
[community=[R0_C@cti!]]
|
||||
request_id: 107891391
|
||||
error_stat: 0
|
||||
error_idx: 0
|
||||
oid: 1.3.6.1.2.1.31.1.1.1.6.1
|
||||
value (tag=0x05): <unspecified>
|
||||
snmp_response
|
||||
[orig_h=10.144.246.184, orig_p=54059/udp, resp_h=10.144.246.161, resp_p=161/udp]
|
||||
is_orig: F
|
||||
[community=[R0_C@cti!]]
|
||||
request_id: 107891391
|
||||
error_stat: 0
|
||||
error_idx: 0
|
||||
oid: 1.3.6.1.2.1.31.1.1.1.6.1
|
||||
value (tag=0x46): 12606463906
|
Loading…
Add table
Add a link
Reference in a new issue