mirror of
https://github.com/zeek/zeek.git
synced 2025-10-10 10:38:20 +00:00
Expanding the HTTP methods used in the signature to detect HTTP traffic.
This commit is contained in:
parent
ac9c44afd8
commit
d0f8edb2a4
1 changed files with 5 additions and 1 deletions
|
@ -1,6 +1,8 @@
|
||||||
|
# List of HTTP headers pulled from:
|
||||||
|
# http://annevankesteren.nl/2007/10/http-methods
|
||||||
signature dpd_http_client {
|
signature dpd_http_client {
|
||||||
ip-proto == tcp
|
ip-proto == tcp
|
||||||
payload /^[[:space:]]*(GET|HEAD|POST)[[:space:]]*/
|
payload /^[[:space:]]*(OPTIONS|GET|HEAD|POST|PUT|DELETE|TRACE|CONNECT|PROPFIND|PROPPATCH|MKCOL|COPY|MOVE|LOCK|UNLOCK|VERSION-CONTROL|REPORT|CHECKOUT|CHECKIN|UNCHECKOUT|MKWORKSPACE|UPDATE|LABEL|MERGE|BASELINE-CONTROL|MKACTIVITY|ORDERPATCH|ACL|PATCH|SEARCH|BCOPY|BDELETE|BMOVE|BPROPFIND|BPROPPATCH|NOTIFY|POLL|SUBSCRIBE|UNSUBSCRIBE|X-MS-ENUMATTS|RPC_OUT_DATA|RPC_IN_DATA)[[:space:]]*/
|
||||||
tcp-state originator
|
tcp-state originator
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -11,3 +13,5 @@ signature dpd_http_server {
|
||||||
requires-reverse-signature dpd_http_client
|
requires-reverse-signature dpd_http_client
|
||||||
enable "http"
|
enable "http"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue