Bernhard Amann
cde8153c18
switch to set if record or simple value is desired.
2011-11-15 08:36:03 -08:00
Robin Sommer
fa76330afb
Merge remote-tracking branch 'origin/fastpath'
...
* origin/fastpath:
Binary packaging script tweaks.
More default "weird" tuning for the "SYN_with_data" notice.
Tiny bugfix for http file extraction along with test.
2011-11-15 07:53:36 -08:00
Seth Hall
4942767c4d
More default "weird" tuning for the "SYN_with_data" notice.
...
- I think the default tuning should be that anything not requiring
a session to be established should use ACTION_LOG_PER_ORIG.
- We need to get some tie-in with the metrics framework in place
so that we can find when lots of these values are being suppressed.
2011-11-14 16:12:38 -05:00
Seth Hall
d14349a6f8
Merge remote-tracking branch 'origin/master' into fastpath
2011-11-14 16:06:44 -05:00
Seth Hall
b12d2c768e
Tiny bugfix for http file extraction along with test.
2011-11-14 15:24:15 -05:00
Bernhard Amann
1d39eaf32d
small fixes, less leakiness
2011-11-04 15:03:40 -07:00
Bernhard Amann
2aa0f6da57
beautify script calls, track filters
2011-11-04 14:33:34 -07:00
Bernhard Amann
72736510de
Merge remote-tracking branch 'origin/master' into input
2011-11-04 14:12:59 -07:00
Bernhard Amann
2e3874331d
support for filters and little event fix
2011-11-04 12:41:10 -07:00
Robin Sommer
e0692b898e
Merge branch 'master' into topic/robin/pp-alarms
2011-11-03 15:30:41 -07:00
Robin Sommer
41a443677b
Merge remote-tracking branch 'origin/fastpath'
...
* origin/fastpath:
No longer write to the PacketFilter::LOG stream if not reading traffic.
2011-11-03 15:27:23 -07:00
Robin Sommer
c4d6f814ff
Tuning the pretty-printed alarms output.
...
- Now including the included time range into the subject.
- With some notices, it got confused who's the orginator.
2011-11-02 18:09:09 -07:00
Bernhard Amann
86730c13dd
more complex types...
2011-11-02 15:36:35 -07:00
Bernhard Amann
b245d4168a
yay, basic table assignment.
2011-11-02 15:36:35 -07:00
Bernhard Amann
5b0c307f87
very basic input to event working...
2011-11-02 15:36:34 -07:00
Bernhard Amann
3654060246
compiles. sill doesn't do much.
2011-11-02 15:36:34 -07:00
Bernhard Amann
9c8b0dec3b
event from c++ to script works (at last...)
2011-11-02 15:36:33 -07:00
Bernhard Amann
0eafeb0369
works (thanks to robin)
2011-11-02 15:36:33 -07:00
Seth Hall
507b51c957
No longer write to the PacketFilter::LOG stream if not reading traffic.
2011-11-02 15:09:57 -04:00
Robin Sommer
69b61be0ef
Merge branch 'master' of ssh://git.bro-ids.org/bro
...
Conflicts:
scripts/policy/frameworks/control/controller.bro
2011-10-27 12:41:18 -07:00
Seth Hall
75e470ac9a
The control framework no longer sends functions with the configuration_update command.
2011-10-27 15:29:28 -04:00
Robin Sommer
6ff90d443d
Merge branch 'master' of ssh://git.bro-ids.org/bro
2011-10-27 11:23:56 -07:00
Robin Sommer
ff32f5f833
Fixing send_id() problem.
...
We no longer update &redef functions. Updating code on the fly isn't
fully supported.
2011-10-27 11:22:10 -07:00
Seth Hall
ae3ae9a75b
Awful fix for SSH login detection.
...
- We need a counted measure of payload bytes (not ack tracking and
not with the IP header which is what we have now).
2011-10-27 09:41:34 -04:00
Robin Sommer
f3ed235ba7
Tuning the format of the pretty-printed alarm summaries.
...
Turns out the old format doesn't work well with the new scripts.
2011-10-26 21:12:16 -07:00
Robin Sommer
5b79d2b15f
Baseline updates.
...
Also a small tweak to the genDocSourcesList.sh as I was seein
non-consistent output order.
2011-10-26 15:27:03 -07:00
Robin Sommer
ec2a8d7904
Merge remote-tracking branch 'origin/topic/robin/pp-alarms'
...
* origin/topic/robin/pp-alarms:
Removing debugging code.
Now actually pretty-printing the notices.
Small fixes, and new option to specify a different dest address.
A new notice script that pretty-prints alarms in the summary email.
Adding a dummy log writer WRITER_NONE that just discards everything.
2011-10-26 14:44:46 -07:00
Robin Sommer
314e9c41f9
Removing debugging code.
2011-10-26 14:39:07 -07:00
Robin Sommer
351b0b2aaa
Adding instructions to local.bro how to do ACTION_ALARM by default.
2011-10-26 14:30:50 -07:00
Robin Sommer
eb6313adcb
Now actually pretty-printing the notices.
...
Output is similar to Bro 1.x.
2011-10-26 13:42:42 -07:00
Robin Sommer
39ed489028
Small fixes, and new option to specify a different dest address.
2011-10-26 11:12:50 -07:00
Robin Sommer
73d5643302
A new notice script that pretty-prints alarms in the summary email.
...
It works already, but the actual pretty-printing is still missing.
2011-10-26 10:40:12 -07:00
Seth Hall
17d03c9936
Fix a problem with DNS servers being logged that aren't actually servers.
2011-10-25 16:20:29 -04:00
Seth Hall
3d6d75b647
Updating test baselines for recent changes.
2011-10-25 14:51:32 -04:00
Jon Siwek
55978d1c18
Changed generated root cert DN format for RFC2253 compliance.
2011-10-25 11:09:31 -05:00
Seth Hall
b2323305f8
Adding sub messages to emails.
2011-10-25 11:36:24 -04:00
Seth Hall
4753f2aeca
Adding extra fields to smtp and http to track transaction depth.
...
- This will for help linking in analysis scripts and databases later.
- Test baseline updates coming in a few minutes.
2011-10-25 11:34:48 -04:00
Seth Hall
2131468b08
Merging this branch. It's working better than the existing code.
2011-10-25 11:17:19 -04:00
Seth Hall
dcc8d8456a
Removed some fields from http analysis that weren't commonly needed or were wrong.
2011-10-25 09:32:31 -04:00
Seth Hall
320739e183
Updated/fixed MSIE version parsing in the software framework.
2011-10-25 09:30:06 -04:00
Jon Siwek
522e0e4d46
Update Mozilla trust roots to index certs by subject distinguished name.
2011-10-25 07:52:24 -05:00
Seth Hall
e6a8489780
Testing a fix for SSH login detection heuristic.
2011-10-25 00:01:04 -04:00
Seth Hall
7f838b6181
Merge branch 'topic/seth/weird-updates'
2011-10-24 23:47:31 -04:00
Seth Hall
ff51068598
Fixing a bug with handling downgrade from weird conn to orig.
2011-10-22 01:13:15 -04:00
Seth Hall
7746f5b223
Final notice email tuning.
2011-10-21 23:08:56 -04:00
Seth Hall
0e79ec46b6
More notice email tuning.
2011-10-21 22:58:44 -04:00
Seth Hall
75e5caeff5
Attempt to make hostname notice email extension work and small format adjustments.
2011-10-21 22:51:56 -04:00
Seth Hall
74240610c5
Fixed a problem with sending notice emails I introduced earlier.
2011-10-21 22:41:43 -04:00
Seth Hall
29bace02b2
More small weird refinements to reduce overload attacks.
2011-10-21 14:31:40 -04:00
Seth Hall
0cdcf490d6
Restoring former default weird behavior for unsolicited_SYN_response.
2011-10-21 14:17:54 -04:00