Robin Sommer
0a3e160a8d
Merge remote branch 'origin/topic/seth/dns-updates'
...
* origin/topic/seth/dns-updates:
Fixed some bugs with capturing data in the base DNS script.
Some updates to the base DNS script.
Closes #702 .
2011-12-18 15:20:00 -08:00
Robin Sommer
f3c2811e14
Merge remote branch 'origin/topic/seth/ssl-updates-for-2.0'
...
* origin/topic/seth/ssl-updates-for-2.0:
Added is_orig fields to the SSL events and adapted script.
Closes #692 .
2011-12-18 15:15:57 -08:00
Robin Sommer
8c53446292
Merge remote branch 'origin/fastpath'
...
* origin/fastpath:
Fixed major bug with cluster synchronization (it was broken!)
2011-12-16 02:37:56 -08:00
Robin Sommer
4e17ef63f0
Merge remote branch 'origin/fastpath'
...
* origin/fastpath:
Fix missing action in notice policy for looking up GeoIP data.
Better persistent state config warning messages (fixes #433 ).
A few updates for SQL injection detection.
Fixed some DPD signatures for IRC. Fixes ticket #311 .
Removing Off_Port_Protocol_Found notice.
SSH::Interesting_Hostname_Login cleanup. Fixes #664 .
Teach Broxygen to more generally reference attribute values by name.
Fixed a really dumb bug that was causing the malware hash registry script to break.
Fix Broxygen confusing scoped id at start of line as function parameter.
Remove remnant of libmagic optionality
2011-12-16 02:36:43 -08:00
Seth Hall
0b8b14a0ed
Fixed major bug with cluster synchronization (it was broken!)
2011-12-15 15:59:51 -05:00
Jon Siwek
86cba4c33f
Fix missing action in notice policy for looking up GeoIP data.
2011-12-13 16:17:44 -06:00
Seth Hall
61aa592db5
A few updates for SQL injection detection.
...
- The biggest change is the change in notice names from
HTTP::SQL_Injection_Attack_Against to
HTTP::SQL_Injection_Victim
- A few new SQL injection attacks in the tests that we need to
support at some point.
2011-12-12 14:26:54 -05:00
Seth Hall
76a0b9ad3c
Fixed some DPD signatures for IRC. Fixes ticket #311 .
...
- The larger issue from ticket 313 still stands.
2011-12-10 22:33:49 -05:00
Seth Hall
6478b4acaf
Removing Off_Port_Protocol_Found notice.
...
- Other very small cleanup.
2011-12-10 00:18:10 -05:00
Seth Hall
00fb187927
SSH::Interesting_Hostname_Login cleanup. Fixes #664 .
2011-12-10 00:13:37 -05:00
Seth Hall
ec721dffec
Added is_orig fields to the SSL events and adapted script.
...
- Added a field named $last_alert to the SSL log. This doesn't even
indicate the direction the alert was sent, but we need to start somewhere.
- The x509_certificate function has an is_orig field now instead of
is_server and it's position in the argument list has moved.
- A bit of reorganization and cleanup in the core analyzer.
2011-12-09 16:56:12 -05:00
Seth Hall
3391270527
Fixed a really dumb bug that was causing the malware hash registry script to break.
2011-12-08 14:25:52 -05:00
Seth Hall
04e2773d30
Fixed some bugs with capturing data in the base DNS script.
2011-12-08 13:06:45 -05:00
Jon Siwek
506a42638a
Omit loading local-<node>.bro scripts from base cluster framework.
...
The loading of these is better handled by BroControl and it seems
odd to load them from a base/ script anyway since they'll contain
site/policy specific code.
Addresses #663
2011-12-05 13:02:39 -06:00
Robin Sommer
df3ae4b30d
Merge remote-tracking branch 'origin/topic/jsiwek/remote-log-peer'
...
* origin/topic/jsiwek/remote-log-peer:
Add a remote_log_peer event which contains an event_peer record param.
Closes #493 .
2011-12-01 16:02:11 -08:00
Jon Siwek
0c8b5a712d
Add a remote_log_peer event which contains an event_peer record param.
...
Addresses #493 .
2011-12-01 14:07:08 -06:00
Jon Siwek
14c1d2ae1f
Remove example redef of SMTP::entity_excerpt_len from local.bro.
2011-12-01 09:31:38 -06:00
Jon Siwek
8d7ca1360f
Fix error emitted when loading local.bro in bare mode
...
Regarding the redef of SMTP::entity_excerpt_len without having
been previously defined.
2011-11-30 13:56:30 -06:00
Seth Hall
70004cb04d
Small updates to address the "globals" ticket.
...
Fixes #633
2011-11-30 11:35:53 -05:00
Seth Hall
bb47289bfa
Some updates to the base DNS script.
...
- Answers and TTLs are now vectors.
- The warning that was being generated (dns_reply_seen_after_done)
from transaction ID reuse is fixed.
- Updated the single failing btest baseline.
2011-11-30 10:19:41 -05:00
Robin Sommer
fa76330afb
Merge remote-tracking branch 'origin/fastpath'
...
* origin/fastpath:
Binary packaging script tweaks.
More default "weird" tuning for the "SYN_with_data" notice.
Tiny bugfix for http file extraction along with test.
2011-11-15 07:53:36 -08:00
Seth Hall
4942767c4d
More default "weird" tuning for the "SYN_with_data" notice.
...
- I think the default tuning should be that anything not requiring
a session to be established should use ACTION_LOG_PER_ORIG.
- We need to get some tie-in with the metrics framework in place
so that we can find when lots of these values are being suppressed.
2011-11-14 16:12:38 -05:00
Seth Hall
d14349a6f8
Merge remote-tracking branch 'origin/master' into fastpath
2011-11-14 16:06:44 -05:00
Seth Hall
b12d2c768e
Tiny bugfix for http file extraction along with test.
2011-11-14 15:24:15 -05:00
Robin Sommer
41a443677b
Merge remote-tracking branch 'origin/fastpath'
...
* origin/fastpath:
No longer write to the PacketFilter::LOG stream if not reading traffic.
2011-11-03 15:27:23 -07:00
Seth Hall
507b51c957
No longer write to the PacketFilter::LOG stream if not reading traffic.
2011-11-02 15:09:57 -04:00
Robin Sommer
69b61be0ef
Merge branch 'master' of ssh://git.bro-ids.org/bro
...
Conflicts:
scripts/policy/frameworks/control/controller.bro
2011-10-27 12:41:18 -07:00
Seth Hall
75e470ac9a
The control framework no longer sends functions with the configuration_update command.
2011-10-27 15:29:28 -04:00
Robin Sommer
6ff90d443d
Merge branch 'master' of ssh://git.bro-ids.org/bro
2011-10-27 11:23:56 -07:00
Robin Sommer
ff32f5f833
Fixing send_id() problem.
...
We no longer update &redef functions. Updating code on the fly isn't
fully supported.
2011-10-27 11:22:10 -07:00
Seth Hall
ae3ae9a75b
Awful fix for SSH login detection.
...
- We need a counted measure of payload bytes (not ack tracking and
not with the IP header which is what we have now).
2011-10-27 09:41:34 -04:00
Robin Sommer
f3ed235ba7
Tuning the format of the pretty-printed alarm summaries.
...
Turns out the old format doesn't work well with the new scripts.
2011-10-26 21:12:16 -07:00
Robin Sommer
5b79d2b15f
Baseline updates.
...
Also a small tweak to the genDocSourcesList.sh as I was seein
non-consistent output order.
2011-10-26 15:27:03 -07:00
Robin Sommer
ec2a8d7904
Merge remote-tracking branch 'origin/topic/robin/pp-alarms'
...
* origin/topic/robin/pp-alarms:
Removing debugging code.
Now actually pretty-printing the notices.
Small fixes, and new option to specify a different dest address.
A new notice script that pretty-prints alarms in the summary email.
Adding a dummy log writer WRITER_NONE that just discards everything.
2011-10-26 14:44:46 -07:00
Robin Sommer
314e9c41f9
Removing debugging code.
2011-10-26 14:39:07 -07:00
Robin Sommer
351b0b2aaa
Adding instructions to local.bro how to do ACTION_ALARM by default.
2011-10-26 14:30:50 -07:00
Robin Sommer
eb6313adcb
Now actually pretty-printing the notices.
...
Output is similar to Bro 1.x.
2011-10-26 13:42:42 -07:00
Robin Sommer
39ed489028
Small fixes, and new option to specify a different dest address.
2011-10-26 11:12:50 -07:00
Robin Sommer
73d5643302
A new notice script that pretty-prints alarms in the summary email.
...
It works already, but the actual pretty-printing is still missing.
2011-10-26 10:40:12 -07:00
Seth Hall
17d03c9936
Fix a problem with DNS servers being logged that aren't actually servers.
2011-10-25 16:20:29 -04:00
Seth Hall
3d6d75b647
Updating test baselines for recent changes.
2011-10-25 14:51:32 -04:00
Jon Siwek
55978d1c18
Changed generated root cert DN format for RFC2253 compliance.
2011-10-25 11:09:31 -05:00
Seth Hall
b2323305f8
Adding sub messages to emails.
2011-10-25 11:36:24 -04:00
Seth Hall
4753f2aeca
Adding extra fields to smtp and http to track transaction depth.
...
- This will for help linking in analysis scripts and databases later.
- Test baseline updates coming in a few minutes.
2011-10-25 11:34:48 -04:00
Seth Hall
2131468b08
Merging this branch. It's working better than the existing code.
2011-10-25 11:17:19 -04:00
Seth Hall
dcc8d8456a
Removed some fields from http analysis that weren't commonly needed or were wrong.
2011-10-25 09:32:31 -04:00
Seth Hall
320739e183
Updated/fixed MSIE version parsing in the software framework.
2011-10-25 09:30:06 -04:00
Jon Siwek
522e0e4d46
Update Mozilla trust roots to index certs by subject distinguished name.
2011-10-25 07:52:24 -05:00
Seth Hall
e6a8489780
Testing a fix for SSH login detection heuristic.
2011-10-25 00:01:04 -04:00
Seth Hall
7f838b6181
Merge branch 'topic/seth/weird-updates'
2011-10-24 23:47:31 -04:00