Seth Hall
ae3ae9a75b
Awful fix for SSH login detection.
...
- We need a counted measure of payload bytes (not ack tracking and
not with the IP header which is what we have now).
2011-10-27 09:41:34 -04:00
Robin Sommer
f3ed235ba7
Tuning the format of the pretty-printed alarm summaries.
...
Turns out the old format doesn't work well with the new scripts.
2011-10-26 21:12:16 -07:00
Robin Sommer
5b79d2b15f
Baseline updates.
...
Also a small tweak to the genDocSourcesList.sh as I was seein
non-consistent output order.
2011-10-26 15:27:03 -07:00
Robin Sommer
ec2a8d7904
Merge remote-tracking branch 'origin/topic/robin/pp-alarms'
...
* origin/topic/robin/pp-alarms:
Removing debugging code.
Now actually pretty-printing the notices.
Small fixes, and new option to specify a different dest address.
A new notice script that pretty-prints alarms in the summary email.
Adding a dummy log writer WRITER_NONE that just discards everything.
2011-10-26 14:44:46 -07:00
Robin Sommer
314e9c41f9
Removing debugging code.
2011-10-26 14:39:07 -07:00
Robin Sommer
eb6313adcb
Now actually pretty-printing the notices.
...
Output is similar to Bro 1.x.
2011-10-26 13:42:42 -07:00
Robin Sommer
39ed489028
Small fixes, and new option to specify a different dest address.
2011-10-26 11:12:50 -07:00
Robin Sommer
73d5643302
A new notice script that pretty-prints alarms in the summary email.
...
It works already, but the actual pretty-printing is still missing.
2011-10-26 10:40:12 -07:00
Jon Siwek
55978d1c18
Changed generated root cert DN format for RFC2253 compliance.
2011-10-25 11:09:31 -05:00
Seth Hall
b2323305f8
Adding sub messages to emails.
2011-10-25 11:36:24 -04:00
Seth Hall
4753f2aeca
Adding extra fields to smtp and http to track transaction depth.
...
- This will for help linking in analysis scripts and databases later.
- Test baseline updates coming in a few minutes.
2011-10-25 11:34:48 -04:00
Seth Hall
2131468b08
Merging this branch. It's working better than the existing code.
2011-10-25 11:17:19 -04:00
Seth Hall
dcc8d8456a
Removed some fields from http analysis that weren't commonly needed or were wrong.
2011-10-25 09:32:31 -04:00
Seth Hall
320739e183
Updated/fixed MSIE version parsing in the software framework.
2011-10-25 09:30:06 -04:00
Jon Siwek
522e0e4d46
Update Mozilla trust roots to index certs by subject distinguished name.
2011-10-25 07:52:24 -05:00
Seth Hall
e6a8489780
Testing a fix for SSH login detection heuristic.
2011-10-25 00:01:04 -04:00
Seth Hall
7f838b6181
Merge branch 'topic/seth/weird-updates'
2011-10-24 23:47:31 -04:00
Seth Hall
ff51068598
Fixing a bug with handling downgrade from weird conn to orig.
2011-10-22 01:13:15 -04:00
Seth Hall
7746f5b223
Final notice email tuning.
2011-10-21 23:08:56 -04:00
Seth Hall
0e79ec46b6
More notice email tuning.
2011-10-21 22:58:44 -04:00
Seth Hall
75e5caeff5
Attempt to make hostname notice email extension work and small format adjustments.
2011-10-21 22:51:56 -04:00
Seth Hall
74240610c5
Fixed a problem with sending notice emails I introduced earlier.
2011-10-21 22:41:43 -04:00
Seth Hall
29bace02b2
More small weird refinements to reduce overload attacks.
2011-10-21 14:31:40 -04:00
Seth Hall
0cdcf490d6
Restoring former default weird behavior for unsolicited_SYN_response.
2011-10-21 14:17:54 -04:00
Seth Hall
f0b32b21ee
weird.bro rewrite.
...
- I want to test it for a short while before committing it to
master just to make sure it is a sane modification.
2011-10-21 14:08:54 -04:00
Seth Hall
8b56c54348
Slightly restructured http file hashing to fix a bug.
2011-10-21 14:03:31 -04:00
Seth Hall
3900d88e60
Field name change to notice framwork. $result -> $action
...
- $result is renamed to $action to reflect changes to the notice framework
since there is already another result-like field ($suppress_for) and
there may be more in the future.
- Slipped in a change to add connection information to notice emails too.
2011-10-21 14:01:39 -04:00
Seth Hall
8661abe9d9
Small script refinements and documentation updates.
2011-10-21 13:58:58 -04:00
Seth Hall
0803df2e14
Changed communication option from listen_encrypted to listen_ssl.
...
- Robin pointed out that SSL is providing authentication
as well as encryption so listen_ssl is a more
proper variable name.
2011-10-07 23:57:08 -04:00
Seth Hall
6d67f7830d
Added to the likely_server_ports set for protocols with analyzers.
...
- Updated some tests since Bro is getting the direction
correct now.
- Updated BPF filter test since I added a few ports to IRC
as well.
2011-10-07 13:44:28 -04:00
Seth Hall
686946d0dd
Internal simplication for FTP analysis scripts.
2011-10-07 13:36:02 -04:00
Seth Hall
8600b676e6
Fixed a TODO in the DNS analysis script.
2011-10-07 13:32:44 -04:00
Seth Hall
acc4d6ccd3
Removed unused script code from init-bare.bro
2011-10-07 13:31:28 -04:00
Seth Hall
da9b8cc283
Modification to the Communication framework API.
...
- Simplified the communication API and made it easier to change
to encrypted connections by not having separate variables to
define encrypted and unencrypted ports.
- Now, to enable listening without configuring nodes just
load the frameworks/communication/listen script.
- If encrypted listening is desired set the following:
redef Communication::listen_encrypted=T;
- Accompanying test updates.
2011-10-07 13:29:26 -04:00
Seth Hall
1dd3ba7f7d
Fixed another "identifier not exported" error.
2011-10-07 03:32:28 -04:00
Seth Hall
9e41a7976b
Merge branch 'master' of ssh://git.bro-ids.org/bro
2011-10-07 02:51:52 -04:00
Seth Hall
9602e6e2f3
Fixed the "identifier is not exported" error.
2011-10-07 02:51:40 -04:00
Robin Sommer
a08c478079
Fixing a number of reporter calls.
2011-10-06 21:26:49 -07:00
Robin Sommer
90d2136fd1
Filtering some potentially high-volume DNS weirds.
2011-10-06 18:10:15 -07:00
Robin Sommer
fe77d385e0
Merge remote-tracking branch 'origin/topic/jsiwek/broctl-tweaks'
...
* origin/topic/jsiwek/broctl-tweaks:
Consolidating some node-specific functionality from scripts in broctl repo.
2011-10-05 16:54:39 -07:00
Robin Sommer
25fe7e91db
Merge remote-tracking branch 'origin/fastpath'
...
* origin/fastpath:
Add check for optional HTTP::Info status_code.
Changing some external testing scripts.
Conflicts:
scripts/base/protocols/http/main.bro
2011-10-05 16:24:33 -07:00
Jon Siwek
88e089864b
Consolidating some node-specific functionality from scripts in broctl repo.
2011-10-05 16:33:40 -05:00
Seth Hall
0e4fecdfe4
HTTP bug fix reported by Martin.
2011-10-05 09:35:19 -04:00
Seth Hall
26290bb56c
More script tuning
...
- Moved some of the weird events back to the base/ directory.
- Fixed more bugs with SSL certificate handling.
2011-10-04 17:06:45 -04:00
Jon Siwek
c9a540b992
Add check for optional HTTP::Info status_code.
2011-10-04 14:27:51 -05:00
Seth Hall
5a04190ffe
More adjustment to reduce Weird volumes.
...
- New script extracted from weird.bro to implement the
connection related "weird" data into an optionally
loaded script.
- Adjusted the default notice tuning to stop ignoring
the connection related weirds since they aren't loaded
by default anymore.
2011-10-04 13:58:55 -04:00
Seth Hall
aa9fdf38bb
Clean up to cluster framework to make event handling clearer.
...
- Fixed a bug where notices were being passed to proxies.
This was a mistake and should greatly reduce load on
many clusters.
- Cluster event regex variables renamed to:
- Notice::manager2worker_events
- Notice::manager2proxy_events
- Notice::worker2manager_events
- Notice::worker2proxy_events
- Notice::proxy2manager_events
- Notice::proxy2worker_events
- The default Notice::policy set is cleared for all cluster
nodes except for managers to cause all default notice
processing to occur on managers. This should reduce load
on workers slightly.
2011-10-04 11:57:50 -04:00
Seth Hall
e6a3dbfb5d
Fixed a bug in the notice framework.
...
- The notice alarm shorthand PolicyItem wasn't actually setting the action.
2011-10-03 10:45:37 -04:00
Seth Hall
be30dde827
Bug fix for FTP analysis script.
2011-10-03 00:06:05 -04:00
Robin Sommer
221d1663be
Merge branch 'master' of ssh://git.bro-ids.org/bro
...
Conflicts:
scripts/base/protocols/http/main.bro
2011-09-29 18:54:50 -07:00