Bernhard Amann
9b7eb293f1
Add documentation, consts and tests for the new events.
...
This also fixes the heartbleed detector to work for encrypted attacks in this
branch again. It stopped working, because the SSL analyzer now successfully detects
established connections, and the scripts usually disable analyzing after that.
(The heartbeat branch should not have been affected)
2014-04-24 12:05:30 -07:00
Bernhard Amann
ef41cc7189
Nicer notices for heartbleed.
...
Duplicates are now excluded and the notice texts contain a bit more useful information.
2014-04-16 10:48:22 -07:00
Bernhard Amann
2414aaf4bb
enable detection of encrypted heartbleeds.
2014-04-08 21:57:37 -07:00
Bernhard Amann
2942a26280
also extract payload data in ssl_heartbeat
2014-04-08 12:44:51 -07:00
Bernhard Amann
f2c2da92c6
add to local.bro, add disclaimer
2014-04-08 11:53:01 -07:00
Bernhard Amann
cb87f834f9
make tls heartbeat messages a bit better.
2014-04-08 11:40:48 -07:00
Bernhard Amann
4d33bdbb1e
fix tabs.
2014-04-08 11:28:13 -07:00
Bernhard Amann
c41810a337
polish script and probably detect encrypted attacks too.
2014-04-08 11:19:30 -07:00
Bernhard Amann
335a30b08f
detect and alert on simple case of heartbleed
2014-04-08 11:03:12 -07:00