mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 14:48:21 +00:00

* 'fatemabw/bro' of https://github.com/fatemabw/bro: DNSSEC support in Bro I made several changes: - renamed event/record types - reformatted the info added to dns.log - removed the "addl" scripts that added extended dnssec info to dns.log - simplifications/improvements to the internal parsing logic
35 lines
1 KiB
Text
35 lines
1 KiB
Text
# @TEST-EXEC: bro -C -r $TRACES/dnssec/ds.pcap %INPUT > output
|
|
# @TEST-EXEC: btest-diff dns.log
|
|
# @TEST-EXEC: btest-diff output
|
|
|
|
#@load policy/protocols/dns/auth-addl
|
|
|
|
event dns_RRSIG(c: connection, msg: dns_msg, ans: dns_answer, rrsig: dns_rrsig_rr)
|
|
{
|
|
print "RRSIG", rrsig, bytestring_to_hexstr(rrsig$signature);
|
|
}
|
|
|
|
event dns_DNSKEY(c: connection, msg: dns_msg, ans: dns_answer, dnskey: dns_dnskey_rr)
|
|
{
|
|
print "DNSKEY", dnskey, bytestring_to_hexstr(dnskey$public_key);
|
|
}
|
|
|
|
event dns_NSEC(c: connection, msg: dns_msg, ans: dns_answer, next_name: string, bitmaps: string_vec)
|
|
{
|
|
print "NSEC", next_name, bitmaps;
|
|
|
|
for ( i in bitmaps )
|
|
print bytestring_to_hexstr(bitmaps[i]);
|
|
}
|
|
|
|
event dns_NSEC3(c: connection, msg: dns_msg, ans: dns_answer, nsec3: dns_nsec3_rr)
|
|
{
|
|
print "NSEC3", nsec3,
|
|
bytestring_to_hexstr(nsec3$nsec_salt),
|
|
bytestring_to_hexstr(nsec3$nsec_hash);
|
|
}
|
|
|
|
event dns_DS(c: connection, msg: dns_msg, ans: dns_answer, ds: dns_ds_rr)
|
|
{
|
|
print "DS", ds, bytestring_to_hexstr(ds$digest_val);
|
|
}
|