mirror of
https://github.com/zeek/zeek.git
synced 2025-10-03 07:08:19 +00:00

Changed some configuration defaults to potentially more same values. The callback function is now a hook to allow costomization of the events that are raised. Tests now exist. Test baselines are updated.
80 lines
2.2 KiB
Text
80 lines
2.2 KiB
Text
FILE_NEW
|
|
file #0, 0, 0
|
|
FILE_OVER_NEW_CONNECTION
|
|
FILE_STATE_REMOVE
|
|
file #0, 77, 0
|
|
[orig_h=10.10.1.4, orig_p=1470/tcp, resp_h=74.53.140.153, resp_p=25/tcp]
|
|
FILE_BOF_BUFFER
|
|
Hello\x0d\x0a\x0d\x0a \x0d
|
|
MIME_TYPE
|
|
text/plain
|
|
source: SMTP
|
|
MD5: 58aff3af22807bc5f4b6357c0038256c
|
|
SHA1: c39dc8cd0f8d8b1f7fc8b362c41e69fdf20f668a
|
|
SHA256: 8d057f3af311c20675eea767a9df5fa31ff3597c6d5d50fd0cdc34766c40204d
|
|
FILE_NEW
|
|
file #1, 0, 0
|
|
FILE_OVER_NEW_CONNECTION
|
|
FILE_STATE_REMOVE
|
|
file #1, 1868, 0
|
|
[orig_h=10.10.1.4, orig_p=1470/tcp, resp_h=74.53.140.153, resp_p=25/tcp]
|
|
FILE_BOF_BUFFER
|
|
<html xmlns
|
|
MIME_TYPE
|
|
text/html
|
|
source: SMTP
|
|
MD5: afd68ae5c63caf6050dc5440bd72c5dd
|
|
SHA1: a4825db9a78b6c631f3c97d363be47faf65e8386
|
|
SHA256: 8d9e5bb6072fbbf5b4a5fabe89ede8c8c54915efe33704fe71420d50438f5f81
|
|
FILE_NEW
|
|
file #2, 0, 0
|
|
FILE_OVER_NEW_CONNECTION
|
|
FILE_STATE_REMOVE
|
|
file #2, 10809, 0
|
|
[orig_h=10.10.1.4, orig_p=1470/tcp, resp_h=74.53.140.153, resp_p=25/tcp]
|
|
FILE_BOF_BUFFER
|
|
Version 4.9
|
|
MIME_TYPE
|
|
text/plain
|
|
source: SMTP
|
|
MD5: 30a60389acc290515651391154ba1b33
|
|
SHA1: 5d3e96afdef531571b685aa2a3729e6fe635e413
|
|
SHA256: 6ea20e4b4f218a715ddfd0c27a92def1020a47a1c2cc6971a6710746efabf868
|
|
FILE_NEW
|
|
file #3, 0, 0
|
|
FILE_OVER_NEW_CONNECTION
|
|
FILE_STATE_REMOVE
|
|
file #3, 204, 0
|
|
[orig_h=192.168.133.100, orig_p=49648/tcp, resp_h=192.168.133.102, resp_p=25/tcp]
|
|
FILE_BOF_BUFFER
|
|
\x0d\x0a> On 25 J
|
|
MIME_TYPE
|
|
text/plain
|
|
source: SMTP
|
|
MD5: f6bf92b103a9d008e070c53bdf9a640c
|
|
SHA1: 3443cbe561b33a606d2c0638eca61deb303c4dd7
|
|
SHA256: acdef841cc054f2afdf800cb2c48300244ca1376d0438141e91ef60986fbeb6d
|
|
FILE_NEW
|
|
file #4, 0, 0
|
|
FILE_OVER_NEW_CONNECTION
|
|
FILE_STATE_REMOVE
|
|
file #4, 1406, 0
|
|
[orig_h=192.168.133.100, orig_p=49655/tcp, resp_h=17.167.150.73, resp_p=443/tcp]
|
|
MIME_TYPE
|
|
application/x-x509-user-cert
|
|
source: SSL
|
|
MD5: 1bf9696d9f337805383427e88781d001
|
|
SHA1: f5ccb1a724133607548b00d8eb402efca3076d58
|
|
SHA256: f94f3f5bf51899148fa4c51a1b39bd98cd0bf053f2e838eb68a2a96d0359ed56
|
|
FILE_NEW
|
|
file #5, 0, 0
|
|
FILE_OVER_NEW_CONNECTION
|
|
FILE_STATE_REMOVE
|
|
file #5, 1092, 0
|
|
[orig_h=192.168.133.100, orig_p=49655/tcp, resp_h=17.167.150.73, resp_p=443/tcp]
|
|
MIME_TYPE
|
|
application/x-x509-ca-cert
|
|
source: SSL
|
|
MD5: 48f0e38385112eeca5fc9ffd402eaecd
|
|
SHA1: 8e8321ca08b08e3726fe1d82996884eeb5f0d655
|
|
SHA256: ac2b922ecfd5e01711772fea8ed372de9d1e2245fce3f57a9cdbec77296a424b
|