zeek/testing/btest/Baseline/scripts.base.frameworks.file-analysis.bifs.set_timeout_interval/bro..stdout
Jon Siwek cbbe7b52dc Review/fix/change file reassembly functionality.
- Re-arrange how some fa_file fields (e.g. source, connection info, mime
  type) get updated/set for consistency.

- Add more robust mechanisms for flushing the reassembly buffer.
  The goal being to report all gaps and deliveries to file analyzers
  regardless of the state of the reassembly buffer at the time it has to
  be flushed.
2014-12-16 14:05:15 -06:00

28 lines
707 B
Text

FILE_NEW
file #0, 0, 0
FILE_OVER_NEW_CONNECTION
FILE_STATE_REMOVE
file #0, 1022920, 0
[orig_h=192.168.72.14, orig_p=3254/tcp, resp_h=65.54.95.206, resp_p=80/tcp]
FILE_BOF_BUFFER
MZ\x90\0^C\0\0\0^D\0\0
MIME_TYPE
application/x-dosexec
total bytes: 1022920
source: HTTP
MD5: fc13fee1d44ef737a3133f1298b21d28
SHA1: 7d99803eaf3b6e8dfa3581348bc694089579d25a
SHA256: dcb87a62a2b5d449abc138776000fd1b14edc690e9da6ea325b8f352ab033202
FILE_NEW
file #1, 0, 0
FILE_OVER_NEW_CONNECTION
FILE_TIMEOUT
FILE_TIMEOUT
FILE_GAP
FILE_STATE_REMOVE
file #1, 206024, 816896
[orig_h=192.168.72.14, orig_p=3257/tcp, resp_h=65.54.95.14, resp_p=80/tcp]
FILE_BOF_BUFFER
\x1b\xb8=\xb1\xff^PU^P\xce\xc3^
total bytes: 1022920
source: HTTP