mirror of
https://github.com/zeek/zeek.git
synced 2025-10-10 10:38:20 +00:00

- Several places were just using old variable names or not loading scripts correctly after they'd been renamed/moved. - Revert/adjust a change in how HTTP file handles are generated that broke partial content responses. - Turn some libmagic builtin checks back on; seems some are actually useful (e.g. text detection seems to be a builtin). The rule going forward probably will be only to turn off a builtin if we confirm it causes issues. - Removed some tests that are redundant or not necessary anymore because the generic file analysis tests cover them. - A couple FTP tests still fail that I think need an actual solution via script changes.
22 lines
483 B
Text
22 lines
483 B
Text
FILE_NEW
|
|
file #0, 0, 0
|
|
MIME_TYPE
|
|
application/x-dosexec
|
|
FILE_OVER_NEW_CONNECTION
|
|
FILE_STATE_REMOVE
|
|
file #0, 1022920, 0
|
|
[orig_h=192.168.72.14, orig_p=3254/tcp, resp_h=65.54.95.206, resp_p=80/tcp]
|
|
total bytes: 1022920
|
|
source: HTTP
|
|
FILE_NEW
|
|
file #1, 0, 0
|
|
MIME_TYPE
|
|
application/octet-stream
|
|
FILE_OVER_NEW_CONNECTION
|
|
FILE_TIMEOUT
|
|
FILE_TIMEOUT
|
|
FILE_STATE_REMOVE
|
|
file #1, 206024, 0
|
|
[orig_h=192.168.72.14, orig_p=3257/tcp, resp_h=65.54.95.14, resp_p=80/tcp]
|
|
total bytes: 1022920
|
|
source: HTTP
|