mirror of
https://github.com/zeek/zeek.git
synced 2025-10-03 15:18:20 +00:00

We should now quite reliably detect scans/attacks, even when encrypted and not succesful.
21 lines
903 B
Text
21 lines
903 B
Text
# TEST-EXEC: bro -C -r $TRACES/tls/heartbleed.pcap %INPUT
|
|
# TEST-EXEC: mv notice.log notice-heartbleed.log
|
|
# TEST-EXEC: btest-diff notice-heartbleed.log
|
|
|
|
# @TEST-EXEC: bro -C -r $TRACES/tls/heartbleed-success.pcap %INPUT
|
|
# @TEST-EXEC: mv notice.log notice-heartbleed-success.log
|
|
# @TEST-EXEC: btest-diff notice-heartbleed-success.log
|
|
|
|
# @TEST-EXEC: bro -C -r $TRACES/tls/heartbleed-encrypted.pcap %INPUT
|
|
# @TEST-EXEC: mv notice.log notice-encrypted.log
|
|
# @TEST-EXEC: btest-diff notice-encrypted.log
|
|
|
|
# @TEST-EXEC: bro -C -r $TRACES/tls/heartbleed-encrypted-success.pcap %INPUT
|
|
# @TEST-EXEC: mv notice.log notice-encrypted-success.log
|
|
# @TEST-EXEC: btest-diff notice-encrypted-success.log
|
|
|
|
# @TEST-EXEC: bro -C -r $TRACES/tls/heartbleed-encrypted-short.pcap %INPUT
|
|
# @TEST-EXEC: mv notice.log notice-encrypted-short.log
|
|
# @TEST-EXEC: btest-diff notice-encrypted-short.log
|
|
|
|
@load protocols/ssl/heartbleed
|