Re: dpd.sig rejection syntax

TQ <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CAM2MKSof5M90H6Hm9anP+KQZGUKqiHUPFfpWe1T7Cn5vHXntnw@mail.gmail.com>
Thanks Jon.  Life saver as always!

On Mon, Apr 22, 2019 at 11:22 AM Jon Siwek <[email protected]> wrote:

> On Sun, Apr 21, 2019 at 2:58 PM TQ <[email protected]> wrote:
>
> > There are two protocols, A and B which use <STX> and <ETX> to
> encapsulate their data.  Both protocols operate over 20+ ports, and the
> only difference is that protocol B starts with lowercase 's' after \x02.
> I've looked over the dpd.sig files on Zeek GitHub but didn't find anything
> for rejection.
>
> Here's more extensive documentation on signatures:
>
> https://docs.zeek.org/en/latest/frameworks/signatures.html
>
> The negated "requires-signature" condition may be relevant to you.
>
> >  I've tried adding (!s), [!s] after \x02, but protocol A stops
> logging... so I know there's a syntax issue.
>
> The syntax generally follows these rules:
>
> http://westes.github.io/flex/manual/Patterns.html
>
> So [^s] means "anything except an 's' character"
>
> - Jon
>

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.