Re: Download packet
Yoann Vandoorselaere <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <1204623259.5965.224.camel@arwen> |
Hello Konrad, Le jeudi 21 février 2008 à 00:05 +0100, Konrad Kosmowski a écrit : > > You already have packet payload in Prewikka, > > In what format it is stored? I've looked at database and it is BLOB > type (obviously) but for packets - how are they stored in IDMEF spec? > Seriously I am ignorant. Please explain. ;) We store the different packet headers fields as additional data within IDMEF messages (section 4.2.4.6 of the IDMEF RFC). > > so I don't expect that this would be hard to implement. Still, the question > > would be, "who is gonna write the code?" It's not a widely-requested > > feature, so it probably wouldn't be on the hot list. > > Heh the ability to analyze a packet data with a tool that can > interpret it in various formats/protocols etc. like Wireshark is a > feature that IMHO is essential. > > IMHO it would be extremely hard to implement what Wireshark does in > Prewikka so it makes no sense to implement it there - Wireshark does > it extremely well so just pass the file from Prewikka to client > application and you are done with this feature. > > I compare Prelude to Mc Afee IPS systems that are quite commercial > standards these days and these systems do that. So it IMHO is an > feature to copy. > > > Your best bet is to open a ticket on Trac asking for the feature to be > > added. > > I'll try. :) This would be a great functionality to add to the Snort sensor, and it should be pretty easy to implement. Please don't hesitate to open a ticket for this enhancement. Regards, -- Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies Tel: +33 (0)8 70 70 21 58 Fax: +33(0)4 78 42 21 58 http://www.prelude-ids.com _______________________________________________ Prelude-user site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-user