some question about http inspector

谁是我的卡多 via Snort-sigs <[email protected]>
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <[email protected]>
Hello,&nbsp; &nbsp; &nbsp; First, Thank you for&nbsp;reading&nbsp;my e-mail!


I am analyzing the HTTP&nbsp;inspector&nbsp; source code about snort 3.&nbsp;What can I do to get the full content of the&nbsp; HTTP request or response message body after combine rather than the split content&nbsp;in the HTTP source code&nbsp;? such as flow:





GET /xxxxxxxxxxxxxxxxxxx&nbsp; &nbsp;HTTP/1.1

.............



HTTP/1.1 200 OK
..................


abc1111111111111111111111111111111111111111111111111111


I want to get the full respose message body "abc1111111111111111111111111111111111111111111111111111".
Can you give me some clues?
I would appreciate it so much for you time.

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.