[Bro] Quick smtp-url-extraction question

Hosom, Stephen M hosom at battelle.org
Thu Aug 14 09:58:44 PDT 2014


Please close it and use Aashish's. Mine is actually a variation of his suite, so getting it from him works. 

-----Original Message-----
From: Seth Hall [mailto:seth at icir.org] 
Sent: Thursday, August 14, 2014 11:31 AM
To: Aashish Sharma
Cc: Hosom, Stephen M; Lankau, John; bro at bro-ids.org
Subject: Re: [Bro] Quick smtp-url-extraction question


On Aug 14, 2014, at 10:30 AM, Aashish Sharma <asharma at lbl.gov> wrote:

> 3) if you are running bro-2.3, use smtp-url-extraction-bloom.bro - it uses bloom filters to check against URL's in the http stream. So its less taxing on memory compared to (2). 

Thanks, Aashish.

I've been working on this script for a while this morning just doing general clean up and documentation.  Right now I'm getting ready to add cluster support to it.  I'll 

Stephen, cool if I close your pull request since I think that Aashish's script has more functionality?

  .Seth

--
Seth Hall
International Computer Science Institute
(Bro) because everyone has a network
http://www.bro.org/





More information about the Bro mailing list