[Bro] Logging packet with mismatch content_size and data is being sent after reset
robin.gruyters at gmail.com
Fri Dec 18 08:51:30 PST 2015
I wonder if you could help me.
I have created a policy that logs when a http stream has mismatch
content-size versus body.
This works fine but I need to add an extra check to see if data is being
sent after a reset.
I have uploaded my policy for you to see.
i know the weird.bro policy logs 'data_after_reset', but I don't know how
to incorporate this in my policy.
Could you please help me?
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Bro