[Bro-Dev] [JIRA] (BIT-1130) Fix some misidentification of SOCKS traffic

grigorescu (JIRA) jira at bro-tracker.atlassian.net
Tue Feb 11 14:01:37 PST 2014

grigorescu created BIT-1130:

             Summary: Fix some misidentification of SOCKS traffic
                 Key: BIT-1130
                 URL: https://bro-tracker.atlassian.net/browse/BIT-1130
             Project: Bro Issue Tracker
          Issue Type: Improvement
          Components: Bro
            Reporter: grigorescu

Added a constraint that the SOCKS command be 1, 2 or 3, which are the defined commands. This helps to address some traffic that was being misidentified as SOCKS. Has been running at CMU without issues.

This message was sent by Atlassian JIRA

More information about the bro-dev mailing list