[Bro-Dev] Outstanding 2.5 tickets recap

Seth Hall seth at icir.org
Fri Oct 7 18:43:26 PDT 2016

> On Oct 7, 2016, at 10:36 AM, Robin Sommer <robin at icir.org> wrote:
> - SMB file not used?, https://bro-tracker.atlassian.net/browse/BIT-1721
>  Seth/Vlad: I noticed yesterday that an SMB .bif doesn't seem to be
>  used?

Vlad said he tested compiling that in and no tests were affected.  I'll test it with my private test suite as well.

> - missing uid field in SMB1 script, https://bro-tracker.atlassian.net/browse/BIT-1688?filter=10001
>  Seth?

Sorry, I think know the fix, I just need to get to it.

> - missing certain logs if logger node is enabled, https://bro-tracker.atlassian.net/browse/BIT-1700
>  Seth, does adding that 3rd option for now looks like a viable
>  compromise?

Yep, that's fine, but I left a note on the ticket with some more thoughts.

> - Very long "pipe_name" in dce_rpc.log, https://bro-tracker.atlassian.net/browse/BIT-1702
>  Seth/Vlad, sounds like the current suspicion is that this is trouble with fragmentation?

Yeah, it's that plus an actual parser error.  I have a sample and I'm working on it now.

> - Python 3.5 compatibility in broccoli-python, https://bro-tracker.atlassian.net/browse/BIT-1711?filter=10001
>  Seth, this is just waiting on more feedback on the problem I think

Left a note.

I'll be working on stuff this weekend... again. :)


Seth Hall
International Computer Science Institute
(Bro) because everyone has a network

More information about the bro-dev mailing list