[Bro-Dev] SSH Capabilities Bug: Fix for 2.6?

Vlad Grigorescu vlad at es.net
Mon Oct 15 13:26:15 PDT 2018


During BroCon, someone brought a bug in the SSH analyzer to my attention.

The SSH Capabilities record has the following field, which is being set
incorrectly:

        ## Are these the capabilities of the server?
>         is_server:                  bool;
>


> result->Assign(6, new Val(${msg.is_orig}, TYPE_BOOL));
>

Obviously, I'd like to fix this. I'm curious to hear thoughts about getting
this into 2.6. I know that the hassh package currently works around the
broken logic.

  --Vlad
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.icsi.berkeley.edu/pipermail/bro-dev/attachments/20181015/8a704da8/attachment.html 


More information about the bro-dev mailing list