[Bro] Quick question

James Lay jlay at slave-tothe-box.net
Fri Mar 22 12:33:17 PDT 2013


Hey all

So quick question, from the notice log:

1363973380.007453       5L7Bsj0Y8dj     x.x.x.x    36237   
206.169.145.206 80      tcp     HTTP::MD5       x.x.x.x 
88c48daab78eee9f856c8bff2141f09b 
http://r3---sn-ufuxaxjvh-v53e.c.pack.google.com/edgedl/toolbar/t7/data/7.4.3607.2246/GoogleToolbarInstaller_updater_signed.exe?ms=nvh&mv=u&mt=1363972912&ir=1&cms_redirect=yes 
88c48daab78eee9f856c8bff2141f09b x.x.x.x    206.169.145.206 80      -   
    bro     Notice::ACTION_LOG      6       3600.000000     F       -    
   -       -       -       -       -       -       -


What's this telling me?  Usually there's something like Invalid Cert or 
something like that in the notice.log to tell me why it hit, just wasn't 
seeing the reason here.  Thank you.

James



More information about the Bro mailing list