[Bro] Quick question
James Lay
jlay at slave-tothe-box.net
Fri Mar 22 12:33:17 PDT 2013
Hey all
So quick question, from the notice log:
1363973380.007453 5L7Bsj0Y8dj x.x.x.x 36237
206.169.145.206 80 tcp HTTP::MD5 x.x.x.x
88c48daab78eee9f856c8bff2141f09b
http://r3---sn-ufuxaxjvh-v53e.c.pack.google.com/edgedl/toolbar/t7/data/7.4.3607.2246/GoogleToolbarInstaller_updater_signed.exe?ms=nvh&mv=u&mt=1363972912&ir=1&cms_redirect=yes
88c48daab78eee9f856c8bff2141f09b x.x.x.x 206.169.145.206 80 -
bro Notice::ACTION_LOG 6 3600.000000 F -
- - - - - - -
What's this telling me? Usually there's something like Invalid Cert or
something like that in the notice.log to tell me why it hit, just wasn't
seeing the reason here. Thank you.
James
More information about the Bro
mailing list