[Bro] DNS and base64 woes
rkovar at gmail.com
Mon Jul 6 12:38:57 PDT 2015
I've been working on detecting base64 encrypted DNS exfil with Bro and
noticed that the default bro_dns.log makes all dns outbound calls
lowercase. But since base64 is case sensitive I can't decode the actual
content anymore… This appears to be a function of the bif.strings.bro (
However, I was wondering if there is a method/switch for bro to report the
DNS string as actually seen in the traffic? Example is show below:
The actual request is:
But bro_dns.log records it as:
"Illegitimi non carborundum"
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Bro