[Bro-Dev] [JIRA] (BIT-1545) SSH connection not recording entire flow correctly

2016-03-10 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1545?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=24800#comment-24800 ] Vern Paxson commented on BIT-1545: -- I'm definitely a fan of at least adding transparency that the value has

[Bro-Dev] [JIRA] (BIT-1535) conn.log conn_state field or documentation is wrong

2016-02-10 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1535?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Vern Paxson reassigned BIT-1535: Assignee: Vern Paxson > conn.log conn_state field or documentation is wrong >

[Bro-Dev] [JIRA] (BIT-1535) conn.log conn_state field or documentation is wrong

2016-02-10 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1535?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=24102#comment-24102 ] Vern Paxson edited comment on BIT-1535 at 2/10/16 3:03 PM: --- Yeah, historically "RSTR"

[Bro-Dev] [JIRA] (BIT-1506) Bro fails to build on OS X 10.11 (El Capitan) due to OpenSSL header removal

2015-11-16 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1506?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=22900#comment-22900 ] Vern Paxson commented on BIT-1506: -- @Vlad: _au contraire_. Maybe no one runs Bro on OS X for live traffic,

[Bro-Dev] [JIRA] (BIT-903) -b turns off -f

2015-10-19 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-903?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=22626#comment-22626 ] Vern Paxson commented on BIT-903: - FYI it's annoying to be told that my report is a "duplicate" of *one filed 3

[Bro-Dev] [JIRA] (BIT-903) -b turns off -f

2015-10-19 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-903?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=22628#comment-22628 ] Vern Paxson commented on BIT-903: - Got it. The phrase then to use would be "Superseded by BIT-1407" > -b turns

[Bro-Dev] [JIRA] (BIT-1411) SQL_Injection_Victim is a misleading name

2015-09-08 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1411?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=22013#comment-22013 ] Vern Paxson commented on BIT-1411: -- I fully agree with the rationale behind splitting it - just want the name

[Bro-Dev] [JIRA] (BIT-1411) SQL_Injection_Victim is a misleading name

2015-09-06 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1411?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=21972#comment-21972 ] Vern Paxson commented on BIT-1411: -- @Matthias: perhaps. That works for values/types that can have attributes

[Bro-Dev] [JIRA] (BIT-1431) Loss of information due to analyzer capitalization changes

2015-07-08 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1431?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=21200#comment-21200 ] Vern Paxson commented on BIT-1431: -- This can break in a nasty way. The original reason for

[Bro-Dev] [JIRA] (BIT-1427) rare SSH successful login heuristic FPs

2015-06-21 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1427?focusedWorklogId=10100page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-10100 ] Vern Paxson logged work on BIT-1427: Author: Vern Paxson

[Bro-Dev] [JIRA] (BIT-1427) rare SSH successful login heuristic FPs

2015-06-21 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1427?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Vern Paxson updated BIT-1427: - Resolution: Fixed Fix Version/s: 2.4 Status: Closed (was: Open) Already presumed

[Bro-Dev] [JIRA] (BIT-1427) rare SSH successful login heuristic FPs

2015-06-21 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1427?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=21006#comment-21006 ] Vern Paxson commented on BIT-1427: -- Thanks, Vlad. I'll close this. Once we upgrade to 2.4,

[Bro-Dev] [JIRA] (BIT-1428) Customizable email subject lines

2015-06-20 Thread Vern Paxson (JIRA)
Vern Paxson created BIT-1428: Summary: Customizable email subject lines Key: BIT-1428 URL: https://bro-tracker.atlassian.net/browse/BIT-1428 Project: Bro Issue Tracker Issue Type: New Feature

[Bro-Dev] [JIRA] (BIT-1418) SSH::Login_By_Password_Guesser is not implemented

2015-06-05 Thread Vern Paxson (JIRA)
Vern Paxson created BIT-1418: Summary: SSH::Login_By_Password_Guesser is not implemented Key: BIT-1418 URL: https://bro-tracker.atlassian.net/browse/BIT-1418 Project: Bro Issue Tracker Issue

[Bro-Dev] [JIRA] (BIT-1417) FTP_UnexpectedConn notice has gone away

2015-06-05 Thread Vern Paxson (JIRA)
Vern Paxson created BIT-1417: Summary: FTP_UnexpectedConn notice has gone away Key: BIT-1417 URL: https://bro-tracker.atlassian.net/browse/BIT-1417 Project: Bro Issue Tracker Issue Type: Problem

[Bro-Dev] [JIRA] (BIT-1419) HTTPProxyFound notice has gone away

2015-06-05 Thread Vern Paxson (JIRA)
Vern Paxson created BIT-1419: Summary: HTTPProxyFound notice has gone away Key: BIT-1419 URL: https://bro-tracker.atlassian.net/browse/BIT-1419 Project: Bro Issue Tracker Issue Type: New Feature

[Bro-Dev] [JIRA] (BIT-1407) -f silently fails if base/frameworks/packet-filter isn't loaded

2015-06-01 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1407?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=20903#comment-20903 ] Vern Paxson commented on BIT-1407: -- While there's an appeal to processing arguments in

[Bro-Dev] [JIRA] (BIT-1409) DNS ZoneTransfer notice missing

2015-06-01 Thread Vern Paxson (JIRA)
Vern Paxson created BIT-1409: Summary: DNS ZoneTransfer notice missing Key: BIT-1409 URL: https://bro-tracker.atlassian.net/browse/BIT-1409 Project: Bro Issue Tracker Issue Type: Problem

[Bro-Dev] [JIRA] (BIT-1407) -f silently fails if base/frameworks/packet-filter isn't loaded

2015-06-01 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1407?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=20904#comment-20904 ] Vern Paxson commented on BIT-1407: -- Also, regarding the policy script adding the -f flag: how

[Bro-Dev] [JIRA] (BIT-1411) SQL_Injection_Victim is a misleading name

2015-06-01 Thread Vern Paxson (JIRA)
Vern Paxson created BIT-1411: Summary: SQL_Injection_Victim is a misleading name Key: BIT-1411 URL: https://bro-tracker.atlassian.net/browse/BIT-1411 Project: Bro Issue Tracker Issue Type:

[Bro-Dev] [JIRA] (BIT-1412) Documentation/control of Jira markup shortcuts?

2015-06-01 Thread Vern Paxson (JIRA)
Vern Paxson created BIT-1412: Summary: Documentation/control of Jira markup shortcuts? Key: BIT-1412 URL: https://bro-tracker.atlassian.net/browse/BIT-1412 Project: Bro Issue Tracker Issue Type:

[Bro-Dev] [JIRA] (BIT-1412) Documentation/control of Jira markup shortcuts?

2015-06-01 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1412?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=20909#comment-20909 ] Vern Paxson commented on BIT-1412: -- Yes I see those but those aren't the shortcuts enabled for

[Bro-Dev] [JIRA] (BIT-1405) Notice framework documentation glitch

2015-05-30 Thread Vern Paxson (JIRA)
Vern Paxson created BIT-1405: Summary: Notice framework documentation glitch Key: BIT-1405 URL: https://bro-tracker.atlassian.net/browse/BIT-1405 Project: Bro Issue Tracker Issue Type: Problem

[Bro-Dev] [JIRA] (BIT-1406) Trouble locating -b documentation

2015-05-30 Thread Vern Paxson (JIRA)
Vern Paxson created BIT-1406: Summary: Trouble locating -b documentation Key: BIT-1406 URL: https://bro-tracker.atlassian.net/browse/BIT-1406 Project: Bro Issue Tracker Issue Type: Problem

[Bro-Dev] [JIRA] (BIT-1407) -f silently fails if base/frameworks/packet-filter isn't loaded

2015-05-30 Thread Vern Paxson (JIRA)
Vern Paxson created BIT-1407: Summary: -f silently fails if base/frameworks/packet-filter isn't loaded Key: BIT-1407 URL: https://bro-tracker.atlassian.net/browse/BIT-1407 Project: Bro Issue Tracker

[Bro-Dev] [JIRA] (BIT-1405) Notice framework documentation confusion

2015-05-30 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1405?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Vern Paxson updated BIT-1405: - Description: The [Notice documentation|https://www.bro.org/sphinx/frameworks/notice.html] includes the

[Bro-Dev] [JIRA] (BIT-1397) broctl --help is mysterious

2015-05-23 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1397?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=20720#comment-20720 ] Vern Paxson commented on BIT-1397: -- @robin: yeah, I think that's fine. I just want the error

[Bro-Dev] [JIRA] (BIT-1397) broctl --help is mysterious

2015-05-17 Thread Vern Paxson (JIRA)
Vern Paxson created BIT-1397: Summary: broctl --help is mysterious Key: BIT-1397 URL: https://bro-tracker.atlassian.net/browse/BIT-1397 Project: Bro Issue Tracker Issue Type: Problem

[Bro-Dev] [JIRA] (BIT-1397) broctl --help is mysterious

2015-05-17 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1397?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=20710#comment-20710 ] Vern Paxson commented on BIT-1397: -- No, I don't have write access. I had expected that

[Bro-Dev] [JIRA] (BIT-1255) TCP reassembly issue

2015-02-27 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1255?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=19804#comment-19804 ] Vern Paxson commented on BIT-1255: -- That behavior is to not chew up tons of buffer when

[Bro-Dev] [JIRA] (BIT-1167) Add subnet support to intel framework

2014-03-27 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1167?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=15905#comment-15905 ] Vern Paxson commented on BIT-1167: -- I don't know if this is the issue Robin had in mind, but

[Bro-Dev] [JIRA] (BIT-1159) type checking inconsistencies

2014-03-20 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1159?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=15818#comment-15818 ] Vern Paxson commented on BIT-1159: -- Runtime as a general style for this sounds fine, but I'd

[Bro-Dev] [JIRA] (BIT-1156) DNS analyzer parses TXT records imcompletely

2014-03-13 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1156?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=15726#comment-15726 ] Vern Paxson commented on BIT-1156: -- Does payload of DNS TXT records mean that an individual

[Bro-Dev] [JIRA] (BIT-1045) Review usage of InternalError when parsing network traffic

2013-07-29 Thread Vern Paxson (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1045?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13401#comment-13401 ] Vern Paxson commented on BIT-1045: -- In line with what you frame, the history behind these is