[Bro-Dev] [JIRA] (BIT-1449) Wrap Broker Bifs into script-level functions

2016-04-26 Thread Daniel Thayer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1449?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=25904#comment-25904 ] Daniel Thayer commented on BIT-1449: Branch "topic/dnthayer/ticket1449" in the bro git repo contains these

[Bro-Dev] [JIRA] (BIT-1575) AF_Packet hash in 4.4 is not symmetric anymore, needs a different tactics

2016-04-26 Thread Michal Purzynski (JIRA)
Michal Purzynski created BIT-1575: - Summary: AF_Packet hash in 4.4 is not symmetric anymore, needs a different tactics Key: BIT-1575 URL: https://bro-tracker.atlassian.net/browse/BIT-1575 Project:

[Bro-Dev] [JIRA] (BIT-1574) Please merge topic/johanna/imap-starttls

2016-04-26 Thread Johanna Amann (JIRA)
Johanna Amann created BIT-1574: -- Summary: Please merge topic/johanna/imap-starttls Key: BIT-1574 URL: https://bro-tracker.atlassian.net/browse/BIT-1574 Project: Bro Issue Tracker Issue Type:

[Bro-Dev] [JIRA] (BIT-1574) Please merge topic/johanna/imap-starttls

2016-04-26 Thread Johanna Amann (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1574?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Johanna Amann updated BIT-1574: --- Status: Merge Request (was: Open) > Please merge topic/johanna/imap-starttls >

[Bro-Dev] [JIRA] (BIT-1449) Wrap Broker Bifs into script-level functions

2016-04-26 Thread Daniel Thayer (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1449?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Daniel Thayer reassigned BIT-1449: -- Assignee: Daniel Thayer > Wrap Broker Bifs into script-level functions >

[Bro-Dev] [JIRA] (BIT-1573) 3 useless EventHandlerPtr in the ARP Analyzer

2016-04-26 Thread Johanna Amann (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1573?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=25902#comment-25902 ] Johanna Amann commented on BIT-1573: I might miss something - but it seems that those EventHanderPtrs are

[Bro-Dev] [JIRA] (BIT-1573) 3 useless EventHandlerPtr in the ARP Analyzer

2016-04-26 Thread llh (JIRA)
llh created BIT-1573: Summary: 3 useless EventHandlerPtr in the ARP Analyzer Key: BIT-1573 URL: https://bro-tracker.atlassian.net/browse/BIT-1573 Project: Bro Issue Tracker Issue Type: Improvement

[Bro-Dev] [JIRA] (BIT-274) Finding lines where redefs occurred

2016-04-26 Thread Adam Slagell (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-274?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Adam Slagell reassigned BIT-274: Assignee: (was: Jon Schipp) > Finding lines where redefs occurred >

[Bro-Dev] [JIRA] (BIT-1033) add script based on BBN's ICMP analyzer

2016-04-26 Thread Adam Slagell (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1033?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Adam Slagell reassigned BIT-1033: - Assignee: Vlad Grigorescu (was: Jon Schipp) > add script based on BBN's ICMP analyzer >

Re: [Bro-Dev] Deleting old branches

2016-04-26 Thread Vlad Grigorescu
Hooray, thanks for taking this on! I just did a quick check for branches named ticket* or bit* and all those tickets have been closed (I wanted to check if they had been left open with the idea that someone would circle back to that branch and add feature X). >From my end, all the topic/vladg

[Bro-Dev] [JIRA] (BIT-1571) Connection summaries w/ IPv6 have poor readabiity

2016-04-26 Thread Adam Slagell (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1571?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Adam Slagell updated BIT-1571: -- Attachment: text.html Or don’t count it in the port statistics, but still count it in the protocol

Re: [Bro-Dev] [JIRA] (BIT-1571) Connection summaries w/ IPv6 have poor readabiity

2016-04-26 Thread Slagell, Adam J
Or don’t count it in the port statistics, but still count it in the protocol stats. So you would see a ton of protocol #1 But I think I like your suggestion better because it separates things like 53/tcp and 53/udp. On Apr 26, 2016, at 9:04 AM, Vlad Grigorescu

Re: [Bro-Dev] [JIRA] (BIT-1571) Connection summaries w/ IPv6 have poor readabiity

2016-04-26 Thread Vlad Grigorescu
I'm not sure I agree without additional context. ICMP exfil is a known technique. Wouldn't you want to know if all of a sudden, you started seeing gigs of ICMP? Or is there some other limitation that would make detecting this problematic? What I would recommend instead is simply adding the

[Bro-Dev] [JIRA] (BIT-1571) Connection summaries w/ IPv6 have poor readabiity

2016-04-26 Thread Adam Slagell (JIRA)
[ https://bro-tracker.atlassian.net/browse/BIT-1571?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=25900#comment-25900 ] Adam Slagell commented on BIT-1571: --- Talking with Seth, he agrees that it probably just makes more sense to

[Bro-Dev] [Auto] Merge Status

2016-04-26 Thread Merge Tracker
Open Merge Requests === IDComponentReporterAssignee Updated For VersionPrioritySummary --- -- -- - --