[Snort-openappid] Kontiki Client detector

Y M snort at ...46...
Wed Aug 19 09:55:30 EDT 2015


Hi,
The below detector is for the client of the below system. No pcaps available for this one, sorry :).
--[[detection_name: kontiki_clientversion: 1description: Kontiki Client for the Kontiki Enterprise Video Content Management--]]
require "DetectorCommon"local DC = DetectorCommon
local proto = DC.ipproto.tcp;DetectorPackageInfo = {        name = "kontiki_client",        proto = proto,        server = {                init = 'DetectorInit',                clean = 'DetectorClean',                minimum_matches = 1        }}
function DetectorInit(detectorInstance)
        gDetector = detectorInstance;        gAppId = gDetector:open_createApp("kontiki_client");
        if gDetector.addAppUrl then                gDetector:addAppUrl(0, 0, 0, gAppId, 0, "kontiki.com", "/", "http:", "", gAppId);        end        if gDetector.addHttpPattern then                gDetector:addHttpPattern(2, 5, 0, gAppId, 0, 0, 0, "Kontiki Client", gAppId);        end
        return gDetector;end
function DetectorClean()end
Thank you.YM 		 	   		  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-openappid/attachments/20150819/dbd37bfc/attachment.html>


More information about the Snort-openappid mailing list