[Snort-openappid] Additional Apple maps detector

Y M snort at ...46...
Sat Sep 5 12:46:29 EDT 2015




Hello,
Here is an additional detector for Apple Maps app based on user-agent. As always, pcap is available.
--[[detection_name: apple_maps_appversion: 1description: Apple Maps application on OS X.--]]
require "DetectorCommon"local DC = DetectorCommon
local proto = DC.ipproto.tcp;DetectorPackageInfo = {        name = "apple_maps_app",        proto = proto,        server = {                init = 'DetectorInit',                clean = 'DetectorClean',                minimum_matches = 1        }}
function DetectorInit(detectorInstance)
        gDetector = detectorInstance;        gAppId = gDetector:open_createApp("apple_maps_app");
        if gDetector.addHttpPattern then                gDetector:addHttpPattern(2, 5, 0, gAppId, 0, 0, 0, "com.apple.geod/", gAppId);        end
        return gDetector;end
function DetectorClean()end
Thanks.YM
 		 	   		  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-openappid/attachments/20150905/76b50271/attachment.html>


More information about the Snort-openappid mailing list