Next: About this document ...
Up: The Bro 0.8 User
Previous: Bibliography
Contents
- ! operator
- Expressions
- !in operator
- Expressions
| Expressions
$
record constructor operator
- Expressions
| Expressions
- $ record field access operator
- Accessing Fields Using ``$''
- ( operator
- Expressions
- ) operator
- Expressions
- + operator
- Expressions
- ++ operator
- Expressions
- + addition operator
- Arithmetic Operators
| Temporal Addition
| Expressions
- + unary operator
- Arithmetic Operators
- - subtraction operator
- Arithmetic Operators
| Temporal Subtraction
| Expressions
- - unary operator
- Arithmetic Operators
| Temporal Negation
- * multiplication operator
- Arithmetic Operators
| Temporal Multiplication
| Expressions
- / division operator
- Arithmetic Operators
| Temporal Division
| Expressions
- += operator
- Filtering
- - operator
- Expressions
- - operator
- Expressions
- 4Dgifts username
- The hot-ids Module
- : operator
- Expressions
"|"|
short-circuit ``or''
- Logical Operators
| Expressions
&&
short-circuit ``and''
- Logical Operators
| Expressions
- ! ``not'' operator
- Logical Operators
- <
- Arithmetic Operators
- T
- Boolean Constants
- F
- Boolean Constants
- %modulus operator
- Expressions
- % format
- Predefined Functions
- = operator
- Expressions
==
equality operator
- Comparison Operators
| Exact Pattern Matching
| Expressions
| Expressions
"!
exact match negation
- Exact Pattern Matching
exact pattern match operator
- Exact Pattern Matching
"!=
inequality operator
- Comparison Operators
| Exact Pattern Matching
| Expressions
| Expressions
<
less-than operator
- Comparison Operators
| Expressions
<=
less-or-equal operator
- Comparison Operators
| Expressions
>
greater-than operator
- Comparison Operators
| Expressions
>=
greater-or-equal operator
- Comparison Operators
| Expressions
- ? operator
- Expressions
?$
record field test
- Expressions
- [ operator
- Expressions
| Expressions
- ] operator
- Expressions
| Expressions
- aborted execution
- Flags
- absolute time
- Temporal Types
- access
- allowable /16 network pairs
- hot variables
- allowable address pairs
- hot variables
- allowable services
- hot variables
- fatal inbound services
- hot variables
- forbidden attempted services
- hot variables
- forbidden inbound services
- hot variables
- forbidden services
- hot variables
- sensitive /24 destination networks
- hot variables
- sensitive /24 source networks
- hot variables
- sensitive destination addresses
- hot variables
- sensitive source addresses
- hot variables
- service allowed to a particular host
- hot variables
- service allowed to particular host pairs
- hot variables
- account_tried event
- scan event handlers
- ack above a hole (possible packet drop message)
- Additional handlers for ``weird''
- ack_above_hole event
- General Processing Events
| Additional handlers for ``weird''
- acknowledgment holes
- Additional handlers for ``weird''
- actions
- Actions for ``weird'' events
| Actions for ``weird'' events
| Actions for ``weird'' events
| Actions for ``weird'' events
| Actions for ``weird'' events
| Actions for ``weird'' events
| Actions for ``weird'' events
- WEIRD_FILE
- Actions for ``weird'' events
- WEIRD_IGNORE
- Actions for ``weird'' events
- WEIRD_LOG_ALWAYS
- Actions for ``weird'' events
- WEIRD_LOG_ONCE
- Actions for ``weird'' events
- WEIRD_LOG_PER_CONN
- Actions for ``weird'' events
- WEIRD_LOG_PER_ORIG
- Actions for ``weird'' events
- WEIRD_UNSPECIFIED
- Actions for ``weird'' events
- activating_encryption event
- login event handlers
- active module
- The active Module
- active_conn variable
- The active Module
- active_connection function
- Predefined Functions
- active_connection_reuse (``weird'' event)
- Events handled by conn_weird
- active_file function
- Predefined Functions
- add keyword
- Statements
- add statement
- Statements
- &add_func attribute
- Refinement
- add_interface function
- Predefined Functions
- add_tcpdump_filter function
- Predefined Functions
- addition
- numeric
- Arithmetic Operators
- temporal
- Temporal Addition
- additional information associated with a connection
- The connection record
| Connection summaries
- addl
- The connection record
- connection field
- The connection record
- addl_web variable
- scan variables
- addr
- see types, addr
- address masking
- Net Type
| Predefined Functions
| Predefined Functions
- address scanning
- The scan Analyzer
- address type
- Address Type to Address Operators
- constants
- Address Constants
- operators
- Address Operators
- addresses
- hot destinations
- hot variables
- hot sources
- hot variables
- in a connection
- Connection summaries
- local
- Site variables
| Site variables
| Site variables
| Site-specific functions
- mapping to hostnames
- The hf utility
- neighbor
- Site variables
| Site variables
| Site variables
- addrs
- The dns_mapping record
- dns_mapping field
- The dns_mapping record
\a
alert escape
- String Constants
- allow_16_net_pairs variable
- hot variables
- allow_pairs variable
- hot variables
- allow_services variable
- hot variables
- allow_services_pairs variable
- hot variables
- allow_services_to variable
- hot variables
- allow_spoof_services variable
- hot variables
- allowable /16 network pairs
- hot variables
- allowable address pairs
- hot variables
- altering log files
- login variables
- always_hot_ids variable
- The hot-ids Module
- always_hot_login_ids variable
- login variables
- analy analyzer
- The analy Analyzer
- analysis
- bidirectional vs. unidirectional
- Events handled by conn_weird
- off-line
- Traffic traces
| Flags
| Predefined Functions
| Connection functions
- on-line
- Live traffic
| Flags
| Predefined Variables
| Predefined Functions
| Connection functions
- analyzers
- Analyzers and Events to The interconn Analyzer
- load
- Loading Analyzers
- print-filter
- Filtering
| Filtering
- print-filter
- Filtering
- conn
- Generic Connection Analysis
- tcp
- no title
- udp
- no title
- site
- Site-specific information
- hot
- The hot Analyzer
- scan
- The scan Analyzer
- finger
- The finger Analyzer
- ftp
- The ftp Analyzer
- http
- The http Analyzer
- ident
- The ident Analyzer
- login
- The login Analyzer
- portmapper
- The portmapper Analyzer
- analy
- The analy Analyzer
- activating
- Activating an Analyzer
- application-specific
- The finger Analyzer to portmapper event handlers
- filtering
- Filtering to Filtering
- finger
- event handlers
- finger event handlers to finger event handlers
- variables
- finger variables to finger variables
- ftp
- event handlers
- ftp event handlers to ftp event handlers
- functions
- ftp functions to ftp functions
- variables
- ftp variables to ftp variables
- generic
- Generic Connection Analysis to Connection functions
- hot
- functions
- hot functions to hot functions
- variables
- hot variables to hot variables
- http
- event handlers
- http event handlers to http event handlers
- variables
- http variables to http variables
- ident
- event handlers
- ident event handlers to ident event handlers
- variables
- ident variables to ident variables
- instantiating
- Activating an Analyzer
- loading
- Loading Analyzers
- login
- event handlers
- login event handlers to login event handlers
- functions
- login functions to login functions
- variables
- login variables to login variables
- portmapper
- event handlers
- portmapper event handlers to portmapper event handlers
- functions
- portmapper functions to portmapper functions
- variables
- portmapper variables to portmapper variables
- scan
- event handlers
- scan event handlers to scan event handlers
- functions
- scan functions to scan functions
- variables
- scan variables to scan variables
- site-specific information
- Site-specific information to Site-specific functions
&&
``and'' operator
- Logical Operators
| Expressions
- anonymous function expression
- Expressions
- anticode.com
- login variables
- ``any'' type
- The any type to The any type
- replacing with union type
- Predefined Functions
- any_RPC_okay variable
- portmapper variables
- appending to a file
- Predefined Functions
- arithmetic expression
- Expressions
- array
- associative
- Tables
- multi-dimensional
- Declaring Tables
- as
- Files
- RLIMIT_NOFILE
- Files
- ASCII
- as usual character set
- String Operators
- assigning records
- Record Assignment to Record Assignment
- assignment expression
- Expressions
- associative array
- Tables
- attack
- Land
- hot functions
- attackers
- weenie
- The hot-ids Module
- attacks
- smurf
- login variables
- ATTEMPT_INTERVAL internal variable
- Generic TCP connection events
- attempted connections
- Generic TCP connection events
- attempted services
- forbidden
- hot variables
- attributes
- Attributes
- &add_func
- Refinement
- &create_expire
- Table Attributes
- &default
- Table Attributes
- &delete_func
- Refinement
- &expire_func
- Table Attributes
- &read_expire
- Table Attributes
- record fields
- Record Assignment
- &redef
- Refinement
- &write_expire
- Table Attributes
- auth error (RPC status code)
- portmapper functions
- auth-failed/ authentication annotation
- login event handlers
- auth/ authentication annotation
- login event handlers
- authentication
- accepted
- login event handlers
- rejected
- login event handlers
- skipped
- login event handlers
- authentication annotations
- ident event handlers
| login event handlers
| login event handlers
| login event handlers
| login event handlers
| login event handlers
- auth-failed/
- login event handlers
- auth/
- login event handlers
- confused/
- login event handlers
| login event handlers
- ident/
- ident event handlers
- (skipped)
- login event handlers
- authentication dialog
- Predefined Functions
| Predefined Functions
| The login Analyzer
| login analyzer confusion
- evasion
- login analyzer confusion
- authentication_accepted event
- login event handlers
- authentication_rejected event
- login event handlers
- authentication_skipped event
- login event handlers
- avoiding processing
- Predefined Functions
- backdoor
- avoiding false positives
- login variables
- prompts
- login variables
- triggered by ephemeral port
- login variables
- triggered by terminal type
- login variables
- backdoor_prompts variable
- login variables
- backspace character
- Predefined Functions
\b
backspace escape
- String Constants
- bad address mask
- run-time error
- Predefined Functions
- bad fmt date argument
- run-time error
- Predefined Functions
- bad fmt editing character
- run-time error
- Predefined Functions
- bad fmt field width
- run-time error
- Predefined Functions
- bad fmt floating-point argument
- run-time error
- Predefined Functions
- bad fmt format specifier
- run-time error
- Predefined Functions
- bad fmt integer argument
- run-time error
- Predefined Functions
- bad fmt precision
- run-time error
- Predefined Functions
- bad format
- Predefined Functions
- bad length argument (not a table or set)
- run-time error
- Predefined Functions
- bad second argument to mask_addr()
- Predefined Functions
- bad time
- bad time
- format conversion error
- Predefined Functions
- bad type for Date format
- Predefined Functions
- bad type for floating-point format
- Predefined Functions
- bad type for integer format
- Predefined Functions
- bad_HTTP_reply (``weird'' event)
- Events handled by conn_weird
- bad_HTTP_version (``weird'' event)
- Events handled by conn_weird
- bad_ICMP_checksum (``weird'' event)
- Events handled by conn_weird
- bad_ident_reply (``weird'' event)
- Events handled by conn_weird_addl
- bad_ident_request (``weird'' event)
- Events handled by conn_weird_addl
- bad_IP_checksum (``weird'' event)
- Events handled by net_weird
- bad_option event
- login event handlers
- bad_option_termination event
- login event handlers
- bad_pm_port (``weird'' event)
- Events generated by the
- bad_rlogin_prolog (``weird'' event)
- Events handled by conn_weird
- bad_RPC (``weird'' event)
- Events handled by conn_weird
- bad_RPC_program (``weird'' event)
- Events handled by conn_weird
- bad_SYN_ack (``weird'' event)
- Events handled by conn_weird
- bad_TCP_checksum (``weird'' event)
- Events handled by conn_weird
- bad_TCP_header_len (``weird'' event)
- Events handled by net_weird
- bad_UDP_checksum (``weird'' event)
- Events handled by conn_weird
- baroque_SYN (``weird'' event)
- Events handled by conn_weird
- beginning time of a connection
- The connection record
| Connection summaries
\a
bell escape
- String Constants
- bidirectional vs. unidirectional analysis
- Events handled by conn_weird
- big endian
- Predefined Functions
| The analy Analyzer
- /bin/eject exploit
- login variables
- BIND
- non-blocking DNS lookups
- The Bro source code
- blank_in_HTTP_request (``weird'' event)
- Events handled by conn_weird
- bool
- see types, bool
- booleans
- Booleans to Logical Operators
- Bourne shell
- Predefined Functions
- BPF (Berkeley Packet Filter)
- tuning
- Tuning BPF
- BPF buffers
- ensuring they are large
- Tuning BPF
- break keyword
- Statements
- break statement
- Statements
- Bro
- checkpointing
- Flags
- execution aborted
- Flags
- flags
- -P
- The dns Module
- -f
- Flags
- -h
- Flags
- -i
- Flags
- -p
- Flags
- -r
- Flags
- -w
- Flags
- -v
- Flags
- -F
- Flags
- -O
- Flags
- -P
- Flags
- -W
- Flags
- installing
- Building and installing Bro
- interactive use
- Using Bro interactively
- not running as root
- Tuning BPF
- optimizer
- Flags
- private caches
- Flags
| Flags
- references
- Introduction
- running
- Running Bro
- search path
- Run-time environment
- shadow
- Filtering
- source code
- The Bro source code
- startup slow due to compiling regular expressions
- Flags
- system configuration
- Tuning BPF
- usage
- Flags
- version
- Flags
- watchdog
- Flags
- web page
- The Bro source code
- wedging
- Flags
- Bro bugs/limitations
- causing ``weird'' events
- The weird Module
- .bro suffix
- Run-time environment
- .bro-dns-cache
- The dns Module
- .bro-RE-cache.v1
- Flags
- bro_done event
- General Processing Events
- $BRO_ID environment variable
- The log Module
- bro_init event
- Filtering
| Filtering
| General Processing Events
- bro_log_file variable
- Predefined Variables
| The log Module
- $BRO_PREFIXES environment variable
- Flags
| Run-time environment
- bro_signal event
- General Processing Events
- $BROPATH environment variable
- Run-time environment
- BS
- Predefined Functions
- buffer overflow tools
- login variables
- buffer size patch for libpcap
- Tuning BPF
- buffers
- large for BPF
- Tuning BPF
- buggy implementations
- causing ``weird'' events
- The weird Module
- bugs
- $ pattern operator not supported
- Embedded Pattern Matching
- appalling
- Additional handlers for ``weird''
| Additional handlers for ``weird''
- causing ``weird'' events
- The weird Module
- tcpdump
- Filtering
- building Bro
- Building and installing Bro
- byte_len function
- Predefined Functions
- bytes in connection
- Connection summaries
| Connection functions
- caches
- Bro's private ones
- Flags
- CALLIT portmapper call
- The portmapper Analyzer
- can't open
- run-time error
- Run-time environment
- can_drop_connectivity variable
- scan variables
- cannot create directory
- Predefined Functions
- capture_filter global variable
- Flags
- capture_filter variable
- Predefined Variables
| Filtering to Filtering
\r
carriage return escape
- String Constants
- casting
- not provided in Bro
- The any type
- cat function
- Predefined Functions
- Central Intelligence Agency
- detection
- hot variables
- cf utility program
- no title
- character set
- ASCII
- String Operators
- check_hot function
- hot functions
- check_info record
- login functions
| login functions
| login functions
| login functions
| login functions
- forbidden
- login functions
- hot
- login functions
- hot_id
- login functions
- check_scan function
- scan functions
- check_spoof function
- hot functions
- checkpointing Bro
- Flags
- checksum error
- ICMP
- Events handled by conn_weird
- IP
- Events handled by net_weird
- TCP
- Events handled by conn_weird
- UDP
- Events handled by conn_weird
- Christmas packet
- Events handled by conn_weird
- CIA detection
- hot variables
- CIDR
- Net Type
| Predefined Functions
| Predefined Functions
| Site variables
- clean function
- Predefined Functions
- cleanup event
- General Processing Events
- client port
- triggering a backdoor
- login variables
- clock time
- Predefined Functions
| Predefined Functions
- close function
- Predefined Functions
- Cold Fusion exploits
- http variables
- command shell
- Predefined Functions
- setuid root
- login variables
- compiling Bro
- Building and installing Bro
- compiling regular expressions
- Flags
- completed connections
- Generic TCP connection events
- compound statement
- Statements
- concatenation of strings
- Predefined Functions
- conditional expression
- Expressions
- configuration options
- -enable-brov6
- The Bro source code
- confused login analysis
- login analyzer confusion
- confused/ authentication annotation
- login event handlers
| login event handlers
- confusion of heuristics
- login analyzer confusion
- conn analyzer
- Generic Connection Analysis
- conn_id record
- The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
- conn_size function
- Connection functions
- conn_state function
- Connection functions
- conn_stats event
- The analy Analyzer
- conn_weird event
- Events handled by conn_weird
- conn_weird_addl event
- Events handled by conn_weird_addl
- connection
- additional information
- The connection record
| Connection summaries
- addresses
- The connection record
| The connection record
| Connection summaries
- analysis
- Generic Connection Analysis
| The hot Analyzer
| The analy Analyzer
- attempt
- Generic TCP connection events
- bytes
- The connection record
| Connection summaries
| Connection functions
- completion
- Generic TCP connection events
| Generic TCP connection events
- definitions
- Definitions of connections
- detecting sensitive
- hot functions
- duration
- The connection record
| Connection summaries
- establishment
- Generic TCP connection events
- events
- Generic TCP connection events
- finished
- Generic TCP connection events
- flags
- Connection summaries
- functions
- Connection functions
| Connection functions
- generic analysis
- Generic Connection Analysis
- half finished
- Generic TCP connection events
- hosts
- Connection summaries
- hot
- The connection record
| Connection functions
| login functions
| login functions
- hot analysis
- The hot Analyzer
- ICMP
- Definitions of connections
- ID
- Connection functions
| Connection functions
- initiator
- The connection record
| The connection record
- logging
- Connection functions
- new
- Generic TCP connection events
- non-existing
- Run-time errors for non-existing
- originator
- The connection record
| The connection record
- partial
- Generic TCP connection events
- partial close
- Generic TCP connection events
- pending
- Generic TCP connection events
- ports
- The connection record
| The connection record
- recording
- Connection functions
- rejected
- Generic TCP connection events
- reset
- Generic TCP connection events
- reuse
- Events handled by conn_weird
- sensitivity
- The connection record
- sequence numbers
- Predefined Functions
| Predefined Functions
- service
- The connection record
| Connection summaries
| Connection functions
| Connection functions
- simultaneous open
- Events handled by conn_weird
- size
- The connection record
| Connection summaries
| Connection functions
- start time
- The connection record
| Connection summaries
- state
- The connection record
| Connection summaries
| Connection functions
- summaries
- Connection summaries
- TCP
- Definitions of connections
- terminating with extreme prejudice
- Connection functions
- testing for existence
- Predefined Functions
- UDP
- Definitions of connections
- connection events
- TCP-specific
- Generic TCP connection events
- connection id is not a known connection
- Predefined Functions
| Run-time errors for non-existing
- connection id is not a known login connection
- Predefined Functions
| Predefined Functions
- connection record
- The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
- connection size
- undetermined for RST termination
- ftp variables
- connection states
- Connection summaries
| Connection summaries
| Connection summaries
| Connection summaries
| Connection summaries
| Connection summaries
| Connection summaries
| Connection summaries
| Connection summaries
| Connection summaries
| Connection summaries
| Connection summaries
| Connection summaries
- OTH
- Connection summaries
- REJ
- Connection summaries
- RSTO
- Connection summaries
- RSTOS0
- Connection summaries
- RSTR
- Connection summaries
- RSTRH
- Connection summaries
- S0
- Connection summaries
- S1
- Connection summaries
- S2
- Connection summaries
- S3
- Connection summaries
- SF
- Connection summaries
- SH
- Connection summaries
- SHR
- Connection summaries
- connection summary files
- Connection summaries
| Connection summaries
- red
- Connection summaries
| Connection summaries
- connection_attempt event
- Generic TCP connection events
- connection_established event
- Generic TCP connection events
| login event handlers
- connection_finished event
- Generic TCP connection events
- connection_half_finished event
- Generic TCP connection events
- connection_originator_SYN_ack (``weird'' event)
- Events handled by conn_weird
- connection_partial_close event
- Generic TCP connection events
- connection_pending event
- Generic TCP connection events
- connection_record function
- Predefined Functions
- connection_rejected event
- Generic TCP connection events
- connection_reset event
- Generic TCP connection events
- connectivity
- dropping
- scan variables
| scan functions
- const statement
- Statements
- const variable declaration
- Modifiability
- constant expression
- Expressions
- constant variables
- Statements
- constants
- The analy Analyzer
| The analy Analyzer
| The analy Analyzer
| The analy Analyzer
- address
- Address Constants
- boolean
- Boolean Constants
- count
- Numeric Constants
- ENDIAN_BIG
- The analy Analyzer
- ENDIAN_CONFUSED
- The analy Analyzer
- ENDIAN_LITTLE
- The analy Analyzer
- ENDIAN_UNKNOWN
- The analy Analyzer
- floating-point
- Numeric Constants
- hostname
- Address Constants
- integer
- Numeric Constants
- interval
- Temporal Constants to Temporal Constants
- net
- Net Constants
- pattern
- Pattern Constants to Pattern Constants
- port
- Port Constants
- record
- Record Constants to Record Constants
- string
- String Constants to String Constants
- temporal
- Temporal Constants
- time
- Temporal Constants to Temporal Constants
- contains_string function
- Predefined Functions
- CONTENTS_BOTH direction
- Predefined Functions
- CONTENTS_NONE direction
- Predefined Functions
- CONTENTS_ORIG direction
- Predefined Functions
- CONTENTS_RESP direction
- Predefined Functions
- control packets (SYN/FIN/RST)
- Flags
| The tcp analyzer
- conversion of non-IPv4 address to net
- Predefined Functions
- converting an IPv6 address to net
- run-time error
- Predefined Functions
- copy
- shallow vs. deep
- Record Assignment
| Table Assignment
- corrupted packets
- Events handled by conn_weird
| Events handled by net_weird
- count
- see types, count
- count maximum
- Predefined Functions
- count minimum
- Predefined Functions
- &create_expire attribute
- Table Attributes
- creating directories
- Predefined Functions
- creation_time
- The dns_mapping record
- dns_mapping field
- The dns_mapping record
- crud
- Generic TCP connection events
| The weird Module
- current_time function
- Predefined Functions
- d format
- Predefined Functions
| Predefined Functions
- daemon username
- The hot-ids Module
| ident variables
- daemons
- as innocuous user names
- ident variables
- data
- unanalyzed
- Events handled by conn_weird
- data_after_reset (``weird'' event)
- Events handled by conn_weird
- data_before_established (``weird'' event)
- Events handled by conn_weird
- day interval unit
- Temporal Constants
- debugging
- filtering problems
- Filtering
- decrement expressions
- Expressions
- deep copy
- Record Assignment
| Table Assignment
- default
- filtering
- Filtering
- &default attribute
- Table Attributes
- default values
- Table Attributes
- DEL
- Predefined Functions
| Predefined Functions
- delete character
- Predefined Functions
- delete keyword
- Statements
- delete statement
- Statements
- &delete_func attribute
- Refinement
- demux module
- The demux Module
- demux_conn function
- The demux Module
- denial of service
- excessively large fragments
- Events handled by flow_weird
- Land attack
- Events generated by the
- detecting scans
- The scan Analyzer
- detecting sensitive connections
- hot functions
- determine_service function
- Connection functions
- /dev/bpf
- Tuning BPF
- direct_login_prompts variable
- Predefined Variables
| login variables
- directions
- Predefined Functions
| Predefined Functions
| Predefined Functions
| Predefined Functions
- CONTENTS_BOTH
- Predefined Functions
- CONTENTS_NONE
- Predefined Functions
- CONTENTS_ORIG
- Predefined Functions
- CONTENTS_RESP
- Predefined Functions
- directories
- creating
- Predefined Functions
- directory names
- sensitive
- login variables
- discarder_check_icmp function
- Predefined Functions
- discarder_check_ip function
- Predefined Functions
- discarder_check_tcp function
- Predefined Functions
- discarder_check_udp function
- Predefined Functions
- discarder_maxlen variable
- Predefined Variables
- diverse network use
- causing ``weird'' events
- The weird Module
- division
- numeric
- Arithmetic Operators
- temporal
- Temporal Division
- DMZ
- spoof detection
- hot variables
- DNS
- Bro's private cache
- The dns Module
- forcing access to
- Flags
- mappings
- The dns_mapping record
- DNS lookups
- non-blocking
- The Bro source code
- dns module
- The dns Module
- dns_interesting_changes variable
- dns variables
- dns_mapping record
- no title
| The dns_mapping record
| The dns_mapping record
| The dns_mapping record
| The dns_mapping record
| The dns_mapping record
| The dns_mapping record
| The dns_mapping record
| The dns_mapping record
- dns_mapping_altered event
- dns event handlers
- dns_mapping_lost_name event
- dns event handlers
- dns_mapping_name_changed event
- dns event handlers
- dns_mapping_new_name event
- dns event handlers
- dns_mapping_unverified event
- dns event handlers
- dns_mapping_valid event
- dns event handlers
- done_with_network global variable
- Expressions
- done_with_network variable
- Predefined Variables
- dotted quads
- The hf utility
- double
- see types, double
- double maximum
- Predefined Functions
- double minimum
- Predefined Functions
- drop-connectivity shell script
- scan functions
- drop_address function
- scan functions
- dropping connectivity
- scan variables
| scan functions
- DUMP portmapper call
- The portmapper Analyzer
- duration
- The connection record
- connection field
- The connection record
- duration of a connection
- The connection record
| Connection summaries
- dynamic defaults
- Table Attributes
- e format
- Predefined Functions
- edit function
- Predefined Functions
- edit_and_check_line function
- login functions
- edit_and_check_password function
- login functions
- edit_and_check_user function
- login functions
- edited_input_trouble variable
- login variables
- editing
- Predefined Functions
- eggdrop sensitive filename
- ftp variables
- eggdrop sensitive login input
- login variables
- eject exploit
- login variables
- else keyword
- Statements
- embedded NUL
- run-time error
- Run-time errors for strings
- -enable-brov6 configuration option
- The Bro source code
- encrypted login sessions
- login event handlers
- encryption
- leading to ``excessive lines''
- login event handlers
- endian issues
- Predefined Functions
| The analy Analyzer
- ENDIAN_BIG constant
- The analy Analyzer
- ENDIAN_CONFUSED constant
- The analy Analyzer
- ENDIAN_LITTLE constant
- The analy Analyzer
- endian_type statistic
- The analy Analyzer
- ENDIAN_UNKNOWN constant
- The analy Analyzer
- endpoint record
- The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| Connection summaries
- endpoint_id function
- The port-name Module
- enum
- see types, enum
| see types, enum
- enumerations
- Enumerations to Enumerations
- environment
- accessing
- Predefined Functions
- responder
- login analyzer confusion
- Telnet options
- login analyzer confusion
- environment variables
- $BRO_ID
- The log Module
- $BRO_PREFIXES
- Flags
| Run-time environment
- $BROPATH
- Run-time environment
- $USER
- login analyzer confusion
- ephemeral port
- Connection functions
- triggering a backdoor
- login variables
- ephemeral ports
- confused with sensitive services
- hot variables
- equality expression
- Expressions
- escape sequences
- String Constants
- established connections
- Generic TCP connection events
- /etc/inetd.conf
- hot variables
- /etc/passwd
- http variables
- /etc/shadow
- http variables
- evasion
- authentication dialog
- The login Analyzer
| login analyzer confusion
- excessively small fragments
- Events handled by flow_weird
- inconsistent fragment size
- Events handled by flow_weird
- inconsistent fragments
- Events handled by flow_weird
- inconsistent RPC retransmission
- Events handled by conn_weird
- inconsistent TCP retransmission
- Additional handlers for ``weird''
- inserting NULs
- String Constants
- length mismatch
- Events handled by conn_weird
- using tunneling
- login event handlers
- event
- see types, event
- event engine
- Event handlers
- event handler
- invocation
- Event handlers
- event handlers
- Event handlers to Event handlers
- event handling
- weird
- Events handled by conn_weird to Additional handlers for ``weird''
- event keyword
- Statements
- event scheduling expression
- Expressions
- event statement
- Statements
- event type
- Event handlers to Event handlers
- events
- bro_init
- Filtering
| Filtering
- bro_init
- General Processing Events
- net_done
- General Processing Events
- bro_done
- General Processing Events
- bro_signal
- General Processing Events
- net_stats_update
- General Processing Events
- ack_above_hole
- General Processing Events
- new_connection
- Generic TCP connection events
- connection_established
- Generic TCP connection events
- connection_attempt
- Generic TCP connection events
- partial_connection
- Generic TCP connection events
- connection_finished
- Generic TCP connection events
- connection_rejected
- Generic TCP connection events
- connection_half_finished
- Generic TCP connection events
- connection_reset
- Generic TCP connection events
- connection_partial_close
- Generic TCP connection events
- connection_pending
- Generic TCP connection events
- udp_request
- The udp analyzer
- udp_reply
- The udp analyzer
- account_tried
- scan event handlers
- dns_mapping_valid
- dns event handlers
- dns_mapping_unverified
- dns event handlers
- dns_mapping_new_name
- dns event handlers
- dns_mapping_lost_name
- dns event handlers
- dns_mapping_name_changed
- dns event handlers
- dns_mapping_altered
- dns event handlers
- finger_request
- finger event handlers
- finger_reply
- finger event handlers
- ftp_request
- ftp event handlers
- ftp_reply
- ftp event handlers
- http_request
- http event handlers
- ident_request
- ident event handlers
- ident_reply
- ident event handlers
- ident_error
- ident event handlers
- login_failure
- login event handlers
- login_success
- login event handlers
- login_input_line
- login event handlers
- login_output_line
- login event handlers
- login_confused
- login event handlers
- login_confused_text
- login event handlers
- login_terminal
- login event handlers
- excessive_line
- login event handlers
- inconsistent_option
- login event handlers
- bad_option
- login event handlers
- bad_option_termination
- login event handlers
- authentication_accepted
- login event handlers
- authentication_rejected
- login event handlers
- authentication_skipped
- login event handlers
- connection_established
- login event handlers
- partial_connection
- login event handlers
- activating_encryption
- login event handlers
- pm_request_null
- portmapper event handlers
- pm_request_set
- portmapper event handlers
- pm_request_unset
- portmapper event handlers
- pm_request_getport
- portmapper event handlers
- pm_request_dump
- portmapper event handlers
- pm_request_callit
- portmapper event handlers
- pm_attempt_null
- portmapper event handlers
- pm_attempt_set
- portmapper event handlers
- pm_attempt_unset
- portmapper event handlers
- pm_attempt_getport
- portmapper event handlers
- pm_attempt_dump
- portmapper event handlers
- pm_attempt_callit
- portmapper event handlers
- pm_bad_port
- portmapper event handlers
- conn_stats
- The analy Analyzer
- conn_weird
- Events handled by conn_weird
- conn_weird_addl
- Events handled by conn_weird_addl
- flow_weird
- Events handled by flow_weird
- net_weird
- Events handled by net_weird
- rexmit_inconsistency
- Additional handlers for ``weird''
- ack_above_hole
- Additional handlers for ``weird''
- exceptional
- The weird Module to Additional handlers for ``weird''
- finish
- General Processing Events
| General Processing Events
- general Bro processing
- General Processing Events
- generic TCP connection
- Generic TCP connection events
- initialization
- General Processing Events
- scheduling
- Expressions
- startup
- General Processing Events
- termination
- General Processing Events
| General Processing Events
- exceptional events
- The weird Module to Additional handlers for ``weird''
- excess_RPC (``weird'' event)
- Events handled by conn_weird
- excessive_line event
- login event handlers
- excessive_RPC_len (``weird'' event)
- Events handled by conn_weird
- excessive_typeahead (login confusion state)
- login analyzer confusion
- excessively long lines
- login event handlers
- excessively_large_fragment (``weird'' event)
- Events handled by flow_weird
- excessively_small_fragment (``weird'' event)
- Events handled by flow_weird
- excluding hosts
- Filtering
- executables
- running
- Predefined Functions
- exit function
- Predefined Functions
- expanded_line
- login functions
- check_info field
- login functions
- expiration
- timer
- Expressions
| Predefined Variables
- &expire_func attribute
- Table Attributes
- explicit typing
- Typing
- exploit tools
- login variables
- smashdu.c
- login variables
- exploits
- login variables
| login variables
| login variables
- /bin/eject
- login variables
- buffer overflow
- login variables
- eject
- login variables
- loadmodule
- login variables
- Unix
- login variables
- expression statement
- Statements
- expressions
- Expressions to Expressions
- parenthesized
- Expressions
- constant
- Expressions
- variable
- Expressions
- increment
- Expressions
- decrement
- Expressions
- negation
- Expressions
- positivation
- Expressions
- arithmetic
- Expressions
- logical
- Expressions
- equality
- Expressions
- relational
- Expressions
- conditional
- Expressions
- assignment
- Expressions
- function call
- Expressions
- anonymous function
- Expressions
- event scheduling
- Expressions
- index
- Expressions
- membership
- Expressions
- pattern matching
- Expressions
- record field access
- Expressions
- record constructor
- Expressions
- record field test
- Expressions
- extra_repeat_text (login confusion state)
- login analyzer confusion
- EZsetup username
- The hot-ids Module
- -F flag
- Flags
| Flags
- f format
- Predefined Functions
- failure of heuristics
- login analyzer confusion
- fatal run-time error
- non-existing connection
- Predefined Functions
- fetch utility
- login variables
- fflush
- Predefined Functions
- field attributes
- Record Assignment
\f
formfeed escape
- String Constants
- file
- see types, file
- file type
- Files to Files
- filenames
- sensitive
- ftp variables
| login variables
- files
- appending
- Predefined Functions
- opening
- Predefined Functions
| Predefined Functions
- testing if open
- Predefined Functions
- filtering
- default
- Filtering
- filters
- Filtering to Filtering
- displaying
- Filtering
- errors
- Filtering
- FIN control packet
- Flags
| The tcp analyzer
- FIN_advanced_last_seq (``weird'' event)
- Events handled by conn_weird
- FIN_after_reset (``weird'' event)
- Events handled by conn_weird
- FIN_storm (``weird'' event)
- Events handled by conn_weird
- Finger
- analysis
- The finger Analyzer
- weird events
- Events handled by conn_weird
- finger analyzer
- The finger Analyzer
- finger_reply event
- finger event handlers
- finger_request event
- finger event handlers
- finish event
- General Processing Events
| General Processing Events
- firewall
- reactive
- scan variables
| scan functions
- flag_rejected_service variable
- hot variables
- flag_successful_inbound_service variable
- hot variables
- flag_successful_service variable
- hot variables
- flags
- -P
- The dns Module
- -f
- Flags
- -h
- Flags
- -i
- Flags
- -p
- Flags
- -r
- Flags
- -w
- Flags
- -v
- Flags
- -F
- Flags
- -O
- Flags
- -P
- Flags
- -W
- Flags
- flags of connection
- Connection summaries
- flex utility
- Pattern Constants
- flow_weird event
- Events handled by flow_weird
- flush_all function
- Predefined Functions
- fmt function
- Predefined Functions
- for keyword
- Statements
- for statement
- Statements
- forbidden check_info record
- login functions
- forbidden_id_patterns variable
- The hot-ids Module
- forbidden_ids variable
- The hot-ids Module
- forbidden_ids_if_no_password variable
- The hot-ids Module
- forcing access to Bro's private DNS cache
- Flags
- format
- %
- Predefined Functions
- d
- Predefined Functions
| Predefined Functions
- e
- Predefined Functions
- f
- Predefined Functions
- g
- Predefined Functions
- precision
- Predefined Functions
- width
- Predefined Functions
- formatting text
- Predefined Functions
- .forward
- ftp variables
- frag module
- The frag Module
- fragment reassembly
- The frag Module
- fragment_inconsistency (``weird'' event)
- Events handled by flow_weird
- fragment_overlap (``weird'' event)
- Events handled by flow_weird
- fragment_protocol_inconsistency (``weird'' event)
- Events handled by flow_weird
- fragment_size_inconsistency (``weird'' event)
- Events handled by flow_weird
- fragment_with_DF (``weird'' event)
- Events handled by flow_weird
- fragments
- excessively large
- Events handled by flow_weird
- excessively small
- Events handled by flow_weird
- inconsistent
- Events handled by flow_weird
- inconsistent protocols
- Events handled by flow_weird
- inconsistent sizes
- Events handled by flow_weird
- overlapping
- Events handled by flow_weird
- TCP vs. UDP
- The frag Module
- frogs
- dissecting
- http variables
- FTP
- analysis
- The ftp Analyzer
- ephemeral ports confused with sensitive services
- hot variables
- log file
- ftp variables
- session information
- The ftp_session_info record
- weird events
- Events handled by conn_weird
- ftp analyzer
- The ftp Analyzer
- ftp session summary file
- ftp variables
- ftp_guest_ids variable
- ftp variables
- ftp_hot_files variable
- ftp variables
- ftp_hot_guest_files variable
- ftp variables
- ftp_not_actually_hot_files variable
- ftp variables
- ftp_port record
- Predefined Functions
| Predefined Functions
- ftp_reply event
- ftp event handlers
- ftp_request event
- ftp event handlers
- ftp_session_info record
- no title
| The ftp_session_info record
| The ftp_session_info record
| The ftp_session_info record
| The ftp_session_info record
| The ftp_session_info record
| The ftp_session_info record
| The ftp_session_info record
| The ftp_session_info record
| The ftp_session_info record
- ftp_skip_hot variable
- ftp variables
- full_id_string function
- Connection functions
- function
- see types, function
- function call expression
- Expressions
- function invocation
- Expressions
- function keyword
- Expressions
- function type
- Functions to Functions
- functions
- Functions to Functions
- active_connection
- Predefined Functions
- active_file
- Predefined Functions
- add_interface
- Predefined Functions
- add_tcpdump_filter
- Predefined Functions
- log_hook
- Predefined Functions
- byte_len
- Predefined Functions
- cat
- Predefined Functions
- clean
- Predefined Functions
- close
- Predefined Functions
- connection_record
- Predefined Functions
- contains_string
- Predefined Functions
- current_time
- Predefined Functions
- discarder_check_icmp
- Predefined Functions
- discarder_check_ip
- Predefined Functions
- discarder_check_tcp
- Predefined Functions
- discarder_check_udp
- Predefined Functions
- edit
- Predefined Functions
- exit
- Predefined Functions
- flush_all
- Predefined Functions
- fmt
- Predefined Functions
- get_login_state
- Predefined Functions
- get_orig_seq
- Predefined Functions
- get_resp_seq
- Predefined Functions
- getenv
- Predefined Functions
- is_tcp_port
- Predefined Functions
- length
- Predefined Functions
- log_file_name
- Predefined Functions
- mask_addr
- Predefined Functions
- max_count
- Predefined Functions
- max_double
- Predefined Functions
- max_interval
- Predefined Functions
- min_count
- Predefined Functions
- min_double
- Predefined Functions
- min_interval
- Predefined Functions
- mkdir
- Predefined Functions
- network_time
- Predefined Functions
- open
- Predefined Functions
- open_for_append
- Predefined Functions
- open_log_file
- Predefined Functions
- parse_ftp_pasv
- Predefined Functions
- parse_ftp_port
- Predefined Functions
- reading_live_traffic
- Predefined Functions
- set_buf
- Predefined Functions
- set_contents_file
- Predefined Functions
- set_login_state
- Predefined Functions
- set_record_packets
- Predefined Functions
- skip_further_processing
- Predefined Functions
- sub_bytes
- Predefined Functions
- system
- Predefined Functions
- to_lower
- Predefined Functions
- to_net
- Predefined Functions
- to_upper
- Predefined Functions
- conn_size
- Connection functions
- conn_state
- Connection functions
- determine_service
- Connection functions
- full_id_string
- Connection functions
- id_string
- Connection functions
- log_hot_conn
- Connection functions
- record_connection
- Connection functions
- service_name
- Connection functions
- terminate_connection
- Connection functions
- is_local_addr
- Site-specific functions
- check_spoof
- hot functions
- check_hot
- hot functions
- drop_address
- scan functions
- check_scan
- scan functions
- endpoint_id
- The port-name Module
- log_hook
- The log Module
| The log Module
- log_hook
- The log Module
- demux_conn
- The demux Module
- is_ftp_data_conn
- ftp functions
- is_login_conn
- login functions
- hot_login
- login functions
- is_hot_id
- login functions
- is_forbidden_id
- login functions
- edit_and_check_line
- login functions
- edit_and_check_user
- login functions
- edit_and_check_password
- login functions
- rpc_prog
- portmapper functions
- pm_check_getport
- portmapper functions
- pm_activity
- portmapper functions
- pm_request
- portmapper functions
- pm_attempt
- portmapper functions
- report_weird
- weird functions
- report_weird_conn
- weird functions
- report_weird_orig
- weird functions
- open
- Files
- open_for_append
- Files
- anonymous
- Expressions
- redefining
- Functions
- site-specific
- Site-specific functions
- g format
- Predefined Functions
- garbage args (RPC status code)
- portmapper functions
- general Bro processing events
- General Processing Events
- general scripting
- Predefined Functions
- generic connection analysis
- Generic Connection Analysis
- GET HTTP method
- http variables
- get_login_state function
- Predefined Functions
- get_orig_seq function
- Predefined Functions
- get_resp_seq function
- Predefined Functions
- getenv function
- Predefined Functions
- GETPORT portmapper call
- The portmapper Analyzer
- global scope
- of enumerations
- Enumerations
- global variable declaration
- Scope
- global variables
- Scope
- interfaces
- Live traffic
- capture_filter
- Flags
- restrict_filter
- Flags
- interfaces
- Flags
- done_with_network
- Expressions
- -h flag
- Flags
- half-finished connections
- Generic TCP connection events
- handling signals
- General Processing Events
- HEAD HTTP method
- http variables
- headers
- truncated
- Events handled by net_weird
- help message
- Flags
- heuristics
- attacker-induced confusion
- login analyzer confusion
- confusion
- login analyzer confusion
- environment
- login analyzer confusion
- extracting username information
- The login Analyzer
| login analyzer confusion
- missing login prompt
- login analyzer confusion
- missing username
- login analyzer confusion
| login analyzer confusion
- multiple login prompts
- login analyzer confusion
| login analyzer confusion
- multiple usernames
- login analyzer confusion
- type-ahead
- login analyzer confusion
- VMS
- login analyzer confusion
| login analyzer confusion
| login analyzer confusion
\x
hex-digits hexadecimal escape
- String Constants
- hf utility program
- no title
- host order (vs. network order)
- Predefined Functions
- hostname
- The dns_mapping record
- dns_mapping field
- The dns_mapping record
- hostnames
- Address Constants
- mapping addresses to
- The hf utility
- hosts
- excluding
- Filtering
- in a connection
- Connection summaries
- hot
- The connection record
- connection field
- The connection record
- hot /24 destination networks
- hot variables
- hot /24 source networks
- hot variables
- hot analyzer
- The hot Analyzer
- hot check_info record
- login functions
- hot connection
- analysis
- The hot Analyzer
- logging
- Connection functions
- hot connections
- login functions
| login functions
- hot destination addresses
- hot variables
- hot detection
- hot functions
- hot source addresses
- hot variables
- hot usernames
- The hot-ids Module
- hot-ids module
- The hot-ids Module
- hot_dst_24nets variable
- hot variables
- hot_dsts variable
- hot variables
- hot_id check_info record
- login functions
- hot_ident_exceptions variable
- ident variables
- hot_ident_ids variable
- ident variables
- hot_ids variable
- The hot-ids Module
- hot_login function
- login functions
- hot_login_ids variable
- login variables
- hot_names variable
- finger variables
- hot_src_24nets variable
- hot variables
- hot_srcs variable
- hot variables
- hot_ssh_orig_ports variable
- login variables
- hot_telnet_orig_ports variable
- login variables
- hot_terminal_types variable
- login variables
- hr (hours) interval unit
- Temporal Constants
- HTTP
- analysis
- The http Analyzer
- log file
- http variables
- weird events
- Events handled by conn_weird
- http analyzer
- The http Analyzer
- HTTP methods
- http variables
| http variables
| http variables
| http variables
- GET
- http variables
- HEAD
- http variables
- POST
- http variables
- HTTP packets
- contents not being recorded
- Flags
- http session summary file
- http variables
- http_request event
- http event handlers
- HTTP_unknown_method (``weird'' event)
- Events handled by conn_weird
- HTTP_version_mismatch (``weird'' event)
- Events handled by conn_weird
- HUP signal
- General Processing Events
- -i flag
- Flags
- ICMP
- checksum error
- Events handled by conn_weird
- connections
- Definitions of connections
- timeout
- Definitions of connections
- weird events
- Events handled by conn_weird
- id
- The connection record
| The ftp_session_info record
- ftp_session_info field
- The ftp_session_info record
- ID of connection
- Connection functions
| Connection functions
- id_string function
- Connection functions
- IDENT
- analysis
- The ident Analyzer
- weird events
- Events handled by conn_weird_addl
- ident analyzer
- The ident Analyzer
- ident/ authentication annotation
- ident event handlers
- ident_error event
- ident event handlers
- ident_reply event
- ident event handlers
- ident_request event
- ident event handlers
- ident_request_addendum (``weird'' event)
- Events handled by conn_weird_addl
- IEUser
- useless FTP username
- ftp variables
- if keyword
- Statements
- if statement
- Statements
- implicit typing
- Typing
- in operator
- Embedded Pattern Matching
| Expressions
| Expressions
- in-order delivery
- The analy Analyzer
"!in
negation of in operator
- Embedded Pattern Matching
- inappropriate_FIN (``weird'' event)
- Events handled by conn_weird
- inbound services
- fatal
- hot variables
- forbidden
- hot variables
- incompletely_captured_fragment (``weird'' event)
- Events handled by flow_weird
- inconsistent acknowledgment
- Additional handlers for ``weird''
- inconsistent retransmission
- Events handled by conn_weird
| Additional handlers for ``weird''
- inconsistent_option event
- login event handlers
- increment expressions
- Expressions
- index
- of a table
- Tables
- index expression
- Expressions
- inetd.conf
- hot variables
- inferring types
- Typing
- information associated with a connection
- The connection record
| Connection summaries
- ingreslock popular backdoor
- hot variables
- initialization event
- General Processing Events
- initialization of variables
- Initialization
- input
- analysis
- The login Analyzer
- editing
- login variables
- input_trouble variable
- login variables
- installing Bro
- Installing Bro
- int
- see types, int
- INT signal
- General Processing Events
- integers
- network vs. host order
- Predefined Functions
- interfaces global variable
- Live traffic
| Flags
- interfaces variable
- Predefined Variables
- internal networks
- spoof detection
- hot variables
- internal variables
- ATTEMPT_INTERVAL
- Generic TCP connection events
- PARTIAL_CLOSE_INTERVAL
- Generic TCP connection events
- WATCHDOG_INTERVAL
- Flags
- internally_truncated_header (``weird'' event)
- Events handled by net_weird
- Internet Relay Chat (IRC)
- attacker subpopulation
- login variables
- interval
- see types, interval
- interval maximum
- Predefined Functions
- interval minimum
- Predefined Functions
- interval units
- usec
- Temporal Constants
- sec
- Temporal Constants
- min
- Temporal Constants
- hr
- Temporal Constants
- day
- Temporal Constants
- invocation
- function
- Expressions
- invoking event handlers
- Event handlers
- IP
- checksum error
- Events handled by net_weird
- fragments
- Events handled by flow_weird
- identification field
- The analy Analyzer
- weird events
- Events handled by net_weird
- IPv4/IPv6 address constants
- Address Constants
- IPv6 and lack of CIDR prefixes
- Net Type
- IPv6 support
- Address Type
- IRC
- login variables
- is not a TCP connection
- Predefined Functions
| Predefined Functions
- is_forbidden_id function
- login functions
- is_ftp_data_conn function
- ftp functions
- is_hot_id function
- login functions
- is_local_addr function
- Site-specific functions
- is_login_conn function
- login functions
- is_tcp_port function
- Predefined Functions
- isascii
- Predefined Functions
| Predefined Functions
- islower
- Predefined Functions
- isupper
- Predefined Functions
- keystrokes
- analysis
- The login Analyzer
- editing
- login variables
- keywords
- print
- Statements
- log
- Statements
- event
- Statements
- if
- Statements
- else
- Statements
- for
- Statements
- next
- Statements
- break
- Statements
- return
- Statements
- add
- Statements
- delete
- Statements
- function
- Expressions
- schedule
- Expressions
- kiddies
- script
- hot variables
- Land attack
- hot functions
| Events generated by the
- Land_attack (``weird'' event)
- Events generated by the
- large BPF buffers
- Tuning BPF
(
operator
- Expressions
| Expressions
- length
- of strings
- Predefined Functions
- of table or set
- Predefined Functions
- length function
- Predefined Functions
- length mismatch
- UDP
- Events handled by conn_weird
- length() requires a table/set argument
- Predefined Functions
- length() takes exactly one argument
- Predefined Functions
- lex utility
- Pattern Constants
- libpcap buffer size patch
- Tuning BPF
- libpcap library
- Tuning BPF
- libraries
- libpcap
- Tuning BPF
- libpcap
- Tuning BPF
- line editing
- Predefined Functions
- Linux
- compiling Bro under
- The Bro source code
- super exploit
- login variables
- little endian
- Predefined Functions
| The analy Analyzer
- live traffic
- Statements
| Predefined Functions
- load
- shedding
- Predefined Functions
- loadmodule exploit
- login variables
- local addresses
- Site variables
| Site variables
| Site variables
| Site-specific functions
- spoofing
- hot variables
| hot variables
| hot functions
- local statement
- Statements
- local variable declaration
- Scope
- local variables
- Statements
| Scope
- local_16_nets variable
- Site variables
- local_24_nets variable
- Site variables
- local_nets variable
- Site variables
- log file
- Predefined Variables
| Predefined Functions
| The log Module
- altering
- login variables
- connection summary (red)
- Connection functions
- FTP
- ftp variables
- HTTP
- http variables
- weird events
- The weird Module
- log keyword
- Statements
- log module
- The log Module
- log statement
- Statements
- log_file_name function
- Predefined Functions
- log_hook function
- The log Module
| The log Module
| The log Module
- log_hook predefined function
- Predefined Functions
- log_hot_conn function
- Connection functions
- log_if_not_denied
- The ftp_session_info record
- ftp_session_info field
- The ftp_session_info record
- log_if_not_unavail
- The ftp_session_info record
- ftp_session_info field
- The ftp_session_info record
- log_it
- The ftp_session_info record
- ftp_session_info field
- The ftp_session_info record
- LOG_NOTICE syslog level
- Statements
- logging
- connection
- Connection functions
- control of
- Predefined Functions
- logical expression
- Expressions
- logical negation
- Logical Operators
- login analysis
- confusion
- login analyzer confusion
- login analyzer
- The login Analyzer
- login confusion states
- login analyzer confusion
| login analyzer confusion
| login analyzer confusion
| login analyzer confusion
| login analyzer confusion
| login analyzer confusion
| login analyzer confusion
| login analyzer confusion
| login analyzer confusion
| login analyzer confusion
| login analyzer confusion
| login analyzer confusion
- excessive_typeahead
- login analyzer confusion
- extra_repeat_text
- login analyzer confusion
- multiple_login_prompts
- login analyzer confusion
- multiple_USERs
- login analyzer confusion
- no_login_prompt
- login analyzer confusion
- no_username
- login analyzer confusion
- no_username2
- login analyzer confusion
- non_empty_multi_login
- login analyzer confusion
- possible_login_ploy
- login analyzer confusion
- repeat_without_username
- login analyzer confusion
- responder_environment
- login analyzer confusion
- username_with_embedded_repeat
- login analyzer confusion
- login prompts
- missing
- login analyzer confusion
- repeated
- login analyzer confusion
| login analyzer confusion
- login session
- The login Analyzer
- state
- Predefined Functions
| Predefined Functions
- login_confused event
- login event handlers
- login_confused_text event
- login event handlers
- login_failure event
- login event handlers
- login_failure_msgs variable
- Predefined Variables
| login variables
- login_input_line event
- login event handlers
- login_non_failure_msgs variable
- Predefined Variables
| login variables
- login_output_line event
- login event handlers
- login_prompts variable
- Predefined Variables
| login variables
- LOGIN_STATE_AUTHENTICATE state of login connection
- Predefined Functions
- LOGIN_STATE_CONFUSED state of login connection
- Predefined Functions
- LOGIN_STATE_LOGGED_IN state of login connection
- Predefined Functions
- LOGIN_STATE_SKIP state of login connection
- Predefined Functions
- login_success event
- login event handlers
- login_success_msgs variable
- Predefined Variables
| login variables
- login_terminal event
- login event handlers
- login_timeouts variable
- Predefined Variables
| login variables
- ls utility
- login variables
- lynx utility
- login variables
- magic terminal types
- login variables
- management
- of state
- Table Attributes
- mask_addr function
- Predefined Functions
- masking
- Predefined Functions
| Predefined Functions
- max_count function
- Predefined Functions
- max_double function
- Predefined Functions
- max_interval function
- Predefined Functions
- max_request_length variable
- finger variables
- max_timer_expires variable
- Predefined Variables
- maximum
- Predefined Functions
- Maximum Segment Lifetime (MSL)
- Events handled by conn_weird
- maximums
- Predefined Functions
| Predefined Functions
| Predefined Functions
- count
- Predefined Functions
- double
- Predefined Functions
- interval
- Predefined Functions
- membership expression
- Expressions
- memory management
- Table Attributes
- message
- connection id is not a known connection
- Predefined Functions
- not exactly one edit character
- Predefined Functions
- precision specified for non-floating point format
- Predefined Functions
- ridiculous field width or precision
- Predefined Functions
- bad format
- Predefined Functions
- bad type for Date format
- Predefined Functions
- bad type for integer format
- Predefined Functions
- bad type for floating-point format
- Predefined Functions
- wrong number of fmt arguments
- Predefined Functions
- too many arguments for format
- Predefined Functions
- too few arguments for format
- Predefined Functions
- connection id is not a known login connection
- Predefined Functions
- is not a TCP connection
- Predefined Functions
- is not a TCP connection
- Predefined Functions
- length() takes exactly one argument
- Predefined Functions
- length() requires a table/set argument
- Predefined Functions
- bad second argument to mask_addr()
- Predefined Functions
- cannot create directory
- Predefined Functions
- connection id is not a known login connection
- Predefined Functions
- conversion of non-IPv4 address to net
- Predefined Functions
- connection id is not a known connection
- Run-time errors for non-existing
- string without NUL terminator
- Run-time errors for strings
- string with embedded NUL
- Run-time errors for strings
- min (minutes) interval unit
- Temporal Constants
- min_count function
- Predefined Functions
- min_double function
- Predefined Functions
- min_interval function
- Predefined Functions
- minimum
- Predefined Functions
- minimums
- Predefined Functions
| Predefined Functions
| Predefined Functions
- count
- Predefined Functions
- double
- Predefined Functions
- interval
- Predefined Functions
- mismatch (RPC status code)
- portmapper functions
- missing login prompts
- login analyzer confusion
- missing username
- login analyzer confusion
| login analyzer confusion
- mkdir failure
- run-time error
- Predefined Functions
- mkdir function
- Predefined Functions
- modifiability of variables
- Modifiability
- modules
- port-name
- The port-name Module
- mt
- The mt Module
- log
- The log Module
- active
- The active Module
- demux
- The demux Module
- dns
- The dns Module
- frag
- The frag Module
- hot-ids
- The hot-ids Module
- weird
- The weird Module
- dns
- event handlers
- dns event handlers to dns event handlers
- variables
- dns variables to dns variables
- MSL (Maximum Segment Lifetime)
- Events handled by conn_weird
- mt module
- The mt Module
- multi-dimensional table
- Declaring Tables
- multiple login prompts
- login analyzer confusion
| login analyzer confusion
- multiple usernames
- login analyzer confusion
- multiple_HTTP_request_elements (``weird'' event)
- Events handled by conn_weird
- multiple_login_prompts (login confusion state)
- login analyzer confusion
- multiple_RPCs (``weird'' event)
- Events handled by conn_weird
- multiple_USERs (login confusion state)
- login analyzer confusion
- multiplication
- numeric
- Arithmetic Operators
- temporal
- Temporal Multiplication
- name
- of log file
- Predefined Functions
- names
- case-sensitive
- Defining records
- Napster
- tunneled over Telnet or Rlogin
- login event handlers
- negation
- logical
- Logical Operators
- temporal
- Temporal Negation
- negation expression
- Expressions
- neighbor addresses
- Site variables
| Site variables
| Site variables
- neighbor_16_nets variable
- Site variables
- neighbor_24_nets variable
- Site variables
- neighbor_nets variable
- Site variables
- net
- see types, net
- constants
- Net Constants
- operators
- Net Operators
- net type
- Net Type to Net Operators
- net_done event
- General Processing Events
- net_stats record
- General Processing Events
| General Processing Events
- net_stats_update event
- General Processing Events
- net_weird event
- Events handled by net_weird
- network cleanup event
- General Processing Events
- Network File System (NFS)
- portmapper variables
- network interfaces
- Live traffic
| Flags
| Predefined Variables
- network order (vs. host order)
- Predefined Functions
- network prefixes
- Net Type
| Predefined Functions
| Site variables
| Site variables
- network statistics
- General Processing Events
- Network Virtual Terminal (NVT)
- login event handlers
- network_time function
- Predefined Functions
- networks
- hot destinations
- hot variables
- hot sources
- hot variables
- never_shut_down variable
- scan variables
- new connection
- Generic TCP connection events
- new_connection event
- Generic TCP connection events
\n
newline escape
- String Constants
- next keyword
- Statements
- next statement
- Statements
- NFS (Network File System)
- portmapper variables
- NFS traffic
- high volume fragments
- The frag Module
- NFS_services variable
- portmapper variables
- NFS_world_servers variable
- portmapper variables
- no such connection
- run-time error
- Run-time errors for non-existing
- no_login_prompt (login confusion state)
- login analyzer confusion
- no_username (login confusion state)
- login analyzer confusion
- no_username2 (login confusion state)
- login analyzer confusion
- non-blocking DNS lookups
- The Bro source code
- non-existing connection
- fatal run-time error
- Predefined Functions
- non_ASCII_hosts variable
- login variables
- non_backdoor_prompts variable
- login variables
- non_empty_multi_login (login confusion state)
- login analyzer confusion
<none>
username
- login analyzer confusion
- not a login connection
- run-time error
- Predefined Functions
| Predefined Functions
- not a TCP connection
- run-time error
- Predefined Functions
| Predefined Functions
- not exactly one edit character
- Predefined Functions
"!in
negation of in operator
- Embedded Pattern Matching
- ! ``not'' operator
- Logical Operators
- NT
- not supported
- Supported platforms
- NUL
- Predefined Functions
- NUL_in_line (``weird'' event)
- Events handled by conn_weird
- NULL portmapper call
- The portmapper Analyzer
- null statement
- Statements
- NULs
- Events handled by conn_weird
- allowed in strings
- String Constants
| Run-time errors for non-existing
- disallowed in certain function calls
- Run-time errors for non-existing
- terminating string constants
- String Constants
- termination
- Run-time errors for non-existing
- terminator missing
- run-time error
- Run-time errors for strings
- num_in_order statistic
- The analy Analyzer
- num_OO statistic
- The analy Analyzer
- num_pkts statistic
- The analy Analyzer
- num_repl statistic
- The analy Analyzer
- num_requests
- The ftp_session_info record
- ftp_session_info field
- The ftp_session_info record
- num_rxmit statistic
- The analy Analyzer
- num_rxmit_bytes statistic
- The analy Analyzer
- number of elements
- in table or set
- Predefined Functions
- numeric types
- count
- Bro Types
- int
- Bro Types
- double
- Bro Types
- nuucp username
- The hot-ids Module
| ident variables
- NVT (Network Virtual Terminal)
- login event handlers
- NVT options
- authentication
- login event handlers
| login event handlers
- bad
- login event handlers
- bad termination
- login event handlers
- encryption
- login event handlers
- inconsistent
- login event handlers
- -O flag
- Flags
\
octal-digits octal escape
- String Constants
- off-line analysis
- Traffic traces
| Flags
| Predefined Functions
| Connection functions
- ok (RPC status code)
- portmapper functions
- on-line analysis
- Live traffic
| Flags
| Predefined Variables
| Predefined Functions
| Connection functions
- open function
- Files
| Predefined Functions
- open_for_append function
- Files
| Predefined Functions
- open_log_file function
- Predefined Functions
- opening a file
- Predefined Functions
| Predefined Functions
- operator
&&
``and''
- Logical Operators
| Expressions
(
parenthesis
- Expressions
| Expressions
- ! ``not''
- Logical Operators
"|"|
``or''
- Logical Operators
| Expressions
)
parenthesis
- Expressions
| Expressions
- operators
- +=
- Filtering
- +
- Arithmetic Operators
- -
- Arithmetic Operators
- *
- Arithmetic Operators
- /
- Arithmetic Operators
- +
- Arithmetic Operators
- -
- Arithmetic Operators
- -
- Temporal Negation
- +
- Temporal Addition
- -
- Temporal Subtraction
- *
- Temporal Multiplication
- /
- Temporal Division
- $
- Accessing Fields Using ``$''
- ++
- Expressions
- -
- Expressions
- !
- Expressions
- -
- Expressions
- +
- Expressions
- +
- Expressions
- -
- Expressions
- *
- Expressions
- /
- Expressions
- ?
- Expressions
- :
- Expressions
- =
- Expressions
- (
- Expressions
- )
- Expressions
- [
- Expressions
- ]
- Expressions
- in
- Expressions
- !in
- Expressions
- in
- Expressions
- !in
- Expressions
- [
- Expressions
- ]
- Expressions
- address
- Address Operators
- arithmetic
- Arithmetic Operators to Arithmetic Operators
- associativity
- Arithmetic Operators
- operand conversion
- Arithmetic Operators
- precedence
- Arithmetic Operators
- comparison
- Comparison Operators to Comparison Operators
- associativity
- Comparison Operators
- operand conversion
- Comparison Operators
- precedence
- Comparison Operators
- logical
- Logical Operators to Logical Operators
- associativity
- Logical Operators
- precedence
- Logical Operators
- net
- Net Operators
- pattern
- Pattern Operators
- ports
- Port Operators
- string
- String Operators
- temporal
- Temporal Operators
- optimizer for policy script interpreter
- Flags
- optimizing your system for Bro
- Tuning BPF
- options
- Telnet
- The login Analyzer
"|"|
``or'' operator
- Logical Operators
| Expressions
- orig
- The connection record
- orig_h
- The connection record
- conn_id field
- The connection record
- orig_p
- The connection record
- conn_id field
- The connection record
- originator_RPC_reply (``weird'' event)
- Events handled by conn_weird
- OTH connection state
- Connection summaries
- out-of-order delivery
- The analy Analyzer
- OutOfBox username
- The hot-ids Module
- output_trouble variable
- login variables
- -P flag
- Flags
| Flags
| The dns Module
- packet filter
- access
- Tuning BPF
- permissions
- Tuning BPF
- packets
- control (SYN/FIN/RST)
- Flags
| The tcp analyzer
- corrupted
- Events handled by conn_weird
| Events handled by net_weird
- drops
- General Processing Events
| Additional handlers for ``weird''
- recording
- Predefined Functions
- replication
- The analy Analyzer
- storms
- Events handled by conn_weird
- time
- Predefined Functions
()
- Expressions
| Expressions
- parenthesized expression
- Expressions
- parse_ftp_pasv function
- Predefined Functions
- parse_ftp_port function
- Predefined Functions
- partial connections
- Generic TCP connection events
- PARTIAL_CLOSE_INTERVAL internal variable
- Generic TCP connection events
- partial_connection event
- Generic TCP connection events
| login event handlers
- partial_finger_request (``weird'' event)
- Events handled by conn_weird
- partial_ftp_request (``weird'' event)
- Events handled by conn_weird
- partial_ident_request (``weird'' event)
- Events handled by conn_weird
- partial_portmapper_request (``weird'' event)
- Events handled by conn_weird
- partial_RPC (``weird'' event)
- Events handled by conn_weird
- partially closed connections
- Generic TCP connection events
- passwd
- http variables
- passwords
- guessing
- The scan Analyzer
- inadvertently exposed
- The login Analyzer
- sniffing
- The login Analyzer
- PATH_UTMP sensitive pattern
- login variables
- pattern
- see types, pattern
- pattern matching
- Patterns
- embedded
- Embedded Pattern Matching
- exact
- Exact Pattern Matching
- pattern matching expression
- Expressions
- patterns
- Patterns to Embedded Pattern Matching
- pending connections
- Generic TCP connection events
- pending_data_when_closed (``weird'' event)
- Events handled by conn_weird
- performance
- analysis tradeoffs
- Activating an Analyzer
- filtering
- Filtering
- pm_activity function
- portmapper functions
- pm_attempt function
- portmapper functions
- pm_attempt portmapper attempt
- portmapper event handlers
- pm_attempt_callit event
- portmapper event handlers
- pm_attempt_dump event
- portmapper event handlers
- pm_attempt_getport event
- portmapper event handlers
- pm_attempt_null event
- portmapper event handlers
- pm_attempt_set event
- portmapper event handlers
- pm_attempt_unset event
- portmapper event handlers
- pm_bad_port event
- portmapper event handlers
- pm_callit_request portmapper call
- portmapper event handlers
- pm_check_getport function
- portmapper functions
- pm_mapping portmapper mapping record
- portmapper event handlers
- pm_port_request portmapper request
- portmapper event handlers
- pm_request function
- portmapper functions
- pm_request_callit event
- portmapper event handlers
- pm_request_dump event
- portmapper event handlers
- pm_request_getport event
- portmapper event handlers
- pm_request_null event
- portmapper event handlers
- pm_request_set event
- portmapper event handlers
- pm_request_unset event
- portmapper event handlers
- policy/ policy directory
- Run-time environment
- policy directories
- Run-time environment
- policy script interpreter
- optimizer
- Flags
- policy/local/ policy directory
- Run-time environment
- polymorphic functions
- need for
- Predefined Functions
| Predefined Functions
| Events handled by conn_weird_addl
- popular backdoors
- hot variables
- ingreslock
- hot variables
- port
- see types, port
- ephemeral
- Connection functions
- port scanning
- The scan Analyzer
- port type
- Port Type to Port Operators
- port-name module
- The port-name Module
- port_names variable
- The connection record
| Connection functions
| The port-name Module
- portmapper analyzer
- The portmapper Analyzer
- portmapper attempts
- portmapper event handlers
- pm_attempt
- portmapper event handlers
- portmapper calls
- portmapper event handlers
- CALLIT
- The portmapper Analyzer
- DUMP
- The portmapper Analyzer
- GETPORT
- The portmapper Analyzer
- NULL
- The portmapper Analyzer
- pm_callit_request
- portmapper event handlers
- SET
- The portmapper Analyzer
- UNSET
- The portmapper Analyzer
- portmapper mapping records
- portmapper event handlers
- pm_mapping
- portmapper event handlers
- portmapper requests
- portmapper event handlers
- pm_port_request
- portmapper event handlers
- ports
- constants
- Port Constants
- operators
- Port Operators
- TCP
- Port Type
- TCP vs. UDP
- Predefined Functions
- UDP
- Port Type
- positivation expression
- Expressions
- possible future changes
- timer type
- Expressions
- breaking string constants across multiple lines
- String Constants
- constants for absolute times
- Temporal Constants
- use of any type for bypassing strong typing
- The any type
- possible packet drop messages
- Additional handlers for ``weird''
- ack above a hole
- Additional handlers for ``weird''
- possible_login_ploy (login confusion state)
- login analyzer confusion
- possible_port_scan_thresh variable
- scan variables
- possible_split_routing (``weird'' event)
- Events handled by conn_weird
- POST HTTP method
- http variables
- precision
- of formatted strings
- Predefined Functions
- precision specified for non-floating point format
- Predefined Functions
- predefined functions
- Predefined Functions to Functions for manipulating time
- active_connection
- Predefined Functions
- active_file
- Predefined Functions
- add_interface
- Predefined Functions
- add_tcpdump_filter
- Predefined Functions
- log_hook
- Predefined Functions
- byte_len
- Predefined Functions
- cat
- Predefined Functions
- clean
- Predefined Functions
- close
- Predefined Functions
- connection_record
- Predefined Functions
- contains_string
- Predefined Functions
- current_time
- Predefined Functions
- discarder_check_icmp
- Predefined Functions
- discarder_check_ip
- Predefined Functions
- discarder_check_tcp
- Predefined Functions
- discarder_check_udp
- Predefined Functions
- edit
- Predefined Functions
- exit
- Predefined Functions
- flush_all
- Predefined Functions
- fmt
- Predefined Functions
- get_login_state
- Predefined Functions
- get_orig_seq
- Predefined Functions
- get_resp_seq
- Predefined Functions
- getenv
- Predefined Functions
- is_tcp_port
- Predefined Functions
- length
- Predefined Functions
- log_file_name
- Predefined Functions
- mask_addr
- Predefined Functions
- max_count
- Predefined Functions
- max_double
- Predefined Functions
- max_interval
- Predefined Functions
- min_count
- Predefined Functions
- min_double
- Predefined Functions
- min_interval
- Predefined Functions
- mkdir
- Predefined Functions
- network_time
- Predefined Functions
- open
- Predefined Functions
- open_for_append
- Predefined Functions
- open_log_file
- Predefined Functions
- parse_ftp_pasv
- Predefined Functions
- parse_ftp_port
- Predefined Functions
- reading_live_traffic
- Predefined Functions
- set_buf
- Predefined Functions
- set_contents_file
- Predefined Functions
- set_login_state
- Predefined Functions
- set_record_packets
- Predefined Functions
- skip_further_processing
- Predefined Functions
- sub_bytes
- Predefined Functions
- system
- Predefined Functions
- to_lower
- Predefined Functions
- to_net
- Predefined Functions
- to_upper
- Predefined Functions
- predefined variables
- Predefined Variables to Predefined Variables
- bro_log_file
- Predefined Variables
- capture_filter
- Predefined Variables
- direct_login_prompts
- Predefined Variables
- discarder_maxlen
- Predefined Variables
- done_with_network
- Predefined Variables
- interfaces
- Predefined Variables
- login_failure_msgs
- Predefined Variables
- login_non_failure_msgs
- Predefined Variables
- login_prompts
- Predefined Variables
- login_success_msgs
- Predefined Variables
- login_timeouts
- Predefined Variables
- max_timer_expires
- Predefined Variables
- restrict_filter
- Predefined Variables
- skip_authentication
- Predefined Variables
- prefixes
- Flags
| Run-time environment
- network
- Net Type
| Predefined Functions
| Site variables
| Site variables
- premature_connection_reuse (``weird'' event)
- Events handled by conn_weird
- priming Bro's private caches (DNS, regular expression)
- Flags
- print keyword
- Statements
- print statement
- Statements
- print-filter analyzer
- Filtering
| Filtering
| Filtering
- printf
- Predefined Functions
- processing
- avoiding
- Predefined Functions
- prog unavail (RPC status code)
- portmapper functions
- programs
- hf
- no title
- cf
- no title
- -r flag
- Flags
- reactive firewall
- scan variables
| scan functions
- &read_expire attribute
- Table Attributes
- reading tcpdump files
- Flags
- reading_live_traffic function
- Predefined Functions
- record
- see types, record
- ftp_port
- Predefined Functions
- ftp_port
- Predefined Functions
- connection
- The connection record
- record constructor expression
- Expressions
- record field access expression
- Expressions
- record field test expression
- Expressions
- record_connection function
- Connection functions
- recorded traffic
- Predefined Functions
- recording connections
- Connection functions
- recording packets
- Predefined Functions
- records
- Records to Record Assignment
| Predefined Functions
| Predefined Functions
| General Processing Events
| General Processing Events
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| The connection record
| Connection summaries
| no title
| The dns_mapping record
| The dns_mapping record
| no title
| The ftp_session_info record
| login functions
- assignment
- Record Assignment to Record Assignment
- check_info
- login functions
- conn_id
- The connection record
| The connection record
| The connection record
- connection
- The connection record
| The connection record
| The connection record
| The connection record
| The connection record
- dns_mapping
- no title
| The dns_mapping record
| The dns_mapping record
- endpoint
- The connection record
| The connection record
| The connection record
| Connection summaries
- field attributes
- Record Assignment
- fields
- Records
- accessing
- Accessing Fields Using ``$''
- legal names
- Defining records
- ftp_port
- Predefined Functions
| Predefined Functions
- ftp_session_info
- no title
| The ftp_session_info record
- net_stats
- General Processing Events
| General Processing Events
- red connection summary file
- Connection summaries
| Connection summaries
- &redef attribute
- Refinement
- redefining functions
- Functions
- redefining variables
- Refinement
- refinement
- Refinement
- regular expressions
- Bro's private cache
- Flags
- compiling
- Flags
- REJ connection state
- Connection summaries
- rejected connections
- Generic TCP connection events
- relational expression
- Expressions
- relationals
- address
- Address Type
- net
- Net Operators
- numeric
- Comparison Operators
- string
- String Operators
- temporal
- Temporal Relationals
- relative time
- Temporal Types
- remote procedure call (RPC)
- The portmapper Analyzer
- repeat text
- login analyzer confusion
| login analyzer confusion
- repeat text (VMS)
- login analyzer confusion
- repeat_without_username (login confusion state)
- login analyzer confusion
- repeated_SYN_reply_wo_ack (``weird'' event)
- Events handled by conn_weird
- repeated_SYN_with_ack (``weird'' event)
- Events handled by conn_weird
- replication of packets
- The analy Analyzer
- report_accounts_tried variable
- scan variables
- report_outbound_peer_scan variable
- scan variables
- report_peer_scan variable
- scan variables
- report_remote_accounts_tried variable
- scan variables
- report_weird function
- weird functions
- report_weird_conn function
- weird functions
- report_weird_orig function
- weird functions
- req_addr
- The dns_mapping record
- dns_mapping field
- The dns_mapping record
- req_host
- The dns_mapping record
- dns_mapping field
- The dns_mapping record
- request
- The ftp_session_info record
- ftp_session_info field
- The ftp_session_info record
- request_t
- The ftp_session_info record
- ftp_session_info field
- The ftp_session_info record
- reserved multicast addresss
- portmapper variables
- sun-rpc.mcast.net
- portmapper variables
- reset connections
- Generic TCP connection events
- resp
- The connection record
- resp_h
- The connection record
- conn_id field
- The connection record
- resp_p
- The connection record
- conn_id field
- The connection record
- responder_environment (login confusion state)
- login analyzer confusion
- responder_RPC_call (``weird'' event)
- Events handled by conn_weird
- restrict_filter global variable
- Flags
- restrict_filter variable
- Predefined Variables
| Filtering to Filtering
- restricting traffic
- Filtering
- retransmission
- inconsistent
- Events handled by conn_weird
| Additional handlers for ``weird''
- return keyword
- Statements
- return statement
- Statements
- rewt username
- The hot-ids Module
| login variables
- rexmit_inconsistency event
- Additional handlers for ``weird''
- .rhosts
- ftp variables
| The login Analyzer
| login analyzer confusion
| login variables
| login event handlers
- ridiculous field width or precision
- Predefined Functions
)
operator
- Expressions
| Expressions
- RLIMIT_NOFILE a
- Files
- Rlogin
- session state
- Predefined Functions
| Predefined Functions
- sessions
- The login Analyzer
- weird events
- Events handled by conn_weird
- rlogin_id_okay_if_no_password_exposed variable
- login variables
- rlogin_text_after_rejected (``weird'' event)
- Events handled by conn_weird
- root
- backdoors
- login variables
- Bro not running as
- Tuning BPF
- setuid
- login variables
- router_prompts variable
- login variables
- routing
- split
- Events handled by conn_weird
- RPC (Remote Procedure Call)
- The portmapper Analyzer
- reserved multicast address
- portmapper variables
- weird events
- Events handled by conn_weird
- RPC status codes
- portmapper functions
| portmapper functions
| portmapper functions
| portmapper functions
| portmapper functions
| portmapper functions
| portmapper functions
| portmapper functions
- auth error
- portmapper functions
- garbage args
- portmapper functions
- mismatch
- portmapper functions
- ok
- portmapper functions
- prog unavail
- portmapper functions
- system err
- portmapper functions
- timeout
- portmapper functions
- unknown
- portmapper functions
- RPC_dump_okay variable
- portmapper variables
- RPC_okay variable
- portmapper variables
- RPC_okay_nets variable
- portmapper variables
- RPC_okay_services variable
- portmapper variables
- rpc_prog function
- portmapper functions
- rpc_programs variable
- portmapper variables
- RPC_rexmit_inconsistency (``weird'' event)
- Events handled by conn_weird
- RST control packet
- Flags
| The tcp analyzer
- RST termination
- causing undetermined connection size
- ftp variables
- RST_storm (``weird'' event)
- Events handled by conn_weird
- RST_with_data (``weird'' event)
- Events handled by conn_weird
- RSTO connection state
- Connection summaries
- RSTOS0 connection state
- Connection summaries
- RSTR connection state
- Connection summaries
- RSTRH connection state
- Connection summaries
- run-time error
- bad address mask
- Predefined Functions
- bad fmt date argument
- Predefined Functions
- bad fmt editing character
- Predefined Functions
- bad fmt field width
- Predefined Functions
- bad fmt floating-point argument
- Predefined Functions
- bad fmt format specifier
- Predefined Functions
- bad fmt integer argument
- Predefined Functions
- bad fmt precision
- Predefined Functions
- bad length argument (not a table or set)
- Predefined Functions
- can't open
- Run-time environment
- converting an IPv6 address to net
- Predefined Functions
- embedded NUL
- Run-time errors for strings
- mkdir failure
- Predefined Functions
- no such connection
- Run-time errors for non-existing
- non-existing connection
- Predefined Functions
- not a login connection
- Predefined Functions
| Predefined Functions
- not a TCP connection
- Predefined Functions
| Predefined Functions
- NULs
- terminator missing
- Run-time errors for strings
- watchdog timer expired
- Flags
- wrong number of fmt arguments
- Predefined Functions
- wrong number of length arguments
- Predefined Functions
- running Bro
- Running Bro
- running outside scripts or executables
- Predefined Functions
- S0 connection state
- Connection summaries
- S1 connection state
- Connection summaries
- S2 connection state
- Connection summaries
- S3 connection state
- Connection summaries
- same_local_net_is_spoof variable
- hot variables
- save file
- control over what's recorded
- Predefined Functions
- reading
- Flags
- writing
- Flags
- scalars
- Declaring Tables
- scan analyzer
- The scan Analyzer
- scan detection
- The scan Analyzer to scan event handlers
- scanning
- address
- The scan Analyzer
- port
- The scan Analyzer
- shutting down
- scan variables
| scan functions
- stealth
- Generic TCP connection events
| hot functions
| scan functions
| Events handled by conn_weird
| Events handled by conn_weird
- schedule keyword
- Expressions
- scheduling events
- Expressions
- scoping of variables
- Scope
- script kiddies
- hot variables
- scripting
- general
- Predefined Functions
- scripts
- running
- Predefined Functions
- standard
- Analyzers and Events to The interconn Analyzer
- search path
- Run-time environment
- searching for strings
- Patterns
- sec (seconds) interval unit
- Temporal Constants
- semi-colon statement termination
- Statements
- sensitive /24 destination networks
- hot variables
- sensitive /24 source networks
- hot variables
- sensitive destination addresses
- hot variables
- sensitive filenames
- ftp variables
| login variables
- eggdrop
- ftp variables
- sensitive information
- inadvertently exposed
- The login Analyzer
- sensitive login inputs
- login variables
- eggdrop
- login variables
- sensitive patterns
- login variables
- PATH_UTMP
- login variables
- sensitive POST URIs
- http variables
- wwwroot
- http variables
- sensitive services
- confused with ephemeral ports
- hot variables
- sensitive source addresses
- hot variables
- sensitive usernames
- The hot-ids Module
- sensitive_post_URIs variable
- http variables
- sensitive_URIs variable
- http variables
- sensitivity associated with a connection
- The connection record
- sequence numbers
- connection originator
- Predefined Functions
- connection responder
- Predefined Functions
- service
- The connection record
- connection field
- The connection record
- service associated with a connection
- The connection record
| Connection summaries
| Connection functions
| Connection functions
- service_name function
- Connection functions
- services
- allowable
- hot variables
- allowed to a particular host
- hot variables
- allowed to particular host pairs
- hot variables
- fatal if inbound
- hot variables
- forbidden
- hot variables
- forbidden if attempted
- hot variables
- forbidden if inbound
- hot variables
- set
- see types, set
- SET portmapper call
- The portmapper Analyzer
- set size
- Predefined Functions
- set type
- Sets to Sets
- set_buf function
- Predefined Functions
- set_contents_file function
- Predefined Functions
- set_login_state function
- Predefined Functions
- set_record_packets function
- Predefined Functions
- setrlimit system calls
- Files
- setuid root
- login variables
- SF connection state
- Connection summaries
- sgiweb username
- The hot-ids Module
- sh
- Predefined Functions
- SH connection state
- Connection summaries
- shadow
- http variables
- shadowing
- Filtering
- shallow copy
- Record Assignment
| Table Assignment
- shedding load
- Predefined Functions
- shell escape
- Predefined Functions
- shell scripts
- drop-connectivity
- scan functions
- short-circuit
&&
``and'' operator
- Logical Operators
| Expressions
- short-circuit
"|"|
``or'' operator
- Logical Operators
| Expressions
- SHR connection state
- Connection summaries
- shut_down_all_scans variable
- scan variables
- shut_down_scans variable
- scan variables
- shut_down_thresh variable
- scan variables
- shutting down scans
- scan variables
| scan functions
- SIGHUP
- General Processing Events
- SIGINT
- General Processing Events
- signal handling
- General Processing Events
- SIGTERM
- General Processing Events
- simultaneous open
- Events handled by conn_weird
- simultaneous_open (``weird'' event)
- Events handled by conn_weird
- site addresses
- Site-specific functions
- site analyzer
- Site-specific information
- site-specific
- functions
- Site-specific functions to Site-specific functions
- information
- Site-specific information
- variables
- Site variables to Site variables
- size
- The connection record
- endpoint field
- The connection record
- of table or set
- Predefined Functions
- size of connection
- Connection summaries
| Connection functions
- skip_accounts_tried variable
- scan variables
- skip_authentication variable
- Predefined Variables
| login variables
- skip_further_processing function
- Predefined Functions
- skip_logins_to variable
- login variables
- skip_outbound_services variable
- scan variables
- skip_scan_nets_24 variable
- scan variables
- skip_scan_sources variable
- scan variables
- skip_unexpected variable
- ftp variables
- skip_unexpected_net variable
- ftp variables
- (skipped) authentication annotation
- login event handlers
- slow startup due to compiling regular expressions
- Flags
- smashdu.c exploit tool
- login variables
- smurf attacks
- login variables
- sniffer logs
- login variables
- sniffing
- The login Analyzer
- source code
- for Bro
- The Bro source code
- split routing
- Events handled by conn_weird
- spontaneous_FIN (``weird'' event)
- Events handled by conn_weird
- spontaneous_RST (``weird'' event)
- Events handled by conn_weird
- spoofing
- allowable services
- hot variables
- detection
- hot variables
| hot functions
- spook detection
- hot variables
- sprintf
- Predefined Functions
- standard scripts
- Analyzers and Events to The interconn Analyzer
- start time of a connection
- The connection record
| Connection summaries
- start_time
- The connection record
- connection field
- The connection record
- startup
- event
- General Processing Events
- transients
- Events handled by conn_weird
- startup slow due to compiling regular expressions
- Flags
- state
- The connection record
- endpoint field
- The connection record
- of a Telnet/Rlogin session
- Predefined Functions
| Predefined Functions
- state management
- Table Attributes
- state of connection
- Connection summaries
| Connection functions
- state of login connections
- Predefined Functions
| Predefined Functions
| Predefined Functions
| Predefined Functions
- LOGIN_STATE_AUTHENTICATE
- Predefined Functions
- LOGIN_STATE_CONFUSED
- Predefined Functions
- LOGIN_STATE_LOGGED_IN
- Predefined Functions
- LOGIN_STATE_SKIP
- Predefined Functions
- statements
- Statements to Statements
- expression
- Statements
- print
- Statements
- log
- Statements
- event
- Statements
- if
- Statements
- for
- Statements
- next
- Statements
- break
- Statements
- return
- Statements
- add
- Statements
- delete
- Statements
- compound
- Statements
- null
- Statements
- local
- Statements
- const
- Statements
- multi-line
- Statements
- semi-colon termination
- Statements
- static typing
- Bro Types
- statistical analysis
- The analy Analyzer
- statistics
- The analy Analyzer
| The analy Analyzer
| The analy Analyzer
| The analy Analyzer
| The analy Analyzer
| The analy Analyzer
| The analy Analyzer
- endian_type
- The analy Analyzer
- num_in_order
- The analy Analyzer
- num_OO
- The analy Analyzer
- num_pkts
- The analy Analyzer
- num_repl
- The analy Analyzer
- num_rxmit
- The analy Analyzer
- num_rxmit_bytes
- The analy Analyzer
- stderr
- Predefined Variables
| Predefined Functions
| The log Module
- stdout
- Statements
| Predefined Functions
- stealth scans
- Generic TCP connection events
| hot functions
| scan functions
| Events handled by conn_weird
| Events handled by conn_weird
- storms
- Events handled by conn_weird
- strftime
- Predefined Functions
- string
- see types, string
- extraction
- Predefined Functions
- formatting
- Predefined Functions
- string constants
- NUL terminated
- String Constants
- string with embedded NUL
- Run-time errors for strings
- string without NUL terminator
- Run-time errors for strings
"<string-with-NUL>"
error value
- Run-time errors for strings
- strings
- Strings to String Operators
- cleaned up
- Predefined Functions
- concatenation
- Predefined Functions
- length
- Predefined Functions
- termination with NULs
- Run-time errors for non-existing
- strlen
- Predefined Functions
- strstr
- Predefined Functions
- sub-tables
- lack of
- Accessing Tables
- sub_bytes function
- Predefined Functions
- subnets
- Net Type
| Predefined Functions
| Predefined Functions
| Site variables
| Site variables
- substrings
- Predefined Functions
- subtraction
- numeric
- Arithmetic Operators
- temporal
- Temporal Subtraction
- sun-rpc.mcast.net reserved multicast address
- portmapper variables
- suppress_pm_log variable
- portmapper variables
- SYN control packet
- Flags
| The tcp analyzer
- SYN_after_close (``weird'' event)
- Events handled by conn_weird
- SYN_after_partial (``weird'' event)
- Events handled by conn_weird
- SYN_after_reset (``weird'' event)
- Events handled by conn_weird
- SYN_inside_connection (``weird'' event)
- Events handled by conn_weird
- SYN_seq_jump (``weird'' event)
- Events handled by conn_weird
- SYN_with_data (``weird'' event)
- Events handled by conn_weird
- syslog
- Statements
- syslog levels
- Statements
- LOG_NOTICE
- Statements
- system callss
- Files
- setrlimit
- Files
- system configuration
- Tuning BPF
- system err (RPC status code)
- portmapper functions
- system function
- Predefined Functions
- T/TCP
- Events handled by conn_weird
\t
tab escape
- String Constants
- table
- see types, table
- table size
- Predefined Functions
- tables
- Tables to Deleting Table Elements
- clearing entries
- Table Assignment
- TCP
- analysis
- The tcp analyzer
- checksum error
- Events handled by conn_weird
- Christmas packet
- Events handled by conn_weird
- connections
- Definitions of connections
- corrupted header
- Events handled by net_weird
- events
- Generic TCP connection events
- fragments
- The frag Module
- transaction
- Events handled by conn_weird
- weird events
- Events handled by conn_weird
- tcp analyzer
- no title
- TCP control packets (SYN/FIN/RST)
- Flags
| The tcp analyzer
- TCP vs. UDP ports
- Predefined Functions
- TCP Wrappers
- reset vs. rejected connections
- Generic TCP connection events
- TCP-specific connection events
- Generic TCP connection events
- TCP_christmas (``weird'' event)
- Events handled by conn_weird
- tcpdump
- Tuning BPF
| Running Bro on network
| Flags
| Flags
| Flags
| Flags
| Filtering
| Filtering
| Filtering
- bugs
- Filtering
- filters
- Flags
| Filtering
- merging save files
- Flags
- reading save files
- Running Bro on network
| Flags
- running concurrently with Bro
- Tuning BPF
- shadow
- Filtering
- turning off optimization
- Filtering
- writing save files
- Flags
- Telnet
- options
- The login Analyzer
- authentication
- login event handlers
| login event handlers
- bad
- login event handlers
- bad termination
- login event handlers
- encryption
- login event handlers
- environment
- login analyzer confusion
- inconsistent
- login event handlers
- session state
- Predefined Functions
| Predefined Functions
- sessions
- The login Analyzer
- temporal
- addition
- Temporal Addition
- constants
- Temporal Constants
- division
- Temporal Division
- multiplication
- Temporal Multiplication
- negation
- Temporal Negation
- relationals
- Temporal Relationals
- subtraction
- Temporal Subtraction
- types
- Temporal Types
- TERM signal
- General Processing Events
- terminal type backdoors
- login variables
- VT666
- login variables
- terminate_connection function
- Connection functions
- terminate_successful_inbound_service variable
- hot variables
- terminating connections forcibly
- Connection functions
- termination event
- General Processing Events
| General Processing Events
- text
- formatting
- Predefined Functions
- TFreak
- login variables
- time
- see types, time
| Temporal Types to Temporal Relationals
- clock
- Predefined Functions
| Predefined Functions
- packet
- Predefined Functions
- timeout (RPC status code)
- portmapper functions
- timer expiration
- Expressions
| Predefined Variables
- timers
- Expressions
- timestamps
- mapping to readable form
- The cf utility
- to_lower function
- Predefined Functions
- to_net function
- Predefined Functions
- to_upper function
- Predefined Functions
- tolower
- Predefined Functions
- too few arguments for format
- Predefined Functions
- too many arguments for format
- Predefined Functions
- toupper
- Predefined Functions
- trace file
- control over what's recorded
- Predefined Functions
- reading
- Flags
- writing
- Flags
- traffic
- live vs. recorded
- Statements
| Predefined Functions
- restricting
- Filtering
- transaction TCP
- Events handled by conn_weird
- transients
- startup
- Events handled by conn_weird
- trojaning
- login variables
- truncated headers
- Events handled by net_weird
- truncated_header (``weird'' event)
- Events handled by net_weird
- truncated_IP (``weird'' event)
- Events handled by net_weird
- tunneling
- login event handlers
- type casting
- not provided in Bro
- The any type
- type inference
- Typing
- type-ahead
- maximum allowed
- login analyzer confusion
- types
- bool
- Bro Types
- numeric
- Bro Types
- count
- Bro Types
- int
- Bro Types
- double
- Bro Types
- enumeration
- Bro Types
- enum
- Bro Types
- string
- Bro Types
- pattern
- Bro Types
- temporal
- Bro Types
- time
- Bro Types
- interval
- Bro Types
- port
- Bro Types
- addr
- Bro Types
- net
- Bro Types
- record
- Bro Types
- table
- Bro Types
- set
- Bro Types
- file
- Bro Types
- function
- Bro Types
- event
- Bro Types
- bool
- Logical Operators
- count
- Numeric Types
- int
- Numeric Types
- double
- Numeric Types
- numeric
- Numeric Types
- numeric
- to Comparison Operators
- enum
- Enumerations
- string
- Strings
- pattern
- Patterns
- time
- Temporal Types
- interval
- Temporal Types
- conversion
- Type Conversions to Type Conversions
- automatic
- Type Conversions
- numeric
- bool not numeric
- Mixing Numeric Types
- intermixing
- Mixing Numeric Types
- overview
- Bro Types
- types, need fors
- The connection record
- union
- The connection record
- typing
- static
- Bro Types
- typing of variables
- Typing
- UDP
- analysis
- The udp analyzer
- checksum error
- Events handled by conn_weird
- ``connections''
- Definitions of connections
- fragments
- The frag Module
- length mismatch
- Events handled by conn_weird
- timeout
- Definitions of connections
- weird events
- Events handled by conn_weird
- udp analyzer
- no title
- UDP_datagram_length_mismatch (``weird'' event)
- Events handled by conn_weird
- udp_reply event
- The udp analyzer
- udp_request event
- The udp analyzer
- unanalyzed data
- Events handled by conn_weird
- undirectional analysis
- Events handled by conn_weird
- union type
- need for
- Predefined Functions
- union types, need for
- The connection record
- Unix analysis
- The login Analyzer
- Unix support
- Supported platforms
- Unix timestamps
- The cf utility
- unknown (RPC status code)
- portmapper functions
- unpaired_RPC_response (``weird'' event)
- Events handled by conn_weird
- UNSET portmapper call
- The portmapper Analyzer
- unsolicited_SYN_response (``weird'' event)
- Events handled by conn_weird
- unusual events
- The weird Module to Additional handlers for ``weird''
- prevalence in actual network traffic
- The weird Module
- usage message
- Flags
- usec (microseconds) interval unit
- Temporal Constants
- user
- The ftp_session_info record
- ftp_session_info field
- The ftp_session_info record
- $USER environment variable
- login analyzer confusion
- user keystrokes
- analysis
- The login Analyzer
- editing
- login variables
- \tt Username: (VMS login prompt)
- login analyzer confusion
- username_with_embedded_repeat (login confusion state)
- login analyzer confusion
- usernames
- The hot-ids Module
| The hot-ids Module
| The hot-ids Module
| The hot-ids Module
| The hot-ids Module
| The hot-ids Module
| The hot-ids Module
| The hot-ids Module
| ident variables
| ident variables
| ident variables
| login variables
- 4Dgifts
- The hot-ids Module
- daemon
- The hot-ids Module
| ident variables
- extracting
- The login Analyzer
| login analyzer confusion
- EZsetup
- The hot-ids Module
- missing
- login analyzer confusion
| login analyzer confusion
<none>
- login analyzer confusion
- nuucp
- The hot-ids Module
| ident variables
- OutOfBox
- The hot-ids Module
- repeated
- login analyzer confusion
- rewt
- The hot-ids Module
| login variables
- sensitive
- The hot-ids Module
- sgiweb
- The hot-ids Module
- uucp
- The hot-ids Module
| ident variables
- /usr/local/lib/bro/ policy directory
- Run-time environment
- utilities
- fetch
- login variables
- flex
- Pattern Constants
- lex
- Pattern Constants
- ls
- login variables
- lynx
- login variables
- utility programs
- hf
- no title
- cf
- no title
- uucp username
- The hot-ids Module
| ident variables
- -v flag
- Flags
- valid
- The dns_mapping record
- dns_mapping field
- The dns_mapping record
- values
- overview
- Overview
- vantage point
- Events handled by conn_weird
- variable declarations
- Scope
| Scope
| Modifiability
- const
- Modifiability
- global
- Scope
- local
- Scope
- variable expression
- Expressions
- variables
- bro_log_file
- Predefined Variables
- capture_filter
- Predefined Variables
- direct_login_prompts
- Predefined Variables
- discarder_maxlen
- Predefined Variables
- done_with_network
- Predefined Variables
- interfaces
- Predefined Variables
- login_failure_msgs
- Predefined Variables
- login_non_failure_msgs
- Predefined Variables
- login_prompts
- Predefined Variables
- login_success_msgs
- Predefined Variables
- login_timeouts
- Predefined Variables
- max_timer_expires
- Predefined Variables
- restrict_filter
- Predefined Variables
- skip_authentication
- Predefined Variables
- capture_filter
- Filtering
- restrict_filter
- Filtering
- restrict_filter
- to Filtering
- capture_filter
- to Filtering
- port_names
- The connection record
- port_names
- Connection functions
- local_nets
- Site variables
- local_16_nets
- Site variables
- local_24_nets
- Site variables
- neighbor_nets
- Site variables
- neighbor_16_nets
- Site variables
- neighbor_24_nets
- Site variables
- same_local_net_is_spoof
- hot variables
- allow_spoof_services
- hot variables
- allow_pairs
- hot variables
- allow_16_net_pairs
- hot variables
- hot_srcs
- hot variables
- hot_dsts
- hot variables
- hot_src_24nets
- hot variables
- hot_dst_24nets
- hot variables
- allow_services
- hot variables
- allow_services_to
- hot variables
- allow_services_pairs
- hot variables
- flag_successful_service
- hot variables
- flag_successful_inbound_service
- hot variables
- terminate_successful_inbound_service
- hot variables
- flag_rejected_service
- hot variables
- report_peer_scan
- scan variables
- report_outbound_peer_scan
- scan variables
- possible_port_scan_thresh
- scan variables
- report_accounts_tried
- scan variables
- report_remote_accounts_tried
- scan variables
- skip_accounts_tried
- scan variables
- skip_outbound_services
- scan variables
- addl_web
- scan variables
- skip_scan_sources
- scan variables
- skip_scan_nets_24
- scan variables
- can_drop_connectivity
- scan variables
- shut_down_scans
- scan variables
- shut_down_all_scans
- scan variables
- shut_down_thresh
- scan variables
- never_shut_down
- scan variables
- port_names
- The port-name Module
- bro_log_file
- The log Module
- active_conn
- The active Module
- dns_interesting_changes
- dns variables
- hot_names
- finger variables
- max_request_length
- finger variables
- forbidden_ids
- The hot-ids Module
- forbidden_ids_if_no_password
- The hot-ids Module
- forbidden_id_patterns
- The hot-ids Module
- always_hot_ids
- The hot-ids Module
- hot_ids
- The hot-ids Module
- ftp_guest_ids
- ftp variables
- ftp_skip_hot
- ftp variables
- ftp_hot_files
- ftp variables
- ftp_not_actually_hot_files
- ftp variables
- ftp_hot_guest_files
- ftp variables
- skip_unexpected
- ftp variables
- skip_unexpected_net
- ftp variables
- sensitive_URIs
- http variables
- sensitive_post_URIs
- http variables
- hot_ident_ids
- ident variables
- hot_ident_exceptions
- ident variables
- input_trouble
- login variables
- edited_input_trouble
- login variables
- output_trouble
- login variables
- backdoor_prompts
- login variables
- non_backdoor_prompts
- login variables
- hot_terminal_types
- login variables
- hot_telnet_orig_ports
- login variables
- hot_ssh_orig_ports
- login variables
- skip_authentication
- login variables
- direct_login_prompts
- login variables
- login_prompts
- login variables
- login_failure_msgs
- login variables
- login_non_failure_msgs
- login variables
- router_prompts
- login variables
- login_success_msgs
- login variables
- login_timeouts
- login variables
- non_ASCII_hosts
- login variables
- skip_logins_to
- login variables
- always_hot_login_ids
- login variables
- hot_login_ids
- login variables
- rlogin_id_okay_if_no_password_exposed
- login variables
- rpc_programs
- portmapper variables
- NFS_services
- portmapper variables
- RPC_okay
- portmapper variables
- RPC_okay_nets
- portmapper variables
- RPC_okay_services
- portmapper variables
- NFS_world_servers
- portmapper variables
- RPC_dump_okay
- portmapper variables
- any_RPC_okay
- portmapper variables
- suppress_pm_log
- portmapper variables
- weird_action
- weird variables
- weird_action_filters
- weird variables
- weird_ignore_host
- weird variables
- weird_do_not_ignore_repeats
- weird variables
- attributes
- Attributes
- constant
- Statements
- initialization
- Initialization
- local
- Statements
- modifiability
- Modifiability
- overview
- Overview
- redefining
- Refinement
- refinement
- Refinement
- scope
- Statements
- scoping
- Scope
- typing
- Typing
- version message
- Flags
- VMS input editing
- login analyzer confusion
| login analyzer confusion
| login analyzer confusion
- VMS login prompts
- login analyzer confusion
- \tt Username:
- login analyzer confusion
- VT666 terminal type backdoor
- login variables
- -W flag
- Flags
| Flags
- walld
- portmapper variables
| portmapper variables
| portmapper event handlers
| portmapper event handlers
- watchdog
- Flags
- watchdog timer expired
- run-time error
- Flags
- WATCHDOG_INTERVAL internal variable
- Flags
- ``weird'' event
- Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird
| Events handled by conn_weird_addl
| Events handled by conn_weird_addl
| Events handled by conn_weird_addl
| Events handled by flow_weird
| Events handled by flow_weird
| Events handled by flow_weird
| Events handled by flow_weird
| Events handled by flow_weird
| Events handled by flow_weird
| Events handled by flow_weird
| Events handled by flow_weird
| Events handled by net_weird
| Events handled by net_weird
| Events handled by net_weird
| Events handled by net_weird
| Events handled by net_weird
| Events generated by the
| Events generated by the
- active_connection_reuse
- Events handled by conn_weird
- bad_HTTP_reply
- Events handled by conn_weird
- bad_HTTP_version
- Events handled by conn_weird
- bad_ICMP_checksum
- Events handled by conn_weird
- bad_ident_reply
- Events handled by conn_weird_addl
- bad_ident_request
- Events handled by conn_weird_addl
- bad_IP_checksum
- Events handled by net_weird
- bad_pm_port
- Events generated by the
- bad_rlogin_prolog
- Events handled by conn_weird
- bad_RPC
- Events handled by conn_weird
- bad_RPC_program
- Events handled by conn_weird
- bad_SYN_ack
- Events handled by conn_weird
- bad_TCP_checksum
- Events handled by conn_weird
- bad_TCP_header_len
- Events handled by net_weird
- bad_UDP_checksum
- Events handled by conn_weird
- baroque_SYN
- Events handled by conn_weird
- blank_in_HTTP_request
- Events handled by conn_weird
- connection_originator_SYN_ack
- Events handled by conn_weird
- data_after_reset
- Events handled by conn_weird
- data_before_established
- Events handled by conn_weird
- excess_RPC
- Events handled by conn_weird
- excessive_RPC_len
- Events handled by conn_weird
- excessively_large_fragment
- Events handled by flow_weird
- excessively_small_fragment
- Events handled by flow_weird
- FIN_advanced_last_seq
- Events handled by conn_weird
- FIN_after_reset
- Events handled by conn_weird
- FIN_storm
- Events handled by conn_weird
- fragment_inconsistency
- Events handled by flow_weird
- fragment_overlap
- Events handled by flow_weird
- fragment_protocol_inconsistency
- Events handled by flow_weird
- fragment_size_inconsistency
- Events handled by flow_weird
- fragment_with_DF
- Events handled by flow_weird
- HTTP_unknown_method
- Events handled by conn_weird
- HTTP_version_mismatch
- Events handled by conn_weird
- ident_request_addendum
- Events handled by conn_weird_addl
- inappropriate_FIN
- Events handled by conn_weird
- incompletely_captured_fragment
- Events handled by flow_weird
- internally_truncated_header
- Events handled by net_weird
- Land_attack
- Events generated by the
- multiple_HTTP_request_elements
- Events handled by conn_weird
- multiple_RPCs
- Events handled by conn_weird
- NUL_in_line
- Events handled by conn_weird
- originator_RPC_reply
- Events handled by conn_weird
- partial_finger_request
- Events handled by conn_weird
- partial_ftp_request
- Events handled by conn_weird
- partial_ident_request
- Events handled by conn_weird
- partial_portmapper_request
- Events handled by conn_weird
- partial_RPC
- Events handled by conn_weird
- pending_data_when_closed
- Events handled by conn_weird
- possible_split_routing
- Events handled by conn_weird
- premature_connection_reuse
- Events handled by conn_weird
- repeated_SYN_reply_wo_ack
- Events handled by conn_weird
- repeated_SYN_with_ack
- Events handled by conn_weird
- responder_RPC_call
- Events handled by conn_weird
- rlogin_text_after_rejected
- Events handled by conn_weird
- RPC_rexmit_inconsistency
- Events handled by conn_weird
- RST_storm
- Events handled by conn_weird
- RST_with_data
- Events handled by conn_weird
- simultaneous_open
- Events handled by conn_weird
- spontaneous_FIN
- Events handled by conn_weird
- spontaneous_RST
- Events handled by conn_weird
- SYN_after_close
- Events handled by conn_weird
- SYN_after_partial
- Events handled by conn_weird
- SYN_after_reset
- Events handled by conn_weird
- SYN_inside_connection
- Events handled by conn_weird
- SYN_seq_jump
- Events handled by conn_weird
- SYN_with_data
- Events handled by conn_weird
- TCP_christmas
- Events handled by conn_weird
- truncated_header
- Events handled by net_weird
- truncated_IP
- Events handled by net_weird
- UDP_datagram_length_mismatch
- Events handled by conn_weird
- unpaired_RPC_response
- Events handled by conn_weird
- unsolicited_SYN_response
- Events handled by conn_weird
- weird event summary file
- The weird Module
- weird events
- The weird Module to Additional handlers for ``weird''
- actions
- Actions for ``weird'' events
- additional handlers
- Additional handlers for ``weird''
- generated by standard scripts
- Events generated by the
- handled by conn_weird
- Events handled by conn_weird
- handled by conn_weird_addl
- Events handled by conn_weird_addl
- handled by flow_weird
- Events handled by flow_weird
- handled by net_weird
- Events handled by net_weird
- prevalence in actual network traffic
- The weird Module
- weird module
- The weird Module
- weird_action variable
- weird variables
- weird_action_filters variable
- weird variables
- weird_do_not_ignore_repeats variable
- weird variables
- WEIRD_FILE action
- Actions for ``weird'' events
- WEIRD_IGNORE action
- Actions for ``weird'' events
- weird_ignore_host variable
- weird variables
- WEIRD_LOG_ALWAYS action
- Actions for ``weird'' events
- WEIRD_LOG_ONCE action
- Actions for ``weird'' events
- WEIRD_LOG_PER_CONN action
- Actions for ``weird'' events
- WEIRD_LOG_PER_ORIG action
- Actions for ``weird'' events
- WEIRD_UNSPECIFIED action
- Actions for ``weird'' events
- whitespace
- in statements
- Statements
- width
- of formatted strings
- Predefined Functions
- Windows
- not supported
- Supported platforms
- write file
- control over what's recorded
- Predefined Functions
- &write_expire attribute
- Table Attributes
- writing tcpdump files
- Flags
- wrong number of fmt arguments
- Predefined Functions
- wrong number of fmt arguments
- run-time error
- Predefined Functions
- wrong number of length arguments
- run-time error
- Predefined Functions
- www.anticode.com
- login variables
- wwwroot sensitive POST URI
- http variables
- yield
- of a table
- Tables
- ypserv
- portmapper variables
Vern Paxson
2002-11-17