Snort mailing list archives

Re: Difficulty with Obfuscate option


From: "David F. Severski" <davidski () deadheaven com>
Date: Tue, 11 Dec 2001 14:40:20 -0800

I haven't heard of any obvious mistakes I've been making in my understanding 
or utilization of the obfuscation code, so I've done a little digging into 
log.c.  As near as I can tell, the recent adds for the obfuscation mask 
(-B) are preventing obufscation from operating the way I'd like it to.

Attached is a patch to enable sanitization in a way that works for me.  In 
addition, this also enables meaningful obfuscation from packet dump mode.  
Would someone mind taking a look at this and seeing if this makes sense?  I 
am by no means a C programmer so this could break things in...er...
"interesting" ways.

Thanks!

David

Attachment: sanitize.patch
Description:

Attachment: _bin
Description:


Current thread: