Actions
Bug #1435
closedEVE-Log alert payload option loses data
Affected Versions:
Effort:
Difficulty:
Label:
Description
It would seem that EVE-Log alert payload loses data before/during payload->base64 conversion. Below is an excerpt from base64-decoded "image payload". The dots are really dots in the base64 source as well which implies that the information is lost before/during the conversion.
OiCCPPhotoshop ICC profile..x..SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE...........Q,..
Rule used to trigger
alert http any any -> any any (msg:"FILE store all"; filestore; sid:15; rev:1;)
All printable characters seem to be intact and the filestore saves an intact file.
I have attached a pcap that replicates the problem plus the produced EVE-log.
Files
Actions