Actions
Bug #5778
openftp fileinfo and extraction seem not to trigger when it should
Affected Versions:
Effort:
Difficulty:
Label:
Description
I have tested current master and latest stable 6.0.9.
Please see the attached pcap TLPW.
I may be wrong , but i don't see a reason why we should , the very least have some ftp fileinfo events.
Wireshark also does not extract the files - just for info.
I thought this is better to be logged and investigated rather, hence opening the issue.
Files
Updated by Peter Manev almost 2 years ago
In my previous message
why we should
should read
why we should not
Updated by Peter Manev almost 2 years ago
Please be careful if you extract files - the pcap should contain malware.
Updated by Andreas Herz almost 2 years ago
I found another pcap with ftp-data where the file extraction is working, but not properly. It's octet-stream/data instead of zip. Not sure if it's expected or if we could do better on this protocol.
Actions