Patches for Chaosreader
Jens Lechtenboerger
chaos at informationelle-selbstbestimmung-im-internet.de
Fri Feb 10 09:37:19 UTC 2012
Dear reader,
I don't know anything about the Debian way of accepting patches for
packages, and a quick Web search did not really tell me how to
proceed.
Anyways, last year I started extending choasreader, but I was unable
to contact the original author: E-mail to Brendan Gregg
<brendan at sun.com> returned as undeliverable.
I'd be happy if you integrated my additions into the Debian version
of chaosreader. If you are interested, my version with the
following additions is available at:
http://www.informationelle-selbstbestimmung-im-internet.de/node16.html
* Switch to GPLv3.
* Integrate diff to reassemble chunked HTTP transfers.
* Parse linux cooked captures, which result from listening on
`any´ interface. (Chaosreader0.94 does not produce any output
for such pcaps.)
* Use HTTP Content-Type to identify file types such as HTML,
XML, Javascript, CSS; use those types for better file extensions
than `data´.
* More systematic Content-Type handling based on MIME
types. (More image types included in Image Report based on MIME
types.)
* Uncompress gzip'ed data.
* Add new command line switch (`-n´) to show host names in
HTTPlog and to create href-links from HTTPlog rows to the
corresponding rows in the table on index.html.
* Add new command line switch (`-d´) to parse captured DNS
replies and show DNS names instead of IP addresses on index
page; save DNS replies as text files.
If there is a recommended way of submitting patches, I'd be grateful
for guidance.
Best wishes
Jens
More information about the forensics-devel
mailing list