You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/doc
Frank Honza 1c8943dedd add RFB parser
This commit adds support for the Remote Framebuffer Protocol (RFB) as
used, for example, by various VNC implementations. It targets the
official versions 3.3, 3.7 and 3.8 of the protocol and provides logging
for the RFB handshake communication for now. Logged events include
endpoint versions, details of the security (i.e. authentication)
exchange as well as metadata about the image transfer parameters.
Detection is enabled using keywords for:

 - rfb.name: Session name as sticky buffer
 - rfb.sectype: Security type, e.g. VNC-style challenge-response
 - rfb.secresult: Result of the security exchange, e.g. OK, FAIL, ...

The latter could be used, for example, to detect brute-force attempts
on open VNC servers, while the name could be used to map unwanted VNC
sessions to the desktop owners or machines.

We also ship example EVE-JSON output and keyword docs as part of the
Sphinx source for Suricata's RTD documentation.
6 years ago
..
devguide devguide: document new app-layer retvals 6 years ago
doxygen
userguide add RFB parser 6 years ago
AUTHORS docs: replace redmine links and enforce https on oisf urls 9 years ago
Basic_Setup.txt
GITGUIDE
INSTALL docs: replace redmine links and enforce https on oisf urls 9 years ago
INSTALL.PF_RING docs: replace redmine links and enforce https on oisf urls 9 years ago
INSTALL.WINDOWS
Makefile.am doc: Add chassis for dev docs 7 years ago
NEWS docs: replace redmine links and enforce https on oisf urls 9 years ago
README
Setting_up_IPSinline_for_Linux.txt docs: replace redmine links and enforce https on oisf urls 9 years ago
TODO docs: replace redmine links and enforce https on oisf urls 9 years ago
Third_Party_Installation_Guides.txt

README