From 89a363aff68b80f81e8f244a5292cdc5de4d5ec0 Mon Sep 17 00:00:00 2001 From: Luca Deri Date: Sun, 8 Nov 2020 10:07:35 +0100 Subject: Updated ESNI/SNI alarm generation prolicy --- src/lib/protocols/tls.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'src/lib') diff --git a/src/lib/protocols/tls.c b/src/lib/protocols/tls.c index 7f9e8d5c0..5c0cc5145 100644 --- a/src/lib/protocols/tls.c +++ b/src/lib/protocols/tls.c @@ -1539,7 +1539,9 @@ int processClientServerHello(struct ndpi_detection_module_struct *ndpi_struct, /* Add check for missing SNI */ if((flow->protos.stun_ssl.ssl.client_requested_server_name[0] == 0) - && (flow->protos.stun_ssl.ssl.ssl_version >= 0x0302) /* TLSv1.1 */) { + && (flow->protos.stun_ssl.ssl.ssl_version >= 0x0302) /* TLSv1.1 */ + && (flow->protos.stun_ssl.ssl.encrypted_sni.esni == NULL) /* No ESNI */ + ) { /* This is a bit suspicious */ NDPI_SET_BIT(flow->risk, NDPI_TLS_MISSING_SNI); } -- cgit v1.2.3