From 53126a0af9341d609247ef63b494c44b33a93baf Mon Sep 17 00:00:00 2001 From: Toni Uhlig Date: Wed, 10 Apr 2024 16:06:29 +0200 Subject: bump libnDPI to 142c8f5afb90629762920db6703831826513e00b * fixed `git format` hash length Signed-off-by: Toni Uhlig --- .../results/flow-captured/caches_cfg/teams.pcap.out | 4 ++-- .../caches_global/lru_ipv6_caches.pcapng.out | 2 ++ .../flow-captured/caches_global/teams.pcap.out | 4 ++-- test/results/flow-captured/default/elf.pcap.out | 2 ++ test/results/flow-captured/default/ftp.pcap.out | 1 - .../default/lru_ipv6_caches.pcapng.out | 2 ++ .../default/portable_executable.pcap.out | 1 + test/results/flow-captured/default/shell.pcap.out | 4 ++++ .../flow-captured/default/stun_signal.pcapng.out | 4 ++-- test/results/flow-captured/default/teams.pcap.out | 4 ++-- .../default/telegram_videocall.pcapng.out | 6 ------ .../results/flow-captured/default/wa_video.pcap.out | 3 +++ .../stun_mapped_address_disabled/teams.pcap.out | 21 +++++++++++++++++++++ 13 files changed, 43 insertions(+), 15 deletions(-) create mode 100644 test/results/flow-captured/default/elf.pcap.out create mode 100644 test/results/flow-captured/default/portable_executable.pcap.out create mode 100644 test/results/flow-captured/default/shell.pcap.out create mode 100644 test/results/flow-captured/stun_mapped_address_disabled/teams.pcap.out (limited to 'test/results/flow-captured') diff --git a/test/results/flow-captured/caches_cfg/teams.pcap.out b/test/results/flow-captured/caches_cfg/teams.pcap.out index 7a0343add..e2f4067c2 100644 --- a/test/results/flow-captured/caches_cfg/teams.pcap.out +++ b/test/results/flow-captured/caches_cfg/teams.pcap.out @@ -17,5 +17,5 @@ Flow 60 not-detected: tcp 151.11.50.139:2222 -> 192.168.1.6:54750 Flow 60 midstream: tcp 151.11.50.139:2222 -> 192.168.1.6:54750 Flow 79 risky: udp 93.71.110.205:16333 -> 192.168.1.6:50036 Flow 10 risky: udp 192.168.1.6:64046 -> 192.168.1.1:53 -Flow 81 risky: udp 52.114.252.8:3479 -> 192.168.1.6:50016 -Flow 80 risky: udp 52.114.252.21:3480 -> 192.168.1.6:50036 +Flow 68 risky: udp 192.168.1.6:50016 -> 52.114.250.141:3478 +Flow 70 risky: udp 192.168.1.6:50036 -> 52.114.250.137:3478 diff --git a/test/results/flow-captured/caches_global/lru_ipv6_caches.pcapng.out b/test/results/flow-captured/caches_global/lru_ipv6_caches.pcapng.out index 79c0e80d8..0247c3886 100644 --- a/test/results/flow-captured/caches_global/lru_ipv6_caches.pcapng.out +++ b/test/results/flow-captured/caches_global/lru_ipv6_caches.pcapng.out @@ -1,2 +1,4 @@ Flow 2 risky: udp 3991:72d:336e:65ec:c5bf:a5fa:83ad:23de:6881 -> 3024:e5ee:ac2f:cd76:5dd6:a7a1:f17f:5c27:60506 +Flow 7 risky: udp 2118:ec33:112b:7908:2c80:27ff:fef7:d71f:48415 -> 32fb:f967:681e:e96b:face:b00c::74fd:3478 +Flow 12 risky: udp 3069:c624:1d42:9469:98b1:67ff:fe43:325:56131 -> 32fb:f967:681e:e96b:face:b00c::74fd:3478 Flow 3 risky: udp 2a2f:8509:1cb2:466d:ecbf:69d6:109c:608:62229 -> 3991:72d:336e:65ec:c5bf:a5fa:83ad:23de:6881 diff --git a/test/results/flow-captured/caches_global/teams.pcap.out b/test/results/flow-captured/caches_global/teams.pcap.out index 7a0343add..e2f4067c2 100644 --- a/test/results/flow-captured/caches_global/teams.pcap.out +++ b/test/results/flow-captured/caches_global/teams.pcap.out @@ -17,5 +17,5 @@ Flow 60 not-detected: tcp 151.11.50.139:2222 -> 192.168.1.6:54750 Flow 60 midstream: tcp 151.11.50.139:2222 -> 192.168.1.6:54750 Flow 79 risky: udp 93.71.110.205:16333 -> 192.168.1.6:50036 Flow 10 risky: udp 192.168.1.6:64046 -> 192.168.1.1:53 -Flow 81 risky: udp 52.114.252.8:3479 -> 192.168.1.6:50016 -Flow 80 risky: udp 52.114.252.21:3480 -> 192.168.1.6:50036 +Flow 68 risky: udp 192.168.1.6:50016 -> 52.114.250.141:3478 +Flow 70 risky: udp 192.168.1.6:50036 -> 52.114.250.137:3478 diff --git a/test/results/flow-captured/default/elf.pcap.out b/test/results/flow-captured/default/elf.pcap.out new file mode 100644 index 000000000..658a3e527 --- /dev/null +++ b/test/results/flow-captured/default/elf.pcap.out @@ -0,0 +1,2 @@ +Flow 2 not-detected: tcp 127.0.0.1:41150 -> 127.0.0.1:33333 +Flow 1 not-detected: udp 127.0.0.1:60150 -> 127.0.0.1:33333 diff --git a/test/results/flow-captured/default/ftp.pcap.out b/test/results/flow-captured/default/ftp.pcap.out index 859c0bfef..d8242ebed 100644 --- a/test/results/flow-captured/default/ftp.pcap.out +++ b/test/results/flow-captured/default/ftp.pcap.out @@ -1,3 +1,2 @@ Flow 1 risky: tcp 192.168.1.212:50694 -> 90.130.70.73:21 Flow 3 not-detected: tcp 192.168.1.212:50696 -> 90.130.70.73:24523 -Flow 2 risky: tcp 192.168.1.212:50695 -> 90.130.70.73:25685 diff --git a/test/results/flow-captured/default/lru_ipv6_caches.pcapng.out b/test/results/flow-captured/default/lru_ipv6_caches.pcapng.out index 79c0e80d8..0247c3886 100644 --- a/test/results/flow-captured/default/lru_ipv6_caches.pcapng.out +++ b/test/results/flow-captured/default/lru_ipv6_caches.pcapng.out @@ -1,2 +1,4 @@ Flow 2 risky: udp 3991:72d:336e:65ec:c5bf:a5fa:83ad:23de:6881 -> 3024:e5ee:ac2f:cd76:5dd6:a7a1:f17f:5c27:60506 +Flow 7 risky: udp 2118:ec33:112b:7908:2c80:27ff:fef7:d71f:48415 -> 32fb:f967:681e:e96b:face:b00c::74fd:3478 +Flow 12 risky: udp 3069:c624:1d42:9469:98b1:67ff:fe43:325:56131 -> 32fb:f967:681e:e96b:face:b00c::74fd:3478 Flow 3 risky: udp 2a2f:8509:1cb2:466d:ecbf:69d6:109c:608:62229 -> 3991:72d:336e:65ec:c5bf:a5fa:83ad:23de:6881 diff --git a/test/results/flow-captured/default/portable_executable.pcap.out b/test/results/flow-captured/default/portable_executable.pcap.out new file mode 100644 index 000000000..53f91eaea --- /dev/null +++ b/test/results/flow-captured/default/portable_executable.pcap.out @@ -0,0 +1 @@ +Flow 1 not-detected: tcp 172.16.99.201:1732 -> 64.227.107.71:4444 diff --git a/test/results/flow-captured/default/shell.pcap.out b/test/results/flow-captured/default/shell.pcap.out new file mode 100644 index 000000000..a84f36af1 --- /dev/null +++ b/test/results/flow-captured/default/shell.pcap.out @@ -0,0 +1,4 @@ +Flow 4 not-detected: tcp 127.0.0.1:54970 -> 127.0.0.1:33333 +Flow 1 not-detected: tcp 127.0.0.1:47638 -> 127.0.0.1:33333 +Flow 2 not-detected: udp 127.0.0.1:54112 -> 127.0.0.1:33333 +Flow 3 not-detected: udp 127.0.0.1:58538 -> 127.0.0.1:33333 diff --git a/test/results/flow-captured/default/stun_signal.pcapng.out b/test/results/flow-captured/default/stun_signal.pcapng.out index dad2b24a0..44fe66f11 100644 --- a/test/results/flow-captured/default/stun_signal.pcapng.out +++ b/test/results/flow-captured/default/stun_signal.pcapng.out @@ -1,15 +1,15 @@ Flow 14 risky: udp 192.168.12.169:43068 -> 18.195.131.143:61156 Flow 3 risky: udp 192.168.12.169:47204 -> 35.158.183.167:443 -Flow 2 risky: udp 192.168.12.169:47204 -> 172.253.121.127:19302 Flow 6 risky: udp 192.168.12.169:39518 -> 35.158.183.167:443 -Flow 1 risky: udp 192.168.12.169:39518 -> 172.253.121.127:19302 Flow 23 risky: udp 192.168.12.169:47767 -> 18.195.131.143:61498 Flow 9 risky: udp 192.168.12.169:43068 -> 35.158.183.167:443 Flow 10 risky: udp 192.168.12.169:43068 -> 172.253.121.127:19302 Flow 12 risky: udp 192.168.12.169:39950 -> 35.158.183.167:443 Flow 11 risky: udp 192.168.12.169:39950 -> 172.253.121.127:19302 +Flow 20 risky: udp 192.168.12.169:37970 -> 35.158.122.211:3478 Flow 22 risky: udp 192.168.12.169:47767 -> 18.195.131.143:54054 Flow 17 risky: udp 192.168.12.169:47767 -> 35.158.122.211:443 Flow 15 risky: udp 192.168.12.169:47767 -> 172.253.121.127:19302 Flow 18 risky: udp 192.168.12.169:37970 -> 35.158.122.211:443 Flow 16 risky: udp 192.168.12.169:37970 -> 172.253.121.127:19302 +Flow 19 risky: udp 192.168.12.169:47767 -> 35.158.122.211:3478 diff --git a/test/results/flow-captured/default/teams.pcap.out b/test/results/flow-captured/default/teams.pcap.out index 7a0343add..e2f4067c2 100644 --- a/test/results/flow-captured/default/teams.pcap.out +++ b/test/results/flow-captured/default/teams.pcap.out @@ -17,5 +17,5 @@ Flow 60 not-detected: tcp 151.11.50.139:2222 -> 192.168.1.6:54750 Flow 60 midstream: tcp 151.11.50.139:2222 -> 192.168.1.6:54750 Flow 79 risky: udp 93.71.110.205:16333 -> 192.168.1.6:50036 Flow 10 risky: udp 192.168.1.6:64046 -> 192.168.1.1:53 -Flow 81 risky: udp 52.114.252.8:3479 -> 192.168.1.6:50016 -Flow 80 risky: udp 52.114.252.21:3480 -> 192.168.1.6:50036 +Flow 68 risky: udp 192.168.1.6:50016 -> 52.114.250.141:3478 +Flow 70 risky: udp 192.168.1.6:50036 -> 52.114.250.137:3478 diff --git a/test/results/flow-captured/default/telegram_videocall.pcapng.out b/test/results/flow-captured/default/telegram_videocall.pcapng.out index e0cc6941a..4184bab7a 100644 --- a/test/results/flow-captured/default/telegram_videocall.pcapng.out +++ b/test/results/flow-captured/default/telegram_videocall.pcapng.out @@ -1,8 +1,5 @@ Flow 26 risky: udp 192.168.12.169:42405 -> 93.36.13.115:35393 Flow 18 risky: udp 192.168.12.169:40643 -> 91.108.9.35:1400 -Flow 14 risky: udp 192.168.12.169:40906 -> 91.108.17.2:1400 -Flow 13 risky: udp 192.168.12.169:40906 -> 91.108.13.23:1400 -Flow 12 risky: udp 192.168.12.169:40906 -> 91.108.9.35:1400 Flow 24 risky: udp 192.168.12.169:42405 -> 10.46.103.200:42554 Flow 19 risky: udp 192.168.12.169:49667 -> 91.108.13.23:1400 Flow 25 risky: udp 192.168.12.169:40906 -> 10.46.103.200:42554 @@ -11,6 +8,3 @@ Flow 20 risky: udp 192.168.12.169:49780 -> 91.108.17.2:1400 Flow 22 risky: udp 192.168.12.169:37530 -> 91.108.13.23:1400 Flow 34 midstream: tcp 18.195.162.93:443 -> 192.168.12.169:38956 Flow 21 risky: udp 192.168.12.169:37849 -> 91.108.9.35:1400 -Flow 17 risky: udp 192.168.12.169:42197 -> 91.108.17.2:1400 -Flow 16 risky: udp 192.168.12.169:42197 -> 91.108.13.23:1400 -Flow 15 risky: udp 192.168.12.169:42197 -> 91.108.9.35:1400 diff --git a/test/results/flow-captured/default/wa_video.pcap.out b/test/results/flow-captured/default/wa_video.pcap.out index 91366f18d..32d1e558c 100644 --- a/test/results/flow-captured/default/wa_video.pcap.out +++ b/test/results/flow-captured/default/wa_video.pcap.out @@ -1,4 +1,7 @@ Flow 3 risky: udp 192.168.2.12:53688 -> 31.13.86.48:3478 Flow 11 risky: udp 192.168.2.12:53688 -> 91.252.56.51:32641 Flow 7 risky: udp 192.168.2.12:53688 -> 157.240.196.62:3478 +Flow 5 risky: udp 192.168.2.12:53688 -> 157.240.193.48:3478 +Flow 6 risky: udp 192.168.2.12:53688 -> 179.60.192.48:3478 +Flow 4 risky: udp 192.168.2.12:53688 -> 185.60.216.51:3478 Flow 10 risky: udp 192.168.2.12:53688 -> 1.60.78.64:59491 diff --git a/test/results/flow-captured/stun_mapped_address_disabled/teams.pcap.out b/test/results/flow-captured/stun_mapped_address_disabled/teams.pcap.out new file mode 100644 index 000000000..e2f4067c2 --- /dev/null +++ b/test/results/flow-captured/stun_mapped_address_disabled/teams.pcap.out @@ -0,0 +1,21 @@ +Flow 7 risky: tcp 192.168.1.6:60535 -> 52.114.77.33:443 +Flow 48 risky: tcp 192.168.1.6:60559 -> 52.114.77.33:443 +Flow 64 risky: tcp 192.168.1.6:50018 -> 52.114.250.123:443 +Flow 78 risky: udp 93.71.110.205:16332 -> 192.168.1.6:50016 +Flow 67 risky: tcp 192.168.1.6:50021 -> 52.114.250.123:443 +Flow 43 risky: tcp 192.168.1.6:60554 -> 52.113.194.132:443 +Flow 76 risky: udp 192.168.1.6:50016 -> 192.168.0.4:50005 +Flow 77 risky: udp 192.168.1.6:50036 -> 192.168.0.4:50020 +Flow 36 risky: udp 192.168.1.6:61245 -> 192.168.1.1:53 +Flow 4 risky: tcp 192.168.1.6:60532 -> 52.114.77.33:443 +Flow 25 risky: tcp 192.168.1.6:60543 -> 52.114.77.33:443 +Flow 51 risky: tcp 192.168.1.6:60561 -> 52.114.77.33:443 +Flow 74 risky: tcp 192.168.1.6:60567 -> 52.114.77.136:443 +Flow 30 risky: tcp 192.168.1.6:60546 -> 167.99.215.164:4434 +Flow 61 risky: tcp 192.168.1.6:60566 -> 167.99.215.164:4434 +Flow 60 not-detected: tcp 151.11.50.139:2222 -> 192.168.1.6:54750 +Flow 60 midstream: tcp 151.11.50.139:2222 -> 192.168.1.6:54750 +Flow 79 risky: udp 93.71.110.205:16333 -> 192.168.1.6:50036 +Flow 10 risky: udp 192.168.1.6:64046 -> 192.168.1.1:53 +Flow 68 risky: udp 192.168.1.6:50016 -> 52.114.250.141:3478 +Flow 70 risky: udp 192.168.1.6:50036 -> 52.114.250.137:3478 -- cgit v1.2.3