Kacper Why

Results 53 comments of Kacper Why

From `doc/INSTALL`: ``` ## dependencies libpcap0.8 (>= 0.9.8), libpcre3 (>= 8.10), libresolv ```

first occurance is ` ** dump_dns.o:dump_dns.c:(.text+0xa8): undefined reference to "__ns_parserr"`, indicates you are missing `libresolv`

The symbols you are missing are definitely provided by libresolv.so on my system. Look, I am not sure anyone has ever tried prads in cygwin before. The environment might prove...

Well, maybe the symbols are in the cygwin dll, but the makefile expects there to be a working -lresolv to link with, and that this library provides the required symbols....

a quick look into my crystal ball yeilded this gem from 2004: https://cygwin.com/ml/cygwin/2004-11/msg00024.html You can try to install minires-devel in cygwin and see if that provides the needed resolver symbols.

Yes, p0fv3 has been interesting from the start. It would need a little rewriting prads in-memory asset database though. The old sigs could be used to augment the v3 sigs,...

FWIW the existing SYN/SYNACK sigs are from p0f so using p0fv3 as a library somehow would be preferrable if possible.

Hia, I agree that the old signatures still have some value. Regardless of the approach you are taking - within or outside of prads - I would love to hear...

Your approach seems reasonable. If prads gets a p0fv3 classifier maybe we can extend the sigs to support quirks. I like your machine learning approach, which I belive has the...

Hi Chris, I am wondering if your best approach would not be to make a prototype in a high-level language. We originally made PRADS in perl, and only when we...