Patches for Chaosreader

Jens Lechtenboerger chaos at informationelle-selbstbestimmung-im-internet.de
Fri Feb 10 09:37:19 UTC 2012


Dear reader,

I don't know anything about the Debian way of accepting patches for
packages, and a quick Web search did not really tell me how to
proceed.

Anyways, last year I started extending choasreader, but I was unable
to contact the original author: E-mail to Brendan Gregg
<brendan at sun.com> returned as undeliverable.

I'd be happy if you integrated my additions into the Debian version
of chaosreader.  If you are interested, my version with the
following additions is available at:
http://www.informationelle-selbstbestimmung-im-internet.de/node16.html
    * Switch to GPLv3.
    * Integrate diff to reassemble chunked HTTP transfers.
    * Parse linux cooked captures, which result from listening on
      `any´ interface. (Chaosreader0.94 does not produce any output
      for such pcaps.)
    * Use HTTP Content-Type to identify file types such as HTML,
      XML, Javascript, CSS; use those types for better file extensions
      than `data´.
    * More systematic Content-Type handling based on MIME
      types. (More image types included in Image Report based on MIME
      types.)  
    * Uncompress gzip'ed data.
    * Add new command line switch (`-n´) to show host names in
      HTTPlog and to create href-links from HTTPlog rows to the
      corresponding rows in the table on index.html. 
    * Add new command line switch (`-d´) to parse captured DNS
      replies and show DNS names instead of IP addresses on index
      page; save DNS replies as text files.

If there is a recommended way of submitting patches, I'd be grateful
for guidance.

Best wishes
Jens



More information about the forensics-devel mailing list