Finding Md5 checksums in Snort

  • I am working on getting the md5 sums form Live traffic. I had checked that we can write a rule to generate alerts on the basis of the  "protected_content" where we can specify the hash as md5|sha256|sha512. What I had observed is that snort is calculating the md5 sums of object to get them matched with given hash. And it is also mentioned that this is a computational extensive rule means it is calculating the hashes.
    What I had seen is we need to define the length of the object which we are matching. But I am looking for more generalized solution.
    I want to dump all the md5 sums of the objects on the fly traffic.

    Any suggestions are welcomed.

Log in to reply