Finding Md5 checksums in Snort
-
I am working on getting the md5 sums form Live traffic. I had checked that we can write a rule to generate alerts on the basis of the "protected_content" where we can specify the hash as md5|sha256|sha512. What I had observed is that snort is calculating the md5 sums of object to get them matched with given hash. And it is also mentioned that this is a computational extensive rule means it is calculating the hashes.
What I had seen is we need to define the length of the object which we are matching. But I am looking for more generalized solution.
I want to dump all the md5 sums of the objects on the fly traffic.Any suggestions are welcomed.