Browse Source

remove unnecessary packets from sality_botnet.pcap

aidmar.wainakh 6 years ago
parent
commit
c1390f950f
4 changed files with 8 additions and 1 deletions
  1. 1 1
      code/Attack/SalityBotnet.py
  2. BIN
      code/resources/sality_botnet.pcap
  3. 7 0
      id2t
  4. BIN
      resources/sality_botnet.pcap

+ 1 - 1
code/Attack/SalityBotnet.py

@@ -133,7 +133,7 @@ class SalityBotnet(BaseAttack.BaseAttack):
             if ip_pkt.getfieldval("ttl") not in ttl_map:
                 source_ttl = self.statistics.get_most_used_ttl(ip_pkt.getfieldval("src"))
                 if not source_ttl:
-                    source_ttl = self.statistics.process_db_query("SELECT ttlValue FROM ip_ttl ORDER BY RAND() LIMIT 1;")
+                    source_ttl = self.statistics.process_db_query("SELECT ttlValue FROM ip_ttl ORDER BY RANDOM() LIMIT 1;")
                 ttl_map[ip_pkt.getfieldval("ttl")] = source_ttl
             ip_pkt.setfieldval("ttl", ttl_map[ip_pkt.getfieldval("ttl")])
 

BIN
code/resources/sality_botnet.pcap


+ 7 - 0
id2t

@@ -0,0 +1,7 @@
+#!/bin/sh
+# Find the executable
+ID2T_DIR=$(readlink -f $0)
+SCRIPT_PATH=${ID2T_DIR%/*}
+cd $SCRIPT_PATH
+# Execute ID2T
+exec ./code/CLI.py "$@"

BIN
resources/sality_botnet.pcap