diff options
author | Moshe Kaplan <me@moshekaplan.com> | 2018-03-28 22:58:29 -0400 |
---|---|---|
committer | Peter Wu <peter@lekensteyn.nl> | 2018-03-29 15:33:53 +0000 |
commit | e2ec760d5ec00168d20b6c87095d8752934d732f (patch) | |
tree | 17dcf9d15a396d22af4d0ec6244943192759c9d1 /docbook/release-notes.asciidoc | |
parent | c7d06ea675388d8af2ae44a3b86500298cb3dcf5 (diff) |
Extend 'HTTP Referer statistics' to sequence HTTP Redirects
This patch adds support for sequencing HTTP Redirects. This enables
tracking of HTTP-based redirects, which may not have a Referer header.
As such, this patch also renames 'HTTP Referer statistics' to
'HTTP Request Sequences' to better reflect the more generic
functionality.
Note that this does not fully support RFC 3986. An external library like
uriparser.github.io may be a better option for efficient, full relative
HTTP URL resolution.
A Sample PCAP to test functionality is available here:
https://wiki.wireshark.org/SampleCaptures?action=AttachFile&do=get&target=http_redirects.pcapng
A sample PCAP to demonstrate usefulness is available here:
https://www.malware-traffic-analysis.net/2015/08/31/page2.html
(examine request to hxxp://lk2gaflsgh.jgy658snfyfnvh.com/service.php)
Change-Id: I9edd1a1de86228b0dcb1df9f6f30e24379684321
Reviewed-on: https://code.wireshark.org/review/26679
Petri-Dish: Peter Wu <peter@lekensteyn.nl>
Tested-by: Petri Dish Buildbot
Reviewed-by: Peter Wu <peter@lekensteyn.nl>
Diffstat (limited to 'docbook/release-notes.asciidoc')
-rw-r--r-- | docbook/release-notes.asciidoc | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/docbook/release-notes.asciidoc b/docbook/release-notes.asciidoc index 50c0196d06..1b9e4fb57c 100644 --- a/docbook/release-notes.asciidoc +++ b/docbook/release-notes.asciidoc @@ -42,7 +42,7 @@ Dumpcap might not quit if Wireshark or TShark crashes. The following features are new (or have been significantly updated) since version 2.5.0: -* HTTP Referer statistics are now supported. +* HTTP Request sequences are now supported. * Wireshark now supports MaxMind DB files. Support for GeoIP and GeoLite Legacy databases has been removed. * The Windows packages are now built using Microsoft Visual Studio 2017. |