Closed zar1n closed 8 years ago
Investigate on this issue. Thanks for reporting.
I check also others Tor pcap and a better detection is definitely needed.
Hi,
The first thing you could do is revert commit 392a14241fa68512099ea6096a640275461af7d0.
Tor certificates common names DO start with "www." so currently no Tor traffic is detected as such, you only get false positives.
@afiaux I'll check better. Thanks for suggestion.
Hello,
Link to flow dump file - https://www.dropbox.com/s/aaz4cqse2cw2qs5/static1.e621.net.pcap?dl=0 URL - https://static1.e621.net/data/d1/00/d100146df07c78366c10ae89787dcbc8.jpg (nswf)
And several URLs without flow dump files: https://casino.bwin.com https://ru.partypoker.com/
Used nDPI version 1.7.0 from sourcefordge.
Thank you.