<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RDEP Traffic Content in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/rdep-traffic-content/m-p/651931#M87743</link>
    <description>&lt;P&gt;I am using RDEP to subscribe to IDS sensors and retrieve alerts.  In a specific signature I am interested in the content of the traffic from the attacker and victim.  In the XML format for RDEP, this content seems encrypted in some way, what format is the &amp;lt;content&amp;gt;&amp;lt;fromAttacker&amp;gt;&amp;lt;/fromAttacker&amp;gt;&amp;lt;/content&amp;gt; given?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://" target="_blank"&gt;https://&lt;/A&gt;&amp;lt;sensor&amp;gt;/cgi-bin/event-server gives&lt;/P&gt;&lt;P&gt;&amp;lt;evAlert eventId="1164894001049869927" severity="low"&amp;gt;&lt;/P&gt;&lt;P&gt; ...&lt;/P&gt;&lt;P&gt;&amp;lt;context&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;fromAttacker&amp;gt;UE9TVCAvbm90aWZ5LyBIVFRQLzEuMQ0=&amp;lt;/fromAttacker&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/context&amp;gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&amp;lt;/evAlert&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the same event, in CLI gives:&lt;/P&gt;&lt;P&gt;#show events alert low&lt;/P&gt;&lt;P&gt;evIdsAlert: eventId=1164894001049869927 severity=low vendor=Cisco &lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;  context: &lt;/P&gt;&lt;P&gt;    fromAttacker: &lt;/P&gt;&lt;P&gt;000000  50 4F 53 54 20 2F 6E 6F  74 69 66 79 2F 20 48 54  POST /notify/ HT&lt;/P&gt;&lt;P&gt;000010  54 50 2F 31 2E 31 0D                              TP/1.1.&lt;/P&gt;&lt;P&gt;  riskRatingValue: 37&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I decipher the first to read like the second?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:25:48 GMT</pubDate>
    <dc:creator>tami.martin</dc:creator>
    <dc:date>2019-03-10T10:25:48Z</dc:date>
    <item>
      <title>RDEP Traffic Content</title>
      <link>https://community.cisco.com/t5/network-security/rdep-traffic-content/m-p/651931#M87743</link>
      <description>&lt;P&gt;I am using RDEP to subscribe to IDS sensors and retrieve alerts.  In a specific signature I am interested in the content of the traffic from the attacker and victim.  In the XML format for RDEP, this content seems encrypted in some way, what format is the &amp;lt;content&amp;gt;&amp;lt;fromAttacker&amp;gt;&amp;lt;/fromAttacker&amp;gt;&amp;lt;/content&amp;gt; given?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://" target="_blank"&gt;https://&lt;/A&gt;&amp;lt;sensor&amp;gt;/cgi-bin/event-server gives&lt;/P&gt;&lt;P&gt;&amp;lt;evAlert eventId="1164894001049869927" severity="low"&amp;gt;&lt;/P&gt;&lt;P&gt; ...&lt;/P&gt;&lt;P&gt;&amp;lt;context&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;fromAttacker&amp;gt;UE9TVCAvbm90aWZ5LyBIVFRQLzEuMQ0=&amp;lt;/fromAttacker&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/context&amp;gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&amp;lt;/evAlert&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the same event, in CLI gives:&lt;/P&gt;&lt;P&gt;#show events alert low&lt;/P&gt;&lt;P&gt;evIdsAlert: eventId=1164894001049869927 severity=low vendor=Cisco &lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;  context: &lt;/P&gt;&lt;P&gt;    fromAttacker: &lt;/P&gt;&lt;P&gt;000000  50 4F 53 54 20 2F 6E 6F  74 69 66 79 2F 20 48 54  POST /notify/ HT&lt;/P&gt;&lt;P&gt;000010  54 50 2F 31 2E 31 0D                              TP/1.1.&lt;/P&gt;&lt;P&gt;  riskRatingValue: 37&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I decipher the first to read like the second?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:25:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rdep-traffic-content/m-p/651931#M87743</guid>
      <dc:creator>tami.martin</dc:creator>
      <dc:date>2019-03-10T10:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: RDEP Traffic Content</title>
      <link>https://community.cisco.com/t5/network-security/rdep-traffic-content/m-p/651932#M87749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's base64 encoded.  You will need to decode it. Whatever you've written your code in should have a module/library for handling base64.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 18:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rdep-traffic-content/m-p/651932#M87749</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-01-19T18:42:18Z</dc:date>
    </item>
  </channel>
</rss>

