# Bro Script to detect plain text passwords?

**URL:** <https://community.zeek.org/t/bro-script-to-detect-plain-text-passwords/3345>\
**Category:** Zeek\
**Created:** [November 4, 2014, 11:24pm UTC](https://community.zeek.org/t/bro-script-to-detect-plain-text-passwords/3345 "2014-11-04T23:24:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeff\_Hammett](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@Jeff\_Hammett](https://community.zeek.org/u/Jeff_Hammett)\
**Post date:** [November 4, 2014, 11:24pm UTC](https://community.zeek.org/t/bro-script-to-detect-plain-text-passwords/3345/1 "2014-11-04T23:24:02Z")

</div>

I recently demo’d Tenable’s Passive Vulnerability Scanner, but found that it wasn’t a good fit for my environment. However it did have one nice feature I liked, the ability to detect passwords sent in plain text.

Does Bro have this functionality? Or would it be feasible to write a script to do so? (I haven’t written any scripts yet, but am interested).

I think I would be most interested in detecting plain text passwords used for http logins, but wouldn’t mind monitoring for other protocols as well.

Jeff

---

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [November 5, 2014, 12:32am UTC](https://community.zeek.org/t/bro-script-to-detect-plain-text-passwords/3345/2 "2014-11-05T00:32:02Z")

</div>

Absolutely. This is something well suited for Bro’s policy scripts.

-AK

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [November 5, 2014, 2:09am UTC](https://community.zeek.org/t/bro-script-to-detect-plain-text-passwords/3345/3 "2014-11-05T02:09:00Z")

</div>

> Does Bro have this functionality? Or would it be feasible to write a script to do so? (I haven’t written any scripts yet, but am interested).

Even better, it's something that we ship with, it just needs to be enabled. We decided to have a default setting of not capturing passwords. If you run Bro through BroControl, add the following line to your local.bro and do the check/install/restart commands in broctl.

redef HTTP::default\_capture\_password = T;

It will be in a field in your http.log named "password". There will also be a field named "username".

> I think I would be most interested in detecting plain text passwords used for http logins, but wouldn’t mind monitoring for other protocols as well.

For FTP:  
redef FTP::default\_capture\_password = T;

Channel passwords are logged by default for IRC too.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Nick\_Pratley](https://avatars.discourse-cdn.com/v4/letter/n/b77776/32.png) [@Nick\_Pratley](https://community.zeek.org/u/Nick_Pratley)\
**Post date:** [November 5, 2014, 2:25am UTC](https://community.zeek.org/t/bro-script-to-detect-plain-text-passwords/3345/4 "2014-11-05T02:25:51Z")

</div>

An example of detecting HTTP basic authentication is given here:  
[http://ryesecurity.blogspot.com.au/2012/05/learning-bro-scripting-language.html](http://ryesecurity.blogspot.com.au/2012/05/learning-bro-scripting-language.html)

---

<div class="post-metadata">

**Author:** ![Nick\_Pratley](https://avatars.discourse-cdn.com/v4/letter/n/b77776/32.png) [@Nick\_Pratley](https://community.zeek.org/u/Nick_Pratley)\
**Post date:** [November 5, 2014, 2:29am UTC](https://community.zeek.org/t/bro-script-to-detect-plain-text-passwords/3345/5 "2014-11-05T02:29:47Z")

</div>

Oh, I hadn't seen this before I sent my reply. Good to know, thanks.

---

<div class="post-metadata">

**Author:** ![Jeff\_Hammett](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@Jeff\_Hammett](https://community.zeek.org/u/Jeff_Hammett)\
**Post date:** [November 5, 2014, 3:36pm UTC](https://community.zeek.org/t/bro-script-to-detect-plain-text-passwords/3345/6 "2014-11-05T15:36:13Z")

</div>

Thanks! This is what I was looking for. One more question, how would I go about logging an entry in the notice.log when plaintext passwords are discovered?

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:42pm UTC](https://community.zeek.org/t/bro-script-to-detect-plain-text-passwords/3345/7 "2022-05-06T15:42:12Z")

</div>


