# Extracting File from Particular FTP Commands

**URL:** <https://community.zeek.org/t/extracting-file-from-particular-ftp-commands/3190>\
**Category:** Zeek\
**Created:** [July 22, 2014, 4:36am UTC](https://community.zeek.org/t/extracting-file-from-particular-ftp-commands/3190 "2014-07-22T04:36:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pete](https://avatars.discourse-cdn.com/v4/letter/p/3ab097/32.png) [@Pete](https://community.zeek.org/u/Pete)\
**Post date:** [July 22, 2014, 4:36am UTC](https://community.zeek.org/t/extracting-file-from-particular-ftp-commands/3190/1 "2014-07-22T04:36:25Z")

</div>

I am looking to extract data from an FTP session, but would only like to do so for those  
using the RETR or STOR command. I've been able to extract data from all FTP sessions by  
looking for the FTP\_DATA source during a file\_new event, but can't seem to find a way to  
access the associated ftp record with the command attribute. I'm assuming that this is  
complicated by the separate connection for ftp data. I've thought about modifying the default FTP::file\_over\_new\_connection event to associate the ftp command channel with the data  
channel, but was wondering if there is a better (more accepted) approach before doing so.  
Any advise would be appreciated.

My current file\_new event is as follows:

event file\_new(f: fa\_file)  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if ( f$source != "FTP\_DATA" )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;return;

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;for ( cid in f$conns )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if ( f$conns[cid]?$ftp )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;print fmt("Command: %s", f$conns[cid]$ftp$command);  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;local fname = fmt("%s\_%s.bin", to\_lower(f$source), f$id);  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Files::add\_analyzer(f, Files::ANALYZER\_EXTRACT, [$extract\_filename=fname]);  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}

To modify the base/protocols/ftp/files.bro script, I was going to simply add a statement  
to save the stored ftp record from ftp\_data\_expected to the current connection (c) which  
holds the FTP\_DATA data.

event file\_over\_new\_connection(f: fa\_file, c: connection, is\_orig: bool) &priority=5  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if ( [c$id$resp\_h, c$id$resp\_p] !in ftp\_data\_expected )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;return;

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;local ftp = ftp\_data\_expected[c$id$resp\_h, c$id$resp\_p];  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;c$ftp = ftp;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ftp$fuid = f$id;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if ( f?$mime\_type )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ftp$mime\_type = f$mime\_type;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}

---

<div class="post-metadata">

**Author:** ![Siwek\_Jon](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@Siwek\_Jon](https://community.zeek.org/u/Siwek_Jon)\
**Post date:** [July 22, 2014, 2:19pm UTC](https://community.zeek.org/t/extracting-file-from-particular-ftp-commands/3190/2 "2014-07-22T14:19:01Z")

</div>

Maybe have your own “file\_over\_new\_connection” handler that sets the field. The downside to modifying the default handler in-place is that you have to remember the change will be overwritten on the next Bro install. The downside of having your own handler is sometimes duplication of logic (e.g. the “ftp\_data\_expected" table lookup). You can decide which is better, but the general suggestion is usually to just maintain your own event handlers separately.

- Jon

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/extracting-file-from-particular-ftp-commands/3190/3 "2022-05-06T15:41:55Z")

</div>


