# http-body and binary content

**URL:** <https://community.zeek.org/t/http-body-and-binary-content/1248>\
**Category:** Zeek\
**Created:** [October 11, 2007, 7:47pm UTC](https://community.zeek.org/t/http-body-and-binary-content/1248 "2007-10-11T19:47:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Reed\_Porada](https://avatars.discourse-cdn.com/v4/letter/r/96bed5/32.png) [@Reed\_Porada](https://community.zeek.org/u/Reed_Porada)\
**Post date:** [October 11, 2007, 7:47pm UTC](https://community.zeek.org/t/http-body-and-binary-content/1248/1 "2007-10-11T19:47:07Z")

</div>

I want to reassemble the http-content for various streams. Right now I have been able to generically reassembled all of the content, but with mixed results. The plaintext content seems to be reassembling fine, however, binary content has had mixed results. I have successfully reassembled several gifs (minus a newline), but others I have not. Looking at the hexdump of the content output, it seems like some gifs are being outputed in ASCII Hex, and others real binary. I then looked at the packet captures, and ethereal is showing the binary of the gifs. The subtle difference that I have noticed is that the successful gifs do not have any "X-..." optional headers in them, whereas those that are failing have had "X-Cache" and "X-Pad" for example.

Any thoughts on why Bro changes its output based on the optional headers? Or why it could be sometimes outputting binary and others ASCII Hex?

Thanks,  
-Reed

---

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [October 12, 2007, 3:38am UTC](https://community.zeek.org/t/http-body-and-binary-content/1248/2 "2007-10-12T03:38:30Z")

</div>

> Any thoughts on why Bro changes its output based on the optional  
> headers?

This almost for sure isn't the problem, as I don't believe there's any  
code relating to looking at the headers in this regard.

> Or why it could be sometimes outputting binary and others  
> ASCII Hex?

How are you using/printing the values recovered by Bro? Best bet is that  
you're running into Bro introducing some escape sequences.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![Reed\_Porada](https://avatars.discourse-cdn.com/v4/letter/r/96bed5/32.png) [@Reed\_Porada](https://community.zeek.org/u/Reed_Porada)\
**Post date:** [October 12, 2007, 1:59pm UTC](https://community.zeek.org/t/http-body-and-binary-content/1248/3 "2007-10-12T13:59:07Z")

</div>

> > Any thoughts on why Bro changes its output based on the optional  
> > headers?
> 
> This almost for sure isn't the problem, as I don't believe there's any  
> code relating to looking at the headers in this regard.

I kinda figured that, but just wanted to make sure.

> > Or why it could be sometimes outputting binary and others  
> > ASCII Hex?
> 
> How are you using/printing the values recovered by Bro? Best bet is that  
> you're running into Bro introducing some escape sequences.

I am storing the values as strings and printing to an open file. I was concatenating the data using the fmt() command. Given what you said, I switched to the cat () function and that works. Thanks for making me think about it more.

The only thing I am still noticing is that with a print it appends a newline to each print statement. Is there anyway to prevent this?

Thanks again,

-Reed

---

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [October 31, 2007, 8:03pm UTC](https://community.zeek.org/t/http-body-and-binary-content/1248/4 "2007-10-31T20:03:04Z")

</div>

> The only thing I am still noticing is that with a print it appends a  
> newline to each print statement. Is there anyway to prevent this?

Not presently, as it's built into "print". We have in mind a framework for  
controlling behavior like this, but no active work yet on implementing it.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:38pm UTC](https://community.zeek.org/t/http-body-and-binary-content/1248/5 "2022-05-06T15:38:23Z")

</div>


