# Trying to extract HTTP payload

**URL:** <https://community.zeek.org/t/trying-to-extract-http-payload/2440>\
**Category:** Zeek\
**Created:** [September 18, 2012, 2:04am UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440 "2012-09-18T02:04:04Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abhishek\_Chanda](https://avatars.discourse-cdn.com/v4/letter/a/b5e925/32.png) [@Abhishek\_Chanda](https://community.zeek.org/u/Abhishek_Chanda)\
**Post date:** [September 18, 2012, 2:04am UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/1 "2012-09-18T02:04:04Z")

</div>

Hi,

I am trying to extract HTTP payload and bro throws an error:

achanda@achanda-OptiPlex-780:~/bro/scripts$ bro -i eth0 http-reply  
error in ./site, line 1: read failed with "Is a directory"  
achanda@achanda-OptiPlex-780:~/bro/scripts$ bro -i eth0 contents  
error in ./site, line 1: read failed with "Is a directory"  
achanda@achanda-OptiPlex-780:~/bro/scripts$

I tried to run bro from the top level installation directory but that  
failed since it could not find the scripts. What am I missing?

Thanks

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [September 18, 2012, 2:12am UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/2 "2012-09-18T02:12:53Z")

</div>

What version of Bro are you running? There is not http-reply script anymore (it was removed in 2.0).

2.0 and 2.1 can extract payloads in several ways. There is currently only one mechanism builtin for doing it though by matching the sniffed mime type of the response body.

This will do it if you are just interested in running from the command line...  
&nbsp;&nbsp;bro -r somepackets.pcap "HTTP::extract\_file\_types=/.\*/"

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Abhishek\_Chanda](https://avatars.discourse-cdn.com/v4/letter/a/b5e925/32.png) [@Abhishek\_Chanda](https://community.zeek.org/u/Abhishek_Chanda)\
**Post date:** [September 18, 2012, 5:08pm UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/3 "2012-09-18T17:08:51Z")

</div>

Hi,

Thanks for the reply.  
This is bro 2.1. Now, I ran this:

sudo ./bro -i eth0 "HTTP::extract\_file\_types=/.jpg/"

But no file gets saved in the current directory. The entry appears in  
http.log though with a 200 OK

1347988043.663837 SWYFHjGx0x6 192.168.10.185 58146 74.200.247.186 80 0 - - - - - 0 7240 200 OK - - - (empty) - - - image/jpeg - -  
1347988052.178112 BVcSiCSyzA4 192.168.10.185 46424 54.240.160.141 80 0 - - - - - 0 31225 200 OK - - - (empty) - - - image/jpeg - -  
#close 2012-09-18-10-07-40

Is there something else I need to do?

Thanks

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [September 18, 2012, 5:14pm UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/4 "2012-09-18T17:14:34Z")

</div>

sudo ./bro -i eth0 "HTTP::extract\_file\_types=/.\*\.jpg/"

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Abhishek\_Chanda](https://avatars.discourse-cdn.com/v4/letter/a/b5e925/32.png) [@Abhishek\_Chanda](https://community.zeek.org/u/Abhishek_Chanda)\
**Post date:** [September 18, 2012, 5:23pm UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/5 "2012-09-18T17:23:56Z")

</div>

Hi,

It still does not seem to work, there is nothing in the current  
directory. Here is an entry from http.log

1347988766.291078 t3VZX9hEzl7 192.168.10.185 48299 184.172.154.91 80 0 - - - - - 0 1131 200 OK - - - (empty) - - - image/jpeg - -

There are similar entries which do not have a file name.

Thanks

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [September 18, 2012, 5:40pm UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/6 "2012-09-18T17:40:48Z")

</div>

sudo ./bro -i eth0 "HTTP::extract\_file\_types=/.\*\.jpeg/"

🙂

.Seth

---

<div class="post-metadata">

**Author:** ![Doug\_Burks](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@Doug\_Burks](https://community.zeek.org/u/Doug_Burks)\
**Post date:** [September 18, 2012, 5:43pm UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/7 "2012-09-18T17:43:30Z")

</div>

The blank fields in http.log could be the result of checksum offloading:  
[http://securityonion.blogspot.com/2011/10/when-is-full-packet-capture-not-full.html](http://securityonion.blogspot.com/2011/10/when-is-full-packet-capture-not-full.html)  
Doug

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [September 18, 2012, 5:53pm UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/8 "2012-09-18T17:53:53Z")

</div>

Hah! Good catch Doug. Ironically, the file extraction as he's doing it will still work fine.

Abhishek, you can have Bro ignore checksums with the -C command line argument, but you definitely do not want to run Bro in production with that argument because it opens the door to easy evasions.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Abhishek\_Chanda](https://avatars.discourse-cdn.com/v4/letter/a/b5e925/32.png) [@Abhishek\_Chanda](https://community.zeek.org/u/Abhishek_Chanda)\
**Post date:** [September 18, 2012, 6:27pm UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/9 "2012-09-18T18:27:40Z")

</div>

Hi Seth and Doug,

Thanks for the replies.  
I still could not get Bro to work though. I am trying to save a gif  
file since I thought this would cause less confusion with the file  
MIME and extension. I disabled TCP checksum offloading as Doug  
suggested. I ran Bro as:

sudo ./bro -C -i eth1 "HTTP::extract\_file\_types=/.\*\.gif/"

I then pointed my browser to a gif image. The entry for the image  
appears in http.log but the image does not get saved. I am sure that  
the interface is correct. What else can go wrong?

Thanks

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [September 18, 2012, 6:32pm UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/10 "2012-09-18T18:32:24Z")

</div>

What's the line in http.log?

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Abhishek\_Chanda](https://avatars.discourse-cdn.com/v4/letter/a/b5e925/32.png) [@Abhishek\_Chanda](https://community.zeek.org/u/Abhishek_Chanda)\
**Post date:** [September 18, 2012, 6:37pm UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/11 "2012-09-18T18:37:02Z")

</div>

Here:

1347993371.841877 J6Gs3YxcaZ3 10.0.3.15 33554  
216.92.99.29 80 1 GET [www.effetech.com](http://www.effetech.com)  
/images/msn2\_full.gif - Mozilla/5.0 (X11; Ubuntu; Linux i686;  
rv:13.0) Gecko/20100101 Firefox/13.0.1 0 47818 200 OK  
&nbsp;&nbsp;&nbsp;- - - (empty) - - - image/gif  
&nbsp;&nbsp;&nbsp;&nbsp;- -

I cleared my browser cache before I tried to get the image.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/trying-to-extract-http-payload/2440/12 "2022-05-06T15:40:34Z")

</div>


