Commit Graph

5 Commits

Author SHA1 Message Date
leetcrypt 20d30815a3 Fix FRP payload detection, byte accounting, and cloud-IP correlation in flock_tap
- Move the FRP auth-payload scan out of the SYN-only branch. SYN packets carry
  no payload, so payload-based FRP detection never fired; it now runs on every
  TCP segment where the frp/auth/proxy_type bytes actually appear.
- Remove the per-packet `bytes_up += 64` approximation in on_tcp_connect, which
  double-counted against real ip.len accounting and corrupted bandwidth stats.
- Correlate connections against known Flock cloud IPs (static seed list + IPs
  learned from DNS answers) so cameras that reach cloud IPs without their own
  DNS/SNI are classified CLOUD_CONNECTED.
- Match the Flock auth0 tenant in DNS detection, consistent with the SNI path.
- Install a SIGINT handler so the report is always produced on Ctrl+C.
- Drop unused scapy TLS imports (SNI is parsed manually).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-07-19 22:25:40 -07:00
ek0ms savi0r 61d21be3f9 Update README.md 2026-07-19 06:02:17 +00:00
ek0ms savi0r e6c41a69a6 Upload files to "modules" 2026-07-19 06:01:32 +00:00
ek0ms savi0r 587f14697e Upload files to "/" 2026-07-19 06:01:00 +00:00
ek0ms savi0r aa9eb3e7f6 Initial commit 2026-07-19 06:00:07 +00:00