-
Notifications
You must be signed in to change notification settings - Fork 359
Open
Description
Running dockerized 4.8.0 version
Before enabling ja3 zkg two months ago, outputs of "rita show-useragents" and "useragents.html" from html-report matched.
Since ja3 zkg installation, "rita show-useragents" and "useragents.html" don't match at all.
useragents.html is filled with 1000 ja3 hashes all used 1 time while show-useragents only displays 819 occurences of 1 time use.
rita show-useragents lastweek | grep ,1$ | wc -l
819
Example:
rita show-user-agents lastweek output snip
User Agent,Times Used
11e1137464a4343105031631d470cd92,12662
3e5e8d5979858e1f495ff02782601670,7710
28a2c9bd18a11de089ef85a160da29e4,6479
3fed133de60c35724739b913924b6c24,3978
Debian APT-HTTP/1.3 (1.4.11),3854
Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33,3783
HTML report output snip
User Agent Times Used
48b822f5ebf7646c7886969c18de908f 1
fc9ef63605fe74399ea14d0556bf2c35 1
b044fef1febe704bcb7b9a3b5c1cf675 1
2f07c6d21d5bf537d866371a99f054c3 1
e5359b0f68ca972adf7e192fd8c01ebe 1
983203c4a1ac38a4c4c1e14403d02ecd 1
92ca88530c12182264332eae85c180ba 1
7a34b08d43190057863fd8438fca4cf2 1
5464aa06da909e8e9f32bb4ae046d327 1
1a2dd688b1f2551493b7d540f8d4bdb2 1
f61eff6f78df0ec9336e97214005bf31 1
Expectation is to have html-reports match exactly the show-X commands
Metadata
Metadata
Assignees
Labels
No labels