diff options
| author | srdusr <[email protected]> | 2024-05-21 22:24:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2024-05-21 22:24:00 +0200 |
| commit | fbedc55d5aa861c381701c9f913b34ee7ab57ec4 (patch) | |
| tree | d34c3648b61d417f2a5d8690e0eb4a76bd64c943 /NAMES.md | |
| parent | e0f4c701028aa81026a17cf9ebfb36112184f4bc (diff) | |
| download | packeteer-fbedc55d5aa861c381701c9f913b34ee7ab57ec4.tar.gz packeteer-fbedc55d5aa861c381701c9f913b34ee7ab57ec4.zip | |
Add GUI parity for -c/-a, mDNS/SSH dissectors, and two new fuzz harnesses
GUI parity: checksum_status()/reassembled_http_status() moved out of
main.cpp into a shared wireframe/packet_diagnostics.hpp so the GUI can
show the same -c/-a diagnostics for the selected packet without
duplicating the Ethernet/IPv4/TCP walk. Visually verified under Xvfb
with the same split-segment scenario used to verify -a on the CLI.
Two new L7 dissectors: mDNS (reuses parse_dns outright - RFC 6762
keeps DNS's wire format, just a different port) and SSH's cleartext
identification banner. Live-verified against this machine's real
sshd and a real DNS-wire-format packet sent to port 5353.
Two new fuzz harnesses (fuzz_checksum, fuzz_tcp_reassembly) covering
code added here that the original nine harnesses never
touched. All 12 run clean across ~90M executions with no crashes.
NAMES.md and PLAN.md updated with this round's decisions and naming
candidates.
Diffstat (limited to 'NAMES.md')
| -rw-r--r-- | NAMES.md | 39 |
1 files changed, 39 insertions, 0 deletions
@@ -102,3 +102,42 @@ No changes to the recommendation above - `frameshark`/`spanshark` (brand lineage) or `peek`/`probe` (terse-CLI lane) are still the strongest picks. `octet` is the one addition here worth weighing seriously: it's the most precise single word for what the tool actually operates on. + +## More candidates (added after TCP reassembly, checksums, privilege +## dropping, and a wider L7 protocol set - DNS/mDNS/HTTP/TLS SNI/SSH/ICMP) + +The project has since grown two angles the earlier lists didn't have +anything for: **stitching segments back into a stream** (TCP +reassembly, wireframe/net/tcp_reassembly.hpp) and **actively dropping +root** the moment the capture handle is open (wireframe/privileges.hpp) +rather than just capturing passively. + +- `flowtap` - "flow" is the actual industry term for what + TcpReassembler tracks (a 4-tuple's worth of state across many + packets), not just "stream" +- `stitchtap` - literal, describes reassembly specifically; maybe too + literal/cute +- `reflow` - re- (reassemble) + flow; short, but collides conceptually + with CSS/text "reflow", possibly confusing +- `dropcap` - pun on dropping root/CAP_NET_RAW after opening the + capture handle, which doubles as an actual typography term ("drop + cap": an oversized first letter) - two real meanings landing on the + same word is rare enough to be worth serious consideration +- `polytap` - poly- (many protocols: DNS/HTTP/TLS/mDNS/SSH/ICMP) + tap, + keeps the -tap suffix family from the first list +- `layershark` / `stackshark` - extends the -shark lineage with the + OSI-layer angle (L2 through L7 all decoded by hand now) +- `dissect` - plain English word, no jargon, describes exactly what + the tool does at every layer; downside is it's a very generic verb, + likely to collide with something already using it + +## Current standing recommendation + +Given how much the project now actually does - full L2-L7 decode +(including reassembly), pcapng, filtering, checksum verification, +privilege dropping, dual TUI/GUI frontends - a name that still reads +as "one narrow tool" undersells it less than it used to when this list +started. `frameshark` remains the strongest brand-lineage pick; +`dropcap` is the strongest new candidate from this round, on the +strength of its double meaning actually being true of the tool's own +behavior rather than a stretch. |