Skip to content

Filter language improvements: mod()/random() and --no-filters (#714, #1232) - #1326

Open
eaescob wants to merge 2 commits into
masterfrom
filter-714
Open

eaescob wants to merge 2 commits into
masterfrom
filter-714

Conversation

@eaescob

@eaescob eaescob commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This PR bundles two small filter-related improvements.

#714 — mod() and random() chance functions

  • mod(offset, divisor) returns true when (field_value % divisor) != 0, e.g.:
    if (mod(tcp.seq, 2)) { drop(); kill(); }
    
  • random() returns true 50% of the time.
  • random(percent) returns true percent% of the time (0-100).
  • The existing random(offset, start, length) data randomizer is preserved.

#1232 — --no-filters command-line flag

  • New long option --no-filters loads filter files passed with -F/--filter but keeps them disabled at startup.
  • Users can then enable them later through the interactive UI.
  • The existing :0 / :1 filename suffix still overrides the per-file enabled state.

Test plan

  • cmake --build build -j passes.
  • etterfilter compiles and -t disassembles mod()/random() examples.
  • ettercap -h shows the new --no-filters option.

Generated with Devin

eaescob and others added 2 commits September 4, 2026 11:10
- Add FFUNC_MOD and FFUNC_CHANCE opcodes.
- mod(offset, divisor): returns true if (field_value % divisor) != 0, so
  filters can do e.g.  if (mod(tcp.seq, 2)) { drop(); kill(); }.
- random(): 50% chance of being true.
- random(percent): percent chance (0-100) of being true.
- random(offset, start, length) keeps the existing data randomization.
- Update etterfilter disassembler to show the new functions.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
The -F/--filter option always loaded filter scripts as enabled. Add a new
--no-filters long option that loads the supplied filter files but sets them
disabled so the user can enable them later through the interactive UI.

The existing ":0" / ":1" filename suffix still overrides the per-file
enabled state, so -F script.ef:1 can force-enable a single filter while
--no-filters keeps the rest disabled.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@eaescob eaescob changed the title Filter functions: mod() and random() chance (#714) Filter language improvements: mod()/random() and --no-filters (#714, #1232) Sep 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant