|
Packit |
03b34a |
/*
|
|
Packit |
03b34a |
* $Id: libnet_build_tcp.c,v 1.11 2004/01/28 19:45:00 mike Exp $
|
|
Packit |
03b34a |
*
|
|
Packit |
03b34a |
* libnet
|
|
Packit |
03b34a |
* libnet_build_tcp.c - TCP packet assembler
|
|
Packit |
03b34a |
*
|
|
Packit |
03b34a |
* Copyright (c) 1998 - 2004 Mike D. Schiffman <mike@infonexus.com>
|
|
Packit |
03b34a |
* All rights reserved.
|
|
Packit |
03b34a |
*
|
|
Packit |
03b34a |
* Redistribution and use in source and binary forms, with or without
|
|
Packit |
03b34a |
* modification, are permitted provided that the following conditions
|
|
Packit |
03b34a |
* are met:
|
|
Packit |
03b34a |
* 1. Redistributions of source code must retain the above copyright
|
|
Packit |
03b34a |
* notice, this list of conditions and the following disclaimer.
|
|
Packit |
03b34a |
* 2. Redistributions in binary form must reproduce the above copyright
|
|
Packit |
03b34a |
* notice, this list of conditions and the following disclaimer in the
|
|
Packit |
03b34a |
* documentation and/or other materials provided with the distribution.
|
|
Packit |
03b34a |
*
|
|
Packit |
03b34a |
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
|
|
Packit |
03b34a |
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
Packit |
03b34a |
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
Packit |
03b34a |
* ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
|
|
Packit |
03b34a |
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
|
Packit |
03b34a |
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
|
Packit |
03b34a |
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
|
Packit |
03b34a |
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
|
Packit |
03b34a |
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
|
Packit |
03b34a |
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
|
Packit |
03b34a |
* SUCH DAMAGE.
|
|
Packit |
03b34a |
*
|
|
Packit |
03b34a |
*/
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
#if (HAVE_CONFIG_H)
|
|
Packit |
03b34a |
#include "../include/config.h"
|
|
Packit |
03b34a |
#endif
|
|
Packit |
03b34a |
#if (!(_WIN32) || (__CYGWIN__))
|
|
Packit |
03b34a |
#include "../include/libnet.h"
|
|
Packit |
03b34a |
#else
|
|
Packit |
03b34a |
#include "../include/win32/libnet.h"
|
|
Packit |
03b34a |
#endif
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
libnet_ptag_t
|
|
Packit |
03b34a |
libnet_build_tcp(
|
|
Packit |
03b34a |
uint16_t sp, uint16_t dp, uint32_t seq, uint32_t ack,
|
|
Packit |
03b34a |
uint8_t control, uint16_t win, uint16_t sum, uint16_t urg, uint16_t h_len,
|
|
Packit |
03b34a |
const uint8_t *payload, uint32_t payload_s, libnet_t *l, libnet_ptag_t ptag)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
int n, offset;
|
|
Packit |
03b34a |
libnet_pblock_t *p = NULL;
|
|
Packit |
03b34a |
libnet_ptag_t ptag_data = 0;
|
|
Packit |
03b34a |
struct libnet_tcp_hdr tcp_hdr;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if (l == NULL)
|
|
Packit |
03b34a |
return -1;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if (payload_s && !payload)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
snprintf(l->err_buf, LIBNET_ERRBUF_SIZE,
|
|
Packit |
03b34a |
"%s(): payload inconsistency\n", __func__);
|
|
Packit |
03b34a |
return -1;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
p = libnet_pblock_probe(l, ptag, LIBNET_TCP_H, LIBNET_PBLOCK_TCP_H);
|
|
Packit |
03b34a |
if (p == NULL)
|
|
Packit |
03b34a |
return -1;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
memset(&tcp_hdr, 0, sizeof(tcp_hdr));
|
|
Packit |
03b34a |
tcp_hdr.th_sport = htons(sp); /* source port */
|
|
Packit |
03b34a |
tcp_hdr.th_dport = htons(dp); /* destination port */
|
|
Packit |
03b34a |
tcp_hdr.th_seq = htonl(seq); /* sequence number */
|
|
Packit |
03b34a |
tcp_hdr.th_ack = htonl(ack); /* acknowledgement number */
|
|
Packit |
03b34a |
tcp_hdr.th_flags = control; /* control flags */
|
|
Packit |
03b34a |
tcp_hdr.th_x2 = 0; /* UNUSED */
|
|
Packit |
03b34a |
tcp_hdr.th_off = 5; /* 20 byte header */
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
/* check to see if there are TCP options to include */
|
|
Packit |
03b34a |
if (p->prev && p->prev->type == LIBNET_PBLOCK_TCPO_H)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
/* Note that the tcp options pblock is already padded */
|
|
Packit |
03b34a |
tcp_hdr.th_off += (p->prev->b_len/4);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
tcp_hdr.th_win = htons(win); /* window size */
|
|
Packit |
03b34a |
tcp_hdr.th_sum = (sum ? htons(sum) : 0); /* checksum */
|
|
Packit |
03b34a |
tcp_hdr.th_urp = htons(urg); /* urgent pointer */
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
n = libnet_pblock_append(l, p, (uint8_t *)&tcp_hdr, LIBNET_TCP_H);
|
|
Packit |
03b34a |
if (n == -1)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
goto bad;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if (ptag == LIBNET_PTAG_INITIALIZER)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
libnet_pblock_update(l, p, h_len, LIBNET_PBLOCK_TCP_H);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
offset = payload_s;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
/* If we are going to modify a TCP data block, find it, and figure out the
|
|
Packit |
03b34a |
* "offset", the possibly negative amount by which we are increasing the ip
|
|
Packit |
03b34a |
* data length. */
|
|
Packit |
03b34a |
if (ptag)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
libnet_pblock_t* datablock = p->prev;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if (datablock && datablock->type == LIBNET_PBLOCK_TCPO_H)
|
|
Packit |
03b34a |
datablock = datablock->prev;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if (datablock && datablock->type == LIBNET_PBLOCK_TCPDATA)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
ptag_data = datablock->ptag;
|
|
Packit |
03b34a |
offset -= datablock->b_len;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
p->h_len += offset;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
/* If we are modifying a TCP block, we should look forward and apply the offset
|
|
Packit |
03b34a |
* to our IPv4 header, if we have one.
|
|
Packit |
03b34a |
*/
|
|
Packit |
03b34a |
if (p->next)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
libnet_pblock_t* ipblock = p->next;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if(ipblock->type == LIBNET_PBLOCK_IPO_H)
|
|
Packit |
03b34a |
ipblock = ipblock->next;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if(ipblock && ipblock->type == LIBNET_PBLOCK_IPV4_H)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
struct libnet_ipv4_hdr * ip_hdr = (struct libnet_ipv4_hdr *)ipblock->buf;
|
|
Packit |
03b34a |
int ip_len = ntohs(ip_hdr->ip_len) + offset;
|
|
Packit |
03b34a |
ip_hdr->ip_len = htons(ip_len);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
/* if there is a payload, add it in the context */
|
|
Packit |
03b34a |
if (payload_s)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
/* update ptag_data with the new payload */
|
|
Packit |
03b34a |
libnet_pblock_t* p_data = libnet_pblock_probe(l, ptag_data, payload_s, LIBNET_PBLOCK_TCPDATA);
|
|
Packit |
03b34a |
if (!p_data)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
goto bad;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
n = libnet_pblock_append(l, p_data, payload, payload_s);
|
|
Packit |
03b34a |
if (n == -1)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
goto bad;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if (ptag_data == LIBNET_PTAG_INITIALIZER)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
int insertbefore = p->ptag;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
/* Then we created it, and we need to shuffle it back until it's before
|
|
Packit |
03b34a |
* the tcp header and options. */
|
|
Packit |
03b34a |
libnet_pblock_update(l, p_data, payload_s, LIBNET_PBLOCK_TCPDATA);
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if(p->prev && p->prev->type == LIBNET_PBLOCK_TCPO_H)
|
|
Packit |
03b34a |
insertbefore = p->prev->ptag;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
libnet_pblock_insert_before(l, insertbefore, p_data->ptag);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
else
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
libnet_pblock_t* p_data = libnet_pblock_find(l, ptag_data);
|
|
Packit |
03b34a |
libnet_pblock_delete(l, p_data);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if (sum == 0)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
/*
|
|
Packit |
03b34a |
* If checksum is zero, by default libnet will compute a checksum
|
|
Packit |
03b34a |
* for the user. The programmer can override this by calling
|
|
Packit |
03b34a |
* libnet_toggle_checksum(l, ptag, 1);
|
|
Packit |
03b34a |
*/
|
|
Packit |
03b34a |
libnet_pblock_setflags(p, LIBNET_PBLOCK_DO_CHECKSUM);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
return (p->ptag);
|
|
Packit |
03b34a |
bad:
|
|
Packit |
03b34a |
libnet_pblock_delete(l, p);
|
|
Packit |
03b34a |
return (-1);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
libnet_ptag_t
|
|
Packit |
03b34a |
libnet_build_tcp_options(const uint8_t *options, uint32_t options_s, libnet_t *l,
|
|
Packit |
03b34a |
libnet_ptag_t ptag)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
static const uint8_t padding[] = { 0 };
|
|
Packit |
03b34a |
int n, offset, underflow;
|
|
Packit |
03b34a |
uint32_t i, j, adj_size;
|
|
Packit |
03b34a |
libnet_pblock_t *p, *p_temp;
|
|
Packit |
03b34a |
struct libnet_ipv4_hdr *ip_hdr;
|
|
Packit |
03b34a |
struct libnet_tcp_hdr *tcp_hdr;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if (l == NULL)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
return (-1);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
underflow = 0;
|
|
Packit |
03b34a |
offset = 0;
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
/* check options list size */
|
|
Packit |
03b34a |
if (options_s > LIBNET_MAXOPTION_SIZE)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
snprintf(l->err_buf, LIBNET_ERRBUF_SIZE,
|
|
Packit |
03b34a |
"%s(): options list is too large %d\n", __func__, options_s);
|
|
Packit |
03b34a |
return (-1);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
adj_size = options_s;
|
|
Packit |
03b34a |
if (adj_size % 4)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
/* size of memory block with padding */
|
|
Packit |
03b34a |
adj_size += 4 - (options_s % 4);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
/* if this pblock already exists, determine if there is a size diff */
|
|
Packit |
03b34a |
if (ptag)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
p_temp = libnet_pblock_find(l, ptag);
|
|
Packit |
03b34a |
if (p_temp)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
if (adj_size >= p_temp->b_len)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
offset = adj_size - p_temp->b_len;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
else
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
offset = p_temp->b_len - adj_size;
|
|
Packit |
03b34a |
underflow = 1;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
/*
|
|
Packit |
03b34a |
* Find the existing protocol block if a ptag is specified, or create
|
|
Packit |
03b34a |
* a new one.
|
|
Packit |
03b34a |
*/
|
|
Packit |
03b34a |
p = libnet_pblock_probe(l, ptag, adj_size, LIBNET_PBLOCK_TCPO_H);
|
|
Packit |
03b34a |
if (p == NULL)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
return (-1);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
n = libnet_pblock_append(l, p, options, options_s);
|
|
Packit |
03b34a |
if (n == -1)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
goto bad;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
n = libnet_pblock_append(l, p, padding, adj_size - options_s);
|
|
Packit |
03b34a |
if (n == -1)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
goto bad;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
if (ptag && p->next)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
p_temp = p->next;
|
|
Packit |
03b34a |
while ((p_temp->next) && (p_temp->type != LIBNET_PBLOCK_TCP_H))
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
p_temp = p_temp->next;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
if (p_temp->type == LIBNET_PBLOCK_TCP_H)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
/*
|
|
Packit |
03b34a |
* Count up number of 32-bit words in options list, padding if
|
|
Packit |
03b34a |
* neccessary.
|
|
Packit |
03b34a |
*/
|
|
Packit |
03b34a |
for (i = 0, j = 0; i < p->b_len; i++)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
(i % 4) ? j : j++;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
tcp_hdr = (struct libnet_tcp_hdr *)p_temp->buf;
|
|
Packit |
03b34a |
tcp_hdr->th_off = j + 5;
|
|
Packit |
03b34a |
if (!underflow)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
p_temp->h_len += offset;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
else
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
p_temp->h_len -= offset;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
while ((p_temp->next) && (p_temp->type != LIBNET_PBLOCK_IPV4_H))
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
p_temp = p_temp->next;
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
if (p_temp->type == LIBNET_PBLOCK_IPV4_H)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
ip_hdr = (struct libnet_ipv4_hdr *)p_temp->buf;
|
|
Packit |
03b34a |
if (!underflow)
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
ip_hdr->ip_len += htons(offset);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
else
|
|
Packit |
03b34a |
{
|
|
Packit |
03b34a |
ip_hdr->ip_len -= htons(offset);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
return (ptag ? ptag : libnet_pblock_update(l, p, adj_size,
|
|
Packit |
03b34a |
LIBNET_PBLOCK_TCPO_H));
|
|
Packit |
03b34a |
bad:
|
|
Packit |
03b34a |
libnet_pblock_delete(l, p);
|
|
Packit |
03b34a |
return (-1);
|
|
Packit |
03b34a |
}
|
|
Packit |
03b34a |
|
|
Packit |
03b34a |
/* EOF */
|