2 * (C)opyright 1992-1998 Darren Reed. (from tcplog)
4 * See the IPFILTER.LICENCE file for details on licencing.
14 #include <sys/types.h>
16 #include <sys/timeb.h>
17 #include <sys/socket.h>
19 #include <sys/ioctl.h>
20 #include <sys/stropts.h>
22 #include <sys/pfmod.h>
23 #include <sys/bufmod.h>
27 #include <netinet/in.h>
28 #include <netinet/in_systm.h>
29 #include <netinet/ip.h>
30 #include <netinet/if_ether.h>
31 #include <netinet/ip_var.h>
32 #include <netinet/udp.h>
33 #include <netinet/udp_var.h>
34 #include <netinet/tcp.h>
35 #include <netinet/tcpip.h>
37 #include "ip_compat.h"
40 static char snitid
[] = "%W% %G% (C)1995 Darren Reed";
43 #define BUFSPACE 32768
48 * Be careful to only include those defined in the flags option for the
49 * interface are included in the header size.
68 tcp
= (tcphdr_t
*)(ip
+ 1);
69 bcopy(ep
, (char *)ip
, sizeof(*ip
));
70 bcopy(ep
+ (ip
->ip_hl
<< 2), (char *)tcp
, sizeof(*tcp
));
72 if (ip
->ip_off
& 0x1fff != 0)
74 if (0 == detect(ip
, tcp
))
80 int readloop(fd
, port
, dst
)
84 static u_char buf
[BUFSPACE
];
85 register u_char
*bp
, *cp
, *bufend
;
86 register struct sb_hdr
*hp
;
90 time_t now
= time(NULL
);
91 int flags
= 0, i
, done
= 0;
96 dbuf
.maxlen
= sizeof(buf
);
98 * no control data buffer...
101 (void) signal(SIGALRM
, nullbell
);
103 i
= getmsg(fd
, NULL
, &dbuf
, &flags
);
105 (void) signal(SIGALRM
, nullbell
);
108 if ((time(NULL
) - now
) > timeout
)
118 * loop through each snapshot in the chunk
120 while (bp
< bufend
) {
122 * get past bufmod header
124 hp
= (struct sb_hdr
*)bp
;
125 cp
= (u_char
*)((char *)bp
+ sizeof(*hp
));
126 bcopy(cp
, (char *)&eh
, sizeof(eh
));
130 bp
+= hp
->sbh_totlen
;
131 cc
-= hp
->sbh_totlen
;
133 if (eh
.ether_type
!= ETHERTYPE_IP
)
137 done
+= ack_recv(cp
);
145 int initdevice(device
, tout
)
152 struct packetfilt pfil
;
154 u_short
*fwp
= pfil
.Pf_Filter
;
155 char devname
[16], *s
, buf
[256];
156 int i
, offset
, fd
, snaplen
= 58, chunksize
= BUFSPACE
;
158 (void) sprintf(devname
, "/dev/%s", device
);
161 while (*s
&& !isdigit(*s
))
165 fprintf(stderr
, "bad device name %s\n", devname
);
173 if ((fd
= open(devname
, O_RDWR
)) < 0)
175 fprintf(stderr
, "O_RDWR(0) ");
179 if (dlattachreq(fd
, i
) == -1 || dlokack(fd
, buf
) == -1)
181 fprintf(stderr
, "DLPI error\n");
184 dlbindreq(fd
, ETHERTYPE_IP
, 0, DL_CLDLS
, 0, 0);
189 if (strioctl(fd
, DLIOCRAW
, -1, 0, NULL
) == -1)
191 fprintf(stderr
, "DLIOCRAW error\n");
195 * Create some filter rules for our TCP watcher. We only want ethernet
196 * pacets which are IP protocol and only the TCP packets from IP.
199 *fwp
++ = ENF_PUSHWORD
+ offset
;
200 *fwp
++ = ENF_PUSHLIT
| ENF_CAND
;
201 *fwp
++ = htons(ETHERTYPE_IP
);
202 *fwp
++ = ENF_PUSHWORD
+ sizeof(struct ether_header
)/sizeof(short)+4;
203 *fwp
++ = ENF_PUSHLIT
| ENF_AND
;
204 *fwp
++ = htons(0x00ff);
205 *fwp
++ = ENF_PUSHLIT
| ENF_COR
;
206 *fwp
++ = htons(IPPROTO_TCP
);
207 *fwp
++ = ENF_PUSHWORD
+ sizeof(struct ether_header
)/sizeof(short)+4;
208 *fwp
++ = ENF_PUSHLIT
| ENF_AND
;
209 *fwp
++ = htons(0x00ff);
210 *fwp
++ = ENF_PUSHLIT
| ENF_CAND
;
211 *fwp
++ = htons(IPPROTO_UDP
);
212 pfil
.Pf_FilterLen
= (fwp
- &pfil
.Pf_Filter
[0]);
214 * put filter in place.
217 if (ioctl(fd
, I_PUSH
, "pfmod") == -1)
219 perror("ioctl: I_PUSH pf");
222 if (strioctl(fd
, PFIOCSETF
, -1, sizeof(pfil
), (char *)&pfil
) == -1)
224 perror("ioctl: PFIOCSETF");
229 * arrange to get messages from the NIT STREAM and use NIT_BUF option
231 if (ioctl(fd
, I_PUSH
, "bufmod") == -1)
233 perror("ioctl: I_PUSH bufmod");
237 strioctl(fd
, SBIOCSSNAP
, -1, sizeof(i
), (char *)&i
);
243 if (strioctl(fd
, SBIOCSTIME
, -1, sizeof(to
), (char *)&to
) == -1)
245 perror("strioctl(SBIOCSTIME)");
251 if (ioctl(fd
, I_FLUSH
, FLUSHR
) == -1)