2 * netsniff-ng - the packet sniffing beast
3 * Copyright 2011 Daniel Borkmann.
4 * Subject to the GPL, version 2.
15 #include <netinet/in.h>
16 #include <sys/socket.h>
17 #include <netinet/in.h>
18 #include <arpa/inet.h>
19 #include <sys/select.h>
25 extern int print_stun_probe(char *server
, int sport
, int tport
);
27 #define BINDING_REQUEST 0x0001
28 #define BINDING_RESPONSE 0x0101
30 #define MAPPED_ADDRESS 0x0001
33 #define REQUEST_LEN 20
35 #define ID_COOKIE_FIELD htonl(((int) 'a' << 24) + \
43 uint32_t magic_cookie
;
53 struct stun_mapped_addr
{
60 static int stun_test(const char *server_ip
, int server_port
,
68 struct timeval timeout
;
69 struct stun_header
*hdr
, *rhdr
;
70 struct stun_attrib
*attr
;
71 struct stun_mapped_addr
*addr
;
72 struct sockaddr_in saddr
, daddr
;
78 sock
= socket(PF_INET
, SOCK_DGRAM
, IPPROTO_UDP
);
80 panic("Cannot obtain socket!\n");
84 saddr
.sin_family
= PF_INET
;
85 saddr
.sin_port
= htons(tun_port
);
86 saddr
.sin_addr
.s_addr
= INADDR_ANY
;
88 ret
= bind(sock
, (struct sockaddr
*) &saddr
, sizeof(saddr
));
90 panic("Cannot bind udp socket!\n");
93 hdr
= (struct stun_header
*) pkt
;
94 hdr
->type
= htons(BINDING_REQUEST
);
96 hdr
->magic_cookie
= ID_COOKIE_FIELD
;
97 hdr
->transid
[0] = htonl(rand());
98 hdr
->transid
[1] = htonl(rand());
99 hdr
->transid
[2] = htonl(rand());
101 daddr
.sin_family
= PF_INET
;
102 daddr
.sin_port
= htons(server_port
);
103 daddr
.sin_addr
.s_addr
= inet_addr(server_ip
);
105 ret
= sendto(sock
, pkt
, len
, 0, (struct sockaddr
*) &daddr
,
108 printf("Error sending request (%s)!\n", strerror(errno
));
112 timeout
.tv_sec
= TIMEOUT
/ 1000;
113 timeout
.tv_usec
= (TIMEOUT
% 1000) * 1000;
116 FD_SET(sock
, &fdset
);
118 ret
= select(sock
+ 1, &fdset
, NULL
, NULL
, &timeout
);
120 printf("STUN server timeout!\n");
124 memset(rpkt
, 0, sizeof(rpkt
));
125 len
= read(sock
, rpkt
, sizeof(rpkt
));
129 if (len
< REQUEST_LEN
) {
130 printf("Bad STUN response (%s)!\n", strerror(errno
));
134 rhdr
= (struct stun_header
*) rpkt
;
135 if (ntohs(rhdr
->type
) != BINDING_RESPONSE
) {
136 printf("Wrong STUN response type!\n");
140 if (rhdr
->len
== 0) {
141 printf("No attributes in STUN response!\n");
145 if (rhdr
->magic_cookie
!= hdr
->magic_cookie
||
146 rhdr
->transid
[0] != hdr
->transid
[0] ||
147 rhdr
->transid
[1] != hdr
->transid
[1] ||
148 rhdr
->transid
[2] != hdr
->transid
[2]) {
149 printf("Got wrong STUN transaction id!\n");
154 max
= ntohs(rhdr
->len
) + REQUEST_LEN
;
156 while (off
+ 8 < max
) {
157 attr
= (struct stun_attrib
*) (rpkt
+ off
);
158 if (ntohs(attr
->type
) != MAPPED_ADDRESS
)
161 addr
= (struct stun_mapped_addr
*) (rpkt
+ off
+ 4);
162 if (addr
->family
!= 0x1)
165 in
.s_addr
= addr
->ip
;
166 printf("Public mapping %s:%u!\n",
167 inet_ntoa(in
), ntohs(addr
->port
));
171 off
+= ntohs(attr
->len
);
177 int print_stun_probe(char *server
, int sport
, int tport
)
182 printf("STUN on %s:%u\n", server
, sport
);
185 hp
= gethostbyname(server
);
188 address
= inet_ntoa(*(struct in_addr
*) hp
->h_addr_list
[0]);
189 return stun_test(address
, sport
, tport
);