-
Notifications
You must be signed in to change notification settings - Fork 2
/
dissectors.go
128 lines (113 loc) · 4.94 KB
/
dissectors.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
//
// Copyright (c) 2023 Christian Pointner <[email protected]>
// All rights reserved.
//
// Redistribution and use in source and binary forms, with or without
// modification, are permitted provided that the following conditions are met:
//
// * Redistributions of source code must retain the above copyright notice, this
// list of conditions and the following disclaimer.
//
// * Redistributions in binary form must reproduce the above copyright notice,
// this list of conditions and the following disclaimer in the documentation
// and/or other materials provided with the distribution.
//
// * Neither the name of whawty.auth nor the names of its
// contributors may be used to endorse or promote products derived from
// this software without specific prior written permission.
//
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
// AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
// IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
// DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
// FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
// DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
// SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
// CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
// OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
//
package main
import (
"fmt"
"os"
"strconv"
"golang.org/x/net/icmp"
"golang.org/x/net/ipv4"
"golang.org/x/net/ipv6"
tcpip "gvisor.dev/gvisor/pkg/tcpip/header"
)
func dissectIPv4(packet []byte) ([]Property, Dissector, []byte) {
header, err := ipv4.ParseHeader(packet)
if err != nil {
fmt.Fprintf(os.Stderr, "unable to parse IPv4 header: %v\n", err)
return nil, nil, packet
}
var props []Property
props = append(props, Property{"ipv4/length", strconv.Itoa(header.TotalLen)})
props = append(props, Property{"ipv4/src", header.Src.String()})
props = append(props, Property{"ipv4/dst", header.Dst.String()})
proto, next := lookupIPProto(header.Protocol)
props = append(props, Property{"ipv4/protocol", proto})
return props, next, packet[ipv4.HeaderLen:]
}
func dissectIPv6(packet []byte) ([]Property, Dissector, []byte) {
header, err := ipv6.ParseHeader(packet)
if err != nil {
fmt.Fprintf(os.Stderr, "unable to parse IPv6 header: %v\n", err)
return nil, nil, packet
}
var props []Property
props = append(props, Property{"ipv6/payload-length", strconv.Itoa(header.PayloadLen)})
props = append(props, Property{"ipv6/src", header.Src.String()})
props = append(props, Property{"ipv6/dst", header.Dst.String()})
proto, next := lookupIPProto(header.NextHeader)
props = append(props, Property{"ipv6/next-header", proto})
return props, next, packet[ipv6.HeaderLen:]
}
func dissectICMP(packet []byte) ([]Property, Dissector, []byte) {
message, err := icmp.ParseMessage(1, packet) // golang.org/x/net/internal/iana -> ProtocolICMP = 1
if err != nil {
fmt.Fprintf(os.Stderr, "unable to parse ICMP message: %v\n", err)
return nil, nil, packet
}
msgType, _ := message.Type.(ipv4.ICMPType)
var props []Property
props = append(props, Property{"icmp/type", msgType.String()})
props = append(props, Property{"icmp/code", strconv.Itoa(message.Code)})
return props, nil, packet[ipv6.HeaderLen:]
}
func dissectICMPv6(packet []byte) ([]Property, Dissector, []byte) {
message, err := icmp.ParseMessage(58, packet) // golang.org/x/net/internal/iana -> ProtocolIPv6ICMP = 58
if err != nil {
fmt.Fprintf(os.Stderr, "unable to parse ICMP message: %v\n", err)
return nil, nil, packet
}
msgType, _ := message.Type.(ipv6.ICMPType)
var props []Property
props = append(props, Property{"icmpv6/type", msgType.String()})
props = append(props, Property{"icmpv6/code", strconv.Itoa(message.Code)})
return props, nil, packet[ipv6.HeaderLen:]
}
func dissectUDP(packet []byte) ([]Property, Dissector, []byte) {
if len(packet) < tcpip.UDPMinimumSize {
fmt.Fprintf(os.Stderr, "unable to parse UDP message: packet is too short\n")
return nil, nil, packet
}
udpPacket := tcpip.UDP(packet)
var props []Property
props = append(props, Property{"udp/sport", strconv.Itoa(int(udpPacket.SourcePort()))})
props = append(props, Property{"udp/dport", strconv.Itoa(int(udpPacket.DestinationPort()))})
return props, nil, udpPacket.Payload()
}
func dissectTCP(packet []byte) ([]Property, Dissector, []byte) {
if len(packet) < tcpip.TCPMinimumSize {
fmt.Fprintf(os.Stderr, "unable to parse TCP message: packet is too short\n")
return nil, nil, packet
}
tcpPacket := tcpip.TCP(packet)
var props []Property
props = append(props, Property{"tcp/sport", strconv.Itoa(int(tcpPacket.SourcePort()))})
props = append(props, Property{"tcp/dport", strconv.Itoa(int(tcpPacket.DestinationPort()))})
return props, nil, tcpPacket.Payload()
}