srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2025-11-18 22:04:00 +0200
committersrdusr <[email protected]>2025-11-18 22:04:00 +0200
commita8f4866576fd70894ef0080c7797708db664880e (patch)
tree4a3e0c7cd6f6f585c8e58fa0b3d721dbe5250343 /PLAN.md
parent3af3e356d6fdf43e6772dc2e91b322f8e8148f62 (diff)
downloadpacketeer-a8f4866576fd70894ef0080c7797708db664880e.tar.gz
packeteer-a8f4866576fd70894ef0080c7797708db664880e.zip
Add SNMP (v1/v2c) with a minimal local ASN.1 BER reader
First dissector needing actual ASN.1 decoding - a small local tag/length/value reader, not a general ASN.1 decoder, just enough to walk SNMP's own SEQUENCE/INTEGER/OCTET STRING structure. v3 wraps the PDU in its own security-parameters header instead of a plain community string and can be encrypted, so it's reported by version alone, the same "don't take on real crypto" call already made for TLS/QUIC. Community strings are shown as-is, matching FTP's PASS precedent -- v1/v2c send them in the clear regardless. SnmpDissector takes its port in the constructor so it can be registered twice, at 161 (agent) and 162 (trap receiver). Unlike DHCP's 67/68, trap traffic never touches 161 on either side (ephemeral source port straight to 162), so there's no shared port for l7_summarize()'s dst-then-src fallback to land on - both ports need explicit registration. Live-verified against a real snmpd (net-snmp 5.9.5.2) on loopback: a real snmpget GetRequest/GetResponse exchange decoded correctly with matching request-ids across both directions, and a real snmptrap SNMPv2-Trap on port 162 confirmed the second registered port actually gets used.
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md24
1 files changed, 23 insertions, 1 deletions
diff --git a/PLAN.md b/PLAN.md
index 392e02e..50d4981 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -31,7 +31,7 @@ unowned buffers) via a real-world capture pipeline.
4. [done] Bounded channel + drop-on-backpressure between capture and render
5. [in progress] L7 dissector interface, add protocols incrementally --
interface + DNS + HTTP + TLS SNI + mDNS + SSH banner + NTP + DHCP +
- FTP + SMTP + TFTP + QUIC done (packeteer/l7/); ARP/VLAN/IGMP done
+ FTP + SMTP + TFTP + QUIC + SNMP done (packeteer/l7/); ARP/VLAN/IGMP done
at the L2/L3 level too (packeteer/net/); more protocols can still
be added incrementally,
by design
@@ -540,3 +540,25 @@ None currently open.
This also serves as a real-traffic confirmation that the
L7Registry fix works: without it, none of this would have decoded
at all, since tls_dissector claims port 443 first.
+- SNMP (l7/snmp.hpp), scoped to v1/v2c - the first dissector needing
+ actual ASN.1 BER decoding, via a small local TLV reader (tag/length/
+ value only, not a general ASN.1 decoder: no indefinite-length
+ encoding, no multi-byte tag numbers, nothing beyond what SNMP's own
+ SEQUENCE/INTEGER/OCTET STRING structure uses). v3 wraps the PDU in
+ its own security-parameters header instead of a plain community
+ string, and the PDU can be encrypted - reported by version alone,
+ not decoded further, the same "don't take on real crypto" call as
+ TLS/QUIC. Community strings are shown as-is, not redacted: v1/v2c
+ send them in the clear regardless, same reasoning as FTP's PASS.
+ SnmpDissector takes its port in the constructor rather than a fixed
+ override, so it's registered twice - 161 (agent) and 162 (trap
+ receiver). Unlike DHCP's 67/68, there's no port shared by both
+ directions for l7_summarize()'s dst-then-src fallback to land on: a
+ trap goes from an ephemeral source port straight to 162, touching
+ 161 nowhere at all, so both had to be registered explicitly rather
+ than relying on the fallback the way DHCP could.
+ Live-verified against a real snmpd (net-snmp 5.9.5.2) on loopback: a
+ real `snmpget` GetRequest/GetResponse exchange on port 161 decoded
+ correctly with matching request-ids across both directions, and a
+ real `snmptrap` SNMPv2-Trap on port 162 confirmed the second
+ registered port actually gets used, not just the first.