diff options
| author | srdusr <[email protected]> | 2024-05-27 22:00:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2024-05-27 22:00:00 +0200 |
| commit | b565d7d9c47ca1ec5af0effd828431ee96027d60 (patch) | |
| tree | fbe0c9c897e78f507443507354d5b1d8fb851099 /include/wireframe/l7/ssh.hpp | |
| parent | fbedc55d5aa861c381701c9f913b34ee7ab57ec4 (diff) | |
| download | packeteer-b565d7d9c47ca1ec5af0effd828431ee96027d60.tar.gz packeteer-b565d7d9c47ca1ec5af0effd828431ee96027d60.zip | |
Rename project from wireframe to packeteer
Decided on the name after weighing alternatives in NAMES.md: packeteer
(packet + -eer, "one who wields packets") fit the project's actual
scope better than the wire/frame pun once it had grown into full
L2-L7 dissection, reassembly, checksums, privilege dropping, and dual
TUI/GUI frontends. No existing packet-capture project uses the name;
the one real-world collision (Packeteer, Inc., a networking company
acquired and folded into Blue Coat/Symantec by 2008) is long defunct.
Mechanical rename throughout: CMake project/target names, the
wireframe:: namespace and include/wireframe/ directory (git mv,
history preserved), every #include path, CLI/GUI help text, and the
project's own working directory. NAMES.md rewritten to record the
decision instead of leaving stale self-referential etymology behind
from the blind rename pass.
Verified after every step: full rebuild (all four targets, no
warnings) and the full test suite (128/128 cases, 366/366 assertions)
both from a fresh reconfigure and again after the directory move.
Diffstat (limited to 'include/wireframe/l7/ssh.hpp')
| -rw-r--r-- | include/wireframe/l7/ssh.hpp | 65 |
1 files changed, 0 insertions, 65 deletions
diff --git a/include/wireframe/l7/ssh.hpp b/include/wireframe/l7/ssh.hpp deleted file mode 100644 index efa471f..0000000 --- a/include/wireframe/l7/ssh.hpp +++ /dev/null @@ -1,65 +0,0 @@ -#pragma once - -#include <cstdint> -#include <optional> -#include <span> -#include <string> -#include <string_view> - -#include "wireframe/l7/dissector.hpp" - -// SSH's identification exchange (RFC 4253 section 4.2) is the one part -// of an SSH connection sent in the clear, before key exchange starts -// encrypting everything: both sides open with a single line of the -// form "SSH-protoversion-softwareversion[ comments]" terminated by -// CR LF (a bare LF is tolerated too, same leniency this project's HTTP -// dissector already uses). Only that first line is ever readable -- -// everything after key exchange is opaque, so this dissector only ever -// has one line to look at, on either side of the connection. -namespace wireframe::net { - -inline constexpr std::uint16_t kSshPort = 22; - -struct SshBanner { - std::string proto_version; - std::string software_version; -}; - -inline std::optional<SshBanner> parse_ssh_banner(std::span<const unsigned char> payload) { - std::string_view text(reinterpret_cast<const char*>(payload.data()), payload.size()); - if (text.substr(0, 4) != "SSH-") return std::nullopt; - - std::size_t line_end = text.find("\r\n"); - if (line_end == std::string_view::npos) { - line_end = text.find('\n'); - if (line_end == std::string_view::npos) return std::nullopt; - } - std::string_view line = text.substr(4, line_end - 4); // past "SSH-" - - std::size_t dash = line.find('-'); - if (dash == std::string_view::npos) return std::nullopt; - - SshBanner banner; - banner.proto_version = std::string(line.substr(0, dash)); - - // The software version runs up to the first space (start of an - // optional comment) or the end of the line, whichever is first. - std::string_view rest = line.substr(dash + 1); - std::size_t space = rest.find(' '); - banner.software_version = std::string(space == std::string_view::npos ? rest - : rest.substr(0, space)); - return banner; -} - -class SshDissector : public L7Dissector { -public: - std::uint16_t port() const override { return kSshPort; } - - std::optional<std::string> summarize(std::span<const unsigned char> payload) const override { - auto banner = parse_ssh_banner(payload); - if (!banner) return std::nullopt; - return "SSH " + banner->proto_version + " " + banner->software_version; - } -}; - -} // namespace wireframe::net |