diff options
| author | srdusr <[email protected]> | 2024-05-21 22:24:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2024-05-21 22:24:00 +0200 |
| commit | fbedc55d5aa861c381701c9f913b34ee7ab57ec4 (patch) | |
| tree | d34c3648b61d417f2a5d8690e0eb4a76bd64c943 /include/wireframe/l7/ssh.hpp | |
| parent | e0f4c701028aa81026a17cf9ebfb36112184f4bc (diff) | |
| download | packeteer-fbedc55d5aa861c381701c9f913b34ee7ab57ec4.tar.gz packeteer-fbedc55d5aa861c381701c9f913b34ee7ab57ec4.zip | |
Add GUI parity for -c/-a, mDNS/SSH dissectors, and two new fuzz harnesses
GUI parity: checksum_status()/reassembled_http_status() moved out of
main.cpp into a shared wireframe/packet_diagnostics.hpp so the GUI can
show the same -c/-a diagnostics for the selected packet without
duplicating the Ethernet/IPv4/TCP walk. Visually verified under Xvfb
with the same split-segment scenario used to verify -a on the CLI.
Two new L7 dissectors: mDNS (reuses parse_dns outright - RFC 6762
keeps DNS's wire format, just a different port) and SSH's cleartext
identification banner. Live-verified against this machine's real
sshd and a real DNS-wire-format packet sent to port 5353.
Two new fuzz harnesses (fuzz_checksum, fuzz_tcp_reassembly) covering
code added here that the original nine harnesses never
touched. All 12 run clean across ~90M executions with no crashes.
NAMES.md and PLAN.md updated with this round's decisions and naming
candidates.
Diffstat (limited to 'include/wireframe/l7/ssh.hpp')
| -rw-r--r-- | include/wireframe/l7/ssh.hpp | 65 |
1 files changed, 65 insertions, 0 deletions
diff --git a/include/wireframe/l7/ssh.hpp b/include/wireframe/l7/ssh.hpp new file mode 100644 index 0000000..efa471f --- /dev/null +++ b/include/wireframe/l7/ssh.hpp @@ -0,0 +1,65 @@ +#pragma once + +#include <cstdint> +#include <optional> +#include <span> +#include <string> +#include <string_view> + +#include "wireframe/l7/dissector.hpp" + +// SSH's identification exchange (RFC 4253 section 4.2) is the one part +// of an SSH connection sent in the clear, before key exchange starts +// encrypting everything: both sides open with a single line of the +// form "SSH-protoversion-softwareversion[ comments]" terminated by +// CR LF (a bare LF is tolerated too, same leniency this project's HTTP +// dissector already uses). Only that first line is ever readable -- +// everything after key exchange is opaque, so this dissector only ever +// has one line to look at, on either side of the connection. +namespace wireframe::net { + +inline constexpr std::uint16_t kSshPort = 22; + +struct SshBanner { + std::string proto_version; + std::string software_version; +}; + +inline std::optional<SshBanner> parse_ssh_banner(std::span<const unsigned char> payload) { + std::string_view text(reinterpret_cast<const char*>(payload.data()), payload.size()); + if (text.substr(0, 4) != "SSH-") return std::nullopt; + + std::size_t line_end = text.find("\r\n"); + if (line_end == std::string_view::npos) { + line_end = text.find('\n'); + if (line_end == std::string_view::npos) return std::nullopt; + } + std::string_view line = text.substr(4, line_end - 4); // past "SSH-" + + std::size_t dash = line.find('-'); + if (dash == std::string_view::npos) return std::nullopt; + + SshBanner banner; + banner.proto_version = std::string(line.substr(0, dash)); + + // The software version runs up to the first space (start of an + // optional comment) or the end of the line, whichever is first. + std::string_view rest = line.substr(dash + 1); + std::size_t space = rest.find(' '); + banner.software_version = std::string(space == std::string_view::npos ? rest + : rest.substr(0, space)); + return banner; +} + +class SshDissector : public L7Dissector { +public: + std::uint16_t port() const override { return kSshPort; } + + std::optional<std::string> summarize(std::span<const unsigned char> payload) const override { + auto banner = parse_ssh_banner(payload); + if (!banner) return std::nullopt; + return "SSH " + banner->proto_version + " " + banner->software_version; + } +}; + +} // namespace wireframe::net |