diff options
| author | srdusr <[email protected]> | 2025-11-18 22:04:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2025-11-18 22:04:00 +0200 |
| commit | a8f4866576fd70894ef0080c7797708db664880e (patch) | |
| tree | 4a3e0c7cd6f6f585c8e58fa0b3d721dbe5250343 /tests/test_dhcp.cpp | |
| parent | 3af3e356d6fdf43e6772dc2e91b322f8e8148f62 (diff) | |
| download | packeteer-a8f4866576fd70894ef0080c7797708db664880e.tar.gz packeteer-a8f4866576fd70894ef0080c7797708db664880e.zip | |
Add SNMP (v1/v2c) with a minimal local ASN.1 BER reader
First dissector needing actual ASN.1 decoding - a small local
tag/length/value reader, not a general ASN.1 decoder, just enough to
walk SNMP's own SEQUENCE/INTEGER/OCTET STRING structure. v3 wraps the
PDU in its own security-parameters header instead of a plain community
string and can be encrypted, so it's reported by version alone, the
same "don't take on real crypto" call already made for TLS/QUIC.
Community strings are shown as-is, matching FTP's PASS precedent --
v1/v2c send them in the clear regardless.
SnmpDissector takes its port in the constructor so it can be
registered twice, at 161 (agent) and 162 (trap receiver). Unlike
DHCP's 67/68, trap traffic never touches 161 on either side (ephemeral
source port straight to 162), so there's no shared port for
l7_summarize()'s dst-then-src fallback to land on - both ports need
explicit registration.
Live-verified against a real snmpd (net-snmp 5.9.5.2) on loopback: a
real snmpget GetRequest/GetResponse exchange decoded correctly with
matching request-ids across both directions, and a real snmptrap
SNMPv2-Trap on port 162 confirmed the second registered port actually
gets used.
Diffstat (limited to 'tests/test_dhcp.cpp')
0 files changed, 0 insertions, 0 deletions