diff options
| author | srdusr <[email protected]> | 2025-07-01 00:40:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2025-07-01 00:40:00 +0200 |
| commit | 407249eb5d654b5a951c43bc1722fd397d5d922c (patch) | |
| tree | c367bf95c3855152d477a7eed5e709b3094a427c /tests/test_ftp.cpp | |
| parent | 9046e6a10fd2d987cf6f6dc601ed3a75d286793f (diff) | |
| download | packeteer-407249eb5d654b5a951c43bc1722fd397d5d922c.tar.gz packeteer-407249eb5d654b5a951c43bc1722fd397d5d922c.zip | |
Add FTP, SMTP, TFTP, and IGMP; fix an IGMPv3 group-address misparse
FTP and SMTP share HTTP's line-based response-code-or-command shape
but keep their own command vocabularies in separate files rather than
sharing a parser. FTP passwords are shown as-is, not redacted - FTP
sends them in the clear regardless, matching Wireshark's own behavior.
TFTP is a small binary opcode protocol (RFC 1350) instead. IGMP sits
directly on IP like ICMP, so it's dispatched by protocol number rather
than through the port-keyed L7Registry the other three use.
Live-verified: FTP/SMTP against minimal real TCP servers written for
this (nothing installed locally), a full command/response exchange
decoded correctly in both directions. TFTP against a real atftpd
server and atftp client - the RRQ decoded correctly even though the
transfer itself didn't complete (an atftpd sandbox issue, not this
code). IGMP against real multicast traffic on wlp1s0, including a
genuine query from the actual router.
That live IGMP traffic caught a real bug before it shipped further:
parse_igmp() read bytes[4:8] as a group address for every message
type, but IGMPv3 reports use those bytes for Reserved+RecordCount
instead - a real V3 report showed "group=0.0.0.1" (0 reserved, 1
record, misread as an IP). Fixed by only populating group for the
types where it's genuinely an address; re-verified against the same
live traffic, and a regression test locks in the exact pattern.
Diffstat (limited to 'tests/test_ftp.cpp')
| -rw-r--r-- | tests/test_ftp.cpp | 51 |
1 files changed, 51 insertions, 0 deletions
diff --git a/tests/test_ftp.cpp b/tests/test_ftp.cpp new file mode 100644 index 0000000..0015f42 --- /dev/null +++ b/tests/test_ftp.cpp @@ -0,0 +1,51 @@ +#include <doctest/doctest.h> + +#include <vector> + +#include "packeteer/l7/ftp.hpp" + +using namespace packeteer::net; + +namespace { + +std::vector<unsigned char> to_bytes(const std::string& s) { + return std::vector<unsigned char>(s.begin(), s.end()); +} + +} // namespace + +TEST_CASE("parse_ftp decodes a greeting response") { + auto msg = parse_ftp(to_bytes("220 (vsFTPd 3.0.5)\r\n")); + REQUIRE(msg.has_value()); + CHECK(msg->is_response); + CHECK(msg->command_or_code == "220"); + CHECK(msg->argument == "(vsFTPd 3.0.5)"); +} + +TEST_CASE("parse_ftp decodes a USER command") { + auto msg = parse_ftp(to_bytes("USER anonymous\r\n")); + REQUIRE(msg.has_value()); + CHECK_FALSE(msg->is_response); + CHECK(msg->command_or_code == "USER"); + CHECK(msg->argument == "anonymous"); +} + +TEST_CASE("parse_ftp decodes a command with no argument") { + auto msg = parse_ftp(to_bytes("PASV\r\n")); + REQUIRE(msg.has_value()); + CHECK(msg->command_or_code == "PASV"); + CHECK(msg->argument.empty()); +} + +TEST_CASE("parse_ftp rejects an unrecognized command word") { + CHECK_FALSE(parse_ftp(to_bytes("BOGUS foo\r\n")).has_value()); +} + +TEST_CASE("FtpDissector claims port 21 and formats command and argument together") { + FtpDissector dissector; + CHECK(dissector.port() == kFtpPort); + + auto summary = dissector.summarize(to_bytes("RETR file.txt\r\n")); + REQUIRE(summary.has_value()); + CHECK(*summary == "FTP RETR file.txt"); +} |