From b565d7d9c47ca1ec5af0effd828431ee96027d60 Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Mon, 27 May 2024 22:00:00 +0200 Subject: Rename project from wireframe to packeteer Decided on the name after weighing alternatives in NAMES.md: packeteer (packet + -eer, "one who wields packets") fit the project's actual scope better than the wire/frame pun once it had grown into full L2-L7 dissection, reassembly, checksums, privilege dropping, and dual TUI/GUI frontends. No existing packet-capture project uses the name; the one real-world collision (Packeteer, Inc., a networking company acquired and folded into Blue Coat/Symantec by 2008) is long defunct. Mechanical rename throughout: CMake project/target names, the wireframe:: namespace and include/wireframe/ directory (git mv, history preserved), every #include path, CLI/GUI help text, and the project's own working directory. NAMES.md rewritten to record the decision instead of leaving stale self-referential etymology behind from the blind rename pass. Verified after every step: full rebuild (all four targets, no warnings) and the full test suite (128/128 cases, 366/366 assertions) both from a fresh reconfigure and again after the directory move. --- include/wireframe/l7/dissector.hpp | 45 ------------ include/wireframe/l7/dns.hpp | 108 ---------------------------- include/wireframe/l7/http.hpp | 113 ------------------------------ include/wireframe/l7/mdns.hpp | 44 ------------ include/wireframe/l7/ssh.hpp | 65 ----------------- include/wireframe/l7/tls.hpp | 139 ------------------------------------- 6 files changed, 514 deletions(-) delete mode 100644 include/wireframe/l7/dissector.hpp delete mode 100644 include/wireframe/l7/dns.hpp delete mode 100644 include/wireframe/l7/http.hpp delete mode 100644 include/wireframe/l7/mdns.hpp delete mode 100644 include/wireframe/l7/ssh.hpp delete mode 100644 include/wireframe/l7/tls.hpp (limited to 'include/wireframe/l7') diff --git a/include/wireframe/l7/dissector.hpp b/include/wireframe/l7/dissector.hpp deleted file mode 100644 index 9b2cc32..0000000 --- a/include/wireframe/l7/dissector.hpp +++ /dev/null @@ -1,45 +0,0 @@ -#pragma once - -#include -#include -#include -#include -#include - -// Small interface/vtable for L7 dissectors (PLAN.md's architecture -// sketch), so protocols can be registered and added incrementally -// without touching the L2-L4 decode path or main.cpp's dispatch logic. -namespace wireframe::net { - -class L7Dissector { -public: - virtual ~L7Dissector() = default; - - // The transport port this dissector claims (e.g. 53 for DNS). A - // single fixed port is enough for the protocols in scope so far; - // dissectors needing a port range or heuristic sniffing can widen - // this later without changing the registry's shape. - virtual std::uint16_t port() const = 0; - - // A one-line summary of the payload, or nullopt if it doesn't look - // like this protocol (e.g. truncated/malformed). - virtual std::optional summarize(std::span payload) const = 0; -}; - -class L7Registry { -public: - void add(const L7Dissector* dissector) { dissectors_.push_back(dissector); } - - std::optional dissect(std::uint16_t port, - std::span payload) const { - for (const auto* dissector : dissectors_) { - if (dissector->port() == port) return dissector->summarize(payload); - } - return std::nullopt; - } - -private: - std::vector dissectors_; -}; - -} // namespace wireframe::net diff --git a/include/wireframe/l7/dns.hpp b/include/wireframe/l7/dns.hpp deleted file mode 100644 index 5c1ab36..0000000 --- a/include/wireframe/l7/dns.hpp +++ /dev/null @@ -1,108 +0,0 @@ -#pragma once - -#include -#include -#include -#include -#include - -#include "wireframe/byteio.hpp" -#include "wireframe/l7/dissector.hpp" - -// Hand-rolled DNS message parsing: header + the first question record. -// Answer/authority/additional records aren't decoded (not needed for a -// one-line summary), so name-compression pointers there are never -// followed - a pointer in the question section itself is rejected -// rather than chased, keeping this a pure forward scan with no risk of -// a pointer loop. -namespace wireframe::net { - -inline constexpr std::uint16_t kDnsPort = 53; - -struct DnsHeader { - std::uint16_t id; - bool is_response; - std::uint8_t opcode; - std::uint8_t rcode; - std::uint16_t qdcount; - std::uint16_t ancount; -}; - -struct DnsQuestion { - std::string name; - std::uint16_t qtype; -}; - -struct DnsMessage { - DnsHeader header; - std::optional question; // first question only -}; - -// Reads a (possibly multi-label) dotted name starting at offset. -// Returns the name and the offset just past it, or nullopt on -// truncation or a compression pointer (0xC0 prefix - valid in -// answer/authority records, not supported here). -inline std::optional> read_dns_name( - std::span bytes, std::size_t offset) { - std::string name; - while (true) { - if (offset >= bytes.size()) return std::nullopt; - std::uint8_t len = bytes[offset]; - if (len == 0) { - ++offset; - break; - } - if ((len & 0xC0) == 0xC0) return std::nullopt; // compression pointer: unsupported - ++offset; - if (offset + len > bytes.size()) return std::nullopt; - if (!name.empty()) name += '.'; - for (std::uint8_t i = 0; i < len; ++i) name += static_cast(bytes[offset + i]); - offset += len; - } - return std::make_pair(std::move(name), offset); -} - -inline std::optional parse_dns(std::span bytes) { - if (bytes.size() < 12) return std::nullopt; - - DnsHeader header{}; - header.id = read_be16(bytes, 0); - std::uint16_t flags = read_be16(bytes, 2); - header.is_response = (flags & 0x8000) != 0; - header.opcode = static_cast((flags >> 11) & 0x0F); - header.rcode = static_cast(flags & 0x0F); - header.qdcount = read_be16(bytes, 4); - header.ancount = read_be16(bytes, 6); - - DnsMessage msg{header, std::nullopt}; - if (header.qdcount >= 1) { - if (auto result = read_dns_name(bytes, 12)) { - auto& [name, next_offset] = *result; - if (next_offset + 4 <= bytes.size()) { - msg.question = DnsQuestion{std::move(name), read_be16(bytes, next_offset)}; - } - } - } - return msg; -} - -class DnsDissector : public L7Dissector { -public: - std::uint16_t port() const override { return kDnsPort; } - - std::optional summarize(std::span payload) const override { - auto msg = parse_dns(payload); - if (!msg) return std::nullopt; - - std::string out = "DNS "; - out += msg->header.is_response ? "response" : "query"; - out += " id=" + std::to_string(msg->header.id); - if (msg->header.is_response) out += " ancount=" + std::to_string(msg->header.ancount); - if (msg->question) { - out += " " + msg->question->name + " type=" + std::to_string(msg->question->qtype); - } - return out; - } -}; - -} // namespace wireframe::net diff --git a/include/wireframe/l7/http.hpp b/include/wireframe/l7/http.hpp deleted file mode 100644 index 4780b23..0000000 --- a/include/wireframe/l7/http.hpp +++ /dev/null @@ -1,113 +0,0 @@ -#pragma once - -#include -#include -#include -#include -#include - -#include "wireframe/l7/dissector.hpp" - -// Best-effort, single-segment HTTP/1.x request/status-line parsing (plus -// the Host: header for requests). No TCP stream reassembly, so a -// message split across multiple packets is only partially visible here -// - the same scope DNS already has (single UDP datagram, no -// reassembly). Good enough for a one-line summary, not a full dissector. -namespace wireframe::net { - -inline constexpr std::uint16_t kHttpPort = 80; - -struct HttpMessage { - bool is_request; - std::string method_or_version; // request: method (GET); response: "HTTP/1.1" - std::string target_or_status; // request: target path; response: status code - std::optional host; // request only, from a Host: header if present -}; - -inline std::optional parse_http(std::span payload) { - std::string_view text(reinterpret_cast(payload.data()), payload.size()); - - std::size_t line_end = text.find("\r\n"); - std::size_t term_len = 2; - if (line_end == std::string_view::npos) { - line_end = text.find('\n'); - term_len = 1; - if (line_end == std::string_view::npos) return std::nullopt; - } - std::string_view first_line = text.substr(0, line_end); - - std::size_t sp1 = first_line.find(' '); - if (sp1 == std::string_view::npos) return std::nullopt; - std::size_t sp2 = first_line.find(' ', sp1 + 1); - if (sp2 == std::string_view::npos) return std::nullopt; - - std::string_view field1 = first_line.substr(0, sp1); - std::string_view field2 = first_line.substr(sp1 + 1, sp2 - sp1 - 1); - - HttpMessage msg; - - if (field1.substr(0, 5) == "HTTP/") { - msg.is_request = false; - msg.method_or_version = std::string(field1); - msg.target_or_status = std::string(field2); - return msg; - } - - static constexpr std::string_view kMethods[] = {"GET", "POST", "PUT", "DELETE", - "HEAD", "OPTIONS", "PATCH", "CONNECT", - "TRACE"}; - bool known_method = false; - for (auto method : kMethods) { - if (field1 == method) { - known_method = true; - break; - } - } - if (!known_method) return std::nullopt; - - msg.is_request = true; - msg.method_or_version = std::string(field1); - msg.target_or_status = std::string(field2); - - // Best-effort Host: header scan, bounded by whatever this one - // packet contains and terminated at the first blank line (end of - // headers) or the end of the payload - never loops past text.size(). - std::size_t pos = line_end + term_len; - while (pos < text.size()) { - std::size_t next_end = text.find("\r\n", pos); - std::size_t header_len = (next_end == std::string_view::npos) ? text.size() - pos - : next_end - pos; - std::string_view header_line = text.substr(pos, header_len); - if (header_line.empty()) break; // blank line: end of headers - - if (header_line.size() > 5 && - (header_line.substr(0, 5) == "Host:" || header_line.substr(0, 5) == "host:")) { - std::size_t value_start = 5; - while (value_start < header_line.size() && header_line[value_start] == ' ') { - ++value_start; - } - msg.host = std::string(header_line.substr(value_start)); - } - - if (next_end == std::string_view::npos) break; - pos = next_end + 2; - } - - return msg; -} - -class HttpDissector : public L7Dissector { -public: - std::uint16_t port() const override { return kHttpPort; } - - std::optional summarize(std::span payload) const override { - auto msg = parse_http(payload); - if (!msg) return std::nullopt; - - std::string out = "HTTP " + msg->method_or_version + " " + msg->target_or_status; - if (msg->host) out += " Host: " + *msg->host; - return out; - } -}; - -} // namespace wireframe::net diff --git a/include/wireframe/l7/mdns.hpp b/include/wireframe/l7/mdns.hpp deleted file mode 100644 index 887d811..0000000 --- a/include/wireframe/l7/mdns.hpp +++ /dev/null @@ -1,44 +0,0 @@ -#pragma once - -#include -#include -#include -#include - -#include "wireframe/l7/dissector.hpp" -#include "wireframe/l7/dns.hpp" - -// mDNS (RFC 6762) reuses DNS's exact wire format - same header layout, -// same question/name encoding - just over a different port (5353, -// usually to/from the multicast address 224.0.0.251) and typically -// with many questions/answers per packet instead of DNS's usual one. -// parse_dns() already only looks at the first question, which is true -// here too; the only real difference worth a label is which protocol -// this traffic actually is, so real-world capture output doesn't read -// "DNS" for traffic that never touched a resolver. -namespace wireframe::net { - -inline constexpr std::uint16_t kMdnsPort = 5353; - -class MdnsDissector : public L7Dissector { -public: - std::uint16_t port() const override { return kMdnsPort; } - - std::optional summarize(std::span payload) const override { - auto msg = parse_dns(payload); - if (!msg) return std::nullopt; - - // No id= field here unlike DnsDissector's summary: RFC 6762 - // 18.1 has multicast queries send it as zero, so printing it - // would just be "id=0" noise on real traffic. - std::string out = "mDNS "; - out += msg->header.is_response ? "response" : "query"; - if (msg->header.is_response) out += " ancount=" + std::to_string(msg->header.ancount); - if (msg->question) { - out += " " + msg->question->name + " type=" + std::to_string(msg->question->qtype); - } - return out; - } -}; - -} // namespace wireframe::net diff --git a/include/wireframe/l7/ssh.hpp b/include/wireframe/l7/ssh.hpp deleted file mode 100644 index efa471f..0000000 --- a/include/wireframe/l7/ssh.hpp +++ /dev/null @@ -1,65 +0,0 @@ -#pragma once - -#include -#include -#include -#include -#include - -#include "wireframe/l7/dissector.hpp" - -// SSH's identification exchange (RFC 4253 section 4.2) is the one part -// of an SSH connection sent in the clear, before key exchange starts -// encrypting everything: both sides open with a single line of the -// form "SSH-protoversion-softwareversion[ comments]" terminated by -// CR LF (a bare LF is tolerated too, same leniency this project's HTTP -// dissector already uses). Only that first line is ever readable -- -// everything after key exchange is opaque, so this dissector only ever -// has one line to look at, on either side of the connection. -namespace wireframe::net { - -inline constexpr std::uint16_t kSshPort = 22; - -struct SshBanner { - std::string proto_version; - std::string software_version; -}; - -inline std::optional parse_ssh_banner(std::span payload) { - std::string_view text(reinterpret_cast(payload.data()), payload.size()); - if (text.substr(0, 4) != "SSH-") return std::nullopt; - - std::size_t line_end = text.find("\r\n"); - if (line_end == std::string_view::npos) { - line_end = text.find('\n'); - if (line_end == std::string_view::npos) return std::nullopt; - } - std::string_view line = text.substr(4, line_end - 4); // past "SSH-" - - std::size_t dash = line.find('-'); - if (dash == std::string_view::npos) return std::nullopt; - - SshBanner banner; - banner.proto_version = std::string(line.substr(0, dash)); - - // The software version runs up to the first space (start of an - // optional comment) or the end of the line, whichever is first. - std::string_view rest = line.substr(dash + 1); - std::size_t space = rest.find(' '); - banner.software_version = std::string(space == std::string_view::npos ? rest - : rest.substr(0, space)); - return banner; -} - -class SshDissector : public L7Dissector { -public: - std::uint16_t port() const override { return kSshPort; } - - std::optional summarize(std::span payload) const override { - auto banner = parse_ssh_banner(payload); - if (!banner) return std::nullopt; - return "SSH " + banner->proto_version + " " + banner->software_version; - } -}; - -} // namespace wireframe::net diff --git a/include/wireframe/l7/tls.hpp b/include/wireframe/l7/tls.hpp deleted file mode 100644 index 1c6dc57..0000000 --- a/include/wireframe/l7/tls.hpp +++ /dev/null @@ -1,139 +0,0 @@ -#pragma once - -#include -#include -#include -#include - -#include "wireframe/byteio.hpp" -#include "wireframe/l7/dissector.hpp" - -// TLS ClientHello -> SNI extension parsing. Most web traffic is TLS -// today, so HTTP alone covers a shrinking fraction of it - SNI is what -// makes a packet analyzer useful against that traffic without -// decrypting anything: the server name is sent in cleartext in the -// ClientHello, before any encryption starts, in every TLS version this -// parses (the ClientHello/extension wire format hasn't changed across -// versions - only what happens after it has). -// -// Same scope as the other L7 dissectors: single-segment, best-effort. -// A ClientHello padded across multiple TCP segments (large cookie/PSK -// extensions, unusual but possible) is only partially visible here. -// Every length field is bounds-checked against what's actually left in -// the buffer before use - this is exactly the kind of nested, -// attacker-influenced TLV structure the project's decoders are meant -// to get right. -namespace wireframe::net { - -inline constexpr std::uint16_t kTlsPort = 443; -inline constexpr std::uint8_t kTlsContentTypeHandshake = 0x16; -inline constexpr std::uint8_t kTlsHandshakeTypeClientHello = 0x01; -inline constexpr std::uint16_t kTlsExtensionServerName = 0x0000; - -struct TlsClientHello { - std::optional server_name; // SNI, if the extension was present and well-formed -}; - -inline std::optional parse_tls_client_hello(std::span bytes) { - // Record header: ContentType(1) ProtocolVersion(2) Length(2) - if (bytes.size() < 5) return std::nullopt; - if (bytes[0] != kTlsContentTypeHandshake) return std::nullopt; - std::uint16_t record_len = read_be16(bytes, 3); - if (bytes.size() < static_cast(5) + record_len) return std::nullopt; - - std::span handshake = bytes.subspan(5); - - // Handshake header: HandshakeType(1) Length(3, 24-bit BE) - if (handshake.size() < 4) return std::nullopt; - if (handshake[0] != kTlsHandshakeTypeClientHello) return std::nullopt; - std::uint32_t hs_len = (static_cast(handshake[1]) << 16) | - (static_cast(handshake[2]) << 8) | - static_cast(handshake[3]); - - std::span body = handshake.subspan(4); - if (body.size() < hs_len) return std::nullopt; - body = body.first(hs_len); // never read past the declared handshake body - - std::size_t offset = 0; - - // client_version(2) + random(32) - if (body.size() < offset + 34) return std::nullopt; - offset += 34; - - // legacy_session_id: length(1) + data - if (body.size() < offset + 1) return std::nullopt; - std::uint8_t session_id_len = body[offset]; - offset += 1; - if (body.size() < offset + session_id_len) return std::nullopt; - offset += session_id_len; - - // cipher_suites: length(2) + data - if (body.size() < offset + 2) return std::nullopt; - std::uint16_t cipher_suites_len = read_be16(body, offset); - offset += 2; - if (body.size() < static_cast(offset) + cipher_suites_len) return std::nullopt; - offset += cipher_suites_len; - - // legacy_compression_methods: length(1) + data - if (body.size() < offset + 1) return std::nullopt; - std::uint8_t compression_len = body[offset]; - offset += 1; - if (body.size() < offset + compression_len) return std::nullopt; - offset += compression_len; - - TlsClientHello hello; - if (offset == body.size()) return hello; // no extensions block: no SNI, still a valid hello - - // extensions: length(2) + data - if (body.size() < offset + 2) return std::nullopt; - std::uint16_t extensions_len = read_be16(body, offset); - offset += 2; - if (body.size() < static_cast(offset) + extensions_len) return std::nullopt; - std::size_t extensions_end = offset + extensions_len; - - while (offset + 4 <= extensions_end) { - std::uint16_t ext_type = read_be16(body, offset); - std::uint16_t ext_len = read_be16(body, offset + 2); - std::size_t ext_data_start = offset + 4; - std::size_t ext_data_end = ext_data_start + ext_len; - if (ext_data_end > extensions_end) break; // malformed: stop, keep what we have - - if (ext_type == kTlsExtensionServerName && ext_len >= 2) { - // ServerNameList: list_len(2) + entries; only the first - // entry is used, matching every real client's behavior of - // sending exactly one host_name entry. - std::uint16_t list_len = read_be16(body, ext_data_start); - std::size_t list_start = ext_data_start + 2; - std::size_t list_end = list_start + list_len; - if (list_end <= ext_data_end && list_start + 3 <= list_end) { - std::uint8_t name_type = body[list_start]; - std::uint16_t name_len = read_be16(body, list_start + 1); - std::size_t name_start = list_start + 3; - if (name_type == 0 && name_start + name_len <= list_end) { - hello.server_name = std::string( - reinterpret_cast(body.data() + name_start), name_len); - } - } - } - - offset = ext_data_end; - } - - return hello; -} - -class TlsSniDissector : public L7Dissector { -public: - std::uint16_t port() const override { return kTlsPort; } - - std::optional summarize(std::span payload) const override { - auto hello = parse_tls_client_hello(payload); - if (!hello) return std::nullopt; - - std::string out = "TLS ClientHello"; - if (hello->server_name) out += " SNI=" + *hello->server_name; - return out; - } -}; - -} // namespace wireframe::net -- cgit v1.2.3