Esempio n. 1
0
int nat_fix_upstream(nat_ctx_t *ctx, unsigned char *buf, size_t buflen,
                     const struct sockaddr *addr, socklen_t addrlen) {
  uint8_t iphdr_len;
  if (buflen < SHADOWVPN_USERTOKEN_LEN + 20) {
    errf("nat: ip packet too short");
    return -1;
  }
  ipv4_hdr_t *iphdr = (ipv4_hdr_t *)(buf + SHADOWVPN_USERTOKEN_LEN);
  if ((iphdr->ver & 0xf0) != 0x40) {
    // check header, currently IPv4 only
    // bypass IPv6
    return 0;
  }
  iphdr_len = (iphdr->ver & 0x0f) * 4;

  // print_hex_memory(buf, SHADOWVPN_USERTOKEN_LEN);
  client_info_t *client = NULL;
  HASH_FIND(hh1, ctx->token_to_clients, buf, SHADOWVPN_USERTOKEN_LEN, client);
  if (client == NULL) {
    errf("nat: client not found for given user token");
    return -1;
  }
  // print_hex_memory(iphdr, buflen - SHADOWVPN_USERTOKEN_LEN);

  // save source address
  client->source_addr.addrlen =  addrlen;
  memcpy(&client->source_addr.addr, addr, addrlen);

  int32_t acc = 0;
  // save tun input ip to client
  client->input_tun_ip = iphdr->saddr;

  // overwrite IP
  iphdr->saddr = client->output_tun_ip;

  // add old, sub new
  acc = client->input_tun_ip - iphdr->saddr;
  ADJUST_CHECKSUM(acc, iphdr->checksum);

  if (0 == (iphdr->frag & htons(0x1fff))) {
    // only adjust tcp & udp when frag offset == 0
    void *ip_payload = buf + SHADOWVPN_USERTOKEN_LEN + iphdr_len;
    if (iphdr->proto == IPPROTO_TCP) {
      if (buflen < iphdr_len + 20) {
        errf("nat: tcp packet too short");
        return -1;
      }
      tcp_hdr_t *tcphdr = ip_payload;
      ADJUST_CHECKSUM(acc, tcphdr->checksum);
    } else if (iphdr->proto == IPPROTO_UDP) {
      if (buflen < iphdr_len + 8) {
        errf("nat: udp packet too short");
        return -1;
      }
      udp_hdr_t *udphdr = ip_payload;
      ADJUST_CHECKSUM(acc, udphdr->checksum);
    }
  }
  return 0;
}
Esempio n. 2
0
static int
UdpAliasOut(struct libalias *la, struct ip *pip, int create)
{
    struct udphdr *ud;
    struct alias_link *lnk;
    int error;

    LIBALIAS_LOCK_ASSERT(la);
/* Return if proxy-only mode is enabled */
    if (la->packetAliasMode & PKT_ALIAS_PROXY_ONLY)
        return (PKT_ALIAS_OK);

    ud = (struct udphdr *)ip_next(pip);

    lnk = FindUdpTcpOut(la, pip->ip_src, pip->ip_dst,
        ud->uh_sport, ud->uh_dport,
        IPPROTO_UDP, create);
    if (lnk != NULL) {
        u_short alias_port;
        struct in_addr alias_address;
        struct alias_data ad;
        ad.lnk = lnk;
        ad.oaddr = NULL;
        ad.aaddr = &alias_address;
        ad.aport = &alias_port;
        ad.sport = &ud->uh_sport;
        ad.dport = &ud->uh_dport;
        ad.maxpktsize = 0;

        alias_address = GetAliasAddress(lnk);
        alias_port = GetAliasPort(lnk);

        /* Walk out chain. */
        error = find_handler(OUT, UDP, la, pip, &ad);

/* If UDP checksum is not zero, adjust since source port is */
/* being aliased and source address is being altered        */
        if (ud->uh_sum != 0) {
            int accumulate;

            accumulate = ud->uh_sport;
            accumulate -= alias_port;
            accumulate += twowords(&pip->ip_src);
            accumulate -= twowords(&alias_address);
            ADJUST_CHECKSUM(accumulate, ud->uh_sum);
        }
/* Put alias port in UDP header */
        ud->uh_sport = alias_port;

/* Change source address */
        DifferentialChecksum(&pip->ip_sum,
            &alias_address, &pip->ip_src, 2);
        pip->ip_src = alias_address;

        return (PKT_ALIAS_OK);
    }
    return (PKT_ALIAS_IGNORED);
}
Esempio n. 3
0
void
mss_fixup_dowork (struct buffer *buf, uint16_t maxmss)
{
  int hlen, olen, optlen;
  uint8_t *opt;
  uint16_t *mss;
  int accumulate;
  struct openvpn_tcphdr *tc;

  ASSERT (BLEN (buf) >= (int) sizeof (struct openvpn_tcphdr));

  verify_align_4 (buf);
  tc = (struct openvpn_tcphdr *) BPTR (buf);
  hlen = OPENVPN_TCPH_GET_DOFF (tc->doff_res);

  /* Invalid header length or header without options. */
  if (hlen <= (int) sizeof (struct openvpn_tcphdr)
      || hlen > BLEN (buf))
    return;

  for (olen = hlen - sizeof (struct openvpn_tcphdr),
	 opt = (uint8_t *)(tc + 1);
       olen > 0;
       olen -= optlen, opt += optlen) {
    if (*opt == OPENVPN_TCPOPT_EOL)
      break;
    else if (*opt == OPENVPN_TCPOPT_NOP)
      optlen = 1;
    else {
      optlen = *(opt + 1);
      if (optlen <= 0 || optlen > olen)
        break;
      if (*opt == OPENVPN_TCPOPT_MAXSEG) {
        if (optlen != OPENVPN_TCPOLEN_MAXSEG)
          continue;
        mss = (uint16_t *)(opt + 2);
        if (ntohs (*mss) > maxmss) {
          dmsg (D_MSS, "MSS: %d -> %d",
               (int) ntohs (*mss),
	       (int) maxmss);
          accumulate = *mss;
          *mss = htons (maxmss);
          accumulate -= *mss;
          ADJUST_CHECKSUM (accumulate, tc->check);
        }
      }
    }
  }
}
Esempio n. 4
0
void
correct_mss(struct tcphdr *tc, ssize_t pktlen, u_int16_t maxmss)
{
	int hlen, olen, optlen;
	u_char *opt;
	u_int16_t *mss;
	int accumulate;

	hlen = tc->th_off << 2;

	/* Invalid header length or header without options. */
	if (hlen <= sizeof(struct tcphdr) || hlen > pktlen)
		return;

	/* MSS option only allowed within SYN packets. */
	if (!(tc->th_flags & TH_SYN))
		return;

	for (olen = hlen - sizeof(struct tcphdr), opt = (u_char *)(tc + 1);
	     olen > 0; olen -= optlen, opt += optlen) {
		if (*opt == TCPOPT_EOL)
			break;
		else if (*opt == TCPOPT_NOP)
			optlen = 1;
		else {
			optlen = *(opt + 1);
			if (optlen <= 0 || optlen > olen)
				break;
			if (*opt == TCPOPT_MAXSEG) {
				if (optlen != TCPOLEN_MAXSEG)
					continue;
				mss = (u_int16_t *)(opt + 2);
				if (ntohs(*mss) > maxmss) {
					if (verbose)
						fprintf(stderr,
							"MSS: %u -> %u\n",
							ntohs(*mss), maxmss);
					accumulate = *mss;
					*mss = htons(maxmss);
					accumulate -= *mss;
					ADJUST_CHECKSUM(accumulate, tc->th_sum);
				}
			}
		}
	}
}
Esempio n. 5
0
static int
IcmpAliasIn1(struct libalias *la, struct ip *pip)
{

/*
    De-alias incoming echo and timestamp replies.
    Alias incoming echo and timestamp requests.
*/
    struct alias_link *lnk;
    struct icmp *ic;

    LIBALIAS_LOCK_ASSERT(la);

    ic = (struct icmp *)ip_next(pip);

/* Get source address from ICMP data field and restore original data */
    lnk = FindIcmpIn(la, pip->ip_src, pip->ip_dst, ic->icmp_id, 1);
    if (lnk != NULL) {
        u_short original_id;
        int accumulate;

        original_id = GetOriginalPort(lnk);

/* Adjust ICMP checksum */
        accumulate = ic->icmp_id;
        accumulate -= original_id;
        ADJUST_CHECKSUM(accumulate, ic->icmp_cksum);

/* Put original sequence number back in */
        ic->icmp_id = original_id;

/* Put original address back into IP header */
        {
            struct in_addr original_address;

            original_address = GetOriginalAddress(lnk);
            DifferentialChecksum(&pip->ip_sum,
                &original_address, &pip->ip_dst, 2);
            pip->ip_dst = original_address;
        }

        return (PKT_ALIAS_OK);
    }
    return (PKT_ALIAS_IGNORED);
}
Esempio n. 6
0
static int
IcmpAliasOut1(struct ip *pip)
{
/*
    Alias outgoing echo and timestamp requests.
    De-alias outgoing echo and timestamp replies.
*/
    struct alias_link *link;
    struct icmp *ic;

    ic = (struct icmp *) ((char *) pip + (pip->ip_hl << 2));

/* Save overwritten data for when echo packet returns */
    link = FindIcmpOut(pip->ip_src, pip->ip_dst, ic->icmp_id, 1);
    if (link != NULL)
    {
        u_short alias_id;
        int accumulate;

        alias_id = GetAliasPort(link);

/* Since data field is being modified, adjust ICMP checksum */
        accumulate  = ic->icmp_id;
        accumulate -= alias_id;
        ADJUST_CHECKSUM(accumulate, ic->icmp_cksum);

/* Alias sequence number */
        ic->icmp_id = alias_id;

/* Change source address */
        {
            struct in_addr alias_address;

            alias_address = GetAliasAddress(link);
            DifferentialChecksum(&pip->ip_sum,
                                 (u_short *) &alias_address,
                                 (u_short *) &pip->ip_src,
                                 2);
            pip->ip_src = alias_address;
        }

        return(PKT_ALIAS_OK);
    }
    return(PKT_ALIAS_IGNORED);
}
Esempio n. 7
0
static void
AliasHandlePptpOut(struct libalias *la,
    struct ip *pip,		/* IP packet to examine/patch */
    struct alias_link *lnk)
{				/* The PPTP control link */
	struct alias_link *pptp_lnk;
	PptpCallId cptr;
	PptpCode codes;
	u_int16_t ctl_type;	/* control message type */
	struct tcphdr *tc;

	/* Verify valid PPTP control message */
	if ((cptr = AliasVerifyPptp(pip, &ctl_type)) == NULL)
		return;

	/* Modify certain PPTP messages */
	switch (ctl_type) {
	case PPTP_OutCallRequest:
	case PPTP_OutCallReply:
	case PPTP_InCallRequest:
	case PPTP_InCallReply:
		/*
		 * Establish PPTP link for address and Call ID found in
		 * control message.
		 */
		pptp_lnk = AddPptp(la, GetOriginalAddress(lnk), GetDestAddress(lnk),
		    GetAliasAddress(lnk), cptr->cid1);
		break;
	case PPTP_CallClearRequest:
	case PPTP_CallDiscNotify:
		/*
		 * Find PPTP link for address and Call ID found in control
		 * message.
		 */
		pptp_lnk = FindPptpOutByCallId(la, GetOriginalAddress(lnk),
		    GetDestAddress(lnk),
		    cptr->cid1);
		break;
	default:
		return;
	}

	if (pptp_lnk != NULL) {
		int accumulate = cptr->cid1;

		/* alias the Call Id */
		cptr->cid1 = GetAliasPort(pptp_lnk);

		/* Compute TCP checksum for revised packet */
		tc = (struct tcphdr *)ip_next(pip);
		accumulate -= cptr->cid1;
		ADJUST_CHECKSUM(accumulate, tc->th_sum);

		switch (ctl_type) {
		case PPTP_OutCallReply:
		case PPTP_InCallReply:
			codes = (PptpCode) (cptr + 1);
			if (codes->resCode == 1)	/* Connection
							 * established, */
				SetDestCallId(pptp_lnk,	/* note the Peer's Call
								 * ID. */
				    cptr->cid2);
			else
				SetExpire(pptp_lnk, 0);	/* Connection refused. */
			break;
		case PPTP_CallDiscNotify:	/* Connection closed. */
			SetExpire(pptp_lnk, 0);
			break;
		}
	}
}
Esempio n. 8
0
static int
UdpAliasIn(struct libalias *la, struct ip *pip)
{
	struct udphdr *ud;
	struct alias_link *lnk;

	LIBALIAS_LOCK_ASSERT(la);

	ud = (struct udphdr *)ip_next(pip);

	lnk = FindUdpTcpIn(la, pip->ip_src, pip->ip_dst,
	    ud->uh_sport, ud->uh_dport,
	    IPPROTO_UDP, !(la->packetAliasMode & PKT_ALIAS_PROXY_ONLY));
	if (lnk != NULL) {
		struct in_addr alias_address;
		struct in_addr original_address;
		struct in_addr proxy_address;
		u_short alias_port;
		u_short proxy_port;
		int accumulate;
		int error;
		struct alias_data ad = {
			.lnk = lnk, 
			.oaddr = &original_address, 
			.aaddr = &alias_address,
			.aport = &alias_port,
			.sport = &ud->uh_sport,
			.dport = &ud->uh_dport,
			.maxpktsize = 0
		};

		alias_address = GetAliasAddress(lnk);
		original_address = GetOriginalAddress(lnk);
		proxy_address = GetProxyAddress(lnk);
		alias_port = ud->uh_dport;
		ud->uh_dport = GetOriginalPort(lnk);
		proxy_port = GetProxyPort(lnk);

		/* Walk out chain. */		
		error = find_handler(IN, UDP, la, pip, &ad);
		/* If we cannot figure out the packet, ignore it. */
		if (error < 0)
			return (PKT_ALIAS_IGNORED);

/* If UDP checksum is not zero, then adjust since destination port */
/* is being unaliased and destination address is being altered.    */
		if (ud->uh_sum != 0) {
			accumulate = alias_port;
			accumulate -= ud->uh_dport;
			accumulate += twowords(&alias_address);
			accumulate -= twowords(&original_address);

/* If this is a proxy packet, modify checksum because of source change.*/
        		if (proxy_port != 0) {
		                accumulate += ud->uh_sport;
		                accumulate -= proxy_port;
	                }

	                if (proxy_address.s_addr != 0) {
				accumulate += twowords(&pip->ip_src);
				accumulate -= twowords(&proxy_address);
	                }

			ADJUST_CHECKSUM(accumulate, ud->uh_sum);
		}
/* XXX: Could the two if's below be concatenated to one ? */
/* Restore source port and/or address in case of proxying*/

    		if (proxy_port != 0)
        		ud->uh_sport = proxy_port;

    		if (proxy_address.s_addr != 0) {
        		DifferentialChecksum(&pip->ip_sum,
                	    &proxy_address, &pip->ip_src, 2);
	        	pip->ip_src = proxy_address;
    		}

/* Restore original IP address */
		DifferentialChecksum(&pip->ip_sum,
		    &original_address, &pip->ip_dst, 2);
		pip->ip_dst = original_address;

		return (PKT_ALIAS_OK);
	}
	return (PKT_ALIAS_IGNORED);
}

static int
UdpAliasOut(struct libalias *la, struct ip *pip, int maxpacketsize, int create)
{
	struct udphdr *ud;
	struct alias_link *lnk;
	struct in_addr dest_address;
	struct in_addr proxy_server_address;
	u_short dest_port;
	u_short proxy_server_port;
	int proxy_type;
	int error;

	LIBALIAS_LOCK_ASSERT(la);

/* Return if proxy-only mode is enabled and not proxyrule found.*/
	ud = (struct udphdr *)ip_next(pip);
	proxy_type = ProxyCheck(la, &proxy_server_address, 
		&proxy_server_port, pip->ip_src, pip->ip_dst, 
		ud->uh_dport, pip->ip_p);
	if (proxy_type == 0 && (la->packetAliasMode & PKT_ALIAS_PROXY_ONLY))
		return (PKT_ALIAS_OK);

/* If this is a transparent proxy, save original destination,
 * then alter the destination and adjust checksums */
	dest_port = ud->uh_dport;
	dest_address = pip->ip_dst;

	if (proxy_type != 0) {
	        int accumulate;

		accumulate = twowords(&pip->ip_dst);
		accumulate -= twowords(&proxy_server_address);

	        ADJUST_CHECKSUM(accumulate, pip->ip_sum);

		if (ud->uh_sum != 0) {
			accumulate = twowords(&pip->ip_dst);
			accumulate -= twowords(&proxy_server_address);
    			accumulate += ud->uh_dport;
	        	accumulate -= proxy_server_port;
	    		ADJUST_CHECKSUM(accumulate, ud->uh_sum);
		}
	        pip->ip_dst = proxy_server_address;
	        ud->uh_dport = proxy_server_port;
	}
	lnk = FindUdpTcpOut(la, pip->ip_src, pip->ip_dst,
	    ud->uh_sport, ud->uh_dport,
	    IPPROTO_UDP, create);
	if (lnk != NULL) {
		u_short alias_port;
		struct in_addr alias_address;
		struct alias_data ad = {
			.lnk = lnk, 
			.oaddr = NULL,
			.aaddr = &alias_address,
			.aport = &alias_port,
			.sport = &ud->uh_sport,
			.dport = &ud->uh_dport,
			.maxpktsize = 0
		};

/* Save original destination address, if this is a proxy packet.
 * Also modify packet to include destination encoding.  This may
 * change the size of IP header. */
		if (proxy_type != 0) {
	                SetProxyPort(lnk, dest_port);
	                SetProxyAddress(lnk, dest_address);
	                ProxyModify(la, lnk, pip, maxpacketsize, proxy_type);
	                ud = (struct udphdr *)ip_next(pip);
	        }

		alias_address = GetAliasAddress(lnk);
		alias_port = GetAliasPort(lnk);

		/* Walk out chain. */		
		error = find_handler(OUT, UDP, la, pip, &ad);

/* If UDP checksum is not zero, adjust since source port is */
/* being aliased and source address is being altered        */
		if (ud->uh_sum != 0) {
			int accumulate;

			accumulate = ud->uh_sport;
			accumulate -= alias_port;
			accumulate += twowords(&pip->ip_src);
			accumulate -= twowords(&alias_address);
			ADJUST_CHECKSUM(accumulate, ud->uh_sum);
		}
/* Put alias port in UDP header */
		ud->uh_sport = alias_port;

/* Change source address */
		DifferentialChecksum(&pip->ip_sum,
		    &alias_address, &pip->ip_src, 2);
		pip->ip_src = alias_address;

		return (PKT_ALIAS_OK);
	}
	return (PKT_ALIAS_IGNORED);
}



static int
TcpAliasIn(struct libalias *la, struct ip *pip)
{
	struct tcphdr *tc;
	struct alias_link *lnk;

	LIBALIAS_LOCK_ASSERT(la);
	tc = (struct tcphdr *)ip_next(pip);

	lnk = FindUdpTcpIn(la, pip->ip_src, pip->ip_dst,
	    tc->th_sport, tc->th_dport,
	    IPPROTO_TCP,
	    !(la->packetAliasMode & PKT_ALIAS_PROXY_ONLY));
	if (lnk != NULL) {
		struct in_addr alias_address;
		struct in_addr original_address;
		struct in_addr proxy_address;
		u_short alias_port;
		u_short proxy_port;
		int accumulate, error;

		/* 
		 * The init of MANY vars is a bit below, but aliashandlepptpin 
		 * seems to need the destination port that came within the
		 * packet and not the original one looks below [*].
		 */

		struct alias_data ad = {
			.lnk = lnk, 
			.oaddr = NULL,
			.aaddr = NULL,
			.aport = NULL,
			.sport = &tc->th_sport,
			.dport = &tc->th_dport,
			.maxpktsize = 0
		};

		/* Walk out chain. */		
		error = find_handler(IN, TCP, la, pip, &ad);

		alias_address = GetAliasAddress(lnk);
		original_address = GetOriginalAddress(lnk);
		proxy_address = GetProxyAddress(lnk);
		alias_port = tc->th_dport;
		tc->th_dport = GetOriginalPort(lnk);
		proxy_port = GetProxyPort(lnk);

		/* 
		 * Look above, if anyone is going to add find_handler AFTER 
		 * this aliashandlepptpin/point, please redo alias_data too.
		 * Uncommenting the piece here below should be enough.
		 */
#if 0
				 struct alias_data ad = {
					.lnk = lnk,
					.oaddr = &original_address,
					.aaddr = &alias_address,
					.aport = &alias_port,
					.sport = &ud->uh_sport,
					.dport = &ud->uh_dport,
					.maxpktsize = 0
				};
		
				/* Walk out chain. */
				error = find_handler(la, pip, &ad);
				if (error == EHDNOF)
					printf("Protocol handler not found\n");
#endif

/* Adjust TCP checksum since destination port is being unaliased */
/* and destination port is being altered.                        */
		accumulate = alias_port;
		accumulate -= tc->th_dport;
		accumulate += twowords(&alias_address);
		accumulate -= twowords(&original_address);

/* If this is a proxy, then modify the TCP source port and
   checksum accumulation */
		if (proxy_port != 0) {
			accumulate += tc->th_sport;
			tc->th_sport = proxy_port;
			accumulate -= tc->th_sport;
			accumulate += twowords(&pip->ip_src);
			accumulate -= twowords(&proxy_address);
		}
/* See if ACK number needs to be modified */
		if (GetAckModified(lnk) == 1) {
			int delta;

			tc = (struct tcphdr *)ip_next(pip);
			delta = GetDeltaAckIn(tc->th_ack, lnk);
			if (delta != 0) {
				accumulate += twowords(&tc->th_ack);
				tc->th_ack = htonl(ntohl(tc->th_ack) - delta);
				accumulate -= twowords(&tc->th_ack);
			}
		}
		ADJUST_CHECKSUM(accumulate, tc->th_sum);

/* Restore original IP address */
		accumulate = twowords(&pip->ip_dst);
		pip->ip_dst = original_address;
		accumulate -= twowords(&pip->ip_dst);

/* If this is a transparent proxy packet, then modify the source
   address */
		if (proxy_address.s_addr != 0) {
			accumulate += twowords(&pip->ip_src);
			pip->ip_src = proxy_address;
			accumulate -= twowords(&pip->ip_src);
		}
		ADJUST_CHECKSUM(accumulate, pip->ip_sum);

/* Monitor TCP connection state */
		tc = (struct tcphdr *)ip_next(pip);
		TcpMonitorIn(tc->th_flags, lnk);

		return (PKT_ALIAS_OK);
	}
	return (PKT_ALIAS_IGNORED);
}

static int
TcpAliasOut(struct libalias *la, struct ip *pip, int maxpacketsize, int create)
{
	int proxy_type, error;
	u_short dest_port;
	u_short proxy_server_port;
	struct in_addr dest_address;
	struct in_addr proxy_server_address;
	struct tcphdr *tc;
	struct alias_link *lnk;

	LIBALIAS_LOCK_ASSERT(la);
	tc = (struct tcphdr *)ip_next(pip);

	if (create)
		proxy_type = ProxyCheck(la, &proxy_server_address, 
		    &proxy_server_port, pip->ip_src, pip->ip_dst, 
		    tc->th_dport, pip->ip_p);
	else
		proxy_type = 0;

	if (proxy_type == 0 && (la->packetAliasMode & PKT_ALIAS_PROXY_ONLY))
		return (PKT_ALIAS_OK);

/* If this is a transparent proxy, save original destination,
   then alter the destination and adjust checksums */
	dest_port = tc->th_dport;
	dest_address = pip->ip_dst;
	if (proxy_type != 0) {
		int accumulate;

		accumulate = tc->th_dport;
		tc->th_dport = proxy_server_port;
		accumulate -= tc->th_dport;
		accumulate += twowords(&pip->ip_dst);
		accumulate -= twowords(&proxy_server_address);
		ADJUST_CHECKSUM(accumulate, tc->th_sum);

		accumulate = twowords(&pip->ip_dst);
		pip->ip_dst = proxy_server_address;
		accumulate -= twowords(&pip->ip_dst);
		ADJUST_CHECKSUM(accumulate, pip->ip_sum);
	}
	lnk = FindUdpTcpOut(la, pip->ip_src, pip->ip_dst,
	    tc->th_sport, tc->th_dport,
	    IPPROTO_TCP, create);
	if (lnk == NULL)
		return (PKT_ALIAS_IGNORED);
	if (lnk != NULL) {
		u_short alias_port;
		struct in_addr alias_address;
		int accumulate;
		struct alias_data ad = {
			.lnk = lnk, 
			.oaddr = NULL,
			.aaddr = &alias_address,
			.aport = &alias_port,
			.sport = &tc->th_sport,
			.dport = &tc->th_dport,
			.maxpktsize = maxpacketsize
		};

/* Save original destination address, if this is a proxy packet.
   Also modify packet to include destination encoding.  This may
   change the size of IP header. */
		if (proxy_type != 0) {
			SetProxyPort(lnk, dest_port);
			SetProxyAddress(lnk, dest_address);
			ProxyModify(la, lnk, pip, maxpacketsize, proxy_type);
			tc = (struct tcphdr *)ip_next(pip);
		}
/* Get alias address and port */
		alias_port = GetAliasPort(lnk);
		alias_address = GetAliasAddress(lnk);

/* Monitor TCP connection state */
		tc = (struct tcphdr *)ip_next(pip);
		TcpMonitorOut(tc->th_flags, lnk);
		
		/* Walk out chain. */		
		error = find_handler(OUT, TCP, la, pip, &ad);

/* Adjust TCP checksum since source port is being aliased */
/* and source address is being altered                    */
		accumulate = tc->th_sport;
		tc->th_sport = alias_port;
		accumulate -= tc->th_sport;
		accumulate += twowords(&pip->ip_src);
		accumulate -= twowords(&alias_address);

/* Modify sequence number if necessary */
		if (GetAckModified(lnk) == 1) {
			int delta;
			
			tc = (struct tcphdr *)ip_next(pip);
			delta = GetDeltaSeqOut(tc->th_seq, lnk);
			if (delta != 0) {
				accumulate += twowords(&tc->th_seq);
				tc->th_seq = htonl(ntohl(tc->th_seq) + delta);
				accumulate -= twowords(&tc->th_seq);
			}
		}
		ADJUST_CHECKSUM(accumulate, tc->th_sum);

/* Change source address */
		accumulate = twowords(&pip->ip_src);
		pip->ip_src = alias_address;
		accumulate -= twowords(&pip->ip_src);
		ADJUST_CHECKSUM(accumulate, pip->ip_sum);

		return (PKT_ALIAS_OK);
	}
	return (PKT_ALIAS_IGNORED);
}




/* Fragment Handling

    FragmentIn()
    FragmentOut()

The packet aliasing module has a limited ability for handling IP
fragments.  If the ICMP, TCP or UDP header is in the first fragment
received, then the ID number of the IP packet is saved, and other
fragments are identified according to their ID number and IP address
they were sent from.  Pointers to unresolved fragments can also be
saved and recalled when a header fragment is seen.
*/

/* Local prototypes */
static int	FragmentIn(struct libalias *la, struct in_addr ip_src, 
		    struct in_addr *ip_dst, u_short ip_id, u_short *ip_sum);		    
static int	FragmentOut(struct libalias *, struct in_addr *ip_src, 
		    u_short *ip_sum);

static int
FragmentIn(struct libalias *la, struct in_addr ip_src, struct in_addr *ip_dst,
    u_short ip_id, u_short *ip_sum)
{
	struct alias_link *lnk;

	LIBALIAS_LOCK_ASSERT(la);
	lnk = FindFragmentIn2(la, ip_src, *ip_dst, ip_id);
	if (lnk != NULL) {
		struct in_addr original_address;

		GetFragmentAddr(lnk, &original_address);
		DifferentialChecksum(ip_sum,
		    &original_address, ip_dst, 2);
		*ip_dst = original_address;

		return (PKT_ALIAS_OK);
	}
	return (PKT_ALIAS_UNRESOLVED_FRAGMENT);
}

static int
FragmentOut(struct libalias *la, struct in_addr *ip_src, u_short *ip_sum)
{
	struct in_addr alias_address;

	LIBALIAS_LOCK_ASSERT(la);
	alias_address = FindAliasAddress(la, *ip_src);
	DifferentialChecksum(ip_sum,
	    &alias_address, ip_src, 2);
	*ip_src = alias_address;

	return (PKT_ALIAS_OK);
}






/* Outside World Access

	PacketAliasSaveFragment()
	PacketAliasGetFragment()
	PacketAliasFragmentIn()
	PacketAliasIn()
	PacketAliasOut()
	PacketUnaliasOut()

(prototypes in alias.h)
*/

int
LibAliasSaveFragment(struct libalias *la, char *ptr)
{
	int iresult;
	struct alias_link *lnk;
	struct ip *pip;

	LIBALIAS_LOCK(la);
	pip = (struct ip *)ptr;
	lnk = AddFragmentPtrLink(la, pip->ip_src, pip->ip_id);
	iresult = PKT_ALIAS_ERROR;
	if (lnk != NULL) {
		SetFragmentPtr(lnk, ptr);
		iresult = PKT_ALIAS_OK;
	}
	LIBALIAS_UNLOCK(la);
	return (iresult);
}

char           *
LibAliasGetFragment(struct libalias *la, char *ptr)
{
	struct alias_link *lnk;
	char *fptr;
	struct ip *pip;

	LIBALIAS_LOCK(la);
	pip = (struct ip *)ptr;
	lnk = FindFragmentPtr(la, pip->ip_src, pip->ip_id);
	if (lnk != NULL) {
		GetFragmentPtr(lnk, &fptr);
		SetFragmentPtr(lnk, NULL);
		SetExpire(lnk, 0);	/* Deletes link */
	} else		
		fptr = NULL;

	LIBALIAS_UNLOCK(la);
	return (fptr);
}

void
LibAliasFragmentIn(struct libalias *la, char *ptr,	/* Points to correctly
							 * de-aliased header
							 * fragment */
    char *ptr_fragment		/* Points to fragment which must be
				 * de-aliased   */
)
{
	struct ip *pip;
	struct ip *fpip;

	LIBALIAS_LOCK(la);
	(void)la;
	pip = (struct ip *)ptr;
	fpip = (struct ip *)ptr_fragment;

	DifferentialChecksum(&fpip->ip_sum,
	    &pip->ip_dst, &fpip->ip_dst, 2);
	fpip->ip_dst = pip->ip_dst;
	LIBALIAS_UNLOCK(la);
}

/* Local prototypes */
static int
LibAliasOutLocked(struct libalias *la, char *ptr,
		  int maxpacketsize, int create);
static int
LibAliasInLocked(struct libalias *la, char *ptr,
		  int maxpacketsize);

int
LibAliasIn(struct libalias *la, char *ptr, int maxpacketsize)
{
	int res;

	LIBALIAS_LOCK(la);
	res = LibAliasInLocked(la, ptr, maxpacketsize);
	LIBALIAS_UNLOCK(la);
	return (res);
}
Esempio n. 9
0
static int
IcmpAliasOut2(struct libalias *la, struct ip *pip)
{
/*
    Alias outgoing ICMP error messages containing
    IP header and first 64 bits of datagram.
*/
	struct ip *ip;
	struct icmp *ic, *ic2;
	struct udphdr *ud;
	struct tcphdr *tc;
	struct alias_link *lnk;

	LIBALIAS_LOCK_ASSERT(la);
	ic = (struct icmp *)ip_next(pip);
	ip = &ic->icmp_ip;

	ud = (struct udphdr *)ip_next(ip);
	tc = (struct tcphdr *)ip_next(ip);
	ic2 = (struct icmp *)ip_next(ip);

	if (ip->ip_p == IPPROTO_UDP)
		lnk = FindUdpTcpOut(la, ip->ip_dst, ip->ip_src,
		    ud->uh_dport, ud->uh_sport,
		    IPPROTO_UDP, 0);
	else if (ip->ip_p == IPPROTO_TCP)
		lnk = FindUdpTcpOut(la, ip->ip_dst, ip->ip_src,
		    tc->th_dport, tc->th_sport,
		    IPPROTO_TCP, 0);
	else if (ip->ip_p == IPPROTO_ICMP) {
		if (ic2->icmp_type == ICMP_ECHO || ic2->icmp_type == ICMP_TSTAMP)
			lnk = FindIcmpOut(la, ip->ip_dst, ip->ip_src, ic2->icmp_id, 0);
		else
			lnk = NULL;
	} else
		lnk = NULL;

	if (lnk != NULL) {
		if (ip->ip_p == IPPROTO_UDP || ip->ip_p == IPPROTO_TCP) {
			int accumulate;
			struct in_addr alias_address;
			u_short alias_port;

			alias_address = GetAliasAddress(lnk);
			alias_port = GetAliasPort(lnk);

/* Adjust ICMP checksum */
			accumulate = twowords(&ip->ip_dst);
			accumulate -= twowords(&alias_address);
			accumulate += ud->uh_dport;
			accumulate -= alias_port;
			ADJUST_CHECKSUM(accumulate, ic->icmp_cksum);

/*
 * Alias address in IP header if it comes from the host
 * the original TCP/UDP packet was destined for.
 */
			if (pip->ip_src.s_addr == ip->ip_dst.s_addr) {
				DifferentialChecksum(&pip->ip_sum,
				    &alias_address, &pip->ip_src, 2);
				pip->ip_src = alias_address;
			}
/* Alias address and port number of original IP packet
fragment contained in ICMP data section */
			ip->ip_dst = alias_address;
			ud->uh_dport = alias_port;
		} else if (ip->ip_p == IPPROTO_ICMP) {
			int accumulate;
			struct in_addr alias_address;
			u_short alias_id;

			alias_address = GetAliasAddress(lnk);
			alias_id = GetAliasPort(lnk);

/* Adjust ICMP checksum */
			accumulate = twowords(&ip->ip_dst);
			accumulate -= twowords(&alias_address);
			accumulate += ic2->icmp_id;
			accumulate -= alias_id;
			ADJUST_CHECKSUM(accumulate, ic->icmp_cksum);

/*
 * Alias address in IP header if it comes from the host
 * the original ICMP message was destined for.
 */
			if (pip->ip_src.s_addr == ip->ip_dst.s_addr) {
				DifferentialChecksum(&pip->ip_sum,
				    &alias_address, &pip->ip_src, 2);
				pip->ip_src = alias_address;
			}
/* Alias address of original IP packet and sequence number of
   embedded ICMP datagram */
			ip->ip_dst = alias_address;
			ic2->icmp_id = alias_id;
		}
		return (PKT_ALIAS_OK);
	}
	return (PKT_ALIAS_IGNORED);
}
Esempio n. 10
0
static int
IcmpAliasIn2(struct libalias *la, struct ip *pip)
{

	LIBALIAS_LOCK_ASSERT(la);
/*
    Alias incoming ICMP error messages containing
    IP header and first 64 bits of datagram.
*/
	struct ip *ip;
	struct icmp *ic, *ic2;
	struct udphdr *ud;
	struct tcphdr *tc;
	struct alias_link *lnk;

	ic = (struct icmp *)ip_next(pip);
	ip = &ic->icmp_ip;

	ud = (struct udphdr *)ip_next(ip);
	tc = (struct tcphdr *)ip_next(ip);
	ic2 = (struct icmp *)ip_next(ip);

	if (ip->ip_p == IPPROTO_UDP)
		lnk = FindUdpTcpIn(la, ip->ip_dst, ip->ip_src,
		    ud->uh_dport, ud->uh_sport,
		    IPPROTO_UDP, 0);
	else if (ip->ip_p == IPPROTO_TCP)
		lnk = FindUdpTcpIn(la, ip->ip_dst, ip->ip_src,
		    tc->th_dport, tc->th_sport,
		    IPPROTO_TCP, 0);
	else if (ip->ip_p == IPPROTO_ICMP) {
		if (ic2->icmp_type == ICMP_ECHO || ic2->icmp_type == ICMP_TSTAMP)
			lnk = FindIcmpIn(la, ip->ip_dst, ip->ip_src, ic2->icmp_id, 0);
		else
			lnk = NULL;
	} else
		lnk = NULL;

	if (lnk != NULL) {
		if (ip->ip_p == IPPROTO_UDP || ip->ip_p == IPPROTO_TCP) {
			int accumulate, accumulate2;
			struct in_addr original_address;
			u_short original_port;

			original_address = GetOriginalAddress(lnk);
			original_port = GetOriginalPort(lnk);

/* Adjust ICMP checksum */
			accumulate = twowords(&ip->ip_src);
			accumulate -= twowords(&original_address);
			accumulate += ud->uh_sport;
			accumulate -= original_port;
			accumulate2 = accumulate;
			accumulate2 += ip->ip_sum;
			ADJUST_CHECKSUM(accumulate, ip->ip_sum);
			accumulate2 -= ip->ip_sum;
			ADJUST_CHECKSUM(accumulate2, ic->icmp_cksum);

/* Un-alias address in IP header */
			DifferentialChecksum(&pip->ip_sum,
			    &original_address, &pip->ip_dst, 2);
			pip->ip_dst = original_address;

/* Un-alias address and port number of original IP packet
fragment contained in ICMP data section */
			ip->ip_src = original_address;
			ud->uh_sport = original_port;
		} else if (ip->ip_p == IPPROTO_ICMP) {
			int accumulate, accumulate2;
			struct in_addr original_address;
			u_short original_id;

			original_address = GetOriginalAddress(lnk);
			original_id = GetOriginalPort(lnk);

/* Adjust ICMP checksum */
			accumulate = twowords(&ip->ip_src);
			accumulate -= twowords(&original_address);
			accumulate += ic2->icmp_id;
			accumulate -= original_id;
			accumulate2 = accumulate;
			accumulate2 += ip->ip_sum;
			ADJUST_CHECKSUM(accumulate, ip->ip_sum);
			accumulate2 -= ip->ip_sum;
			ADJUST_CHECKSUM(accumulate2, ic->icmp_cksum);

/* Un-alias address in IP header */
			DifferentialChecksum(&pip->ip_sum,
			    &original_address, &pip->ip_dst, 2);
			pip->ip_dst = original_address;

/* Un-alias address of original IP packet and sequence number of
   embedded ICMP datagram */
			ip->ip_src = original_address;
			ic2->icmp_id = original_id;
		}
		return (PKT_ALIAS_OK);
	}
	return (PKT_ALIAS_IGNORED);
}
Esempio n. 11
0
int
LibAliasUnaliasOut(struct libalias *la, char *ptr,	/* valid IP packet */
    int maxpacketsize		/* for error checking */
)
{
	struct ip *pip;
	struct icmp *ic;
	struct udphdr *ud;
	struct tcphdr *tc;
	struct alias_link *lnk;
	int iresult = PKT_ALIAS_IGNORED;

	LIBALIAS_LOCK(la);
	pip = (struct ip *)ptr;

	/* Defense against mangled packets */
	if (ntohs(pip->ip_len) > maxpacketsize
	    || (pip->ip_hl << 2) > maxpacketsize)
		goto getout;

	ud = (struct udphdr *)ip_next(pip);
	tc = (struct tcphdr *)ip_next(pip);
	ic = (struct icmp *)ip_next(pip);

	/* Find a link */
	if (pip->ip_p == IPPROTO_UDP)
		lnk = FindUdpTcpIn(la, pip->ip_dst, pip->ip_src,
		    ud->uh_dport, ud->uh_sport,
		    IPPROTO_UDP, 0);
	else if (pip->ip_p == IPPROTO_TCP)
		lnk = FindUdpTcpIn(la, pip->ip_dst, pip->ip_src,
		    tc->th_dport, tc->th_sport,
		    IPPROTO_TCP, 0);
	else if (pip->ip_p == IPPROTO_ICMP)
		lnk = FindIcmpIn(la, pip->ip_dst, pip->ip_src, ic->icmp_id, 0);
	else
		lnk = NULL;

	/* Change it from an aliased packet to an unaliased packet */
	if (lnk != NULL) {
		if (pip->ip_p == IPPROTO_UDP || pip->ip_p == IPPROTO_TCP) {
			int accumulate;
			struct in_addr original_address;
			u_short original_port;

			original_address = GetOriginalAddress(lnk);
			original_port = GetOriginalPort(lnk);

			/* Adjust TCP/UDP checksum */
			accumulate = twowords(&pip->ip_src);
			accumulate -= twowords(&original_address);

			if (pip->ip_p == IPPROTO_UDP) {
				accumulate += ud->uh_sport;
				accumulate -= original_port;
				ADJUST_CHECKSUM(accumulate, ud->uh_sum);
			} else {
				accumulate += tc->th_sport;
				accumulate -= original_port;
				ADJUST_CHECKSUM(accumulate, tc->th_sum);
			}

			/* Adjust IP checksum */
			DifferentialChecksum(&pip->ip_sum,
			    &original_address, &pip->ip_src, 2);

			/* Un-alias source address and port number */
			pip->ip_src = original_address;
			if (pip->ip_p == IPPROTO_UDP)
				ud->uh_sport = original_port;
			else
				tc->th_sport = original_port;

			iresult = PKT_ALIAS_OK;

		} else if (pip->ip_p == IPPROTO_ICMP) {

			int accumulate;
			struct in_addr original_address;
			u_short original_id;

			original_address = GetOriginalAddress(lnk);
			original_id = GetOriginalPort(lnk);

			/* Adjust ICMP checksum */
			accumulate = twowords(&pip->ip_src);
			accumulate -= twowords(&original_address);
			accumulate += ic->icmp_id;
			accumulate -= original_id;
			ADJUST_CHECKSUM(accumulate, ic->icmp_cksum);

			/* Adjust IP checksum */
			DifferentialChecksum(&pip->ip_sum,
			    &original_address, &pip->ip_src, 2);

			/* Un-alias source address and port number */
			pip->ip_src = original_address;
			ic->icmp_id = original_id;

			iresult = PKT_ALIAS_OK;
		}
	}
getout:
	LIBALIAS_UNLOCK(la);
	return (iresult);

}
Esempio n. 12
0
static int
AliasHandleUdpNbt(
    struct libalias *la,
    struct ip *pip,		/* IP packet to examine/patch */
    struct alias_link *lnk,
    struct in_addr *alias_address,
    u_short alias_port
)
{
	struct udphdr *uh;
	NbtDataHeader *ndh;
	u_char *p = NULL;
	char *pmax;
#ifdef LIBALIAS_DEBUG
	char addrbuf[INET_ADDRSTRLEN];
#endif

	(void)la;
	(void)lnk;

	/* Calculate data length of UDP packet */
	uh = (struct udphdr *)ip_next(pip);
	pmax = (char *)uh + ntohs(uh->uh_ulen);

	ndh = (NbtDataHeader *)udp_next(uh);
	if ((char *)(ndh + 1) > pmax)
		return (-1);
#ifdef LIBALIAS_DEBUG
	printf("\nType=%02x,", ndh->type);
#endif
	switch (ndh->type) {
	case DGM_DIRECT_UNIQ:
	case DGM_DIRECT_GROUP:
	case DGM_BROADCAST:
		p = (u_char *) ndh + 14;
		p = AliasHandleName(p, pmax);	/* Source Name */
		p = AliasHandleName(p, pmax);	/* Destination Name */
		break;
	case DGM_ERROR:
		p = (u_char *) ndh + 11;
		break;
	case DGM_QUERY:
	case DGM_POSITIVE_RES:
	case DGM_NEGATIVE_RES:
		p = (u_char *) ndh + 10;
		p = AliasHandleName(p, pmax);	/* Destination Name */
		break;
	}
	if (p == NULL || (char *)p > pmax)
		p = NULL;
#ifdef LIBALIAS_DEBUG
	printf("%s:%d-->", inet_ntoa_r(ndh->source_ip, INET_NTOA_BUF(addrbuf)),
	    ntohs(ndh->source_port));
#endif
	/* Doing an IP address and Port number Translation */
	if (uh->uh_sum != 0) {
		int acc;
		u_short *sptr;

		acc = ndh->source_port;
		acc -= alias_port;
		sptr = (u_short *) & (ndh->source_ip);
		acc += *sptr++;
		acc += *sptr;
		sptr = (u_short *) alias_address;
		acc -= *sptr++;
		acc -= *sptr;
		ADJUST_CHECKSUM(acc, uh->uh_sum);
	}
	ndh->source_ip = *alias_address;
	ndh->source_port = alias_port;
#ifdef LIBALIAS_DEBUG
	printf("%s:%d\n", inet_ntoa_r(ndh->source_ip, INET_NTOA_BUF(addrbuf)),
	    ntohs(ndh->source_port));
	fflush(stdout);
#endif
	return ((p == NULL) ? -1 : 0);
}
Esempio n. 13
0
int
PacketUnaliasOut(char *ptr,           /* valid IP packet */
                 int  maxpacketsize   /* for error checking */
                )
{
    struct ip		*pip;
    struct icmp 	*ic;
    struct udphdr	*ud;
    struct tcphdr 	*tc;
    struct alias_link 	*link;
    int 		iresult = PKT_ALIAS_IGNORED;

    pip = (struct ip *) ptr;

    /* Defense against mangled packets */
    if (ntohs(pip->ip_len) > maxpacketsize
     || (pip->ip_hl<<2) > maxpacketsize)
        return(iresult);

    ud = (struct udphdr *) ((char *) pip + (pip->ip_hl << 2));
    tc = (struct tcphdr *) ud;
    ic = (struct icmp *) ud;

    /* Find a link */
    if (pip->ip_p == IPPROTO_UDP)
        link = FindUdpTcpIn(pip->ip_dst, pip->ip_src,
                            ud->uh_dport, ud->uh_sport,
                            IPPROTO_UDP, 0);
    else if (pip->ip_p == IPPROTO_TCP)
        link = FindUdpTcpIn(pip->ip_dst, pip->ip_src,
                            tc->th_dport, tc->th_sport,
                            IPPROTO_TCP, 0);
    else if (pip->ip_p == IPPROTO_ICMP) 
        link = FindIcmpIn(pip->ip_dst, pip->ip_src, ic->icmp_id, 0);
    else
        link = NULL;

    /* Change it from an aliased packet to an unaliased packet */
    if (link != NULL)
    {
        if (pip->ip_p == IPPROTO_UDP || pip->ip_p == IPPROTO_TCP)
        {
            u_short        *sptr;
            int 	   accumulate;
            struct in_addr original_address;
            u_short        original_port;

            original_address = GetOriginalAddress(link);
            original_port = GetOriginalPort(link);
    
            /* Adjust TCP/UDP checksum */
            sptr = (u_short *) &(pip->ip_src);
            accumulate  = *sptr++;
            accumulate += *sptr;
            sptr = (u_short *) &original_address;
            accumulate -= *sptr++;
            accumulate -= *sptr;

            if (pip->ip_p == IPPROTO_UDP) {
                accumulate += ud->uh_sport;
                accumulate -= original_port;
                ADJUST_CHECKSUM(accumulate, ud->uh_sum);
	    } else { 
                accumulate += tc->th_sport;
                accumulate -= original_port;
                ADJUST_CHECKSUM(accumulate, tc->th_sum);
	    }

            /* Adjust IP checksum */
            DifferentialChecksum(&pip->ip_sum,
                                 (u_short *) &original_address,
                                 (u_short *) &pip->ip_src,
                                 2);

            /* Un-alias source address and port number */ 
            pip->ip_src = original_address;
            if (pip->ip_p == IPPROTO_UDP) 
                ud->uh_sport = original_port; 
	    else   
                tc->th_sport = original_port; 
            
	    iresult = PKT_ALIAS_OK;

        } else if (pip->ip_p == IPPROTO_ICMP) {

            u_short        *sptr;
            int            accumulate;
            struct in_addr original_address;
            u_short        original_id;

            original_address = GetOriginalAddress(link);
            original_id = GetOriginalPort(link);

            /* Adjust ICMP checksum */
            sptr = (u_short *) &(pip->ip_src);
            accumulate  = *sptr++;
            accumulate += *sptr;
            sptr = (u_short *) &original_address;
            accumulate -= *sptr++;
            accumulate -= *sptr;
            accumulate += ic->icmp_id;
            accumulate -= original_id;
            ADJUST_CHECKSUM(accumulate, ic->icmp_cksum);

            /* Adjust IP checksum */
            DifferentialChecksum(&pip->ip_sum,
                                 (u_short *) &original_address,
                                 (u_short *) &pip->ip_src,
                                 2);

            /* Un-alias source address and port number */
            pip->ip_src = original_address;
            ic->icmp_id = original_id;

	    iresult = PKT_ALIAS_OK;
        }
    }
    return(iresult);

}
Esempio n. 14
0
static int
TcpAliasOut(struct ip *pip, int maxpacketsize)
{
    int proxy_type;
    u_short dest_port;
    u_short proxy_server_port;
    struct in_addr dest_address;
    struct in_addr proxy_server_address;
    struct tcphdr *tc;
    struct alias_link *link;

    tc = (struct tcphdr *) ((char *) pip + (pip->ip_hl << 2));

    proxy_type = ProxyCheck(pip, &proxy_server_address, &proxy_server_port);

    if (proxy_type == 0 && (packetAliasMode & PKT_ALIAS_PROXY_ONLY))
        return PKT_ALIAS_OK;

/* If this is a transparent proxy, save original destination,
   then alter the destination and adjust checksums */
    dest_port = tc->th_dport;
    dest_address = pip->ip_dst;
    if (proxy_type != 0)
    {
        int accumulate;
        u_short *sptr;

        accumulate = tc->th_dport;
        tc->th_dport = proxy_server_port;
        accumulate -= tc->th_dport;

        sptr = (u_short *) &(pip->ip_dst);
        accumulate += *sptr++;
        accumulate += *sptr;
        sptr = (u_short *) &proxy_server_address;
        accumulate -= *sptr++;
        accumulate -= *sptr;

        ADJUST_CHECKSUM(accumulate, tc->th_sum);

        sptr = (u_short *) &(pip->ip_dst);
        accumulate  = *sptr++;
        accumulate += *sptr;
        pip->ip_dst = proxy_server_address;
        sptr = (u_short *) &(pip->ip_dst);
        accumulate -= *sptr++;
        accumulate -= *sptr;

        ADJUST_CHECKSUM(accumulate, pip->ip_sum);
    }

    link = FindUdpTcpOut(pip->ip_src, pip->ip_dst,
                         tc->th_sport, tc->th_dport,
                         IPPROTO_TCP, 1);
    if (link !=NULL)
    {
        u_short alias_port;
        struct in_addr alias_address;
        int accumulate;
        u_short *sptr;

/* Save original destination address, if this is a proxy packet.
   Also modify packet to include destination encoding.  This may
   change the size of IP header. */
        if (proxy_type != 0)
        {
            SetProxyPort(link, dest_port);
            SetProxyAddress(link, dest_address);
            ProxyModify(link, pip, maxpacketsize, proxy_type);
            tc = (struct tcphdr *) ((char *) pip + (pip->ip_hl << 2));
        }

/* Get alias address and port */
        alias_port = GetAliasPort(link);
        alias_address = GetAliasAddress(link);

/* Monitor TCP connection state */
        TcpMonitorOut(pip, link);

/* Special processing for IP encoding protocols */
        if (ntohs(tc->th_dport) == FTP_CONTROL_PORT_NUMBER
         || ntohs(tc->th_sport) == FTP_CONTROL_PORT_NUMBER)
            AliasHandleFtpOut(pip, link, maxpacketsize);
        else if (ntohs(tc->th_dport) == IRC_CONTROL_PORT_NUMBER_1
         || ntohs(tc->th_dport) == IRC_CONTROL_PORT_NUMBER_2)
            AliasHandleIrcOut(pip, link, maxpacketsize);
        else if (ntohs(tc->th_dport) == RTSP_CONTROL_PORT_NUMBER_1
         || ntohs(tc->th_sport) == RTSP_CONTROL_PORT_NUMBER_1
         || ntohs(tc->th_dport) == RTSP_CONTROL_PORT_NUMBER_2
         || ntohs(tc->th_sport) == RTSP_CONTROL_PORT_NUMBER_2) 
            AliasHandleRtspOut(pip, link, maxpacketsize);
        else if (ntohs(tc->th_dport) == PPTP_CONTROL_PORT_NUMBER
         || ntohs(tc->th_sport) == PPTP_CONTROL_PORT_NUMBER)
            AliasHandlePptpOut(pip, link);

/* Adjust TCP checksum since source port is being aliased */
/* and source address is being altered                    */
        accumulate  = tc->th_sport;
        tc->th_sport = alias_port;
        accumulate -= tc->th_sport;

        sptr = (u_short *) &(pip->ip_src);
        accumulate += *sptr++;
        accumulate += *sptr;
        sptr = (u_short *) &alias_address;
        accumulate -= *sptr++;
        accumulate -= *sptr;

/* Modify sequence number if necessary */
        if (GetAckModified(link) == 1)
        {
            int delta;

            delta = GetDeltaSeqOut(pip, link);
            if (delta != 0)
            {
                sptr = (u_short *) &tc->th_seq;
                accumulate += *sptr++;
                accumulate += *sptr;
                tc->th_seq = htonl(ntohl(tc->th_seq) + delta);
                sptr = (u_short *) &tc->th_seq;
                accumulate -= *sptr++;
                accumulate -= *sptr;
            }
        }

        ADJUST_CHECKSUM(accumulate, tc->th_sum);

/* Change source address */
        sptr = (u_short *) &(pip->ip_src);
        accumulate  = *sptr++;
        accumulate += *sptr;
        pip->ip_src = alias_address;
        sptr = (u_short *) &(pip->ip_src);
        accumulate -= *sptr++;
        accumulate -= *sptr;

        ADJUST_CHECKSUM(accumulate, pip->ip_sum);

        return(PKT_ALIAS_OK);
    }
    return(PKT_ALIAS_IGNORED);
}
Esempio n. 15
0
static void
AliasHandlePptpIn(struct libalias *la,
    struct ip *pip,		/* IP packet to examine/patch */
    struct alias_link *lnk)
{				/* The PPTP control link */
	struct alias_link *pptp_lnk;
	PptpCallId cptr;
	u_int16_t *pcall_id;
	u_int16_t ctl_type;	/* control message type */
	struct tcphdr *tc;

	/* Verify valid PPTP control message */
	if ((cptr = AliasVerifyPptp(pip, &ctl_type)) == NULL)
		return;

	/* Modify certain PPTP messages */
	switch (ctl_type) {
	case PPTP_InCallConn:
	case PPTP_WanErrorNotify:
	case PPTP_SetLinkInfo:
		pcall_id = &cptr->cid1;
		break;
	case PPTP_OutCallReply:
	case PPTP_InCallReply:
		pcall_id = &cptr->cid2;
		break;
	case PPTP_CallDiscNotify:	/* Connection closed. */
		pptp_lnk = FindPptpInByCallId(la, GetDestAddress(lnk),
		    GetAliasAddress(lnk),
		    cptr->cid1);
		if (pptp_lnk != NULL)
			SetExpire(pptp_lnk, 0);
		return;
	default:
		return;
	}

	/* Find PPTP link for address and Call ID found in PPTP Control Msg */
	pptp_lnk = FindPptpInByPeerCallId(la, GetDestAddress(lnk),
	    GetAliasAddress(lnk),
	    *pcall_id);

	if (pptp_lnk != NULL) {
		int accumulate = *pcall_id;

		/* De-alias the Peer's Call Id. */
		*pcall_id = GetOriginalPort(pptp_lnk);

		/* Compute TCP checksum for modified packet */
		tc = (struct tcphdr *)ip_next(pip);
		accumulate -= *pcall_id;
		ADJUST_CHECKSUM(accumulate, tc->th_sum);

		if (ctl_type == PPTP_OutCallReply || ctl_type == PPTP_InCallReply) {
			PptpCode codes = (PptpCode) (cptr + 1);

			if (codes->resCode == 1)	/* Connection
							 * established, */
				SetDestCallId(pptp_lnk,	/* note the Call ID. */
				    cptr->cid1);
			else
				SetExpire(pptp_lnk, 0);	/* Connection refused. */
		}
	}
}
Esempio n. 16
0
static int
UdpAliasIn(struct libalias *la, struct ip *pip)
{
    struct udphdr *ud;
    struct alias_link *lnk;

    LIBALIAS_LOCK_ASSERT(la);
/* Return if proxy-only mode is enabled */
    if (la->packetAliasMode & PKT_ALIAS_PROXY_ONLY)
        return (PKT_ALIAS_OK);

    ud = (struct udphdr *)ip_next(pip);

    lnk = FindUdpTcpIn(la, pip->ip_src, pip->ip_dst,
        ud->uh_sport, ud->uh_dport,
        IPPROTO_UDP, 1);
    if (lnk != NULL) {
        struct in_addr alias_address;
        struct in_addr original_address;
        u_short alias_port;
        int accumulate;
        int r = 0, error;
        struct alias_data ad;
        ad.lnk = lnk;
        ad.oaddr = &original_address;
        ad.aaddr = &alias_address;
        ad.aport = &alias_port;
        ad.sport = &ud->uh_sport;
        ad.dport = &ud->uh_dport;
        ad.maxpktsize = 0;


        alias_address = GetAliasAddress(lnk);
        original_address = GetOriginalAddress(lnk);
        alias_port = ud->uh_dport;
        ud->uh_dport = GetOriginalPort(lnk);

        /* Walk out chain. */
        error = find_handler(IN, UDP, la, pip, &ad);

/* If UDP checksum is not zero, then adjust since destination port */
/* is being unaliased and destination address is being altered.    */
        if (ud->uh_sum != 0) {
            accumulate = alias_port;
            accumulate -= ud->uh_dport;
            accumulate += twowords(&alias_address);
            accumulate -= twowords(&original_address);
            ADJUST_CHECKSUM(accumulate, ud->uh_sum);
        }
/* Restore original IP address */
        DifferentialChecksum(&pip->ip_sum,
            &original_address, &pip->ip_dst, 2);
        pip->ip_dst = original_address;

        /*
         * If we cannot figure out the packet, ignore it.
         */
        if (r < 0)
            return (PKT_ALIAS_IGNORED);
        else
            return (PKT_ALIAS_OK);
    }
    return (PKT_ALIAS_IGNORED);
}
Esempio n. 17
0
static int
TcpAliasIn(struct ip *pip)
{
    struct tcphdr *tc;
    struct alias_link *link;

    tc = (struct tcphdr *) ((char *) pip + (pip->ip_hl << 2));

    link = FindUdpTcpIn(pip->ip_src, pip->ip_dst,
                        tc->th_sport, tc->th_dport,
                        IPPROTO_TCP,
                        !(packetAliasMode & PKT_ALIAS_PROXY_ONLY));
    if (link != NULL)
    {
        struct in_addr alias_address;
        struct in_addr original_address;
        struct in_addr proxy_address;
        u_short alias_port;
        u_short proxy_port;
        int accumulate;
        u_short *sptr;

/* Special processing for IP encoding protocols */
        if (ntohs(tc->th_dport) == PPTP_CONTROL_PORT_NUMBER
         || ntohs(tc->th_sport) == PPTP_CONTROL_PORT_NUMBER)
            AliasHandlePptpIn(pip, link);

        alias_address = GetAliasAddress(link);
        original_address = GetOriginalAddress(link);
        proxy_address = GetProxyAddress(link);
        alias_port = tc->th_dport;
        tc->th_dport = GetOriginalPort(link);
        proxy_port = GetProxyPort(link);

/* Adjust TCP checksum since destination port is being unaliased */
/* and destination port is being altered.                        */
        accumulate  = alias_port;
        accumulate -= tc->th_dport;
        sptr = (u_short *) &alias_address;
        accumulate += *sptr++;
        accumulate += *sptr;
        sptr = (u_short *) &original_address;
        accumulate -= *sptr++;
        accumulate -= *sptr;

/* If this is a proxy, then modify the TCP source port and
   checksum accumulation */
        if (proxy_port != 0)
        {
            accumulate += tc->th_sport;
            tc->th_sport = proxy_port;
            accumulate -= tc->th_sport;

            sptr = (u_short *) &pip->ip_src;
            accumulate += *sptr++;
            accumulate += *sptr;
            sptr = (u_short *) &proxy_address;
            accumulate -= *sptr++;
            accumulate -= *sptr;
        }

/* See if ACK number needs to be modified */
        if (GetAckModified(link) == 1)
        {
            int delta;

            delta = GetDeltaAckIn(pip, link);
            if (delta != 0)
            {
                sptr = (u_short *) &tc->th_ack;
                accumulate += *sptr++;
                accumulate += *sptr;
                tc->th_ack = htonl(ntohl(tc->th_ack) - delta);
                sptr = (u_short *) &tc->th_ack;
                accumulate -= *sptr++;
                accumulate -= *sptr;
            }
        }

        ADJUST_CHECKSUM(accumulate, tc->th_sum);

/* Restore original IP address */
        sptr = (u_short *) &pip->ip_dst;
        accumulate  = *sptr++;
        accumulate += *sptr;
        pip->ip_dst = original_address;
        sptr = (u_short *) &pip->ip_dst;
        accumulate -= *sptr++;
        accumulate -= *sptr;

/* If this is a transparent proxy packet, then modify the source
   address */
        if (proxy_address.s_addr != 0)
        {
            sptr = (u_short *) &pip->ip_src;
            accumulate += *sptr++;
            accumulate += *sptr;
            pip->ip_src = proxy_address;
            sptr = (u_short *) &pip->ip_src;
            accumulate -= *sptr++;
            accumulate -= *sptr;
        }

        ADJUST_CHECKSUM(accumulate, pip->ip_sum);

/* Monitor TCP connection state */
        TcpMonitorIn(pip, link);

        return(PKT_ALIAS_OK);
    }
    return(PKT_ALIAS_IGNORED);
}
Esempio n. 18
0
static int
UdpAliasOut(struct ip *pip)
{
    struct udphdr *ud;
    struct alias_link *link;

/* Return if proxy-only mode is enabled */
    if (packetAliasMode & PKT_ALIAS_PROXY_ONLY)
        return PKT_ALIAS_OK;

    ud = (struct udphdr *) ((char *) pip + (pip->ip_hl << 2));

    link = FindUdpTcpOut(pip->ip_src, pip->ip_dst,
                         ud->uh_sport, ud->uh_dport,
                         IPPROTO_UDP, 1);
    if (link != NULL)
    {
        u_short alias_port;
        struct in_addr alias_address;

        alias_address = GetAliasAddress(link);
        alias_port = GetAliasPort(link);

/* Special processing for IP encoding protocols */
	if (ntohs(ud->uh_dport) == CUSEEME_PORT_NUMBER)
	    AliasHandleCUSeeMeOut(pip, link);
/* If NETBIOS Datagram, It should be alias address in UDP Data, too */
	else if (ntohs(ud->uh_dport) == NETBIOS_DGM_PORT_NUMBER
	      || ntohs(ud->uh_sport) == NETBIOS_DGM_PORT_NUMBER)
	    AliasHandleUdpNbt(pip, link, &alias_address, alias_port);
	else if (ntohs(ud->uh_dport) == NETBIOS_NS_PORT_NUMBER
	      || ntohs(ud->uh_sport) == NETBIOS_NS_PORT_NUMBER)
	    AliasHandleUdpNbtNS(pip, link, &pip->ip_src, &ud->uh_sport,
				&alias_address, &alias_port);
/*
 * We don't know in advance what TID the TFTP server will choose,
 * so we create a wilcard link (destination port is unspecified)
 * that will match any TID from a given destination.
 */
	else if (ntohs(ud->uh_dport) == TFTP_PORT_NUMBER)
	    FindRtspOut(pip->ip_src, pip->ip_dst,
			ud->uh_sport, alias_port, IPPROTO_UDP);

/* If UDP checksum is not zero, adjust since source port is */
/* being aliased and source address is being altered        */
        if (ud->uh_sum != 0)
        {
            int accumulate;
            u_short *sptr;

            accumulate  = ud->uh_sport;
            accumulate -= alias_port;
            sptr = (u_short *) &(pip->ip_src);
            accumulate += *sptr++;
            accumulate += *sptr;
            sptr = (u_short *) &alias_address;
            accumulate -= *sptr++;
            accumulate -= *sptr;
            ADJUST_CHECKSUM(accumulate, ud->uh_sum);
        }

/* Put alias port in UDP header */
        ud->uh_sport = alias_port;

/* Change source address */
        DifferentialChecksum(&pip->ip_sum,
                             (u_short *) &alias_address,
                             (u_short *) &pip->ip_src,
                             2);
        pip->ip_src = alias_address;

        return(PKT_ALIAS_OK);
    }
    return(PKT_ALIAS_IGNORED);
}
Esempio n. 19
0
static int
UdpAliasIn(struct ip *pip)
{
    struct udphdr *ud;
    struct alias_link *link;

/* Return if proxy-only mode is enabled */
    if (packetAliasMode & PKT_ALIAS_PROXY_ONLY)
        return PKT_ALIAS_OK;

    ud = (struct udphdr *) ((char *) pip + (pip->ip_hl << 2));

    link = FindUdpTcpIn(pip->ip_src, pip->ip_dst,
                        ud->uh_sport, ud->uh_dport,
                        IPPROTO_UDP, 1);
    if (link != NULL)
    {
        struct in_addr alias_address;
        struct in_addr original_address;
        u_short alias_port;
        int accumulate;
        u_short *sptr;
	int r = 0;

        alias_address = GetAliasAddress(link);
        original_address = GetOriginalAddress(link);
        alias_port = ud->uh_dport;
        ud->uh_dport = GetOriginalPort(link);

/* Special processing for IP encoding protocols */
	if (ntohs(ud->uh_dport) == CUSEEME_PORT_NUMBER)
	    AliasHandleCUSeeMeIn(pip, original_address);
/* If NETBIOS Datagram, It should be alias address in UDP Data, too */
	else if (ntohs(ud->uh_dport) == NETBIOS_DGM_PORT_NUMBER
	      || ntohs(ud->uh_sport) == NETBIOS_DGM_PORT_NUMBER)
	    r = AliasHandleUdpNbt(pip, link, &original_address, ud->uh_dport);
	else if (ntohs(ud->uh_dport) == NETBIOS_NS_PORT_NUMBER
	      || ntohs(ud->uh_sport) == NETBIOS_NS_PORT_NUMBER)
	    r = AliasHandleUdpNbtNS(pip, link, &alias_address, &alias_port,
				    &original_address, &ud->uh_dport);

/* If UDP checksum is not zero, then adjust since destination port */
/* is being unaliased and destination address is being altered.    */
        if (ud->uh_sum != 0)
        {
            accumulate  = alias_port;
            accumulate -= ud->uh_dport;
            sptr = (u_short *) &alias_address;
            accumulate += *sptr++;
            accumulate += *sptr;
            sptr = (u_short *) &original_address;
            accumulate -= *sptr++;
            accumulate -= *sptr;
            ADJUST_CHECKSUM(accumulate, ud->uh_sum);
        }

/* Restore original IP address */
        DifferentialChecksum(&pip->ip_sum,
                             (u_short *) &original_address,
                             (u_short *) &pip->ip_dst,
                             2);
        pip->ip_dst = original_address;

	/*
	 * If we cannot figure out the packet, ignore it.
	 */
	if (r < 0)
	    return(PKT_ALIAS_IGNORED);
	else
	    return(PKT_ALIAS_OK);
    }
    return(PKT_ALIAS_IGNORED);
}
Esempio n. 20
0
static int
TcpAliasIn(struct libalias *la, struct ip *pip)
{
    struct tcphdr *tc;
    struct alias_link *lnk;

    LIBALIAS_LOCK_ASSERT(la);
    tc = (struct tcphdr *)ip_next(pip);

    lnk = FindUdpTcpIn(la, pip->ip_src, pip->ip_dst,
        tc->th_sport, tc->th_dport,
        IPPROTO_TCP,
        !(la->packetAliasMode & PKT_ALIAS_PROXY_ONLY));
    if (lnk != NULL) {
        struct in_addr alias_address;
        struct in_addr original_address;
        struct in_addr proxy_address;
        u_short alias_port;
        u_short proxy_port;
        int accumulate, error;

        /*
         * The init of MANY vars is a bit below, but aliashandlepptpin
         * seems to need the destination port that came within the
         * packet and not the original one looks below [*].
         */

        struct alias_data ad;
        ad.lnk = lnk;
        ad.oaddr = NULL;
        ad.aaddr = NULL;
        ad.aport = NULL;
        ad.sport = &tc->th_sport;
        ad.dport = &tc->th_dport;
        ad.maxpktsize = 0;

        /* Walk out chain. */
        error = find_handler(IN, TCP, la, pip, &ad);

        alias_address = GetAliasAddress(lnk);
        original_address = GetOriginalAddress(lnk);
        proxy_address = GetProxyAddress(lnk);
        alias_port = tc->th_dport;
        tc->th_dport = GetOriginalPort(lnk);
        proxy_port = GetProxyPort(lnk);

        /*
         * Look above, if anyone is going to add find_handler AFTER
         * this aliashandlepptpin/point, please redo alias_data too.
         * Uncommenting the piece here below should be enough.
         */
#if 0
                 struct alias_data ad = {
                    .lnk = lnk,
                    .oaddr = &original_address,
                    .aaddr = &alias_address,
                    .aport = &alias_port,
                    .sport = &ud->uh_sport,
                    .dport = &ud->uh_dport,
                    .maxpktsize = 0
                };

                /* Walk out chain. */
                error = find_handler(la, pip, &ad);
                if (error == EHDNOF)
                    printf("Protocol handler not found\n");
#endif

/* Adjust TCP checksum since destination port is being unaliased */
/* and destination port is being altered.                        */
        accumulate = alias_port;
        accumulate -= tc->th_dport;
        accumulate += twowords(&alias_address);
        accumulate -= twowords(&original_address);

/* If this is a proxy, then modify the TCP source port and
   checksum accumulation */
        if (proxy_port != 0) {
            accumulate += tc->th_sport;
            tc->th_sport = proxy_port;
            accumulate -= tc->th_sport;
            accumulate += twowords(&pip->ip_src);
            accumulate -= twowords(&proxy_address);
        }
/* See if ACK number needs to be modified */
        if (GetAckModified(lnk) == 1) {
            int delta;

            delta = GetDeltaAckIn(pip, lnk);
            if (delta != 0) {
                accumulate += twowords(&tc->th_ack);
                tc->th_ack = htonl(ntohl(tc->th_ack) - delta);
                accumulate -= twowords(&tc->th_ack);
            }
        }
        ADJUST_CHECKSUM(accumulate, tc->th_sum);

/* Restore original IP address */
        accumulate = twowords(&pip->ip_dst);
        pip->ip_dst = original_address;
        accumulate -= twowords(&pip->ip_dst);

/* If this is a transparent proxy packet, then modify the source
   address */
        if (proxy_address.s_addr != 0) {
            accumulate += twowords(&pip->ip_src);
            pip->ip_src = proxy_address;
            accumulate -= twowords(&pip->ip_src);
        }
        ADJUST_CHECKSUM(accumulate, pip->ip_sum);

/* Monitor TCP connection state */
        TcpMonitorIn(pip, lnk);

        return (PKT_ALIAS_OK);
    }
    return (PKT_ALIAS_IGNORED);
}

static int
TcpAliasOut(struct libalias *la, struct ip *pip, int maxpacketsize, int create)
{
    int proxy_type, error;
    u_short dest_port;
    u_short proxy_server_port;
    struct in_addr dest_address;
    struct in_addr proxy_server_address;
    struct tcphdr *tc;
    struct alias_link *lnk;

    LIBALIAS_LOCK_ASSERT(la);
    tc = (struct tcphdr *)ip_next(pip);

    if (create)
        proxy_type =
            ProxyCheck(la, pip, &proxy_server_address, &proxy_server_port);
    else
        proxy_type = 0;

    if (proxy_type == 0 && (la->packetAliasMode & PKT_ALIAS_PROXY_ONLY))
        return (PKT_ALIAS_OK);

/* If this is a transparent proxy, save original destination,
   then alter the destination and adjust checksums */
    dest_port = tc->th_dport;
    dest_address = pip->ip_dst;
    if (proxy_type != 0) {
        int accumulate;

        accumulate = tc->th_dport;
        tc->th_dport = proxy_server_port;
        accumulate -= tc->th_dport;
        accumulate += twowords(&pip->ip_dst);
        accumulate -= twowords(&proxy_server_address);
        ADJUST_CHECKSUM(accumulate, tc->th_sum);

        accumulate = twowords(&pip->ip_dst);
        pip->ip_dst = proxy_server_address;
        accumulate -= twowords(&pip->ip_dst);
        ADJUST_CHECKSUM(accumulate, pip->ip_sum);
    }
    lnk = FindUdpTcpOut(la, pip->ip_src, pip->ip_dst,
        tc->th_sport, tc->th_dport,
        IPPROTO_TCP, create);
    if (lnk == NULL)
        return (PKT_ALIAS_IGNORED);
    if (lnk != NULL) {
        u_short alias_port;
        struct in_addr alias_address;
        int accumulate;
        struct alias_data ad;
        ad.lnk = lnk;
        ad.oaddr = NULL;
        ad.aaddr = &alias_address;
        ad.aport = &alias_port;
        ad.sport = &tc->th_sport;
        ad.dport = &tc->th_dport;
        ad.maxpktsize = maxpacketsize;

/* Save original destination address, if this is a proxy packet.
   Also modify packet to include destination encoding.  This may
   change the size of IP header. */
        if (proxy_type != 0) {
            SetProxyPort(lnk, dest_port);
            SetProxyAddress(lnk, dest_address);
            ProxyModify(la, lnk, pip, maxpacketsize, proxy_type);
            tc = (struct tcphdr *)ip_next(pip);
        }
/* Get alias address and port */
        alias_port = GetAliasPort(lnk);
        alias_address = GetAliasAddress(lnk);

/* Monitor TCP connection state */
        TcpMonitorOut(pip, lnk);

        /* Walk out chain. */
        error = find_handler(OUT, TCP, la, pip, &ad);

/* Adjust TCP checksum since source port is being aliased */
/* and source address is being altered                    */
        accumulate = tc->th_sport;
        tc->th_sport = alias_port;
        accumulate -= tc->th_sport;
        accumulate += twowords(&pip->ip_src);
        accumulate -= twowords(&alias_address);

/* Modify sequence number if necessary */
        if (GetAckModified(lnk) == 1) {
            int delta;

            delta = GetDeltaSeqOut(pip, lnk);
            if (delta != 0) {
                accumulate += twowords(&tc->th_seq);
                tc->th_seq = htonl(ntohl(tc->th_seq) + delta);
                accumulate -= twowords(&tc->th_seq);
            }
        }
        ADJUST_CHECKSUM(accumulate, tc->th_sum);

/* Change source address */
        accumulate = twowords(&pip->ip_src);
        pip->ip_src = alias_address;
        accumulate -= twowords(&pip->ip_src);
        ADJUST_CHECKSUM(accumulate, pip->ip_sum);

        return (PKT_ALIAS_OK);
    }
    return (PKT_ALIAS_IGNORED);
}
Esempio n. 21
0
void
client_nat_transform(const struct client_nat_option_list *list,
                     struct buffer *ipbuf,
                     const int direction)
{
    struct ip_tcp_udp_hdr *h = (struct ip_tcp_udp_hdr *) BPTR(ipbuf);
    int i;
    uint32_t addr, *addr_ptr;
    const uint32_t *from, *to;
    int accumulate = 0;
    unsigned int amask;
    unsigned int alog = 0;

    if (check_debug_level(D_CLIENT_NAT))
    {
        print_pkt(&h->ip, "BEFORE", direction, D_CLIENT_NAT);
    }

    for (i = 0; i < list->n; ++i)
    {
        const struct client_nat_entry *e = &list->entries[i]; /* current NAT rule */
        if (e->type ^ direction)
        {
            addr = *(addr_ptr = &h->ip.daddr);
            amask = 2;
        }
        else
        {
            addr = *(addr_ptr = &h->ip.saddr);
            amask = 1;
        }
        if (direction)
        {
            from = &e->foreign_network;
            to = &e->network;
        }
        else
        {
            from = &e->network;
            to = &e->foreign_network;
        }

        if (((addr & e->netmask) == *from) && !(amask & alog))
        {
            /* pre-adjust IP checksum */
            ADD_CHECKSUM_32(accumulate, addr);

            /* do NAT transform */
            addr = (addr & ~e->netmask) | *to;

            /* post-adjust IP checksum */
            SUB_CHECKSUM_32(accumulate, addr);

            /* write the modified address to packet */
            *addr_ptr = addr;

            /* mark as modified */
            alog |= amask;
        }
    }
    if (alog)
    {
        if (check_debug_level(D_CLIENT_NAT))
        {
            print_pkt(&h->ip, "AFTER", direction, D_CLIENT_NAT);
        }

        ADJUST_CHECKSUM(accumulate, h->ip.check);

        if (h->ip.protocol == OPENVPN_IPPROTO_TCP)
        {
            if (BLEN(ipbuf) >= sizeof(struct openvpn_iphdr) + sizeof(struct openvpn_tcphdr))
            {
                ADJUST_CHECKSUM(accumulate, h->u.tcp.check);
            }
        }
        else if (h->ip.protocol == OPENVPN_IPPROTO_UDP)
        {
            if (BLEN(ipbuf) >= sizeof(struct openvpn_iphdr) + sizeof(struct openvpn_udphdr))
            {
                ADJUST_CHECKSUM(accumulate, h->u.udp.check);
            }
        }
    }
}