3dc430116248ba11415528851e34ed28d56daaa6
[my-code/hdw-sniff.git] / parse.c
1 /*
2  * parse.c - parsing of pcap packages
3  *
4  * author: hackbard@hackdaworld.dyndns.org
5  *
6  */
7
8 #include "parse.h"
9 #include "main.h"
10
11 /* all the parsing stuff will go here
12  *
13  * different protocols should get to seperated files though ...
14  */
15
16 unsigned int int_s(unsigned int val) {
17
18   unsigned int swapped;
19
20   swapped=(val&0x000000ff)<<24;
21   swapped|=(val&0x0000ff00)<<8;
22   swapped|=(val&0x00ff0000)>>8;
23   swapped|=(val&0xff000000)>>24;
24
25   return swapped;
26 }
27
28 int switch_active_state(char *state) {
29
30   switch(*state) {
31     case '-':
32       *state='\\';
33       break;
34     case '\\':
35       *state='|';
36       break;
37     case '|':
38       *state='/';
39       break;
40     default:
41       *state='-';
42       break;
43   }
44
45   return 23;
46 }
47
48 void parse_package(unsigned char *ptr,const struct pcap_pkthdr *pcap_header,const unsigned char *pkg) {
49
50   t_info *info;
51   int i;
52   t_sta new_sta;
53   t_sta *sta;
54   unsigned char *package=NULL;
55   //t_frame4_hdr *f4hdr;
56   t_frame3_hdr *f3hdr;
57   //t_frame2_hdr *f2hdr;
58   //t_frame1_hdr *f1hdr;
59   t_beacon_fb *beacon_fb;
60   t_prism_hdr *prismhdr=NULL;
61   int ret;
62   char string[MESSAGE_MAX];
63   char sc[MAX_SYSCALL_CHARS];
64   unsigned char new;
65
66   info=(t_info *)ptr;
67
68   info->count++;
69
70   memset(&new_sta,0,sizeof(t_sta));
71   new=0;
72
73   if(info->dump_fd!=0) {
74     ret=write(info->dump_fd,pcap_header,sizeof(struct pcap_pkthdr));
75     if(ret!=sizeof(struct pcap_pkthdr))
76       display_console(info,"warning, pcap header write failed!");
77     ret=write(info->dump_fd,package,pcap_header->caplen);
78     if(ret!=pcap_header->caplen)
79       display_console(info,"warning, package write failed!");
80   }
81   
82   /* maybe there is offset to the actual ieee802.11 frame,
83      for example prism header ...
84      in that case, hack the source! */
85   if(info->mode&MODE_IEEE80211) {
86     package=(unsigned char *)pkg;
87     prismhdr=NULL;
88   }
89   else if(info->mode&MODE_PRISM) {
90     package=(unsigned char *)pkg+sizeof(t_prism_hdr);
91     prismhdr=(t_prism_hdr *)pkg;
92   }
93
94   /* management */
95   if(FCTL_TYPE(package[0])==FCTL_TYPE_MGMT) {
96     info->count_m++;
97
98     /* beacon frames */
99     if(FCTL_STYPE(package[0])==FCTL_STYPE_BEACON) {
100       f3hdr=(t_frame3_hdr *)package;
101       beacon_fb=(t_beacon_fb *)(package+sizeof(t_frame3_hdr));
102       // check sta
103       memcpy(new_sta.addr,f3hdr->addr2,ADDR_LEN);
104       ret=list_search_data(&(info->sniffed_sta),&new_sta,ADDR_LEN);
105       if((ret==L_EMPTY_LIST)|(ret==L_NO_SUCH_ELEMENT)) {
106         list_add_element(&(info->sniffed_sta),&new_sta,sizeof(t_sta));
107         sta=(t_sta *)info->sniffed_sta.current->data;
108         new=1;
109       }
110       else sta=(t_sta *)info->sniffed_sta.current->data;
111       // fill in stuff ...
112       memcpy(sta->ssid,beacon_fb->ssid,beacon_fb->ssid_length);
113       if((CAP_INFO_ESS(beacon_fb->cap_info))&
114          (CAP_INFO_IBSS(beacon_fb->cap_info)==0)) sta->ap=AP;
115       if(CAP_INFO_PRIVACY(beacon_fb->cap_info)) sta->wep=WEP;
116       sta->count_mgmt++;
117       switch_active_state(&(sta->active));
118       if(info->mode&MODE_IEEE80211) sta->sq=0;
119       else if(info->mode&MODE_PRISM)
120         sta->sq=(prismhdr->signal.data)-(prismhdr->noise.data);
121       strncpy(string,"last: beacon, source: ",MESSAGE_MAX);
122       for(i=0;i<ADDR_LEN;i++)
123         snprintf(&string[22+3*i],4,"%02x%c",sta->addr[i],
124                  (i==ADDR_LEN-1)?'.':':');
125       string[22+3*ADDR_LEN+1]=0;
126       display_console(info,string);
127       if(new) {
128         snprintf(sc,MAX_SYSCALL_CHARS,
129                  "flite 'access point found: %s'",
130                  sta->ssid);
131         system(sc);
132         if(sta->wep&WEP) strncpy(sc,"flite ' crypted'",MAX_SYSCALL_CHARS);
133         else strncpy(sc,"flite 'not crypted'",MAX_SYSCALL_CHARS);
134         system(sc);
135       } 
136     }
137
138   }
139
140   /* control */
141   else if(FCTL_TYPE(package[0])==FCTL_TYPE_CTRL) {
142     info->count_c++;
143     display_console(info,"last: got control frame");
144   }
145
146   /* data */
147   else if(FCTL_TYPE(package[0])==FCTL_TYPE_DATA) {
148     info->count_d++;
149     display_console(info,"last: got data frame");
150   }
151
152
153 }