some more data filtering, fixed data/ctrl bug, some more special info output.
[my-code/hdw-sniff.git] / parse.c
1 /*
2  * parse.c - parsing of pcap packages
3  *
4  * author: hackbard@hackdaworld.dyndns.org
5  *
6  */
7
8 #include "parse.h"
9 #include "main.h"
10
11 /* all the parsing stuff will go here
12  *
13  * different protocols should get to seperated files though ...
14  */
15
16 unsigned int int_s(unsigned int val) {
17
18   unsigned int swapped;
19
20   swapped=(val&0x000000ff)<<24;
21   swapped|=(val&0x0000ff00)<<8;
22   swapped|=(val&0x00ff0000)>>8;
23   swapped|=(val&0xff000000)>>24;
24
25   return swapped;
26 }
27
28 int switch_active_state(char *state) {
29
30   switch(*state) {
31     case '-':
32       *state='\\';
33       break;
34     case '\\':
35       *state='|';
36       break;
37     case '|':
38       *state='/';
39       break;
40     default:
41       *state='-';
42       break;
43   }
44
45   return 23;
46 }
47
48 void parse_package(unsigned char *ptr,const struct pcap_pkthdr *pcap_header,const unsigned char *pkg) {
49
50   t_info *info;
51   int i;
52   t_sta new_sta;
53   t_sta *sta;
54   unsigned char *package=NULL;
55   t_frame4_hdr *f4hdr;
56   t_frame3_hdr *f3hdr;
57   //t_frame2_hdr *f2hdr;
58   //t_frame1_hdr *f1hdr;
59   t_beacon_fb *beacon_fb;
60   unsigned char *data;
61   t_prism_hdr *prismhdr=NULL;
62   int ret;
63   char string[MESSAGE_MAX];
64   char sc[MAX_SYSCALL_CHARS];
65   unsigned char new;
66   unsigned char foo;
67
68   info=(t_info *)ptr;
69
70   info->count++;
71
72   memset(&new_sta,0,sizeof(t_sta));
73   new=0;
74   foo=0;
75
76   if(info->dump_fd!=0) {
77     ret=write(info->dump_fd,pcap_header,sizeof(struct pcap_pkthdr));
78     if(ret!=sizeof(struct pcap_pkthdr))
79       display_console(info,"warning, pcap header write failed!");
80     ret=write(info->dump_fd,package,pcap_header->caplen);
81     if(ret!=pcap_header->caplen)
82       display_console(info,"warning, package write failed!");
83   }
84   
85   /* prism or ieee802.11 header ? */
86   if(info->mode&MODE_IEEE80211) {
87     package=(unsigned char *)pkg;
88     prismhdr=NULL;
89   }
90   else if(info->mode&MODE_PRISM) {
91     package=(unsigned char *)pkg+sizeof(t_prism_hdr);
92     prismhdr=(t_prism_hdr *)pkg;
93   }
94
95   /* management */
96   if(FCTL_TYPE(package[0])==FCTL_TYPE_MGMT) {
97     info->count_m++;
98
99     /* beacon frames */
100     if(FCTL_STYPE(package[0])==FCTL_STYPE_BEACON) {
101       f3hdr=(t_frame3_hdr *)package;
102       beacon_fb=(t_beacon_fb *)(package+sizeof(t_frame3_hdr));
103       // check sta
104       memcpy(new_sta.addr,f3hdr->addr2,ADDR_LEN);
105       ret=list_search_data(&(info->sniffed_sta),&new_sta,ADDR_LEN);
106       if((ret==L_EMPTY_LIST)|(ret==L_NO_SUCH_ELEMENT)) {
107         list_add_element(&(info->sniffed_sta),&new_sta,sizeof(t_sta));
108         sta=(t_sta *)info->sniffed_sta.current->data;
109         new=1;
110       }
111       else sta=(t_sta *)info->sniffed_sta.current->data;
112       // fill in stuff ...
113       memcpy(sta->ssid,beacon_fb->ssid,beacon_fb->ssid_length);
114       if((CAP_INFO_ESS(beacon_fb->cap_info))&
115          (CAP_INFO_IBSS(beacon_fb->cap_info)==0)) sta->ap=AP;
116       if(CAP_INFO_PRIVACY(beacon_fb->cap_info)) sta->wep=WEP;
117       sta->count_mgmt++;
118       switch_active_state(&(sta->active));
119       if(info->mode&MODE_IEEE80211) sta->sq=0;
120       else if(info->mode&MODE_PRISM)
121         sta->sq=(prismhdr->signal.data)-(prismhdr->noise.data);
122       strncpy(string,"last: beacon, source: ",MESSAGE_MAX);
123       for(i=0;i<ADDR_LEN;i++)
124         snprintf(&string[22+3*i],4,"%02x%c",sta->addr[i],
125                  (i==ADDR_LEN-1)?'.':':');
126       string[22+3*ADDR_LEN+1]=0;
127       display_console(info,string);
128       if(new) {
129         snprintf(sc,MAX_SYSCALL_CHARS,
130                  "flite 'access point found: %s'",
131                  sta->ssid);
132         system(sc);
133         if(sta->wep&WEP) strncpy(sc,"flite ' crypted'",MAX_SYSCALL_CHARS);
134         else strncpy(sc,"flite 'not crypted'",MAX_SYSCALL_CHARS);
135         system(sc);
136       } 
137     }
138
139   }
140
141   /* control */
142   else if(FCTL_TYPE(package[0])==FCTL_TYPE_CTRL) {
143     info->count_c++;
144     display_console(info,"last: got control frame");
145   }
146
147   /* data */
148   else if(FCTL_TYPE(package[0])==FCTL_TYPE_DATA) {
149     info->count_d++;
150
151     //if(FCTL_STYPE(package[0])==FCTL_STYPE_DATA) {
152       if(FCTL_TODS(package[0])&FCTL_FROMDS(package[0])) {
153         f4hdr=(t_frame4_hdr *)package;
154         data=package+sizeof(t_frame4_hdr);
155         memcpy(new_sta.addr,f4hdr->addr4,ADDR_LEN);
156         foo=1;
157       }
158       else {
159         f3hdr=(t_frame3_hdr *)package;
160         data=package+sizeof(t_frame3_hdr);
161         if(FCTL_TODS(package[0])) {
162           memcpy(new_sta.addr,f3hdr->addr2,ADDR_LEN);
163           memcpy(new_sta.bssid,f3hdr->addr1,ADDR_LEN);
164         }
165         else if(FCTL_FROMDS(package[0])) {
166           memcpy(new_sta.addr,f3hdr->addr3,ADDR_LEN);
167           memcpy(new_sta.bssid,f3hdr->addr2,ADDR_LEN);
168         }
169         else {
170           memcpy(new_sta.addr,f3hdr->addr2,ADDR_LEN);
171           memcpy(new_sta.bssid,f3hdr->addr3,ADDR_LEN);
172         }
173       }
174       ret=list_search_data(&(info->sniffed_sta),&new_sta,ADDR_LEN);
175       if((ret==L_EMPTY_LIST)|(ret==L_NO_SUCH_ELEMENT)) {
176         list_add_element(&(info->sniffed_sta),&new_sta,sizeof(t_sta));
177         sta=(t_sta *)info->sniffed_sta.current->data;
178         new=1;
179       }
180       else sta=(t_sta *)info->sniffed_sta.current->data;
181       // fill in stuff ...
182       sta->count_data++;
183       switch_active_state(&(sta->active));
184       if(info->mode&MODE_IEEE80211) sta->sq=0;
185       else if(info->mode&MODE_PRISM)
186         sta->sq=(prismhdr->signal.data)-(prismhdr->noise.data);
187       if(new) {
188         strcpy(sc,"flite 'new station. data package'");
189         system(sc);
190       }
191       if(foo) {
192         sta->wds=1;
193         strcpy(sc,"flite 'wds package'");
194         system(sc);
195       }
196       memcpy(sta->snap,data,6);
197     //}
198
199     display_console(info,"last: got data frame");
200   }
201
202
203 }