2018-09-03 04:44:54 +00:00
|
|
|
package matcher
|
2018-08-13 07:19:59 +00:00
|
|
|
|
|
|
|
import (
|
|
|
|
"encoding/json"
|
|
|
|
"fmt"
|
2018-09-03 04:44:54 +00:00
|
|
|
"log"
|
2018-08-13 07:19:59 +00:00
|
|
|
"net"
|
|
|
|
"strconv"
|
|
|
|
"sync/atomic"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
omd "git.loafle.net/overflow/model/discovery"
|
|
|
|
omm "git.loafle.net/overflow/model/meta"
|
|
|
|
omu "git.loafle.net/overflow/model/util"
|
2018-09-03 04:44:54 +00:00
|
|
|
"git.loafle.net/overflow_scanner/probe/discovery/session"
|
|
|
|
"git.loafle.net/overflow_scanner/probe/internal/matcher"
|
|
|
|
"git.loafle.net/overflow_scanner/probe/internal/pcap"
|
2018-08-13 07:19:59 +00:00
|
|
|
"github.com/google/gopacket"
|
|
|
|
"github.com/google/gopacket/layers"
|
|
|
|
)
|
|
|
|
|
2018-09-03 04:44:54 +00:00
|
|
|
func scanV4(discoverySession session.DiscoverySession, targetHost *omd.Host) error {
|
|
|
|
ps, err := pcap.RetainScanner(targetHost.Zone)
|
2018-08-13 07:19:59 +00:00
|
|
|
if nil != err {
|
2018-09-03 04:44:54 +00:00
|
|
|
return fmt.Errorf("Discovery: Cannot retain pcap instance %v", err)
|
2018-08-13 07:19:59 +00:00
|
|
|
}
|
|
|
|
defer func() {
|
2018-09-03 04:44:54 +00:00
|
|
|
go pcap.ReleaseScanner(targetHost.Zone)
|
2018-08-13 07:19:59 +00:00
|
|
|
}()
|
|
|
|
|
2018-09-03 04:44:54 +00:00
|
|
|
udpChan := ps.OpenUDP(targetHost.Address)
|
2018-08-13 07:19:59 +00:00
|
|
|
defer func() {
|
2018-09-03 04:44:54 +00:00
|
|
|
go ps.CloseUDP(targetHost.Address, udpChan)
|
2018-08-13 07:19:59 +00:00
|
|
|
}()
|
|
|
|
|
|
|
|
timerStopped := make(chan struct{})
|
|
|
|
go func() {
|
|
|
|
ports := make(map[int]*omd.Port)
|
|
|
|
|
|
|
|
var delay atomic.Value
|
|
|
|
delay.Store(false)
|
2018-09-03 04:44:54 +00:00
|
|
|
ticker := time.NewTicker(time.Millisecond * 500)
|
2018-08-13 07:19:59 +00:00
|
|
|
for {
|
|
|
|
select {
|
|
|
|
case packet, ok := <-udpChan:
|
|
|
|
if !ok {
|
2018-09-03 04:44:54 +00:00
|
|
|
// olog.Logger().Debug("Discovery: udp channel is closed")
|
2018-08-13 07:19:59 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
delay.Store(true)
|
2018-09-03 04:44:54 +00:00
|
|
|
if p := handlePacketUDP4(discoverySession, targetHost, ports, packet); nil != p {
|
|
|
|
discoverySession.AddPort(p)
|
2018-08-13 07:19:59 +00:00
|
|
|
}
|
|
|
|
case <-ticker.C:
|
|
|
|
if false == delay.Load().(bool) {
|
|
|
|
ticker.Stop()
|
|
|
|
timerStopped <- struct{}{}
|
|
|
|
return
|
|
|
|
}
|
|
|
|
delay.Store(false)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}()
|
|
|
|
|
2018-09-03 04:44:54 +00:00
|
|
|
if err := sendUDP4(discoverySession, ps, targetHost); nil != err {
|
|
|
|
log.Printf("sendUDP4 %v", err)
|
|
|
|
return nil
|
2018-08-13 07:19:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
select {
|
|
|
|
case <-timerStopped:
|
2018-09-03 04:44:54 +00:00
|
|
|
return nil
|
2018-09-03 10:33:20 +00:00
|
|
|
case <-discoverySession.StopChan():
|
|
|
|
return nil
|
2018-08-13 07:19:59 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-09-03 04:44:54 +00:00
|
|
|
func sendUDP4(discoverySession session.DiscoverySession, ps pcap.PCapScanner, host *omd.Host) error {
|
|
|
|
dp := discoverySession.DiscoverPort()
|
|
|
|
|
2018-08-13 07:19:59 +00:00
|
|
|
ip := net.ParseIP(host.Address)
|
|
|
|
if nil == ip {
|
2018-09-03 04:44:54 +00:00
|
|
|
return fmt.Errorf("IP(%s) of host is not valid", host.Address)
|
2018-08-13 07:19:59 +00:00
|
|
|
}
|
|
|
|
|
2018-09-03 04:44:54 +00:00
|
|
|
matchers := matcher.GetUDPMatchers()
|
2018-08-13 07:19:59 +00:00
|
|
|
|
|
|
|
conn, err := net.ListenUDP("udp", &net.UDPAddr{IP: net.IPv4zero, Port: 0})
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
defer func() {
|
|
|
|
conn.Close()
|
|
|
|
}()
|
|
|
|
|
2018-09-03 04:44:54 +00:00
|
|
|
for _, _matcher := range matchers {
|
|
|
|
INNER_LOOP:
|
2018-08-13 07:19:59 +00:00
|
|
|
for portNumber := dp.FirstScanRange; portNumber < dp.LastScanRange; portNumber++ {
|
|
|
|
if nil != dp.ExcludePorts {
|
|
|
|
for _, exPortNumber := range dp.ExcludePorts {
|
|
|
|
if portNumber == exPortNumber {
|
2018-09-03 04:44:54 +00:00
|
|
|
continue INNER_LOOP
|
2018-08-13 07:19:59 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-09-03 04:44:54 +00:00
|
|
|
if !_matcher.IsSend(portNumber) {
|
|
|
|
continue INNER_LOOP
|
2018-08-13 07:19:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
addr := &net.UDPAddr{IP: ip.To4(), Port: portNumber}
|
2018-09-03 04:44:54 +00:00
|
|
|
for i := 0; i < _matcher.PacketCount(); i++ {
|
|
|
|
p := _matcher.Packet(i)
|
2018-09-03 07:59:17 +00:00
|
|
|
if _, err := conn.WriteToUDP(p.Buffer, addr); err != nil {
|
2018-09-03 04:44:54 +00:00
|
|
|
log.Print("UDP write error", err)
|
2018-08-13 07:19:59 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-09-03 04:44:54 +00:00
|
|
|
timer := time.NewTimer(time.Microsecond * 100)
|
2018-08-13 07:19:59 +00:00
|
|
|
|
|
|
|
select {
|
|
|
|
case <-timer.C:
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2018-09-03 04:44:54 +00:00
|
|
|
func handlePacketUDP4(discoverySession session.DiscoverySession, host *omd.Host, ports map[int]*omd.Port, packet gopacket.Packet) *omd.Port {
|
2018-08-13 07:19:59 +00:00
|
|
|
ipLayer := packet.Layer(layers.LayerTypeIPv4)
|
|
|
|
|
|
|
|
if ipLayer.(*layers.IPv4).SrcIP.String() == host.Zone.Address {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2018-09-03 04:44:54 +00:00
|
|
|
dp := discoverySession.DiscoverPort()
|
|
|
|
|
2018-08-13 07:19:59 +00:00
|
|
|
if net := packet.NetworkLayer(); net == nil {
|
|
|
|
} else if udpLayer := packet.Layer(layers.LayerTypeUDP); udpLayer == nil {
|
|
|
|
} else if udp, ok := udpLayer.(*layers.UDP); ok {
|
|
|
|
|
2018-09-03 04:44:54 +00:00
|
|
|
// srcIP := ipLayer.(*layers.IPv4).SrcIP
|
2018-08-13 07:19:59 +00:00
|
|
|
port := int(udp.SrcPort)
|
2018-09-03 04:44:54 +00:00
|
|
|
|
2018-08-13 07:19:59 +00:00
|
|
|
if _, ok := ports[port]; ok || !dp.Contains(port) {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
p := &omd.Port{
|
|
|
|
MetaPortType: omm.ToMetaPortType(omm.MetaPortTypeEnumUDP),
|
|
|
|
PortNumber: json.Number(strconv.Itoa(port)),
|
|
|
|
UDPLayer: udpLayer,
|
|
|
|
DiscoveredDate: omu.NowPtr(),
|
|
|
|
}
|
|
|
|
p.Host = host
|
|
|
|
ports[port] = p
|
|
|
|
|
|
|
|
return p
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|