2018-08-13 07:19:59 +00:00
|
|
|
package ipv4
|
|
|
|
|
|
|
|
import (
|
|
|
|
"encoding/json"
|
|
|
|
"fmt"
|
|
|
|
"net"
|
|
|
|
"strconv"
|
|
|
|
"sync"
|
|
|
|
"sync/atomic"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
omd "git.loafle.net/overflow/model/discovery"
|
|
|
|
omm "git.loafle.net/overflow/model/meta"
|
|
|
|
omu "git.loafle.net/overflow/model/util"
|
|
|
|
"git.loafle.net/overflow_scanner/probe/pcap"
|
|
|
|
|
|
|
|
logging "git.loafle.net/commons/logging-go"
|
|
|
|
"github.com/google/gopacket"
|
|
|
|
"github.com/google/gopacket/layers"
|
|
|
|
)
|
|
|
|
|
|
|
|
func scanPortTCP(host *omd.Host, dp *omd.DiscoverPort, resultChan chan interface{}, errChan chan error, stopChan chan struct{}, wg *sync.WaitGroup) {
|
|
|
|
defer func() {
|
|
|
|
wg.Done()
|
|
|
|
}()
|
|
|
|
|
|
|
|
ps, err := pcap.RetainScanner(host.Zone)
|
|
|
|
if nil != err {
|
|
|
|
errChan <- fmt.Errorf("Discovery: Cannot retain pcap instance %v", err)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
defer func() {
|
|
|
|
go pcap.ReleaseScanner(host.Zone)
|
|
|
|
}()
|
|
|
|
|
|
|
|
tcpChan := ps.OpenTCP(host.Address)
|
|
|
|
defer func() {
|
|
|
|
go ps.CloseTCP(host.Address, tcpChan)
|
|
|
|
}()
|
|
|
|
|
|
|
|
timerStopped := make(chan struct{})
|
|
|
|
go func() {
|
|
|
|
ports := make(map[int]*omd.Port)
|
|
|
|
|
|
|
|
var delay atomic.Value
|
|
|
|
delay.Store(false)
|
|
|
|
ticker := time.NewTicker(time.Millisecond * 500)
|
|
|
|
for {
|
|
|
|
select {
|
|
|
|
case packet, ok := <-tcpChan:
|
|
|
|
if !ok {
|
|
|
|
logging.Logger().Debugf("Discovery: tcp channel is closed")
|
|
|
|
return
|
|
|
|
}
|
|
|
|
delay.Store(true)
|
|
|
|
if p := handlePacketTCP(host, dp, ports, packet); nil != p {
|
|
|
|
resultChan <- p
|
|
|
|
}
|
|
|
|
case <-ticker.C:
|
|
|
|
if false == delay.Load().(bool) {
|
|
|
|
ticker.Stop()
|
|
|
|
timerStopped <- struct{}{}
|
|
|
|
return
|
|
|
|
}
|
|
|
|
delay.Store(false)
|
|
|
|
case <-stopChan:
|
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}()
|
|
|
|
|
2018-08-15 06:18:40 +00:00
|
|
|
if err := sendTCP(ps, host, dp, stopChan); nil != err {
|
2018-08-13 07:19:59 +00:00
|
|
|
errChan <- err
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
select {
|
|
|
|
case <-stopChan:
|
|
|
|
return
|
|
|
|
case <-timerStopped:
|
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-08-15 06:18:40 +00:00
|
|
|
func sendTCP(ps pcap.PCapScanner, host *omd.Host, dp *omd.DiscoverPort, stopChan chan struct{}) error {
|
2018-08-13 07:19:59 +00:00
|
|
|
tcpPacket, err := makePacketPortTCP(host)
|
|
|
|
if nil != err {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
buf := gopacket.NewSerializeBuffer()
|
|
|
|
|
|
|
|
Loop:
|
|
|
|
for portNumber := dp.FirstScanRange; portNumber < dp.LastScanRange; portNumber++ {
|
|
|
|
if nil != dp.ExcludePorts {
|
|
|
|
for _, exPortNumber := range dp.ExcludePorts {
|
|
|
|
if portNumber == exPortNumber {
|
|
|
|
continue Loop
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
tcpPacket.TCP.DstPort = layers.TCPPort(portNumber)
|
2018-08-15 06:18:40 +00:00
|
|
|
if err := tcpPacket.TCP.SetNetworkLayerForChecksum(tcpPacket.IP); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2018-08-13 07:19:59 +00:00
|
|
|
|
2018-08-15 06:18:40 +00:00
|
|
|
if err := gopacket.SerializeLayers(buf, tcpPacket.Opts, tcpPacket.Eth, tcpPacket.IP, tcpPacket.TCP); err != nil {
|
2018-08-13 07:19:59 +00:00
|
|
|
return err
|
|
|
|
}
|
2018-08-15 06:18:40 +00:00
|
|
|
if err := ps.WritePacketData(buf.Bytes()); err != nil {
|
2018-08-13 07:19:59 +00:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
timer := time.NewTimer(time.Microsecond * 100)
|
|
|
|
|
|
|
|
select {
|
|
|
|
case <-stopChan:
|
|
|
|
return nil
|
|
|
|
case <-timer.C:
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func handlePacketTCP(host *omd.Host, dp *omd.DiscoverPort, ports map[int]*omd.Port, packet *layers.TCP) *omd.Port {
|
|
|
|
if nil == packet || packet.DstPort != 60000 {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2018-08-15 06:18:40 +00:00
|
|
|
if packet.SYN && packet.ACK {
|
|
|
|
port := int(packet.SrcPort)
|
2018-08-13 07:19:59 +00:00
|
|
|
|
2018-08-15 06:18:40 +00:00
|
|
|
if _, ok := ports[port]; ok || !dp.Contains(port) {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
logging.Logger().Debugf("Discovery: IP of TCP(%d) src %s", port, host.Address)
|
2018-08-13 07:19:59 +00:00
|
|
|
|
2018-08-15 06:18:40 +00:00
|
|
|
p := &omd.Port{
|
|
|
|
MetaPortType: omm.ToMetaPortType(omm.MetaPortTypeEnumTCP),
|
|
|
|
PortNumber: json.Number(strconv.Itoa(port)),
|
|
|
|
DiscoveredDate: omu.NowPtr(),
|
|
|
|
}
|
|
|
|
p.Host = host
|
|
|
|
|
|
|
|
ports[port] = p
|
2018-08-13 07:19:59 +00:00
|
|
|
|
2018-08-15 06:18:40 +00:00
|
|
|
return p
|
2018-08-13 07:19:59 +00:00
|
|
|
}
|
|
|
|
|
2018-08-15 06:18:40 +00:00
|
|
|
return nil
|
2018-08-13 07:19:59 +00:00
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
type PortPacketTCP struct {
|
2018-08-15 06:18:40 +00:00
|
|
|
Eth *layers.Ethernet
|
|
|
|
IP *layers.IPv4
|
|
|
|
TCP *layers.TCP
|
|
|
|
Opts gopacket.SerializeOptions
|
|
|
|
//PacketConn net.PacketConn
|
2018-08-13 07:19:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func makePacketPortTCP(host *omd.Host) (*PortPacketTCP, error) {
|
|
|
|
packetTCP := &PortPacketTCP{}
|
|
|
|
|
|
|
|
srcIP := net.ParseIP(host.Zone.Address)
|
|
|
|
if nil == srcIP {
|
|
|
|
return nil, fmt.Errorf("Discovery: IP(%s) of zone is not valid", host.Zone.Address)
|
|
|
|
}
|
|
|
|
dstIP := net.ParseIP(host.Address)
|
|
|
|
if nil == dstIP {
|
|
|
|
return nil, fmt.Errorf("Discovery: IP(%s) of host is not valid", host.Address)
|
|
|
|
}
|
|
|
|
|
2018-08-15 06:18:40 +00:00
|
|
|
srcMac, err := net.ParseMAC("30:9C:23:15:A3:09")
|
|
|
|
if nil != err {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
dstMac, err := net.ParseMAC("50:E5:49:46:93:28")
|
|
|
|
if nil != err {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
packetTCP.Eth = &layers.Ethernet{
|
|
|
|
SrcMAC: srcMac,
|
|
|
|
DstMAC: dstMac,
|
|
|
|
EthernetType: layers.EthernetTypeIPv4,
|
|
|
|
}
|
|
|
|
|
2018-08-13 07:19:59 +00:00
|
|
|
packetTCP.IP = &layers.IPv4{
|
2018-08-15 06:18:40 +00:00
|
|
|
SrcIP: srcIP,
|
|
|
|
DstIP: dstIP,
|
2018-08-13 07:19:59 +00:00
|
|
|
Version: 4,
|
|
|
|
TTL: 64,
|
|
|
|
Protocol: layers.IPProtocolTCP,
|
|
|
|
}
|
|
|
|
packetTCP.TCP = &layers.TCP{
|
|
|
|
SrcPort: 60000,
|
|
|
|
DstPort: 0, // will be incremented during the scan
|
|
|
|
SYN: true,
|
|
|
|
Seq: 0,
|
|
|
|
}
|
|
|
|
packetTCP.Opts = gopacket.SerializeOptions{
|
|
|
|
ComputeChecksums: true,
|
|
|
|
FixLengths: true,
|
|
|
|
}
|
|
|
|
|
|
|
|
return packetTCP, nil
|
|
|
|
}
|