probe/_discoverer/ipv4/port_tcp.go
crusader ffd94e2c8e ing
2018-08-29 21:04:23 +09:00

212 lines
4.4 KiB
Go

package ipv4
import (
"encoding/json"
"fmt"
"net"
"strconv"
"sync"
"sync/atomic"
"time"
"go.uber.org/zap"
olog "git.loafle.net/overflow/log-go"
omd "git.loafle.net/overflow/model/discovery"
omm "git.loafle.net/overflow/model/meta"
omu "git.loafle.net/overflow/model/util"
"git.loafle.net/overflow_scanner/probe/pcap"
"github.com/google/gopacket"
"github.com/google/gopacket/layers"
)
func scanPortTCP(host *omd.Host, dp *omd.DiscoverPort, resultChan chan interface{}, errChan chan error, stopChan chan struct{}, wg *sync.WaitGroup) {
defer func() {
wg.Done()
}()
ps, err := pcap.RetainScanner(host.Zone)
if nil != err {
errChan <- fmt.Errorf("Discovery: Cannot retain pcap instance %v", err)
return
}
defer func() {
go pcap.ReleaseScanner(host.Zone)
}()
tcpChan := ps.OpenTCP(host.Address)
defer func() {
go ps.CloseTCP(host.Address, tcpChan)
}()
timerStopped := make(chan struct{})
go func() {
ports := make(map[int]*omd.Port)
var delay atomic.Value
delay.Store(false)
ticker := time.NewTicker(time.Millisecond * 500)
for {
select {
case packet, ok := <-tcpChan:
if !ok {
olog.Logger().Debug("Discovery: tcp channel is closed")
return
}
delay.Store(true)
if p := handlePacketTCP(host, dp, ports, packet); nil != p {
resultChan <- p
}
case <-ticker.C:
if false == delay.Load().(bool) {
ticker.Stop()
timerStopped <- struct{}{}
return
}
delay.Store(false)
case <-stopChan:
return
}
}
}()
if err := sendTCP(ps, host, dp, stopChan); nil != err {
errChan <- err
return
}
select {
case <-stopChan:
return
case <-timerStopped:
return
}
}
func sendTCP(ps pcap.PCapScanner, host *omd.Host, dp *omd.DiscoverPort, stopChan chan struct{}) error {
tcpPacket, err := makePacketPortTCP(host)
if nil != err {
return err
}
buf := gopacket.NewSerializeBuffer()
Loop:
for portNumber := dp.FirstScanRange; portNumber < dp.LastScanRange; portNumber++ {
if nil != dp.ExcludePorts {
for _, exPortNumber := range dp.ExcludePorts {
if portNumber == exPortNumber {
continue Loop
}
}
}
tcpPacket.TCP.DstPort = layers.TCPPort(portNumber)
if err := tcpPacket.TCP.SetNetworkLayerForChecksum(tcpPacket.IP); err != nil {
return err
}
if err := gopacket.SerializeLayers(buf, tcpPacket.Opts, tcpPacket.Eth, tcpPacket.IP, tcpPacket.TCP); err != nil {
return err
}
if err := ps.WritePacketData(buf.Bytes()); err != nil {
return err
}
timer := time.NewTimer(time.Microsecond * 100)
select {
case <-stopChan:
return nil
case <-timer.C:
}
}
return nil
}
func handlePacketTCP(host *omd.Host, dp *omd.DiscoverPort, ports map[int]*omd.Port, packet *layers.TCP) *omd.Port {
if nil == packet || packet.DstPort != 60000 {
return nil
}
if packet.SYN && packet.ACK {
port := int(packet.SrcPort)
if _, ok := ports[port]; ok || !dp.Contains(port) {
return nil
}
olog.Logger().Debug("Discovery", zap.String("ip", host.Address), zap.Int("port", port))
p := &omd.Port{
MetaPortType: omm.ToMetaPortType(omm.MetaPortTypeEnumTCP),
PortNumber: json.Number(strconv.Itoa(port)),
DiscoveredDate: omu.NowPtr(),
}
p.Host = host
ports[port] = p
return p
}
return nil
}
type PortPacketTCP struct {
Eth *layers.Ethernet
IP *layers.IPv4
TCP *layers.TCP
Opts gopacket.SerializeOptions
//PacketConn net.PacketConn
}
func makePacketPortTCP(host *omd.Host) (*PortPacketTCP, error) {
packetTCP := &PortPacketTCP{}
srcIP := net.ParseIP(host.Zone.Address)
if nil == srcIP {
return nil, fmt.Errorf("Discovery: IP(%s) of zone is not valid", host.Zone.Address)
}
dstIP := net.ParseIP(host.Address)
if nil == dstIP {
return nil, fmt.Errorf("Discovery: IP(%s) of host is not valid", host.Address)
}
srcMac, err := net.ParseMAC("30:9C:23:15:A3:09")
if nil != err {
return nil, err
}
dstMac, err := net.ParseMAC("50:E5:49:46:93:28")
if nil != err {
return nil, err
}
packetTCP.Eth = &layers.Ethernet{
SrcMAC: srcMac,
DstMAC: dstMac,
EthernetType: layers.EthernetTypeIPv4,
}
packetTCP.IP = &layers.IPv4{
SrcIP: srcIP,
DstIP: dstIP,
Version: 4,
TTL: 64,
Protocol: layers.IPProtocolTCP,
}
packetTCP.TCP = &layers.TCP{
SrcPort: 60000,
DstPort: 0, // will be incremented during the scan
SYN: true,
Seq: 0,
}
packetTCP.Opts = gopacket.SerializeOptions{
ComputeChecksums: true,
FixLengths: true,
}
return packetTCP, nil
}