⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 _cnfp.c

📁 This directory contains source code for tcpdump, a tool for network monitoring and data acquisition
💻 C
字号:
/* $OpenBSD: print-cnfp.c,v 1.2 1998/06/25 20:26:59 mickey Exp $ */

/*
 * Copyright (c) 1998 Michael Shalayeff
 * All rights reserved.
 *
 * Redistribution and use in source and binary forms, with or without
 * modification, are permitted provided that the following conditions
 * are met:
 * 1. Redistributions of source code must retain the above copyright
 *    notice, this list of conditions and the following disclaimer.
 * 2. Redistributions in binary form must reproduce the above copyright
 *    notice, this list of conditions and the following disclaimer in the
 *    documentation and/or other materials provided with the distribution.
 * 3. All advertising materials mentioning features or use of this software
 *    must display the following acknowledgement:
 * This product includes software developed by Michael Shalayeff.
 * 4. The name of the author may not be used to endorse or promote products
 *    derived from this software without specific prior written permission.
 *
 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
 */

/* Cisco NetFlow protocol */

#include <stdio.h>
#include <string.h>
#include <sys/types.h>
#include <sys/time.h>
#include <sys/socket.h>
#include <netdb.h>
#include <netinet/in.h>
#include <arpa/inet.h>

#include "interfac.h"
#include "tcp.h"

extern int snprintf (char *str, size_t count, const char *fmt, ...);

struct nfhdr
{
  u_int32_t ver_cnt;            /* version [15], and # of records */
  u_int32_t msys_uptime;
  u_int32_t utc_sec;
  u_int32_t utc_nsec;
  u_int32_t sequence;           /* v5 flow sequence number */
  u_int32_t reserved;           /* v5 only */
};

struct nfrec
{
  struct in_addr src_ina;
  struct in_addr dst_ina;
  struct in_addr nhop_ina;
  u_int32_t ifaces;             /* src,dst ifaces */
  u_int32_t packets;
  u_int32_t octets;
  u_int32_t start_time;         /* sys_uptime value */
  u_int32_t last_time;          /* sys_uptime value */
  u_int32_t ports;              /* src,dst ports */
  u_int32_t proto_tos;          /* proto, tos, pad, flags(v5) */
  u_int32_t asses;              /* v1: flags; v5: src,dst AS */
  u_int32_t masks;              /* src,dst addr prefix */

};

void cnfp_print (const u_char * cp, u_int len, const u_char * bp)
{
  struct protoent    *pent;
  const struct nfhdr *nh;
  const struct nfrec *nr;
  const struct ip    *ip;
  int    nrecs, ver;
  time_t t;

  ip = (struct ip *) bp;
  nh = (struct nfhdr *) cp;

  if ((u_char *) (nh + 1) > snapend)
     return;

  nrecs = ntohl (nh->ver_cnt) & 0xffff;
  ver   = (ntohl (nh->ver_cnt) & 0xffff0000) >> 16;
  t     = ntohl (nh->utc_sec);
  /* (p = ctime(&t))[24] = '\0'; */

  PRINTF ("NetFlow v%x, %u.%03u uptime, %u.%09u, ", ver,
          ntohl (nh->msys_uptime) / 1000,
          ntohl (nh->msys_uptime) % 1000,
          ntohl (nh->utc_sec),
          ntohl (nh->utc_nsec));

  if (ver == 5)
  {
    PRINTF ("#%u, ", htonl (nh->sequence));
    nr = (struct nfrec *) &nh[1];
    snaplen -= 24;
  }
  else
  {
    nr = (struct nfrec *) &nh->sequence;
    snaplen -= 16;
  }

  PRINTF ("%2u recs", nrecs);

  for (; nrecs-- && (u_char *) (nr + 1) <= snapend; nr++)
  {
    char buf[20];
    char asbuf[20];

    PRINTF ("\r\n  started %u.%03u, last %u.%03u",
            ntohl (nr->start_time) / 1000,
            ntohl (nr->start_time) % 1000,
            ntohl (nr->last_time) / 1000,
            ntohl (nr->last_time) % 1000);

    asbuf[0] = buf[0] = '\0';
    if (ver == 5)
    {
      snprintf (buf, sizeof(buf), "/%u", (BYTE)((ntohl (nr->masks) >> 24) & 0xff));
      snprintf (asbuf, sizeof(asbuf), "%u:", (WORD)((ntohl (nr->asses) >> 16) & 0xffff));
    }
    PRINTF ("\r\n    %s%s%s:%u ",
            inet_ntoa(nr->src_ina), buf, asbuf, ntohl (nr->ports) >> 16);

    if (ver == 5)
    {
      snprintf (buf, sizeof(buf), "/%d", (BYTE)((ntohl (nr->masks) >> 16) & 0xff));
      snprintf (asbuf, sizeof(asbuf), "%u:", (WORD)(ntohl (nr->asses) & 0xffff));
    }
    PRINTF ("> %s%s%s:%u ", inet_ntoa(nr->dst_ina), buf, asbuf, ntohl (nr->ports) & 0xffff);

    PRINTF (">> %s\n    ", inet_ntoa (nr->nhop_ina));

    pent = getprotobynumber ((ntohl (nr->proto_tos) >> 8) & 0xff);
    if (!pent || nflag)
         PRINTF ("%u ", (ntohl (nr->proto_tos) >> 8) & 0xff);
    else PRINTF ("%s ", pent->p_name);

    /* tcp flags for tcp only
     */
    if (pent && pent->p_proto == IPPROTO_TCP)
    {
      int flags;

      if (ver == 1)
           flags = (ntohl (nr->asses) >> 24) & 0xff;
      else flags = (ntohl (nr->proto_tos) >> 16) & 0xff;

      if (flags & TH_FIN)
         PUTCHAR ('F');
      if (flags & TH_SYN)
         PUTCHAR ('S');
      if (flags & TH_RST)
         PUTCHAR ('R');
      if (flags & TH_PUSH)
         PUTCHAR ('P');
      if (flags & TH_ACK)
         PUTCHAR ('A');
      if (flags & TH_URG)
         PUTCHAR ('U');
      if (flags)
         PUTCHAR (' ');
    }
    PRINTF ("tos %u, %u (%u octets)",
            ntohl (nr->proto_tos) & 0xff, ntohl (nr->packets),
            ntohl (nr->octets));
  }
}

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -