📄 _cnfp.c
字号:
/* $OpenBSD: print-cnfp.c,v 1.2 1998/06/25 20:26:59 mickey Exp $ */
/*
* Copyright (c) 1998 Michael Shalayeff
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
* 3. All advertising materials mentioning features or use of this software
* must display the following acknowledgement:
* This product includes software developed by Michael Shalayeff.
* 4. The name of the author may not be used to endorse or promote products
* derived from this software without specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
* IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
* IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
* THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*/
/* Cisco NetFlow protocol */
#include <stdio.h>
#include <string.h>
#include <sys/types.h>
#include <sys/time.h>
#include <sys/socket.h>
#include <netdb.h>
#include <netinet/in.h>
#include <arpa/inet.h>
#include "interfac.h"
#include "tcp.h"
extern int snprintf (char *str, size_t count, const char *fmt, ...);
struct nfhdr
{
u_int32_t ver_cnt; /* version [15], and # of records */
u_int32_t msys_uptime;
u_int32_t utc_sec;
u_int32_t utc_nsec;
u_int32_t sequence; /* v5 flow sequence number */
u_int32_t reserved; /* v5 only */
};
struct nfrec
{
struct in_addr src_ina;
struct in_addr dst_ina;
struct in_addr nhop_ina;
u_int32_t ifaces; /* src,dst ifaces */
u_int32_t packets;
u_int32_t octets;
u_int32_t start_time; /* sys_uptime value */
u_int32_t last_time; /* sys_uptime value */
u_int32_t ports; /* src,dst ports */
u_int32_t proto_tos; /* proto, tos, pad, flags(v5) */
u_int32_t asses; /* v1: flags; v5: src,dst AS */
u_int32_t masks; /* src,dst addr prefix */
};
void cnfp_print (const u_char * cp, u_int len, const u_char * bp)
{
struct protoent *pent;
const struct nfhdr *nh;
const struct nfrec *nr;
const struct ip *ip;
int nrecs, ver;
time_t t;
ip = (struct ip *) bp;
nh = (struct nfhdr *) cp;
if ((u_char *) (nh + 1) > snapend)
return;
nrecs = ntohl (nh->ver_cnt) & 0xffff;
ver = (ntohl (nh->ver_cnt) & 0xffff0000) >> 16;
t = ntohl (nh->utc_sec);
/* (p = ctime(&t))[24] = '\0'; */
PRINTF ("NetFlow v%x, %u.%03u uptime, %u.%09u, ", ver,
ntohl (nh->msys_uptime) / 1000,
ntohl (nh->msys_uptime) % 1000,
ntohl (nh->utc_sec),
ntohl (nh->utc_nsec));
if (ver == 5)
{
PRINTF ("#%u, ", htonl (nh->sequence));
nr = (struct nfrec *) &nh[1];
snaplen -= 24;
}
else
{
nr = (struct nfrec *) &nh->sequence;
snaplen -= 16;
}
PRINTF ("%2u recs", nrecs);
for (; nrecs-- && (u_char *) (nr + 1) <= snapend; nr++)
{
char buf[20];
char asbuf[20];
PRINTF ("\r\n started %u.%03u, last %u.%03u",
ntohl (nr->start_time) / 1000,
ntohl (nr->start_time) % 1000,
ntohl (nr->last_time) / 1000,
ntohl (nr->last_time) % 1000);
asbuf[0] = buf[0] = '\0';
if (ver == 5)
{
snprintf (buf, sizeof(buf), "/%u", (BYTE)((ntohl (nr->masks) >> 24) & 0xff));
snprintf (asbuf, sizeof(asbuf), "%u:", (WORD)((ntohl (nr->asses) >> 16) & 0xffff));
}
PRINTF ("\r\n %s%s%s:%u ",
inet_ntoa(nr->src_ina), buf, asbuf, ntohl (nr->ports) >> 16);
if (ver == 5)
{
snprintf (buf, sizeof(buf), "/%d", (BYTE)((ntohl (nr->masks) >> 16) & 0xff));
snprintf (asbuf, sizeof(asbuf), "%u:", (WORD)(ntohl (nr->asses) & 0xffff));
}
PRINTF ("> %s%s%s:%u ", inet_ntoa(nr->dst_ina), buf, asbuf, ntohl (nr->ports) & 0xffff);
PRINTF (">> %s\n ", inet_ntoa (nr->nhop_ina));
pent = getprotobynumber ((ntohl (nr->proto_tos) >> 8) & 0xff);
if (!pent || nflag)
PRINTF ("%u ", (ntohl (nr->proto_tos) >> 8) & 0xff);
else PRINTF ("%s ", pent->p_name);
/* tcp flags for tcp only
*/
if (pent && pent->p_proto == IPPROTO_TCP)
{
int flags;
if (ver == 1)
flags = (ntohl (nr->asses) >> 24) & 0xff;
else flags = (ntohl (nr->proto_tos) >> 16) & 0xff;
if (flags & TH_FIN)
PUTCHAR ('F');
if (flags & TH_SYN)
PUTCHAR ('S');
if (flags & TH_RST)
PUTCHAR ('R');
if (flags & TH_PUSH)
PUTCHAR ('P');
if (flags & TH_ACK)
PUTCHAR ('A');
if (flags & TH_URG)
PUTCHAR ('U');
if (flags)
PUTCHAR (' ');
}
PRINTF ("tos %u, %u (%u octets)",
ntohl (nr->proto_tos) & 0xff, ntohl (nr->packets),
ntohl (nr->octets));
}
}
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -