codekingpro/portable-devtools
114k
1import re2import sys3 4 5def lookup(address, port, s):6 """7 Parse the pfctl state output s, to look up the destination host8 matching the client (address, port).9 10 Returns an (address, port) tuple, or None.11 """12 # We may get an ipv4-mapped ipv6 address here, e.g. ::ffff:127.0.0.1.13 # Those still appear as "127.0.0.1" in the table, so we need to strip the prefix.14 address = re.sub(r"^::ffff:(?=\d+.\d+.\d+.\d+$)", "", address)15 s = s.decode()16 17 # ALL tcp 192.168.1.13:57474 -> 23.205.82.58:443 ESTABLISHED:ESTABLISHED18 specv4 = f"{address}:{port}"19 20 # ALL tcp 2a01:e35:8bae:50f0:9d9b:ef0d:2de3:b733[58505] -> 2606:4700:30::681f:4ad0[443] ESTABLISHED:ESTABLISHED21 specv6 = f"{address}[{port}]"22 23 for i in s.split("\n"):24 if "ESTABLISHED:ESTABLISHED" in i and specv4 in i:25 s = i.split()26 if len(s) > 4:27 if sys.platform.startswith("freebsd"):28 # strip parentheses for FreeBSD pfctl29 s = s[3][1:-1].split(":")30 else:31 s = s[4].split(":")32 33 if len(s) == 2:34 return s[0], int(s[1])35 elif "ESTABLISHED:ESTABLISHED" in i and specv6 in i:36 s = i.split()37 if len(s) > 4:38 s = s[4].split("[")39 port = s[1].split("]")40 port = port[0]41 return s[0], int(port)42 raise RuntimeError("Could not resolve original destination.")43 