-
Notifications
You must be signed in to change notification settings - Fork 22
Expand file tree
/
Copy pathcTCPReassembler.cpp
More file actions
125 lines (108 loc) · 3.43 KB
/
Copy pathcTCPReassembler.cpp
File metadata and controls
125 lines (108 loc) · 3.43 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
/*
*
* Copyright (C) 2013 Anwar Mohamed <anwarelmakrahy[at]gmail.com>
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to Anwar Mohamed
* anwarelmakrahy[at]gmail.com
*
*/
#include "Packetyzer.h"
#include <map>
#include <fstream>
using namespace std;
using namespace Packetyzer::Elements;
cTCPReassembler::cTCPReassembler(cPacket* Packet, UINT TotalSize, UINT BodySize)
{
RefPacket = Packet;
this->TotalSize = TotalSize;
CurrentSize = BodySize;
isReassembled = FALSE;
DataStreamContainer = new DATASTREAM;
DataStreamContainer->Pointer = Packet->TCPData;
DataStreamContainer->Size = BodySize;
DataStream[ntohl(Packet->TCPHeader->Sequence)] = DataStreamContainer;
}
BOOL cTCPReassembler::AddPacket(cPacket* Packet)
{
if (isReassembled ||
!Packet->isTCPPacket ||
!BelongsToStream(Packet))
return FALSE;
DataStreamContainer = new DATASTREAM;
DataStreamContainer->Pointer = Packet->TCPData;
DataStreamContainer->Size = Packet->TCPDataSize;
CurrentSize += Packet->TCPDataSize;
if (DataStream[ntohl(Packet->TCPHeader->Sequence)] == NULL)
DataStream[ntohl(Packet->TCPHeader->Sequence)] = DataStreamContainer;
else {
CurrentSize -= DataStream[ntohl(Packet->TCPHeader->Sequence)]->Size;
delete DataStream[ntohl(Packet->TCPHeader->Sequence)];
DataStream[ntohl(Packet->TCPHeader->Sequence)] = DataStreamContainer;
}
if (CurrentSize == TotalSize)
isReassembled = TRUE;
return TRUE;
}
cTCPReassembler::~cTCPReassembler()
{
Empty();
}
void cTCPReassembler::Empty()
{
for (DataStreamIterator = DataStream.begin();
DataStreamIterator != DataStream.end();
++DataStreamIterator)
{
delete DataStreamIterator->second;
}
DataStream.clear();
}
BOOL cTCPReassembler::BelongsToStream(cPacket* Packet)
{
if (Packet->IPHeader->DestinationAddress == RefPacket->IPHeader->DestinationAddress &&
Packet->IPHeader->SourceAddress == RefPacket->IPHeader->SourceAddress &&
Packet->TCPHeader->DestinationPort == RefPacket->TCPHeader->DestinationPort &&
Packet->TCPHeader->SourcePort == RefPacket->TCPHeader->SourcePort &&
Packet->TCPHeader->Acknowledge == RefPacket->TCPHeader->Acknowledge &&
Packet->TCPDataSize > 0)
return TRUE;
return FALSE;
}
BOOL cTCPReassembler::Identify(cPacket* Packet, UINT AssumedDataSize)
{
if (Packet->TCPHeader->SynchroniseFlag == 1 &&
Packet->TCPHeader->AcknowledgmentFlag == 0 &&
Packet->TCPHeader->PushFlag == 0 &&
Packet->TCPHeader->FinishFlag == 0 &&
Packet->TCPDataSize == 0)
return TRUE;
else
return FALSE;
}
UCHAR* cTCPReassembler::GetReassembledStream()
{
Stream = new UCHAR[TotalSize];
PositionPointer = 0;
for (DataStreamIterator = DataStream.begin();
DataStreamIterator != DataStream.end();
++DataStreamIterator)
{
memcpy(
&Stream[PositionPointer],
DataStreamIterator->second->Pointer,
DataStreamIterator->second->Size);
PositionPointer += DataStreamIterator->second->Size;
}
return Stream;
}