File: check_http.pl

package info (click to toggle)
nfqueue-bindings 0.4-3
  • links: PTS
  • area: main
  • in suites: wheezy
  • size: 232 kB
  • sloc: ansic: 257; python: 211; perl: 183; makefile: 28; sh: 25
file content (96 lines) | stat: -rwxr-xr-x 1,718 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
#!/usr/bin/perl -w
#
# see http://search.cpan.org/~atrak/NetPacket-0.04/

use strict;

BEGIN {
	push @INC,"perl";
	push @INC,"build/perl";
	push @INC,"NetPacket-0.04";
};

use nfqueue;

use NetPacket::IP qw(IP_PROTO_TCP);
use NetPacket::TCP;
use Socket qw(AF_INET AF_INET6);

my $debug = 1;
my $q;

sub cleanup()
{
	print "unbind\n";
	$q->unbind(AF_INET);
	print "close\n";
	$q->close();
}

my @http_checks = (
	"^GET ",
	"^User-Agent",
);

sub _check_http
{
	my $data = shift;

	foreach my $check (@http_checks) {
		return 0 unless ($data =~ /$check/moi);
	}

	return 1;
}

sub cb
{
	my ($dummy,$payload) = @_;

	if ($payload) {
		print "\n";

		my $ip_obj = NetPacket::IP->decode($payload->get_data());
		print "Id: " . $payload->swig_id_get() . "\n";

		if($ip_obj->{proto} == IP_PROTO_TCP) {
			# decode the TCP header
			my $tcp_obj = NetPacket::TCP->decode($ip_obj->{data});

			if ($tcp_obj->{flags} & NetPacket::TCP::SYN) {
				print("$ip_obj->{src_ip} => $ip_obj->{dest_ip} $ip_obj->{proto}\n");
				print "TCP src_port: $tcp_obj->{src_port}\n";
				print "TCP dst_port: $tcp_obj->{dest_port}\n";
				print "TCP flags   : $tcp_obj->{flags}\n";
			}
			elsif ($tcp_obj->{flags} & NetPacket::TCP::PSH) {
				print "TCP data:\n";
				print "*" x 50 . "\n";
				print $tcp_obj->{data};
				print "*" x 50 . "\n";
				if ($tcp_obj->{dest_port} == 80) {
					_check_http($tcp_obj->{data}) or return $payload->set_verdict($nfqueue::NF_DROP);
				}
			}
		}

		print "\n";
		$payload->set_verdict($nfqueue::NF_ACCEPT);
	}
}


$q = new nfqueue::queue();

$SIG{INT} = "cleanup";

print "setting callback\n";
$q->set_callback(\&cb);

print "open\n";
$q->fast_open(0, AF_INET);

print "trying to run\n";
$q->try_run();