2001-06-12 13:17:16 +08:00
|
|
|
/*
|
2001-06-15 15:39:43 +08:00
|
|
|
* Copyright (c) 2001
|
2001-06-12 13:17:16 +08:00
|
|
|
* Fortress Technologies, Inc. All rights reserved.
|
|
|
|
* Charlie Lenahan (clenahan@fortresstech.com)
|
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted provided that: (1) source code distributions
|
|
|
|
* retain the above copyright notice and this paragraph in its entirety, (2)
|
|
|
|
* distributions including binary code include the above copyright notice and
|
|
|
|
* this paragraph in its entirety in the documentation or other materials
|
|
|
|
* provided with the distribution, and (3) all advertising materials mentioning
|
|
|
|
* features or use of this software display the following acknowledgement:
|
|
|
|
* ``This product includes software developed by the University of California,
|
|
|
|
* Lawrence Berkeley Laboratory and its contributors.'' Neither the name of
|
|
|
|
* the University nor the names of its contributors may be used to endorse
|
|
|
|
* or promote products derived from this software without specific prior
|
|
|
|
* written permission.
|
|
|
|
* THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR IMPLIED
|
|
|
|
* WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF
|
|
|
|
* MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
|
|
|
|
*/
|
|
|
|
|
2003-11-16 17:36:07 +08:00
|
|
|
#ifndef lint
|
|
|
|
static const char rcsid[] _U_ =
|
2004-09-24 05:57:24 +08:00
|
|
|
"@(#) $Header: /tcpdump/master/tcpdump/print-802_11.c,v 1.30 2004-09-23 21:57:25 dyoung Exp $ (LBL)";
|
2003-11-16 17:36:07 +08:00
|
|
|
#endif
|
2001-06-12 13:17:16 +08:00
|
|
|
|
|
|
|
#ifdef HAVE_CONFIG_H
|
|
|
|
#include "config.h"
|
|
|
|
#endif
|
|
|
|
|
2002-08-01 16:52:55 +08:00
|
|
|
#include <tcpdump-stdinc.h>
|
2001-06-12 13:17:16 +08:00
|
|
|
|
|
|
|
#include <stdio.h>
|
|
|
|
#include <pcap.h>
|
|
|
|
#include <string.h>
|
|
|
|
|
|
|
|
#include "interface.h"
|
|
|
|
#include "addrtoname.h"
|
|
|
|
#include "ethertype.h"
|
|
|
|
|
|
|
|
#include "extract.h"
|
|
|
|
|
2004-09-24 05:57:24 +08:00
|
|
|
#include "cpack.h"
|
|
|
|
|
2001-06-12 13:17:16 +08:00
|
|
|
#include "ieee802_11.h"
|
2004-09-24 05:57:24 +08:00
|
|
|
#include "ieee802_11_radio.h"
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2004-09-24 05:57:24 +08:00
|
|
|
#define PRINT_RATE(_sep, _r, _suf) \
|
|
|
|
printf("%s%2.1f%s", _sep, (.5 * ((_r) & 0x7f)), _suf)
|
2002-05-13 16:30:19 +08:00
|
|
|
#define PRINT_RATES(p) \
|
2001-06-15 15:39:43 +08:00
|
|
|
do { \
|
2002-05-13 16:30:19 +08:00
|
|
|
int z; \
|
Add a few more GCC warnings on GCC >= 2 for ".devel" builds.
From Neil T. Spring: fixes for many of those warnings:
addrtoname.c, configure.in: Linux needs netinet/ether.h for
ether_ntohost
print-*.c: change char *foo = "bar" to const char *foo = "bar"
to appease -Wwrite-strings; should affect no run-time behavior.
print-*.c: make some variables unsigned.
print-bgp.c: plen ('prefix len') is unsigned, no reason to
validate by comparing to zero.
print-cnfp.c, print-rx.c: use intoa, provided by addrtoname,
instead of inet_ntoa.
print-domain.c: unsigned int l; (l=foo()) < 0 is guaranteed to
be false, so check for (u_int)-1, which represents failure,
explicitly.
print-isakmp.c: complete initialization of attrmap objects.
print-lwres.c: "if(x); print foo;" seemed much more likely to be
intended to be "if(x) { print foo; }".
print-smb.c: complete initialization of some structures.
In addition, add some fixes for the signed vs. unsigned comparison
warnings:
extract.h: cast the result of the byte-extraction-and-combining,
as, at least for the 16-bit version, C's integral promotions
will turn "u_int16_t" into "int" if there are other "int"s
nearby.
print-*.c: make some more variables unsigned, or add casts to an
unsigned type of signed values known not to be negative, or add
casts to "int" of unsigned values known to fit in an "int", and
make other changes needed to handle the aforementioned variables
now being unsigned.
print-isakmp.c: clean up the handling of error/status indicators
in notify messages.
print-ppp.c: get rid of a check that an unsigned quantity is >=
0.
print-radius.c: clean up some of the bounds checking.
print-smb.c: extract the word count into a "u_int" to avoid the
aforementioned problems with C's integral promotions.
print-snmp.c: change a check that an unsigned variable is >= 0
to a check that it's != 0.
Also, fix some formats to use "%u" rather than "%d" for unsigned
quantities.
2002-09-05 08:00:07 +08:00
|
|
|
const char *sep = " ["; \
|
2002-05-13 16:30:19 +08:00
|
|
|
for (z = 0; z < p.rates.length ; z++) { \
|
2004-09-24 05:57:24 +08:00
|
|
|
PRINT_RATE(sep, p.rates.rate[z], \
|
|
|
|
(p.rates.rate[z] & 0x80 ? "*" : "")); \
|
2002-05-13 16:30:19 +08:00
|
|
|
sep = " "; \
|
|
|
|
} \
|
|
|
|
if (p.rates.length != 0) \
|
|
|
|
printf(" Mbit]"); \
|
2001-06-15 15:39:43 +08:00
|
|
|
} while (0)
|
2001-06-12 13:17:16 +08:00
|
|
|
|
|
|
|
static const char *auth_alg_text[]={"Open System","Shared Key","EAP"};
|
|
|
|
static const char *subtype_text[]={
|
|
|
|
"Assoc Request",
|
|
|
|
"Assoc Response",
|
|
|
|
"ReAssoc Request",
|
|
|
|
"ReAssoc Response",
|
|
|
|
"Probe Request",
|
|
|
|
"Probe Response",
|
2003-11-27 10:51:04 +08:00
|
|
|
"",
|
|
|
|
"",
|
2001-06-12 13:17:16 +08:00
|
|
|
"Beacon",
|
|
|
|
"ATIM",
|
|
|
|
"Disassociation",
|
|
|
|
"Authentication",
|
|
|
|
"DeAuthentication",
|
2003-11-27 10:51:04 +08:00
|
|
|
"",
|
|
|
|
""
|
2001-06-12 13:17:16 +08:00
|
|
|
};
|
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
static const char *status_text[] = {
|
|
|
|
"Succesful", /* 0 */
|
|
|
|
"Unspecified failure", /* 1 */
|
|
|
|
"Reserved", /* 2 */
|
|
|
|
"Reserved", /* 3 */
|
|
|
|
"Reserved", /* 4 */
|
|
|
|
"Reserved", /* 5 */
|
|
|
|
"Reserved", /* 6 */
|
|
|
|
"Reserved", /* 7 */
|
|
|
|
"Reserved", /* 8 */
|
|
|
|
"Reserved", /* 9 */
|
|
|
|
"Cannot Support all requested capabilities in the Capability Information field", /* 10 */
|
|
|
|
"Reassociation denied due to inability to confirm that association exists", /* 11 */
|
|
|
|
"Association denied due to reason outside the scope of the standard", /* 12 */
|
|
|
|
"Responding station does not support the specified authentication algorithm ", /* 13 */
|
|
|
|
"Received an Authentication frame with authentication transaction " \
|
|
|
|
"sequence number out of expected sequence", /* 14 */
|
|
|
|
"Authentication rejected because of challenge failure", /* 15 */
|
|
|
|
"Authentication rejected due to timeout waiting for next frame in sequence", /* 16 */
|
|
|
|
"Association denied because AP is unable to handle additional associated stations", /* 17 */
|
|
|
|
"Association denied due to requesting station not supporting all of the " \
|
|
|
|
"data rates in BSSBasicRateSet parameter", /* 18 */
|
|
|
|
NULL
|
|
|
|
};
|
|
|
|
|
|
|
|
static const char *reason_text[] = {
|
|
|
|
"Reserved", /* 0 */
|
|
|
|
"Unspecified reason", /* 1 */
|
|
|
|
"Previous authentication no longer valid", /* 2 */
|
|
|
|
"Deauthenticated because sending station is leaving (or has left) IBSS or ESS", /* 3 */
|
|
|
|
"Disassociated due to inactivity", /* 4 */
|
|
|
|
"Disassociated because AP is unable to handle all currently associated stations", /* 5 */
|
|
|
|
"Class 2 frame receivedfrom nonauthenticated station", /* 6 */
|
|
|
|
"Class 3 frame received from nonassociated station", /* 7 */
|
|
|
|
"Disassociated because sending station is leaving (or has left) BSS", /* 8 */
|
|
|
|
"Station requesting (re)association is not authenticated with responding station", /* 9 */
|
|
|
|
NULL
|
|
|
|
};
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
|
|
|
wep_print(const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
u_int32_t iv;
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*p, IEEE802_11_IV_LEN + IEEE802_11_KID_LEN))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
iv = EXTRACT_LE_32BITS(p);
|
|
|
|
|
|
|
|
printf("Data IV:%3x Pad %x KeyID %x", IV_IV(iv), IV_PAD(iv),
|
|
|
|
IV_KEYID(iv));
|
|
|
|
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
|
|
|
parse_elements(struct mgmt_body_t *pbody, const u_char *p, int offset)
|
2001-06-15 15:39:43 +08:00
|
|
|
{
|
2001-06-13 15:25:57 +08:00
|
|
|
for (;;) {
|
2001-06-15 15:39:43 +08:00
|
|
|
if (!TTEST2(*(p + offset), 1))
|
2002-05-13 16:30:19 +08:00
|
|
|
return 1;
|
2001-06-15 15:39:43 +08:00
|
|
|
switch (*(p + offset)) {
|
|
|
|
case E_SSID:
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*(p + offset), 2))
|
2001-06-15 15:39:43 +08:00
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
memcpy(&pbody->ssid, p + offset, 2);
|
|
|
|
offset += 2;
|
|
|
|
if (pbody->ssid.length <= 0)
|
|
|
|
break;
|
|
|
|
if (!TTEST2(*(p + offset), pbody->ssid.length))
|
|
|
|
return 0;
|
|
|
|
memcpy(&pbody->ssid.ssid, p + offset,
|
|
|
|
pbody->ssid.length);
|
|
|
|
offset += pbody->ssid.length;
|
|
|
|
pbody->ssid.ssid[pbody->ssid.length] = '\0';
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case E_CHALLENGE:
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*(p + offset), 2))
|
2001-06-15 15:39:43 +08:00
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
memcpy(&pbody->challenge, p + offset, 2);
|
|
|
|
offset += 2;
|
|
|
|
if (pbody->challenge.length <= 0)
|
|
|
|
break;
|
|
|
|
if (!TTEST2(*(p + offset), pbody->challenge.length))
|
|
|
|
return 0;
|
|
|
|
memcpy(&pbody->challenge.text, p + offset,
|
|
|
|
pbody->challenge.length);
|
|
|
|
offset += pbody->challenge.length;
|
|
|
|
pbody->challenge.text[pbody->challenge.length] = '\0';
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case E_RATES:
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*(p + offset), 2))
|
2001-06-15 15:39:43 +08:00
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
memcpy(&(pbody->rates), p + offset, 2);
|
|
|
|
offset += 2;
|
|
|
|
if (pbody->rates.length <= 0)
|
|
|
|
break;
|
|
|
|
if (!TTEST2(*(p + offset), pbody->rates.length))
|
|
|
|
return 0;
|
|
|
|
memcpy(&pbody->rates.rate, p + offset,
|
|
|
|
pbody->rates.length);
|
|
|
|
offset += pbody->rates.length;
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case E_DS:
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*(p + offset), 3))
|
2001-06-15 15:39:43 +08:00
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
memcpy(&pbody->ds, p + offset, 3);
|
|
|
|
offset += 3;
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case E_CF:
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*(p + offset), 8))
|
2001-06-15 15:39:43 +08:00
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
memcpy(&pbody->cf, p + offset, 8);
|
|
|
|
offset += 8;
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case E_TIM:
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*(p + offset), 2))
|
2001-06-15 15:39:43 +08:00
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
memcpy(&pbody->tim, p + offset, 2);
|
|
|
|
offset += 2;
|
|
|
|
if (!TTEST2(*(p + offset), 3))
|
2001-06-15 15:39:43 +08:00
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
memcpy(&pbody->tim.count, p + offset, 3);
|
|
|
|
offset += 3;
|
2001-06-15 15:39:43 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (pbody->tim.length <= 3)
|
|
|
|
break;
|
|
|
|
if (!TTEST2(*(p + offset), pbody->tim.length - 3))
|
|
|
|
return 0;
|
|
|
|
memcpy(pbody->tim.bitmap, p + (pbody->tim.length - 3),
|
|
|
|
(pbody->tim.length - 3));
|
|
|
|
offset += pbody->tim.length - 3;
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
default:
|
2001-06-12 13:17:16 +08:00
|
|
|
#if 0
|
2003-07-23 01:35:04 +08:00
|
|
|
printf("(1) unhandled element_id (%d) ",
|
|
|
|
*(p + offset) );
|
2001-06-12 13:17:16 +08:00
|
|
|
#endif
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += *(p + offset + 1) + 2;
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
}
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/*********************************************************************************
|
|
|
|
* Print Handle functions for the management frame types
|
|
|
|
*********************************************************************************/
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
2003-12-10 17:51:03 +08:00
|
|
|
handle_beacon(const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
struct mgmt_body_t pbody;
|
2001-06-15 15:39:43 +08:00
|
|
|
int offset = 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
memset(&pbody, 0, sizeof(pbody));
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*p, IEEE802_11_TSTAMP_LEN + IEEE802_11_BCNINT_LEN +
|
|
|
|
IEEE802_11_CAPINFO_LEN))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-15 15:39:43 +08:00
|
|
|
memcpy(&pbody.timestamp, p, 8);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_TSTAMP_LEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.beacon_interval = EXTRACT_LE_16BITS(p+offset);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_BCNINT_LEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.capability_info = EXTRACT_LE_16BITS(p+offset);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_CAPINFO_LEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!parse_elements(&pbody, p, offset))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-11-27 10:18:53 +08:00
|
|
|
printf(" (");
|
2002-05-13 16:30:19 +08:00
|
|
|
fn_print(pbody.ssid.ssid, NULL);
|
|
|
|
printf(")");
|
|
|
|
PRINT_RATES(pbody);
|
2002-12-11 12:56:44 +08:00
|
|
|
printf(" %s CH: %u%s",
|
2001-06-15 15:39:43 +08:00
|
|
|
CAPABILITY_ESS(pbody.capability_info) ? "ESS" : "IBSS",
|
|
|
|
pbody.ds.channel,
|
|
|
|
CAPABILITY_PRIVACY(pbody.capability_info) ? ", PRIVACY" : "" );
|
|
|
|
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
2003-12-10 17:51:03 +08:00
|
|
|
handle_assoc_request(const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
struct mgmt_body_t pbody;
|
2001-06-15 15:39:43 +08:00
|
|
|
int offset = 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
memset(&pbody, 0, sizeof(pbody));
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*p, IEEE802_11_CAPINFO_LEN + IEEE802_11_LISTENINT_LEN))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.capability_info = EXTRACT_LE_16BITS(p);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_CAPINFO_LEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.listen_interval = EXTRACT_LE_16BITS(p+offset);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_LISTENINT_LEN;
|
2001-06-15 15:39:43 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!parse_elements(&pbody, p, offset))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-11-27 10:18:53 +08:00
|
|
|
printf(" (");
|
2002-05-13 16:30:19 +08:00
|
|
|
fn_print(pbody.ssid.ssid, NULL);
|
|
|
|
printf(")");
|
|
|
|
PRINT_RATES(pbody);
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
2003-12-10 17:51:03 +08:00
|
|
|
handle_assoc_response(const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
struct mgmt_body_t pbody;
|
2001-06-15 15:39:43 +08:00
|
|
|
int offset = 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
memset(&pbody, 0, sizeof(pbody));
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*p, IEEE802_11_CAPINFO_LEN + IEEE802_11_STATUS_LEN +
|
|
|
|
IEEE802_11_AID_LEN))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.capability_info = EXTRACT_LE_16BITS(p);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_CAPINFO_LEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.status_code = EXTRACT_LE_16BITS(p+offset);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_STATUS_LEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.aid = EXTRACT_LE_16BITS(p+offset);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_AID_LEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!parse_elements(&pbody, p, offset))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-11-27 10:18:53 +08:00
|
|
|
printf(" AID(%x) :%s: %s", ((u_int16_t)(pbody.aid << 2 )) >> 2 ,
|
2001-06-15 15:39:43 +08:00
|
|
|
CAPABILITY_PRIVACY(pbody.capability_info) ? " PRIVACY " : "",
|
|
|
|
(pbody.status_code < 19 ? status_text[pbody.status_code] : "n/a"));
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
2003-12-10 17:51:03 +08:00
|
|
|
handle_reassoc_request(const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
struct mgmt_body_t pbody;
|
2001-06-15 15:39:43 +08:00
|
|
|
int offset = 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
memset(&pbody, 0, sizeof(pbody));
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*p, IEEE802_11_CAPINFO_LEN + IEEE802_11_LISTENINT_LEN +
|
|
|
|
IEEE802_11_AP_LEN))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.capability_info = EXTRACT_LE_16BITS(p);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_CAPINFO_LEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.listen_interval = EXTRACT_LE_16BITS(p+offset);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_LISTENINT_LEN;
|
|
|
|
memcpy(&pbody.ap, p+offset, IEEE802_11_AP_LEN);
|
|
|
|
offset += IEEE802_11_AP_LEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!parse_elements(&pbody, p, offset))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-11-27 10:18:53 +08:00
|
|
|
printf(" (");
|
2002-05-13 16:30:19 +08:00
|
|
|
fn_print(pbody.ssid.ssid, NULL);
|
|
|
|
printf(") AP : %s", etheraddr_string( pbody.ap ));
|
2001-06-15 15:39:43 +08:00
|
|
|
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
2003-12-10 17:51:03 +08:00
|
|
|
handle_reassoc_response(const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
/* Same as a Association Reponse */
|
2003-12-10 17:51:03 +08:00
|
|
|
return handle_assoc_response(p);
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
2003-12-10 17:51:03 +08:00
|
|
|
handle_probe_request(const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
struct mgmt_body_t pbody;
|
2001-06-15 15:39:43 +08:00
|
|
|
int offset = 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
memset(&pbody, 0, sizeof(pbody));
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
if (!parse_elements(&pbody, p, offset))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-11-27 10:18:53 +08:00
|
|
|
printf(" (");
|
2002-05-13 16:30:19 +08:00
|
|
|
fn_print(pbody.ssid.ssid, NULL);
|
|
|
|
printf(")");
|
|
|
|
PRINT_RATES(pbody);
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
2003-12-10 17:51:03 +08:00
|
|
|
handle_probe_response(const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
struct mgmt_body_t pbody;
|
2001-06-15 15:39:43 +08:00
|
|
|
int offset = 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
memset(&pbody, 0, sizeof(pbody));
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*p, IEEE802_11_TSTAMP_LEN + IEEE802_11_BCNINT_LEN +
|
|
|
|
IEEE802_11_CAPINFO_LEN))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
|
|
|
|
memcpy(&pbody.timestamp, p, IEEE802_11_TSTAMP_LEN);
|
|
|
|
offset += IEEE802_11_TSTAMP_LEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.beacon_interval = EXTRACT_LE_16BITS(p+offset);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_BCNINT_LEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.capability_info = EXTRACT_LE_16BITS(p+offset);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_CAPINFO_LEN;
|
2001-06-15 15:39:43 +08:00
|
|
|
|
|
|
|
if (!parse_elements(&pbody, p, offset))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-11-27 10:18:53 +08:00
|
|
|
printf(" (");
|
2002-05-13 16:30:19 +08:00
|
|
|
fn_print(pbody.ssid.ssid, NULL);
|
|
|
|
printf(") ");
|
|
|
|
PRINT_RATES(pbody);
|
|
|
|
printf(" CH: %u%s", pbody.ds.channel,
|
|
|
|
CAPABILITY_PRIVACY(pbody.capability_info) ? ", PRIVACY" : "" );
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
|
|
|
handle_atim(void)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
/* the frame body for ATIM is null. */
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
2003-12-10 17:51:03 +08:00
|
|
|
handle_disassoc(const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
struct mgmt_body_t pbody;
|
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
memset(&pbody, 0, sizeof(pbody));
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*p, IEEE802_11_REASON_LEN))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.reason_code = EXTRACT_LE_16BITS(p);
|
|
|
|
|
2003-11-27 10:18:53 +08:00
|
|
|
printf(": %s",
|
2003-07-23 01:35:04 +08:00
|
|
|
(pbody.reason_code < 10) ? reason_text[pbody.reason_code]
|
|
|
|
: "Reserved" );
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
2003-12-10 17:51:03 +08:00
|
|
|
handle_auth(const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
struct mgmt_body_t pbody;
|
2001-06-15 15:39:43 +08:00
|
|
|
int offset = 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
memset(&pbody, 0, sizeof(pbody));
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-13 15:25:57 +08:00
|
|
|
if (!TTEST2(*p, 6))
|
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.auth_alg = EXTRACT_LE_16BITS(p);
|
|
|
|
offset += 2;
|
2001-06-15 15:39:43 +08:00
|
|
|
pbody.auth_trans_seq_num = EXTRACT_LE_16BITS(p + offset);
|
2001-06-12 13:17:16 +08:00
|
|
|
offset += 2;
|
2001-06-15 15:39:43 +08:00
|
|
|
pbody.status_code = EXTRACT_LE_16BITS(p + offset);
|
2001-06-12 13:17:16 +08:00
|
|
|
offset += 2;
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!parse_elements(&pbody, p, offset))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
if ((pbody.auth_alg == 1) &&
|
2003-07-23 01:35:04 +08:00
|
|
|
((pbody.auth_trans_seq_num == 2) ||
|
|
|
|
(pbody.auth_trans_seq_num == 3))) {
|
2003-11-27 10:18:53 +08:00
|
|
|
printf(" (%s)-%x [Challenge Text] %s",
|
2003-07-23 01:35:04 +08:00
|
|
|
(pbody.auth_alg < 4) ? auth_alg_text[pbody.auth_alg]
|
|
|
|
: "Reserved",
|
2001-06-15 15:39:43 +08:00
|
|
|
pbody.auth_trans_seq_num,
|
2003-07-23 01:35:04 +08:00
|
|
|
((pbody.auth_trans_seq_num % 2)
|
|
|
|
? ((pbody.status_code < 19)
|
|
|
|
? status_text[pbody.status_code]
|
|
|
|
: "n/a") : ""));
|
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
2003-11-27 10:18:53 +08:00
|
|
|
printf(" (%s)-%x: %s",
|
2003-07-23 01:35:04 +08:00
|
|
|
(pbody.auth_alg < 4) ? auth_alg_text[pbody.auth_alg] : "Reserved",
|
|
|
|
pbody.auth_trans_seq_num,
|
|
|
|
(pbody.auth_trans_seq_num % 2)
|
|
|
|
? ((pbody.status_code < 19) ? status_text[pbody.status_code]
|
|
|
|
: "n/a")
|
|
|
|
: "");
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
2003-12-10 17:51:03 +08:00
|
|
|
handle_deauth(const struct mgmt_header_t *pmh, const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
struct mgmt_body_t pbody;
|
2001-06-15 15:39:43 +08:00
|
|
|
int offset = 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
const char *reason = NULL;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
memset(&pbody, 0, sizeof(pbody));
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!TTEST2(*p, IEEE802_11_REASON_LEN))
|
2001-06-13 15:25:57 +08:00
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
pbody.reason_code = EXTRACT_LE_16BITS(p);
|
2003-07-23 01:35:04 +08:00
|
|
|
offset += IEEE802_11_REASON_LEN;
|
|
|
|
|
|
|
|
reason = (pbody.reason_code < 10) ? reason_text[pbody.reason_code]
|
|
|
|
: "Reserved";
|
2001-06-15 15:39:43 +08:00
|
|
|
|
|
|
|
if (eflag) {
|
2003-11-27 10:18:53 +08:00
|
|
|
printf(": %s", reason);
|
2001-06-15 15:39:43 +08:00
|
|
|
} else {
|
2003-11-27 10:18:53 +08:00
|
|
|
printf(" (%s): %s", etheraddr_string(pmh->sa), reason);
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/*********************************************************************************
|
|
|
|
* Print Body funcs
|
|
|
|
*********************************************************************************/
|
|
|
|
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
|
|
|
mgmt_body_print(u_int16_t fc, const struct mgmt_header_t *pmh,
|
2002-09-06 05:25:34 +08:00
|
|
|
const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
2003-11-27 10:18:53 +08:00
|
|
|
printf("%s", subtype_text[FC_SUBTYPE(fc)]);
|
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
switch (FC_SUBTYPE(fc)) {
|
|
|
|
case ST_ASSOC_REQUEST:
|
2003-12-10 17:51:03 +08:00
|
|
|
return handle_assoc_request(p);
|
2001-06-15 15:39:43 +08:00
|
|
|
case ST_ASSOC_RESPONSE:
|
2003-12-10 17:51:03 +08:00
|
|
|
return handle_assoc_response(p);
|
2001-06-15 15:39:43 +08:00
|
|
|
case ST_REASSOC_REQUEST:
|
2003-12-10 17:51:03 +08:00
|
|
|
return handle_reassoc_request(p);
|
2001-06-15 15:39:43 +08:00
|
|
|
case ST_REASSOC_RESPONSE:
|
2003-12-10 17:51:03 +08:00
|
|
|
return handle_reassoc_response(p);
|
2001-06-15 15:39:43 +08:00
|
|
|
case ST_PROBE_REQUEST:
|
2003-12-10 17:51:03 +08:00
|
|
|
return handle_probe_request(p);
|
2001-06-15 15:39:43 +08:00
|
|
|
case ST_PROBE_RESPONSE:
|
2003-12-10 17:51:03 +08:00
|
|
|
return handle_probe_response(p);
|
2001-06-15 15:39:43 +08:00
|
|
|
case ST_BEACON:
|
2003-12-10 17:51:03 +08:00
|
|
|
return handle_beacon(p);
|
2001-06-15 15:39:43 +08:00
|
|
|
case ST_ATIM:
|
2003-07-23 01:35:04 +08:00
|
|
|
return handle_atim();
|
2001-06-15 15:39:43 +08:00
|
|
|
case ST_DISASSOC:
|
2003-12-10 17:51:03 +08:00
|
|
|
return handle_disassoc(p);
|
2001-06-15 15:39:43 +08:00
|
|
|
case ST_AUTH:
|
|
|
|
if (!TTEST2(*p, 3))
|
|
|
|
return 0;
|
|
|
|
if ((p[0] == 0 ) && (p[1] == 0) && (p[2] == 0)) {
|
|
|
|
printf("Authentication (Shared-Key)-3 ");
|
2003-07-23 01:35:04 +08:00
|
|
|
return wep_print(p);
|
2001-06-15 15:39:43 +08:00
|
|
|
}
|
2003-12-10 17:51:03 +08:00
|
|
|
return handle_auth(p);
|
2001-06-15 15:39:43 +08:00
|
|
|
case ST_DEAUTH:
|
2003-12-10 17:51:03 +08:00
|
|
|
return handle_deauth(pmh, p);
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
default:
|
2003-11-19 10:01:40 +08:00
|
|
|
printf("Unhandled Management subtype(%x)",
|
2001-06-15 15:39:43 +08:00
|
|
|
FC_SUBTYPE(fc));
|
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/*********************************************************************************
|
|
|
|
* Handles printing all the control frame types
|
|
|
|
*********************************************************************************/
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
|
|
|
ctrl_body_print(u_int16_t fc, const u_char *p)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
2001-06-15 15:39:43 +08:00
|
|
|
switch (FC_SUBTYPE(fc)) {
|
|
|
|
case CTRL_PS_POLL:
|
2003-07-23 01:36:57 +08:00
|
|
|
printf("Power Save-Poll");
|
|
|
|
if (!TTEST2(*p, CTRL_PS_POLL_HDRLEN))
|
2001-06-15 15:39:43 +08:00
|
|
|
return 0;
|
2003-07-23 01:36:57 +08:00
|
|
|
printf(" AID(%x)",
|
2001-09-18 05:57:50 +08:00
|
|
|
EXTRACT_LE_16BITS(&(((const struct ctrl_ps_poll_t *)p)->aid)));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case CTRL_RTS:
|
2003-07-23 01:35:04 +08:00
|
|
|
printf("Request-To-Send");
|
2003-07-23 01:36:57 +08:00
|
|
|
if (!TTEST2(*p, CTRL_RTS_HDRLEN))
|
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!eflag)
|
|
|
|
printf(" TA:%s ",
|
2001-09-18 05:57:50 +08:00
|
|
|
etheraddr_string(((const struct ctrl_rts_t *)p)->ta));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case CTRL_CTS:
|
2003-07-23 01:35:04 +08:00
|
|
|
printf("Clear-To-Send");
|
2003-07-23 01:36:57 +08:00
|
|
|
if (!TTEST2(*p, CTRL_CTS_HDRLEN))
|
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!eflag)
|
|
|
|
printf(" RA:%s ",
|
2001-09-18 05:57:50 +08:00
|
|
|
etheraddr_string(((const struct ctrl_cts_t *)p)->ra));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case CTRL_ACK:
|
2003-07-23 01:35:04 +08:00
|
|
|
printf("Acknowledgment");
|
2003-07-23 01:36:57 +08:00
|
|
|
if (!TTEST2(*p, CTRL_ACK_HDRLEN))
|
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!eflag)
|
|
|
|
printf(" RA:%s ",
|
2001-09-18 05:57:50 +08:00
|
|
|
etheraddr_string(((const struct ctrl_ack_t *)p)->ra));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case CTRL_CF_END:
|
2003-07-23 01:35:04 +08:00
|
|
|
printf("CF-End");
|
2003-07-23 01:36:57 +08:00
|
|
|
if (!TTEST2(*p, CTRL_END_HDRLEN))
|
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!eflag)
|
|
|
|
printf(" RA:%s ",
|
2001-09-18 05:57:50 +08:00
|
|
|
etheraddr_string(((const struct ctrl_end_t *)p)->ra));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case CTRL_END_ACK:
|
2003-07-23 01:35:04 +08:00
|
|
|
printf("CF-End+CF-Ack");
|
2003-07-23 01:36:57 +08:00
|
|
|
if (!TTEST2(*p, CTRL_END_ACK_HDRLEN))
|
|
|
|
return 0;
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!eflag)
|
|
|
|
printf(" RA:%s ",
|
2001-09-18 05:57:50 +08:00
|
|
|
etheraddr_string(((const struct ctrl_end_ack_t *)p)->ra));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
default:
|
2003-07-23 01:35:04 +08:00
|
|
|
printf("Unknown Ctrl Subtype");
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
2001-06-13 15:25:57 +08:00
|
|
|
return 1;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
/*
|
2001-06-12 13:17:16 +08:00
|
|
|
* Print Header funcs
|
2001-06-15 15:39:43 +08:00
|
|
|
*/
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
/*
|
2001-06-12 13:17:16 +08:00
|
|
|
* Data Frame - Address field contents
|
|
|
|
*
|
|
|
|
* To Ds | From DS | Addr 1 | Addr 2 | Addr 3 | Addr 4
|
|
|
|
* 0 | 0 | DA | SA | BSSID | n/a
|
|
|
|
* 0 | 1 | DA | BSSID | SA | n/a
|
|
|
|
* 1 | 0 | BSSID | SA | DA | n/a
|
|
|
|
* 1 | 1 | RA | TA | DA | SA
|
2001-06-15 15:39:43 +08:00
|
|
|
*/
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2002-12-18 16:53:18 +08:00
|
|
|
static void
|
|
|
|
data_header_print(u_int16_t fc, const u_char *p, const u_int8_t **srcp,
|
|
|
|
const u_int8_t **dstp)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
2003-02-04 13:53:21 +08:00
|
|
|
switch (FC_SUBTYPE(fc)) {
|
|
|
|
case DATA_DATA:
|
|
|
|
case DATA_NODATA:
|
|
|
|
break;
|
|
|
|
case DATA_DATA_CF_ACK:
|
|
|
|
case DATA_NODATA_CF_ACK:
|
|
|
|
printf("CF Ack ");
|
|
|
|
break;
|
|
|
|
case DATA_DATA_CF_POLL:
|
|
|
|
case DATA_NODATA_CF_POLL:
|
|
|
|
printf("CF Poll ");
|
|
|
|
break;
|
|
|
|
case DATA_DATA_CF_ACK_POLL:
|
|
|
|
case DATA_NODATA_CF_ACK_POLL:
|
|
|
|
printf("CF Ack/Poll ");
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
#define ADDR1 (p + 4)
|
|
|
|
#define ADDR2 (p + 10)
|
|
|
|
#define ADDR3 (p + 16)
|
|
|
|
#define ADDR4 (p + 24)
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!FC_TO_DS(fc) && !FC_FROM_DS(fc)) {
|
|
|
|
if (srcp != NULL)
|
|
|
|
*srcp = ADDR2;
|
|
|
|
if (dstp != NULL)
|
|
|
|
*dstp = ADDR1;
|
|
|
|
if (!eflag)
|
|
|
|
return;
|
|
|
|
printf("DA:%s SA:%s BSSID:%s ",
|
|
|
|
etheraddr_string(ADDR1), etheraddr_string(ADDR2),
|
|
|
|
etheraddr_string(ADDR3));
|
|
|
|
} else if (!FC_TO_DS(fc) && FC_FROM_DS(fc)) {
|
|
|
|
if (srcp != NULL)
|
|
|
|
*srcp = ADDR3;
|
|
|
|
if (dstp != NULL)
|
|
|
|
*dstp = ADDR1;
|
|
|
|
if (!eflag)
|
|
|
|
return;
|
|
|
|
printf("DA:%s BSSID:%s SA:%s ",
|
|
|
|
etheraddr_string(ADDR1), etheraddr_string(ADDR2),
|
|
|
|
etheraddr_string(ADDR3));
|
|
|
|
} else if (FC_TO_DS(fc) && !FC_FROM_DS(fc)) {
|
|
|
|
if (srcp != NULL)
|
|
|
|
*srcp = ADDR2;
|
|
|
|
if (dstp != NULL)
|
|
|
|
*dstp = ADDR3;
|
|
|
|
if (!eflag)
|
|
|
|
return;
|
|
|
|
printf("BSSID:%s SA:%s DA:%s ",
|
|
|
|
etheraddr_string(ADDR1), etheraddr_string(ADDR2),
|
|
|
|
etheraddr_string(ADDR3));
|
|
|
|
} else if (FC_TO_DS(fc) && FC_FROM_DS(fc)) {
|
|
|
|
if (srcp != NULL)
|
|
|
|
*srcp = ADDR4;
|
|
|
|
if (dstp != NULL)
|
|
|
|
*dstp = ADDR3;
|
|
|
|
if (!eflag)
|
|
|
|
return;
|
|
|
|
printf("RA:%s TA:%s DA:%s SA:%s ",
|
|
|
|
etheraddr_string(ADDR1), etheraddr_string(ADDR2),
|
|
|
|
etheraddr_string(ADDR3), etheraddr_string(ADDR4));
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
2001-06-15 15:39:43 +08:00
|
|
|
|
|
|
|
#undef ADDR1
|
|
|
|
#undef ADDR2
|
|
|
|
#undef ADDR3
|
|
|
|
#undef ADDR4
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2002-12-18 16:53:18 +08:00
|
|
|
static void
|
|
|
|
mgmt_header_print(const u_char *p, const u_int8_t **srcp,
|
|
|
|
const u_int8_t **dstp)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
2001-06-15 15:39:43 +08:00
|
|
|
const struct mgmt_header_t *hp = (const struct mgmt_header_t *) p;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2002-12-18 16:53:18 +08:00
|
|
|
if (srcp != NULL)
|
|
|
|
*srcp = hp->sa;
|
|
|
|
if (dstp != NULL)
|
|
|
|
*dstp = hp->da;
|
|
|
|
if (!eflag)
|
|
|
|
return;
|
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
printf("BSSID:%s DA:%s SA:%s ",
|
|
|
|
etheraddr_string((hp)->bssid), etheraddr_string((hp)->da),
|
|
|
|
etheraddr_string((hp)->sa));
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
|
2002-12-18 16:53:18 +08:00
|
|
|
static void
|
|
|
|
ctrl_header_print(u_int16_t fc, const u_char *p, const u_int8_t **srcp,
|
|
|
|
const u_int8_t **dstp)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
2002-12-18 16:53:18 +08:00
|
|
|
if (srcp != NULL)
|
|
|
|
*srcp = NULL;
|
|
|
|
if (dstp != NULL)
|
|
|
|
*dstp = NULL;
|
|
|
|
if (!eflag)
|
|
|
|
return;
|
|
|
|
|
2001-06-15 15:39:43 +08:00
|
|
|
switch (FC_SUBTYPE(fc)) {
|
|
|
|
case CTRL_PS_POLL:
|
|
|
|
printf("BSSID:%s TA:%s ",
|
2001-09-18 05:57:50 +08:00
|
|
|
etheraddr_string(((const struct ctrl_ps_poll_t *)p)->bssid),
|
|
|
|
etheraddr_string(((const struct ctrl_ps_poll_t *)p)->ta));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case CTRL_RTS:
|
|
|
|
printf("RA:%s TA:%s ",
|
2001-09-18 05:57:50 +08:00
|
|
|
etheraddr_string(((const struct ctrl_rts_t *)p)->ra),
|
|
|
|
etheraddr_string(((const struct ctrl_rts_t *)p)->ta));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case CTRL_CTS:
|
|
|
|
printf("RA:%s ",
|
2001-09-18 05:57:50 +08:00
|
|
|
etheraddr_string(((const struct ctrl_cts_t *)p)->ra));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case CTRL_ACK:
|
|
|
|
printf("RA:%s ",
|
2001-09-18 05:57:50 +08:00
|
|
|
etheraddr_string(((const struct ctrl_ack_t *)p)->ra));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case CTRL_CF_END:
|
|
|
|
printf("RA:%s BSSID:%s ",
|
2001-09-18 05:57:50 +08:00
|
|
|
etheraddr_string(((const struct ctrl_end_t *)p)->ra),
|
|
|
|
etheraddr_string(((const struct ctrl_end_t *)p)->bssid));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
case CTRL_END_ACK:
|
|
|
|
printf("RA:%s BSSID:%s ",
|
2001-09-18 05:57:50 +08:00
|
|
|
etheraddr_string(((const struct ctrl_end_ack_t *)p)->ra),
|
|
|
|
etheraddr_string(((const struct ctrl_end_ack_t *)p)->bssid));
|
2001-06-15 15:39:43 +08:00
|
|
|
break;
|
|
|
|
default:
|
|
|
|
printf("(H) Unknown Ctrl Subtype");
|
2002-12-18 16:53:18 +08:00
|
|
|
break;
|
2001-06-15 15:39:43 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
static int
|
|
|
|
extract_header_length(u_int16_t fc)
|
2001-06-15 15:39:43 +08:00
|
|
|
{
|
|
|
|
switch (FC_TYPE(fc)) {
|
|
|
|
case T_MGMT:
|
2003-07-23 01:36:57 +08:00
|
|
|
return MGMT_HDRLEN;
|
2001-06-15 15:39:43 +08:00
|
|
|
case T_CTRL:
|
|
|
|
switch (FC_SUBTYPE(fc)) {
|
2001-06-12 13:17:16 +08:00
|
|
|
case CTRL_PS_POLL:
|
2003-07-23 01:36:57 +08:00
|
|
|
return CTRL_PS_POLL_HDRLEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
case CTRL_RTS:
|
2003-07-23 01:36:57 +08:00
|
|
|
return CTRL_RTS_HDRLEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
case CTRL_CTS:
|
2003-07-23 01:36:57 +08:00
|
|
|
return CTRL_CTS_HDRLEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
case CTRL_ACK:
|
2003-07-23 01:36:57 +08:00
|
|
|
return CTRL_ACK_HDRLEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
case CTRL_CF_END:
|
2003-07-23 01:36:57 +08:00
|
|
|
return CTRL_END_HDRLEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
case CTRL_END_ACK:
|
2003-07-23 01:36:57 +08:00
|
|
|
return CTRL_END_ACK_HDRLEN;
|
2001-06-12 13:17:16 +08:00
|
|
|
default:
|
2003-07-23 01:35:04 +08:00
|
|
|
return 0;
|
2001-06-15 15:39:43 +08:00
|
|
|
}
|
|
|
|
case T_DATA:
|
2003-07-23 01:35:04 +08:00
|
|
|
return (FC_TO_DS(fc) && FC_FROM_DS(fc)) ? 30 : 24;
|
2001-06-15 15:39:43 +08:00
|
|
|
default:
|
2003-07-23 01:35:04 +08:00
|
|
|
printf("unknown IEEE802.11 frame type (%d)", FC_TYPE(fc));
|
|
|
|
return 0;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
2002-12-18 16:53:18 +08:00
|
|
|
* Print the 802.11 MAC header if eflag is set, and set "*srcp" and "*dstp"
|
|
|
|
* to point to the source and destination MAC addresses in any case if
|
|
|
|
* "srcp" and "dstp" aren't null.
|
2001-06-12 13:17:16 +08:00
|
|
|
*/
|
|
|
|
static inline void
|
2002-12-18 16:53:18 +08:00
|
|
|
ieee_802_11_hdr_print(u_int16_t fc, const u_char *p, const u_int8_t **srcp,
|
|
|
|
const u_int8_t **dstp)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
2003-02-04 13:53:21 +08:00
|
|
|
if (vflag) {
|
|
|
|
if (FC_MORE_DATA(fc))
|
|
|
|
printf("More Data ");
|
|
|
|
if (FC_MORE_FLAG(fc))
|
|
|
|
printf("More Fragments ");
|
|
|
|
if (FC_POWER_MGMT(fc))
|
|
|
|
printf("Pwr Mgmt ");
|
|
|
|
if (FC_RETRY(fc))
|
|
|
|
printf("Retry ");
|
|
|
|
if (FC_ORDER(fc))
|
|
|
|
printf("Strictly Ordered ");
|
|
|
|
if (FC_WEP(fc))
|
|
|
|
printf("WEP Encrypted ");
|
2003-07-23 01:36:57 +08:00
|
|
|
if (FC_TYPE(fc) != T_CTRL || FC_SUBTYPE(fc) != CTRL_PS_POLL)
|
|
|
|
printf("%dus ",
|
|
|
|
EXTRACT_LE_16BITS(
|
|
|
|
&((const struct mgmt_header_t *)p)->duration));
|
2003-02-04 13:53:21 +08:00
|
|
|
}
|
|
|
|
|
2001-06-12 13:17:16 +08:00
|
|
|
switch (FC_TYPE(fc)) {
|
|
|
|
case T_MGMT:
|
2002-12-18 16:53:18 +08:00
|
|
|
mgmt_header_print(p, srcp, dstp);
|
2001-06-12 13:17:16 +08:00
|
|
|
break;
|
|
|
|
case T_CTRL:
|
2002-12-18 16:53:18 +08:00
|
|
|
ctrl_header_print(fc, p, srcp, dstp);
|
2001-06-12 13:17:16 +08:00
|
|
|
break;
|
|
|
|
case T_DATA:
|
2002-12-18 16:53:18 +08:00
|
|
|
data_header_print(fc, p, srcp, dstp);
|
2001-06-12 13:17:16 +08:00
|
|
|
break;
|
|
|
|
default:
|
|
|
|
printf("(header) unknown IEEE802.11 frame type (%d)",
|
|
|
|
FC_TYPE(fc));
|
2002-12-18 16:53:18 +08:00
|
|
|
*srcp = NULL;
|
|
|
|
*dstp = NULL;
|
2001-06-12 13:17:16 +08:00
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2002-12-19 17:39:10 +08:00
|
|
|
static u_int
|
2002-12-12 15:28:35 +08:00
|
|
|
ieee802_11_print(const u_char *p, u_int length, u_int caplen)
|
2001-06-12 13:17:16 +08:00
|
|
|
{
|
|
|
|
u_int16_t fc;
|
2003-07-23 01:35:04 +08:00
|
|
|
u_int hdrlen;
|
2002-12-18 16:53:18 +08:00
|
|
|
const u_int8_t *src, *dst;
|
2001-06-12 13:17:16 +08:00
|
|
|
u_short extracted_ethertype;
|
|
|
|
|
2002-12-12 15:39:19 +08:00
|
|
|
if (caplen < IEEE802_11_FC_LEN) {
|
|
|
|
printf("[|802.11]");
|
2002-12-19 17:39:10 +08:00
|
|
|
return caplen;
|
2002-12-12 15:39:19 +08:00
|
|
|
}
|
|
|
|
|
2002-09-06 05:25:34 +08:00
|
|
|
fc = EXTRACT_LE_16BITS(p);
|
2003-07-23 01:35:04 +08:00
|
|
|
hdrlen = extract_header_length(fc);
|
2002-09-06 05:25:34 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (caplen < hdrlen) {
|
2002-09-06 05:25:34 +08:00
|
|
|
printf("[|802.11]");
|
2003-07-23 01:35:04 +08:00
|
|
|
return hdrlen;
|
2002-09-06 05:25:34 +08:00
|
|
|
}
|
2001-06-12 13:17:16 +08:00
|
|
|
|
2002-12-18 16:53:18 +08:00
|
|
|
ieee_802_11_hdr_print(fc, p, &src, &dst);
|
2001-06-12 13:17:16 +08:00
|
|
|
|
Add a new routine "default_print_packet()", which takes a pointer to the
beginning of the raw packet data, the captured length of the raw packet
data, and the length of the link-layer header, and:
if "-e" was specified, prints all the raw packet data;
if "-e" was not specified, prints all the raw packet data past
the link-layer header, if there is any.
Use that routine in all the "xxx_if_print()" routines if "-x" was
specified.
Make "arcnet_encap_print()" static - it's not used outside
"print-arcnet.c".
Add missing info printing code to "atm_if_print()".
Print the packet data in "lane_if_print()", not in "lane_print()", as
"lane_print()" can be called from other "xxx_if_print()" routines, and
those routines will also print the packet data if "-x" was specified -
no need to print it twice.
2002-12-18 17:41:13 +08:00
|
|
|
/*
|
|
|
|
* Go past the 802.11 header.
|
|
|
|
*/
|
2003-07-23 01:35:04 +08:00
|
|
|
length -= hdrlen;
|
|
|
|
caplen -= hdrlen;
|
|
|
|
p += hdrlen;
|
2001-06-12 13:17:16 +08:00
|
|
|
|
|
|
|
switch (FC_TYPE(fc)) {
|
|
|
|
case T_MGMT:
|
2002-12-18 16:53:18 +08:00
|
|
|
if (!mgmt_body_print(fc,
|
2003-07-23 01:35:04 +08:00
|
|
|
(const struct mgmt_header_t *)(p - hdrlen), p)) {
|
2001-06-13 15:25:57 +08:00
|
|
|
printf("[|802.11]");
|
2003-07-23 01:35:04 +08:00
|
|
|
return hdrlen;
|
2001-06-13 15:25:57 +08:00
|
|
|
}
|
2001-06-12 13:17:16 +08:00
|
|
|
break;
|
|
|
|
case T_CTRL:
|
2003-07-23 01:35:04 +08:00
|
|
|
if (!ctrl_body_print(fc, p - hdrlen)) {
|
2001-06-13 15:25:57 +08:00
|
|
|
printf("[|802.11]");
|
2003-07-23 01:35:04 +08:00
|
|
|
return hdrlen;
|
2001-06-13 15:25:57 +08:00
|
|
|
}
|
2001-06-12 13:17:16 +08:00
|
|
|
break;
|
|
|
|
case T_DATA:
|
|
|
|
/* There may be a problem w/ AP not having this bit set */
|
2002-06-12 01:08:37 +08:00
|
|
|
if (FC_WEP(fc)) {
|
2002-09-06 05:25:34 +08:00
|
|
|
if (!wep_print(p)) {
|
2001-06-13 15:25:57 +08:00
|
|
|
printf("[|802.11]");
|
2003-07-23 01:35:04 +08:00
|
|
|
return hdrlen;
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
2003-07-23 01:35:04 +08:00
|
|
|
} else if (llc_print(p, length, caplen, dst, src,
|
|
|
|
&extracted_ethertype) == 0) {
|
|
|
|
/*
|
|
|
|
* Some kinds of LLC packet we cannot
|
|
|
|
* handle intelligently
|
|
|
|
*/
|
|
|
|
if (!eflag)
|
|
|
|
ieee_802_11_hdr_print(fc, p - hdrlen, NULL,
|
|
|
|
NULL);
|
|
|
|
if (extracted_ethertype)
|
|
|
|
printf("(LLC %s) ",
|
|
|
|
etherproto_string(
|
|
|
|
htons(extracted_ethertype)));
|
|
|
|
if (!xflag && !qflag)
|
|
|
|
default_print(p, caplen);
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
default:
|
2003-07-23 01:35:04 +08:00
|
|
|
printf("unknown 802.11 frame type (%d)", FC_TYPE(fc));
|
2001-06-12 13:17:16 +08:00
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
return hdrlen;
|
2002-12-12 15:28:35 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* This is the top level routine of the printer. 'p' points
|
|
|
|
* to the 802.11 header of the packet, 'h->ts' is the timestamp,
|
2004-03-18 07:24:35 +08:00
|
|
|
* 'h->len' is the length of the packet off the wire, and 'h->caplen'
|
2002-12-12 15:28:35 +08:00
|
|
|
* is the number of bytes actually captured.
|
|
|
|
*/
|
2002-12-19 17:39:10 +08:00
|
|
|
u_int
|
|
|
|
ieee802_11_if_print(const struct pcap_pkthdr *h, const u_char *p)
|
2002-12-12 15:28:35 +08:00
|
|
|
{
|
2002-12-19 17:39:10 +08:00
|
|
|
return ieee802_11_print(p, h->len, h->caplen);
|
2002-12-12 15:28:35 +08:00
|
|
|
}
|
|
|
|
|
2004-09-24 05:57:24 +08:00
|
|
|
static int
|
|
|
|
print_radiotap_field(struct cpack_state *s, u_int32_t bit)
|
|
|
|
{
|
|
|
|
union {
|
|
|
|
int8_t i8;
|
|
|
|
u_int8_t u8;
|
|
|
|
int16_t i16;
|
|
|
|
u_int16_t u16;
|
|
|
|
u_int32_t u32;
|
|
|
|
u_int64_t u64;
|
|
|
|
} u, u2;
|
|
|
|
int rc;
|
|
|
|
|
|
|
|
switch (bit) {
|
|
|
|
case IEEE80211_RADIOTAP_FLAGS:
|
|
|
|
case IEEE80211_RADIOTAP_RATE:
|
|
|
|
case IEEE80211_RADIOTAP_DB_ANTSIGNAL:
|
|
|
|
case IEEE80211_RADIOTAP_DB_ANTNOISE:
|
|
|
|
case IEEE80211_RADIOTAP_ANTENNA:
|
|
|
|
rc = cpack_uint8(s, &u.u8);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_DBM_ANTSIGNAL:
|
|
|
|
case IEEE80211_RADIOTAP_DBM_ANTNOISE:
|
|
|
|
rc = cpack_int8(s, &u.i8);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_CHANNEL:
|
|
|
|
rc = cpack_uint16(s, &u.u16);
|
|
|
|
if (rc != 0)
|
|
|
|
break;
|
|
|
|
rc = cpack_uint16(s, &u2.u16);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_FHSS:
|
|
|
|
case IEEE80211_RADIOTAP_LOCK_QUALITY:
|
|
|
|
case IEEE80211_RADIOTAP_TX_ATTENUATION:
|
|
|
|
rc = cpack_uint16(s, &u.u16);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_DB_TX_ATTENUATION:
|
|
|
|
rc = cpack_uint8(s, &u.u8);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_DBM_TX_POWER:
|
|
|
|
rc = cpack_uint8(s, &u.i8);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_TSFT:
|
|
|
|
rc = cpack_uint64(s, &u.u64);
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
/* this bit indicates a field whose
|
|
|
|
* size we do not know, so we cannot
|
|
|
|
* proceed.
|
|
|
|
*/
|
|
|
|
printf("[0x%08x] ", bit);
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (rc != 0) {
|
|
|
|
printf("[|802.11]");
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
switch (bit) {
|
|
|
|
case IEEE80211_RADIOTAP_CHANNEL:
|
|
|
|
printf("%u MHz ", u.u16);
|
|
|
|
if (u2.u16 != 0)
|
|
|
|
printf("(0x%04x) ", u2.u16);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_FHSS:
|
|
|
|
printf("fhset %d fhpat %d ", u.u16 & 0xff, (u.u16 >> 8) & 0xff);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_RATE:
|
|
|
|
PRINT_RATE("", u.u8, " Mb/s ");
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_DBM_ANTSIGNAL:
|
|
|
|
printf("%ddB signal ", u.i8);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_DBM_ANTNOISE:
|
|
|
|
printf("%ddB noise ", u.i8);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_DB_ANTSIGNAL:
|
|
|
|
printf("%ddB signal ", u.u8);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_DB_ANTNOISE:
|
|
|
|
printf("%ddB noise ", u.u8);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_LOCK_QUALITY:
|
|
|
|
printf("%u sq ", u.u16);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_TX_ATTENUATION:
|
|
|
|
printf("%d tx power ", -(int)u.u16);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_DB_TX_ATTENUATION:
|
|
|
|
printf("%ddB tx power ", -(int)u.u8);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_DBM_TX_POWER:
|
|
|
|
printf("%ddBm tx power ", u.i8);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_FLAGS:
|
|
|
|
if (u.u8 & IEEE80211_RADIOTAP_F_CFP)
|
|
|
|
printf("cfp ");
|
|
|
|
if (u.u8 & IEEE80211_RADIOTAP_F_SHORTPRE)
|
|
|
|
printf("short preamble ");
|
|
|
|
if (u.u8 & IEEE80211_RADIOTAP_F_WEP)
|
|
|
|
printf("wep ");
|
|
|
|
if (u.u8 & IEEE80211_RADIOTAP_F_FRAG)
|
|
|
|
printf("fragmented ");
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_ANTENNA:
|
|
|
|
printf("antenna %d ", u.u8);
|
|
|
|
break;
|
|
|
|
case IEEE80211_RADIOTAP_TSFT:
|
|
|
|
printf("%" PRIu64 "us tsft ", u.u64);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2002-12-19 17:39:10 +08:00
|
|
|
static u_int
|
2002-12-17 17:13:45 +08:00
|
|
|
ieee802_11_radio_print(const u_char *p, u_int length, u_int caplen)
|
2004-09-24 05:57:24 +08:00
|
|
|
{
|
|
|
|
#define BITNO_32(x) (((x) >> 16) ? 16 + BITNO_16((x) >> 16) : BITNO_16((x)))
|
|
|
|
#define BITNO_16(x) (((x) >> 8) ? 8 + BITNO_8((x) >> 8) : BITNO_8((x)))
|
|
|
|
#define BITNO_8(x) (((x) >> 4) ? 4 + BITNO_4((x) >> 4) : BITNO_4((x)))
|
|
|
|
#define BITNO_4(x) (((x) >> 2) ? 2 + BITNO_2((x) >> 2) : BITNO_2((x)))
|
|
|
|
#define BITNO_2(x) (((x) & 2) ? 1 : 0)
|
|
|
|
#define BIT(n) (1 << n)
|
|
|
|
#define IS_EXTENDED(__p) \
|
|
|
|
(EXTRACT_LE_32BITS(__p) & BIT(IEEE80211_RADIOTAP_EXT)) != 0
|
|
|
|
|
|
|
|
struct cpack_state cpacker;
|
|
|
|
struct ieee80211_radiotap_header *hdr;
|
|
|
|
u_int32_t present, next_present;
|
|
|
|
u_int32_t *presentp, *last_presentp;
|
|
|
|
enum ieee80211_radiotap_type bit;
|
|
|
|
int bit0;
|
|
|
|
const u_char *iter;
|
|
|
|
u_int len;
|
|
|
|
|
|
|
|
if (caplen < sizeof(*hdr)) {
|
|
|
|
printf("[|802.11]");
|
|
|
|
return caplen;
|
|
|
|
}
|
|
|
|
|
|
|
|
hdr = (struct ieee80211_radiotap_header *)p;
|
|
|
|
|
|
|
|
len = EXTRACT_LE_16BITS(&hdr->it_len);
|
|
|
|
|
|
|
|
if (caplen < len) {
|
|
|
|
printf("[|802.11]");
|
|
|
|
return caplen;
|
|
|
|
}
|
|
|
|
for (last_presentp = &hdr->it_present;
|
|
|
|
IS_EXTENDED(last_presentp) &&
|
|
|
|
(u_char*)(last_presentp + 1) <= p + len;
|
|
|
|
last_presentp++);
|
|
|
|
|
|
|
|
/* are there more bitmap extensions than bytes in header? */
|
|
|
|
if (IS_EXTENDED(last_presentp)) {
|
|
|
|
printf("[|802.11]");
|
|
|
|
return caplen;
|
|
|
|
}
|
|
|
|
|
|
|
|
iter = (u_char*)(last_presentp + 1);
|
|
|
|
|
|
|
|
if (cpack_init(&cpacker, (u_int8_t*)iter, len - (iter - p)) != 0) {
|
|
|
|
/* XXX */
|
|
|
|
printf("[|802.11]");
|
|
|
|
return caplen;
|
|
|
|
}
|
|
|
|
|
|
|
|
for (bit0 = 0, presentp = &hdr->it_present; presentp <= last_presentp;
|
|
|
|
presentp++, bit0 += 32) {
|
|
|
|
for (present = EXTRACT_LE_32BITS(presentp); present;
|
|
|
|
present = next_present) {
|
|
|
|
/* clear the least significant bit that is set */
|
|
|
|
next_present = present & (present - 1);
|
|
|
|
|
|
|
|
/* extract the least significant bit that is set */
|
|
|
|
bit = bit0 + BITNO_32(present ^ next_present);
|
|
|
|
|
|
|
|
if (print_radiotap_field(&cpacker, bit) != 0)
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
out:
|
|
|
|
return len + ieee802_11_print(p + len, length - len, caplen - len);
|
|
|
|
#undef BITNO_32
|
|
|
|
#undef BITNO_16
|
|
|
|
#undef BITNO_8
|
|
|
|
#undef BITNO_4
|
|
|
|
#undef BITNO_2
|
|
|
|
#undef BIT
|
|
|
|
}
|
|
|
|
|
|
|
|
static u_int
|
|
|
|
ieee802_11_avs_radio_print(const u_char *p, u_int length, u_int caplen)
|
2002-12-17 17:13:45 +08:00
|
|
|
{
|
|
|
|
u_int32_t caphdr_len;
|
|
|
|
|
|
|
|
caphdr_len = EXTRACT_32BITS(p + 4);
|
|
|
|
if (caphdr_len < 8) {
|
|
|
|
/*
|
|
|
|
* Yow! The capture header length is claimed not
|
|
|
|
* to be large enough to include even the version
|
|
|
|
* cookie or capture header length!
|
|
|
|
*/
|
|
|
|
printf("[|802.11]");
|
2002-12-19 17:39:10 +08:00
|
|
|
return caplen;
|
2002-12-17 17:13:45 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
if (caplen < caphdr_len) {
|
|
|
|
printf("[|802.11]");
|
2002-12-19 17:39:10 +08:00
|
|
|
return caplen;
|
2002-12-17 17:13:45 +08:00
|
|
|
}
|
|
|
|
|
2002-12-19 17:39:10 +08:00
|
|
|
return caphdr_len + ieee802_11_print(p + caphdr_len,
|
|
|
|
length - caphdr_len, caplen - caphdr_len);
|
2002-12-17 17:13:45 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
#define PRISM_HDR_LEN 144
|
|
|
|
|
|
|
|
#define WLANCAP_MAGIC_COOKIE_V1 0x80211001
|
2002-12-12 15:28:35 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* For DLT_PRISM_HEADER; like DLT_IEEE802_11, but with an extra header,
|
|
|
|
* containing information such as radio information, which we
|
|
|
|
* currently ignore.
|
2002-12-17 17:13:45 +08:00
|
|
|
*
|
|
|
|
* If, however, the packet begins with WLANCAP_MAGIC_COOKIE_V1, it's
|
|
|
|
* really DLT_IEEE802_11_RADIO (currently, on Linux, there's no
|
|
|
|
* ARPHRD_ type for DLT_IEEE802_11_RADIO, as there is a
|
|
|
|
* ARPHRD_IEEE80211_PRISM for DLT_PRISM_HEADER, so
|
|
|
|
* ARPHRD_IEEE80211_PRISM is used for DLT_IEEE802_11_RADIO, and
|
|
|
|
* the first 4 bytes of the header are used to indicate which it is).
|
2002-12-12 15:28:35 +08:00
|
|
|
*/
|
2002-12-19 17:39:10 +08:00
|
|
|
u_int
|
|
|
|
prism_if_print(const struct pcap_pkthdr *h, const u_char *p)
|
2002-12-12 15:28:35 +08:00
|
|
|
{
|
|
|
|
u_int caplen = h->caplen;
|
|
|
|
u_int length = h->len;
|
|
|
|
|
2002-12-17 17:13:45 +08:00
|
|
|
if (caplen < 4) {
|
2002-12-12 15:28:35 +08:00
|
|
|
printf("[|802.11]");
|
2002-12-19 17:39:10 +08:00
|
|
|
return caplen;
|
2002-12-12 15:28:35 +08:00
|
|
|
}
|
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (EXTRACT_32BITS(p) == WLANCAP_MAGIC_COOKIE_V1)
|
2004-09-24 05:57:24 +08:00
|
|
|
return ieee802_11_avs_radio_print(p, length, caplen);
|
2002-12-17 17:13:45 +08:00
|
|
|
|
2003-07-23 01:35:04 +08:00
|
|
|
if (caplen < PRISM_HDR_LEN) {
|
|
|
|
printf("[|802.11]");
|
|
|
|
return caplen;
|
2002-12-17 17:13:45 +08:00
|
|
|
}
|
2003-07-23 01:35:04 +08:00
|
|
|
|
|
|
|
return PRISM_HDR_LEN + ieee802_11_print(p + PRISM_HDR_LEN,
|
|
|
|
length - PRISM_HDR_LEN, caplen - PRISM_HDR_LEN);
|
2002-12-12 15:28:35 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* For DLT_IEEE802_11_RADIO; like DLT_IEEE802_11, but with an extra
|
|
|
|
* header, containing information such as radio information, which we
|
|
|
|
* currently ignore.
|
|
|
|
*/
|
2002-12-19 17:39:10 +08:00
|
|
|
u_int
|
|
|
|
ieee802_11_radio_if_print(const struct pcap_pkthdr *h, const u_char *p)
|
2002-12-12 15:28:35 +08:00
|
|
|
{
|
|
|
|
u_int caplen = h->caplen;
|
|
|
|
u_int length = h->len;
|
|
|
|
|
2002-12-12 15:39:19 +08:00
|
|
|
if (caplen < 8) {
|
|
|
|
printf("[|802.11]");
|
2002-12-19 17:39:10 +08:00
|
|
|
return caplen;
|
2002-12-12 15:39:19 +08:00
|
|
|
}
|
|
|
|
|
2002-12-19 17:39:10 +08:00
|
|
|
return ieee802_11_radio_print(p, length, caplen);
|
2001-06-12 13:17:16 +08:00
|
|
|
}
|