1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237
| #include <stdio.h> #include <stdint.h> #include <stdlib.h> #include <string.h> #include <dirent.h>
unsigned short checksum(void *addr, int count) { register long sum = 0;
while (count > 1) { sum += *(unsigned short *)addr; addr += 2; count -= 2; }
if (count > 0) sum += *(unsigned char *)addr;
while (sum >> 16) sum = (sum & 0xFFFF) + (sum >> 16);
return ~sum; }
void printHex(const unsigned char *packet, unsigned int offset, unsigned int size) { int i = 0;int count = 0; for (; i < size; i++) { printf("%02x ", packet[offset + i]); if (i >= 0x50) { printf("...\n"); break; } if ((i + 1) % 16 == 0) printf("\n"); } if (i % 16 != 0) printf("\n"); }
void construct_pseudo_header(unsigned char *pseudo_header, const unsigned char *packet, unsigned short protocol, unsigned short length) { memcpy(pseudo_header, &packet[26], 4); memcpy(&pseudo_header[4], &packet[30], 4); pseudo_header[8] = 0; pseudo_header[9] = protocol; pseudo_header[10] = length >> 8; pseudo_header[11] = length & 0xFF; }
void process_icmp(const unsigned char *packet, unsigned int offset, unsigned int size, unsigned int IPlength) { printf("=========================================================================\n"); printf("识别到使用的协议为 ICMP,开始解析......\n");
unsigned short ICMPlength = size - offset; printf("ICMP 长度为 %d,其内容为:\n", ICMPlength); printHex(packet, offset, ICMPlength);
unsigned short icmp_checksum = (packet[offset + 2] << 8) | packet[offset + 3]; printf("报文中 checksum 字段为: 0x%02x 0x%02x\n", icmp_checksum >> 8, icmp_checksum & 0xFF);
unsigned char *icmp_data = (unsigned char *)malloc(ICMPlength); memcpy(icmp_data, &packet[offset], ICMPlength);
printf("清空 checksum 字段后,报文变为:\n"); icmp_data[2] = 0x00; icmp_data[3] = 0x00; printHex(icmp_data, 0, ICMPlength);
unsigned short calculated_checksum = checksum(icmp_data, ICMPlength); printf("本地计算 checksum 为: 0x%02x 0x%02x\n", calculated_checksum & 0xFF, calculated_checksum >> 8);
free(icmp_data); }
void process_tcp(const unsigned char *packet, unsigned int offset, unsigned int size, unsigned int IPlength) { printf("=========================================================================\n"); printf("识别到使用的协议为 TCP,开始解析......\n");
unsigned short TCPlength = size - offset; printf("TCP 长度为 %d,其内容为:\n", TCPlength); printHex(packet, offset, TCPlength);
unsigned short tcp_checksum = (packet[offset + 16] << 8) | packet[offset + 17]; printf("报文中 checksum 字段为: 0x%02x 0x%02x\n", tcp_checksum >> 8, tcp_checksum & 0xFF);
unsigned char pseudo_header[12]; construct_pseudo_header(pseudo_header, packet, 0x06, TCPlength);
unsigned char *checksum_data = (unsigned char *)malloc(12 + TCPlength); memcpy(checksum_data, pseudo_header, 12); memcpy(&checksum_data[12], &packet[offset], TCPlength);
printf("清空 checksum 字段后,报文变为:\n"); checksum_data[28] = 0x00; checksum_data[29] = 0x00; printHex(packet, offset, TCPlength);
unsigned short calculated_checksum = checksum(checksum_data, 12 + TCPlength); printf("本地计算 checksum 为: 0x%02x 0x%02x\n", calculated_checksum & 0xFF, calculated_checksum >> 8);
free(checksum_data); }
void process_udp(const unsigned char *packet, unsigned int offset, unsigned int size, unsigned int IPlength) { printf("=========================================================================\n"); printf("识别到使用的协议为 UDP,开始解析......\n");
unsigned short UDPlength = size - offset; printf("UDP 长度为 %d,其内容为:\n", UDPlength); printHex(packet, offset, UDPlength);
unsigned short udp_checksum = (packet[offset + 6] << 8) | packet[offset + 7]; printf("报文中 checksum 字段为: 0x%02x 0x%02x\n", udp_checksum >> 8, udp_checksum & 0xFF);
unsigned char pseudo_header[12]; construct_pseudo_header(pseudo_header, packet, 0x11, UDPlength);
unsigned char *checksum_data = (unsigned char *)malloc(12 + UDPlength); memcpy(checksum_data, pseudo_header, 12); memcpy(&checksum_data[12], &packet[offset], UDPlength);
printf("清空 checksum 字段后,报文变为:\n"); checksum_data[18] = 0x00; checksum_data[19] = 0x00; printHex(packet, offset, UDPlength);
unsigned short calculated_checksum = checksum(checksum_data, 12 + UDPlength); printf("本地计算 checksum 为: 0x%02x 0x%02x\n", calculated_checksum & 0xFF, calculated_checksum >> 8);
free(checksum_data); }
void process_packet(unsigned char *packet, int size) { if (size < 20) { printf("Invalid packet size: %d bytes\n", size); return; }
unsigned short IPVersion = (packet[12] << 8) | packet[13]; switch (IPVersion) { case 0x0800: { printf("=========================================================================\n"); printf("识别到使用的协议为 IPV4,开始解析......\n"); unsigned short IPlength = (packet[14] & 0x0F) << 2; printf("IP 头长度为 %d,其内容为:\n", IPlength); printHex(packet, 14, IPlength);
unsigned short packet_checksum = (packet[24] << 8) | packet[25]; printf("在该段报文中,checksum字段为:0x%02x 0x%02x\n",packet_checksum >> 8,packet_checksum & 0x00ff); printf("清空源报文中checksum字段,开始本地校验......\n"); packet[24] = 0x00; packet[25] = 0x00; printf("清空checksum字段后报文变为:\n"); printHex(packet,14,IPlength); unsigned short my_checksum = checksum((void *)packet+14, IPlength); printf("本地checksum计算为:0x%02x 0x%02x\n",my_checksum & 0x00ff,my_checksum >> 8);
unsigned short protocol = packet[23]; unsigned int offset = 14 + IPlength;
if (protocol == 0x01) { process_icmp(packet, offset, size, IPlength); } else if (protocol == 0x06) { process_tcp(packet, offset, size, IPlength); } else if (protocol == 0x11) { process_udp(packet, offset, size, IPlength); } break; } default: printf("未知的协议类型: 0x%02x\n", IPVersion); break; } }
void read_and_process_file(const char *filename) { FILE *file = fopen(filename, "rb"); if (!file) { perror("Error opening file"); return; }
unsigned char buffer[2048]; int read_size;
while ((read_size = fread(buffer, 1, sizeof(buffer), file)) > 0) { printf("\n读取到大小为 %d 字节的报文文件: %s\n", read_size, filename); process_packet(buffer, read_size); }
fclose(file); }
void process_bin_files_in_directory(const char *directory) { struct dirent *entry; DIR *dir = opendir(directory);
if (!dir) { perror("Error opening directory"); return; }
while ((entry = readdir(dir)) != NULL) { if (strstr(entry->d_name, ".bin")) { char filepath[1024]; snprintf(filepath, sizeof(filepath), "%s/%s", directory, entry->d_name);
printf("\n处理文件: %s", filepath); read_and_process_file(filepath); } }
closedir(dir); }
int main() { printf("从当前目录读取 .bin 文件...\n"); process_bin_files_in_directory(".");
return 0; }
|