3. Cell Packet format

   The basic unit of communication for onion routers and onion
   proxies is a fixed-width "cell".

   On a version 1 connection, each cell contains the following:

        CircID                                [CIRCID_LEN bytes]
        Command                               [1 byte]
        Payload (padded with 0 bytes)         [PAYLOAD_LEN bytes]

   On a version 2 or higher connection, all cells are as in version 1
   connections, except for variable-length cells, whose format is:

        CircID                                [CIRCID_LEN octets]
        Command                               [1 octet]
        Length                                [2 octets; big-endian integer]
        Payload                               [Length bytes]

   On a version 2 connection, variable-length cells are indicated by a
   command byte equal to 7 ("VERSIONS").  On a version 3 or
   higher connection, variable-length cells are indicated by a command
   byte equal to 7 ("VERSIONS"), or greater than or equal to 128.

   CIRCID_LEN is 2 for link protocol versions 1, 2, and 3.  CIRCID_LEN
   is 4 for link protocol version 4 or higher.  The VERSIONS cell itself
   always has CIRCID_LEN == 2 for backward compatibility.

   The CircID field determines which circuit, if any, the cell is
   associated with.

   The 'Command' field of a fixed-length cell holds one of the following
         0 -- PADDING     (Padding)                 (See Sec 7.2)
         1 -- CREATE      (Create a circuit)        (See Sec 5.1)
         2 -- CREATED     (Acknowledge create)      (See Sec 5.1)
         3 -- RELAY       (End-to-end data)         (See Sec 5.5 and 6)
         4 -- DESTROY     (Stop using a circuit)    (See Sec 5.4)
         5 -- CREATE_FAST (Create a circuit, no PK) (See Sec 5.1)
         6 -- CREATED_FAST (Circuit created, no PK) (See Sec 5.1)
         8 -- NETINFO     (Time and address info)   (See Sec 4.5)
         9 -- RELAY_EARLY (End-to-end data; limited)(See Sec 5.6)
         10 -- CREATE2    (Extended CREATE cell)    (See Sec 5.1)
         11 -- CREATED2   (Extended CREATED cell)    (See Sec 5.1)

    Variable-length command values are:
         7 -- VERSIONS    (Negotiate proto version) (See Sec 4)
         128 -- VPADDING  (Variable-length padding) (See Sec 7.2)
         129 -- CERTS     (Certificates)            (See Sec 4.2)
         130 -- AUTH_CHALLENGE (Challenge value)    (See Sec 4.3)
         131 -- AUTHENTICATE (Client authentication)(See Sec 4.5)
         132 -- AUTHORIZE (Client authorization)    (Not yet used)

   The interpretation of 'Payload' depends on the type of the cell.
      PADDING: Payload is unused.
      CREATE:  Payload contains the handshake challenge.
      CREATED: Payload contains the handshake response.
      RELAY:   Payload contains the relay header and relay body.
      DESTROY: Payload contains a reason for closing the circuit.
               (see 5.4)
   Upon receiving any other value for the command field, an OR must
   drop the cell.  Since more cell types may be added in the future, ORs
   should generally not warn when encountering unrecognized commands.

   The payload is padded with 0 bytes.

   PADDING cells are currently used to implement connection keepalive.
   If there is no other traffic, ORs and OPs send one another a PADDING
   cell every few minutes.

   CREATE, CREATED, and DESTROY cells are used to manage circuits;
   see section 5 below.

   RELAY cells are used to send commands and data along a circuit; see
   section 6 below.

   VERSIONS and NETINFO cells are used to set up connections in link
   protocols v2 and higher; in link protocol v3 and higher, CERTS,
   AUTH_CHALLENGE, and AUTHENTICATE may also be used.  See section 4



import ssl
import socket
import struct
import binascii

s = socket.socket()
ssl_sock = ssl.wrap_socket(s)
ssl_sock.connect(("", 443))

pkt = struct.pack(">HBHH", 0, 7, 2, 3)

recv_pkt = ssl_sock.recv(1500)
print ":".join("{:02x}".format(ord(c)) for c in recv_pkt)






import ssl
import socket
import struct
import binascii

s = socket.socket()
ssl_sock = ssl.wrap_socket(s)
ssl_sock.connect((" ", 443))

pkt = struct.pack(">HBHH", 0, 7, 2, 3)

peerAddr= [int(x) for x in ssl_sock.getpeername()[0].split(".")]

#recv_pkt = sock.recv(payload_len)
#print recv_pkt

#All recieved data printed
recv_pkt = ssl_sock.recv(1500)
#print recv_pkt
print ":".join("{:02x}".format(ord(c)) for c in recv_pkt)
print "Data recieved is above"
#while len(recv_pkt)<= 512
# payload = struct.unpack(">H")

# 512 - COMMAND_LEN - PAYLOAD_LEN = 512 - 1 - 509 = 2

# default to v1

#currently locking up at this section
circ_id, command = ssl_sock.recv(CIRCID_LEN), ssl_sock.recv(1)
print circ_id
print command

# according to spec, command is 7 if not using v1
# -> if not v1
if command != 7:
    # Negotiate proto version and set PAYLOAD_LEN accordingly

# finally, get the entire payload, and just that
payload = ssl_sock.recv(PAYLOAD_LEN)

print payload

#cnetinf = recv_pkt(ssl_sock, 'CellNetInfo')

# Not sure if this is correct, I got it by:
# 512 - COMMAND_LEN - PAYLOAD_LEN = 512 - 1 - 509 = 2

# default to v1

circ_id, command = ssl_sock.recv(CIRCID_LEN), ssl_sock.recv(1)

# according to spec, command is 7 if not using v1
# -> if not v1
if command != 7:
    # Here you need to "Negotiate proto version"
    # Then, set PAYLOAD_LEN accordingly:

# finally, get the entire payload, and just that
payload = ssl_sock.recv(PAYLOAD_LEN)


00:00 07 00:04 00:03:00:04

这意味着&#34;没有电路&#34;,cmd 7(VERSIONS),4个字节的有效载荷,表示服务器支持版本3和4.由于您的代码请求版本3,协议版本将为3(即CIRCID_LEN = 2用于以下单元格)。下一个单元格是

00:00 81 03:88 ...

这意味着仍然没有电路,命令0x81 = 129(CERTS),有效载荷长度0x388 = 904。以下904字节应为有效负载,由证书数据组成。在此之后,一个新的单元格开始。


import ssl
import socket
import struct

s = socket.socket()
ssl_sock = ssl.wrap_socket(s)
ssl_sock.connect(("", 9001))

versions_in = set([1,2,3,4])

pkt = struct.pack(">HBH", 0, 7, 2*len(versions_in))
for v in versions_in:
    pkt += struct.pack(">H", v)

recv_pkt = ssl_sock.recv(1500)

class Parser(object):

    def __init__(self):
        self.version = -1
        self.idx = 1

    def parse(self, data):
        print "packet", self.idx
        self.idx += 1

        CIRCID_LEN = 2
        if self.version >= 4:
            CIRCID_LEN = 4
        print "CIRCID_LEN =", CIRCID_LEN

        circ_id, data = data[:CIRCID_LEN], data[CIRCID_LEN:]
        print "circ_id =", ":".join("{:02x}".format(ord(c)) for c in circ_id)

        cmd = ord(data[0])
        data = data[1:]
        print "cmd = {:d}".format(cmd)

        PAYLOAD_LEN = 509
        if cmd == 7 or cmd >= 128:
            PAYLOAD_LEN = struct.unpack_from(">H", data)[0]
            data = data[2:]
        print "PAYLOAD_LEN =", PAYLOAD_LEN

        payload, data = data[:PAYLOAD_LEN], data[PAYLOAD_LEN:]
        print "payload =", ":".join("{:02x}".format(ord(c)) for c in payload)

        if cmd == 7:
            versions = set()
            while payload:
                versions.add(struct.unpack_from(">H", payload)[0])
                payload = payload[2:]
            self.version = max(versions_in&versions)
            print "our versions:", versions_in
            print "server supported versions:", versions
            print "thus we use protocol version", self.version

        return data

p = Parser()
while recv_pkt:
    recv_pkt = p.parse(recv_pkt)
