我想检测传入的互联网数据包的ip选项。这是我的代码。
//#define IPPROTO_IP 0
//#define IP_OPTIONS 68
#define SENDER_PORT_NUM 53
#define SENDER_IP_ADDR "127.0.0.1"
#define true 1
static void bail(const char *error)
{
printf("%s: %s\n", error, strerror(errno));
exit(1);
}
struct ip_datagram{
unsigned char ver_ihl;
unsigned char tos;
unsigned short totlen;
unsigned short id;
unsigned short flags_offs;
unsigned char ttl;
unsigned char proto;
unsigned short checksum;
unsigned long src;
unsigned long dst;
unsigned char payload[1500];
};
int main(){
int s,b,sso,gso, i;
int contatore = 5;
int enabled = 1;
char *data, *buffer;
int addrlen;
struct sockaddr_in addr;
struct ip_datagram *ip, *ip_reply;
struct icmphdr* icmp;
//char *src_addr="93.34.229.111";
char *dst_addr="127.0.0.1";
data = malloc(sizeof(struct ip_datagram)+ sizeof(struct icmphdr));
buffer = malloc(sizeof(struct ip_datagram)+ sizeof(struct icmphdr));
ip = (struct ip_datagram *) (data );
icmp = (struct icmphdr*) (data + sizeof(struct ip_datagram));
ip->ver_ihl = 45;
//ip->ihl = 15;
ip->totlen = sizeof(struct ip_datagram);
ip->proto = IPPROTO_ICMP;
//ip->src =(inet_addr(src_addr));
ip->dst = inet_addr(dst_addr);
ip->checksum = in_cksum((unsigned short *)ip, sizeof(struct ip_datagram));
icmp->type = ICMP_ECHO;
icmp->checksum = in_cksum((unsigned short *)icmp, sizeof(struct icmphdr));
s = socket(AF_INET, SOCK_RAW, IPPROTO_ICMP);
if(s<0)
printf("errore socket\n");
sso = setsockopt(s, IPPROTO_IP, IP_OPTIONS, &enabled, sizeof(enabled));
if(sso<0)
bail("errore setsockoptions\n");
gso = (s, IPPROTO_IP, IP_OPTIONS, &enabled, sizeof(enabled));
if(gso<0)
bail("errore getsockoptions\n");
else
printf("IP_OPTIONS VALUE :%d\n", enabled);
addr.sin_family = AF_INET;
addr.sin_addr.s_addr = ip->dst;
while(contatore>0){
int sent_bytes = sendto(s, (const char *)data, ip->totlen, 0, (struct sockaddr*)&addr, sizeof(struct sockaddr) );
if(sent_bytes <0){
printf("failed to send packets\n");
return 3;
}
//printf("Sent %d byte packet from %s to %s\n", ip->totlen, src_addr, dst_addr);
printf("Sent %d byte packet to %s\n", ip->totlen, dst_addr);
addrlen = sizeof(addr);
int bytes = recvfrom(s, buffer, sizeof(struct ip_datagram) + sizeof(struct icmphdr), 0, (struct sockaddr*)&addr, &addrlen);
if(bytes<=0){
printf("errore recvfrom\n");
break;
}
else{
char *cp;
ip_reply = (struct ip_datagram*) buffer;
cp = (char *)&ip_reply->src;
printf("Received %d byte reply from %u.%u.%u.%u:\n", ntohs(ip_reply->totlen), cp[0]&0xff,cp[1]&0xff,cp[2]&0xff,cp[3]&0xff);
printf("ID: %d\n", ntohs(ip_reply->id));
printf("TTL: %d\n", ip_reply->ttl);
printf("type of service: %.1X\n", ip_reply->tos);
printf("IP ADDRESS SOURCE: %.4X\n", htonl(ip_reply->src));
printf("IP ADDRESS DESTINATION: %.4X\n", htonl(ip_reply->dst));
printf("versione + header length: %.1X\n", ip_reply->ver_ihl);
contatore--;
printf("-----------------\n");
printf("****************\n");
}
}
}
问题是标头长度为6但是检测所有ip选项的长度应为20。在setsockopt中,也许,启用变量的类型应该是char,但是当我运行程序时我遇到了一些问题:事实上,对于char类型,它给出了无效参数的错误。我想知道如何使用getsockoption打印这些选项。有什么问题?我希望我的问题很清楚:)
答案 0 :(得分:1)
您为IP标头定义的结构可能与IP数据包标头大致兼容,但它不够好并且不易使用。
在我的Linux系统上,系统头文件在/usr/include/linux/ip.h中定义IP头,如下所示:
struct iphdr {
#if defined(__LITTLE_ENDIAN_BITFIELD)
__u8 ihl:4,
version:4;
#elif defined (__BIG_ENDIAN_BITFIELD)
__u8 version:4,
ihl:4;
#else
#error "Please fix <asm/byteorder.h>"
#endif
__u8 tos;
__be16 tot_len;
__be16 id;
__be16 frag_off;
__u8 ttl;
__u8 protocol;
__sum16 check;
__be32 saddr;
__be32 daddr;
/*The options start here. */
};
正如您所看到的,这会正确地破坏IP版本和标头长度,并且为大端或小端目标编译更安全。
使用这样的结构定义,您可以在sizeof(struct iphdr)
字节后找到IP选项的开头,并且整个IP标头的大小将是ip.ihl * 4
,其中ip是{{1} }。
您需要乘以4,因为struct iphdr
是构成IP标头的32位字的数量,而不是标头本身的字节数。
您可以查看IPv4 (Wikipedia),其中包含有关IP标头选项及其格式的一般信息,以及IANAs list of IP Options的完整列表,其中包含指向描述每个选项详细信息的各种RFC的链接。