2019-11-11 17:09:59 +00:00
|
|
|
/* sniffer.h
|
|
|
|
*
|
2023-01-01 17:00:36 +00:00
|
|
|
* Copyright (C) 2006-2022 wolfSSL Inc.
|
2019-11-11 17:09:59 +00:00
|
|
|
*
|
|
|
|
* This file is part of wolfSSL.
|
|
|
|
*
|
|
|
|
* wolfSSL is free software; you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU General Public License as published by
|
|
|
|
* the Free Software Foundation; either version 2 of the License, or
|
|
|
|
* (at your option) any later version.
|
|
|
|
*
|
|
|
|
* wolfSSL is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
* along with this program; if not, write to the Free Software
|
|
|
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA
|
|
|
|
*/
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#ifndef WOLFSSL_SNIFFER_H
|
|
|
|
#define WOLFSSL_SNIFFER_H
|
|
|
|
|
|
|
|
#include <libs/libwolfssl/wolfcrypt/settings.h>
|
2021-08-01 18:00:22 +01:00
|
|
|
#include <libs/libwolfssl/wolfcrypt/asn_public.h>
|
2019-11-11 17:09:59 +00:00
|
|
|
|
2023-01-01 17:00:36 +00:00
|
|
|
#ifdef HAVE_WOLF_EVENT
|
|
|
|
#include <libs/libwolfssl/wolfcrypt/wolfevent.h>
|
|
|
|
#endif
|
|
|
|
|
|
|
|
|
2019-11-11 17:09:59 +00:00
|
|
|
#ifdef _WIN32
|
|
|
|
#ifdef SSL_SNIFFER_EXPORTS
|
|
|
|
#define SSL_SNIFFER_API __declspec(dllexport)
|
|
|
|
#else
|
|
|
|
#define SSL_SNIFFER_API __declspec(dllimport)
|
|
|
|
#endif
|
|
|
|
#else
|
|
|
|
#define SSL_SNIFFER_API
|
|
|
|
#endif /* _WIN32 */
|
|
|
|
|
|
|
|
|
|
|
|
#ifdef __cplusplus
|
|
|
|
extern "C" {
|
|
|
|
#endif
|
|
|
|
|
2023-01-01 17:00:36 +00:00
|
|
|
|
|
|
|
typedef struct IpAddrInfo {
|
|
|
|
int version;
|
|
|
|
union {
|
|
|
|
word32 ip4;
|
|
|
|
byte ip6[16];
|
|
|
|
};
|
|
|
|
} IpAddrInfo;
|
|
|
|
|
|
|
|
typedef struct SnifferStreamInfo {
|
|
|
|
IpAddrInfo src; /* server address in network byte order */
|
|
|
|
IpAddrInfo dst; /* client address in network byte order */
|
|
|
|
word16 dstPort; /* server port */
|
|
|
|
word16 srcPort; /* client port */
|
|
|
|
} SnifferStreamInfo;
|
|
|
|
|
2019-11-11 17:09:59 +00:00
|
|
|
/* @param typeK: (formerly keyType) was shadowing a global declaration in
|
|
|
|
* wolfssl/wolfcrypt/asn.h line 175
|
|
|
|
*/
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetPrivateKey(const char* address, int port,
|
|
|
|
const char* keyFile, int typeK,
|
|
|
|
const char* password, char* error);
|
|
|
|
|
2020-11-08 21:29:44 +00:00
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetPrivateKeyBuffer(const char* address, int port,
|
2023-01-01 17:00:36 +00:00
|
|
|
const char* keyBuf, int keySz,
|
|
|
|
int typeK, const char* password,
|
2020-11-08 21:29:44 +00:00
|
|
|
char* error);
|
|
|
|
|
|
|
|
|
2019-11-11 17:09:59 +00:00
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetNamedPrivateKey(const char* name,
|
|
|
|
const char* address, int port,
|
|
|
|
const char* keyFile, int typeK,
|
|
|
|
const char* password, char* error);
|
2020-11-08 21:29:44 +00:00
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetNamedPrivateKeyBuffer(const char* name,
|
|
|
|
const char* address, int port,
|
2023-01-01 17:00:36 +00:00
|
|
|
const char* keyBuf, int keySz,
|
|
|
|
int typeK, const char* password,
|
2020-11-08 21:29:44 +00:00
|
|
|
char* error);
|
|
|
|
|
2023-01-01 17:00:36 +00:00
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetEphemeralKey(const char* address, int port,
|
|
|
|
const char* keyFile, int typeKey,
|
2020-11-08 21:29:44 +00:00
|
|
|
const char* password, char* error);
|
|
|
|
|
2023-01-01 17:00:36 +00:00
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetEphemeralKeyBuffer(const char* address, int port,
|
|
|
|
const char* keyBuf, int keySz, int typeKey,
|
2020-11-08 21:29:44 +00:00
|
|
|
const char* password, char* error);
|
|
|
|
|
|
|
|
|
2023-01-01 17:00:36 +00:00
|
|
|
WOLFSSL_API
|
2020-11-08 21:29:44 +00:00
|
|
|
SSL_SNIFFER_API int ssl_SetNamedEphemeralKey(const char* name,
|
|
|
|
const char* address, int port,
|
|
|
|
const char* keyFile, int typeKey,
|
|
|
|
const char* password, char* error);
|
|
|
|
|
2023-01-01 17:00:36 +00:00
|
|
|
WOLFSSL_API
|
2020-11-08 21:29:44 +00:00
|
|
|
SSL_SNIFFER_API int ssl_SetNamedEphemeralKeyBuffer(const char* name,
|
|
|
|
const char* address, int port,
|
2023-01-01 17:00:36 +00:00
|
|
|
const char* keyBuf, int keySz, int typeKey,
|
2020-11-08 21:29:44 +00:00
|
|
|
const char* password, char* error);
|
2019-11-11 17:09:59 +00:00
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_DecodePacket(const unsigned char* packet, int length,
|
|
|
|
unsigned char** data, char* error);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_FreeDecodeBuffer(unsigned char** data, char* error);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_FreeZeroDecodeBuffer(unsigned char** data, int sz,
|
|
|
|
char* error);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_Trace(const char* traceFile, char* error);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_EnableRecovery(int onOff, int maxMemory, char* error);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_GetSessionStats(unsigned int* active,
|
|
|
|
unsigned int* total,
|
|
|
|
unsigned int* peak,
|
|
|
|
unsigned int* maxSessions,
|
|
|
|
unsigned int* missedData,
|
|
|
|
unsigned int* reassemblyMemory,
|
|
|
|
char* error);
|
|
|
|
|
2023-01-01 17:00:36 +00:00
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API void ssl_InitSniffer(void);
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API void ssl_InitSniffer_ex(int devId);
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API void ssl_InitSniffer_ex2(int threadNum);
|
2019-11-11 17:09:59 +00:00
|
|
|
|
2023-01-01 17:00:36 +00:00
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API void ssl_FreeSniffer(void);
|
2019-11-11 17:09:59 +00:00
|
|
|
|
|
|
|
|
|
|
|
/* ssl_SetPrivateKey typeKs */
|
|
|
|
enum {
|
|
|
|
FILETYPE_PEM = 1,
|
|
|
|
FILETYPE_DER = 2,
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
* New Sniffer API that provides read-only access to the TLS and cipher
|
|
|
|
* information associated with the SSL session.
|
|
|
|
*/
|
|
|
|
|
|
|
|
typedef struct SSLInfo
|
|
|
|
{
|
|
|
|
unsigned char isValid;
|
|
|
|
/* indicates if the info in this struct is valid: 0 = no, 1 = yes */
|
|
|
|
unsigned char protocolVersionMajor; /* SSL Version: major */
|
|
|
|
unsigned char protocolVersionMinor; /* SSL Version: minor */
|
|
|
|
unsigned char serverCipherSuite0; /* first byte, normally 0 */
|
|
|
|
unsigned char serverCipherSuite; /* second byte, actual suite */
|
|
|
|
unsigned char serverCipherSuiteName[256];
|
|
|
|
/* cipher name, e.g., "TLS_RSA_..." */
|
|
|
|
unsigned char serverNameIndication[128];
|
|
|
|
unsigned int keySize;
|
2020-07-06 17:05:04 +01:00
|
|
|
} SSLInfo;
|
2019-11-11 17:09:59 +00:00
|
|
|
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_DecodePacketWithSessionInfo(
|
|
|
|
const unsigned char* packet, int length,
|
|
|
|
unsigned char** data, SSLInfo* sslInfo, char* error);
|
|
|
|
|
|
|
|
typedef void (*SSLConnCb)(const void* session, SSLInfo* info, void* ctx);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetConnectionCb(SSLConnCb cb);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetConnectionCtx(void* ctx);
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct SSLStats
|
|
|
|
{
|
2023-01-01 17:00:36 +00:00
|
|
|
unsigned long int sslStandardConns; /* server_hello count not including resumed sessions */
|
|
|
|
unsigned long int sslClientAuthConns; /* client's who have presented certificates (mutual authentication) */
|
|
|
|
unsigned long int sslResumedConns; /* resumed connections */
|
|
|
|
unsigned long int sslEphemeralMisses; /* TLS v1.2 and older PFS / ephemeral connections missed (not able to decrypt) */
|
|
|
|
unsigned long int sslResumeMisses; /* Resumption sessions not found */
|
|
|
|
unsigned long int sslCiphersUnsupported; /* No cipher suite match found when compared to supported */
|
|
|
|
unsigned long int sslKeysUnmatched; /* Key callback failures (not found). Applies to WOLFSSL_SNIFFER_WATCH only */
|
|
|
|
unsigned long int sslKeyFails; /* Failures loading or using keys */
|
|
|
|
unsigned long int sslDecodeFails; /* Dropped packets (not application_data or match protocol version) */
|
|
|
|
unsigned long int sslAlerts; /* Number of decoded alert messages */
|
|
|
|
unsigned long int sslDecryptedBytes; /* Number of decrypted bytes */
|
|
|
|
unsigned long int sslEncryptedBytes; /* Number of encrypted bytes */
|
|
|
|
unsigned long int sslEncryptedPackets; /* Number of encrypted packets */
|
|
|
|
unsigned long int sslDecryptedPackets; /* Number of decrypted packets */
|
|
|
|
unsigned long int sslKeyMatches; /* Key callback successes (failures tracked in sslKeysUnmatched). Applies to WOLFSSL_SNIFFER_WATCH only. */
|
|
|
|
unsigned long int sslEncryptedConns; /* Number of created sniffer sessions */
|
|
|
|
unsigned long int sslResumptionInserts; /* Number of sessions reused with resumption */
|
2019-11-11 17:09:59 +00:00
|
|
|
} SSLStats;
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_ResetStatistics(void);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_ReadStatistics(SSLStats* stats);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_ReadResetStatistics(SSLStats* stats);
|
|
|
|
|
2021-08-01 18:00:22 +01:00
|
|
|
|
|
|
|
#if defined(WOLFSSL_STATIC_EPHEMERAL) && defined(WOLFSSL_TLS13)
|
|
|
|
/* macro indicating support for key callback */
|
|
|
|
#undef WOLFSSL_SNIFFER_KEY_CALLBACK
|
|
|
|
#define WOLFSSL_SNIFFER_KEY_CALLBACK
|
2023-01-01 17:00:36 +00:00
|
|
|
|
|
|
|
typedef int (*SSLKeyCb)(void* vSniffer, int namedGroup,
|
|
|
|
const unsigned char* srvPub, unsigned int srvPubSz,
|
|
|
|
const unsigned char* cliPub, unsigned int cliPubSz,
|
|
|
|
DerBuffer* privKey, void* cbCtx, char* error);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
2021-08-01 18:00:22 +01:00
|
|
|
SSL_SNIFFER_API int ssl_SetKeyCallback(SSLKeyCb cb, void* cbCtx);
|
|
|
|
#endif
|
2019-11-11 17:09:59 +00:00
|
|
|
|
2021-08-01 18:00:22 +01:00
|
|
|
|
|
|
|
#ifdef WOLFSSL_SNIFFER_WATCH
|
2019-11-11 17:09:59 +00:00
|
|
|
typedef int (*SSLWatchCb)(void* vSniffer,
|
|
|
|
const unsigned char* certHash,
|
|
|
|
unsigned int certHashSz,
|
|
|
|
const unsigned char* certChain,
|
|
|
|
unsigned int certChainSz,
|
|
|
|
void* ctx, char* error);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetWatchKeyCallback(SSLWatchCb cb, char* error);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetWatchKeyCallback_ex(SSLWatchCb cb, int devId,
|
|
|
|
char* error);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetWatchKeyCtx(void* ctx, char* error);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetWatchKey_buffer(void* vSniffer,
|
|
|
|
const unsigned char* key, unsigned int keySz,
|
|
|
|
int keyType, char* error);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetWatchKey_file(void* vSniffer,
|
|
|
|
const char* keyFile, int keyType,
|
|
|
|
const char* password, char* error);
|
2021-08-01 18:00:22 +01:00
|
|
|
#endif
|
2019-11-11 17:09:59 +00:00
|
|
|
|
2021-08-01 18:00:22 +01:00
|
|
|
#ifdef WOLFSSL_SNIFFER_STORE_DATA_CB
|
2019-11-11 17:09:59 +00:00
|
|
|
typedef int (*SSLStoreDataCb)(const unsigned char* decryptBuf,
|
|
|
|
unsigned int decryptBufSz, unsigned int decryptBufOffset, void* ctx);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_SetStoreDataCallback(SSLStoreDataCb cb);
|
2021-08-01 18:00:22 +01:00
|
|
|
#endif
|
2019-11-11 17:09:59 +00:00
|
|
|
|
2021-08-01 18:00:22 +01:00
|
|
|
#ifdef WOLFSSL_SNIFFER_STORE_DATA_CB
|
2019-11-11 17:09:59 +00:00
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_DecodePacketWithSessionInfoStoreData(
|
|
|
|
const unsigned char* packet, int length, void* ctx,
|
|
|
|
SSLInfo* sslInfo, char* error);
|
2021-08-01 18:00:22 +01:00
|
|
|
#endif
|
2019-11-11 17:09:59 +00:00
|
|
|
|
2021-08-01 18:00:22 +01:00
|
|
|
#ifdef WOLFSSL_SNIFFER_CHAIN_INPUT
|
2019-11-11 17:09:59 +00:00
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_DecodePacketWithChain(void* vChain,
|
|
|
|
unsigned int chainSz, unsigned char** data, char* error);
|
2021-08-01 18:00:22 +01:00
|
|
|
#endif
|
2019-11-11 17:09:59 +00:00
|
|
|
|
2021-08-01 18:00:22 +01:00
|
|
|
#if defined(WOLFSSL_SNIFFER_CHAIN_INPUT) && \
|
|
|
|
defined(WOLFSSL_SNIFFER_STORE_DATA_CB)
|
2019-11-11 17:09:59 +00:00
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_DecodePacketWithChainSessionInfoStoreData(
|
|
|
|
void* vChain, unsigned int chainSz, void* ctx, SSLInfo* sslInfo,
|
|
|
|
char* error);
|
2021-08-01 18:00:22 +01:00
|
|
|
#endif
|
|
|
|
|
2023-01-01 17:00:36 +00:00
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_DecodePacket_GetStream(SnifferStreamInfo* info,
|
|
|
|
const byte* packet, int length, char* error);
|
|
|
|
|
|
|
|
#ifdef WOLFSSL_ASYNC_CRYPT
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_DecodePacketAsync(void* packet, unsigned int packetSz,
|
|
|
|
int isChain, unsigned char** data, char* error, SSLInfo* sslInfo,
|
|
|
|
void* userCtx);
|
|
|
|
|
|
|
|
WOLFSSL_API
|
|
|
|
SSL_SNIFFER_API int ssl_PollSniffer(WOLF_EVENT** events, int maxEvents,
|
|
|
|
WOLF_EVENT_FLAG flags, int* eventCount);
|
|
|
|
|
|
|
|
#endif /* WOLFSSL_ASYNC_CRYPT */
|
|
|
|
|
|
|
|
|
2019-11-11 17:09:59 +00:00
|
|
|
|
|
|
|
#ifdef __cplusplus
|
|
|
|
} /* extern "C" */
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#endif /* wolfSSL_SNIFFER_H */
|
|
|
|
|