diff options
| author | jakob <> | 2001-09-02 18:45:41 +0000 |
|---|---|---|
| committer | jakob <> | 2001-09-02 18:45:41 +0000 |
| commit | 90d432ac9607940d576a7a7e658ba0ff6a86c271 (patch) | |
| tree | 2d2c1927b752de246c54ae351e631eb2be7443a2 /src | |
| parent | 7543c16b6ed60668d4550f8d2acb04dc0a07190b (diff) | |
| download | openbsd-90d432ac9607940d576a7a7e658ba0ff6a86c271.tar.gz openbsd-90d432ac9607940d576a7a7e658ba0ff6a86c271.tar.bz2 openbsd-90d432ac9607940d576a7a7e658ba0ff6a86c271.zip | |
add very basic proxy support using socks5 client code from niklas@.
ok ericj@.
Diffstat (limited to 'src')
| -rw-r--r-- | src/usr.bin/nc/Makefile | 4 | ||||
| -rw-r--r-- | src/usr.bin/nc/nc.1 | 10 | ||||
| -rw-r--r-- | src/usr.bin/nc/netcat.c | 53 | ||||
| -rw-r--r-- | src/usr.bin/nc/socks.c | 144 |
4 files changed, 204 insertions, 7 deletions
diff --git a/src/usr.bin/nc/Makefile b/src/usr.bin/nc/Makefile index 7f761e17ab..150f8295bd 100644 --- a/src/usr.bin/nc/Makefile +++ b/src/usr.bin/nc/Makefile | |||
| @@ -1,6 +1,6 @@ | |||
| 1 | # $OpenBSD: Makefile,v 1.5 2001/06/27 03:13:08 smart Exp $ | 1 | # $OpenBSD: Makefile,v 1.6 2001/09/02 18:45:41 jakob Exp $ |
| 2 | 2 | ||
| 3 | PROG= nc | 3 | PROG= nc |
| 4 | SRCS= netcat.c atomicio.c | 4 | SRCS= netcat.c atomicio.c socks.c |
| 5 | 5 | ||
| 6 | .include <bsd.prog.mk> | 6 | .include <bsd.prog.mk> |
diff --git a/src/usr.bin/nc/nc.1 b/src/usr.bin/nc/nc.1 index 53fc6ecfb5..3025e99c4b 100644 --- a/src/usr.bin/nc/nc.1 +++ b/src/usr.bin/nc/nc.1 | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | .\" $OpenBSD: nc.1,v 1.18 2001/08/30 16:31:51 krw Exp $ | 1 | .\" $OpenBSD: nc.1,v 1.19 2001/09/02 18:45:41 jakob Exp $ |
| 2 | .\" | 2 | .\" |
| 3 | .\" Copyright (c) 1996 David Sacerdote | 3 | .\" Copyright (c) 1996 David Sacerdote |
| 4 | .\" All rights reserved. | 4 | .\" All rights reserved. |
| @@ -37,6 +37,7 @@ | |||
| 37 | .Op Fl i Ar interval | 37 | .Op Fl i Ar interval |
| 38 | .Op Fl p Ar source port | 38 | .Op Fl p Ar source port |
| 39 | .Op Fl s Ar source ip address | 39 | .Op Fl s Ar source ip address |
| 40 | .Op Fl x Ar proxy address Op :port | ||
| 40 | .Op Fl w Ar timeout | 41 | .Op Fl w Ar timeout |
| 41 | .Op Ar hostname | 42 | .Op Ar hostname |
| 42 | .Op Ar port[s] | 43 | .Op Ar port[s] |
| @@ -127,6 +128,13 @@ Use UDP instead of the default option of TCP. | |||
| 127 | Have | 128 | Have |
| 128 | .Nm | 129 | .Nm |
| 129 | give more verbose output. | 130 | give more verbose output. |
| 131 | .It Fl x Ar proxy address Op :port | ||
| 132 | Requests that | ||
| 133 | .Nm | ||
| 134 | should connect to | ||
| 135 | .Ar hostname | ||
| 136 | using a socks5 proxy at address and port. | ||
| 137 | If port is not specified, port 1080 is used. | ||
| 130 | .It Fl z | 138 | .It Fl z |
| 131 | Specifies that | 139 | Specifies that |
| 132 | .Nm | 140 | .Nm |
diff --git a/src/usr.bin/nc/netcat.c b/src/usr.bin/nc/netcat.c index 7bd88ad681..f2b7c19c4a 100644 --- a/src/usr.bin/nc/netcat.c +++ b/src/usr.bin/nc/netcat.c | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: netcat.c,v 1.33 2001/08/25 21:50:13 ericj Exp $ */ | 1 | /* $OpenBSD: netcat.c,v 1.34 2001/09/02 18:45:41 jakob Exp $ */ |
| 2 | /* | 2 | /* |
| 3 | * Copyright (c) 2001 Eric Jackson <ericj@monkey.org> | 3 | * Copyright (c) 2001 Eric Jackson <ericj@monkey.org> |
| 4 | * | 4 | * |
| @@ -61,6 +61,7 @@ char *sflag; /* Source Address */ | |||
| 61 | int tflag; /* Telnet Emulation */ | 61 | int tflag; /* Telnet Emulation */ |
| 62 | int uflag; /* UDP - Default to TCP */ | 62 | int uflag; /* UDP - Default to TCP */ |
| 63 | int vflag; /* Verbosity */ | 63 | int vflag; /* Verbosity */ |
| 64 | int xflag; /* Socks proxy */ | ||
| 64 | int zflag; /* Port Scan Flag */ | 65 | int zflag; /* Port Scan Flag */ |
| 65 | 66 | ||
| 66 | int timeout; | 67 | int timeout; |
| @@ -88,6 +89,9 @@ main(argc, argv) | |||
| 88 | struct servent *sv; | 89 | struct servent *sv; |
| 89 | socklen_t len; | 90 | socklen_t len; |
| 90 | struct sockaddr *cliaddr; | 91 | struct sockaddr *cliaddr; |
| 92 | char *proxy; | ||
| 93 | char *proxyhost, *proxyport; | ||
| 94 | struct addrinfo proxyhints; | ||
| 91 | 95 | ||
| 92 | ret = 1; | 96 | ret = 1; |
| 93 | s = 0; | 97 | s = 0; |
| @@ -96,7 +100,7 @@ main(argc, argv) | |||
| 96 | endp = NULL; | 100 | endp = NULL; |
| 97 | sv = NULL; | 101 | sv = NULL; |
| 98 | 102 | ||
| 99 | while ((ch = getopt(argc, argv, "46hi:klnp:rs:tuvw:z")) != -1) { | 103 | while ((ch = getopt(argc, argv, "46hi:klnp:rs:tuvw:x:z")) != -1) { |
| 100 | switch (ch) { | 104 | switch (ch) { |
| 101 | case '4': | 105 | case '4': |
| 102 | family = AF_INET; | 106 | family = AF_INET; |
| @@ -144,6 +148,10 @@ main(argc, argv) | |||
| 144 | if (timeout < 0 || *endp != '\0') | 148 | if (timeout < 0 || *endp != '\0') |
| 145 | errx(1, "timeout cannot be negative"); | 149 | errx(1, "timeout cannot be negative"); |
| 146 | break; | 150 | break; |
| 151 | case 'x': | ||
| 152 | xflag = 1; | ||
| 153 | proxy = strdup(optarg); | ||
| 154 | break; | ||
| 147 | case 'z': | 155 | case 'z': |
| 148 | zflag = 1; | 156 | zflag = 1; |
| 149 | break; | 157 | break; |
| @@ -183,6 +191,33 @@ main(argc, argv) | |||
| 183 | if (nflag) | 191 | if (nflag) |
| 184 | hints.ai_flags |= AI_NUMERICHOST; | 192 | hints.ai_flags |= AI_NUMERICHOST; |
| 185 | 193 | ||
| 194 | if (xflag) { | ||
| 195 | char *tmp; | ||
| 196 | |||
| 197 | if (uflag) | ||
| 198 | errx(1, "no proxy support for UDP mode"); | ||
| 199 | |||
| 200 | if (lflag) | ||
| 201 | errx(1, "no proxy support for listen"); | ||
| 202 | |||
| 203 | /* XXX IPv6 transport to proxy would probably work */ | ||
| 204 | if (family == AF_INET6) | ||
| 205 | errx(1, "no proxy support for IPv6"); | ||
| 206 | |||
| 207 | if (sflag) | ||
| 208 | errx(1, "no proxy support for local source address"); | ||
| 209 | |||
| 210 | proxyhost = strsep(&proxy, ":"); | ||
| 211 | proxyport = proxy; | ||
| 212 | |||
| 213 | memset(&proxyhints, 0, sizeof(struct addrinfo)); | ||
| 214 | proxyhints.ai_family = family; | ||
| 215 | proxyhints.ai_socktype = SOCK_STREAM; | ||
| 216 | proxyhints.ai_protocol = IPPROTO_TCP; | ||
| 217 | if (nflag) | ||
| 218 | proxyhints.ai_flags |= AI_NUMERICHOST; | ||
| 219 | } | ||
| 220 | |||
| 186 | if (lflag) { | 221 | if (lflag) { |
| 187 | int connfd; | 222 | int connfd; |
| 188 | ret = 0; | 223 | ret = 0; |
| @@ -236,8 +271,14 @@ main(argc, argv) | |||
| 236 | 271 | ||
| 237 | if (s) | 272 | if (s) |
| 238 | close(s); | 273 | close(s); |
| 239 | 274 | ||
| 240 | if ((s = remote_connect(host, portlist[i], hints)) < 0) | 275 | if (xflag) |
| 276 | s = socks_connect(host, portlist[i], hints, | ||
| 277 | proxyhost, proxyport, proxyhints); | ||
| 278 | else | ||
| 279 | s = remote_connect(host, portlist[i], hints); | ||
| 280 | |||
| 281 | if (s < 0) | ||
| 241 | continue; | 282 | continue; |
| 242 | 283 | ||
| 243 | ret = 0; | 284 | ret = 0; |
| @@ -326,6 +367,9 @@ remote_connect(host, port, hints) | |||
| 326 | 367 | ||
| 327 | if (connect(s, res0->ai_addr, res0->ai_addrlen) == 0) | 368 | if (connect(s, res0->ai_addr, res0->ai_addrlen) == 0) |
| 328 | break; | 369 | break; |
| 370 | |||
| 371 | if (error == 0) | ||
| 372 | break; | ||
| 329 | 373 | ||
| 330 | close(s); | 374 | close(s); |
| 331 | s = -1; | 375 | s = -1; |
| @@ -584,6 +628,7 @@ help() | |||
| 584 | \t-u UDP mode\n\ | 628 | \t-u UDP mode\n\ |
| 585 | \t-v Verbose\n\ | 629 | \t-v Verbose\n\ |
| 586 | \t-w secs\t Timeout for connects and final net reads\n\ | 630 | \t-w secs\t Timeout for connects and final net reads\n\ |
| 631 | \t-x addr[:port]\tSpecify socks5 proxy address and port\n\ | ||
| 587 | \t-z Zero-I/O mode [used for scanning]\n\ | 632 | \t-z Zero-I/O mode [used for scanning]\n\ |
| 588 | Port numbers can be individual or ranges: lo-hi [inclusive]\n"); | 633 | Port numbers can be individual or ranges: lo-hi [inclusive]\n"); |
| 589 | exit(1); | 634 | exit(1); |
diff --git a/src/usr.bin/nc/socks.c b/src/usr.bin/nc/socks.c new file mode 100644 index 0000000000..9189858959 --- /dev/null +++ b/src/usr.bin/nc/socks.c | |||
| @@ -0,0 +1,144 @@ | |||
| 1 | /* $OpenBSD: socks.c,v 1.1 2001/09/02 18:45:41 jakob Exp $ */ | ||
| 2 | |||
| 3 | /* | ||
| 4 | * Copyright (c) 1999 Niklas Hallqvist. All rights reserved. | ||
| 5 | * | ||
| 6 | * Redistribution and use in source and binary forms, with or without | ||
| 7 | * modification, are permitted provided that the following conditions | ||
| 8 | * are met: | ||
| 9 | * 1. Redistributions of source code must retain the above copyright | ||
| 10 | * notice, this list of conditions and the following disclaimer. | ||
| 11 | * 2. Redistributions in binary form must reproduce the above copyright | ||
| 12 | * notice, this list of conditions and the following disclaimer in the | ||
| 13 | * documentation and/or other materials provided with the distribution. | ||
| 14 | * 3. All advertising materials mentioning features or use of this software | ||
| 15 | * must display the following acknowledgement: | ||
| 16 | * This product includes software developed by Niklas Hallqvist. | ||
| 17 | * 4. The name of the author may not be used to endorse or promote products | ||
| 18 | * derived from this software without specific prior written permission. | ||
| 19 | * | ||
| 20 | * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR | ||
| 21 | * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES | ||
| 22 | * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. | ||
| 23 | * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, | ||
| 24 | * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT | ||
| 25 | * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, | ||
| 26 | * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY | ||
| 27 | * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT | ||
| 28 | * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF | ||
| 29 | * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. | ||
| 30 | */ | ||
| 31 | |||
| 32 | #include <sys/types.h> | ||
| 33 | #include <sys/socket.h> | ||
| 34 | #include <netinet/in.h> | ||
| 35 | #include <arpa/inet.h> | ||
| 36 | |||
| 37 | #include <err.h> | ||
| 38 | #include <netdb.h> | ||
| 39 | #include <stdio.h> | ||
| 40 | #include <stdlib.h> | ||
| 41 | #include <string.h> | ||
| 42 | #include <unistd.h> | ||
| 43 | |||
| 44 | #define SOCKS_PORT "1080" | ||
| 45 | #define SOCKS_VERSION 5 | ||
| 46 | #define SOCKS_NOAUTH 0 | ||
| 47 | #define SOCKS_NOMETHOD 0xff | ||
| 48 | #define SOCKS_CONNECT 1 | ||
| 49 | #define SOCKS_IPV4 1 | ||
| 50 | #define SOCKS_MAXCMDSZ 10 | ||
| 51 | |||
| 52 | static in_addr_t | ||
| 53 | decode_addr (const char *s) | ||
| 54 | { | ||
| 55 | struct hostent *hp = gethostbyname (s); | ||
| 56 | struct in_addr retval; | ||
| 57 | |||
| 58 | if (hp) | ||
| 59 | return *(in_addr_t *)hp->h_addr_list[0]; | ||
| 60 | if (inet_aton (s, &retval)) | ||
| 61 | return retval.s_addr; | ||
| 62 | errx (1, "cannot decode address \"%s\"", s); | ||
| 63 | } | ||
| 64 | |||
| 65 | static in_port_t | ||
| 66 | decode_port (const char *s) | ||
| 67 | { | ||
| 68 | struct servent *sp; | ||
| 69 | in_port_t port; | ||
| 70 | char *p; | ||
| 71 | |||
| 72 | port = strtol (s, &p, 10); | ||
| 73 | if (s == p) { | ||
| 74 | sp = getservbyname (s, "tcp"); | ||
| 75 | if (sp) | ||
| 76 | return sp->s_port; | ||
| 77 | } | ||
| 78 | if (*s != '\0' && *p == '\0') | ||
| 79 | return htons (port); | ||
| 80 | errx (1, "cannot decode port \"%s\"", s); | ||
| 81 | } | ||
| 82 | |||
| 83 | int | ||
| 84 | socks_connect (char *host, char *port, struct addrinfo hints, | ||
| 85 | char *proxyhost, char *proxyport, struct addrinfo proxyhints) | ||
| 86 | { | ||
| 87 | char *proxyport_default; | ||
| 88 | int proxyfd; | ||
| 89 | unsigned char buf[SOCKS_MAXCMDSZ]; | ||
| 90 | ssize_t cnt; | ||
| 91 | in_addr_t serveraddr; | ||
| 92 | in_port_t serverport; | ||
| 93 | |||
| 94 | if (proxyport) | ||
| 95 | proxyfd = remote_connect(proxyhost, proxyport, proxyhints); | ||
| 96 | else | ||
| 97 | proxyfd = remote_connect(proxyhost, SOCKS_PORT, proxyhints); | ||
| 98 | |||
| 99 | if (!proxyfd) | ||
| 100 | return -1; | ||
| 101 | |||
| 102 | serveraddr = decode_addr (host); | ||
| 103 | serverport = decode_port (port); | ||
| 104 | |||
| 105 | /* Version 5, one method: no authentication */ | ||
| 106 | buf[0] = SOCKS_VERSION; | ||
| 107 | buf[1] = 1; | ||
| 108 | buf[2] = SOCKS_NOAUTH; | ||
| 109 | cnt = write (proxyfd, buf, 3); | ||
| 110 | if (cnt == -1) | ||
| 111 | err (1, "write failed"); | ||
| 112 | if (cnt != 3) | ||
| 113 | errx (1, "short write, %d (expected 3)", cnt); | ||
| 114 | |||
| 115 | read (proxyfd, buf, 2); | ||
| 116 | if (buf[1] == SOCKS_NOMETHOD) | ||
| 117 | errx (1, "authentication method negotiation failed"); | ||
| 118 | |||
| 119 | /* Version 5, connect: IPv4 address */ | ||
| 120 | buf[0] = SOCKS_VERSION; | ||
| 121 | buf[1] = SOCKS_CONNECT; | ||
| 122 | buf[2] = 0; | ||
| 123 | buf[3] = SOCKS_IPV4; | ||
| 124 | memcpy (buf + 4, &serveraddr, sizeof serveraddr); | ||
| 125 | memcpy (buf + 8, &serverport, sizeof serverport); | ||
| 126 | |||
| 127 | /* XXX Handle short writes better */ | ||
| 128 | cnt = write (proxyfd, buf, 10); | ||
| 129 | if (cnt == -1) | ||
| 130 | err (1, "write failed"); | ||
| 131 | if (cnt != 10) | ||
| 132 | errx (1, "short write, %d (expected 10)", cnt); | ||
| 133 | |||
| 134 | /* XXX Handle short reads better */ | ||
| 135 | cnt = read (proxyfd, buf, sizeof buf); | ||
| 136 | if (cnt == -1) | ||
| 137 | err (1, "read failed"); | ||
| 138 | if (cnt != 10) | ||
| 139 | errx (1, "unexpected reply size %d (expected 10)", cnt); | ||
| 140 | if (buf[1] != 0) | ||
| 141 | errx (1, "connection failed, SOCKS error %d", buf[1]); | ||
| 142 | |||
| 143 | return proxyfd; | ||
| 144 | } | ||
