]> The Tcpdump Group git mirrors - tcpdump/blob - print-ppp.c
better handling of unknown data in handle_ctrl_proto()
[tcpdump] / print-ppp.c
1 /*
2 * Copyright (c) 1990, 1991, 1993, 1994, 1995, 1996, 1997
3 * The Regents of the University of California. All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that: (1) source code distributions
7 * retain the above copyright notice and this paragraph in its entirety, (2)
8 * distributions including binary code include the above copyright notice and
9 * this paragraph in its entirety in the documentation or other materials
10 * provided with the distribution, and (3) all advertising materials mentioning
11 * features or use of this software display the following acknowledgement:
12 * ``This product includes software developed by the University of California,
13 * Lawrence Berkeley Laboratory and its contributors.'' Neither the name of
14 * the University nor the names of its contributors may be used to endorse
15 * or promote products derived from this software without specific prior
16 * written permission.
17 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR IMPLIED
18 * WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF
19 * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
20 *
21 * Extensively modified by Motonori Shindo (mshindo@mshindo.net) for more
22 * complete PPP support.
23 */
24
25 /*
26 * TODO:
27 * o resolve XXX as much as possible
28 * o MP support
29 * o BAP support
30 */
31
32 #ifndef lint
33 static const char rcsid[] =
34 "@(#) $Header: /tcpdump/master/tcpdump/print-ppp.c,v 1.72 2002-09-14 13:25:36 hannes Exp $ (LBL)";
35 #endif
36
37 #ifdef HAVE_CONFIG_H
38 #include "config.h"
39 #endif
40
41 #include <tcpdump-stdinc.h>
42
43 #ifdef __bsdi__
44 #include <net/slcompress.h>
45 #include <net/if_ppp.h>
46 #endif
47
48 #include <pcap.h>
49 #include <stdio.h>
50
51 #include "interface.h"
52 #include "extract.h"
53 #include "addrtoname.h"
54 #include "ppp.h"
55 #include "chdlc.h"
56 #include "ethertype.h"
57
58 /*
59 * The following constatns are defined by IANA. Please refer to
60 * http://www.isi.edu/in-notes/iana/assignments/ppp-numbers
61 * for the up-to-date information.
62 */
63
64 /* Protocol Codes defined in ppp.h */
65
66 struct tok ppptype2str[] = {
67 { PPP_IP, "IP" },
68 { PPP_OSI, "OSI" },
69 { PPP_NS, "NS" },
70 { PPP_DECNET, "DECNET" },
71 { PPP_APPLE, "APPLE" },
72 { PPP_IPX, "IPX" },
73 { PPP_VJC, "VJC" },
74 { PPP_VJNC, "VJNC" },
75 { PPP_BRPDU, "BRPDU" },
76 { PPP_STII, "STII" },
77 { PPP_VINES, "VINES" },
78 { PPP_MPLS_UCAST, "MPLS" },
79 { PPP_MPLS_MCAST, "MPLS" },
80
81 { PPP_HELLO, "HELLO" },
82 { PPP_LUXCOM, "LUXCOM" },
83 { PPP_SNS, "SNS" },
84 { PPP_IPCP, "IPCP" },
85 { PPP_OSICP, "OSICP" },
86 { PPP_NSCP, "NSCP" },
87 { PPP_DECNETCP, "DECNETCP" },
88 { PPP_APPLECP, "APPLECP" },
89 { PPP_IPXCP, "IPXCP" },
90 { PPP_STIICP, "STIICP" },
91 { PPP_VINESCP, "VINESCP" },
92 { PPP_MPLSCP, "MPLSCP" },
93
94 { PPP_LCP, "LCP" },
95 { PPP_PAP, "PAP" },
96 { PPP_LQM, "LQM" },
97 { PPP_CHAP, "CHAP" },
98 { PPP_BACP, "BACP" },
99 { PPP_BAP, "BAP" },
100 { PPP_MP, "MP" },
101 { 0, NULL }
102 };
103
104 /* Control Protocols (LCP/IPCP/CCP etc.) Codes defined in RFC 1661 */
105
106 #define CPCODES_VEXT 0 /* Vendor-Specific (RFC2153) */
107 #define CPCODES_CONF_REQ 1 /* Configure-Request */
108 #define CPCODES_CONF_ACK 2 /* Configure-Ack */
109 #define CPCODES_CONF_NAK 3 /* Configure-Nak */
110 #define CPCODES_CONF_REJ 4 /* Configure-Reject */
111 #define CPCODES_TERM_REQ 5 /* Terminate-Request */
112 #define CPCODES_TERM_ACK 6 /* Terminate-Ack */
113 #define CPCODES_CODE_REJ 7 /* Code-Reject */
114 #define CPCODES_PROT_REJ 8 /* Protocol-Reject (LCP only) */
115 #define CPCODES_ECHO_REQ 9 /* Echo-Request (LCP only) */
116 #define CPCODES_ECHO_RPL 10 /* Echo-Reply (LCP only) */
117 #define CPCODES_DISC_REQ 11 /* Discard-Request (LCP only) */
118 #define CPCODES_ID 12 /* Identification (LCP only) RFC1570 */
119 #define CPCODES_TIME_REM 13 /* Time-Remaining (LCP only) RFC1570 */
120 #define CPCODES_RESET_REQ 14 /* Reset-Request (CCP only) RFC1962 */
121 #define CPCODES_RESET_REP 15 /* Reset-Reply (CCP only) */
122
123 #define CPCODES_MAX CPCODES_RESET_REP
124
125 struct tok cpcodes[] = {
126 {CPCODES_VEXT, "Vendor-Extension"}, /* RFC2153 */
127 {CPCODES_CONF_REQ, "Conf-Request"},
128 {CPCODES_CONF_ACK, "Conf-Ack"},
129 {CPCODES_CONF_NAK, "Conf-Nack"},
130 {CPCODES_CONF_REJ, "Conf-Reject"},
131 {CPCODES_TERM_REQ, "Term-Request"},
132 {CPCODES_TERM_ACK, "Term-Ack"},
133 {CPCODES_CODE_REJ, "Code-Reject"},
134 {CPCODES_PROT_REJ, "Prot-Reject"},
135 {CPCODES_ECHO_REQ, "Echo-Request"},
136 {CPCODES_ECHO_RPL, "Echo-Reply"},
137 {CPCODES_DISC_REQ, "Disc-Req"},
138 {CPCODES_ID, "Ident"}, /* RFC1570 */
139 {CPCODES_TIME_REM, "Time-Rem"}, /* RFC1570 */
140 {CPCODES_RESET_REQ, "Reset-Req"}, /* RFC1962 */
141 {CPCODES_RESET_REP, "Reset-Ack"}, /* RFC1962 */
142 {0, NULL}
143 };
144
145 /* LCP Config Options */
146
147 #define LCPOPT_VEXT 0
148 #define LCPOPT_MRU 1
149 #define LCPOPT_ACCM 2
150 #define LCPOPT_AP 3
151 #define LCPOPT_QP 4
152 #define LCPOPT_MN 5
153 #define LCPOPT_DEP6 6
154 #define LCPOPT_PFC 7
155 #define LCPOPT_ACFC 8
156 #define LCPOPT_FCSALT 9
157 #define LCPOPT_SDP 10
158 #define LCPOPT_NUMMODE 11
159 #define LCPOPT_DEP12 12
160 #define LCPOPT_CBACK 13
161 #define LCPOPT_DEP14 14
162 #define LCPOPT_DEP15 15
163 #define LCPOPT_DEP16 16
164 #define LCPOPT_MLMRRU 17
165 #define LCPOPT_MLSSNHF 18
166 #define LCPOPT_MLED 19
167 #define LCPOPT_PROP 20
168 #define LCPOPT_DCEID 21
169 #define LCPOPT_MPP 22
170 #define LCPOPT_LD 23
171 #define LCPOPT_LCPAOPT 24
172 #define LCPOPT_COBS 25
173 #define LCPOPT_PE 26
174 #define LCPOPT_MLHF 27
175 #define LCPOPT_I18N 28
176 #define LCPOPT_SDLOS 29
177 #define LCPOPT_PPPMUX 30
178
179 #define LCPOPT_MIN LCPOPT_VEXT
180 #define LCPOPT_MAX LCPOPT_PPPMUX
181
182 static const char *lcpconfopts[] = {
183 "Vend-Ext", /* (0) */
184 "MRU", /* (1) */
185 "ACCM", /* (2) */
186 "Auth-Prot", /* (3) */
187 "Qual-Prot", /* (4) */
188 "Magic-Num", /* (5) */
189 "deprecated(6)", /* used to be a Quality Protocol */
190 "PFC", /* (7) */
191 "ACFC", /* (8) */
192 "FCS-Alt", /* (9) */
193 "SDP", /* (10) */
194 "Num-Mode", /* (11) */
195 "deprecated(12)", /* used to be a Multi-Link-Procedure*/
196 "Call-Back", /* (13) */
197 "deprecated(14)", /* used to be a Connect-Time */
198 "deprecated(15)", /* used to be a Compund-Frames */
199 "deprecated(16)", /* used to be a Nominal-Data-Encap */
200 "MRRU", /* (17) */
201 "SSNHF", /* (18) */
202 "End-Disc", /* (19) */
203 "Proprietary", /* (20) */
204 "DCE-Id", /* (21) */
205 "MP+", /* (22) */
206 "Link-Disc", /* (23) */
207 "LCP-Auth-Opt", /* (24) */
208 "COBS", /* (25) */
209 "Prefix-elision", /* (26) */
210 "Multilink-header-Form",/* (27) */
211 "I18N", /* (28) */
212 "SDL-over-SONET/SDH", /* (29) */
213 "PPP-Muxing", /* (30) */
214 };
215
216 /* IPV6CP - to be supported */
217 /* ECP - to be supported */
218
219 /* CCP Config Options */
220
221 #define CCPOPT_OUI 0 /* RFC1962 */
222 #define CCPOPT_PRED1 1 /* RFC1962 */
223 #define CCPOPT_PRED2 2 /* RFC1962 */
224 #define CCPOPT_PJUMP 3 /* RFC1962 */
225 /* 4-15 unassigned */
226 #define CCPOPT_HPPPC 16 /* RFC1962 */
227 #define CCPOPT_STACLZS 17 /* RFC1974 */
228 #define CCPOPT_MPPC 18 /* RFC2118 */
229 #define CCPOPT_GFZA 19 /* RFC1962 */
230 #define CCPOPT_V42BIS 20 /* RFC1962 */
231 #define CCPOPT_BSDCOMP 21 /* RFC1977 */
232 /* 22 unassigned */
233 #define CCPOPT_LZSDCP 23 /* RFC1967 */
234 #define CCPOPT_MVRCA 24 /* RFC1975 */
235 #define CCPOPT_DEC 25 /* RFC1976 */
236 #define CCPOPT_DEFLATE 26 /* RFC1979 */
237 /* 27-254 unassigned */
238 #define CCPOPT_RESV 255 /* RFC1962 */
239
240 #define CCPOPT_MIN CCPOPT_OUI
241 #define CCPOPT_MAX CCPOPT_DEFLATE /* XXX: should be CCPOPT_RESV but... */
242
243 static const char *ccpconfopts[] = {
244 "OUI", /* (0) */
245 "Pred-1", /* (1) */
246 "Pred-2", /* (2) */
247 "Puddle", /* (3) */
248 "unassigned(4)", /* (4) */
249 "unassigned(5)", /* (5) */
250 "unassigned(6)", /* (6) */
251 "unassigned(7)", /* (7) */
252 "unassigned(8)", /* (8) */
253 "unassigned(9)", /* (9) */
254 "unassigned(10)", /* (10) */
255 "unassigned(11)", /* (11) */
256 "unassigned(12)", /* (12) */
257 "unassigned(13)", /* (13) */
258 "unassigned(14)", /* (14) */
259 "unassigned(15)", /* (15) */
260 "HP-PPC", /* (16) */
261 "Stac-LZS", /* (17) */
262 "MPPC", /* (18) */
263 "Gand-FZA", /* (19) */
264 "V.42bis", /* (20) */
265 "BSD-Comp", /* (21) */
266 "unassigned(22)", /* (22) */
267 "LZS-DCP", /* (23) */
268 "MVRCA", /* (24) */
269 "DEC", /* (25) */
270 "Deflate", /* (26) */
271 };
272
273 /* BACP Config Options */
274
275 #define BACPOPT_FPEER 1 /* RFC2125 */
276
277 /* SDCP - to be supported */
278
279 /* IPCP Config Options */
280
281 #define IPCPOPT_2ADDR 1 /* RFC1172, RFC1332 (deprecated) */
282 #define IPCPOPT_IPCOMP 2 /* RFC1332 */
283 #define IPCPOPT_ADDR 3 /* RFC1332 */
284 #define IPCPOPT_MOBILE4 4 /* RFC2290 */
285
286 #define IPCPOPT_PRIDNS 129 /* RFC1877 */
287 #define IPCPOPT_PRINBNS 130 /* RFC1877 */
288 #define IPCPOPT_SECDNS 131 /* RFC1877 */
289 #define IPCPOPT_SECNBNS 132 /* RFC1877 */
290
291 /* ATCP - to be supported */
292 /* OSINLCP - to be supported */
293 /* BVCP - to be supported */
294 /* BCP - to be supported */
295 /* IPXCP - to be supported */
296 /* MPLSCP - to be supported */
297
298 /* Auth Algorithms */
299
300 /* 0-4 Reserved (RFC1994) */
301 #define AUTHALG_CHAPMD5 5 /* RFC1994 */
302 #define AUTHALG_MSCHAP1 128 /* RFC2433 */
303 #define AUTHALG_MSCHAP2 129 /* RFC2795 */
304
305 /* FCS Alternatives - to be supported */
306
307 /* Multilink Endpoint Discriminator (RFC1717) */
308 #define MEDCLASS_NULL 0 /* Null Class */
309 #define MEDCLASS_LOCAL 1 /* Locally Assigned */
310 #define MEDCLASS_IPV4 2 /* Internet Protocol (IPv4) */
311 #define MEDCLASS_MAC 3 /* IEEE 802.1 global MAC address */
312 #define MEDCLASS_MNB 4 /* PPP Magic Number Block */
313 #define MEDCLASS_PSNDN 5 /* Public Switched Network Director Number */
314
315 /* PPP LCP Callback */
316 #define CALLBACK_AUTH 0 /* Location determined by user auth */
317 #define CALLBACK_DSTR 1 /* Dialing string */
318 #define CALLBACK_LID 2 /* Location identifier */
319 #define CALLBACK_E164 3 /* E.164 number */
320 #define CALLBACK_X500 4 /* X.500 distinguished name */
321 #define CALLBACK_CBCP 6 /* Location is determined during CBCP nego */
322
323 /* CHAP */
324
325 #define CHAP_CHAL 1
326 #define CHAP_RESP 2
327 #define CHAP_SUCC 3
328 #define CHAP_FAIL 4
329
330 #define CHAP_CODEMIN CHAP_CHAL
331 #define CHAP_CODEMAX CHAP_FAIL
332
333 static const char *chapcode[] = {
334 "Chal", /* (1) */
335 "Resp", /* (2) */
336 "Succ", /* (3) */
337 "Fail", /* (4) */
338 };
339
340 /* PAP */
341
342 #define PAP_AREQ 1
343 #define PAP_AACK 2
344 #define PAP_ANAK 3
345
346 #define PAP_CODEMIN PAP_AREQ
347 #define PAP_CODEMAX PAP_ANAK
348
349 static const char *papcode[] = {
350 "Auth-Req", /* (1) */
351 "Auth-Ack", /* (2) */
352 "Auth-Nak", /* (3) */
353 };
354
355 /* BAP */
356 #define BAP_CALLREQ 1
357 #define BAP_CALLRES 2
358 #define BAP_CBREQ 3
359 #define BAP_CBRES 4
360 #define BAP_LDQREQ 5
361 #define BAP_LDQRES 6
362 #define BAP_CSIND 7
363 #define BAP_CSRES 8
364
365 static void handle_ctrl_proto (u_int proto,const u_char *p, int length);
366 static void handle_chap (const u_char *p, int length);
367 static void handle_pap (const u_char *p, int length);
368 static void handle_bap (const u_char *p, int length);
369 static int print_lcp_config_options (const u_char *p, int);
370 static int print_ipcp_config_options (const u_char *p, int);
371 static int print_ccp_config_options (const u_char *p, int);
372 static int print_bacp_config_options (const u_char *p, int);
373 static void handle_ppp (u_int proto, const u_char *p, int length);
374
375 /* generic Control Protocol (e.g. LCP, IPCP, CCP, etc.) handler */
376 static void
377 handle_ctrl_proto(u_int proto, const u_char *p, int length)
378 {
379 u_int code, len;
380 int (*pfunc)(const u_char *, int);
381 int x, j;
382
383 if (length < 1) {
384 printf("[|%s]",
385 tok2str(ppptype2str, "unknown protocol 0x%04x", proto));
386 return;
387 } else if (length < 4) {
388 printf("[|%s 0x%02x]",
389 tok2str(ppptype2str, "unknown protocol 0x%04x", proto),
390 *p);
391 return;
392 }
393
394 code = *p++;
395
396 printf("%s (%u)",
397 tok2str(cpcodes, "unknown opcode 0x%02x",code),
398 *p++); /* ID */
399
400 len = EXTRACT_16BITS(p);
401 p += 2;
402
403 if (length <= 4)
404 return; /* there may be a NULL confreq etc. */
405
406 switch (code) {
407 case CPCODES_VEXT:
408 if (length < 11)
409 break;
410 printf(", Magic-Num=%08x", EXTRACT_32BITS(p));
411 p += 4;
412 printf(" OUI=%02x%02x%02x", p[0], p[1], p[2]);
413 /* XXX: need to decode Kind and Value(s)? */
414 break;
415 case CPCODES_CONF_REQ:
416 case CPCODES_CONF_ACK:
417 case CPCODES_CONF_NAK:
418 case CPCODES_CONF_REJ:
419 x = len - 4; /* Code(1), Identifier(1) and Length(2) */
420 do {
421 switch (proto) {
422 case PPP_LCP:
423 pfunc = print_lcp_config_options;
424 break;
425 case PPP_IPCP:
426 pfunc = print_ipcp_config_options;
427 break;
428 case PPP_CCP:
429 pfunc = print_ccp_config_options;
430 break;
431 case PPP_BACP:
432 pfunc = print_bacp_config_options;
433 break;
434 default:
435 /*
436 * This should never happen, but we set
437 * "pfunc" to squelch uninitialized
438 * variable warnings from compilers.
439 */
440 pfunc = NULL;
441 break;
442 }
443 if ((j = (*pfunc)(p, len)) == 0)
444 break;
445 x -= j;
446 p += j;
447 } while (x > 0);
448 break;
449
450 case CPCODES_TERM_REQ:
451 case CPCODES_TERM_ACK:
452 /* XXX: need to decode Data? */
453 break;
454 case CPCODES_CODE_REJ:
455 /* XXX: need to decode Rejected-Packet? */
456 break;
457 case CPCODES_PROT_REJ:
458 if (length < 6)
459 break;
460 printf(", Rejected-Protocol=%04x", EXTRACT_16BITS(p));
461 /* XXX: need to decode Rejected-Information? */
462 break;
463 case CPCODES_ECHO_REQ:
464 case CPCODES_ECHO_RPL:
465 case CPCODES_DISC_REQ:
466 case CPCODES_ID:
467 if (length < 8)
468 break;
469 printf(", Magic-Num=%08x", EXTRACT_32BITS(p));
470 /* XXX: need to decode Data? */
471 break;
472 case CPCODES_TIME_REM:
473 if (length < 12)
474 break;
475 printf(", Magic-Num=%08x", EXTRACT_32BITS(p));
476 printf(" Seconds-Remaining=%u", EXTRACT_32BITS(p + 4));
477 /* XXX: need to decode Message? */
478 break;
479 default:
480 print_unknown_data(p,"\n\t",len);
481 break;
482 }
483 }
484
485 /* LCP config options */
486 static int
487 print_lcp_config_options(const u_char *p, int length)
488 {
489 int len, opt;
490
491 if (length < 2)
492 return 0;
493 len = p[1];
494 opt = p[0];
495 if (length < len)
496 return 0;
497 if ((opt >= LCPOPT_MIN) && (opt <= LCPOPT_MAX))
498 printf(", %s ", lcpconfopts[opt]);
499 else {
500 printf(", unknown LCP option 0x%02x", opt);
501 return len;
502 }
503
504 switch (opt) {
505 case LCPOPT_VEXT:
506 if (len >= 6) {
507 printf(" OUI=%02x%02x%02x", p[2], p[3], p[4]);
508 #if 0
509 printf(" kind=%02x", p[5]);
510 printf(" val=")
511 for (i = 0; i < len - 6; i++) {
512 printf("%02x", p[6 + i]);
513 }
514 #endif
515 }
516 break;
517 case LCPOPT_MRU:
518 if (len == 4)
519 printf("=%u", EXTRACT_16BITS(p + 2));
520 break;
521 case LCPOPT_ACCM:
522 if (len == 6)
523 printf("=%08x", EXTRACT_32BITS(p + 2));
524 break;
525 case LCPOPT_AP:
526 if (len >= 4) {
527 if (p[2] == 0xc0 && p[3] == 0x23)
528 printf(" PAP");
529 else if (p[2] == 0xc2 && p[3] == 0x23) {
530 printf(" CHAP/");
531 switch (p[4]) {
532 default:
533 printf("unknown-algorithm-%u", p[4]);
534 break;
535 case AUTHALG_CHAPMD5:
536 printf("MD5");
537 break;
538 case AUTHALG_MSCHAP1:
539 printf("MSCHAPv1");
540 break;
541 case AUTHALG_MSCHAP2:
542 printf("MSCHAPv2");
543 break;
544 }
545 }
546 else if (p[2] == 0xc2 && p[3] == 0x27)
547 printf(" EAP");
548 else if (p[2] == 0xc0 && p[3] == 0x27)
549 printf(" SPAP");
550 else if (p[2] == 0xc1 && p[3] == 0x23)
551 printf(" Old-SPAP");
552 else
553 printf("unknown");
554 }
555 break;
556 case LCPOPT_QP:
557 if (len >= 4) {
558 if (p[2] == 0xc0 && p[3] == 0x25)
559 printf(" LQR");
560 else
561 printf(" unknown");
562 }
563 break;
564 case LCPOPT_MN:
565 if (len == 6)
566 printf("=%08x", EXTRACT_32BITS(p + 2));
567 break;
568 case LCPOPT_PFC:
569 break;
570 case LCPOPT_ACFC:
571 break;
572 case LCPOPT_LD:
573 if (len == 4)
574 printf("=%04x", EXTRACT_16BITS(p + 2));
575 break;
576 case LCPOPT_CBACK:
577 if (len < 3)
578 break;
579 switch (p[2]) { /* Operation */
580 case CALLBACK_AUTH:
581 printf(" UserAuth");
582 break;
583 case CALLBACK_DSTR:
584 printf(" DialString");
585 break;
586 case CALLBACK_LID:
587 printf(" LocalID");
588 break;
589 case CALLBACK_E164:
590 printf(" E.164");
591 break;
592 case CALLBACK_X500:
593 printf(" X.500");
594 break;
595 case CALLBACK_CBCP:
596 printf(" CBCP");
597 break;
598 default:
599 printf(" unknown-operation=%u", p[2]);
600 break;
601 }
602 break;
603 case LCPOPT_MLMRRU:
604 if (len == 4)
605 printf("=%u", EXTRACT_16BITS(p + 2));
606 break;
607 case LCPOPT_MLED:
608 if (len < 3)
609 break;
610 switch (p[2]) { /* class */
611 case MEDCLASS_NULL:
612 printf(" Null");
613 break;
614 case MEDCLASS_LOCAL:
615 printf(" Local"); /* XXX */
616 break;
617 case MEDCLASS_IPV4:
618 if (len != 7)
619 break;
620 printf(" IPv4=%s", ipaddr_string(p + 3));
621 break;
622 case MEDCLASS_MAC:
623 if (len != 9)
624 break;
625 printf(" MAC=%02x:%02x:%02x:%02x:%02x:%02x",
626 p[3], p[4], p[5], p[6], p[7], p[8]);
627 break;
628 case MEDCLASS_MNB:
629 printf(" Magic-Num-Block"); /* XXX */
630 break;
631 case MEDCLASS_PSNDN:
632 printf(" PSNDN"); /* XXX */
633 break;
634 }
635 break;
636
637 /* XXX: to be supported */
638 #if 0
639 case LCPOPT_DEP6:
640 case LCPOPT_FCSALT:
641 case LCPOPT_SDP:
642 case LCPOPT_NUMMODE:
643 case LCPOPT_DEP12:
644 case LCPOPT_DEP14:
645 case LCPOPT_DEP15:
646 case LCPOPT_DEP16:
647 case LCPOPT_MLSSNHF:
648 case LCPOPT_PROP:
649 case LCPOPT_DCEID:
650 case LCPOPT_MPP:
651 case LCPOPT_LCPAOPT:
652 case LCPOPT_COBS:
653 case LCPOPT_PE:
654 case LCPOPT_MLHF:
655 case LCPOPT_I18N:
656 case LCPOPT_SDLOS:
657 case LCPOPT_PPPMUX:
658 break;
659 #endif
660 }
661 return len;
662 }
663
664 /* CHAP */
665 static void
666 handle_chap(const u_char *p, int length)
667 {
668 u_int code, len;
669 int val_size, name_size, msg_size;
670 const u_char *p0;
671 int i;
672
673 p0 = p;
674 if (length < 1) {
675 printf("[|chap]");
676 return;
677 } else if (length < 4) {
678 printf("[|chap 0x%02x]", *p);
679 return;
680 }
681
682 code = *p;
683 if ((code >= CHAP_CODEMIN) && (code <= CHAP_CODEMAX))
684 printf("%s", chapcode[code - 1]);
685 else {
686 printf("0x%02x", code);
687 return;
688 }
689 p++;
690
691 printf("(%u)", *p); /* ID */
692 p++;
693
694 len = EXTRACT_16BITS(p);
695 p += 2;
696
697 /*
698 * Note that this is a generic CHAP decoding routine. Since we
699 * don't know which flavor of CHAP (i.e. CHAP-MD5, MS-CHAPv1,
700 * MS-CHAPv2) is used at this point, we can't decode packet
701 * specifically to each algorithms. Instead, we simply decode
702 * the GCD (Gratest Common Denominator) for all algorithms.
703 */
704 switch (code) {
705 case CHAP_CHAL:
706 case CHAP_RESP:
707 if (length - (p - p0) < 1)
708 return;
709 val_size = *p; /* value size */
710 p++;
711 if (length - (p - p0) < val_size)
712 return;
713 printf(", Value=");
714 for (i = 0; i < val_size; i++)
715 printf("%02x", *p++);
716 name_size = len - (p - p0);
717 printf(", Name=");
718 for (i = 0; i < name_size; i++)
719 safeputchar(*p++);
720 break;
721 case CHAP_SUCC:
722 case CHAP_FAIL:
723 msg_size = len - (p - p0);
724 printf(", Msg=");
725 for (i = 0; i< msg_size; i++)
726 safeputchar(*p++);
727 break;
728 }
729 }
730
731 /* PAP (see RFC 1334) */
732 static void
733 handle_pap(const u_char *p, int length)
734 {
735 u_int code, len;
736 int peerid_len, passwd_len, msg_len;
737 const u_char *p0;
738 int i;
739
740 p0 = p;
741 if (length < 1) {
742 printf("[|pap]");
743 return;
744 } else if (length < 4) {
745 printf("[|pap 0x%02x]", *p);
746 return;
747 }
748
749 code = *p;
750 if ((code >= PAP_CODEMIN) && (code <= PAP_CODEMAX))
751 printf("%s", papcode[code - 1]);
752 else {
753 printf("0x%02x", code);
754 return;
755 }
756 p++;
757
758 printf("(%u)", *p); /* ID */
759 p++;
760
761 len = EXTRACT_16BITS(p);
762 p += 2;
763
764 switch (code) {
765 case PAP_AREQ:
766 if (length - (p - p0) < 1)
767 return;
768 peerid_len = *p; /* Peer-ID Length */
769 p++;
770 if (length - (p - p0) < peerid_len)
771 return;
772 printf(", Peer=");
773 for (i = 0; i < peerid_len; i++)
774 safeputchar(*p++);
775
776 if (length - (p - p0) < 1)
777 return;
778 passwd_len = *p; /* Password Length */
779 p++;
780 if (length - (p - p0) < passwd_len)
781 return;
782 printf(", Name=");
783 for (i = 0; i < passwd_len; i++)
784 safeputchar(*p++);
785 break;
786 case PAP_AACK:
787 case PAP_ANAK:
788 if (length - (p - p0) < 1)
789 return;
790 msg_len = *p; /* Msg-Length */
791 p++;
792 if (length - (p - p0) < msg_len)
793 return;
794 printf(", Msg=");
795 for (i = 0; i< msg_len; i++)
796 safeputchar(*p++);
797 break;
798 }
799 return;
800 }
801
802 /* BAP */
803 static void
804 handle_bap(const u_char *p _U_, int length _U_)
805 {
806 /* XXX: to be supported!! */
807 }
808
809
810 /* IPCP config options */
811 static int
812 print_ipcp_config_options(const u_char *p, int length)
813 {
814 int len, opt;
815
816 if (length < 2)
817 return 0;
818 len = p[1];
819 opt = p[0];
820 if (length < len)
821 return 0;
822 switch (opt) {
823 case IPCPOPT_2ADDR: /* deprecated */
824 if (len != 10)
825 goto invlen;
826 printf(", IP-Addrs src=%s dst=%s",
827 ipaddr_string(p + 2),
828 ipaddr_string(p + 6));
829 break;
830 case IPCPOPT_IPCOMP:
831 if (len < 4)
832 goto invlen;
833 printf(", IP-Comp");
834 if (EXTRACT_16BITS(p + 2) == PPP_VJC) {
835 printf(" VJ-Comp");
836 /* XXX: VJ-Comp parameters should be decoded */
837 } else
838 printf(" unknown-comp-proto=%04x", EXTRACT_16BITS(p + 2));
839 break;
840 case IPCPOPT_ADDR:
841 if (len != 6)
842 goto invlen;
843 printf(", IP-Addr=%s", ipaddr_string(p + 2));
844 break;
845 case IPCPOPT_MOBILE4:
846 if (len != 6)
847 goto invlen;
848 printf(", Home-Addr=%s", ipaddr_string(p + 2));
849 break;
850 case IPCPOPT_PRIDNS:
851 if (len != 6)
852 goto invlen;
853 printf(", Pri-DNS=%s", ipaddr_string(p + 2));
854 break;
855 case IPCPOPT_PRINBNS:
856 if (len != 6)
857 goto invlen;
858 printf(", Pri-NBNS=%s", ipaddr_string(p + 2));
859 break;
860 case IPCPOPT_SECDNS:
861 if (len != 6)
862 goto invlen;
863 printf(", Sec-DNS=%s", ipaddr_string(p + 2));
864 break;
865 case IPCPOPT_SECNBNS:
866 if (len != 6)
867 goto invlen;
868 printf(", Sec-NBNS=%s", ipaddr_string(p + 2));
869 break;
870 default:
871 printf(", unknown-%d", opt);
872 break;
873 }
874 return len;
875
876 invlen:
877 printf(", invalid-length-%d", opt);
878 return 0;
879 }
880
881 /* CCP config options */
882 static int
883 print_ccp_config_options(const u_char *p, int length)
884 {
885 int len, opt;
886
887 if (length < 2)
888 return 0;
889 len = p[1];
890 opt = p[0];
891 if (length < len)
892 return 0;
893 if ((opt >= CCPOPT_MIN) && (opt <= CCPOPT_MAX))
894 printf(", %s", ccpconfopts[opt]);
895 #if 0 /* XXX */
896 switch (opt) {
897 case CCPOPT_OUI:
898 case CCPOPT_PRED1:
899 case CCPOPT_PRED2:
900 case CCPOPT_PJUMP:
901 case CCPOPT_HPPPC:
902 case CCPOPT_STACLZS:
903 case CCPOPT_MPPC:
904 case CCPOPT_GFZA:
905 case CCPOPT_V42BIS:
906 case CCPOPT_BSDCOMP:
907 case CCPOPT_LZSDCP:
908 case CCPOPT_MVRCA:
909 case CCPOPT_DEC:
910 case CCPOPT_DEFLATE:
911 case CCPOPT_RESV:
912 break;
913
914 default:
915 printf(", unknown-%d", opt);
916 break;
917 }
918 #endif
919 return len;
920 }
921
922 /* BACP config options */
923 static int
924 print_bacp_config_options(const u_char *p, int length)
925 {
926 int len, opt;
927
928 if (length < 2)
929 return 0;
930 len = p[1];
931 opt = p[0];
932 if (length < len)
933 return 0;
934 if (opt == BACPOPT_FPEER) {
935 printf(", Favored-Peer");
936 printf(" Magic-Num=%08x", EXTRACT_32BITS(p + 2));
937 } else {
938 printf(", unknown-option-%d", opt);
939 }
940 return len;
941 }
942
943
944 /* PPP */
945 static void
946 handle_ppp(u_int proto, const u_char *p, int length)
947 {
948 switch (proto) {
949 case PPP_LCP:
950 case PPP_IPCP:
951 case PPP_CCP:
952 case PPP_BACP:
953 handle_ctrl_proto(proto, p, length);
954 break;
955 case PPP_CHAP:
956 handle_chap(p, length);
957 break;
958 case PPP_PAP:
959 handle_pap(p, length);
960 break;
961 case PPP_BAP: /* XXX: not yet completed */
962 handle_bap(p, length);
963 break;
964 case ETHERTYPE_IP: /*XXX*/
965 case PPP_IP:
966 ip_print(p, length);
967 break;
968 #ifdef INET6
969 case ETHERTYPE_IPV6: /*XXX*/
970 case PPP_IPV6:
971 ip6_print(p, length);
972 break;
973 #endif
974 case ETHERTYPE_IPX: /*XXX*/
975 case PPP_IPX:
976 ipx_print(p, length);
977 break;
978 case PPP_OSI:
979 isoclns_print(p, length, length, NULL, NULL);
980 break;
981 case PPP_MPLS_UCAST:
982 case PPP_MPLS_MCAST:
983 mpls_print(p, length);
984 break;
985 default:
986 break;
987 }
988 }
989
990 /* Standard PPP printer */
991 u_int
992 ppp_print(register const u_char *p, u_int length)
993 {
994 u_int proto;
995 u_int full_length = length;
996 u_int hdr_len = 0;
997
998 /*
999 * Here, we assume that p points to the Address and Control
1000 * field (if they present).
1001 */
1002 if (length < 2)
1003 goto trunc;
1004 if (*p == PPP_ADDRESS && *(p + 1) == PPP_CONTROL) {
1005 p += 2; /* ACFC not used */
1006 length -= 2;
1007 hdr_len += 2;
1008 }
1009
1010 if (length < 2)
1011 goto trunc;
1012 if (*p % 2) {
1013 proto = *p; /* PFC is used */
1014 p++;
1015 length--;
1016 hdr_len++;
1017 } else {
1018 proto = EXTRACT_16BITS(p);
1019 p += 2;
1020 length -= 2;
1021 hdr_len += 2;
1022 }
1023
1024 printf("%s, length: %u : ",
1025 tok2str(ppptype2str, "unknown-0x%04x", proto),
1026 full_length);
1027
1028 handle_ppp(proto, p, length);
1029 return (hdr_len);
1030 trunc:
1031 printf("[|ppp]");
1032 return (0);
1033 }
1034
1035
1036 /* PPP I/F printer */
1037 void
1038 ppp_if_print(u_char *user _U_, const struct pcap_pkthdr *h,
1039 register const u_char *p)
1040 {
1041 register u_int length = h->len;
1042 register u_int caplen = h->caplen;
1043
1044 ++infodelay;
1045 ts_print(&h->ts);
1046
1047 if (caplen < PPP_HDRLEN) {
1048 printf("[|ppp]");
1049 goto out;
1050 }
1051
1052 /*
1053 * Some printers want to get back at the link level addresses,
1054 * and/or check that they're not walking off the end of the packet.
1055 * Rather than pass them all the way down, we set these globals. */
1056
1057 packetp = p;
1058 snapend = p + caplen;
1059
1060 #if 0
1061 /*
1062 * XXX: seems to assume that there are 2 octets prepended to an
1063 * actual PPP frame. The 1st octet looks like Input/Output flag
1064 * while 2nd octet is unknown, at least to me
1065 * (mshindo@mshindo.net).
1066 *
1067 * That was what the original tcpdump code did.
1068 *
1069 * FreeBSD's "if_ppp.c" *does* set the first octet to 1 for outbound
1070 * packets and 0 for inbound packets - but only if the
1071 * protocol field has the 0x8000 bit set (i.e., it's a network
1072 * control protocol); it does so before running the packet through
1073 * "bpf_filter" to see if it should be discarded, and to see
1074 * if we should update the time we sent the most recent packet...
1075 *
1076 * ...but it puts the original address field back after doing
1077 * so.
1078 *
1079 * NetBSD's "if_ppp.c" doesn't set the first octet in that fashion.
1080 *
1081 * I don't know if any PPP implementation handed up to a BPF
1082 * device packets with the first octet being 1 for outbound and
1083 * 0 for inbound packets, so I (guy@alum.mit.edu) don't know
1084 * whether that ever needs to be checked or not.
1085 *
1086 * Note that NetBSD has a DLT_PPP_SERIAL, which it uses for PPP,
1087 * and its tcpdump appears to assume that the frame always
1088 * begins with an address field and a control field, and that
1089 * the address field might be 0x0f or 0x8f, for Cisco
1090 * point-to-point with HDLC framing as per section 4.3.1 of RFC
1091 * 1547, as well as 0xff, for PPP in HDLC-like framing as per
1092 * RFC 1662.
1093 *
1094 * (Is the Cisco framing in question what DLT_C_HDLC, in
1095 * BSD/OS, is?)
1096 */
1097 if (eflag)
1098 printf("%c %4d %02x ", p[0] ? 'O' : 'I', length, p[1]);
1099 #endif
1100
1101 ppp_print(p, length);
1102
1103 if (xflag)
1104 default_print(p, caplen);
1105 out:
1106 putchar('\n');
1107 --infodelay;
1108 if (infoprint)
1109 info(0);
1110 }
1111
1112 /*
1113 * PPP I/F printer to use if we know that RFC 1662-style PPP in HDLC-like
1114 * framing, or Cisco PPP with HDLC framing as per section 4.3.1 of RFC 1547,
1115 * is being used (i.e., we don't check for PPP_ADDRESS and PPP_CONTROL,
1116 * discard them *if* those are the first two octets, and parse the remaining
1117 * packet as a PPP packet, as "ppp_print()" does).
1118 *
1119 * This handles, for example, DLT_PPP_SERIAL in NetBSD.
1120 */
1121 void
1122 ppp_hdlc_if_print(u_char *user _U_, const struct pcap_pkthdr *h,
1123 register const u_char *p)
1124 {
1125 register u_int length = h->len;
1126 register u_int caplen = h->caplen;
1127 u_int proto;
1128
1129 ++infodelay;
1130 ts_print(&h->ts);
1131
1132 if (caplen < 2) {
1133 printf("[|ppp]");
1134 goto out;
1135 }
1136
1137 /*
1138 * Some printers want to get back at the link level addresses,
1139 * and/or check that they're not walking off the end of the packet.
1140 * Rather than pass them all the way down, we set these globals.
1141 */
1142 packetp = p;
1143 snapend = p + caplen;
1144
1145 switch (p[0]) {
1146
1147 case PPP_ADDRESS:
1148 if (caplen < 4) {
1149 printf("[|ppp]");
1150 goto out;
1151 }
1152
1153 if (eflag)
1154 printf("%02x %02x %d ", p[0], p[1], length);
1155 p += 2;
1156 length -= 2;
1157
1158 proto = EXTRACT_16BITS(p);
1159 p += 2;
1160 length -= 2;
1161 printf("%s: ", tok2str(ppptype2str, "unknown-0x%04x", proto));
1162
1163 handle_ppp(proto, p, length);
1164 break;
1165
1166 case CHDLC_UNICAST:
1167 case CHDLC_BCAST:
1168 chdlc_print(p, length, caplen);
1169 goto out;
1170
1171 default:
1172 if (eflag)
1173 printf("%02x %02x %d ", p[0], p[1], length);
1174 p += 2;
1175 length -= 2;
1176
1177 /*
1178 * XXX - NetBSD's "ppp_netbsd_serial_if_print()" treats
1179 * the next two octets as an Ethernet type; does that
1180 * ever happen?
1181 */
1182 printf("unknown addr %02x; ctrl %02x", p[0], p[1]);
1183 break;
1184 }
1185
1186 if (xflag)
1187 default_print(p, caplen);
1188 out:
1189 putchar('\n');
1190 --infodelay;
1191 if (infoprint)
1192 info(0);
1193 }
1194
1195 #define PPP_BSDI_HDRLEN 24
1196
1197 /* BSD/OS specific PPP printer */
1198 void
1199 ppp_bsdos_if_print(u_char *user _U_, const struct pcap_pkthdr *h _U_,
1200 register const u_char *p _U_)
1201 {
1202 #ifdef __bsdi__
1203 register u_int length = h->len;
1204 register u_int caplen = h->caplen;
1205 register int hdrlength;
1206 u_int16_t ptype;
1207 const u_char *q;
1208 int i;
1209
1210 ++infodelay;
1211 ts_print(&h->ts);
1212
1213 if (caplen < PPP_BSDI_HDRLEN) {
1214 printf("[|ppp]");
1215 goto out;
1216 }
1217
1218 /*
1219 * Some printers want to get back at the link level addresses,
1220 * and/or check that they're not walking off the end of the packet.
1221 * Rather than pass them all the way down, we set these globals.
1222 */
1223 packetp = p;
1224 snapend = p + caplen;
1225 hdrlength = 0;
1226
1227 #if 0
1228 if (p[0] == PPP_ADDRESS && p[1] == PPP_CONTROL) {
1229 if (eflag)
1230 printf("%02x %02x ", p[0], p[1]);
1231 p += 2;
1232 hdrlength = 2;
1233 }
1234
1235 if (eflag)
1236 printf("%d ", length);
1237 /* Retrieve the protocol type */
1238 if (*p & 01) {
1239 /* Compressed protocol field */
1240 ptype = *p;
1241 if (eflag)
1242 printf("%02x ", ptype);
1243 p++;
1244 hdrlength += 1;
1245 } else {
1246 /* Un-compressed protocol field */
1247 ptype = ntohs(*(u_int16_t *)p);
1248 if (eflag)
1249 printf("%04x ", ptype);
1250 p += 2;
1251 hdrlength += 2;
1252 }
1253 #else
1254 ptype = 0; /*XXX*/
1255 if (eflag)
1256 printf("%c ", p[SLC_DIR] ? 'O' : 'I');
1257 if (p[SLC_LLHL]) {
1258 /* link level header */
1259 struct ppp_header *ph;
1260
1261 q = p + SLC_BPFHDRLEN;
1262 ph = (struct ppp_header *)q;
1263 if (ph->phdr_addr == PPP_ADDRESS
1264 && ph->phdr_ctl == PPP_CONTROL) {
1265 if (eflag)
1266 printf("%02x %02x ", q[0], q[1]);
1267 ptype = ntohs(ph->phdr_type);
1268 if (eflag && (ptype == PPP_VJC || ptype == PPP_VJNC)) {
1269 printf("%s ", tok2str(ppptype2str,
1270 "proto-#%d", ptype));
1271 }
1272 } else {
1273 if (eflag) {
1274 printf("LLH=[");
1275 for (i = 0; i < p[SLC_LLHL]; i++)
1276 printf("%02x", q[i]);
1277 printf("] ");
1278 }
1279 }
1280 }
1281 if (eflag)
1282 printf("%d ", length);
1283 if (p[SLC_CHL]) {
1284 q = p + SLC_BPFHDRLEN + p[SLC_LLHL];
1285
1286 switch (ptype) {
1287 case PPP_VJC:
1288 ptype = vjc_print(q, ptype);
1289 hdrlength = PPP_BSDI_HDRLEN;
1290 p += hdrlength;
1291 switch (ptype) {
1292 case PPP_IP:
1293 ip_print(p, length);
1294 break;
1295 #ifdef INET6
1296 case PPP_IPV6:
1297 ip6_print(p, length);
1298 break;
1299 #endif
1300 case PPP_MPLS_UCAST:
1301 case PPP_MPLS_MCAST:
1302 mpls_print(p, length);
1303 break;
1304 }
1305 goto printx;
1306 case PPP_VJNC:
1307 ptype = vjc_print(q, ptype);
1308 hdrlength = PPP_BSDI_HDRLEN;
1309 p += hdrlength;
1310 switch (ptype) {
1311 case PPP_IP:
1312 ip_print(p, length);
1313 break;
1314 #ifdef INET6
1315 case PPP_IPV6:
1316 ip6_print(p, length);
1317 break;
1318 #endif
1319 case PPP_MPLS_UCAST:
1320 case PPP_MPLS_MCAST:
1321 mpls_print(p, length);
1322 break;
1323 }
1324 goto printx;
1325 default:
1326 if (eflag) {
1327 printf("CH=[");
1328 for (i = 0; i < p[SLC_LLHL]; i++)
1329 printf("%02x", q[i]);
1330 printf("] ");
1331 }
1332 break;
1333 }
1334 }
1335
1336 hdrlength = PPP_BSDI_HDRLEN;
1337 #endif
1338
1339 length -= hdrlength;
1340 p += hdrlength;
1341
1342 switch (ptype) {
1343 case PPP_IP:
1344 ip_print(p, length);
1345 break;
1346 #ifdef INET6
1347 case PPP_IPV6:
1348 ip6_print(p, length);
1349 break;
1350 #endif
1351 case PPP_MPLS_UCAST:
1352 case PPP_MPLS_MCAST:
1353 mpls_print(p, length);
1354 break;
1355 default:
1356 printf("%s ", tok2str(ppptype2str, "unknown protocol 0x%04x", ptype));
1357 }
1358
1359 printx:
1360 if (xflag)
1361 default_print((const u_char *)p, caplen - hdrlength);
1362 out:
1363 putchar('\n');
1364 --infodelay;
1365 if (infoprint)
1366 info(0);
1367 #endif /* __bsdi__ */
1368 }