2 Copyright (C) Andrew Tridgell 1995-1999
4 This software may be distributed either under the terms of the
5 BSD-style license that accompanies tcpdump or the GNU GPL version 2
13 static const char rcsid
[] =
14 "@(#) $Header: /tcpdump/master/tcpdump/smbutil.c,v 1.8 2000-07-10 04:47:36 assar Exp $";
17 #include <sys/param.h>
19 #include <sys/types.h>
20 #include <sys/socket.h>
24 #include <netinet/in.h>
25 #include <netinet/if_ether.h>
33 #include "interface.h"
36 extern uchar
*startbuf
;
38 /*******************************************************************
39 interpret a 32 bit dos packed date/time to some parameters
40 ********************************************************************/
41 static void interpret_dos_date(uint32 date
,int *year
,int *month
,int *day
,int *hour
,int *minute
,int *second
)
45 p0
=date
&0xFF; p1
=((date
&0xFF00)>>8)&0xFF;
46 p2
=((date
&0xFF0000)>>16)&0xFF; p3
=((date
&0xFF000000)>>24)&0xFF;
48 *second
= 2*(p0
& 0x1F);
49 *minute
= ((p0
>>5)&0xFF) + ((p1
&0x7)<<3);
52 *month
= ((p2
>>5)&0xFF) + ((p3
&0x1)<<3) - 1;
53 *year
= ((p3
>>1)&0xFF) + 80;
56 /*******************************************************************
57 create a unix date from a dos date
58 ********************************************************************/
59 static time_t make_unix_date(const void *date_ptr
)
64 dos_date
= IVAL(date_ptr
,0);
66 if (dos_date
== 0) return(0);
68 interpret_dos_date(dos_date
,&t
.tm_year
,&t
.tm_mon
,
69 &t
.tm_mday
,&t
.tm_hour
,&t
.tm_min
,&t
.tm_sec
);
77 /*******************************************************************
78 create a unix date from a dos date
79 ********************************************************************/
80 static time_t make_unix_date2(const void *date_ptr
)
85 x2
= ((x
&0xFFFF)<<16) | ((x
&0xFFFF0000)>>16);
88 return(make_unix_date((void *)&x
));
91 /****************************************************************************
92 interpret an 8 byte "filetime" structure to a time_t
93 It's originally in "100ns units since jan 1st 1601"
94 ****************************************************************************/
95 static time_t interpret_long_date(const char *p
)
100 /* this gives us seconds since jan 1st 1601 (approx) */
101 d
= (IVAL(p
,4)*256.0 + CVAL(p
,3)) * (1.0e-7 * (1<<24));
103 /* now adjust by 369 years to make the secs since 1970 */
104 d
-= 369.0*365.25*24*60*60;
106 /* and a fudge factor as we got it wrong by a few days */
107 d
+= (3*24*60*60 + 6*60*60 + 2);
118 /****************************************************************************
119 interpret the weird netbios "name". Return the name type
120 ****************************************************************************/
121 static int name_interpret(char *in
,char *out
)
124 int len
= (*in
++) / 2;
128 if (len
> 30 || len
<1) return(0);
132 if (in
[0] < 'A' || in
[0] > 'P' || in
[1] < 'A' || in
[1] > 'P') {
136 *out
= ((in
[0]-'A')<<4) + (in
[1]-'A');
146 /****************************************************************************
147 find a pointer to a netbios name
148 ****************************************************************************/
149 static char *name_ptr(char *buf
,int ofs
)
151 unsigned char c
= *(unsigned char *)(buf
+ofs
);
153 if ((c
& 0xC0) == 0xC0)
155 uint16 l
= RSVAL(buf
, ofs
) & 0x3FFF;
162 /****************************************************************************
163 extract a netbios name from a buf
164 ****************************************************************************/
165 static int name_extract(char *buf
,int ofs
,char *name
)
167 char *p
= name_ptr(buf
,ofs
);
169 return(name_interpret(p
,name
));
173 /****************************************************************************
174 return the total storage length of a mangled name
175 ****************************************************************************/
176 static int name_len(const unsigned char *s
)
179 unsigned char c
= *(unsigned char *)s
;
180 if ((c
& 0xC0) == 0xC0)
182 while (*s
) s
+= (*s
)+1;
183 return(PTR_DIFF(s
,s0
)+1);
186 static void print_asc(const unsigned char *buf
,int len
)
190 printf("%c",isprint(buf
[i
])?buf
[i
]:'.');
193 static char *name_type_str(int name_type
)
195 static char *f
= NULL
;
197 case 0: f
= "Workstation"; break;
198 case 0x03: f
= "Client?"; break;
199 case 0x20: f
= "Server"; break;
200 case 0x1d: f
= "Master Browser"; break;
201 case 0x1b: f
= "Domain Controller"; break;
202 case 0x1e: f
= "Browser Server"; break;
203 default: f
= "Unknown"; break;
208 void print_data(const unsigned char *buf
, int len
)
214 printf("%02X ",(int)buf
[i
]);
216 if (i
%8 == 0) printf(" ");
218 print_asc(&buf
[i
-16],8); printf(" ");
219 print_asc(&buf
[i
-8],8); printf("\n");
220 if (i
<len
) printf("[%03X] ",i
);
228 if (n
>8) printf(" ");
229 while (n
--) printf(" ");
232 print_asc(&buf
[i
-(i
%16)],n
); printf(" ");
234 if (n
>0) print_asc(&buf
[i
-n
],n
);
240 static void write_bits(unsigned int val
,char *fmt
)
245 while ((p
=strchr(fmt
,'|'))) {
246 int l
= PTR_DIFF(p
,fmt
);
247 if (l
&& (val
& (1<<i
)))
248 printf("%.*s ",l
,fmt
);
254 /* convert a unicode string */
255 static const char *unistr(const char *s
, int *len
)
257 static char buf
[1000];
259 static int use_unicode
= -1;
261 if (use_unicode
== -1) {
262 char *p
= getenv("USE_UNICODE");
263 if (p
&& (atoi(p
) == 1))
269 /* maybe it isn't unicode - a cheap trick */
270 if (!use_unicode
|| (s
[0] && s
[1])) {
277 if (s
[0] == 0 && s
[1] != 0) {
282 while (l
< (sizeof(buf
)-1) && s
[0] && s
[1] == 0) {
292 static const uchar
*fdata1(const uchar
*buf
, const char *fmt
, const uchar
*maxbuf
)
295 char *attrib_fmt
= "READONLY|HIDDEN|SYSTEM|VOLUME|DIR|ARCHIVE|";
298 while (*fmt
&& buf
<maxbuf
) {
301 write_bits(CVAL(buf
,0),attrib_fmt
);
306 write_bits(SVAL(buf
,0),attrib_fmt
);
313 char *p
= strchr(++fmt
,'}');
314 int l
= PTR_DIFF(p
,fmt
);
315 strncpy(bitfmt
,fmt
,l
);
318 write_bits(CVAL(buf
,0),bitfmt
);
328 while (isdigit(*fmt
)) fmt
++;
337 unsigned int x
= reverse
?RIVAL(buf
,0):IVAL(buf
,0);
338 printf("%d (0x%x)",x
, x
);
345 unsigned int x1
= reverse
?RIVAL(buf
,0):IVAL(buf
,0);
346 unsigned int x2
= reverse
?RIVAL(buf
,4):IVAL(buf
,4);
348 printf("0x%08x:%08x",x2
, x1
);
350 printf("%d (0x%08x%08x)",x1
, x2
, x1
);
358 unsigned int x
= reverse
?RSVAL(buf
,0):SVAL(buf
,0);
359 printf("%d (0x%x)",x
, x
);
366 unsigned int x
= reverse
?RIVAL(buf
,0):IVAL(buf
,0);
374 unsigned int x
= reverse
?RSVAL(buf
,0):SVAL(buf
,0);
382 unsigned int x
= CVAL(buf
,0);
390 unsigned int x
= CVAL(buf
,0);
391 printf("%d (0x%x)",x
, x
);
398 printf("%.*s",(int)PTR_DIFF(maxbuf
,buf
),unistr(buf
, &len
));
405 if (*buf
!= 4 && *buf
!= 2)
406 printf("Error! ASCIIZ buffer of type %d (safety=%d)\n",
407 *buf
,(int)PTR_DIFF(maxbuf
,buf
));
408 printf("%.*s",(int)PTR_DIFF(maxbuf
,buf
+1),unistr(buf
+1, &len
));
416 printf("%-*.*s",l
,l
,buf
);
418 fmt
++; while (isdigit(*fmt
)) fmt
++;
424 while (l
--) printf("%02x",*buf
++);
425 fmt
++; while (isdigit(*fmt
)) fmt
++;
435 name_type
= name_extract(startbuf
,PTR_DIFF(buf
,startbuf
),nbuf
);
436 buf
+= name_len(buf
);
437 printf("%-15.15s NameType=0x%02X (%s)",
438 nbuf
,name_type
,name_type_str(name_type
));
442 printf("%-15.15s NameType=0x%02X (%s)",
443 buf
,name_type
,name_type_str(name_type
));
447 fmt
++; while (isdigit(*fmt
)) fmt
++;
454 switch (atoi(fmt
+1)) {
456 if (x
==0 || x
==-1 || x
==0xFFFFFFFF)
459 t
= make_unix_date(buf
);
463 if (x
==0 || x
==-1 || x
==0xFFFFFFFF)
466 t
= make_unix_date2(buf
);
470 t
= interpret_long_date(buf
);
474 printf("%s",t
?asctime(localtime(&t
)):"NULL\n");
475 fmt
++; while (isdigit(*fmt
)) fmt
++;
485 if (buf
>=maxbuf
&& *fmt
)
486 printf("END OF BUFFER\n");
491 const uchar
*fdata(const uchar
*buf
, const char *fmt
, const uchar
*maxbuf
)
501 while (buf
< maxbuf
) {
504 buf2
= fdata(buf
,fmt
,maxbuf
);
506 if (buf2
== buf
) return(buf
);
513 if (buf
>=maxbuf
) return(buf
);
528 if (buf
>=maxbuf
) return(buf
);
531 strncpy(s
,fmt
,p
-fmt
);
533 buf
= fdata1(buf
,s
,maxbuf
);
537 putchar(*fmt
); fmt
++;
542 if (!depth
&& buf
<maxbuf
) {
543 int len
= PTR_DIFF(maxbuf
,buf
);
544 printf("Data: (%d bytes)\n",len
);
558 /* Dos Error Messages */
559 static err_code_struct dos_msgs
[] = {
560 {"ERRbadfunc",1,"Invalid function."},
561 {"ERRbadfile",2,"File not found."},
562 {"ERRbadpath",3,"Directory invalid."},
563 {"ERRnofids",4,"No file descriptors available"},
564 {"ERRnoaccess",5,"Access denied."},
565 {"ERRbadfid",6,"Invalid file handle."},
566 {"ERRbadmcb",7,"Memory control blocks destroyed."},
567 {"ERRnomem",8,"Insufficient server memory to perform the requested function."},
568 {"ERRbadmem",9,"Invalid memory block address."},
569 {"ERRbadenv",10,"Invalid environment."},
570 {"ERRbadformat",11,"Invalid format."},
571 {"ERRbadaccess",12,"Invalid open mode."},
572 {"ERRbaddata",13,"Invalid data."},
573 {"ERR",14,"reserved."},
574 {"ERRbaddrive",15,"Invalid drive specified."},
575 {"ERRremcd",16,"A Delete Directory request attempted to remove the server's current directory."},
576 {"ERRdiffdevice",17,"Not same device."},
577 {"ERRnofiles",18,"A File Search command can find no more files matching the specified criteria."},
578 {"ERRbadshare",32,"The sharing mode specified for an Open conflicts with existing FIDs on the file."},
579 {"ERRlock",33,"A Lock request conflicted with an existing lock or specified an invalid mode, or an Unlock requested attempted to remove a lock held by another process."},
580 {"ERRfilexists",80,"The file named in a Create Directory, Make New File or Link request already exists."},
581 {"ERRbadpipe",230,"Pipe invalid."},
582 {"ERRpipebusy",231,"All instances of the requested pipe are busy."},
583 {"ERRpipeclosing",232,"Pipe close in progress."},
584 {"ERRnotconnected",233,"No process on other end of pipe."},
585 {"ERRmoredata",234,"There is more data to be returned."},
588 /* Server Error Messages */
589 err_code_struct server_msgs
[] = {
590 {"ERRerror",1,"Non-specific error code."},
591 {"ERRbadpw",2,"Bad password - name/password pair in a Tree Connect or Session Setup are invalid."},
592 {"ERRbadtype",3,"reserved."},
593 {"ERRaccess",4,"The requester does not have the necessary access rights within the specified context for the requested function. The context is defined by the TID or the UID."},
594 {"ERRinvnid",5,"The tree ID (TID) specified in a command was invalid."},
595 {"ERRinvnetname",6,"Invalid network name in tree connect."},
596 {"ERRinvdevice",7,"Invalid device - printer request made to non-printer connection or non-printer request made to printer connection."},
597 {"ERRqfull",49,"Print queue full (files) -- returned by open print file."},
598 {"ERRqtoobig",50,"Print queue full -- no space."},
599 {"ERRqeof",51,"EOF on print queue dump."},
600 {"ERRinvpfid",52,"Invalid print file FID."},
601 {"ERRsmbcmd",64,"The server did not recognize the command received."},
602 {"ERRsrverror",65,"The server encountered an internal error, e.g., system file unavailable."},
603 {"ERRfilespecs",67,"The file handle (FID) and pathname parameters contained an invalid combination of values."},
604 {"ERRreserved",68,"reserved."},
605 {"ERRbadpermits",69,"The access permissions specified for a file or directory are not a valid combination. The server cannot set the requested attribute."},
606 {"ERRreserved",70,"reserved."},
607 {"ERRsetattrmode",71,"The attribute mode in the Set File Attribute request is invalid."},
608 {"ERRpaused",81,"Server is paused."},
609 {"ERRmsgoff",82,"Not receiving messages."},
610 {"ERRnoroom",83,"No room to buffer message."},
611 {"ERRrmuns",87,"Too many remote user names."},
612 {"ERRtimeout",88,"Operation timed out."},
613 {"ERRnoresource",89,"No resources currently available for request."},
614 {"ERRtoomanyuids",90,"Too many UIDs active on this session."},
615 {"ERRbaduid",91,"The UID is not known as a valid ID on this session."},
616 {"ERRusempx",250,"Temp unable to support Raw, use MPX mode."},
617 {"ERRusestd",251,"Temp unable to support Raw, use standard read/write."},
618 {"ERRcontmpx",252,"Continue in MPX mode."},
619 {"ERRreserved",253,"reserved."},
620 {"ERRreserved",254,"reserved."},
621 {"ERRnosupport",0xFFFF,"Function not supported."},
624 /* Hard Error Messages */
625 err_code_struct hard_msgs
[] = {
626 {"ERRnowrite",19,"Attempt to write on write-protected diskette."},
627 {"ERRbadunit",20,"Unknown unit."},
628 {"ERRnotready",21,"Drive not ready."},
629 {"ERRbadcmd",22,"Unknown command."},
630 {"ERRdata",23,"Data error (CRC)."},
631 {"ERRbadreq",24,"Bad request structure length."},
632 {"ERRseek",25 ,"Seek error."},
633 {"ERRbadmedia",26,"Unknown media type."},
634 {"ERRbadsector",27,"Sector not found."},
635 {"ERRnopaper",28,"Printer out of paper."},
636 {"ERRwrite",29,"Write fault."},
637 {"ERRread",30,"Read fault."},
638 {"ERRgeneral",31,"General failure."},
639 {"ERRbadshare",32,"A open conflicts with an existing open."},
640 {"ERRlock",33,"A Lock request conflicted with an existing lock or specified an invalid mode, or an Unlock requested attempted to remove a lock held by another process."},
641 {"ERRwrongdisk",34,"The wrong disk was found in a drive."},
642 {"ERRFCBUnavail",35,"No FCBs are available to process request."},
643 {"ERRsharebufexc",36,"A sharing buffer has been exceeded."},
651 err_code_struct
*err_msgs
;
654 {0x01,"ERRDOS",dos_msgs
},
655 {0x02,"ERRSRV",server_msgs
},
656 {0x03,"ERRHRD",hard_msgs
},
657 {0x04,"ERRXOS",NULL
},
658 {0xE1,"ERRRMX1",NULL
},
659 {0xE2,"ERRRMX2",NULL
},
660 {0xE3,"ERRRMX3",NULL
},
661 {0xFF,"ERRCMD",NULL
},
665 /****************************************************************************
666 return a SMB error string from a SMB buffer
667 ****************************************************************************/
668 char *smb_errstr(int class,int num
)
670 static char ret
[128];
675 for (i
=0;err_classes
[i
].class;i
++)
676 if (err_classes
[i
].code
== class)
678 if (err_classes
[i
].err_msgs
)
680 err_code_struct
*err
= err_classes
[i
].err_msgs
;
681 for (j
=0;err
[j
].name
;j
++)
682 if (num
== err
[j
].code
)
684 snprintf(ret
,sizeof(ret
),"%s - %s (%s)",err_classes
[i
].class,
685 err
[j
].name
,err
[j
].message
);
690 snprintf(ret
,sizeof(ret
),"%s - %d",err_classes
[i
].class,num
);
694 snprintf(ret
,sizeof(ret
),"ERROR: Unknown error (%d,%d)",class,num
);