/src/suricata/rust/src/smb/smb3.rs
Line | Count | Source |
1 | | /* Copyright (C) 2018 Open Information Security Foundation |
2 | | * |
3 | | * You can copy, redistribute or modify this Program under the terms of |
4 | | * the GNU General Public License version 2 as published by the Free |
5 | | * Software Foundation. |
6 | | * |
7 | | * This program is distributed in the hope that it will be useful, |
8 | | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
9 | | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
10 | | * GNU General Public License for more details. |
11 | | * |
12 | | * You should have received a copy of the GNU General Public License |
13 | | * version 2 along with this program; if not, write to the Free Software |
14 | | * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA |
15 | | * 02110-1301, USA. |
16 | | */ |
17 | | |
18 | | use nom8::bytes::streaming::{tag, take}; |
19 | | use nom8::number::streaming::{le_u16, le_u32, le_u64}; |
20 | | use nom8::IResult; |
21 | | use nom8::Parser; |
22 | | |
23 | | #[derive(Debug, PartialEq, Eq)] |
24 | | pub struct Smb3TransformRecord<'a> { |
25 | | pub session_id: u64, |
26 | | pub enc_algo: u16, |
27 | | pub enc_data: &'a [u8], |
28 | | } |
29 | | |
30 | 3.74k | pub fn parse_smb3_transform_record(i: &[u8]) -> IResult<&[u8], Smb3TransformRecord<'_>> { |
31 | 3.74k | let (i, _) = tag(&b"\xfdSMB"[..]).parse(i)?; |
32 | 3.70k | let (i, _signature) = take(16_usize).parse(i)?; |
33 | 3.69k | let (i, _nonce) = take(16_usize).parse(i)?; |
34 | 3.68k | let (i, msg_size) = le_u32.parse(i)?; |
35 | 3.68k | let (i, _reserved) = le_u16.parse(i)?; |
36 | 3.68k | let (i, enc_algo) = le_u16.parse(i)?; |
37 | 3.67k | let (i, session_id) = le_u64.parse(i)?; |
38 | 3.66k | let (i, enc_data) = take(msg_size).parse(i)?; |
39 | 3.64k | let record = Smb3TransformRecord { |
40 | 3.64k | session_id, |
41 | 3.64k | enc_algo, |
42 | 3.64k | enc_data, |
43 | 3.64k | }; |
44 | 3.64k | Ok((i, record)) |
45 | 3.74k | } |
46 | | |
47 | | #[cfg(test)] |
48 | | mod tests { |
49 | | use super::*; |
50 | | #[test] |
51 | | fn test_parse_smb3_transform_record() { |
52 | | // https://raw.githubusercontent.com/bro/bro/master/testing/btest/Traces/smb/smb3.pcap |
53 | | let data = hex::decode("fd534d42188d39cea4b1e3f640aff5d0b1569852c0bd665516dbb4b499507f000000000069000000000001003d00009400480000d9f8a66572b40c621bea6f5922a412a8eb2e3cc2af9ce26a277e75898cb523b9eb49ef660a6a1a09368fadd6a58e893e08eb3b7c068bdb74b6cd38e9ed1a2559cefb2ebc2172fd86c08a1a636eb851f20bf53a242f4cfaf7ab44e77291073ad492d6297c3d3a67757c").unwrap(); |
54 | | let result = parse_smb3_transform_record(&data).unwrap(); |
55 | | let record: Smb3TransformRecord = result.1; |
56 | | assert_eq!(record.session_id, 79167320227901); |
57 | | assert_eq!(record.enc_algo, 1); |
58 | | assert_eq!(record.enc_data.len(), 105); |
59 | | } |
60 | | } |