/src/wireshark/epan/dissectors/packet-rip.c
Line | Count | Source |
1 | | /* packet-rip.c |
2 | | * Routines for RIPv1 and RIPv2 packet disassembly |
3 | | * RFC1058 (STD 34), RFC1388, RFC1723, RFC2453 (STD 56) |
4 | | * (c) Copyright Hannes R. Boehm <hannes@boehm.org> |
5 | | * |
6 | | * RFC2082 ( Keyed Message Digest Algorithm ) |
7 | | * Emanuele Caratti <wiz@iol.it> |
8 | | * |
9 | | * Wireshark - Network traffic analyzer |
10 | | * By Gerald Combs <gerald@wireshark.org> |
11 | | * Copyright 1998 Gerald Combs |
12 | | * |
13 | | * SPDX-License-Identifier: GPL-2.0-or-later |
14 | | */ |
15 | | #include "config.h" |
16 | | |
17 | | #include <epan/packet.h> |
18 | | #include <epan/expert.h> |
19 | | #include <epan/prefs.h> |
20 | | #include <epan/to_str.h> |
21 | | |
22 | 16 | #define UDP_PORT_RIP 520 |
23 | | |
24 | | #define RIPv1 1 |
25 | 219 | #define RIPv2 2 |
26 | | |
27 | | void proto_register_rip(void); |
28 | | void proto_reg_handoff_rip(void); |
29 | | |
30 | | static const value_string version_vals[] = { |
31 | | { RIPv1, "RIPv1" }, |
32 | | { RIPv2, "RIPv2" }, |
33 | | { 0, NULL } |
34 | | }; |
35 | | |
36 | | static const value_string command_vals[] = { |
37 | | { 1, "Request" }, |
38 | | { 2, "Response" }, |
39 | | { 3, "Traceon" }, |
40 | | { 4, "Traceoff" }, |
41 | | { 5, "Vendor specific (Sun)" }, |
42 | | { 0, NULL } |
43 | | }; |
44 | | |
45 | 109 | #define AFVAL_UNSPEC 0 |
46 | 9 | #define AFVAL_IP 2 |
47 | | |
48 | | static const value_string family_vals[] = { |
49 | | { AFVAL_UNSPEC, "Unspecified" }, |
50 | | { AFVAL_IP, "IP" }, |
51 | | { 0, NULL } |
52 | | }; |
53 | | |
54 | | #define AUTH_IP_ROUTE 1 |
55 | 0 | #define AUTH_PASSWORD 2 |
56 | 0 | #define AUTH_KEYED_MSG_DIGEST 3 |
57 | | |
58 | | static const value_string rip_auth_type[] = { |
59 | | { AUTH_IP_ROUTE, "IP Route" }, |
60 | | { AUTH_PASSWORD, "Simple Password" }, |
61 | | { AUTH_KEYED_MSG_DIGEST, "Keyed Message Digest" }, |
62 | | { 0, NULL } |
63 | | }; |
64 | | |
65 | 209 | #define RIP_HEADER_LENGTH 4 |
66 | 937 | #define RIP_ENTRY_LENGTH 20 |
67 | 0 | #define MD5_AUTH_DATA_LEN 16 |
68 | | |
69 | | static bool pref_display_routing_domain; |
70 | | |
71 | | static dissector_handle_t rip_handle; |
72 | | |
73 | | static int proto_rip; |
74 | | |
75 | | static int hf_rip_auth; |
76 | | static int hf_rip_auth_data_len; |
77 | | static int hf_rip_auth_passwd; |
78 | | static int hf_rip_auth_seq_num; |
79 | | static int hf_rip_authentication_data; |
80 | | static int hf_rip_command; |
81 | | static int hf_rip_digest_offset; |
82 | | static int hf_rip_family; |
83 | | static int hf_rip_ip; |
84 | | static int hf_rip_key_id; |
85 | | static int hf_rip_metric; |
86 | | static int hf_rip_netmask; |
87 | | static int hf_rip_next_hop; |
88 | | static int hf_rip_route_tag; |
89 | | static int hf_rip_routing_domain; |
90 | | static int hf_rip_version; |
91 | | static int hf_rip_zero_padding; |
92 | | |
93 | | static int ett_rip; |
94 | | static int ett_rip_vec; |
95 | | static int ett_auth_vec; |
96 | | |
97 | | static expert_field ei_rip_unknown_address_family; |
98 | | |
99 | | static void dissect_unspec_rip_vektor(tvbuff_t *tvb, int offset, uint8_t version, |
100 | | proto_tree *tree); |
101 | | static void dissect_ip_rip_vektor(tvbuff_t *tvb, packet_info *pinfo, int offset, uint8_t version, |
102 | | proto_tree *tree); |
103 | | static unsigned dissect_rip_authentication(tvbuff_t *tvb, packet_info* pinfo, int offset, |
104 | | proto_tree *tree); |
105 | | |
106 | | static int |
107 | | dissect_rip(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_) |
108 | 46 | { |
109 | 46 | int offset = 0; |
110 | 46 | proto_tree *rip_tree = NULL; |
111 | 46 | proto_item *ti; |
112 | 46 | uint8_t command; |
113 | 46 | uint8_t version; |
114 | 46 | uint16_t family; |
115 | 46 | unsigned trailer_len = 0; |
116 | 46 | bool is_md5_auth = false; |
117 | | |
118 | 46 | col_set_str(pinfo->cinfo, COL_PROTOCOL, "RIP"); |
119 | 46 | col_clear(pinfo->cinfo, COL_INFO); |
120 | | |
121 | 46 | command = tvb_get_uint8(tvb, 0); |
122 | 46 | version = tvb_get_uint8(tvb, 1); |
123 | | |
124 | 46 | col_set_str(pinfo->cinfo, COL_PROTOCOL, |
125 | 46 | val_to_str_const(version, version_vals, "RIP")); |
126 | 46 | col_add_str(pinfo->cinfo, COL_INFO, |
127 | 46 | val_to_str(pinfo->pool, command, command_vals, "Unknown command (%u)")); |
128 | | |
129 | 46 | ti = proto_tree_add_item(tree, proto_rip, tvb, 0, -1, ENC_NA); |
130 | 46 | rip_tree = proto_item_add_subtree(ti, ett_rip); |
131 | | |
132 | 46 | proto_tree_add_uint(rip_tree, hf_rip_command, tvb, 0, 1, command); |
133 | 46 | proto_tree_add_uint(rip_tree, hf_rip_version, tvb, 1, 1, version); |
134 | 46 | if (version == RIPv2 && pref_display_routing_domain == true) |
135 | 0 | proto_tree_add_item(rip_tree, hf_rip_routing_domain, tvb, 2, 2, |
136 | 0 | ENC_BIG_ENDIAN); |
137 | | |
138 | | /* skip header */ |
139 | 46 | offset = RIP_HEADER_LENGTH; |
140 | | |
141 | | /* zero or more entries */ |
142 | 498 | while (tvb_reported_length_remaining(tvb, offset) > trailer_len ) { |
143 | 492 | family = tvb_get_ntohs(tvb, offset); |
144 | 492 | switch (family) { |
145 | 109 | case AFVAL_UNSPEC: /* Unspecified */ |
146 | | /* |
147 | | * There should be one entry in the request, and a metric |
148 | | * of infinity, meaning "show the entire routing table". |
149 | | */ |
150 | 109 | dissect_unspec_rip_vektor(tvb, offset, version, rip_tree); |
151 | 109 | break; |
152 | 9 | case AFVAL_IP: /* IP */ |
153 | 9 | dissect_ip_rip_vektor(tvb, pinfo, offset, version, rip_tree); |
154 | 9 | break; |
155 | 163 | case 0xFFFF: |
156 | 163 | if( offset == RIP_HEADER_LENGTH ) { |
157 | 12 | trailer_len=dissect_rip_authentication(tvb, pinfo, offset, rip_tree); |
158 | 12 | is_md5_auth = true; |
159 | 12 | break; |
160 | 12 | } |
161 | 151 | if(is_md5_auth && tvb_reported_length_remaining(tvb, offset) == 20) |
162 | 1 | break; |
163 | | /* Intentional fall through */ /* auth Entry MUST be the first! */ |
164 | 355 | default: |
165 | 355 | proto_tree_add_expert_format(rip_tree, pinfo, &ei_rip_unknown_address_family, tvb, offset, |
166 | 355 | RIP_ENTRY_LENGTH, "Unknown address family %u", family); |
167 | 355 | break; |
168 | 492 | } |
169 | | |
170 | 452 | offset += RIP_ENTRY_LENGTH; |
171 | 452 | } |
172 | 6 | return tvb_captured_length(tvb); |
173 | 46 | } |
174 | | |
175 | | static void |
176 | | dissect_unspec_rip_vektor(tvbuff_t *tvb, int offset, uint8_t version, |
177 | | proto_tree *tree) |
178 | 109 | { |
179 | 109 | proto_tree *rip_vektor_tree; |
180 | 109 | uint32_t metric; |
181 | | |
182 | 109 | metric = tvb_get_ntohl(tvb, offset+16); |
183 | 109 | rip_vektor_tree = proto_tree_add_subtree_format(tree, tvb, offset, |
184 | 109 | RIP_ENTRY_LENGTH, ett_rip_vec, NULL, "Address not specified, Metric: %u", |
185 | 109 | metric); |
186 | | |
187 | 109 | proto_tree_add_item(rip_vektor_tree, hf_rip_family, tvb, offset, 2, ENC_BIG_ENDIAN); |
188 | 109 | if (version == RIPv2) { |
189 | 34 | proto_tree_add_item(rip_vektor_tree, hf_rip_route_tag, tvb, offset+2, 2, |
190 | 34 | ENC_BIG_ENDIAN); |
191 | 34 | proto_tree_add_item(rip_vektor_tree, hf_rip_netmask, tvb, offset+8, 4, |
192 | 34 | ENC_BIG_ENDIAN); |
193 | 34 | proto_tree_add_item(rip_vektor_tree, hf_rip_next_hop, tvb, offset+12, 4, |
194 | 34 | ENC_BIG_ENDIAN); |
195 | 34 | } |
196 | 109 | proto_tree_add_uint(rip_vektor_tree, hf_rip_metric, tvb, |
197 | 109 | offset+16, 4, metric); |
198 | 109 | } |
199 | | |
200 | | static void |
201 | | dissect_ip_rip_vektor(tvbuff_t *tvb, packet_info *pinfo, int offset, uint8_t version, |
202 | | proto_tree *tree) |
203 | 9 | { |
204 | 9 | proto_tree *rip_vektor_tree; |
205 | 9 | uint32_t metric; |
206 | | |
207 | 9 | metric = tvb_get_ntohl(tvb, offset+16); |
208 | 9 | rip_vektor_tree = proto_tree_add_subtree_format(tree, tvb, offset, |
209 | 9 | RIP_ENTRY_LENGTH, ett_rip_vec, NULL, "IP Address: %s, Metric: %u", |
210 | 9 | tvb_ip_to_str(pinfo->pool, tvb, offset+4), metric); |
211 | | |
212 | 9 | proto_tree_add_item(rip_vektor_tree, hf_rip_family, tvb, offset, 2, ENC_BIG_ENDIAN); |
213 | 9 | if (version == RIPv2) { |
214 | 1 | proto_tree_add_item(rip_vektor_tree, hf_rip_route_tag, tvb, offset+2, 2, |
215 | 1 | ENC_BIG_ENDIAN); |
216 | 1 | } |
217 | | |
218 | 9 | proto_tree_add_item(rip_vektor_tree, hf_rip_ip, tvb, offset+4, 4, ENC_BIG_ENDIAN); |
219 | | |
220 | 9 | if (version == RIPv2) { |
221 | 1 | proto_tree_add_item(rip_vektor_tree, hf_rip_netmask, tvb, offset+8, 4, |
222 | 1 | ENC_BIG_ENDIAN); |
223 | 1 | proto_tree_add_item(rip_vektor_tree, hf_rip_next_hop, tvb, offset+12, 4, |
224 | 1 | ENC_BIG_ENDIAN); |
225 | 1 | } |
226 | 9 | proto_tree_add_uint(rip_vektor_tree, hf_rip_metric, tvb, |
227 | 9 | offset+16, 4, metric); |
228 | 9 | } |
229 | | |
230 | | static unsigned |
231 | | dissect_rip_authentication(tvbuff_t *tvb, packet_info* pinfo, int offset, proto_tree *tree) |
232 | 12 | { |
233 | 12 | proto_tree *rip_authentication_tree; |
234 | 12 | uint16_t authtype; |
235 | 12 | uint32_t digest_off, auth_data_len; |
236 | | |
237 | 12 | auth_data_len = 0; |
238 | 12 | authtype = tvb_get_ntohs(tvb, offset + 2); |
239 | | |
240 | 12 | rip_authentication_tree = proto_tree_add_subtree_format(tree, tvb, offset, RIP_ENTRY_LENGTH, |
241 | 12 | ett_rip_vec, NULL, "Authentication: %s", val_to_str(pinfo->pool, authtype, rip_auth_type, "Unknown (%u)" ) ); |
242 | | |
243 | 12 | proto_tree_add_uint(rip_authentication_tree, hf_rip_auth, tvb, offset+2, 2, |
244 | 12 | authtype); |
245 | | |
246 | 12 | switch ( authtype ) { |
247 | | |
248 | 0 | case AUTH_PASSWORD: /* Plain text password */ |
249 | 0 | proto_tree_add_item(rip_authentication_tree, hf_rip_auth_passwd, |
250 | 0 | tvb, offset+4, 16, ENC_ASCII); |
251 | 0 | break; |
252 | | |
253 | 0 | case AUTH_KEYED_MSG_DIGEST: /* Keyed MD5 rfc 2082 */ |
254 | 0 | digest_off = tvb_get_ntohs( tvb, offset+4 ); |
255 | 0 | proto_tree_add_item( rip_authentication_tree, hf_rip_digest_offset, tvb, offset+4, 2, ENC_BIG_ENDIAN); |
256 | 0 | proto_tree_add_item( rip_authentication_tree, hf_rip_key_id, tvb, offset+6, 1, ENC_NA); |
257 | 0 | auth_data_len = tvb_get_uint8( tvb, offset+7 ); |
258 | 0 | proto_tree_add_item( rip_authentication_tree, hf_rip_auth_data_len, tvb, offset+7, 1, ENC_NA); |
259 | 0 | proto_tree_add_item( rip_authentication_tree, hf_rip_auth_seq_num, tvb, offset+8, 4, ENC_BIG_ENDIAN); |
260 | 0 | proto_tree_add_item( rip_authentication_tree, hf_rip_zero_padding, tvb, offset+12, 8, ENC_ASCII); |
261 | 0 | rip_authentication_tree = proto_tree_add_subtree( rip_authentication_tree, tvb, offset-4+digest_off, |
262 | 0 | MD5_AUTH_DATA_LEN+4, ett_auth_vec, NULL, "Authentication Data Trailer" ); |
263 | 0 | proto_tree_add_item( rip_authentication_tree, hf_rip_authentication_data, tvb, offset-4+digest_off+4, |
264 | 0 | MD5_AUTH_DATA_LEN, ENC_NA); |
265 | 0 | break; |
266 | 12 | } |
267 | 12 | return auth_data_len; |
268 | 12 | } |
269 | | |
270 | | void |
271 | | proto_register_rip(void) |
272 | 16 | { |
273 | 16 | static hf_register_info hf[] = { |
274 | 16 | { &hf_rip_command, |
275 | 16 | { "Command", "rip.command", |
276 | 16 | FT_UINT8, BASE_DEC, VALS(command_vals), 0, |
277 | 16 | "What type of RIP Command is this", HFILL } |
278 | 16 | }, |
279 | 16 | { &hf_rip_version, |
280 | 16 | { "Version", "rip.version", |
281 | 16 | FT_UINT8, BASE_DEC, VALS(version_vals), 0, |
282 | 16 | "Version of the RIP protocol", HFILL } |
283 | 16 | }, |
284 | 16 | { &hf_rip_routing_domain, |
285 | 16 | { "Routing Domain", "rip.routing_domain", |
286 | 16 | FT_UINT16, BASE_DEC, NULL, 0, |
287 | 16 | "RIPv2 Routing Domain", HFILL } |
288 | 16 | }, |
289 | 16 | { &hf_rip_ip, |
290 | 16 | { "IP Address", "rip.ip", |
291 | 16 | FT_IPv4, BASE_NONE, NULL, 0, |
292 | 16 | NULL, HFILL } |
293 | 16 | }, |
294 | 16 | { &hf_rip_netmask, |
295 | 16 | { "Netmask", "rip.netmask", |
296 | 16 | FT_IPv4, BASE_NETMASK, NULL, 0, |
297 | 16 | NULL, HFILL } |
298 | 16 | }, |
299 | 16 | { &hf_rip_next_hop, |
300 | 16 | { "Next Hop", "rip.next_hop", |
301 | 16 | FT_IPv4, BASE_NONE, NULL, 0, |
302 | 16 | "Next Hop router for this route", HFILL } |
303 | 16 | }, |
304 | 16 | { &hf_rip_metric, |
305 | 16 | { "Metric", "rip.metric", |
306 | 16 | FT_UINT16, BASE_DEC, NULL, 0, |
307 | 16 | "Metric for this route", HFILL } |
308 | 16 | }, |
309 | 16 | { &hf_rip_auth, |
310 | 16 | { "Authentication type", "rip.auth.type", |
311 | 16 | FT_UINT16, BASE_DEC, VALS(rip_auth_type), 0, |
312 | 16 | "Type of authentication", HFILL } |
313 | 16 | }, |
314 | 16 | { &hf_rip_auth_passwd, |
315 | 16 | { "Password", "rip.auth.passwd", |
316 | 16 | FT_STRING, BASE_NONE, NULL, 0, |
317 | 16 | "Authentication password", HFILL } |
318 | 16 | }, |
319 | 16 | { &hf_rip_family, |
320 | 16 | { "Address Family", "rip.family", |
321 | 16 | FT_UINT16, BASE_DEC, VALS(family_vals), 0, |
322 | 16 | NULL, HFILL } |
323 | 16 | }, |
324 | 16 | { &hf_rip_route_tag, |
325 | 16 | { "Route Tag", "rip.route_tag", |
326 | 16 | FT_UINT16, BASE_DEC, NULL, 0, |
327 | 16 | NULL, HFILL } |
328 | 16 | }, |
329 | 16 | { &hf_rip_zero_padding, |
330 | 16 | { "Zero adding", "rip.zero_padding", |
331 | 16 | FT_STRING, BASE_NONE, NULL, 0, |
332 | 16 | "Authentication password", HFILL } |
333 | 16 | }, |
334 | 16 | { &hf_rip_digest_offset, |
335 | 16 | { "Digest Offset", "rip.digest_offset", |
336 | 16 | FT_UINT16, BASE_DEC, NULL, 0, |
337 | 16 | NULL, HFILL } |
338 | 16 | }, |
339 | 16 | { &hf_rip_key_id, |
340 | 16 | { "Key ID", "rip.key_id", |
341 | 16 | FT_UINT8, BASE_DEC, NULL, 0, |
342 | 16 | NULL, HFILL } |
343 | 16 | }, |
344 | 16 | { &hf_rip_auth_data_len, |
345 | 16 | { "Auth Data Len", "rip.auth_data_len", |
346 | 16 | FT_UINT8, BASE_DEC, NULL, 0, |
347 | 16 | NULL, HFILL } |
348 | 16 | }, |
349 | 16 | { &hf_rip_auth_seq_num, |
350 | 16 | { "Seq num", "rip.seq_num", |
351 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
352 | 16 | NULL, HFILL } |
353 | 16 | }, |
354 | 16 | { &hf_rip_authentication_data, |
355 | 16 | { "Authentication Data", "rip.authentication_data", |
356 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
357 | 16 | NULL, HFILL } |
358 | 16 | }, |
359 | 16 | }; |
360 | | |
361 | 16 | static int *ett[] = { |
362 | 16 | &ett_rip, |
363 | 16 | &ett_rip_vec, |
364 | 16 | &ett_auth_vec, |
365 | 16 | }; |
366 | | |
367 | 16 | static ei_register_info ei[] = { |
368 | 16 | { &ei_rip_unknown_address_family, { "rip.unknown_address_family", PI_PROTOCOL, PI_WARN, "Unknown address family", EXPFILL }}, |
369 | 16 | }; |
370 | | |
371 | 16 | expert_module_t* expert_rip; |
372 | 16 | module_t *rip_module; |
373 | | |
374 | 16 | proto_rip = proto_register_protocol("Routing Information Protocol", "RIP", "rip"); |
375 | 16 | proto_register_field_array(proto_rip, hf, array_length(hf)); |
376 | 16 | proto_register_subtree_array(ett, array_length(ett)); |
377 | 16 | expert_rip = expert_register_protocol(proto_rip); |
378 | 16 | expert_register_field_array(expert_rip, ei, array_length(ei)); |
379 | | |
380 | 16 | rip_module = prefs_register_protocol(proto_rip, NULL); |
381 | | |
382 | 16 | prefs_register_bool_preference(rip_module, "display_routing_domain", "Display Routing Domain field", "Display the third and forth bytes of the RIPv2 header as the Routing Domain field (introduced in RFC 1388 [January 1993] and obsolete as of RFC 1723 [November 1994])", &pref_display_routing_domain); |
383 | | |
384 | 16 | rip_handle = register_dissector("rip", dissect_rip, proto_rip); |
385 | 16 | } |
386 | | |
387 | | void |
388 | | proto_reg_handoff_rip(void) |
389 | 16 | { |
390 | 16 | dissector_add_uint_with_preference("udp.port", UDP_PORT_RIP, rip_handle); |
391 | 16 | } |
392 | | |
393 | | /* |
394 | | * Editor modelines - https://www.wireshark.org/tools/modelines.html |
395 | | * |
396 | | * Local variables: |
397 | | * c-basic-offset: 4 |
398 | | * tab-width: 8 |
399 | | * indent-tabs-mode: nil |
400 | | * End: |
401 | | * |
402 | | * vi: set shiftwidth=4 tabstop=8 expandtab: |
403 | | * :indentSize=4:tabSize=8:noTabs=true: |
404 | | */ |