Coverage Report

Created: 2026-09-28 06:52

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wireshark/epan/dissectors/packet-rip.c
Line
Count
Source
1
/* packet-rip.c
2
 * Routines for RIPv1 and RIPv2 packet disassembly
3
 * RFC1058 (STD 34), RFC1388, RFC1723, RFC2453 (STD 56)
4
 * (c) Copyright Hannes R. Boehm <hannes@boehm.org>
5
 *
6
 * RFC2082 ( Keyed Message Digest Algorithm )
7
 *   Emanuele Caratti  <wiz@iol.it>
8
 *
9
 * Wireshark - Network traffic analyzer
10
 * By Gerald Combs <gerald@wireshark.org>
11
 * Copyright 1998 Gerald Combs
12
 *
13
 * SPDX-License-Identifier: GPL-2.0-or-later
14
 */
15
#include "config.h"
16
17
#include <epan/packet.h>
18
#include <epan/expert.h>
19
#include <epan/prefs.h>
20
#include <epan/to_str.h>
21
22
16
#define UDP_PORT_RIP    520
23
24
#define RIPv1   1
25
219
#define RIPv2   2
26
27
void proto_register_rip(void);
28
void proto_reg_handoff_rip(void);
29
30
static const value_string version_vals[] = {
31
    { RIPv1, "RIPv1" },
32
    { RIPv2, "RIPv2" },
33
    { 0, NULL }
34
};
35
36
static const value_string command_vals[] = {
37
    { 1, "Request" },
38
    { 2, "Response" },
39
    { 3, "Traceon" },
40
    { 4, "Traceoff" },
41
    { 5, "Vendor specific (Sun)" },
42
    { 0, NULL }
43
};
44
45
109
#define AFVAL_UNSPEC    0
46
9
#define AFVAL_IP        2
47
48
static const value_string family_vals[] = {
49
    { AFVAL_UNSPEC, "Unspecified" },
50
    { AFVAL_IP,     "IP" },
51
    { 0, NULL }
52
};
53
54
#define AUTH_IP_ROUTE           1
55
0
#define AUTH_PASSWORD           2
56
0
#define AUTH_KEYED_MSG_DIGEST   3
57
58
static const value_string rip_auth_type[] = {
59
    { AUTH_IP_ROUTE,         "IP Route" },
60
    { AUTH_PASSWORD,         "Simple Password" },
61
    { AUTH_KEYED_MSG_DIGEST, "Keyed Message Digest" },
62
    { 0, NULL }
63
};
64
65
209
#define RIP_HEADER_LENGTH 4
66
937
#define RIP_ENTRY_LENGTH 20
67
0
#define MD5_AUTH_DATA_LEN 16
68
69
static bool pref_display_routing_domain;
70
71
static dissector_handle_t rip_handle;
72
73
static int proto_rip;
74
75
static int hf_rip_auth;
76
static int hf_rip_auth_data_len;
77
static int hf_rip_auth_passwd;
78
static int hf_rip_auth_seq_num;
79
static int hf_rip_authentication_data;
80
static int hf_rip_command;
81
static int hf_rip_digest_offset;
82
static int hf_rip_family;
83
static int hf_rip_ip;
84
static int hf_rip_key_id;
85
static int hf_rip_metric;
86
static int hf_rip_netmask;
87
static int hf_rip_next_hop;
88
static int hf_rip_route_tag;
89
static int hf_rip_routing_domain;
90
static int hf_rip_version;
91
static int hf_rip_zero_padding;
92
93
static int ett_rip;
94
static int ett_rip_vec;
95
static int ett_auth_vec;
96
97
static expert_field ei_rip_unknown_address_family;
98
99
static void dissect_unspec_rip_vektor(tvbuff_t *tvb, int offset, uint8_t version,
100
    proto_tree *tree);
101
static void dissect_ip_rip_vektor(tvbuff_t *tvb, packet_info *pinfo, int offset, uint8_t version,
102
    proto_tree *tree);
103
static unsigned dissect_rip_authentication(tvbuff_t *tvb, packet_info* pinfo, int offset,
104
    proto_tree *tree);
105
106
static int
107
dissect_rip(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
108
46
{
109
46
    int         offset      = 0;
110
46
    proto_tree *rip_tree    = NULL;
111
46
    proto_item *ti;
112
46
    uint8_t     command;
113
46
    uint8_t     version;
114
46
    uint16_t    family;
115
46
    unsigned    trailer_len = 0;
116
46
    bool        is_md5_auth = false;
117
118
46
    col_set_str(pinfo->cinfo, COL_PROTOCOL, "RIP");
119
46
    col_clear(pinfo->cinfo, COL_INFO);
120
121
46
    command = tvb_get_uint8(tvb, 0);
122
46
    version = tvb_get_uint8(tvb, 1);
123
124
46
    col_set_str(pinfo->cinfo, COL_PROTOCOL,
125
46
                    val_to_str_const(version, version_vals, "RIP"));
126
46
    col_add_str(pinfo->cinfo, COL_INFO,
127
46
                    val_to_str(pinfo->pool, command, command_vals, "Unknown command (%u)"));
128
129
46
    ti = proto_tree_add_item(tree, proto_rip, tvb, 0, -1, ENC_NA);
130
46
    rip_tree = proto_item_add_subtree(ti, ett_rip);
131
132
46
    proto_tree_add_uint(rip_tree, hf_rip_command, tvb, 0, 1, command);
133
46
    proto_tree_add_uint(rip_tree, hf_rip_version, tvb, 1, 1, version);
134
46
    if (version == RIPv2 && pref_display_routing_domain == true)
135
0
        proto_tree_add_item(rip_tree, hf_rip_routing_domain, tvb, 2, 2,
136
0
                    ENC_BIG_ENDIAN);
137
138
    /* skip header */
139
46
    offset = RIP_HEADER_LENGTH;
140
141
    /* zero or more entries */
142
498
    while (tvb_reported_length_remaining(tvb, offset) > trailer_len ) {
143
492
        family = tvb_get_ntohs(tvb, offset);
144
492
        switch (family) {
145
109
        case AFVAL_UNSPEC: /* Unspecified */
146
            /*
147
                * There should be one entry in the request, and a metric
148
                * of infinity, meaning "show the entire routing table".
149
                */
150
109
            dissect_unspec_rip_vektor(tvb, offset, version, rip_tree);
151
109
            break;
152
9
        case AFVAL_IP: /* IP */
153
9
            dissect_ip_rip_vektor(tvb, pinfo, offset, version, rip_tree);
154
9
            break;
155
163
        case 0xFFFF:
156
163
            if( offset == RIP_HEADER_LENGTH ) {
157
12
                    trailer_len=dissect_rip_authentication(tvb, pinfo, offset, rip_tree);
158
12
                    is_md5_auth = true;
159
12
            break;
160
12
            }
161
151
            if(is_md5_auth && tvb_reported_length_remaining(tvb, offset) == 20)
162
1
                    break;
163
            /* Intentional fall through */ /* auth Entry MUST be the first! */
164
355
        default:
165
355
            proto_tree_add_expert_format(rip_tree, pinfo, &ei_rip_unknown_address_family, tvb, offset,
166
355
                            RIP_ENTRY_LENGTH, "Unknown address family %u", family);
167
355
            break;
168
492
        }
169
170
452
        offset += RIP_ENTRY_LENGTH;
171
452
    }
172
6
    return tvb_captured_length(tvb);
173
46
}
174
175
static void
176
dissect_unspec_rip_vektor(tvbuff_t *tvb, int offset, uint8_t version,
177
                      proto_tree *tree)
178
109
{
179
109
    proto_tree *rip_vektor_tree;
180
109
    uint32_t    metric;
181
182
109
    metric = tvb_get_ntohl(tvb, offset+16);
183
109
    rip_vektor_tree = proto_tree_add_subtree_format(tree, tvb, offset,
184
109
                             RIP_ENTRY_LENGTH, ett_rip_vec, NULL, "Address not specified, Metric: %u",
185
109
                             metric);
186
187
109
    proto_tree_add_item(rip_vektor_tree, hf_rip_family, tvb, offset, 2, ENC_BIG_ENDIAN);
188
109
    if (version == RIPv2) {
189
34
        proto_tree_add_item(rip_vektor_tree, hf_rip_route_tag, tvb, offset+2, 2,
190
34
                        ENC_BIG_ENDIAN);
191
34
        proto_tree_add_item(rip_vektor_tree, hf_rip_netmask, tvb, offset+8, 4,
192
34
                            ENC_BIG_ENDIAN);
193
34
        proto_tree_add_item(rip_vektor_tree, hf_rip_next_hop, tvb, offset+12, 4,
194
34
                            ENC_BIG_ENDIAN);
195
34
    }
196
109
    proto_tree_add_uint(rip_vektor_tree, hf_rip_metric, tvb,
197
109
                        offset+16, 4, metric);
198
109
}
199
200
static void
201
dissect_ip_rip_vektor(tvbuff_t *tvb, packet_info *pinfo, int offset, uint8_t version,
202
                      proto_tree *tree)
203
9
{
204
9
    proto_tree *rip_vektor_tree;
205
9
    uint32_t    metric;
206
207
9
    metric = tvb_get_ntohl(tvb, offset+16);
208
9
    rip_vektor_tree = proto_tree_add_subtree_format(tree, tvb, offset,
209
9
                             RIP_ENTRY_LENGTH, ett_rip_vec, NULL, "IP Address: %s, Metric: %u",
210
9
                             tvb_ip_to_str(pinfo->pool, tvb, offset+4), metric);
211
212
9
    proto_tree_add_item(rip_vektor_tree, hf_rip_family, tvb, offset, 2, ENC_BIG_ENDIAN);
213
9
    if (version == RIPv2) {
214
1
        proto_tree_add_item(rip_vektor_tree, hf_rip_route_tag, tvb, offset+2, 2,
215
1
                        ENC_BIG_ENDIAN);
216
1
    }
217
218
9
    proto_tree_add_item(rip_vektor_tree, hf_rip_ip, tvb, offset+4, 4, ENC_BIG_ENDIAN);
219
220
9
    if (version == RIPv2) {
221
1
        proto_tree_add_item(rip_vektor_tree, hf_rip_netmask, tvb, offset+8, 4,
222
1
                            ENC_BIG_ENDIAN);
223
1
        proto_tree_add_item(rip_vektor_tree, hf_rip_next_hop, tvb, offset+12, 4,
224
1
                            ENC_BIG_ENDIAN);
225
1
    }
226
9
    proto_tree_add_uint(rip_vektor_tree, hf_rip_metric, tvb,
227
9
                        offset+16, 4, metric);
228
9
}
229
230
static unsigned
231
dissect_rip_authentication(tvbuff_t *tvb, packet_info* pinfo, int offset, proto_tree *tree)
232
12
{
233
12
    proto_tree *rip_authentication_tree;
234
12
    uint16_t    authtype;
235
12
    uint32_t    digest_off, auth_data_len;
236
237
12
    auth_data_len = 0;
238
12
    authtype = tvb_get_ntohs(tvb, offset + 2);
239
240
12
    rip_authentication_tree = proto_tree_add_subtree_format(tree, tvb, offset, RIP_ENTRY_LENGTH,
241
12
                        ett_rip_vec, NULL, "Authentication: %s", val_to_str(pinfo->pool, authtype, rip_auth_type, "Unknown (%u)" ) );
242
243
12
    proto_tree_add_uint(rip_authentication_tree, hf_rip_auth, tvb, offset+2, 2,
244
12
                authtype);
245
246
12
    switch ( authtype ) {
247
248
0
    case AUTH_PASSWORD: /* Plain text password */
249
0
        proto_tree_add_item(rip_authentication_tree, hf_rip_auth_passwd,
250
0
                        tvb, offset+4, 16, ENC_ASCII);
251
0
        break;
252
253
0
    case AUTH_KEYED_MSG_DIGEST: /* Keyed MD5 rfc 2082 */
254
0
        digest_off = tvb_get_ntohs( tvb, offset+4 );
255
0
        proto_tree_add_item( rip_authentication_tree, hf_rip_digest_offset, tvb, offset+4, 2, ENC_BIG_ENDIAN);
256
0
        proto_tree_add_item( rip_authentication_tree, hf_rip_key_id, tvb, offset+6, 1, ENC_NA);
257
0
        auth_data_len = tvb_get_uint8( tvb, offset+7 );
258
0
        proto_tree_add_item( rip_authentication_tree, hf_rip_auth_data_len, tvb, offset+7, 1, ENC_NA);
259
0
        proto_tree_add_item( rip_authentication_tree, hf_rip_auth_seq_num, tvb, offset+8, 4, ENC_BIG_ENDIAN);
260
0
        proto_tree_add_item( rip_authentication_tree, hf_rip_zero_padding, tvb, offset+12, 8, ENC_ASCII);
261
0
        rip_authentication_tree = proto_tree_add_subtree( rip_authentication_tree, tvb, offset-4+digest_off,
262
0
                        MD5_AUTH_DATA_LEN+4, ett_auth_vec, NULL, "Authentication Data Trailer" );
263
0
        proto_tree_add_item( rip_authentication_tree, hf_rip_authentication_data, tvb, offset-4+digest_off+4,
264
0
                        MD5_AUTH_DATA_LEN, ENC_NA);
265
0
        break;
266
12
    }
267
12
    return auth_data_len;
268
12
}
269
270
void
271
proto_register_rip(void)
272
16
{
273
16
    static hf_register_info hf[] = {
274
16
        { &hf_rip_command,
275
16
            { "Command", "rip.command",
276
16
              FT_UINT8, BASE_DEC, VALS(command_vals), 0,
277
16
              "What type of RIP Command is this", HFILL }
278
16
        },
279
16
        { &hf_rip_version,
280
16
            { "Version", "rip.version",
281
16
              FT_UINT8, BASE_DEC, VALS(version_vals), 0,
282
16
              "Version of the RIP protocol", HFILL }
283
16
        },
284
16
        { &hf_rip_routing_domain,
285
16
            { "Routing Domain", "rip.routing_domain",
286
16
              FT_UINT16, BASE_DEC, NULL, 0,
287
16
              "RIPv2 Routing Domain", HFILL }
288
16
        },
289
16
        { &hf_rip_ip,
290
16
            { "IP Address", "rip.ip",
291
16
              FT_IPv4, BASE_NONE, NULL, 0,
292
16
              NULL, HFILL }
293
16
        },
294
16
        { &hf_rip_netmask,
295
16
            { "Netmask", "rip.netmask",
296
16
              FT_IPv4, BASE_NETMASK, NULL, 0,
297
16
              NULL, HFILL }
298
16
        },
299
16
        { &hf_rip_next_hop,
300
16
            { "Next Hop", "rip.next_hop",
301
16
              FT_IPv4, BASE_NONE, NULL, 0,
302
16
              "Next Hop router for this route", HFILL }
303
16
        },
304
16
        { &hf_rip_metric,
305
16
            { "Metric", "rip.metric",
306
16
              FT_UINT16, BASE_DEC, NULL, 0,
307
16
              "Metric for this route", HFILL }
308
16
        },
309
16
        { &hf_rip_auth,
310
16
            { "Authentication type", "rip.auth.type",
311
16
              FT_UINT16, BASE_DEC, VALS(rip_auth_type), 0,
312
16
              "Type of authentication", HFILL }
313
16
        },
314
16
        { &hf_rip_auth_passwd,
315
16
            { "Password", "rip.auth.passwd",
316
16
              FT_STRING, BASE_NONE, NULL, 0,
317
16
              "Authentication password", HFILL }
318
16
        },
319
16
        { &hf_rip_family,
320
16
            { "Address Family", "rip.family",
321
16
              FT_UINT16, BASE_DEC, VALS(family_vals), 0,
322
16
              NULL, HFILL }
323
16
        },
324
16
        { &hf_rip_route_tag,
325
16
            { "Route Tag", "rip.route_tag",
326
16
              FT_UINT16, BASE_DEC, NULL, 0,
327
16
              NULL, HFILL }
328
16
        },
329
16
        { &hf_rip_zero_padding,
330
16
            { "Zero adding", "rip.zero_padding",
331
16
              FT_STRING, BASE_NONE, NULL, 0,
332
16
              "Authentication password", HFILL }
333
16
        },
334
16
        { &hf_rip_digest_offset,
335
16
            { "Digest Offset", "rip.digest_offset",
336
16
              FT_UINT16, BASE_DEC, NULL, 0,
337
16
              NULL, HFILL }
338
16
        },
339
16
        { &hf_rip_key_id,
340
16
            { "Key ID", "rip.key_id",
341
16
              FT_UINT8, BASE_DEC, NULL, 0,
342
16
              NULL, HFILL }
343
16
        },
344
16
        { &hf_rip_auth_data_len,
345
16
            { "Auth Data Len", "rip.auth_data_len",
346
16
              FT_UINT8, BASE_DEC, NULL, 0,
347
16
              NULL, HFILL }
348
16
        },
349
16
        { &hf_rip_auth_seq_num,
350
16
            { "Seq num", "rip.seq_num",
351
16
              FT_UINT32, BASE_DEC, NULL, 0,
352
16
              NULL, HFILL }
353
16
        },
354
16
        { &hf_rip_authentication_data,
355
16
            { "Authentication Data", "rip.authentication_data",
356
16
              FT_BYTES, BASE_NONE, NULL, 0,
357
16
              NULL, HFILL }
358
16
        },
359
16
    };
360
361
16
    static int *ett[] = {
362
16
        &ett_rip,
363
16
        &ett_rip_vec,
364
16
        &ett_auth_vec,
365
16
    };
366
367
16
    static ei_register_info ei[] = {
368
16
        { &ei_rip_unknown_address_family, { "rip.unknown_address_family", PI_PROTOCOL, PI_WARN, "Unknown address family", EXPFILL }},
369
16
    };
370
371
16
    expert_module_t* expert_rip;
372
16
    module_t *rip_module;
373
374
16
    proto_rip = proto_register_protocol("Routing Information Protocol", "RIP", "rip");
375
16
    proto_register_field_array(proto_rip, hf, array_length(hf));
376
16
    proto_register_subtree_array(ett, array_length(ett));
377
16
    expert_rip = expert_register_protocol(proto_rip);
378
16
    expert_register_field_array(expert_rip, ei, array_length(ei));
379
380
16
    rip_module = prefs_register_protocol(proto_rip, NULL);
381
382
16
    prefs_register_bool_preference(rip_module, "display_routing_domain", "Display Routing Domain field", "Display the third and forth bytes of the RIPv2 header as the Routing Domain field (introduced in RFC 1388 [January 1993] and obsolete as of RFC 1723 [November 1994])", &pref_display_routing_domain);
383
384
16
    rip_handle = register_dissector("rip", dissect_rip, proto_rip);
385
16
}
386
387
void
388
proto_reg_handoff_rip(void)
389
16
{
390
16
    dissector_add_uint_with_preference("udp.port", UDP_PORT_RIP, rip_handle);
391
16
}
392
393
/*
394
 * Editor modelines  -  https://www.wireshark.org/tools/modelines.html
395
 *
396
 * Local variables:
397
 * c-basic-offset: 4
398
 * tab-width: 8
399
 * indent-tabs-mode: nil
400
 * End:
401
 *
402
 * vi: set shiftwidth=4 tabstop=8 expandtab:
403
 * :indentSize=4:tabSize=8:noTabs=true:
404
 */