strspn(char * hay, char *charlist)
Search for a "span" of string that contains entirely of characters in the charlist. spn stands for "span", probably.
strcspn(char* hay, char *charlist)
Search for a "complimentary span", i.e. a span that has no characters from the charlist.
strpbrk(char *hay, char *charlist)
"Pointer Break", search in hay for the first occurrance of any char from charlist.
http://computer-programming-forum.com/17-c-language/f794ce6a769ce761.htm
May 12, 2016
May 9, 2016
Example code of IPv4 and IPv6 using FREEBIND and IP_TRANSPARENT socket options to send packets using a non-local IP address
http://lists.openwall.net/netdev/2011/11/02/4
Use IP_PKTINFO to set the source IP address if you do not bind it to a particular address.
http://man7.org/linux/man-pages/man7/ip.7.html
Date: Tue, 1 Nov 2011 17:57:07 -0700
From: Maciej Żenczykowski <zenczykowski@...il.com>
To: Linux NetDev <netdev@...r.kernel.org>
Subject: On IP_FREEBIND and IPv6...
Short summary:
IPV6 + IP_FREEBIND doesn't work the way IPV4 + IP_FREEBIND does.
The native IPv6 bind path ignores 'freebind', but honours 'transparent'.
The native and dual-stack IPv4 bind paths honour both.
Does anyone know if this was a (security?) feature? Or is this just a bug?
I'll follow this up with a patch to support freebind for v6 bind (and
another one for v6 udp sendmsg).
Unless I hear some compelling story about why stuff is the way it is.
---
Please find test program source later on.
It basically does:
for test_mode in {native_ipv4, ipv4_on_ipv6_socket, native_ipv6} do:
create a udp socket
set IP_FREEBIND=1
set IP_TRANSPARENT=1 (will fail if not root, ignore failure)
bind socket to an IP address we don't own (one of: 1.2.3.4,
::FFFF:1.2.3.4, 2001:4860:DEAD:CAFE::6006:13) [fails without root for
native ipv6]
send a packet to another IP address (one of: 5.6.7.8,
::FFFF:5.6.7.8, 2001:4860:DEAD:BEEF::6006:13)
Running it generates:
$ ./test
setsockopt(TRANSPARENT=1): Operation not permitted [requires root]
setsockopt(TRANSPARENT=1): Operation not permitted [requires root]
setsockopt(TRANSPARENT=1): Operation not permitted [requires root]
bind(): Cannot assign requested address [native ipv6 bind does not
honour IP_FREEBIND, does honour IP{,V6}_TRANSPARENT]
$ sudo ./test
<no errors, everything succeeds, including bind native ipv6>
While running tcpdump shows:
# tcpdump -s 1555 -n -nn -i eth0 port 11111 or port 22222
>From ./a [ie. with IP_FREEBIND=1, IP_TRANSPARENT=0]:
IP 1.2.3.4.11111 > 5.6.7.8.22222: UDP, length 6 [native IPv4]
IP 1.2.3.4.11111 > 5.6.7.8.22222: UDP, length 6 [dual stack IPv4 on IPv6 socket]
IP6 [machines_true_ipv6_address].51912 >
2001:4860:dead:beef::6006:13.22222: UDP, length 6 [native IPv6, wrong
source since bind failed]
>From sudo ./a [ie. with IP_FREEBIND=1, IP_TRANSPARENT=1]:
IP 1.2.3.4.11111 > 5.6.7.8.22222: UDP, length 6 [native IPv4]
IP 1.2.3.4.11111 > 5.6.7.8.22222: UDP, length 6 [dual stack IPv4 on IPv6 socket]
IP6 2001:4860:dead:cafe::6006:13.vce >
2001:4860:dead:beef::6006:13.22222: UDP, length 6 [native IPv6]
This seems to prove that IP_TRANSPARENT requires root - this is as
expected, while IP_FREEBIND does not require root - again as expected.
However, as apparent above, we are successfully spoofing outgoing
source address on IPv4 UDP (whether native IPv4 or dual-stack IPv4
doesn't matter),
but there doesn't seem to be a way to do this with native IPv6.
ie. the native IPv6 bind path ignores the "freebind" setting, but does
honour the "transparent", while the IPv4 code paths honour both.
- Maciej
---
#include <string.h>
#include <stdio.h>
#include <sys/types.h>
#include <sys/socket.h>
#include <netinet/in.h>
#include <arpa/inet.h>
#define NATIVE_IPv4 0
#define DUAL_STACK 1
#define NATIVE_IPv6 2
int main(int argc, char const * argv[], char const * envp[]) {
struct sockaddr_in saddr4, daddr4;
struct sockaddr_in6 saddr6, daddr6;
int fd, rv, v, mode;
for (mode = 0; mode <= 2; ++mode) {
if (mode == NATIVE_IPv4) {
fd = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP);
if (fd < 0) perror("socket(IPv4 UDP)");
} else {
fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP);
if (fd < 0) perror("socket(IPv6 UDP)");
}
v = 1;
rv = setsockopt(fd, SOL_IP, IP_FREEBIND, &v, sizeof(v));
if (rv < 0) perror("setsockopt(FREEBIND=1)");
v = 1;
rv = setsockopt(fd, SOL_IP, IP_TRANSPARENT, &v, sizeof(v));
if (rv < 0) perror("setsockopt(TRANSPARENT=1)");
if (mode == NATIVE_IPv4) {
memset(&saddr4, 0, sizeof(saddr4));
memset(&daddr4, 0, sizeof(daddr4));
saddr4.sin_family = AF_INET;
daddr4.sin_family = AF_INET;
saddr4.sin_port = htons(11111);
daddr4.sin_port = htons(22222);
inet_pton(AF_INET, "1.2.3.4", &saddr4.sin_addr.s_addr);
inet_pton(AF_INET, "5.6.7.8", &daddr4.sin_addr.s_addr);
rv = bind(fd, (struct sockaddr const *)&saddr4, sizeof(saddr4));
if (rv < 0) perror("bind()");
rv = sendto(fd, "Hello!", 6, 0, (struct sockaddr const
*)&daddr4, sizeof(daddr4));
if (rv < 0) perror("write");
} else {
memset(&saddr6, 0, sizeof(saddr6));
memset(&daddr6, 0, sizeof(daddr6));
saddr6.sin6_family = AF_INET6;
daddr6.sin6_family = AF_INET6;
saddr6.sin6_port = htons(11111);
daddr6.sin6_port = htons(22222);
//saddr6.sin6_flowinfo = 0;
//daddr6.sin6_flowinfo = 0;
if (mode == DUAL_STACK) {
inet_pton(AF_INET6, "::FFFF:1.2.3.4", &saddr6.sin6_addr);
inet_pton(AF_INET6, "::FFFF:5.6.7.8", &daddr6.sin6_addr);
} else {
inet_pton(AF_INET6, "2001:4860:DEAD:CAFE::6006:0013",
&saddr6.sin6_addr);
inet_pton(AF_INET6, "2001:4860:DEAD:BEEF::6006:0013",
&daddr6.sin6_addr);
}
//saddr6.sin6_scope_id = 0;
//daddr6.sin6_scope_id = 0;
rv = bind(fd, (struct sockaddr const *)&saddr6, sizeof(saddr6));
if (rv < 0) perror("bind()");
rv = sendto(fd, "Hello!", 6, 0, (struct sockaddr const
*)&daddr6, sizeof(daddr6));
if (rv < 0) perror("write");
}
rv = close(fd);
if (rv < 0) perror("close");
}
return 0;
}
--
BELOW is my adapted version:
#include <string.h>
#include <stdio.h>
#include <sys/types.h>
#include <sys/socket.h>
#include <netinet/in.h>
//#include <linux/in.h>
#include <arpa/inet.h>
#define NATIVE_IPv4 0
#define DUAL_STACK 1
#define NATIVE_IPv6 2
#if 1
#if !defined(IP_FREEBIND)
#define IP_FREEBIND 15
#endif /* !IP_FREEBIND */
#if !defined(IP_TRANSPARENT)
#define IP_TRANSPARENT 19
#endif /* !IP_TRANSPARENT */
#endif
#define IPV6_TRANSPARENT 75
int main(int argc, char const * argv[], char const * envp[]) {
struct sockaddr_in saddr4, daddr4;
struct sockaddr_in6 saddr6, daddr6;
int fd, rv, v, mode;
for (mode = 2; mode <= 2; ++mode) {
if (mode == NATIVE_IPv4) {
fd = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP);
if (fd < 0) perror("socket(IPv4 UDP)");
} else {
fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP);
if (fd < 0) perror("socket(IPv6 UDP)");
}
v = 1;
rv = setsockopt(fd, SOL_IP, IP_FREEBIND, &v, sizeof(v));
if (rv < 0) perror("setsockopt(FREEBIND=1)");
if (mode == NATIVE_IPv4) {
v = 1;
rv = setsockopt(fd, SOL_IP, IP_TRANSPARENT, &v, sizeof(v));
if (rv < 0) perror("setsockopt(TRANSPARENT=1)");
}else{
v = 1;
rv = setsockopt(fd, SOL_IPV6, IPV6_TRANSPARENT, &v, sizeof(v));
if (rv < 0) perror("setsockopt ipv6 (TRANSPARENT=1)");
}
if (mode == NATIVE_IPv4) {
memset(&saddr4, 0, sizeof(saddr4));
memset(&daddr4, 0, sizeof(daddr4));
saddr4.sin_family = AF_INET;
daddr4.sin_family = AF_INET;
saddr4.sin_port = htons(11111);
daddr4.sin_port = htons(22222);
inet_pton(AF_INET, "1.2.3.4", &saddr4.sin_addr.s_addr);
inet_pton(AF_INET, "5.6.7.8", &daddr4.sin_addr.s_addr);
rv = bind(fd, (struct sockaddr const *)&saddr4, sizeof(saddr4));
if (rv < 0) perror("bind()");
rv = sendto(fd, "Hello!", 6, 0, (struct sockaddr const
*)&daddr4, sizeof(daddr4));
if (rv < 0) perror("write");
} else {
memset(&saddr6, 0, sizeof(saddr6));
memset(&daddr6, 0, sizeof(daddr6));
saddr6.sin6_family = AF_INET6;
daddr6.sin6_family = AF_INET6;
saddr6.sin6_port = htons(11111);
daddr6.sin6_port = htons(22222);
//saddr6.sin6_flowinfo = 0;
//daddr6.sin6_flowinfo = 0;
if (mode == DUAL_STACK) {
inet_pton(AF_INET6, "::FFFF:1.2.3.4", &saddr6.sin6_addr);
inet_pton(AF_INET6, "::FFFF:5.6.7.8", &daddr6.sin6_addr);
} else {
inet_pton(AF_INET6, "2001:4860:DEAD:CAFE::6006:0013",
&saddr6.sin6_addr);
inet_pton(AF_INET6, "2001:4860:DEAD:BEEF::6006:0013",
&daddr6.sin6_addr);
}
//saddr6.sin6_scope_id = 0;
//daddr6.sin6_scope_id = 0;
rv = bind(fd, (struct sockaddr const *)&saddr6, sizeof(saddr6));
if (rv < 0) perror("bind()");
rv = sendto(fd, "Hello!", 6, 0, (struct sockaddr const
*)&daddr6, sizeof(daddr6));
if (rv < 0) perror("write");
}
rv = close(fd);
if (rv < 0) perror("close");
}
return 0;
May 3, 2016
April 28, 2016
customize golang tls listener
How ListenAndServeTLS works in Golang
- it creates a struct of http.Server type, and then calls the server.ListenAndServe method
- http.server.ListenAndServeTLS
- clone server.TLSConfig
- if tls config has no certs OR a certfile is specified, load certs
- create a TLS socket that listens on the TCP port
- call server.Serve using that socket
- Server.serve
- Accept the new connection, returns http.conn
- http.conn.serve()
The customize this, one could write his own function like
this:
srv := &Server{Addr: addr, Handler:
handler}
addr := srv.Addr
if addr == "" {
addr = ":https"
}
config := cloneTLSConfig(srv.TLSConfig)
if config.NextProtos == nil {
config.NextProtos =
[]string{"http/1.1"}
}
if len(config.Certificates) == 0 ||
certFile != "" || keyFile != "" {
var err error
config.Certificates =
make([]tls.Certificate, 1)
config.Certificates[0], err =
tls.LoadX509KeyPair(certFile, keyFile)
if err != nil {
return err
}
}
ln, err := net.Listen("tcp",
addr)
if err != nil {
return err
}
tlsListener :=
tls.NewListener(tcpKeepAliveListener{ln.(*net.TCPListener)}, config)
return srv.Serve(tlsListener)
April 22, 2016
ipset netlink data structure
header:
\x4c\x00 \x00\x00 total length
\x09\x06 type=09 CMD_ADD \x05\x02 flags:0x0205 request/ack/return-all-matching
\xbb\x83\x1a\x57 seq
\x00\x00\x00\x00 port id
extra header
\x02\x00\x00\x00
payload, in the form of Leng-Type-Value
(len and type are 2 bytes, len includes itself and type. 0 Padded to 4-byte alignment)
Type flags:
0x80: NEST structure
0x40: Network Order
\x05\x00 \x01\x00 \x06 \x00\x00\x00 PROTOCOL=6
\x0a\x00 \x02\x00 \x70\x61\x69\x72\x31\x00\x00\x00 SETNAME=pair1
\x24\x00 \x07\x80 IPSET_ATTR_DATA
\x0c\x00 \x01\x80\ IPSET_ATTR_IP
x08\x00\x01\x40\x02\x02\x02\x02 IPV4 2.2.2.2
\x0c\x00\x14\x80 IPSET_ATTR_IP2
\x08\x00\x01\x40 \x04\x04\x04\x04 IP 4.4.4.4
\x08\x00\x09\x40 \x00\x00\x00\x00 IPSTE_ATTR_LINENO 0, network order
== update on 12/13/2018
enum ipset_cmd {
IPSET_CMD_NONE,
IPSET_CMD_PROTOCOL, /* 1: Return protocol version */
IPSET_CMD_CREATE, /* 2: Create a new (empty) set */
IPSET_CMD_DESTROY, /* 3: Destroy a (empty) set */
IPSET_CMD_FLUSH, /* 4: Remove all elements from a set */
IPSET_CMD_RENAME, /* 5: Rename a set */
IPSET_CMD_SWAP, /* 6: Swap two sets */
IPSET_CMD_LIST, /* 7: List sets */
IPSET_CMD_SAVE, /* 8: Save sets */
IPSET_CMD_ADD, /* 9: Add an element to a set */
IPSET_CMD_DEL, /* 10: Delete an element from a set */
IPSET_CMD_TEST, /* 11: Test an element in a set */
IPSET_CMD_HEADER, /* 12: Get set header data only */
IPSET_CMD_TYPE, /* 13: Get set type */
IPSET_MSG_MAX, /* Netlink message commands */
/* Commands in userspace: */
IPSET_CMD_RESTORE = IPSET_MSG_MAX, /* 14: Enter restore mode */
IPSET_CMD_HELP, /* 15: Get help */
IPSET_CMD_VERSION, /* 16: Get program version */
IPSET_CMD_QUIT, /* 17: Quit from interactive mode */
IPSET_CMD_MAX,
IPSET_CMD_COMMIT = IPSET_CMD_MAX, /* 18: Commit buffered commands */
};
command level attributes:
IPSET_ATTR_PROTOCOL, /* 1: Protocol version */
IPSET_ATTR_SETNAME, /* 2: Name of the set */
IPSET_ATTR_TYPENAME, /* 3: Typename */
IPSET_ATTR_SETNAME2 = IPSET_ATTR_TYPENAME, /* Setname at rename/swap */
IPSET_ATTR_REVISION, /* 4: Settype revision */
IPSET_ATTR_FAMILY, /* 5: Settype family */
IPSET_ATTR_FLAGS, /* 6: Flags at command level */
IPSET_ATTR_DATA, /* 7: Nested attributes */
IPSET_ATTR_ADT, /* 8: Multiple data containers */
IPSET_ATTR_LINENO, /* 9: Restore lineno */
IPSET_ATTR_PROTOCOL_MIN, /* 10: Minimal supported version number */
Nested attributes:
/* CADT specific attributes */
IPSET_ATTR_IP = IPSET_ATTR_UNSPEC + 1,
IPSET_ATTR_IP_FROM = IPSET_ATTR_IP,
IPSET_ATTR_IP_TO, /* 2 */
IPSET_ATTR_CIDR, /* 3 */
IPSET_ATTR_PORT, /* 4 */
IPSET_ATTR_PORT_FROM = IPSET_ATTR_PORT,
IPSET_ATTR_PORT_TO, /* 5 */
IPSET_ATTR_TIMEOUT, /* 6 */
IPSET_ATTR_PROTO, /* 7 */
IPSET_ATTR_CADT_FLAGS, /* 8 */
IPSET_ATTR_CADT_LINENO = IPSET_ATTR_LINENO, /* 9 */
/* Reserve empty slots */
IPSET_ATTR_CADT_MAX = 16, 0x10
/* Create-only specific attributes */
IPSET_ATTR_GC, //0x11
IPSET_ATTR_HASHSIZE, //0x12
IPSET_ATTR_MAXELEM, //0x13
IPSET_ATTR_NETMASK, //0x14
IPSET_ATTR_PROBES, //0x15
IPSET_ATTR_RESIZE, //0x16
IPSET_ATTR_SIZE, //0x17
/* Kernel-only */
IPSET_ATTR_ELEMENTS,
IPSET_ATTR_REFERENCES,
IPSET_ATTR_MEMSIZE,
__IPSET_ATTR_CREATE_MAX,
set type family list:
NFPROTO_UNSPEC = 0, //can be used to include both v4 and v6
NFPROTO_IPV4 = 2,
NFPROTO_ARP = 3,
NFPROTO_BRIDGE = 7,
NFPROTO_IPV6 = 10,
NFPROTO_DECNET = 12,
#define NLA_F_NESTED (1 << 15)
#define NLA_F_NET_BYTEORDER (1 << 14)
* strace version 4.23 and upper parses netlink messages. However, the parsing cannot seem to be disabled. You will need the lower version to output hex instead of parsing it.
=== cmd: ipset create filtered hash:ip,port,ip timeout 60
check type is supported?
sendto(3, {{len=56, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_TYPE, flags=NLM_F_REQUEST, seq=1544742655, pid=0}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0),
[{{nla_len=5, nla_type=0x1}, "\x06"}, protocol version
{{nla_len=20, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00"}, type name
{{nla_len=5, nla_type=0x5}, "\x02"}, type family, 2 is ipv4
]}, 56, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 56
recvmsg(3, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base={{len=72, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_TYPE, flags=0, seq=1544742655, pid=23011}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0), [{{nla_len=5, nla_type=NFNETLINK_V1}, "\x06"}, {{nla_len=20, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00"}, {{nla_len=5, nla_type=0x5}, "\x02"}, {{nla_len=5, nla_type=0x4}, "\x05"}, {{nla_len=5, nla_type=0xa}, "\x00"}]}, iov_len=256}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 72
sendto(3, {{len=92, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_CREATE, flags=NLM_F_REQUEST|NLM_F_ACK|0x600, seq=1544742656, pid=0}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0), [
{{nla_len=5, nla_type=NFNETLINK_V1}, "\x06"},
{{nla_len=13, nla_type=0x2}, "\x66\x69\x6c\x74\x65\x72\x65\x64\x00"}, set name "filterd"
{{nla_len=20, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00"}, "hash:ip,port,ip"
{{nla_len=5, nla_type=0x4}, "\x05"}, revision is 5? seems wrong
{{nla_len=5, nla_type=0x5}, "\x02"}, ipv4
{{nla_len=12, nla_type=NLA_F_NESTED|0x7}, "\x08\x00\x06\x40\x00\x00\x00\x3c"} len=8, type=6 (timeout), net-order, 60s
]}, 92, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 92
recvmsg(3, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base={{len=36, type=NLMSG_ERROR, flags=0, seq=1544742656, pid=23011}, {error=0, msg={len=92, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_CREATE, flags=NLM_F_REQUEST|NLM_F_ACK|0x600, seq=1544742656, pid=0}}}, iov_len=4096}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 36
=== cmd: ipset create filtered1 hash:ip,port,ip timeout 60
sendto(3, "\x38\x00\x00\x00\x0d\x06\x01\x00\x22\xe7\x12\x5c\x00\x00\x00\x00\x02\x00\x00\x00\x05\x00\x01\x00\x06\x00\x00\x00\x14\x00\x03\x00\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00\x05\x00\x05\x00\x02\x00\x00\x00", 56, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 56
recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\x48\x00\x00\x00\x0d\x06\x00\x00\x22\xe7\x12\x5c\x3c\x5b\x00\x00\x02\x00\x00\x00\x05\x00\x01\x00\x06\x00\x00\x00\x14\x00\x03\x00\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00\x05\x00\x05\x00\x02\x00\x00\x00\x05\x00\x04\x00\x05\x00\x00\x00\x05\x00\x0a\x00\x00\x00\x00\x00", 256}], msg_controllen=0, msg_flags=0}, 0) = 72
sendto(3, "\x5c\x00\x00\x00\x02\x06\x05\x06\x23\xe7\x12\x5c\x00\x00\x00\x00\x02\x00\x00\x00\x05\x00\x01\x00\x06\x00\x00\x00\x0e\x00\x02\x00\x66\x69\x6c\x74\x65\x72\x65\x64\x31\x00\x00\x00\x14\x00\x03\x00\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00\x05\x00\x04\x00\x05\x00\x00\x00\x05\x00\x05\x00\x02\x00\x00\x00\x0c\x00\x07\x80\x08\x00\x06\x40\x00\x00\x00\x3c", 92, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 92
decoded message:
\x5c\x00\x00\x00 length
\x02\x06 , 0x0602: 0x06 is NFNL_SUBSYS_IPSET, 0x02 is IPSET_CMD_CREATE
#define NFNL_SUBSYS_NONE 0
#define NFNL_SUBSYS_CTNETLINK 1
#define NFNL_SUBSYS_CTNETLINK_EXP 2
#define NFNL_SUBSYS_QUEUE 3
#define NFNL_SUBSYS_ULOG 4
#define NFNL_SUBSYS_OSF 5
#define NFNL_SUBSYS_IPSET 6
#define NFNL_SUBSYS_ACCT 7
#define NFNL_SUBSYS_CTNETLINK_TIMEOUT 8
#define NFNL_SUBSYS_CTHELPER 9
#define NFNL_SUBSYS_COUNT 10
\x05\x06, NLM flags: 0x0605: create | excl | ack |request
/* Flags values */
#define NLM_F_REQUEST 1 /* It is request message. */
#define NLM_F_MULTI 2 /* Multipart message, terminated by NLMSG_DONE */
#define NLM_F_ACK 4 /* Reply with ack, with zero or error code */
#define NLM_F_ECHO 8 /* Echo this request */
#define NLM_F_DUMP_INTR 16 /* Dump was inconsistent due to sequence change */
/* Modifiers to GET request */
#define NLM_F_ROOT 0x100 /* specify tree root */
#define NLM_F_MATCH 0x200 /* return all matching */
#define NLM_F_ATOMIC 0x400 /* atomic GET */
#define NLM_F_DUMP (NLM_F_ROOT|NLM_F_MATCH)
/* Modifiers to NEW request */
#define NLM_F_REPLACE 0x100 /* Override existing */
#define NLM_F_EXCL 0x200 /* Do not touch, if it exists */
#define NLM_F_CREATE 0x400 /* Create, if it does not exist */
#define NLM_F_APPEND 0x800 /* Add to end of list */
\x23\xe7\x12\x5c :seq number
\x00\x00\x00\x00 : port id
\x02\x00\x00\x00 : extra header
\x05\x00 \x01\x00\ x06 length is 5, type is 1, value is 6
\x00\x00\x00, padded to multipe of 4 bytes
\x0e\x00 \x02\x00 \x66\x69\x6c\x74 \x65\x72\x65\x64 \x31\x00\x00\x00, length is 14, type is 2,i.e. set name, name is "filtered1"
\x14\x00 \x03\x00 \x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00
\x05\x00\x04\x00\x05\x00\x00\x00: revision 5
\x05\x00\x05\x00\x02\x00\x00\x00: family 2
\x0c\x00\x07\x80 \x08\x00\x06\x40\x00\x00\x00\x3c, nested attributes, timeout value, networker order of 0x3c
recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\x24\x00\x00\x00\x02\x00\x00\x00\x23\xe7\x12\x5c\x3c\x5b\x00\x00\x00\x00\x00\x00\x5c\x00\x00\x00\x02\x06\x05\x06\x23\xe7\x12\x5c\x00\x00\x00\x00", 4096}], msg_controllen=0, msg_flags=0}, 0) = 36
==cmd: ipset create torlistv6 hash:ip family inet6 hashsize 2048 maxelem 65536
sendto(3, {{len=48, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_TYPE, flags=NLM_F_REQUEST, seq=1544745557, pid=0}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0), [{{nla_len=5, nla_type=NFNETLINK_V1}, "\x06"}, {{nla_len=12, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x00"}, {{nla_len=5, nla_type=0x5}, "\x02"}]}, 48, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 48
recvmsg(3, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base={{len=64, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_TYPE, flags=0, seq=1544745557, pid=19683}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0), [
{{nla_len=5, nla_type=NFNETLINK_V1}, "\x06"},
{{nla_len=12, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x00"},
{{nla_len=5, nla_type=0x5}, "\x02"},
{{nla_len=5, nla_type=0x4}, "\x04"},
{{nla_len=5, nla_type=0xa}, "\x00"}]}, iov_len=256}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 64
sendto(3, {{len=92, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_CREATE, flags=NLM_F_REQUEST|NLM_F_ACK|0x600, seq=1544745558, pid=0}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0), [
{{nla_len=5, nla_type=NFNETLINK_V1}, "\x06"},
{{nla_len=14, nla_type=0x2}, "\x74\x6f\x72\x6c\x69\x73\x74\x76\x36\x00"},
{{nla_len=12, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x00"},
{{nla_len=5, nla_type=0x4}, "\x04"},
{{nla_len=5, nla_type=0x5}, "\x0a"},
{{nla_len=20, nla_type=NLA_F_NESTED|0x7}, "\x08\x00\x12\x40\x00\x00\x08\x00\x08\x00\x13\x40\x00\x01\x00\x00"}
\x08\x00\x12\x40 \x00\x00\x08\x00, hashsize 0x800
\x08\x00\x13\x40 \x00\x01\x00\x00, maxelem 0x10000
]}, 92, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 92
recvmsg(3, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base={{len=36, type=NLMSG_ERROR, flags=0, seq=1544745558, pid=19683}, {error=0, msg={len=92, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_CREATE, flags=NLM_F_REQUEST|NLM_F_ACK|0x600, seq=1544745558, pid=0}}}, iov_len=4096}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 36
\x4c\x00 \x00\x00 total length
\x09\x06 type=09 CMD_ADD \x05\x02 flags:0x0205 request/ack/return-all-matching
\xbb\x83\x1a\x57 seq
\x00\x00\x00\x00 port id
extra header
\x02\x00\x00\x00
payload, in the form of Leng-Type-Value
(len and type are 2 bytes, len includes itself and type. 0 Padded to 4-byte alignment)
Type flags:
0x80: NEST structure
0x40: Network Order
\x05\x00 \x01\x00 \x06 \x00\x00\x00 PROTOCOL=6
\x0a\x00 \x02\x00 \x70\x61\x69\x72\x31\x00\x00\x00 SETNAME=pair1
\x24\x00 \x07\x80 IPSET_ATTR_DATA
\x0c\x00 \x01\x80\ IPSET_ATTR_IP
x08\x00\x01\x40\x02\x02\x02\x02 IPV4 2.2.2.2
\x0c\x00\x14\x80 IPSET_ATTR_IP2
\x08\x00\x01\x40 \x04\x04\x04\x04 IP 4.4.4.4
\x08\x00\x09\x40 \x00\x00\x00\x00 IPSTE_ATTR_LINENO 0, network order
== update on 12/13/2018
enum ipset_cmd {
IPSET_CMD_NONE,
IPSET_CMD_PROTOCOL, /* 1: Return protocol version */
IPSET_CMD_CREATE, /* 2: Create a new (empty) set */
IPSET_CMD_DESTROY, /* 3: Destroy a (empty) set */
IPSET_CMD_FLUSH, /* 4: Remove all elements from a set */
IPSET_CMD_RENAME, /* 5: Rename a set */
IPSET_CMD_SWAP, /* 6: Swap two sets */
IPSET_CMD_LIST, /* 7: List sets */
IPSET_CMD_SAVE, /* 8: Save sets */
IPSET_CMD_ADD, /* 9: Add an element to a set */
IPSET_CMD_DEL, /* 10: Delete an element from a set */
IPSET_CMD_TEST, /* 11: Test an element in a set */
IPSET_CMD_HEADER, /* 12: Get set header data only */
IPSET_CMD_TYPE, /* 13: Get set type */
IPSET_MSG_MAX, /* Netlink message commands */
/* Commands in userspace: */
IPSET_CMD_RESTORE = IPSET_MSG_MAX, /* 14: Enter restore mode */
IPSET_CMD_HELP, /* 15: Get help */
IPSET_CMD_VERSION, /* 16: Get program version */
IPSET_CMD_QUIT, /* 17: Quit from interactive mode */
IPSET_CMD_MAX,
IPSET_CMD_COMMIT = IPSET_CMD_MAX, /* 18: Commit buffered commands */
};
command level attributes:
IPSET_ATTR_PROTOCOL, /* 1: Protocol version */
IPSET_ATTR_SETNAME, /* 2: Name of the set */
IPSET_ATTR_TYPENAME, /* 3: Typename */
IPSET_ATTR_SETNAME2 = IPSET_ATTR_TYPENAME, /* Setname at rename/swap */
IPSET_ATTR_REVISION, /* 4: Settype revision */
IPSET_ATTR_FAMILY, /* 5: Settype family */
IPSET_ATTR_FLAGS, /* 6: Flags at command level */
IPSET_ATTR_DATA, /* 7: Nested attributes */
IPSET_ATTR_ADT, /* 8: Multiple data containers */
IPSET_ATTR_LINENO, /* 9: Restore lineno */
IPSET_ATTR_PROTOCOL_MIN, /* 10: Minimal supported version number */
Nested attributes:
/* CADT specific attributes */
IPSET_ATTR_IP = IPSET_ATTR_UNSPEC + 1,
IPSET_ATTR_IP_FROM = IPSET_ATTR_IP,
IPSET_ATTR_IP_TO, /* 2 */
IPSET_ATTR_CIDR, /* 3 */
IPSET_ATTR_PORT, /* 4 */
IPSET_ATTR_PORT_FROM = IPSET_ATTR_PORT,
IPSET_ATTR_PORT_TO, /* 5 */
IPSET_ATTR_TIMEOUT, /* 6 */
IPSET_ATTR_PROTO, /* 7 */
IPSET_ATTR_CADT_FLAGS, /* 8 */
IPSET_ATTR_CADT_LINENO = IPSET_ATTR_LINENO, /* 9 */
/* Reserve empty slots */
IPSET_ATTR_CADT_MAX = 16, 0x10
/* Create-only specific attributes */
IPSET_ATTR_GC, //0x11
IPSET_ATTR_HASHSIZE, //0x12
IPSET_ATTR_MAXELEM, //0x13
IPSET_ATTR_NETMASK, //0x14
IPSET_ATTR_PROBES, //0x15
IPSET_ATTR_RESIZE, //0x16
IPSET_ATTR_SIZE, //0x17
/* Kernel-only */
IPSET_ATTR_ELEMENTS,
IPSET_ATTR_REFERENCES,
IPSET_ATTR_MEMSIZE,
__IPSET_ATTR_CREATE_MAX,
set type family list:
NFPROTO_UNSPEC = 0, //can be used to include both v4 and v6
NFPROTO_IPV4 = 2,
NFPROTO_ARP = 3,
NFPROTO_BRIDGE = 7,
NFPROTO_IPV6 = 10,
NFPROTO_DECNET = 12,
#define NLA_F_NESTED (1 << 15)
#define NLA_F_NET_BYTEORDER (1 << 14)
* strace version 4.23 and upper parses netlink messages. However, the parsing cannot seem to be disabled. You will need the lower version to output hex instead of parsing it.
=== cmd: ipset create filtered hash:ip,port,ip timeout 60
check type is supported?
sendto(3, {{len=56, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_TYPE, flags=NLM_F_REQUEST, seq=1544742655, pid=0}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0),
[{{nla_len=5, nla_type=0x1}, "\x06"}, protocol version
{{nla_len=20, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00"}, type name
{{nla_len=5, nla_type=0x5}, "\x02"}, type family, 2 is ipv4
]}, 56, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 56
recvmsg(3, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base={{len=72, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_TYPE, flags=0, seq=1544742655, pid=23011}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0), [{{nla_len=5, nla_type=NFNETLINK_V1}, "\x06"}, {{nla_len=20, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00"}, {{nla_len=5, nla_type=0x5}, "\x02"}, {{nla_len=5, nla_type=0x4}, "\x05"}, {{nla_len=5, nla_type=0xa}, "\x00"}]}, iov_len=256}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 72
sendto(3, {{len=92, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_CREATE, flags=NLM_F_REQUEST|NLM_F_ACK|0x600, seq=1544742656, pid=0}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0), [
{{nla_len=5, nla_type=NFNETLINK_V1}, "\x06"},
{{nla_len=13, nla_type=0x2}, "\x66\x69\x6c\x74\x65\x72\x65\x64\x00"}, set name "filterd"
{{nla_len=20, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00"}, "hash:ip,port,ip"
{{nla_len=5, nla_type=0x4}, "\x05"}, revision is 5? seems wrong
{{nla_len=5, nla_type=0x5}, "\x02"}, ipv4
{{nla_len=12, nla_type=NLA_F_NESTED|0x7}, "\x08\x00\x06\x40\x00\x00\x00\x3c"} len=8, type=6 (timeout), net-order, 60s
]}, 92, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 92
recvmsg(3, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base={{len=36, type=NLMSG_ERROR, flags=0, seq=1544742656, pid=23011}, {error=0, msg={len=92, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_CREATE, flags=NLM_F_REQUEST|NLM_F_ACK|0x600, seq=1544742656, pid=0}}}, iov_len=4096}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 36
=== cmd: ipset create filtered1 hash:ip,port,ip timeout 60
sendto(3, "\x38\x00\x00\x00\x0d\x06\x01\x00\x22\xe7\x12\x5c\x00\x00\x00\x00\x02\x00\x00\x00\x05\x00\x01\x00\x06\x00\x00\x00\x14\x00\x03\x00\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00\x05\x00\x05\x00\x02\x00\x00\x00", 56, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 56
recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\x48\x00\x00\x00\x0d\x06\x00\x00\x22\xe7\x12\x5c\x3c\x5b\x00\x00\x02\x00\x00\x00\x05\x00\x01\x00\x06\x00\x00\x00\x14\x00\x03\x00\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00\x05\x00\x05\x00\x02\x00\x00\x00\x05\x00\x04\x00\x05\x00\x00\x00\x05\x00\x0a\x00\x00\x00\x00\x00", 256}], msg_controllen=0, msg_flags=0}, 0) = 72
sendto(3, "\x5c\x00\x00\x00\x02\x06\x05\x06\x23\xe7\x12\x5c\x00\x00\x00\x00\x02\x00\x00\x00\x05\x00\x01\x00\x06\x00\x00\x00\x0e\x00\x02\x00\x66\x69\x6c\x74\x65\x72\x65\x64\x31\x00\x00\x00\x14\x00\x03\x00\x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00\x05\x00\x04\x00\x05\x00\x00\x00\x05\x00\x05\x00\x02\x00\x00\x00\x0c\x00\x07\x80\x08\x00\x06\x40\x00\x00\x00\x3c", 92, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 92
decoded message:
\x5c\x00\x00\x00 length
\x02\x06 , 0x0602: 0x06 is NFNL_SUBSYS_IPSET, 0x02 is IPSET_CMD_CREATE
#define NFNL_SUBSYS_NONE 0
#define NFNL_SUBSYS_CTNETLINK 1
#define NFNL_SUBSYS_CTNETLINK_EXP 2
#define NFNL_SUBSYS_QUEUE 3
#define NFNL_SUBSYS_ULOG 4
#define NFNL_SUBSYS_OSF 5
#define NFNL_SUBSYS_IPSET 6
#define NFNL_SUBSYS_ACCT 7
#define NFNL_SUBSYS_CTNETLINK_TIMEOUT 8
#define NFNL_SUBSYS_CTHELPER 9
#define NFNL_SUBSYS_COUNT 10
\x05\x06, NLM flags: 0x0605: create | excl | ack |request
/* Flags values */
#define NLM_F_REQUEST 1 /* It is request message. */
#define NLM_F_MULTI 2 /* Multipart message, terminated by NLMSG_DONE */
#define NLM_F_ACK 4 /* Reply with ack, with zero or error code */
#define NLM_F_ECHO 8 /* Echo this request */
#define NLM_F_DUMP_INTR 16 /* Dump was inconsistent due to sequence change */
/* Modifiers to GET request */
#define NLM_F_ROOT 0x100 /* specify tree root */
#define NLM_F_MATCH 0x200 /* return all matching */
#define NLM_F_ATOMIC 0x400 /* atomic GET */
#define NLM_F_DUMP (NLM_F_ROOT|NLM_F_MATCH)
/* Modifiers to NEW request */
#define NLM_F_REPLACE 0x100 /* Override existing */
#define NLM_F_EXCL 0x200 /* Do not touch, if it exists */
#define NLM_F_CREATE 0x400 /* Create, if it does not exist */
#define NLM_F_APPEND 0x800 /* Add to end of list */
\x23\xe7\x12\x5c :seq number
\x00\x00\x00\x00 : port id
\x02\x00\x00\x00 : extra header
\x05\x00 \x01\x00\ x06 length is 5, type is 1, value is 6
\x00\x00\x00, padded to multipe of 4 bytes
\x0e\x00 \x02\x00 \x66\x69\x6c\x74 \x65\x72\x65\x64 \x31\x00\x00\x00, length is 14, type is 2,i.e. set name, name is "filtered1"
\x14\x00 \x03\x00 \x68\x61\x73\x68\x3a\x69\x70\x2c\x70\x6f\x72\x74\x2c\x69\x70\x00
\x05\x00\x04\x00\x05\x00\x00\x00: revision 5
\x05\x00\x05\x00\x02\x00\x00\x00: family 2
\x0c\x00\x07\x80 \x08\x00\x06\x40\x00\x00\x00\x3c, nested attributes, timeout value, networker order of 0x3c
recvmsg(3, {msg_name(12)={sa_family=AF_NETLINK, pid=0, groups=00000000}, msg_iov(1)=[{"\x24\x00\x00\x00\x02\x00\x00\x00\x23\xe7\x12\x5c\x3c\x5b\x00\x00\x00\x00\x00\x00\x5c\x00\x00\x00\x02\x06\x05\x06\x23\xe7\x12\x5c\x00\x00\x00\x00", 4096}], msg_controllen=0, msg_flags=0}, 0) = 36
==cmd: ipset create torlistv6 hash:ip family inet6 hashsize 2048 maxelem 65536
sendto(3, {{len=48, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_TYPE, flags=NLM_F_REQUEST, seq=1544745557, pid=0}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0), [{{nla_len=5, nla_type=NFNETLINK_V1}, "\x06"}, {{nla_len=12, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x00"}, {{nla_len=5, nla_type=0x5}, "\x02"}]}, 48, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 48
recvmsg(3, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base={{len=64, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_TYPE, flags=0, seq=1544745557, pid=19683}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0), [
{{nla_len=5, nla_type=NFNETLINK_V1}, "\x06"},
{{nla_len=12, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x00"},
{{nla_len=5, nla_type=0x5}, "\x02"},
{{nla_len=5, nla_type=0x4}, "\x04"},
{{nla_len=5, nla_type=0xa}, "\x00"}]}, iov_len=256}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 64
sendto(3, {{len=92, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_CREATE, flags=NLM_F_REQUEST|NLM_F_ACK|0x600, seq=1544745558, pid=0}, {nfgen_family=AF_INET, version=NFNETLINK_V0, res_id=htons(0), [
{{nla_len=5, nla_type=NFNETLINK_V1}, "\x06"},
{{nla_len=14, nla_type=0x2}, "\x74\x6f\x72\x6c\x69\x73\x74\x76\x36\x00"},
{{nla_len=12, nla_type=0x3}, "\x68\x61\x73\x68\x3a\x69\x70\x00"},
{{nla_len=5, nla_type=0x4}, "\x04"},
{{nla_len=5, nla_type=0x5}, "\x0a"},
{{nla_len=20, nla_type=NLA_F_NESTED|0x7}, "\x08\x00\x12\x40\x00\x00\x08\x00\x08\x00\x13\x40\x00\x01\x00\x00"}
\x08\x00\x12\x40 \x00\x00\x08\x00, hashsize 0x800
\x08\x00\x13\x40 \x00\x01\x00\x00, maxelem 0x10000
]}, 92, 0, {sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, 12) = 92
recvmsg(3, {msg_name={sa_family=AF_NETLINK, nl_pid=0, nl_groups=00000000}, msg_namelen=12, msg_iov=[{iov_base={{len=36, type=NLMSG_ERROR, flags=0, seq=1544745558, pid=19683}, {error=0, msg={len=92, type=NFNL_SUBSYS_IPSET<<8|IPSET_CMD_CREATE, flags=NLM_F_REQUEST|NLM_F_ACK|0x600, seq=1544745558, pid=0}}}, iov_len=4096}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 36
April 7, 2016
curl test api
In curl, use "--data-urlencode" to encode data
use "-G" to send data in "GET" instead of "POST".
curl -G "https://myserver.com:1234/msg?msgtype=PUSH" --data-urlencode "msg=hello how are you"
use "-G" to send data in "GET" instead of "POST".
curl -G "https://myserver.com:1234/msg?msgtype=PUSH" --data-urlencode "msg=hello how are you"
April 6, 2016
March 23, 2016
no trusted RSA public key found, strongswan, IKEv2
My setup:
Linux running strongswan server, 5.3, latest version.
Client is iPhone iOS 9.2
Trying to setup IKEv2 with certificate authentication. MS-CHAPv2 authentication works fine.
Issue: no trusted RSA public key found
After spending hours on the Internet, combing through the strongswan forums and even looking at the source code, I was able to finally find out the issue:
The issue was with the client certificate I generated for iPhone.
The certificate did not have a SAN (Subject Alternative Name). I never knew it was REQUIRED to have one. This is how the check on the server goes:
1. Server needs to make sure a certificate is received from the client.
2. It then does the following checks:
- cert is signed with a known CA.
- cert date is valid
- IMPORTANT: "local ID" specified on iOS has to be a FQDN, and has to match the SAN in the certificate. SAN for FQDN starts with "DNS:". In theory, the ID can also be IPv4 address (IP:) or USER_FQDN with is an email address (email:). If no SAN is found in the cert, the server is supposed to match the DN of the cert, but iOS always submit the local ID as FQDN therefore breaking that, and therefore requiring an SAN for the client cert with the "DNS:" name.
strongswan log will not tell you this if the SAN and local ID does not match, even if turning debug level all the way to 3. It will just say "no trusted RSA public key found". Very confusing.
Well, now you know it.
Linux running strongswan server, 5.3, latest version.
Client is iPhone iOS 9.2
Trying to setup IKEv2 with certificate authentication. MS-CHAPv2 authentication works fine.
Issue: no trusted RSA public key found
After spending hours on the Internet, combing through the strongswan forums and even looking at the source code, I was able to finally find out the issue:
The issue was with the client certificate I generated for iPhone.
The certificate did not have a SAN (Subject Alternative Name). I never knew it was REQUIRED to have one. This is how the check on the server goes:
1. Server needs to make sure a certificate is received from the client.
2. It then does the following checks:
- cert is signed with a known CA.
- cert date is valid
- IMPORTANT: "local ID" specified on iOS has to be a FQDN, and has to match the SAN in the certificate. SAN for FQDN starts with "DNS:". In theory, the ID can also be IPv4 address (IP:) or USER_FQDN with is an email address (email:). If no SAN is found in the cert, the server is supposed to match the DN of the cert, but iOS always submit the local ID as FQDN therefore breaking that, and therefore requiring an SAN for the client cert with the "DNS:" name.
strongswan log will not tell you this if the SAN and local ID does not match, even if turning debug level all the way to 3. It will just say "no trusted RSA public key found". Very confusing.
Well, now you know it.
linuc iptables, NAT and bridge interface
There are some issues using Linux iptables, bridge interface and NAT together. See details from the blog:
http://www.woitasen.com.ar/2011/09/confusion-using-iptables-nat-and-bridge/
The summary is packets forwarded between the bridged interfaces also go through iptables, therefore potentially creating connection-tracking states before it gets to the NAT-enabled outbound interface. Then later, when the packet is routed to the NAT-enabled outbound interface, the NAT table will not be consulted anymore because the conn-track entry already exists for that packet.
The two possible solutions:
http://www.woitasen.com.ar/2011/09/confusion-using-iptables-nat-and-bridge/
The summary is packets forwarded between the bridged interfaces also go through iptables, therefore potentially creating connection-tracking states before it gets to the NAT-enabled outbound interface. Then later, when the packet is routed to the NAT-enabled outbound interface, the NAT table will not be consulted anymore because the conn-track entry already exists for that packet.
The two possible solutions:
- echo 0 > /proc/sys/net/bridge/bridge-nf-call-iptables #To disable Iptables in the bridge.
- Raw table: This table can be used to avoid packets (connection really) to enter the NAT table: iptables -t raw -I PREROUTING -i BRIDGE -s x.x.x.x -j NOTRACK.
March 7, 2016
supervisor add new a process
after adding the process.conf file in /etc/supervisor/conf.d/, run:
supervisorctl reread
supervisorctl update
http://www.onurguzel.com/supervisord-restarting-and-reloading/
supervisorctl reread
supervisorctl update
http://www.onurguzel.com/supervisord-restarting-and-reloading/
March 4, 2016
February 24, 2016
dokuwiki remove register link on top page
lib/tpl/dokuwiki/tpl_header.php, search for "register" and comment out the line.
February 9, 2016
Start your own DOCSIS lab
To setup a DOCSIS Lab you'll need:
- 1x CMTS (no it's not possible to use a Linux based PC convert into a Cable router.Ok? We close this forever or until a hardware manufacturer will sell PCIExpress Coax interfaces. BUT!!!!! If you know a manufacturer who do this, please share!!)
- 1x RG-6 2way Splitter (you have to combine US/DS RF signals into a single Coax cable, yes RF splitter can combine)
- 3x RF attenuator +20dB (you are in lab, so it's not a good idea to blow up your equipments radio)
- 1x 3Way RF splitter (optional, but if you want to test 3 CM simultaneously it's a good idea)
- 1x Return path filter (you are in LAB and have to combine the US and DS, so to clear the risk to have some RF signal harmonic on your DS, this filter is a good idea)
- 1x Linux Box (I've use Debian or use any distro of your choice and provide theses services: DHCP, TFTP, ToD, Syslog and DNS)
- 1x Switch L2 (to connect your Linux box, CMTS and Internet access. Use managable switch caused if you have to trouble shoot the L3 packets, wireshark and a port mirror will became your month employee)
Your connection desing, see: http://commons.wikimedia.org/wiki/File:HFC.jpg
You will have to replace the fiber devices by the coax/RF spliters. They do the same job's on different cable type.
Yes you will have to put money on the table and buy devices. You can found really good deal into the refurbished market but for sure it will not free.
If it's OK, you will continued with the RF plan, Cable modem DOCSIS standard, OID options, Cable modem TEK and required security, DHCP provisioning/relaying and routing.
It's really possible to do it. But always keep in mind that it's not easy, you will spend many hours without results, spend money in devices and materials but it's possible.
Source:
http://www.docsis.org/node/1686
- 1x CMTS (no it's not possible to use a Linux based PC convert into a Cable router.Ok? We close this forever or until a hardware manufacturer will sell PCIExpress Coax interfaces. BUT!!!!! If you know a manufacturer who do this, please share!!)
- 1x RG-6 2way Splitter (you have to combine US/DS RF signals into a single Coax cable, yes RF splitter can combine)
- 3x RF attenuator +20dB (you are in lab, so it's not a good idea to blow up your equipments radio)
- 1x 3Way RF splitter (optional, but if you want to test 3 CM simultaneously it's a good idea)
- 1x Return path filter (you are in LAB and have to combine the US and DS, so to clear the risk to have some RF signal harmonic on your DS, this filter is a good idea)
- 1x Linux Box (I've use Debian or use any distro of your choice and provide theses services: DHCP, TFTP, ToD, Syslog and DNS)
- 1x Switch L2 (to connect your Linux box, CMTS and Internet access. Use managable switch caused if you have to trouble shoot the L3 packets, wireshark and a port mirror will became your month employee)
Your connection desing, see: http://commons.wikimedia.org/wiki/File:HFC.jpg
You will have to replace the fiber devices by the coax/RF spliters. They do the same job's on different cable type.
Yes you will have to put money on the table and buy devices. You can found really good deal into the refurbished market but for sure it will not free.
If it's OK, you will continued with the RF plan, Cable modem DOCSIS standard, OID options, Cable modem TEK and required security, DHCP provisioning/relaying and routing.
It's really possible to do it. But always keep in mind that it's not easy, you will spend many hours without results, spend money in devices and materials but it's possible.
Source:
http://www.docsis.org/node/1686
January 23, 2016
.vimrc edti binary files in hex mode
Add the following to your ~/.vimrc file, and vim will be able to edit *.bin, *.exe, and *.o files in HEX mode:
if has ("autocmd")
" vim -b : edit binary using xxd-format!
augroup Binary
au BufReadPre *.bin,*.exe,*.o let &binary=1
au BufReadPost * if &binary | %!xxd
au BufReadPost * so $VIMRUNTIME/syntax/xxd.vim | set filetype=xxd | endif
au BufWritePre * if &binary | %!xxd -r
au BufWritePre * endif
au BufWritePost * if &binary | %!xxd
au BufWritePost * set nomod | endif
augroup END
endif
if has ("autocmd")
" vim -b : edit binary using xxd-format!
augroup Binary
au BufReadPre *.bin,*.exe,*.o let &binary=1
au BufReadPost * if &binary | %!xxd
au BufReadPost * so $VIMRUNTIME/syntax/xxd.vim | set filetype=xxd | endif
au BufWritePre * if &binary | %!xxd -r
au BufWritePre * endif
au BufWritePost * if &binary | %!xxd
au BufWritePost * set nomod | endif
augroup END
endif
January 14, 2016
lsyncd.conf file
settings = {
delay = 0.1,
maxProcesses = 3,
logfile = "/tmp/lsyncd.log",
}
targetlist = {
"192.168.5.203",
"192.168.5.204"
}
for _, server in ipairs(targetlist) do
sync{
default.rsyncssh,
source="/home/me/mysyncdir",
host=server,
targetdir="mysyncdir"
}
end
delay = 0.1,
maxProcesses = 3,
logfile = "/tmp/lsyncd.log",
}
targetlist = {
"192.168.5.203",
"192.168.5.204"
}
for _, server in ipairs(targetlist) do
sync{
default.rsyncssh,
source="/home/me/mysyncdir",
host=server,
targetdir="mysyncdir"
}
end
Xbox one firewall ports
Here is what we actually need to make this work.
| protocol | port | direction | |
| DNS | UDP | 53 | outbound if you don’t have DNS services on your subnet |
| HTTP | TCP | 80 | outbound |
| Kerberos | UDP | 88 | inbound and outbound (yes, Xbox Live uses Kerberos for authentication.) |
| Xbox | UDP | 3074 | inbound and outbound |
| Xbox | TCP | 3074 | inbound and outbound |
| SIP | UDP | 5060-5061 | inbound and outbound |
January 13, 2016
travel agents to buy international tickets
| 飞翔旅游 SBP Travel |
951-200-3308 909-614-4648 626-275-2811 619-209-7736 |
| 飞霖旅游 FeiLin Travel Inc |
951-461-8723 951-200-0172 626-539-5608 |
| 佳友旅遊 Luckyer Travel | 626-281-2568 |
| Bravo Travel | 626-571-1899 |
| 来来旅行社 Lai Lai Travel | 626-286-6123 |
| 完美旅游 Perfect Trans & Travel Service |
626-300-3888 800-341-7983 |
December 31, 2015
php code to normalize US phone number
This is the power of regex
Source: http://stackoverflow.com/questions/4708248/formatting-phone-numbers-in-php
Source: http://stackoverflow.com/questions/4708248/formatting-phone-numbers-in-php
This is a US phone formatter that works on more versions of numbers than any of the current answers.
$numbers = explode("\n", '(111) 222-3333
((111) 222-3333
1112223333
111 222-3333
111-222-3333
(111)2223333
+11234567890
1-8002353551
123-456-7890 -Hello!
+1 - 1234567890
');
foreach($numbers as $number)
{
print preg_replace('~.*(\d{3})[^\d]{0,7}(\d{3})[^\d]{0,7}(\d{4}).*~', '($1) $2-$3', $number). "\n";
}
And here is a breakdown of the regex:Cell: +1 999-(555 0001)
.* zero or more of anything "Cell: +1 "
(\d{3}) three digits "999"
[^\d]{0,7} zero or up to 7 of something not a digit "-("
(\d{3}) three digits "555"
[^\d]{0,7} zero or up to 7 of something not a digit " "
(\d{4}) four digits "0001"
.* zero or more of anything ")"
Updated: March 11, 2015 to use {0,7} instead of {,7}December 15, 2015
Linux routing based on IPtables MARK
http://www.linuxhorizon.ro/iproute2.html
Backup:
This page is a small HOWTO about the advanced linux routing...
First of all let me tell you where you can find the best source of information about the advanced routing under Linux. Most of you probably know or heard about the Linux Advanced Routing & Traffic Control site. There you can see a very comprehensive source of knowledge based not only on documentation but by easy to understand examples...
Credits: Linux Advanced Routing & Traffic Control, Thea
Ok, then...
This page will show you how to set a linux box to use 2 different ISPs on the same time...
First example:
Goal: To route packets that came from 4 network to different ISPs
Let's presume that you have two ISPs. In the following examples I'll use RDS and ASTRAL (two large ISPs from my country)
For the ASCII art and lynx console browser fans I'll use this kind of chart:
Let's fill up every table with the defaults routes:
The next step is to have some routing rules and routes:
For the RDS table:
The packets that came from the 10.11.11.0/24 and 10.12.12.0/24 networks will go to the RDS routing table and then (because we have a default route) will be passed to the RDS gateway. And similar, the packets that came from the 10.22.22.0/24 and 10.33.33.0/24 network will go to the ASTRAL gateway...
What is happening with the packets that came from other networks that are not shown in the above rules? Well, they just simply go to main routing table and follow the routing rules that reside there... If you want to block them to go to internet just delete the default route from the main table... (of course, doing that your router can not longer go to interent).
Second example:
Goal: To route the packets having the destination port 22/tcp to the RDS and 80/tcp to the ASTRAL (no matter what network generates them).
This example it is almost the same as the first one except that we will use iptables to mark the packets.
Same chart...
Same /etc/iproute2/rt_tables content:
For more documentation go to iptables home page or you can download a good documentation from this site (Security & Privacy Section) or directly from here.
To mark the packets that have the 22 and 80 as destination port we will use the MANGLE table...
For the RDS:
Now you have a routing solution based by the destination port...
Backup:
This page is a small HOWTO about the advanced linux routing...
First of all let me tell you where you can find the best source of information about the advanced routing under Linux. Most of you probably know or heard about the Linux Advanced Routing & Traffic Control site. There you can see a very comprehensive source of knowledge based not only on documentation but by easy to understand examples...
Credits: Linux Advanced Routing & Traffic Control, Thea
Ok, then...
This page will show you how to set a linux box to use 2 different ISPs on the same time...
First example:
Goal: To route packets that came from 4 network to different ISPs
Let's presume that you have two ISPs. In the following examples I'll use RDS and ASTRAL (two large ISPs from my country)
For the ASCII art and lynx console browser fans I'll use this kind of chart:
________
+-------------+ /
| ISP 1 | /
+-------------+ (RDS) +------+
| | gw 10.1.1.1 | /
+------+-------+ +-------------+ /
+----------------+ | eth1 | /
| | | | |
| Local networks +----+ Linux router | | Internet cloud
| | | | |
+----------------+ | eth2 | \
+------+-------+ +-------------+ \
| | ISP 2 | \
+-------------+ (ASTRAL) +------+
| gw 10.8.8.1 | \
+-------------+ \________
We will work only on Linux router box.
From the root prompter do:
echo 1 RDS >> /etc/iproute2/rt_tables echo 2 ASTRAL >> /etc/iproute2/rt_tablesThe /etc/iproute2/rt_tables content after previous commands:
# # reserved values # 255 local 254 main 253 default 0 unspec # # local # #1 inr.ruhep 1 RDS 2 ASTRALNow we have three routing tables as follows: RDS table, ASTRAL table and the main table...
Let's fill up every table with the defaults routes:
The next step is to have some routing rules and routes:
For the RDS table:
ip route add default via 10.1.1.1 dev eth1 table RDS ip rule add from 10.11.11.0/24 table RDS ip rule add from 10.12.12.0/24 table RDSFor the ASTRAL table:
ip route add default via 10.8.8.1 dev eth2 table ASTRAL ip rule add from 10.22.22.0/24 table ASTRAL ip rule add from 10.33.33.0/24 table ASTRALTo see the routing tables:
ip route show table ASTRAL ip route show table RDS ip route show table main # it's the same as "route -n" but in different format...To see the routing tables:
ip rule show # all the rule list ip rule show | grep ASTRAL # only for ASRAL ip rule show | grep RDS # only for RDSLet me explain the above rules.
The packets that came from the 10.11.11.0/24 and 10.12.12.0/24 networks will go to the RDS routing table and then (because we have a default route) will be passed to the RDS gateway. And similar, the packets that came from the 10.22.22.0/24 and 10.33.33.0/24 network will go to the ASTRAL gateway...
What is happening with the packets that came from other networks that are not shown in the above rules? Well, they just simply go to main routing table and follow the routing rules that reside there... If you want to block them to go to internet just delete the default route from the main table... (of course, doing that your router can not longer go to interent).
Second example:
Goal: To route the packets having the destination port 22/tcp to the RDS and 80/tcp to the ASTRAL (no matter what network generates them).
This example it is almost the same as the first one except that we will use iptables to mark the packets.
Same chart...
________
+-------------+ /
| ISP 1 | /
+-------------+ (RDS) +------+
| | gw 10.1.1.1 | /
+------+-------+ +-------------+ /
+----------------+ | eth1 | /
| | | | |
| Local networks +----+ Linux router | | Internet cloud
| | | | |
+----------------+ | eth2 | \
+------+-------+ +-------------+ \
| | ISP 2 | \
+-------------+ (ASTRAL) +------+
| gw 10.8.8.1 | \
+-------------+ \________
Same /etc/iproute2/rt_tables content:
# # reserved values # 255 local 254 main 253 default 0 unspec # # local # #1 inr.ruhep 1 RDS 2 ASTRALBefore you start check your iptables configuration. I strongly recommend to read about iptables if you are unsure about what you will doing next.
For more documentation go to iptables home page or you can download a good documentation from this site (Security & Privacy Section) or directly from here.
To mark the packets that have the 22 and 80 as destination port we will use the MANGLE table...
iptables -A PREROUTING -t mangle -i eth0 -p tcp --dport 22 -j MARK --set-mark 1 iptables -A PREROUTING -t mangle -i eth0 -p tcp --dprot 80 -j MARK --set-mark 2For the RDS table:
ip route add default via 10.1.1.1 dev eth1 table RDS # the same like in the first exampleFor the ASTRAL table:
ip route add default via 10.8.8.1 dev eth2 table ASTRAL # the same like in the first exampleThe next step is to have some routing rules based by the marked packets:
For the RDS:
ip rule add from all fwmark 1 table RDSFor the ASTRAL:
ip rule add from all fwmark 2 table ASTRALYou can use the same commands to see the routing tables and rule lists as in the first example.
Now you have a routing solution based by the destination port...
Subscribe to:
Posts (Atom)