wlantest.c 9.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469
  1. /*
  2. * wlantest - IEEE 802.11 protocol monitoring and testing tool
  3. * Copyright (c) 2010-2015, Jouni Malinen <j@w1.fi>
  4. *
  5. * This software may be distributed under the terms of the BSD license.
  6. * See README for more details.
  7. */
  8. #include "utils/includes.h"
  9. #include "utils/common.h"
  10. #include "utils/eloop.h"
  11. #include "wlantest.h"
  12. static void wlantest_terminate(int sig, void *signal_ctx)
  13. {
  14. eloop_terminate();
  15. }
  16. static void usage(void)
  17. {
  18. printf("wlantest [-cddhqqFt] [-i<ifname>] [-r<pcap file>] "
  19. "[-p<passphrase>]\n"
  20. " [-I<wired ifname>] [-R<wired pcap file>] "
  21. "[-P<RADIUS shared secret>]\n"
  22. " [-n<write pcapng file>]\n"
  23. " [-w<write pcap file>] [-f<MSK/PMK file>]\n"
  24. " [-L<log file>] [-T<PTK file>]\n");
  25. }
  26. static void passphrase_deinit(struct wlantest_passphrase *p)
  27. {
  28. dl_list_del(&p->list);
  29. os_free(p);
  30. }
  31. static void secret_deinit(struct wlantest_radius_secret *r)
  32. {
  33. dl_list_del(&r->list);
  34. os_free(r);
  35. }
  36. static void wlantest_init(struct wlantest *wt)
  37. {
  38. int i;
  39. os_memset(wt, 0, sizeof(*wt));
  40. wt->monitor_sock = -1;
  41. wt->ctrl_sock = -1;
  42. for (i = 0; i < MAX_CTRL_CONNECTIONS; i++)
  43. wt->ctrl_socks[i] = -1;
  44. dl_list_init(&wt->passphrase);
  45. dl_list_init(&wt->bss);
  46. dl_list_init(&wt->secret);
  47. dl_list_init(&wt->radius);
  48. dl_list_init(&wt->pmk);
  49. dl_list_init(&wt->ptk);
  50. dl_list_init(&wt->wep);
  51. }
  52. void radius_deinit(struct wlantest_radius *r)
  53. {
  54. dl_list_del(&r->list);
  55. os_free(r);
  56. }
  57. static void ptk_deinit(struct wlantest_ptk *ptk)
  58. {
  59. dl_list_del(&ptk->list);
  60. os_free(ptk);
  61. }
  62. static void wlantest_deinit(struct wlantest *wt)
  63. {
  64. struct wlantest_passphrase *p, *pn;
  65. struct wlantest_radius_secret *s, *sn;
  66. struct wlantest_radius *r, *rn;
  67. struct wlantest_pmk *pmk, *np;
  68. struct wlantest_ptk *ptk, *npt;
  69. struct wlantest_wep *wep, *nw;
  70. if (wt->ctrl_sock >= 0)
  71. ctrl_deinit(wt);
  72. if (wt->monitor_sock >= 0)
  73. monitor_deinit(wt);
  74. bss_flush(wt);
  75. dl_list_for_each_safe(p, pn, &wt->passphrase,
  76. struct wlantest_passphrase, list)
  77. passphrase_deinit(p);
  78. dl_list_for_each_safe(s, sn, &wt->secret,
  79. struct wlantest_radius_secret, list)
  80. secret_deinit(s);
  81. dl_list_for_each_safe(r, rn, &wt->radius, struct wlantest_radius, list)
  82. radius_deinit(r);
  83. dl_list_for_each_safe(pmk, np, &wt->pmk, struct wlantest_pmk, list)
  84. pmk_deinit(pmk);
  85. dl_list_for_each_safe(ptk, npt, &wt->ptk, struct wlantest_ptk, list)
  86. ptk_deinit(ptk);
  87. dl_list_for_each_safe(wep, nw, &wt->wep, struct wlantest_wep, list)
  88. os_free(wep);
  89. write_pcap_deinit(wt);
  90. write_pcapng_deinit(wt);
  91. clear_notes(wt);
  92. os_free(wt->decrypted);
  93. wt->decrypted = NULL;
  94. }
  95. static void add_passphrase(struct wlantest *wt, const char *passphrase)
  96. {
  97. struct wlantest_passphrase *p;
  98. size_t len = os_strlen(passphrase);
  99. if (len < 8 || len > 63)
  100. return;
  101. p = os_zalloc(sizeof(*p));
  102. if (p == NULL)
  103. return;
  104. os_memcpy(p->passphrase, passphrase, len);
  105. dl_list_add(&wt->passphrase, &p->list);
  106. }
  107. static void add_secret(struct wlantest *wt, const char *secret)
  108. {
  109. struct wlantest_radius_secret *s;
  110. size_t len = os_strlen(secret);
  111. if (len >= MAX_RADIUS_SECRET_LEN)
  112. return;
  113. s = os_zalloc(sizeof(*s));
  114. if (s == NULL)
  115. return;
  116. os_memcpy(s->secret, secret, len);
  117. dl_list_add(&wt->secret, &s->list);
  118. }
  119. static int add_pmk_file(struct wlantest *wt, const char *pmk_file)
  120. {
  121. FILE *f;
  122. u8 pmk[32];
  123. char buf[300], *pos;
  124. struct wlantest_pmk *p;
  125. f = fopen(pmk_file, "r");
  126. if (f == NULL) {
  127. wpa_printf(MSG_ERROR, "Could not open '%s'", pmk_file);
  128. return -1;
  129. }
  130. while (fgets(buf, sizeof(buf), f)) {
  131. pos = buf;
  132. while (*pos && *pos != '\r' && *pos != '\n')
  133. pos++;
  134. *pos = '\0';
  135. if (pos - buf < 2 * 32)
  136. continue;
  137. if (hexstr2bin(buf, pmk, 32) < 0)
  138. continue;
  139. p = os_zalloc(sizeof(*p));
  140. if (p == NULL)
  141. break;
  142. os_memcpy(p->pmk, pmk, 32);
  143. dl_list_add(&wt->pmk, &p->list);
  144. wpa_hexdump(MSG_DEBUG, "Added PMK from file", pmk, 32);
  145. }
  146. fclose(f);
  147. return 0;
  148. }
  149. static int add_ptk_file(struct wlantest *wt, const char *ptk_file)
  150. {
  151. FILE *f;
  152. u8 ptk[64];
  153. size_t ptk_len;
  154. char buf[300], *pos;
  155. struct wlantest_ptk *p;
  156. f = fopen(ptk_file, "r");
  157. if (f == NULL) {
  158. wpa_printf(MSG_ERROR, "Could not open '%s'", ptk_file);
  159. return -1;
  160. }
  161. while (fgets(buf, sizeof(buf), f)) {
  162. pos = buf;
  163. while (*pos && *pos != '\r' && *pos != '\n')
  164. pos++;
  165. *pos = '\0';
  166. ptk_len = pos - buf;
  167. if (ptk_len & 1)
  168. continue;
  169. ptk_len /= 2;
  170. if (ptk_len != 16 && ptk_len != 32 &&
  171. ptk_len != 48 && ptk_len != 64)
  172. continue;
  173. if (hexstr2bin(buf, ptk, ptk_len) < 0)
  174. continue;
  175. p = os_zalloc(sizeof(*p));
  176. if (p == NULL)
  177. break;
  178. if (ptk_len < 48) {
  179. os_memcpy(p->ptk.tk, ptk, ptk_len);
  180. p->ptk.tk_len = ptk_len;
  181. p->ptk_len = 32 + ptk_len;
  182. } else {
  183. os_memcpy(p->ptk.kck, ptk, 16);
  184. p->ptk.kck_len = 16;
  185. os_memcpy(p->ptk.kek, ptk + 16, 16);
  186. p->ptk.kek_len = 16;
  187. os_memcpy(p->ptk.tk, ptk + 32, ptk_len - 32);
  188. p->ptk.tk_len = ptk_len - 32;
  189. p->ptk_len = ptk_len;
  190. }
  191. dl_list_add(&wt->ptk, &p->list);
  192. wpa_hexdump(MSG_DEBUG, "Added PTK from file", ptk, ptk_len);
  193. }
  194. fclose(f);
  195. return 0;
  196. }
  197. int add_wep(struct wlantest *wt, const char *key)
  198. {
  199. struct wlantest_wep *w;
  200. size_t len = os_strlen(key);
  201. if (len != 2 * 5 && len != 2 * 13) {
  202. wpa_printf(MSG_INFO, "Invalid WEP key '%s'", key);
  203. return -1;
  204. }
  205. w = os_zalloc(sizeof(*w));
  206. if (w == NULL)
  207. return -1;
  208. if (hexstr2bin(key, w->key, len / 2) < 0) {
  209. os_free(w);
  210. wpa_printf(MSG_INFO, "Invalid WEP key '%s'", key);
  211. return -1;
  212. }
  213. w->key_len = len / 2;
  214. dl_list_add(&wt->wep, &w->list);
  215. return 0;
  216. }
  217. void add_note(struct wlantest *wt, int level, const char *fmt, ...)
  218. {
  219. va_list ap;
  220. size_t len = 1000;
  221. int wlen;
  222. if (wt->num_notes == MAX_NOTES)
  223. return;
  224. wt->notes[wt->num_notes] = os_malloc(len);
  225. if (wt->notes[wt->num_notes] == NULL)
  226. return;
  227. va_start(ap, fmt);
  228. wlen = vsnprintf(wt->notes[wt->num_notes], len, fmt, ap);
  229. va_end(ap);
  230. if (wlen < 0) {
  231. os_free(wt->notes[wt->num_notes]);
  232. wt->notes[wt->num_notes] = NULL;
  233. return;
  234. }
  235. if (wlen >= len)
  236. wt->notes[wt->num_notes][len - 1] = '\0';
  237. wpa_printf(level, "%s", wt->notes[wt->num_notes]);
  238. wt->num_notes++;
  239. }
  240. void clear_notes(struct wlantest *wt)
  241. {
  242. size_t i;
  243. for (i = 0; i < wt->num_notes; i++) {
  244. os_free(wt->notes[i]);
  245. wt->notes[i] = NULL;
  246. }
  247. wt->num_notes = 0;
  248. }
  249. size_t notes_len(struct wlantest *wt, size_t hdrlen)
  250. {
  251. size_t i;
  252. size_t len = wt->num_notes * hdrlen;
  253. for (i = 0; i < wt->num_notes; i++)
  254. len += os_strlen(wt->notes[i]);
  255. return len;
  256. }
  257. int wlantest_relog(struct wlantest *wt)
  258. {
  259. int ret = 0;
  260. wpa_printf(MSG_INFO, "Re-open log/capture files");
  261. if (wpa_debug_reopen_file())
  262. ret = -1;
  263. if (wt->write_file) {
  264. write_pcap_deinit(wt);
  265. if (write_pcap_init(wt, wt->write_file) < 0)
  266. ret = -1;
  267. }
  268. if (wt->pcapng_file) {
  269. write_pcapng_deinit(wt);
  270. if (write_pcapng_init(wt, wt->pcapng_file) < 0)
  271. ret = -1;
  272. }
  273. return ret;
  274. }
  275. int main(int argc, char *argv[])
  276. {
  277. int c;
  278. const char *read_file = NULL;
  279. const char *read_wired_file = NULL;
  280. const char *ifname = NULL;
  281. const char *ifname_wired = NULL;
  282. const char *logfile = NULL;
  283. struct wlantest wt;
  284. int ctrl_iface = 0;
  285. wpa_debug_level = MSG_INFO;
  286. wpa_debug_show_keys = 1;
  287. if (os_program_init())
  288. return -1;
  289. wlantest_init(&wt);
  290. for (;;) {
  291. c = getopt(argc, argv, "cdf:Fhi:I:L:n:p:P:qr:R:tT:w:W:");
  292. if (c < 0)
  293. break;
  294. switch (c) {
  295. case 'c':
  296. ctrl_iface = 1;
  297. break;
  298. case 'd':
  299. if (wpa_debug_level > 0)
  300. wpa_debug_level--;
  301. break;
  302. case 'f':
  303. if (add_pmk_file(&wt, optarg) < 0)
  304. return -1;
  305. break;
  306. case 'F':
  307. wt.assume_fcs = 1;
  308. break;
  309. case 'h':
  310. usage();
  311. return 0;
  312. case 'i':
  313. ifname = optarg;
  314. break;
  315. case 'I':
  316. ifname_wired = optarg;
  317. break;
  318. case 'L':
  319. logfile = optarg;
  320. break;
  321. case 'n':
  322. wt.pcapng_file = optarg;
  323. break;
  324. case 'p':
  325. add_passphrase(&wt, optarg);
  326. break;
  327. case 'P':
  328. add_secret(&wt, optarg);
  329. break;
  330. case 'q':
  331. wpa_debug_level++;
  332. break;
  333. case 'r':
  334. read_file = optarg;
  335. break;
  336. case 'R':
  337. read_wired_file = optarg;
  338. break;
  339. case 't':
  340. wpa_debug_timestamp = 1;
  341. break;
  342. case 'T':
  343. if (add_ptk_file(&wt, optarg) < 0)
  344. return -1;
  345. break;
  346. case 'w':
  347. wt.write_file = optarg;
  348. break;
  349. case 'W':
  350. if (add_wep(&wt, optarg) < 0)
  351. return -1;
  352. break;
  353. default:
  354. usage();
  355. return -1;
  356. }
  357. }
  358. if (ifname == NULL && ifname_wired == NULL &&
  359. read_file == NULL && read_wired_file == NULL) {
  360. usage();
  361. return 0;
  362. }
  363. if (eloop_init())
  364. return -1;
  365. if (logfile)
  366. wpa_debug_open_file(logfile);
  367. if (wt.write_file && write_pcap_init(&wt, wt.write_file) < 0)
  368. return -1;
  369. if (wt.pcapng_file && write_pcapng_init(&wt, wt.pcapng_file) < 0)
  370. return -1;
  371. if (read_wired_file && read_wired_cap_file(&wt, read_wired_file) < 0)
  372. return -1;
  373. if (read_file && read_cap_file(&wt, read_file) < 0)
  374. return -1;
  375. if (ifname && monitor_init(&wt, ifname) < 0)
  376. return -1;
  377. if (ifname_wired && monitor_init_wired(&wt, ifname_wired) < 0)
  378. return -1;
  379. if (ctrl_iface && ctrl_init(&wt) < 0)
  380. return -1;
  381. eloop_register_signal_terminate(wlantest_terminate, &wt);
  382. eloop_run();
  383. wpa_printf(MSG_INFO, "Processed: rx_mgmt=%u rx_ctrl=%u rx_data=%u "
  384. "fcs_error=%u",
  385. wt.rx_mgmt, wt.rx_ctrl, wt.rx_data, wt.fcs_error);
  386. wlantest_deinit(&wt);
  387. wpa_debug_close_file();
  388. eloop_destroy();
  389. os_program_deinit();
  390. return 0;
  391. }