1998-09-17 03:12:28 +00:00
|
|
|
/* follow.h
|
|
|
|
*
|
|
|
|
* Copyright 1998 Mike Hall <mlh@io.com>
|
|
|
|
*
|
2006-05-21 05:12:17 +00:00
|
|
|
* Wireshark - Network traffic analyzer
|
|
|
|
* By Gerald Combs <gerald@wireshark.org>
|
1998-09-17 03:12:28 +00:00
|
|
|
* Copyright 1998 Gerald Combs
|
2002-08-28 21:04:11 +00:00
|
|
|
*
|
1998-09-17 03:12:28 +00:00
|
|
|
* This program is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU General Public License
|
|
|
|
* as published by the Free Software Foundation; either version 2
|
|
|
|
* of the License, or (at your option) any later version.
|
2002-08-28 21:04:11 +00:00
|
|
|
*
|
1998-09-17 03:12:28 +00:00
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
2002-08-28 21:04:11 +00:00
|
|
|
*
|
1998-09-17 03:12:28 +00:00
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
* along with this program; if not, write to the Free Software
|
2012-06-28 22:56:06 +00:00
|
|
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
1998-09-17 03:12:28 +00:00
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef __FOLLOW_H__
|
|
|
|
#define __FOLLOW_H__
|
|
|
|
|
2013-07-23 08:56:30 +00:00
|
|
|
#ifdef __cplusplus
|
|
|
|
extern "C" {
|
|
|
|
#endif /* __cplusplus */
|
|
|
|
|
2002-01-21 07:37:49 +00:00
|
|
|
#include <epan/packet.h>
|
2013-03-01 23:53:11 +00:00
|
|
|
#include "ws_symbol_export.h"
|
1998-09-17 03:12:28 +00:00
|
|
|
|
2000-08-11 22:18:22 +00:00
|
|
|
#define MAX_IPADDR_LEN 16
|
|
|
|
|
2014-12-27 22:15:41 +00:00
|
|
|
typedef enum {
|
|
|
|
TCP_STREAM = 0,
|
|
|
|
UDP_STREAM,
|
|
|
|
MAX_STREAM
|
|
|
|
} stream_type;
|
|
|
|
|
2006-05-21 05:12:17 +00:00
|
|
|
/* With MSVC and a libwireshark.dll, we need a special declaration. */
|
2013-03-01 23:53:11 +00:00
|
|
|
WS_DLL_PUBLIC gboolean empty_tcp_stream;
|
|
|
|
WS_DLL_PUBLIC gboolean incomplete_tcp_stream;
|
1999-03-23 20:25:50 +00:00
|
|
|
|
1999-11-28 03:35:20 +00:00
|
|
|
typedef struct _tcp_stream_chunk {
|
2000-08-11 22:18:22 +00:00
|
|
|
guint8 src_addr[MAX_IPADDR_LEN];
|
1999-11-28 03:35:20 +00:00
|
|
|
guint16 src_port;
|
|
|
|
guint32 dlen;
|
2013-11-14 17:37:40 +00:00
|
|
|
guint32 packet_num;
|
1999-11-28 03:35:20 +00:00
|
|
|
} tcp_stream_chunk;
|
|
|
|
|
2013-11-13 22:18:01 +00:00
|
|
|
/** Build a follow filter based on the current packet's conversation.
|
|
|
|
*
|
2013-12-02 13:46:30 +00:00
|
|
|
* @param packet_info [in] The current packet.
|
2013-11-13 22:18:01 +00:00
|
|
|
* @return A filter that specifies the conversation. Must be g_free()d
|
|
|
|
* the caller.
|
|
|
|
*/
|
|
|
|
WS_DLL_PUBLIC
|
2013-12-02 13:46:30 +00:00
|
|
|
gchar* build_follow_conv_filter( packet_info * packet_info);
|
2013-11-13 22:18:01 +00:00
|
|
|
|
2014-12-27 22:15:41 +00:00
|
|
|
/** Build a follow filter based on the current TCP/UDP stream index.
|
|
|
|
* follow_index() must be called prior to calling this.
|
2013-11-13 22:18:01 +00:00
|
|
|
*
|
|
|
|
* @return A filter that specifies the current stream. Must be g_free()d
|
|
|
|
* the caller.
|
|
|
|
*/
|
2013-03-01 23:53:11 +00:00
|
|
|
WS_DLL_PUBLIC
|
2014-12-27 22:15:41 +00:00
|
|
|
gchar* build_follow_index_filter(stream_type stream);
|
2013-11-13 22:18:01 +00:00
|
|
|
|
2013-03-01 23:53:11 +00:00
|
|
|
WS_DLL_PUBLIC
|
2014-12-27 22:15:41 +00:00
|
|
|
gboolean follow_addr(stream_type, const address *, guint, const address *, guint );
|
2013-11-13 22:18:01 +00:00
|
|
|
|
2014-12-27 22:15:41 +00:00
|
|
|
/** Select a TCP/UDP stream to follow via its index.
|
2013-11-13 22:18:01 +00:00
|
|
|
*
|
2015-04-28 19:38:15 +00:00
|
|
|
* @param stream [in] The stream type to follow(TCP_STREAM or UDP_STREAM)
|
2013-12-02 13:46:30 +00:00
|
|
|
* @param addr [in] The stream index to follow.
|
2013-11-13 22:18:01 +00:00
|
|
|
* @return TRUE on success, FALSE on failure.
|
|
|
|
*/
|
2013-03-01 23:53:11 +00:00
|
|
|
WS_DLL_PUBLIC
|
2014-12-27 22:15:41 +00:00
|
|
|
gboolean follow_index(stream_type stream, guint32 addr);
|
2013-11-13 22:18:01 +00:00
|
|
|
|
2014-12-27 22:15:41 +00:00
|
|
|
/** Get the current TCP/UDP index being followed.
|
2013-11-13 22:18:01 +00:00
|
|
|
*
|
2014-12-27 22:15:41 +00:00
|
|
|
* @return The current TCP/UDP index. The behavior is undefined
|
|
|
|
* if no TCP/UDP stream is being followed.
|
2013-11-13 22:18:01 +00:00
|
|
|
*/
|
|
|
|
WS_DLL_PUBLIC
|
2014-12-27 22:15:41 +00:00
|
|
|
guint32 get_follow_index(stream_type stream);
|
2013-11-13 22:18:01 +00:00
|
|
|
|
2012-12-26 05:57:06 +00:00
|
|
|
void reassemble_tcp( guint32, guint32, guint32, guint32, const char*, guint32,
|
2013-11-14 17:37:40 +00:00
|
|
|
int, address *, address *, guint, guint, guint32 );
|
2013-03-01 23:53:11 +00:00
|
|
|
WS_DLL_PUBLIC
|
1998-09-27 22:12:47 +00:00
|
|
|
void reset_tcp_reassembly( void );
|
1998-09-17 03:12:28 +00:00
|
|
|
|
2014-12-27 22:15:41 +00:00
|
|
|
WS_DLL_PUBLIC
|
|
|
|
void reset_udp_follow(void);
|
|
|
|
|
2000-08-09 05:18:45 +00:00
|
|
|
typedef struct {
|
2000-08-11 22:18:22 +00:00
|
|
|
guint8 ip_address[2][MAX_IPADDR_LEN];
|
2007-11-03 04:45:35 +00:00
|
|
|
guint32 port[2];
|
2000-08-09 05:18:45 +00:00
|
|
|
unsigned int bytes_written[2];
|
2000-08-11 22:18:22 +00:00
|
|
|
gboolean is_ipv6;
|
2007-11-03 04:45:35 +00:00
|
|
|
} follow_stats_t;
|
2000-08-09 05:18:45 +00:00
|
|
|
|
2013-03-01 23:53:11 +00:00
|
|
|
WS_DLL_PUBLIC
|
2007-11-03 04:45:35 +00:00
|
|
|
void follow_stats(follow_stats_t* stats);
|
2000-08-09 05:18:45 +00:00
|
|
|
|
2013-07-23 08:56:30 +00:00
|
|
|
#ifdef __cplusplus
|
|
|
|
}
|
|
|
|
#endif /* __cplusplus */
|
|
|
|
|
1998-09-17 03:12:28 +00:00
|
|
|
#endif
|