|
| 1 | +#include <stdio.h> |
| 2 | +#include <stdlib.h> |
| 3 | +#include <ctype.h> |
| 4 | +#include <unistd.h> |
| 5 | +#include <in6addr.h> |
| 6 | +#include <ws2tcpip.h> |
| 7 | +#include "windivert.h" |
| 8 | +#include "goodbyedpi.h" |
| 9 | + |
| 10 | +static const char fake_http_request[] = "GET / HTTP/1.1\r\nHost: www.w3.org\r\n" |
| 11 | + "User-Agent: curl/7.65.3\r\nAccept: */*\r\n" |
| 12 | + "Accept-Encoding: deflate, gzip, br\r\n\r\n"; |
| 13 | +static const unsigned char fake_https_request[] = { |
| 14 | + 0x16, 0x03, 0x01, 0x02, 0x00, 0x01, 0x00, 0x01, 0xfc, 0x03, 0x03, 0x9a, 0x8f, 0xa7, 0x6a, 0x5d, |
| 15 | + 0x57, 0xf3, 0x62, 0x19, 0xbe, 0x46, 0x82, 0x45, 0xe2, 0x59, 0x5c, 0xb4, 0x48, 0x31, 0x12, 0x15, |
| 16 | + 0x14, 0x79, 0x2c, 0xaa, 0xcd, 0xea, 0xda, 0xf0, 0xe1, 0xfd, 0xbb, 0x20, 0xf4, 0x83, 0x2a, 0x94, |
| 17 | + 0xf1, 0x48, 0x3b, 0x9d, 0xb6, 0x74, 0xba, 0x3c, 0x81, 0x63, 0xbc, 0x18, 0xcc, 0x14, 0x45, 0x57, |
| 18 | + 0x6c, 0x80, 0xf9, 0x25, 0xcf, 0x9c, 0x86, 0x60, 0x50, 0x31, 0x2e, 0xe9, 0x00, 0x22, 0x13, 0x01, |
| 19 | + 0x13, 0x03, 0x13, 0x02, 0xc0, 0x2b, 0xc0, 0x2f, 0xcc, 0xa9, 0xcc, 0xa8, 0xc0, 0x2c, 0xc0, 0x30, |
| 20 | + 0xc0, 0x0a, 0xc0, 0x09, 0xc0, 0x13, 0xc0, 0x14, 0x00, 0x33, 0x00, 0x39, 0x00, 0x2f, 0x00, 0x35, |
| 21 | + 0x01, 0x00, 0x01, 0x91, 0x00, 0x00, 0x00, 0x0f, 0x00, 0x0d, 0x00, 0x00, 0x0a, 0x77, 0x77, 0x77, |
| 22 | + 0x2e, 0x77, 0x33, 0x2e, 0x6f, 0x72, 0x67, 0x00, 0x17, 0x00, 0x00, 0xff, 0x01, 0x00, 0x01, 0x00, |
| 23 | + 0x00, 0x0a, 0x00, 0x0e, 0x00, 0x0c, 0x00, 0x1d, 0x00, 0x17, 0x00, 0x18, 0x00, 0x19, 0x01, 0x00, |
| 24 | + 0x01, 0x01, 0x00, 0x0b, 0x00, 0x02, 0x01, 0x00, 0x00, 0x23, 0x00, 0x00, 0x00, 0x10, 0x00, 0x0e, |
| 25 | + 0x00, 0x0c, 0x02, 0x68, 0x32, 0x08, 0x68, 0x74, 0x74, 0x70, 0x2f, 0x31, 0x2e, 0x31, 0x00, 0x05, |
| 26 | + 0x00, 0x05, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x33, 0x00, 0x6b, 0x00, 0x69, 0x00, 0x1d, 0x00, |
| 27 | + 0x20, 0xb0, 0xe4, 0xda, 0x34, 0xb4, 0x29, 0x8d, 0xd3, 0x5c, 0x70, 0xd3, 0xbe, 0xe8, 0xa7, 0x2a, |
| 28 | + 0x6b, 0xe4, 0x11, 0x19, 0x8b, 0x18, 0x9d, 0x83, 0x9a, 0x49, 0x7c, 0x83, 0x7f, 0xa9, 0x03, 0x8c, |
| 29 | + 0x3c, 0x00, 0x17, 0x00, 0x41, 0x04, 0x4c, 0x04, 0xa4, 0x71, 0x4c, 0x49, 0x75, 0x55, 0xd1, 0x18, |
| 30 | + 0x1e, 0x22, 0x62, 0x19, 0x53, 0x00, 0xde, 0x74, 0x2f, 0xb3, 0xde, 0x13, 0x54, 0xe6, 0x78, 0x07, |
| 31 | + 0x94, 0x55, 0x0e, 0xb2, 0x6c, 0xb0, 0x03, 0xee, 0x79, 0xa9, 0x96, 0x1e, 0x0e, 0x98, 0x17, 0x78, |
| 32 | + 0x24, 0x44, 0x0c, 0x88, 0x80, 0x06, 0x8b, 0xd4, 0x80, 0xbf, 0x67, 0x7c, 0x37, 0x6a, 0x5b, 0x46, |
| 33 | + 0x4c, 0xa7, 0x98, 0x6f, 0xb9, 0x22, 0x00, 0x2b, 0x00, 0x09, 0x08, 0x03, 0x04, 0x03, 0x03, 0x03, |
| 34 | + 0x02, 0x03, 0x01, 0x00, 0x0d, 0x00, 0x18, 0x00, 0x16, 0x04, 0x03, 0x05, 0x03, 0x06, 0x03, 0x08, |
| 35 | + 0x04, 0x08, 0x05, 0x08, 0x06, 0x04, 0x01, 0x05, 0x01, 0x06, 0x01, 0x02, 0x03, 0x02, 0x01, 0x00, |
| 36 | + 0x2d, 0x00, 0x02, 0x01, 0x01, 0x00, 0x1c, 0x00, 0x02, 0x40, 0x01, 0x00, 0x15, 0x00, 0x96, 0x00, |
| 37 | + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, |
| 38 | + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, |
| 39 | + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, |
| 40 | + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, |
| 41 | + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, |
| 42 | + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, |
| 43 | + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, |
| 44 | + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, |
| 45 | + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, |
| 46 | + 0x00, 0x00, 0x00, 0x00, 0x00 |
| 47 | +}; |
| 48 | + |
| 49 | +static int send_fake_data(const HANDLE w_filter, |
| 50 | + const PWINDIVERT_ADDRESS addr, |
| 51 | + const char *pkt, |
| 52 | + const UINT packetLen, |
| 53 | + const BOOL is_ipv6, |
| 54 | + const BOOL is_https, |
| 55 | + const BYTE set_ttl, |
| 56 | + const BYTE set_checksum |
| 57 | + ) { |
| 58 | + char packet_fake[MAX_PACKET_SIZE]; |
| 59 | + WINDIVERT_ADDRESS addr_new; |
| 60 | + PVOID packet_data; |
| 61 | + UINT packet_dataLen; |
| 62 | + UINT packetLen_new; |
| 63 | + PWINDIVERT_IPHDR ppIpHdr; |
| 64 | + PWINDIVERT_IPV6HDR ppIpV6Hdr; |
| 65 | + PWINDIVERT_TCPHDR ppTcpHdr; |
| 66 | + char *fake_request_data = is_https ? fake_https_request : fake_http_request; |
| 67 | + UINT fake_request_size = is_https ? sizeof(fake_https_request) : sizeof(fake_http_request) - 1; |
| 68 | + |
| 69 | + memcpy(&addr_new, addr, sizeof(WINDIVERT_ADDRESS)); |
| 70 | + memcpy(packet_fake, pkt, packetLen); |
| 71 | + |
| 72 | + if (!is_ipv6) { |
| 73 | + // IPv4 TCP Data packet |
| 74 | + if (!WinDivertHelperParsePacket(packet_fake, packetLen, &ppIpHdr, |
| 75 | + NULL, NULL, NULL, &ppTcpHdr, NULL, &packet_data, &packet_dataLen)) |
| 76 | + return 1; |
| 77 | + } |
| 78 | + else { |
| 79 | + // IPv6 TCP Data packet |
| 80 | + if (!WinDivertHelperParsePacket(packet_fake, packetLen, NULL, |
| 81 | + &ppIpV6Hdr, NULL, NULL, &ppTcpHdr, NULL, &packet_data, &packet_dataLen)) |
| 82 | + return 1; |
| 83 | + } |
| 84 | + |
| 85 | + if (packetLen + fake_request_size + 1 > MAX_PACKET_SIZE) |
| 86 | + return 2; |
| 87 | + |
| 88 | + memcpy(packet_data, fake_request_data, fake_request_size); |
| 89 | + packetLen_new = packetLen - packet_dataLen + fake_request_size; |
| 90 | + |
| 91 | + if (!is_ipv6) { |
| 92 | + ppIpHdr->Length = htons( |
| 93 | + ntohs(ppIpHdr->Length) - |
| 94 | + packet_dataLen + fake_request_size |
| 95 | + ); |
| 96 | + |
| 97 | + if (set_ttl) |
| 98 | + ppIpHdr->TTL = set_ttl; |
| 99 | + } |
| 100 | + else { |
| 101 | + ppIpV6Hdr->Length = htons( |
| 102 | + ntohs(ppIpV6Hdr->Length) - |
| 103 | + packet_dataLen + fake_request_size |
| 104 | + ); |
| 105 | + |
| 106 | + if (set_ttl) |
| 107 | + ppIpV6Hdr->HopLimit = set_ttl; |
| 108 | + } |
| 109 | + |
| 110 | + // Recalculate the checksum |
| 111 | + addr_new.PseudoTCPChecksum = 0; |
| 112 | + WinDivertHelperCalcChecksums(packet_fake, packetLen_new, &addr_new, NULL); |
| 113 | + |
| 114 | + if (set_checksum) { |
| 115 | + // ...and damage it |
| 116 | + ppTcpHdr->Checksum = htons(ntohs(ppTcpHdr->Checksum) - 1); |
| 117 | + } |
| 118 | + //printf("Pseudo checksum: %d\n", addr_new.PseudoTCPChecksum); |
| 119 | + |
| 120 | + WinDivertSend( |
| 121 | + w_filter, packet_fake, |
| 122 | + packetLen_new, |
| 123 | + &addr_new, NULL |
| 124 | + ); |
| 125 | + debug("Fake packet: OK"); |
| 126 | + |
| 127 | + return 0; |
| 128 | +} |
| 129 | + |
| 130 | +int send_fake_http_request(const HANDLE w_filter, |
| 131 | + const PWINDIVERT_ADDRESS addr, |
| 132 | + const char *pkt, |
| 133 | + const UINT packetLen, |
| 134 | + const BOOL is_ipv6, |
| 135 | + const BYTE set_ttl, |
| 136 | + const BYTE set_checksum |
| 137 | + ) { |
| 138 | + return send_fake_data(w_filter, |
| 139 | + addr, |
| 140 | + pkt, |
| 141 | + packetLen, |
| 142 | + is_ipv6, |
| 143 | + FALSE, |
| 144 | + set_ttl, |
| 145 | + set_checksum |
| 146 | + ); |
| 147 | +} |
| 148 | + |
| 149 | +int send_fake_https_request(const HANDLE w_filter, |
| 150 | + const PWINDIVERT_ADDRESS addr, |
| 151 | + const char *pkt, |
| 152 | + const UINT packetLen, |
| 153 | + const BOOL is_ipv6, |
| 154 | + const BYTE set_ttl, |
| 155 | + const BYTE set_checksum |
| 156 | + ) { |
| 157 | + return send_fake_data(w_filter, |
| 158 | + addr, |
| 159 | + pkt, |
| 160 | + packetLen, |
| 161 | + is_ipv6, |
| 162 | + TRUE, |
| 163 | + set_ttl, |
| 164 | + set_checksum |
| 165 | + ); |
| 166 | +} |
0 commit comments