-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathtcpdump.cpp
142 lines (132 loc) · 4.8 KB
/
tcpdump.cpp
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
// tcpdump.cpp : Defines the entry point for the console application.
//
#include "stdafx.h"
#include "WinPCap.h"
static const TCHAR * STARTED = _T("Global\\tcpdump_started");
static const TCHAR * DONE = _T("Global\\tcpdump_done");
static const TCHAR * TIME_TO_EXIT = _T("Global\\tcpdump_time_to_exit");
/*-----------------------------------------------------------------------------
-----------------------------------------------------------------------------*/
bool run(LPCSTR captureFile) {
bool ok = false;
SECURITY_ATTRIBUTES null_dacl;
SECURITY_DESCRIPTOR SD;
ZeroMemory(&null_dacl, sizeof(null_dacl));
null_dacl.nLength = sizeof(null_dacl);
null_dacl.bInheritHandle = FALSE;
if( InitializeSecurityDescriptor(&SD, SECURITY_DESCRIPTOR_REVISION) )
if( SetSecurityDescriptorDacl(&SD, TRUE,(PACL)NULL, FALSE) )
null_dacl.lpSecurityDescriptor = &SD;
HANDLE hMustExit = CreateEvent(&null_dacl, TRUE, FALSE, TIME_TO_EXIT);
HANDLE hDone = CreateEvent(&null_dacl, TRUE, FALSE, DONE);
HANDLE hStarted = OpenEvent(EVENT_MODIFY_STATE, FALSE, STARTED);
if (hStarted) {
SetEvent(hStarted);
CloseHandle(hStarted);
}
CWinPCap pcap;
if (hMustExit && pcap.StartCapture(captureFile)) {
ok = true;
WaitForSingleObject(hMustExit, 3600000); // Let it run for an hour at most
pcap.StopCapture();
}
if (hDone) {
SetEvent(hDone);
CloseHandle(hDone);
}
if (hMustExit) {
CloseHandle(hMustExit);
}
return ok;
}
/*-----------------------------------------------------------------------------
-----------------------------------------------------------------------------*/
bool start(LPCSTR captureFile) {
bool ok = false;
SECURITY_ATTRIBUTES null_dacl;
SECURITY_DESCRIPTOR SD;
ZeroMemory(&null_dacl, sizeof(null_dacl));
null_dacl.nLength = sizeof(null_dacl);
null_dacl.bInheritHandle = FALSE;
if( InitializeSecurityDescriptor(&SD, SECURITY_DESCRIPTOR_REVISION) )
if( SetSecurityDescriptorDacl(&SD, TRUE,(PACL)NULL, FALSE) )
null_dacl.lpSecurityDescriptor = &SD;
HANDLE hStarted = CreateEvent(&null_dacl, TRUE, FALSE, STARTED);
WCHAR exe[MAX_PATH];
GetModuleFileNameW(NULL, exe, MAX_PATH);
WCHAR command_line[MAX_PATH * 2 + 100];
wsprintfW(command_line, L"\"%s\" run \"%S\"", exe, captureFile);
STARTUPINFO si;
memset(&si, 0, sizeof(si));
si.cb = sizeof(si);
PROCESS_INFORMATION pi;
if (CreateProcess(NULL, command_line, NULL, NULL, FALSE, CREATE_NO_WINDOW, NULL, NULL, &si, &pi)) {
if (hStarted)
WaitForSingleObject(hStarted, 30000);
ok = true;
}
CloseHandle(hStarted);
return ok;
}
/*-----------------------------------------------------------------------------
-----------------------------------------------------------------------------*/
bool stop() {
bool ok = false;
HANDLE hMustExit = OpenEvent(EVENT_MODIFY_STATE, FALSE, TIME_TO_EXIT);
HANDLE hDone = OpenEvent(EVENT_MODIFY_STATE, FALSE, DONE);
if (hMustExit && hDone) {
SetEvent(hMustExit);
WaitForSingleObject(hDone, 60000);
ok = true;
}
if (hMustExit)
CloseHandle(hMustExit);
if (hDone)
CloseHandle(hDone);
return ok;
}
/*-----------------------------------------------------------------------------
-----------------------------------------------------------------------------*/
int main(int argc, char *argv[]) {
bool ok = false;
bool valid_command = false;
if (argc > 1) {
valid_command = true;
if (!lstrcmpA(argv[1], "run") && argc > 2) {
ok = run(argv[2]);
} else if (!lstrcmpA(argv[1], "start") && argc > 2) {
ok = start(argv[2]);
if (ok)
printf("Packet capture started\n");
else
printf("FAILED to start packet capture");
} else if (!lstrcmpA(argv[1], "stop")) {
ok = stop();
if (ok)
printf("Packet capture done\n");
else
printf("FAILED to stop packet capture");
} else if (!lstrcmpA(argv[1], "interface")) {
CWinPCap pcap;
pcap.FindInterface();
} else if (!lstrcmpA(argv[1], "check")) {
CWinPCap pcap;
ok = pcap.IsInstalled();
if (ok) {
printf("NPCap detected");
} else {
printf("NPCap not detected. Please make sure it is installed and configured to start automatically.\n");
}
} else {
valid_command = false;
}
}
if (!valid_command) {
printf("Usage:\n"
" tcpdump start <capture file> - Starts capturing in the background.\n"
" tcpdump stop - Stops a running capture.\n"
" tcpdump interface - Display the interface name that will be used for capture.\n"
" tcpdump check - Checks WinPCap install status.\n");
}
return ok ? 0 : 1;
}