亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? snort_ftptelnet.c

?? 著名的入侵檢測系統snort的最新版本的源碼
?? C
?? 第 1 頁 / 共 5 頁
字號:
/* * snort_ftptelnet.c * * Copyright (C) 2004 Sourcefire,Inc * Steven A. Sturges <ssturges@sourcefire.com> * Daniel J. Roelker <droelker@sourcefire.com> * Marc A. Norton <mnorton@sourcefire.com> * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License Version 2 as * published by the Free Software Foundation.  You may not use, modify or * distribute this program under any other version of the GNU General * Public License. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with this program; if not, write to the Free Software * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. * * Description: * * This file wraps the FTPTelnet functionality for Snort * and starts the Normalization & Protocol checks. * * The file takes a Packet structure from the Snort IDS to start the * FTP/Telnet Normalization & Protocol checks.  It also uses the Stream * Interface Module which is also Snort-centric.  Mainly, just a wrapper * to FTP/Telnet functionality, but a key part to starting the basic flow. * * The main bulk of this file is taken up with user configuration and * parsing.  The reason this is so large is because FTPTelnet takes * very detailed configuration parameters for each specified FTP client, * to provide detailed control over an internal network and robust control * of the external network. *  * The main functions of note are: *   - FTPTelnetSnortConf()    the configuration portion *   - SnortFTPTelnet()        the actual normalization & inspection *   - LogEvents()             where we log the FTPTelnet events * * NOTES: * - 16.09.04:  Initial Development.  SAS * */#include <stdlib.h>#include <stdio.h>#include <string.h>#include <sys/types.h>#include "sf_ip.h"#ifndef WIN32#include <sys/socket.h>#include <netinet/in.h>#include <arpa/inet.h>#include <ctype.h>#endif#ifdef HAVE_CONFIG_H#include "config.h"#endif//#include "snort.h"//#include "detect.h"//#include "decode.h"//#include "log.h"//#include "event.h"//#include "generators.h"#include "debug.h"//#include "plugbase.h"//#include "util.h"//#include "event_queue.h"//#include "mstring.h"#define BUF_SIZE 1024#include "ftpp_return_codes.h"#include "ftpp_ui_config.h"#include "ftpp_ui_client_lookup.h"#include "ftpp_ui_server_lookup.h"#include "ftp_cmd_lookup.h"#include "ftp_bounce_lookup.h"#include "ftpp_si.h"#include "ftpp_eo_log.h"#include "pp_telnet.h"#include "pp_ftp.h"#include "stream_api.h"#include "profiler.h"#ifdef PERF_PROFILINGextern PreprocStats ftpPerfStats;extern PreprocStats telnetPerfStats;PreprocStats ftppDetectPerfStats;int ftppDetectCalled = 0;#endifextern FTPTELNET_GLOBAL_CONF FTPTelnetGlobalConf;//extern u_int8_t DecodeBuffer[DECODE_BLEN]; /* decode.c *//* * The definition of the configuration separators in the snort.conf * configure line. */#define CONF_SEPARATORS " \t\n\r"/* * These are the definitions of the parser section delimiting  * keywords to configure FtpTelnet.  When one of these keywords * are seen, we begin a new section. */#define GLOBAL        "global"#define TELNET        "telnet"#define FTP           "ftp"//#define GLOBAL_CLIENT "global_client"#define CLIENT        "client"#define SERVER        "server"/* * GLOBAL subkeyword values */#define ENCRYPTED_TRAFFIC "encrypted_traffic"#define CHECK_ENCRYPTED   "check_encrypted"#define INSPECT_TYPE      "inspection_type"#define INSPECT_TYPE_STATELESS "stateless"#define INSPECT_TYPE_STATEFUL  "stateful"/* * Protocol subkeywords. */#define PORTS             "ports"/* * Telnet subkeywords. */#define AYT_THRESHOLD     "ayt_attack_thresh"#define NORMALIZE         "normalize"#define DETECT_ANOMALIES  "detect_anomalies"/* * FTP SERVER subkeywords. */#define FTP_CMDS          "ftp_cmds"#define PRINT_CMDS        "print_cmds"#define MAX_PARAM_LEN     "def_max_param_len"#define ALT_PARAM_LEN     "alt_max_param_len"#define CMD_VALIDITY      "cmd_validity"#define STRING_FORMAT     "chk_str_fmt"#define TELNET_CMDS       "telnet_cmds"#define DATA_CHAN_CMD     "data_chan_cmds"#define DATA_XFER_CMD     "data_xfer_cmds"#define DATA_CHAN         "data_chan"#define LOGIN_CMD         "login_cmds"#define ENCR_CMD          "encr_cmds"#define DIR_CMD           "dir_cmds"/* * FTP CLIENT subkeywords */#define BOUNCE            "bounce"#define ALLOW_BOUNCE      "bounce_to"#define MAX_RESP_LEN      "max_resp_len"/* * Data type keywords */#define START_CMD_FORMAT    "<"#define END_CMD_FORMAT      ">"#define F_INT               "int"#define F_NUMBER            "number"#define F_CHAR              "char"#define F_DATE              "date"#define F_STRING            "string"#define F_STRING_FMT        "formated_string"#define F_HOST_PORT         "host_port"/* * Optional parameter delimiters */#define START_OPT_FMT       "["#define END_OPT_FMT         "]"#define START_CHOICE_FMT    "{"#define END_CHOICE_FMT      "}"#define OR_FMT              "|"/* * The cmd_validity keyword can be used with the format keyword to * restrict data types.  The interpretation is specific to the data * type.  'format' is only supported with date & char data types. * * A few examples: * * 1. Will perform validity checking of an FTP Mode command to * check for one of the characters A, S, B, or C. * * cmd_validity MODE char ASBC * * * 2. Will perform validity checking of an FTP MDTM command to * check for an optional date argument following the format * specified.  The date would uses the YYYYMMDDHHmmss+TZ format. * * cmd_validity MDTM [ date nnnnnnnnnnnnnn[.n[n[n]]] ] string * * * 3. Will perform validity checking of an FTP ALLO command to * check for an integer, then optionally, the letter R and another * integer. * * cmd_validity ALLO int [ char R int ] *//* * The def_max_param_len & alt_max_param_len keywords can be used to * restrict parameter length for one or more commands.  The space * separated list of commands is enclosed in {}s. * * A few examples: * * 1. Restricts all command parameters to 100 characters * * def_max_param_len 100 * * 2. Overrides CWD pathname to 256 characters * * alt_max_param_len 256 { CWD }  * * 3. Overrides PWD & SYST to no parameters * * alt_max_param_len 0 { PWD SYST }  * *//* * Alert subkeywords */#define BOOL_YES     "yes"#define BOOL_NO      "no"/* * Port list delimiters */#define START_PORT_LIST "{"#define END_PORT_LIST   "}"/* * Keyword for the default client/server configuration */#define DEFAULT "default"/* * The default FTP server configuration for FTP command validation. * Most of this comes from RFC 959, with additional commands being * drawn from other RFCs/Internet Drafts that are in use. *  * Any of the below can be overridden in snort.conf. *  * This is here to eliminate most of it from snort.conf to * avoid an ugly configuration file.  The default_max_param_len * is somewhat arbitrary, but is taken from the majority of * the snort FTP rules that limit parameter size to 100 * characters, as of 18 Sep 2004. *  * The data_chan_cmds, data_xfer_cmds are used to track open * data channel connections. *  * The login_cmds and dir_cmds are used to track state of username * and current directory. */#define DEFAULT_FTP_CONF "hardcoded_config\ def_max_param_len 100 \ ftp_cmds { USER PASS ACCT CWD CDUP SMNT \   QUIT REIN PORT PASV TYPE STRU MODE RETR STOR STOU APPE ALLO REST \   RNFR RNTO ABOR DELE RMD MKD PWD LIST NLST SITE SYST STAT HELP NOOP } \ ftp_cmds { AUTH ADAT PROT PBSZ CONF ENC } \ ftp_cmds { FEAT OPTS } \ ftp_cmds { MDTM REST SIZE MLST MLSD } \ alt_max_param_len 0 { CDUP QUIT REIN PASV STOU ABOR PWD SYST NOOP } \ cmd_validity MODE < char SBC > \ cmd_validity STRU < char FRP > \ cmd_validity ALLO < int [ char R int ] > \ cmd_validity TYPE < { char AE [ char NTC ] | char I | char L [ number ] } > \ cmd_validity PORT < host_port > \ data_chan_cmds { PASV PORT } \ data_xfer_cmds { RETR STOR STOU APPE LIST NLST } \ login_cmds { USER PASS } \ dir_cmds { CWD 250 CDUP 250 PWD 257 } \"static int printedFTPHeader = 0;static int gDefaultServerConfig = 0;static int gDefaultClientConfig = 0;static char *maxToken = NULL;char *NextToken(char *delimiters){    char *retTok = strtok(NULL, delimiters);    if (retTok > maxToken)        return NULL;    return retTok;}/* * Function: ProcessConfOpt(FTPTELNET_CONF_OPT *ConfOpt, *                          char *Option, *                          char *ErrorString, int ErrStrLen) * * Purpose: Set the CONF_OPT on and alert fields. * *          We check to make sure of valid parameters and then set *          the appropriate fields. * * Arguments: ConfOpt       => pointer to the configuration option *            Option        => character pointer to the option being configured *            ErrorString   => error string buffer *            ErrStrLen     => the length of the error string buffer * * Returns: int     => an error code integer (0 = success, *                     >0 = non-fatal error, <0 = fatal error) * */static int ProcessConfOpt(FTPTELNET_CONF_OPT *ConfOpt, char *Option,                          char *ErrorString, int ErrStrLen){    char *pcToken;    pcToken = NextToken(CONF_SEPARATORS);    if(pcToken == NULL)    {        snprintf(ErrorString, ErrStrLen,                "No argument to token '%s'.", Option);        return FTPP_FATAL_ERR;    }    /*     * Check for the alert value      */    if(!strcmp(BOOL_YES, pcToken))    {        ConfOpt->alert = 1;    }    else if(!strcmp(BOOL_NO, pcToken))    {        ConfOpt->alert = 0;    }    else    {        snprintf(ErrorString, ErrStrLen,                "Invalid argument to token '%s'.", Option);        return FTPP_FATAL_ERR;    }    ConfOpt->on = 1;    return FTPP_SUCCESS;}/* * Function: PrintConfOpt(FTPTELNET_CONF_OPT *ConfOpt, *                          char *Option) * * Purpose: Prints the CONF_OPT and alert fields. * * Arguments: ConfOpt       => pointer to the configuration option *            Option        => character pointer to the option being configured * * Returns: int     => an error code integer (0 = success, *                     >0 = non-fatal error, <0 = fatal error) * */static int PrintConfOpt(FTPTELNET_CONF_OPT *ConfOpt, char *Option){    if(!ConfOpt || !Option)    {        return FTPP_INVALID_ARG;    }    if(ConfOpt->on)    {        _dpd.logMsg("      %s: YES alert: %s\n", Option,               ConfOpt->alert ? "YES" : "NO");    }    else    {        _dpd.logMsg("      %s: OFF\n", Option);    }    return FTPP_SUCCESS;}/*  * Function: ProcessInspectType(FTPTELNET_CONF_OPT *ConfOpt, *                          char *ErrorString, int ErrStrLen) * * Purpose: Process the type of inspection. *          This sets the type of inspection for FTPTelnet to do. * * Arguments: GlobalConf    => pointer to the global configuration *            ErrorString   => error string buffer *            ErrStrLen     => the length of the error string buffer * * Returns: int     => an error code integer (0 = success, *                     >0 = non-fatal error, <0 = fatal error) * */static int ProcessInspectType(FTPTELNET_GLOBAL_CONF *GlobalConf,                              char *ErrorString, int ErrStrLen){    char *pcToken;    pcToken = NextToken(CONF_SEPARATORS);    if(pcToken == NULL)    {        snprintf(ErrorString, ErrStrLen,                "No argument to token '%s'.", INSPECT_TYPE);        return FTPP_FATAL_ERR;    }    if(!strcmp(INSPECT_TYPE_STATEFUL, pcToken))    {        GlobalConf->inspection_type = FTPP_UI_CONFIG_STATEFUL;    }    else if(!strcmp(INSPECT_TYPE_STATELESS, pcToken))    {        GlobalConf->inspection_type = FTPP_UI_CONFIG_STATELESS;    }    else    {        snprintf(ErrorString, ErrStrLen,                "Invalid argument to token '%s'.  Must be either "

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
国产精品一卡二| 色婷婷综合激情| 青椒成人免费视频| 日韩综合在线视频| 美女视频黄 久久| 老司机精品视频在线| 一区二区三区国产精华| 久久99精品国产麻豆婷婷洗澡| 国产ts人妖一区二区| 免费日本视频一区| 日韩一区精品视频| 极品少妇xxxx精品少妇偷拍| 国产裸体歌舞团一区二区| 高清免费成人av| 色av一区二区| 3d成人动漫网站| 久久久久99精品一区| 亚洲欧美日韩国产另类专区 | 99免费精品在线| 一本一道久久a久久精品| 欧美熟乱第一页| 欧美成人精品3d动漫h| 欧美国产日韩一二三区| 亚洲美女少妇撒尿| 久久国产精品免费| 99精品视频在线免费观看| 欧美另类高清zo欧美| 久久品道一品道久久精品| 自拍偷在线精品自拍偷无码专区 | 丁香六月综合激情| 欧美亚洲综合久久| 精品少妇一区二区三区| 中文字幕不卡在线| 日本欧美加勒比视频| 成人sese在线| 日韩视频在线你懂得| 国产精品不卡在线观看| 麻豆国产91在线播放| 91麻豆国产福利精品| 日韩欧美在线网站| 亚洲精品一卡二卡| 国产成a人亚洲| 91精品国产综合久久久久久久 | 亚洲激情男女视频| 国产一区二区三区不卡在线观看| 在线视频你懂得一区| 欧美国产日韩亚洲一区| 蜜臀av一区二区在线观看| 一本大道av一区二区在线播放| 精品处破学生在线二十三| 一区二区三区四区国产精品| 丰满岳乱妇一区二区三区| 日韩免费在线观看| 日韩一区精品字幕| 在线精品视频免费播放| 久久久精品影视| 国产日韩欧美一区二区三区综合| 色94色欧美sute亚洲13| 国产999精品久久久久久绿帽| 美女视频黄 久久| 免费看日韩精品| 精品福利一区二区三区| 欧美优质美女网站| 亚洲国产精品成人久久综合一区| 婷婷亚洲久悠悠色悠在线播放| 成人sese在线| 国产精品三级视频| 不卡的av在线| 欧美国产亚洲另类动漫| 国产成人久久精品77777最新版本 国产成人鲁色资源国产91色综 | 日韩精品最新网址| 欧美高清一级片在线| 亚洲电影中文字幕在线观看| 欧美做爰猛烈大尺度电影无法无天| 最新日韩在线视频| 91传媒视频在线播放| 欧美经典三级视频一区二区三区| 国产电影精品久久禁18| 日本一区二区三区国色天香| 国产不卡视频在线播放| 久久久久久久久久久久久久久99 | 欧美一卡在线观看| 视频一区二区中文字幕| 日韩色在线观看| 九九**精品视频免费播放| 日韩一区二区三区观看| 国产一区二区三区免费播放| 欧美激情一区在线| 成人高清免费在线播放| 91国模大尺度私拍在线视频| 亚洲国产日日夜夜| 91精品国产综合久久久久久久| 蜜臀av性久久久久蜜臀aⅴ| 精品噜噜噜噜久久久久久久久试看| 韩国av一区二区三区在线观看 | 久久精品国内一区二区三区| 久久精品一区二区| av动漫一区二区| 偷拍日韩校园综合在线| 欧美videossexotv100| 成人午夜大片免费观看| 亚洲码国产岛国毛片在线| 欧美精品在线一区二区| 国产乱国产乱300精品| 一区二区三区精密机械公司| 欧美不卡视频一区| aa级大片欧美| 麻豆一区二区99久久久久| 国产精品福利一区二区三区| 欧美日韩一级大片网址| 国产成人久久精品77777最新版本| 一级特黄大欧美久久久| 久久精品视频一区二区三区| 欧美性猛片aaaaaaa做受| 麻豆成人久久精品二区三区红| 亚洲日穴在线视频| 久久久久国产精品麻豆 | 日本vs亚洲vs韩国一区三区二区| 中文av一区特黄| 日韩视频一区二区在线观看| 日本高清免费不卡视频| 国产乱人伦精品一区二区在线观看| 玉足女爽爽91| 国产精品色哟哟网站| 日韩免费观看高清完整版 | 亚洲国产精华液网站w| 欧美美女激情18p| 色综合久久久久久久久久久| 国产经典欧美精品| 蜜桃视频免费观看一区| 亚洲国产精品久久不卡毛片| 国产精品久99| 久久精品一二三| 精品久久一区二区三区| 欧美丰满美乳xxx高潮www| 色久优优欧美色久优优| 成人av电影在线| 国产91清纯白嫩初高中在线观看| 国内久久婷婷综合| 久久成人免费网站| 久久99国产精品免费| 久久精品二区亚洲w码| 日韩电影免费一区| 日韩成人一区二区三区在线观看| 亚洲国产精品久久久久婷婷884 | 日韩中文欧美在线| 日本欧美大码aⅴ在线播放| 视频一区二区中文字幕| 午夜精品123| 日本欧美一区二区三区| 日韩av一区二区在线影视| 午夜精品久久久久久久久久| 五月天中文字幕一区二区| 午夜精品久久一牛影视| 日本成人中文字幕在线视频| 奇米影视在线99精品| 久久99最新地址| 国产一区激情在线| 国产成人av电影在线观看| 成人性生交大合| 99re亚洲国产精品| 色婷婷综合五月| 欧美日韩国产一级二级| 日韩一级二级三级精品视频| 久久亚洲一区二区三区明星换脸| 久久夜色精品国产噜噜av| 国产丝袜在线精品| 亚洲黄色免费网站| 首页欧美精品中文字幕| 国产综合成人久久大片91| 成人免费精品视频| 欧美欧美午夜aⅴ在线观看| 欧美xxxx在线观看| 国产精品免费久久久久| 亚洲影视在线观看| 毛片不卡一区二区| 99久久99久久综合| 欧美精品久久一区| 久久久久久日产精品| 亚洲欧美日韩一区二区三区在线观看| 亚洲制服丝袜av| 国产传媒欧美日韩成人| 在线观看一区二区视频| 欧美成人vr18sexvr| 亚洲欧美视频一区| 六月丁香婷婷色狠狠久久| 99久久精品免费观看| 91精品国产91久久久久久一区二区 | 美女网站视频久久| 成人av在线资源网| 欧美一级淫片007| 亚洲欧美一区二区三区久本道91 | 欧美一级夜夜爽| 亚洲欧洲成人av每日更新| 日韩中文欧美在线| 91丝袜美腿高跟国产极品老师 | 一区精品在线播放| 国产制服丝袜一区| 6080日韩午夜伦伦午夜伦| 自拍偷拍欧美激情|