1. Post-dissector
1.1 最简单的Post-dissector
这个示例主要是演示post-dissector脚本的骨架,它的功能是在packet list的所有info列加上了一个字符串"hello world"。
-- @brief A simple post-dissector, just append string to info column -- @author zzq -- @date 2015.08.13local myproto = Proto("hello","Dummy proto to edit info column")-- the dissector function callback function myproto.dissector(tvb,pinfo,tree)pinfo.cols.info:append(" hello world") end-- register our new dummy protocol for post-dissection register_postdissector(myproto)
1.2 识别协议特征
这个示例简单地演示了如何使用post-dissector来识别协议特征。例子中,通过识别tcp载荷中是否含有字符串”weibo“来判断报文是否为weibo报文,如果是,则在packet list的protocol列标出,并在proto tree添加树节点,给出滑动特征在TCP载荷中的位置。
-- @brief A post-dissector, to indentify pattern in payload -- @author zzq -- @date 2015.08.26local weibo = Proto("weibo", "Weibo Service")local function get_payload_offset(data, proto_type)local mac_len = 14;local total_len;local ip_len = (data(14, 1):uint() - 64) * 4;if (proto_type == 0x06) thenlocal tcp_len = (data(46, 1):uint()/16) * 4;total_len = mac_len + ip_len + tcp_len;elseif (proto_type == 0x11) thenlocal udp_len = 8;total_len = mac_len + ip_len + udp_len;endreturn total_len end-- the dissector function callback function weibo.dissector(tvb, pinfo, tree)local proto_type = tvb(23, 1):uint();if(proto_type ~= 0x06) thenreturnendlocal offset = get_payload_offset(tvb, proto_type)local data = tvb(offset):string();local i, j = string.find(data, "weibo")if(i) thenpinfo.cols.protocol = weibo.namelocal subtree = tree:add(weibo, tvb(offset+i-1))subtree:append_text(", ptn_pos: " .. i .. "-" .. j)end end-- register our plugin for post-dissection register_postdissector(weibo)
2. Listener
- 创建Listener
listener = Listener.new([tap], [filter]),其中tap, filter分别是tap和过滤条件 - listener.packet
在条件命中时调用 - listener.draw
在每次需要重绘GUI时调用 - listener.reset
register_menu(name, action, [group])
-- @brief a simple Listener plugin -- @author zzq -- @date 2015.08.13local function zzq_listener()local pkts = 0local win = TextWindow.new("zzq Listener")local tap = Listener.new(nil, "http")win:set_atclose(function() tap:remove() end)function tap.packet (pinfo, tvb, tapinfo)pkts = pkts + 1endfunction tap.draw()win:set("http pkts: " .. pkts)endfunction tap.reset()pkts = 0end-- Rescan all packets and just run taps - don’t reconstruct the display. retap_packets() endregister_menu("freeland/zzq Listener", zzq_listener, MENU_STAT_GENERIC)
要查看运行结果,要选择”Statistics“菜单中的freeland/zzq Listerner子菜单来触发。此插件的运行效果如下图: