x2Fusion

PHP Raw Packet Logger.

Feb 25th, 2016
193
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 5.81 KB | None | 0 0
  1. <?php
  2.  
  3. error_reporting(~E_ALL);
  4.  
  5. //Create a RAW socket
  6. $socket = socket_create(AF_INET , SOCK_RAW , SOL_TCP);  
  7. if($socket)
  8. {
  9.     echo "Starting sniffing...\n";
  10.      $buf = '';
  11.     while(true)
  12.     {
  13.         //Start receiving on the raw socket
  14.         socket_recv ( $socket , $buf , 65536 , 0 );
  15.              
  16.         //Process the packet
  17.         process_packet($buf);
  18.     }
  19. }
  20.  
  21. //Some error - check that you used sudo !!
  22. else
  23. {
  24.     $error_code = socket_last_error();
  25.     $error_message = socket_strerror($error_code);  
  26.      
  27.     echo "Could not create socket : [$error_code] $error_message";
  28. }
  29.  
  30. /**
  31.     Process the captured packet.
  32. */
  33. function process_packet($packet)
  34. {
  35.     //IP Header
  36.     $ip_header_fmt = 'Cip_ver_len/'
  37.     .'Ctos/'
  38.     .'ntot_len/'
  39.     .'nidentification/'
  40.     .'nfrag_off/'
  41.     .'Cttl/'
  42.     .'Cprotocol/nheader_checksum/Nsource_add/Ndest_add/';
  43.        
  44.     //Unpack the IP header    
  45.     $ip_header = unpack($ip_header_fmt , $packet);
  46.    
  47.     if($ip_header['protocol'] == '6')
  48.     {
  49.         print_tcp_packet($packet);
  50.     }
  51. }
  52.  
  53. /*
  54.   Process a TCP Packet :)
  55. */
  56. function print_tcp_packet($packet)
  57. {
  58.     $ip_header_fmt = 'Cip_ver_len/'
  59.     .'Ctos/'
  60.     .'ntot_len/';
  61.      
  62.     $p = unpack($ip_header_fmt , $packet);
  63.     $ip_len = ($p['ip_ver_len'] & 0x0F);
  64.      
  65.     if($ip_len == 5)
  66.     {
  67.          
  68.         //IP Header format for unpack
  69.         $ip_header_fmt = 'Cip_ver_len/'
  70.         .'Ctos/'
  71.         .'ntot_len/'
  72.         .'nidentification/'
  73.         .'nfrag_off/'
  74.         .'Cttl/'
  75.         .'Cprotocol/'
  76.         .'nip_checksum/'
  77.         .'Nsource_add/'
  78.         .'Ndest_add/';
  79.     }
  80.     else if ($ip_len == 6)
  81.     {
  82.         //IP Header format for unpack
  83.         $ip_header_fmt = 'Cip_ver_len/'
  84.         .'Ctos/'
  85.         .'ntot_len/'
  86.         .'nidentification/'
  87.         .'nfrag_off/'
  88.         .'Cttl/'
  89.         .'Cprotocol/'
  90.         .'nip_checksum/'
  91.         .'Nsource_add/'
  92.         .'Ndest_add/'
  93.         .'Noptions_padding/';
  94.     }
  95.      
  96.     $tcp_header_fmt = 'nsource_port/'
  97.     .'ndest_port/'
  98.     .'Nsequence_number/'
  99.     .'Nacknowledgement_number/'
  100.     .'Coffset_reserved/';
  101.      
  102.     //total packet unpack format
  103.     $total_packet = $ip_header_fmt.$tcp_header_fmt.'H*data';
  104.      
  105.     $p = unpack($total_packet , $packet);
  106.     $tcp_header_len = ($p['offset_reserved'] >> 4);
  107.      
  108.     if($tcp_header_len == 5)
  109.     {
  110.         //TCP Header Format for unpack
  111.         $tcp_header_fmt = 'nsource_port/'
  112.         .'ndest_port/'
  113.         .'Nsequence_number/'
  114.         .'Nacknowledgement_number/'
  115.         .'Coffset_reserved/'
  116.         .'Ctcp_flags/'
  117.         .'nwindow_size/'
  118.         .'nchecksum/'
  119.         .'nurgent_pointer/';
  120.     }
  121.     else if($tcp_header_len == 6)
  122.     {
  123.         //TCP Header Format for unpack
  124.         $tcp_header_fmt = 'nsource_port/'
  125.         .'ndest_port/'
  126.         .'Nsequence_number/'
  127.         .'Nacknowledgement_number/'
  128.         .'Coffset_reserved/'
  129.         .'Ctcp_flags/'
  130.         .'nwindow_size/'
  131.         .'nchecksum/'
  132.         .'nurgent_pointer/'
  133.         .'Ntcp_options_padding/';
  134.     }
  135.      
  136.     //total packet unpack format
  137.     $total_packet = $ip_header_fmt.$tcp_header_fmt.'H*data';
  138.      
  139.     //unpack the packet finally
  140.     $packet = unpack($total_packet , $packet);
  141.      
  142.     //prepare the unpacked data
  143.     $sniff = array(
  144.          
  145.         'ip_header' => array(
  146.             'ip_ver' => ($packet['ip_ver_len'] >> 4) ,
  147.             'ip_len' => ($packet['ip_ver_len'] & 0x0F) ,
  148.             'tos' => $packet['tos'] ,
  149.             'tot_len' => $packet['tot_len'] ,
  150.             'identification' => $packet['identification'] ,
  151.             'frag_off' => $packet['frag_off'] ,
  152.             'ttl' => $packet['ttl'] ,
  153.             'protocol' => $packet['protocol'] ,
  154.             'checksum' => $packet['ip_checksum'] ,
  155.             'source_add' => long2ip($packet['source_add']) ,
  156.             'dest_add' => long2ip($packet['dest_add']) ,
  157.         ) ,
  158.    
  159.         'tcp_header' => array(
  160.             'source_port' => $packet['source_port'] ,
  161.             'dest_port' => $packet['dest_port'] ,
  162.             'sequence_number' => $packet['sequence_number'] ,
  163.             'acknowledgement_number' => $packet['acknowledgement_number'] ,
  164.             'tcp_header_length' => ($packet['offset_reserved'] >> 4) ,
  165.              
  166.             'tcp_flags' => array(
  167.                 'cwr' => (($packet['tcp_flags'] & 0x80) >> 7) ,
  168.                 'ecn' => (($packet['tcp_flags'] & 0x40) >> 6) ,
  169.                 'urgent' => (($packet['tcp_flags'] & 0x20) >> 5 ) ,
  170.                 'ack' => (($packet['tcp_flags'] & 0x10) >>4) ,
  171.                 'push' => (($packet['tcp_flags'] & 0x08)>>3) ,
  172.                 'reset' => (($packet['tcp_flags'] & 0x04)>>2) ,
  173.                 'syn' => (($packet['tcp_flags'] & 0x02)>>1) ,
  174.                 'fin' => (($packet['tcp_flags'] & 0x01)) ,
  175.             ) ,
  176.              
  177.             'window_size' => $packet['window_size'] ,
  178.             'checksum' => $packet['checksum'] . ' [0x'.dechex($packet['checksum']).']',
  179.         ) ,
  180.        
  181.         'data' => $packet['data'],
  182.         'hexdata' => hex_to_str($packet['data'])
  183.     );
  184.  
  185.     //print the unpacked data
  186.     print_r($sniff);
  187. }
  188.  
  189. /*
  190.     idea taken from http://ditio.net/2008/11/04/php-string-to-hex-and-hex-to-string-functions/
  191.     modified a bit to show non alphanumeric characters as dot.
  192. */
  193. function hex_to_str($hex)
  194. {
  195.     $string='';
  196.      
  197.     for ($i=0; $i < strlen($hex)-1; $i+=2)
  198.     {
  199.         $d = hexdec($hex[$i].$hex[$i+1]);
  200.          
  201.         //Show only if number of alphabet
  202.         if( ($d >= 48 and $d <= 57) or ($d >= 65 and $d <= 90) or ($d >= 97 and $d <= 122) )
  203.         {
  204.             $string .= chr(hexdec($hex[$i].$hex[$i+1]));
  205.         }
  206.         else
  207.         {
  208.             $string .= '.';
  209.         }
  210.     }
  211.      
  212.     return $string;
  213. }
Advertisement
Add Comment
Please, Sign In to add comment