Guest User

Foo Protocol Example (Wireshark Lua)

a guest
Jun 5th, 2012
63
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Lua 2.02 KB | None | 0 0
  1.  
  2. -- ################
  3. -- # proto_foo.lua
  4. -- ################
  5. local _curport = nil    -- current port under which this protocol is registered
  6. local MIN_LEN = 21      -- min buffer length (21 = 4+8+5+4)
  7. local DEFAULT_PORT = 3456
  8.  
  9. -- 1. Declare the protocol with the Proto() function.
  10. local proto_foo = Proto("foo", "Foo Protocol")
  11.  
  12. -- 2. Declare the protocol's fields with the ProtoField.XXX() functions.
  13. proto_foo.fields.num = ProtoField.uint32("foo.num", "Unsigned integer (32-bit)")
  14. proto_foo.fields.str = ProtoField.stringz("foo.str", "Null-terminated string")
  15. proto_foo.fields.bytes = ProtoField.bytes("foo.bytes", "Byte array")
  16. proto_foo.fields.ip = ProtoField.ipv4("foo.ip", "IPv4 address")
  17.  
  18. -- 3. (OPTIONAL) Declare the protocol's preferences with the Pref.XXX() functions.
  19. proto_foo.prefs.port = Pref.uint("Port", DEFAULT_PORT, "UDP port number")
  20.  
  21. -- 4. Declare the protocol's dissector function
  22. function proto_foo.dissector(buf, pinfo, tree)
  23.    
  24.     if buf:len() >= MIN_LEN then
  25.         local offset = 0
  26.         local f = proto_foo.fields
  27.         local subtree = tree:add(proto_foo, buf())
  28.         subtree:add(f.num   , buf(offset, 4)); offset = offset + 4
  29.         subtree:add(f.str   , buf(offset, 8)); offset = offset + 8
  30.         subtree:add(f.bytes , buf(offset, 5)); offset = offset + 5
  31.         subtree:add(f.ip    , buf(offset, 4)); offset = offset + 4
  32.     end
  33. end
  34.    
  35. -- 5. (OPTIONAL) Declare the protocol's init function. If this function is omitted,
  36. -- perform the protocol registration outside of it.
  37. function proto_foo.init()
  38.  
  39.     -- 6. Register the protocol with a DissectorTable (TCP port in this case)
  40.     local dt = DissectorTable.get("tcp.port")
  41.     if _curport then dt:remove(_curport, proto_foo) end
  42.     dt:add(proto_foo.prefs.port, proto_foo)
  43.     _curport = proto_foo.prefs.port
  44. end
  45.  
  46. -- XXX: do init here if proto_foo.init() does not exist. This file can
  47. -- only ever be loaded once (no way to undeclare a Proto), so no need
  48. -- to remove this dissector from a previously registered dissector table.
  49. --DissectorTable.get("udp.port"):add(proto_foo.prefs.port, proto_foo)
Advertisement
Add Comment
Please, Sign In to add comment