xref: /openbsd-src/usr.sbin/tcpdrop/tcpdrop.c (revision a28daedfc357b214be5c701aa8ba8adb29a7f1c2)
1 /* $OpenBSD: tcpdrop.c,v 1.7 2007/03/28 17:04:03 deraadt Exp $ */
2 
3 /*
4  * Copyright (c) 2004 Markus Friedl <markus@openbsd.org>
5  *
6  * Permission to use, copy, modify, and distribute this software for any
7  * purpose with or without fee is hereby granted, provided that the above
8  * copyright notice and this permission notice appear in all copies.
9  *
10  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
11  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
12  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
13  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
14  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
15  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
16  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17  */
18 
19 #include <sys/param.h>
20 #include <sys/socket.h>
21 #include <sys/sysctl.h>
22 
23 #include <netinet/in.h>
24 #include <netinet/tcp.h>
25 #include <netinet/ip_var.h>
26 #include <netinet/tcp_timer.h>
27 #include <netinet/tcp_var.h>
28 
29 #include <err.h>
30 #include <stdio.h>
31 #include <string.h>
32 #include <stdlib.h>
33 #include <netdb.h>
34 
35 extern char *__progname;
36 
37 /*
38  * Drop a tcp connection.
39  */
40 int
41 main(int argc, char **argv)
42 {
43 	int mib[] = { CTL_NET, PF_INET, IPPROTO_TCP, TCPCTL_DROP };
44 	struct addrinfo hints, *ail, *aif, *laddr, *faddr;
45 	char fhbuf[NI_MAXHOST], fsbuf[NI_MAXSERV];
46 	char lhbuf[NI_MAXHOST], lsbuf[NI_MAXSERV];
47 	char *laddr1, *addr1, *port1, *laddr2, *addr2, *port2;
48 	struct tcp_ident_mapping tir;
49 	int gaierr, rval = 0;
50 
51 	memset(&hints, 0, sizeof(hints));
52 	hints.ai_family = AF_UNSPEC;
53 	hints.ai_socktype = SOCK_STREAM;
54 
55 	if (argc == 3) {
56 		laddr1 = addr1 = strdup(argv[1]);
57 		port1 = strrchr(addr1, ':');
58 		if (port1)
59 			*port1++ = '\0';
60 		else
61 			goto fail;
62 
63 		laddr2 = addr2 = strdup(argv[2]);
64 		port2 = strrchr(addr2, ':');
65 		if (port2)
66 			*port2++ = '\0';
67 		else
68 			goto fail;
69 	} else if (argc == 5) {
70 		laddr1 = addr1 = argv[1];
71 		port1 = argv[2];
72 		laddr2 = addr2 = argv[3];
73 		port2 = argv[4];
74 	} else {
75 fail:
76 		fprintf(stderr,
77 		    "usage: %s local-addr local-port remote-addr remote-port\n",
78 		    __progname);
79 		fprintf(stderr,
80 		    "       %s local-addr:local-port remote-addr:remote-port\n",
81 		    __progname);
82 		exit(1);
83 	}
84 
85 	if (addr1[0] == '[' && addr1[strlen(addr1) - 1] == ']') {
86 		laddr1 = strdup(addr1);
87 		laddr1[strlen(laddr1) - 1] = '\0';
88 		laddr1++;
89 	}
90 	if (addr2[0] == '[' && addr2[strlen(addr2) - 1] == ']') {
91 		laddr2 = strdup(addr2);
92 		laddr2[strlen(laddr2) - 1] = '\0';
93 		laddr2++;
94 	}
95 
96 	if ((gaierr = getaddrinfo(laddr1, port1, &hints, &laddr)) != 0)
97 		errx(1, "%s port %s: %s", addr1, port1,
98 		    gai_strerror(gaierr));
99 
100 	if ((gaierr = getaddrinfo(laddr2, port2, &hints, &faddr)) != 0) {
101 		freeaddrinfo(laddr);
102 		errx(1, "%s port %s: %s", addr2, port2,
103 		    gai_strerror(gaierr));
104 	}
105 
106 	for (ail = laddr; ail; ail = ail->ai_next) {
107 		for (aif = faddr; aif; aif = aif->ai_next) {
108 			if (ail->ai_family != aif->ai_family)
109 				continue;
110 			memcpy(&tir.faddr, aif->ai_addr, aif->ai_addrlen);
111 			memcpy(&tir.laddr, ail->ai_addr, ail->ai_addrlen);
112 
113 			if ((gaierr = getnameinfo(aif->ai_addr, aif->ai_addrlen,
114 			    fhbuf, sizeof(fhbuf), fsbuf, sizeof(fsbuf),
115 			    NI_NUMERICHOST | NI_NUMERICSERV)) != 0)
116 				errx(1, "getnameinfo: %s", gai_strerror(gaierr));
117 			if ((gaierr = getnameinfo(ail->ai_addr, ail->ai_addrlen,
118 			    lhbuf, sizeof(lhbuf), lsbuf, sizeof(lsbuf),
119 			    NI_NUMERICHOST | NI_NUMERICSERV)) != 0)
120 				errx(1, "getnameinfo: %s", gai_strerror(gaierr));
121 
122 			if (sysctl(mib, sizeof (mib) / sizeof (int), NULL,
123 			    NULL, &tir, sizeof(tir)) == -1) {
124 				rval = 1;
125 				warn("%s %s %s %s", lhbuf, lsbuf, fhbuf, fsbuf);
126 			} else {
127 				if (aif->ai_family == PF_INET6)
128 					printf("[%s]:%s [%s]:%s dropped\n",
129 					    lhbuf, lsbuf, fhbuf, fsbuf);
130 				else
131 					printf("%s:%s %s:%s dropped\n",
132 					    lhbuf, lsbuf, fhbuf, fsbuf);
133 			}
134 		}
135 	}
136 	freeaddrinfo(laddr);
137 	freeaddrinfo(faddr);
138 	exit(rval);
139 }
140