]> git.ipfire.org Git - thirdparty/snort3.git/commitdiff
Remove legacy/unused obfuscation api.
authorVictor Roemer <viroemer@cisco.com>
Fri, 8 Apr 2016 18:06:54 +0000 (14:06 -0400)
committerVictor Roemer <viroemer@cisco.com>
Fri, 8 Apr 2016 18:06:54 +0000 (14:06 -0400)
src/actions/actions.cc
src/detection/detect.cc
src/log/CMakeLists.txt
src/log/Makefile.am
src/log/log_text.cc
src/log/obfuscation.cc [deleted file]
src/log/obfuscation.h [deleted file]
src/loggers/unified2.cc
src/managers/inspector_manager.cc

index 90e87cf19e6872b12600162f7f425a25b2ddd0ef..58dd4d852e444049f51958e57f8944eff0a5d0b5 100644 (file)
@@ -25,7 +25,6 @@
 #include "main/snort_types.h"
 #include "main/snort_debug.h"
 #include "utils/util.h"
-#include "log/obfuscation.h"
 #include "stream/stream_api.h"
 #include "packet_io/active.h"
 #include "detection/signature.h"
index 85adbc74eb96836cee70186d5bb0941a06fd2c49..49aef3e7b10d2fe638ab1de53ee5f0e61e0986cd 100644 (file)
@@ -53,7 +53,6 @@
 #include "events/event_wrapper.h"
 #include "events/event_queue.h"
 #include "latency/packet_latency.h"
-#include "log/obfuscation.h"
 #include "profiler/profiler.h"
 #include "stream/stream_api.h"
 #include "packet_io/active.h"
@@ -104,18 +103,6 @@ void snort_inspect(Packet* p)
         }
         else
         {
-#ifdef BUILD_OBFUSCATION
-            /* Not a completely ideal place for this since any entries added on
-             * the packet callback trail will get obliterated - right now there
-             * isn't anything adding entries there.  Really need it here for
-             * stream clean exit, since all of the flushed, reassembled
-             * packets are going to be injected directly into this function and
-             * there may be enough that the obfuscation entry table will
-             * overflow if we don't reset it.  Putting it here does have the
-             * advantage of fewer entries per logging cycle */
-            obApi->resetObfuscationEntries();
-#endif
-
             do_detect = do_detect_content = true;
 
             /*
index b358cb996c8e877a6277f94041f32966e38045a6..a8da0e981420dd0772979ee743b19c455decfbe3 100644 (file)
@@ -2,7 +2,6 @@
 
 set (LOG_INCLUDES
     messages.h
-#   obfuscation.h
     text_log.h
 )
 
@@ -13,7 +12,6 @@ add_library ( log STATIC
     log_text.cc
     log_text.h
     messages.cc
-#   obfuscation.cc
     text_log.cc
 )
 
index 7cf85bc5ef22e2dc8d586f41fca75d508cfaa23c..fb46d293a71af6089ecbf8182864a78c8901d22f 100644 (file)
@@ -14,8 +14,3 @@ log_text.cc \
 log_text.h \
 messages.cc \
 text_log.cc
-
-EXTRA_DIST = \
-obfuscation.h \
-obfuscation.cc
-
index a0a6f7c6ec78b88f837837ea0bc632444c892572..eaab966fa5a05f1e6cf1e5d9e006e73c60f7ce05 100644 (file)
@@ -34,7 +34,6 @@
 
 #include "log.h"
 #include "text_log.h"
-#include "obfuscation.h"
 
 #include "detection/rules.h"
 #include "detection/treenodes.h"
@@ -1376,45 +1375,6 @@ void LogDiv(TextLog* log)
     TextLog_Print(log, "%s\n", SEPARATOR);
 }
 
-#ifdef BUILD_OBFUSCATION
-static int LogObfuscatedData(TextLog* log, Packet* p)
-{
-    uint8_t* payload = NULL;
-    uint16_t payload_len = 0;
-
-    if (obApi->getObfuscatedPayload(p, &payload,
-        (uint16_t*)&payload_len) != OB_RET_SUCCESS)
-    {
-        return -1;
-    }
-
-    LogDiv(log);
-
-    /* dump the application layer data */
-    if (SnortConfig::output_app_data() && !SnortConfig::verbose_byte_dump())
-    {
-        if (SnortConfig::output_char_data())
-            LogCharData(log, (const char*)payload, payload_len);
-        else
-            LogNetData(log, payload, payload_len, p);
-    }
-    else if (SnortConfig::verbose_byte_dump())
-    {
-        uint8_t buf[UINT16_MAX];
-        uint16_t dlen = p->data - p->pkt;
-
-        SafeMemcpy(buf, p->pkt, dlen, buf, buf + sizeof(buf));
-        SafeMemcpy(buf + dlen, payload, payload_len,
-            buf, buf + sizeof(buf));
-
-        LogNetData(log, buf, dlen + payload_len, p);
-    }
-
-    free(payload);
-    return 0;
-}
-#endif
-
 /*--------------------------------------------------------------------
  * Function: LogIPPkt(TextLog*, int, Packet *)
  *
@@ -1506,14 +1466,6 @@ void LogIPPkt(TextLog* log, Packet* p)
 
 void LogPayload(TextLog* log, Packet* p)
 {
-#ifdef BUILD_OBFUSCATION
-    if ((p->dsize > 0) && obApi->payloadObfuscationRequired(p)
-        && (LogObfuscatedData(log, p) == 0))
-    {
-        return;
-    }
-#endif
-
     /* dump the application layer data */
     if (SnortConfig::output_app_data() && !SnortConfig::verbose_byte_dump())
     {
diff --git a/src/log/obfuscation.cc b/src/log/obfuscation.cc
deleted file mode 100644 (file)
index 2855c13..0000000
+++ /dev/null
@@ -1,1403 +0,0 @@
-//--------------------------------------------------------------------------
-// Copyright (C) 2014-2016 Cisco and/or its affiliates. All rights reserved.
-// Copyright (C) 2009-2013 Sourcefire, Inc.
-//
-// This program is free software; you can redistribute it and/or modify it
-// under the terms of the GNU General Public License Version 2 as published
-// by the Free Software Foundation.  You may not use, modify or distribute
-// this program under any other version of the GNU General Public License.
-//
-// This program is distributed in the hope that it will be useful, but
-// WITHOUT ANY WARRANTY; without even the implied warranty of
-// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
-// General Public License for more details.
-//
-// You should have received a copy of the GNU General Public License along
-// with this program; if not, write to the Free Software Foundation, Inc.,
-// 51 Franklin Street, Fifth Floor, Boston, MA  02110-1301, USA.
-//--------------------------------------------------------------------------
-
-#include "obfuscation.h"
-
-#ifdef HAVE_CONFIG_H
-#include "config.h"
-#endif
-
-extern "C" {
-#include <daq.h>
-}
-
-#include "main/snort_types.h"
-#include "main/snort_debug.h"
-#include "protocols/packet.h"
-#include "stream/stream_api.h"
-#include "main/thread.h"
-#include "utils/snort_bounds.h"
-#include "utils/util.h"
-
-#ifdef OBFUSCATION_TEST_STANDALONE
-# ifndef OBFUSCATION_TEST
-#  define OBFUSCATION_TEST
-# endif
-static int TraverseReassembled(
-    Packet*,
-    int (*)(DAQ_PktHdr_t*, uint8_t*, uint8_t*, uint32_t, void*),
-    void*
-);
-#endif
-
-/*******************************************************************************
- * Macros
- ******************************************************************************/
-#define OBFUSCATE_ENTRIES         512
-#define OBFUSCATE_MAXLEN_ENTRIES    8
-#define OBFUSCATE_SLICE_ENTRIES   (OBFUSCATE_ENTRIES - OBFUSCATE_MAXLEN_ENTRIES)
-
-/*******************************************************************************
- * Data structures
- ******************************************************************************/
-typedef struct _ObfuscationEntry
-{
-    Packet* p;
-    ob_size_t offset;
-    ob_size_t length;
-    ob_char_t ob_char;
-} ObfuscationEntry;
-
-typedef struct _ObfuscationStruct
-{
-    int num_entries;
-    int num_maxlen_entries;
-    int sorted;
-    ObfuscationEntry entries[OBFUSCATE_ENTRIES];
-    ObfuscationEntry* sort_entries[OBFUSCATE_ENTRIES];
-    ObfuscationEntry* maxlen_entries[OBFUSCATE_MAXLEN_ENTRIES];
-} ObfuscationStruct;
-
-typedef struct _ObfuscationCallbackData
-{
-    const Packet* packet;
-    ObfuscationCallback user_callback;
-    void* user_data;
-    int entry_index;
-    ob_size_t total_offset;
-} ObfuscationCallbackData;
-
-typedef struct _ObfuscationStreamCallbackData
-{
-    ObfuscationCallbackData* data;
-    uint32_t next_seq;
-    int last_entry_index;
-} ObfuscationStreamCallbackData;
-
-typedef struct _ObfuscatedPayload
-{
-    uint8_t** payload;
-    ob_size_t* payload_len;
-    ob_size_t payload_size;
-} ObfuscatedPayload;
-
-/*******************************************************************************
- * Globals
- ******************************************************************************/
-static THREAD_LOCAL ObfuscationStruct ob_struct;
-
-/*******************************************************************************
- * Private function prototypes
- ******************************************************************************/
-static inline int PayloadObfuscationRequired(Packet*);
-
-static inline void SortObfuscationEntries(void);
-
-static inline void SetObfuscationCallbackData(
-    ObfuscationCallbackData*, Packet*, ObfuscationCallback, void*);
-
-static ObRet AddObfuscationEntry(Packet*, ob_size_t, ob_size_t, ob_char_t);
-static int ObfuscationEntrySort(const void*, const void*);
-
-static ObRet TraverseObfuscationList(ObfuscationCallbackData*,
-    const DAQ_PktHdr_t*, const uint8_t*, ob_size_t);
-
-static ObRet GetObfuscatedPayloadCallback(const DAQ_PktHdr_t*,
-    const uint8_t*, ob_size_t, ob_char_t, void*);
-
-static void PrintObfuscationEntry(const ObfuscationEntry*, int);
-
-/*******************************************************************************
- * API prototypes
- ******************************************************************************/
-static void OB_API_ResetObfuscationEntries(void);
-static ObRet OB_API_AddObfuscationEntry(Packet*, ob_size_t,
-ob_size_t, ob_char_t);
-static int OB_API_PayloadObfuscationRequired(Packet*);
-static ObRet OB_API_ObfuscatePacket(Packet*, ObfuscationCallback, void*);
-static ObRet OB_API_ObfuscatePacketStreamSegments(Packet*,
-ObfuscationCallback, void*);
-static ObRet OB_API_GetObfuscatedPayload(Packet*, uint8_t**, ob_size_t*);
-static void OB_API_PrintObfuscationEntries(int);
-
-/* API accessor */
-ObfuscationApi obfuscationApi =
-{
-    OB_API_ResetObfuscationEntries,        // resetObfuscationEntries
-    OB_API_AddObfuscationEntry,            // addObfuscationEntry
-    OB_API_PayloadObfuscationRequired,     // payloadObfuscationRequired
-    OB_API_ObfuscatePacket,                // obfuscatePacket
-    OB_API_ObfuscatePacketStreamSegments,  // obfuscatePacketStreamSegments
-    OB_API_GetObfuscatedPayload,           // getObfuscatedPayload
-    OB_API_PrintObfuscationEntries         // printObfuscationEntries
-};
-
-ObfuscationApi* obApi = &obfuscationApi;
-
-/*******************************************************************************
- * API Function definitions
- ******************************************************************************/
-// resetObfuscationEntries
-void OB_API_ResetObfuscationEntries(void)
-{
-    ob_struct.num_entries = 0;
-    ob_struct.num_maxlen_entries = 0;
-    ob_struct.sorted = 0;
-}
-
-// addObfuscationEntry
-static ObRet OB_API_AddObfuscationEntry(Packet* p, ob_size_t offset,
-    ob_size_t length, ob_char_t ob_char)
-{
-    if (p == NULL)
-        return OB_RET_ERROR;
-
-    p->packet_flags |= PKT_PAYLOAD_OBFUSCATE;
-
-    return AddObfuscationEntry(p, offset, length, ob_char);
-}
-
-// payloadObfuscationRequired
-static int OB_API_PayloadObfuscationRequired(Packet* p)
-{
-    return PayloadObfuscationRequired(p);
-}
-
-// obfuscatePacket
-static ObRet OB_API_ObfuscatePacket(Packet* p,
-    ObfuscationCallback user_callback, void* user_data)
-{
-    ObfuscationCallbackData callback_data;
-
-    if (!PayloadObfuscationRequired(p))
-        return OB_RET_ERROR;
-
-    SortObfuscationEntries();
-    SetObfuscationCallbackData(&callback_data, p, user_callback, user_data);
-
-    /* Send header information first - isn't obfuscated */
-    if (user_callback(p->pkth, p->pkt, (ob_size_t)(p->data - p->pkt),
-        0, user_data) != OB_RET_SUCCESS)
-    {
-        return OB_RET_ERROR;
-    }
-
-    if (TraverseObfuscationList(&callback_data, NULL, p->data,
-        (ob_size_t)(p->pkth->caplen - (p->data - p->pkt))) != OB_RET_SUCCESS)
-    {
-        return OB_RET_ERROR;
-    }
-
-    return OB_RET_SUCCESS;
-}
-
-// obfuscatePacketStreamSegments
-// FIXIT-L traverse_reassembled() deleted
-// this should also be deleted if it is no longer needed
-static ObRet OB_API_ObfuscatePacketStreamSegments(Packet*,
-    ObfuscationCallback, void*)
-{
-    return OB_RET_ERROR;
-}
-
-// getObfuscatedPayload
-static ObRet OB_API_GetObfuscatedPayload(Packet* p,
-    uint8_t** payload, ob_size_t* payload_len)
-{
-    ObfuscationCallbackData callback_data;
-    ObfuscatedPayload user_data;
-
-    if (!PayloadObfuscationRequired(p))
-        return OB_RET_ERROR;
-
-    if ((payload == NULL) || (payload_len == NULL))
-        return OB_RET_ERROR;
-
-    *payload = NULL;
-    *payload_len = 0;
-
-    user_data.payload = payload;
-    user_data.payload_len = payload_len;
-    user_data.payload_size = 0;
-
-    SortObfuscationEntries();
-    SetObfuscationCallbackData(&callback_data, p,
-        GetObfuscatedPayloadCallback, (void*)&user_data);
-
-    if (TraverseObfuscationList(&callback_data, NULL, p->data,
-        (ob_size_t)(p->pkth->caplen - (p->data - p->pkt))) != OB_RET_SUCCESS)
-    {
-        return OB_RET_ERROR;
-    }
-
-    return OB_RET_SUCCESS;
-}
-
-// printObfuscationEntries
-static void OB_API_PrintObfuscationEntries(int sorted)
-{
-    int i;
-    ObfuscationEntry* entry;
-
-    if (sorted)
-        SortObfuscationEntries();
-
-    for (i = 0; i < ob_struct.num_entries; i++)
-    {
-        LogMessage("Entry: %d\n", i);
-
-        if (sorted)
-            entry = ob_struct.sort_entries[i];
-        else
-            entry = &ob_struct.entries[i];
-
-        PrintObfuscationEntry(entry, 2);
-    }
-}
-
-/*******************************************************************************
- * Private function definitions
- ******************************************************************************/
-
-/*******************************************************************************
- * Function: NumObfuscateMaxLenEntries()
- *
- * Gets the number of current OB_LENGTH_MAX entries that have been added.
- *
- * Arguments
- *  None
- *
- * Returns
- *  The number of current OB_LENGTH_MAX entries.
- *
- ******************************************************************************/
-static inline int NumObfuscateMaxLenEntries(void)
-{
-    return ob_struct.num_maxlen_entries;
-}
-
-/*******************************************************************************
- * Function: NumObfuscateSliceEntries()
- *
- * Gets the number of current slice entries that have been added.
- *
- * Arguments
- *  None
- *
- * Returns
- *  The number of current slice entries.
- *
- ******************************************************************************/
-static inline int NumObfuscateSliceEntries(void)
-{
-    return ob_struct.num_entries - ob_struct.num_maxlen_entries;
-}
-
-/*******************************************************************************
- * Function: ObfuscationEntryOverflow()
- *
- * Determines whether or not there is enough space in the static entry array to
- * add another obfucation entry.
- *
- * Arguments
- *  ob_size_t
- *   The length of the entry that should be added.  If length is OB_LENGTH_MAX
- *   then the max length array is checked.
- *
- * Returns
- *  OB_RET_SUCCESS  if the entry can be added
- *  OB_RET_OVERFLOW  if there isn't enough space to add another entry
- *
- ******************************************************************************/
-static inline ObRet ObfuscationEntryOverflow(ob_size_t length)
-{
-    if (length == OB_LENGTH_MAX)
-    {
-        if (NumObfuscateMaxLenEntries() >= OBFUSCATE_MAXLEN_ENTRIES)
-            return OB_RET_OVERFLOW;
-    }
-    else
-    {
-        if (NumObfuscateSliceEntries() >= OBFUSCATE_SLICE_ENTRIES)
-            return OB_RET_OVERFLOW;
-    }
-
-    return OB_RET_SUCCESS;
-}
-
-/*******************************************************************************
- * Function: PayloadObfuscationRequired()
- *
- * Determines whether or not the packet requires obfuscation.  An obfuscation
- * flag is added to the packet flags when an obfuscation entry is added that
- * is associated with the packet.  If there isn't any data, then it doesn't
- * need obfuscation.
- *
- * Arguments
- *  Packet *p
- *   The Packet to check
- *
- * Returns
- *  0  if obfuscation is not needed.
- *  1  if the packet has been flagged for obfuscation.
- *
- ******************************************************************************/
-static inline int PayloadObfuscationRequired(Packet* p)
-{
-    if ((p == NULL) || (p->pkth == NULL)
-        || (p->pkt == NULL) || (p->data == NULL)
-        || (p->pkt >= p->data)
-        || ((ob_size_t)(p->data - p->pkt) > p->pkth->caplen))
-    {
-        return 0;
-    }
-
-    if (!(p->packet_flags & PKT_PAYLOAD_OBFUSCATE)
-        || (ob_struct.num_entries == 0))
-    {
-        return 0;
-    }
-
-    return 1;
-}
-
-/*******************************************************************************
- * Function: SetObfuscationEntry()
- *
- * Initializes an obfuscation entry with the passed in values.
- *
- * Arguments
- *  ObfuscationEntry *entry
- *   The obfuscation entry to initialize
- *  Packet *p
- *   The Packet to associate with this entry
- *  ob_size_t offset
- *   The offset into the packet to start obfuscation
- *  ob_size_t length
- *   The amount of data to obfuscate starting from offset
- *  ob_char_t ob_char
- *   The character to use when obfuscating
- *
- * Returns
- *  None
- *
- ******************************************************************************/
-static inline void SetObfuscationEntry(ObfuscationEntry* entry,
-    Packet* p, ob_size_t offset, ob_size_t length, ob_char_t ob_char)
-{
-    if (entry == NULL)
-        return;
-
-    entry->p = p;
-    entry->offset = offset;
-    entry->length = length;
-    entry->ob_char = ob_char;
-}
-
-/*******************************************************************************
- * Function: SetObfuscationCallbackData()
- *
- * Initializes the callback data for use in TraverseObfuscationList.
- *
- * Arguments
- *  ObfuscationCallbackData *callback_data
- *   The callback data struct to initialize
- *  Packet *p
- *   The Packet to associate with this entry
- *  ob_size_t offset
- *   The offset into the packet to start obfuscation
- *  ob_size_t length
- *   The amount of data to obfuscate starting from offset
- *  ob_char_t ob_char
- *   The character to use when obfuscating
- *
- * Returns
- *  None
- *
- ******************************************************************************/
-static inline void SetObfuscationCallbackData(
-    ObfuscationCallbackData* callback_data, Packet* packet,
-    ObfuscationCallback user_callback, void* user_data)
-{
-    if (callback_data == NULL)
-        return;
-
-    callback_data->packet = packet;
-    callback_data->user_callback = user_callback;
-    callback_data->user_data = user_data;
-    callback_data->entry_index = 0;
-    callback_data->total_offset = 0;
-}
-
-/*******************************************************************************
- * Function: SetObfuscationStreamCallbackData()
- *
- * Initializes the callback data for use in TraverseObfuscationList.
- *
- * Arguments
- *  ObfuscationStreamCallbackData *stream_callback_data
- *   The stream callback data struct to initialize
- *  ObfuscationCallbackData *callback_data
- *   The callback data struct to initialize
- *  Packet *p
- *   The Packet to associate with this entry
- *  ob_size_t offset
- *   The offset into the packet to start obfuscation
- *  ob_size_t length
- *   The amount of data to obfuscate starting from offset
- *  ob_char_t ob_char
- *   The character to use when obfuscating
- *
- * Returns
- *  None
- *
- ******************************************************************************/
-#if 0
-static inline void SetObfuscationStreamCallbackData(
-    ObfuscationStreamCallbackData* stream_callback_data,
-    ObfuscationCallbackData* callback_data, Packet* packet,
-    ObfuscationCallback user_callback, void* user_data)
-{
-    if ((stream_callback_data == NULL) || (callback_data == NULL))
-        return;
-
-    SetObfuscationCallbackData(callback_data, packet, user_callback, user_data);
-    stream_callback_data->data = callback_data;
-    stream_callback_data->next_seq = 0;
-    stream_callback_data->last_entry_index = 0;
-}
-#endif
-
-/*******************************************************************************
- * Function: SortObfuscationEntries()
- *
- * Uses qsort to sort the entries that have been added.  Possibly qsort is not
- * the most efficient sort here since, in general, the entries will be added
- * from smallest offset to largest.
- *
- * Arguments
- *  None
- *
- * Returns
- *  None
- *
- ******************************************************************************/
-static inline void SortObfuscationEntries(void)
-{
-    if (!ob_struct.sorted)
-    {
-        qsort((void*)ob_struct.sort_entries, ob_struct.num_entries,
-            sizeof(ObfuscationEntry*), ObfuscationEntrySort);
-        ob_struct.sorted = 1;
-    }
-}
-
-/*******************************************************************************
- * Function: AddObfuscationEntry()
- *
- * Adds an obfuscation entry to the obfuscation list.  OB_LENGTH_MAX entries
- * are first checked to see if there is an entry already associated with
- * the Packet passed in.  If there is, the entry with the lesser of the two
- * offsets is used.
- *
- * Arguments
- *  Packet *p
- *   The Packet to be associated with this entry
- *  ob_size_t offset
- *   The offset into the payload of this packet to start obfuscating
- *  ob_size_t length
- *   The length of the payload starting at offset to obfuscate
- *  ob_char_t
- *   The character to use when obfuscating
- *
- * Returns
- *  OB_RET_SUCCESS  if the entry was successfully added
- *  OB_RET_OVERFLOW  if there is no room left to store the entry
- *
- ******************************************************************************/
-static ObRet AddObfuscationEntry(Packet* p, ob_size_t offset,
-    ob_size_t length, ob_char_t ob_char)
-{
-    ObfuscationEntry* entry;
-    int entry_index = ob_struct.num_entries;
-
-    if (length == OB_LENGTH_MAX)
-    {
-        int i;
-
-        /* Check to see if there is an OB_LENGTH_MAX entry already associated
-         * with this packet */
-        for (i = 0; i < ob_struct.num_maxlen_entries; i++)
-        {
-            entry = ob_struct.maxlen_entries[i];
-            if (entry->p == p)
-            {
-                /* Already have an entry for this packet.  Use the entry with
-                 * the lesser of the two offsets */
-                if (offset < entry->offset)
-                {
-                    entry->offset = offset;
-                    entry->ob_char = ob_char;
-                }
-
-                return OB_RET_SUCCESS;
-            }
-        }
-    }
-
-    if (ObfuscationEntryOverflow(length) != OB_RET_SUCCESS)
-        return OB_RET_OVERFLOW;
-
-    /* Reset sorted since we're adding an entry and the list will need
-     * to be sorted again */
-    ob_struct.sorted = 0;
-
-    /* Get the entry at the current index */
-    entry = &ob_struct.entries[entry_index];
-    SetObfuscationEntry(entry, p, offset, length, ob_char);
-
-    ob_struct.sort_entries[entry_index] = entry;
-    ob_struct.num_entries++;
-
-    if (length == OB_LENGTH_MAX)
-    {
-        ob_struct.maxlen_entries[ob_struct.num_maxlen_entries] = entry;
-        ob_struct.num_maxlen_entries++;
-    }
-
-    return OB_RET_SUCCESS;
-}
-
-/*******************************************************************************
- * Function: ObfuscationEntrySort()
- *
- * Sorting callback.  Sorted by offset, then length if the offsets are the same.
- *
- * Arguments
- *  const void *data1
- *   The compare to argument
- *  const void *data2
- *   The argument to compare to the first argument
- *
- * Returns
- *  -1  if the first ObfuscationEntry is considered less than the second
- *   1  if the first ObfuscationEntry is considered greater than the second
- *   0  if both offset and length are equal
- *
- ******************************************************************************/
-static int ObfuscationEntrySort(const void* data1, const void* data2)
-{
-    ObfuscationEntry* ob1 = *((ObfuscationEntry**)data1);
-    ObfuscationEntry* ob2 = *((ObfuscationEntry**)data2);
-
-    if (ob1->offset < ob2->offset)
-        return -1;
-    else if (ob1->offset > ob2->offset)
-        return 1;
-    else if (ob1->length < ob2->length)
-        return -1;
-    else if (ob1->length > ob2->length)
-        return 1;
-
-    return 0;
-}
-
-/*******************************************************************************
- * Function: TraverseObfuscationList()
- *
- * This is the main function for obfuscating a payload or stream segments.
- * It walks through a packet and obfuscation entries, calling the user
- * callback with obfuscated and non-obfuscated instructions.
- *
- * Arguments
- *  ObfuscationCallbackData *data
- *   The state tracking data structure.  Has the packet being obfuscated,
- *   current obfuscation entry and total number of bytes obfuscated thus
- *   far.
- *  DAQ_PktHdr_t *pkth
- *   The pcap header information associated with the payload being
- *   obfuscated.
- *  uint8_t *pkt
- *   The start of the packet including Ethernet headers, etc.
- *  uint8_t *payload
- *   Pointer to the payload data to be obfuscated
- *  ob_size_t
- *   The size of the payload data
- *
- * Returns
- *  OB_RET_SUCCESS  if successfully completed
- *  OB_RET_ERROR  if the user callback doesn't return OB_RET_SUCCESS
- *
- ******************************************************************************/
-static ObRet TraverseObfuscationList(ObfuscationCallbackData* data,
-    const DAQ_PktHdr_t* pkth, const uint8_t* payload_data,
-    ob_size_t payload_size)
-{
-    int i;
-    ob_size_t total_offset = data->total_offset;
-    ob_size_t payload_offset = 0;
-    const DAQ_PktHdr_t* pkth_tmp = pkth;
-#ifdef OBFUSCATION_TEST
-    uint8_t print_array[OB_LENGTH_MAX];
-    ob_size_t start_total_offset = 0;
-    ob_size_t start_payload_offset = 0;
-#endif
-
-    if ((payload_data == NULL) || (payload_size == 0))
-        return OB_RET_ERROR;
-
-#ifdef OBFUSCATION_TEST
-    LogMessage("Payload data: %u bytes\n", payload_size);
-    LogMessage("==============================================================="
-        "=================\n");
-#endif
-
-    /* Start from current saved obfuscation entry index */
-    for (i = data->entry_index; i < ob_struct.num_entries; i++)
-    {
-        /* Get the entry from the sorted array */
-        const ObfuscationEntry* entry = ob_struct.sort_entries[i];
-        ob_size_t ob_offset = entry->offset;
-        ob_size_t ob_length = entry->length;
-
-        /* Make sure it's for the right packet */
-        if (entry->p != data->packet)
-        {
-#ifdef OBFUSCATION_TEST
-            LogMessage("flags1: %08x, flags2: %08x\n", entry->p->packet_flags,
-                data->packet->packet_flags);
-#endif
-            continue;
-        }
-
-        /* We've already obfuscated this part of the packet payload
-         * Account for overflow */
-        if (((ob_offset + ob_length) <= total_offset)
-            && ((ob_offset + ob_length) > ob_offset))
-        {
-            continue;
-        }
-
-#ifdef OBFUSCATION_TEST
-        LogMessage("  Total offset: %u\n\n", total_offset);
-        start_total_offset = total_offset;
-        start_payload_offset = payload_offset;
-#endif
-
-        /* Note the obfuscation offset is only used at this point to determine
-         * the amount of data that does not need to be obfuscated up to the
-         * offset or the length of what needs to be obfuscated if the offset
-         * is less than what's already been logged */
-
-        if (ob_offset > total_offset)
-        {
-            /* Get the amount of non-obfuscated data - need to log straight
-             * packet data up to obfuscation offset */
-            ob_size_t length = ob_offset - total_offset;
-
-            /* If there is more length than what's left in the packet,
-             * truncate it, do we don't overflow */
-            if (length > (payload_size - payload_offset))
-                length = payload_size - payload_offset;
-
-            /* Call the user callback and tell it not to obfuscate the data
-             * by passing in a non-NULL packet pointer */
-            if (data->user_callback(pkth_tmp, payload_data + payload_offset,
-                length, 0, data->user_data) != OB_RET_SUCCESS)
-            {
-                return OB_RET_ERROR;
-            }
-
-#ifdef OBFUSCATION_TEST
-            SafeMemcpy(print_array + payload_offset, payload_data + payload_offset,
-                length, print_array, print_array + sizeof(print_array));
-#endif
-            /* Only the first payload call sends the pcap_pkthdr */
-            pkth_tmp = NULL;
-
-            /* Adjust offsets */
-            payload_offset += length;
-            total_offset += length;
-
-            /* If there is no more packet data, break out of the loop */
-            if (payload_offset == payload_size)
-            {
-#ifdef OBFUSCATION_TEST
-                PrintPacketData(print_array + start_payload_offset, length);
-                LogMessage("\n");
-#endif
-                break;
-            }
-        }
-        else if (ob_offset < total_offset)
-        {
-            /* If the entries offset is less than the current total offset,
-             * decrease the length. */
-            ob_length -= (total_offset - ob_offset);
-        }
-
-        /* Adjust the amount of data to obfuscate if it exceeds the amount of
-         * data left in the packet.  Account for overflow */
-        if (((payload_offset + ob_length) > payload_size)
-            || ((payload_offset + ob_length) <= payload_offset))
-        {
-            ob_length = payload_size - payload_offset;
-        }
-
-        /* Call the user callback and tell it to obfuscate the data by passing
-         * in a NULL packet pointer */
-        if (data->user_callback(pkth_tmp, NULL, ob_length,
-            entry->ob_char, data->user_data) != OB_RET_SUCCESS)
-        {
-            return OB_RET_ERROR;
-        }
-
-#ifdef OBFUSCATION_TEST
-        LogMessage("  Entry: %d\n", i);
-        LogMessage("  --------------------------\n");
-        PrintObfuscationEntry(entry, 4);
-        LogMessage("\n");
-
-        SafeMemset(print_array + payload_offset, entry->ob_char,
-            ob_length, print_array, print_array + sizeof(print_array));
-
-        if (ob_length < entry->length)
-        {
-            if (ob_offset < start_total_offset)
-            {
-                if (payload_offset + ob_length == payload_size)
-                {
-                    LogMessage("  Obfuscating beyond already obfuscated "
-                        "(%u bytes) and to end of payload: %u bytes\n\n",
-                        (start_total_offset - ob_offset), ob_length);
-                }
-                else
-                {
-                    LogMessage("  Obfuscating beyond already obfuscated "
-                        "(%u bytes): %u bytes\n\n",
-                        (start_total_offset - ob_offset), ob_length);
-                }
-            }
-            else
-            {
-                LogMessage("  Obfuscating to end of payload: "
-                    "%u bytes\n\n", ob_length);
-            }
-        }
-        else
-        {
-            LogMessage("  Obfuscating: %u bytes\n\n", ob_length);
-        }
-
-        PrintPacketData(print_array + start_payload_offset,
-            (payload_offset - start_payload_offset) + ob_length);
-
-        if (((entry->offset + entry->length) - (total_offset + ob_length)) > 0)
-        {
-            LogMessage("\n  Remaining amount to obfuscate: %u bytes\n",
-                (entry->offset + entry->length) - (total_offset + ob_length));
-        }
-
-        LogMessage("\n");
-#endif
-
-        /* Only the first payload call sends the pcap_pkthdr */
-        pkth_tmp = NULL;
-
-        /* Adjust offsets */
-        payload_offset += ob_length;
-        total_offset += ob_length;
-
-        /* If there is no more packet data, break out of the loop */
-        if (payload_offset == payload_size)
-            break;
-    }
-
-    /* There's more data in the packet left, meaning we ran out of
-     * obfuscation entries */
-    if (payload_size > payload_offset)
-    {
-        ob_size_t length = payload_size - payload_offset;
-
-        /* Call the user callback and tell it not to obfuscate the data
-         * by passing in a non-NULL packet pointer */
-        if (data->user_callback(pkth_tmp, payload_data + payload_offset,
-            length, 0, data->user_data) != OB_RET_SUCCESS)
-        {
-            return OB_RET_ERROR;
-        }
-
-#ifdef OBFUSCATION_TEST
-        SafeMemcpy(print_array + payload_offset, payload_data + payload_offset,
-            length, print_array, print_array + sizeof(print_array));
-#endif
-
-        /* Adjust offsets - don't need to adjust packet offset since
-         * we're done with the packet */
-        total_offset += length;
-    }
-
-#ifdef OBFUSCATION_TEST
-    LogMessage("Obfuscated payload\n");
-    LogMessage("~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"
-        "~~~~~~~~~~\n");
-    PrintPacketData(print_array, payload_size);
-    LogMessage("\n\n");
-#endif
-
-    /* Save these for next time we come in if necessary.  Mainly for
-     * traversing stream segments */
-    data->entry_index = i;
-    data->total_offset = total_offset;
-
-    return OB_RET_SUCCESS;
-}
-
-/*******************************************************************************
- * Function: GetObfuscationPayloadCallback()
- *
- * ObfuscationCallback for returning an allocated obfuscated payload.
- *
- * Arguments
- *  DAQ_PktHdr_t *pkth
- *   The pcap header information associated with the payload being
- *   obfuscated.
- *  uint8_t *packet_data
- *   Pointer to the packet data to be obfuscated
- *  ob_char_t ob_char
- *   The obfuscation character
- *  ob_size_t length
- *   The length of the portion of packet payload to use
- *  void *user_data
- *   The ObfuscatedPayload data
- *
- * Returns
- *  OB_RET_ERROR  if copying obfuscation data is not successful
- *  OB_RET_SUCCESS  if successful copying data to payload
- *
- ******************************************************************************/
-static ObRet GetObfuscatedPayloadCallback(
-    const DAQ_PktHdr_t*, const uint8_t* packet_data,
-    ob_size_t length, ob_char_t ob_char, void* user_data)
-{
-    ObfuscatedPayload* ob_payload = (ObfuscatedPayload*)user_data;
-    uint8_t* payload;
-    ob_size_t payload_len, payload_size;
-
-    if (ob_payload == NULL)
-        return OB_RET_ERROR;
-
-    if ((ob_payload->payload == NULL) || (ob_payload->payload_len == NULL))
-        return OB_RET_ERROR;
-
-    payload = *ob_payload->payload;
-    payload_len = *ob_payload->payload_len;
-    payload_size = ob_payload->payload_size;
-
-    if ((payload_len + length) > payload_size)
-    {
-        /* Allocate extra so we don't have to reallocate every time in */
-        ob_size_t new_size = payload_len + length + 100;
-        uint8_t* tmp = (uint8_t*)SnortAlloc(new_size);
-
-        if (payload != NULL)
-        {
-            if (SafeMemcpy(tmp, payload, payload_len,
-                tmp, tmp + new_size) != SAFEMEM_SUCCESS)
-            {
-                free(tmp);
-                free(payload);
-                return OB_RET_ERROR;
-            }
-
-            free(payload);
-        }
-
-        payload_size = new_size;
-        ob_payload->payload_size = new_size;
-
-        *ob_payload->payload = tmp;
-        payload = tmp;
-    }
-
-    if (packet_data != NULL)
-    {
-        if (SafeMemcpy(payload + payload_len, packet_data, length,
-            payload, payload + payload_size) != SAFEMEM_SUCCESS)
-        {
-            free(payload);
-            return OB_RET_ERROR;
-        }
-    }
-    else
-    {
-        if (SafeMemset(payload + payload_len, (uint8_t)ob_char, length,
-            payload, payload + payload_size) != SAFEMEM_SUCCESS)
-        {
-            free(payload);
-            return OB_RET_ERROR;
-        }
-    }
-
-    *ob_payload->payload_len += length;
-
-    return OB_RET_SUCCESS;
-}
-
-/*******************************************************************************
- * Function: PrintObfuscationEntry()
- *
- * Prints an obfuscation entry offsetted with optional leading whitespace.
- *
- * Arguments
- *  const ObfuscationEntry *entry
- *   The entry to print
- *  int leading_whitespace
- *   The amount of whitespace to use before printing a line.
- * Returns
- *  None
- *
- ******************************************************************************/
-static void PrintObfuscationEntry(const ObfuscationEntry* entry,
-    int leading_space)
-{
-    if (entry == NULL)
-        return;
-
-    LogMessage("%*sPacket: %p\n", leading_space, "", (void*)entry->p);
-    LogMessage("%*sOffset: %u\n", leading_space, "", entry->offset);
-    LogMessage("%*sLength: %u\n", leading_space, "", entry->length);
-    if (isgraph((int)entry->ob_char))
-        LogMessage("%*sOb char: \'%c\'\n", leading_space, "", entry->ob_char);
-    else
-        LogMessage("%*sOb char: 0x%02x\n", leading_space, "", entry->ob_char);
-}
-
-/******************************************************************************
- * Testing
- ******************************************************************************/
-#ifdef OBFUSCATION_TEST_STANDALONE
-
-#include <getopt.h>
-#include <time.h>
-#include <errno.h>
-#include <stdio.h>
-#include <stdlib.h>
-#include <string.h>
-
-#define PAYLOAD_ALLOC_SIZE  1024
-
-/* Used for standalone testing */
-struct Segment
-{
-    DAQ_PktHdr_t* pkth;
-    uint8_t* data;
-    uint16_t size;
-    Segment* next;
-};
-
-/* Used for standalone testing */
-struct ObPacket
-{
-    Packet p;
-    Segment* seglist;
-};
-
-static uint8_t* ob_payload = NULL;
-static void ObTestAlloc(void**, int, int);
-static void CreateObEntries(Packet*, ob_char_t, ob_size_t,
-ob_size_t, int, int);
-static ObRet ObCallback(DAQ_PktHdr_t*, uint8_t*, ob_char_t,
-ob_size_t, void*);
-static uint8_t* GetPayloadFromFile(char*, ob_size_t*);
-
-static int TraverseReassembled(Packet* p,
-    int (* callback)(DAQ_PktHdr_t*, uint8_t*, void*),
-    void* user_data)
-{
-    ObfuscationCallbackData* callback_data =
-        (ObfuscationCallbackData*)user_data;
-    int segments = 0;
-    Segment* seg;
-    ObPacket* op = (ObPacket*)p;
-
-    for (seg = op->seglist; seg != NULL; seg = seg->next)
-    {
-        if (callback(seg->pkth, seg->data, user_data) != 0)
-            return segments;
-        segments++;
-    }
-
-    return segments;
-}
-
-static void ObTestAlloc(void** ptr, int ptr_size, int this_size)
-{
-    if (ptr == NULL)
-        return;
-
-    if (*ptr == NULL)
-    {
-        *ptr = calloc(1, this_size);
-        if (*ptr == NULL)
-        {
-            fprintf(stderr, "Failed to allocate memory for payload.\n");
-            exit(1);
-        }
-    }
-    else
-    {
-        if (this_size > ptr_size)
-        {
-            *ptr = realloc(*ptr, this_size);
-            if (*ptr == NULL)
-            {
-                fprintf(stderr, "Failed to allocate memory for payload.\n");
-                exit(1);
-            }
-        }
-    }
-}
-
-static void CreateObEntries(Packet* p, ob_char_t ob_char,
-    ob_size_t ob_offset, ob_size_t ob_length, int reverse, int add_maxlen)
-{
-    typedef struct _ob_tmp_struct
-    { ob_size_t offset; ob_size_t length; } ob_tmp_struct_t;
-
-    ob_size_t offset;
-    ob_tmp_struct_t* tmp_struct = NULL;
-    int num_tmps = 0;
-    int i;
-
-    if (p == NULL)
-        return;
-
-    for (offset = (rand() % ob_offset) + 1;
-        offset < (p->dsize - ob_offset);
-        offset += (rand() % ob_offset) + 1)
-    {
-        ob_size_t length = rand() % ob_length + 1;
-
-        ObTestAlloc((void**)&tmp_struct, sizeof(ob_tmp_struct_t) * num_tmps,
-            sizeof(ob_tmp_struct_t) * (num_tmps + 1));
-        tmp_struct[num_tmps].offset = offset;
-        tmp_struct[num_tmps].length = length;
-        num_tmps++;
-
-        if (add_maxlen && (offset > p->dsize/2))
-            obApi->addObfuscationEntry(p, offset, OB_LENGTH_MAX, ob_char);
-
-        if ((offset + length) >= p->dsize)
-            break;
-    }
-
-    if (reverse)
-    {
-        for (i = num_tmps - 1; i >= 0; i--)
-        {
-            obApi->addObfuscationEntry(p, tmp_struct[i].offset,
-                tmp_struct[i].length, ob_char);
-        }
-    }
-    else
-    {
-        for (i = 0; i < num_tmps; i++)
-        {
-            obApi->addObfuscationEntry(p, tmp_struct[i].offset,
-                tmp_struct[i].length, ob_char);
-        }
-    }
-}
-
-static ObRet ObCallback(DAQ_PktHdr_t* pkth, uint8_t* packet_data,
-    ob_char_t ob_char, ob_size_t length, void* user_data)
-{
-    ob_size_t* offset = (ob_size_t*)user_data;
-
-    if (packet_data != NULL)
-        memcpy(ob_payload + *offset, packet_data, length);
-    else
-        memset(ob_payload + *offset, ob_char, length);
-
-    *offset += length;
-    return OB_RET_SUCCESS;
-}
-
-static uint8_t* GetPayloadFromFile(char* payload_file, ob_size_t* payload_bytes)
-{
-    uint8_t* payload = NULL;
-    FILE* fp;
-    ob_size_t bytes;
-
-    if (payload_bytes == NULL)
-        return NULL;
-
-    *payload_bytes = 0;
-
-    fp = fopen(payload_file, "r");
-    if (fp == NULL)
-    {
-        fprintf(stderr, "Could not open payload file \"%s\": %s\n",
-            payload_file, get_error(errno));
-        exit(1);
-    }
-
-    ObTestAlloc((void**)&payload, 0, PAYLOAD_ALLOC_SIZE);
-    while ((bytes = fread(payload + *payload_bytes, sizeof(char),
-            PAYLOAD_ALLOC_SIZE, fp)) == PAYLOAD_ALLOC_SIZE)
-    {
-        ObTestAlloc((void**)&payload, *payload_bytes + bytes,
-            *payload_bytes + bytes + bytes);
-        *payload_bytes += bytes;
-    }
-
-    *payload_bytes += bytes;
-    if (*payload_bytes > OB_LENGTH_MAX)
-        *payload_bytes = OB_LENGTH_MAX;
-
-    return payload;
-}
-
-static uint8_t* GetStaticPayload(ob_char_t ob_char, ob_size_t* payload_bytes)
-{
-    uint8_t* payload = NULL;
-    ob_size_t alloc_size = 1000;
-    ob_char_t char1 = 0x00;
-    ob_char_t char2 = 0x01;
-    ob_char_t c = char1;
-
-    if (c == ob_char)
-        c = char2;
-
-    ObTestAlloc((void**)&payload, 0, alloc_size);
-    memset(payload, c, alloc_size);
-
-    *payload_bytes = alloc_size;
-    return payload;
-}
-
-static void SegmentPayload(Packet* p)
-{
-    ob_size_t length;
-    ob_size_t i;
-    Segment* last;
-    ObPacket* op = (ObPacket*)p;
-
-    for (i = 0; i < p->dsize; i += length)
-    {
-        Segment* seg = NULL;
-
-        length = rand() % 20 + 1;
-        if (i + length > p->dsize)
-            length = p->dsize - i;
-
-        ObTestAlloc((void**)&seg, 0, sizeof(Segment));
-        ObTestAlloc((void**)&seg->data, 0, length);
-        ObTestAlloc((void**)&seg->pkth, 0, sizeof(DAQ_PktHdr_t));
-
-        memcpy(seg->data, p->data + i, length);
-        seg->size = length;
-        seg->pkth->caplen = length;
-
-        if (op->seglist == NULL)
-        {
-            op->seglist = seg;
-            last = seg;
-        }
-        else
-        {
-            last->next = seg;
-            last = seg;
-        }
-
-        if ((i + length) == p->dsize)
-            break;
-    }
-}
-
-void PrintUsage(char* prog)
-{
-    fprintf(stderr, "Usage: %s [options]\n", prog);
-    fprintf(stderr, "  -a (add max length entry)\n");
-    fprintf(stderr, "  -c <obfuscation character>\n");
-    fprintf(stderr, "  -l <max obfuscation length>\n");
-    fprintf(stderr, "  -o <max obfuscation offset>\n");
-    fprintf(stderr, "  -p <payload file>\n");
-    fprintf(stderr, "  -s (use segmentation)\n");
-    fprintf(stderr, "  -r (reverse entries before sorting)\n");
-}
-
-int main(int argc, char* argv[])
-{
-    char c;
-    char* payload_file = NULL;
-    ob_char_t ob_char = 'X';
-    int segment = 0;
-    int reverse = 0;
-    int add_maxlen = 0;
-    ob_size_t ob_offset = 50;
-    ob_size_t ob_length = 16;
-    uint8_t* payload = NULL;
-    ob_size_t payload_bytes = 0;
-    ob_size_t offset = 0;
-    DAQ_PktHdr_t pkth, * pkthtmp;
-    Packet* tmp = PacketManager::encode_new();
-    Packet& packet = *tmp;
-
-    while ((c = getopt(argc, argv, "ac:l:o:p:rsh")) != -1)
-    {
-        switch (c)
-        {
-        case 'a':
-            add_maxlen = 1;
-            break;
-        case 'c':
-            ob_char = (ob_char_t)strtol(optarg, NULL, 0);
-            break;
-        case 'l':
-        {
-            int value;
-            if (!isdigit(optarg[0]))
-            {
-                PrintUsage(argv[0]);
-                fprintf(stderr, "Obfuscation max length must be a "
-                    "positive integer.\n");
-                exit(1);
-            }
-            value = atoi(optarg);
-            if (value > UINT16_MAX)
-            {
-                PrintUsage(argv[0]);
-                fprintf(stderr, "Obfuscation max length must be "
-                    "less than 65535.\n");
-                exit(1);
-            }
-            ob_length = (ob_size_t)value;
-        }
-        break;
-        case 'o':
-        {
-            int value;
-            if (!isdigit(optarg[0]))
-            {
-                PrintUsage(argv[0]);
-                fprintf(stderr, "Obfuscation offset must be a "
-                    "positive integer.\n");
-                exit(1);
-            }
-            value = atoi(optarg);
-            if (value > UINT16_MAX)
-            {
-                PrintUsage(argv[0]);
-                fprintf(stderr, "Obfuscation max offset must "
-                    "be less than 65535.\n");
-                exit(1);
-            }
-            ob_offset = (ob_size_t)value;
-        }
-        break;
-        case 'p':
-            payload_file = strdup(optarg);
-            if (payload_file == NULL)
-            {
-                PrintUsage(argv[0]);
-                fprintf(stderr, "Failed to copy payload file.\n");
-                exit(1);
-            }
-            break;
-        case 'r':
-            reverse = 1;
-            break;
-        case 's':
-            segment = 1;
-            break;
-        case 'h':
-            PrintUsage(argv[0]);
-            exit(0);
-        default:
-            PrintUsage(argv[0]);
-            fprintf(stderr, "Invalid option. Use -h for usage.\n");
-            exit(1);
-        }
-    }
-
-    srand(time(NULL));
-
-    if (payload_file != NULL)
-    {
-        payload = GetPayloadFromFile(payload_file, &payload_bytes);
-        if (payload == NULL)
-        {
-            fprintf(stderr, "Failed to get data from \"%s\"\n", payload_file);
-            exit(1);
-        }
-    }
-    else
-    {
-        payload = GetStaticPayload(ob_char, &payload_bytes);
-    }
-
-    ObTestAlloc((void**)&ob_payload, 0, payload_bytes);
-
-    obApi->resetObfuscationEntries();
-
-    packet.reset();
-    packet.pseudo_type = 0;
-    packet.user_policy_id = 0;
-    packet.iplist_id = 0;
-    packet.ps_proto = 0;
-    packet.disable_inspect = false;
-
-    pkthtmp = (DAQ_PktHdr_t*)&packet.pkth;
-    pkthtmp = &pkth;
-    pkthtmp->caplen = payload_bytes;
-    pkthtmp->ts.tv_sec = 0;
-    pkthtmp->ts.tv_usec = 0;
-
-    packet.packet_flags |= PKT_PAYLOAD_OBFUSCATE;
-    packet.data = payload;
-    packet.dsize = payload_bytes;
-
-    CreateObEntries(&packet, ob_char, ob_offset, ob_length,
-        reverse, add_maxlen);
-    //obApi->printObfuscationEntries();
-
-    if (segment)
-    {
-        SegmentPayload(&packet);
-        if (obApi->payloadObfuscationRequired(&packet))
-            obApi->obfuscateStreamSegments(&packet, ObCallback, &offset);
-    }
-    else
-    {
-        if (obApi->payloadObfuscationRequired(&packet))
-            obApi->obfuscatePayload(&packet, ObCallback, &offset);
-    }
-
-    free(payload);
-    free(ob_payload);
-    if (payload_file != NULL)
-        free(payload_file);
-
-    return 0;
-}
-
-#endif /* OBFUSCATION_TEST_STANDALONE */
-
diff --git a/src/log/obfuscation.h b/src/log/obfuscation.h
deleted file mode 100644 (file)
index c928f5f..0000000
+++ /dev/null
@@ -1,270 +0,0 @@
-//--------------------------------------------------------------------------
-// Copyright (C) 2014-2016 Cisco and/or its affiliates. All rights reserved.
-// Copyright (C) 2009-2013 Sourcefire, Inc.
-//
-// This program is free software; you can redistribute it and/or modify it
-// under the terms of the GNU General Public License Version 2 as published
-// by the Free Software Foundation.  You may not use, modify or distribute
-// this program under any other version of the GNU General Public License.
-//
-// This program is distributed in the hope that it will be useful, but
-// WITHOUT ANY WARRANTY; without even the implied warranty of
-// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
-// General Public License for more details.
-//
-// You should have received a copy of the GNU General Public License along
-// with this program; if not, write to the Free Software Foundation, Inc.,
-// 51 Franklin Street, Fifth Floor, Boston, MA  02110-1301, USA.
-//--------------------------------------------------------------------------
-
-#ifndef OBFUSCATION_H
-#define OBFUSCATION_H
-
-// BUILD_OBFUSCATION is not defined because nothing creates obfuscation
-// entries.  when sdf is ported, BUILD_OBFUSCATION should be deleted so the
-// full code is built.  at that time the api should be turned into an
-// obfuscator class and the test code should be replaced with actual unit
-// tests.  #ifdef BUILD_OBFUSCATION is used in detect.cc, log_text.cc, and
-// unified2.cc.
-
-extern "C" {
-#include <daq.h>
-}
-#include "main/snort_types.h"
-#include "protocols/packet.h"
-
-/*******************************************************************************
- * Macros
- ******************************************************************************/
-/* This should be defined to be greater than or equal to the maximum
- * amount of data expected to be obfuscated */
-#define OB_LENGTH_MAX  UINT16_MAX
-
-/*******************************************************************************
- * Types
- ******************************************************************************/
-typedef uint8_t ob_char_t;
-typedef uint16_t ob_size_t;
-
-typedef enum _ObRet
-{
-    OB_RET_SUCCESS,
-    OB_RET_ERROR,
-    OB_RET_OVERFLOW
-} ObRet;
-
-/*******************************************************************************
- * Callback to use for obfuscating payload or stream segments - see API below.
- *
- * The first chunk of a payload or stream segment whether needing obfuscation
- * or not will pass a valid pcap_pkthdr struct. Subsequent calls will pass NULL
- * for this structure.  This is useful, especially for the stream segment API
- * call to know when a new segment begins.  Any new "payload" will have a valid
- * pcap_pkthdr struct.
- *
- * If the slice sent in has a non-NULL packet data pointer, the data should *NOT*
- * be obfuscated.
- *
- * If the chunk sent in has a NULL packet data pointer, then that chunk of data
- * should be obfuscated with the obfuscation character.
- *
- * The length passed in is the amount of data that should be copied from the
- * packet data pointer or the amount of data that should be written with the
- * obfuscation character.
- *
- * Arguments
- *  DAQ_PktHdr_t *pkth
- *   The pcap header that contains the packet caplen and timestamps
- *  uint8_t *packet_data
- *   A pointer to the current offset into the packet data.  NULL if
- *   obfuscation of the payload slice is required.
- *  ob_char_t ob_char
- *   The obfuscation character to use if packet_data is NULL.
- *  ob_size_t length
- *   The amount of data to be logged or obfuscated.
- *  void *user_data
- *   The user data passed in to the API functions obfuscatePayload() or
- *   obfuscateStreamSegments below.
- *
- * Returns
- *  OB_RET_SUCCESS  if all is good
- *  OB_RET_ERROR  if the rest of the obfuscation should not be done
- *
- ******************************************************************************/
-typedef ObRet (* ObfuscationCallback)
-(
-    const DAQ_PktHdr_t* pkth,
-    const uint8_t* packet_data,
-    ob_size_t length,
-    ob_char_t ob_char,
-    void* user_data
-);
-
-/*******************************************************************************
- * Obfuscation API
- ******************************************************************************/
-typedef struct _ObfuscationApi
-{
-    /*
-     * Resets/clears any entries that have been added
-     * Should be done per packet aquisition
-     *
-     * Arguments
-     *  None
-     *
-     * Returns
-     *  None
-     */
-
-    void (* resetObfuscationEntries)();
-
-    /*
-     * Adds an obfuscation entry to the queue
-     *
-     * Arguments
-     *  Packet *p
-     *   The Packet struct that has the payload data that should be obfuscated
-     *  ob_size_t offset
-     *   The offset from the beginning of the payload to start obfuscation
-     *  ob_size_t length
-     *   The amount of data to obfuscate
-     *  ob_char_t ob_char
-     *   The character to use when obfuscating
-     *
-     * There are two types of entries that can be added.  A slice entry that
-     * has an offset and length less than OB_LENGTH_MAX and an entry with
-     * length OB_LENGTH_MAX that implies obfuscating from offset to the end
-     * of the packet data.
-     *
-     * NOTE --
-     * There is a fixed size of slice entries and OB_LENGTH_MAX entries.
-     * If OB_RET_OVERFLOW is returned when attempting to add a slice entry,
-     * a second call can be made to add an OB_LENGTH_MAX entry.  Only one
-     * OB_LENGTH_MAX entry can be associated with each Packet.  If there is
-     * already an OB_LENGTH_MAX entry for the packet, the lower of the two
-     * offsets will be used.  Although you should check for OB_RET_OVERFLOW
-     * when attempting to add an OB_LENGTH_MAX entry, the fixed size should
-     * be more than enough space to store an entry for each possible packet
-     * that could be in the system at the time.
-     *
-     * Returns
-     *  OB_RET_SUCCESS on sucess
-     *  OB_RET_ERROR  on error
-     *  OB_RET_OVERFLOW  if there is no space left to add an entry
-     */
-
-    ObRet (* addObfuscationEntry)(Packet* p, ob_size_t offset,
-        ob_size_t length, ob_char_t ob_char);
-
-    /*
-     * Determines if there are any obfuscation entries associated with
-     * the given Packet
-     *
-     * Arguments
-     *  Packet *
-     *   The Packet to check
-     *
-     * Returns
-     *  1  if the packet requires obfuscation
-     *  0  if it doesn't
-     */
-
-    int (* payloadObfuscationRequired)(Packet* p);
-
-    /*
-     * Obfuscate the payload associated with the Packet.  Mainly for use by the
-     * output system to print or log an obfuscated payload.  The callback will
-     * be called for both payload segments that need obfuscation and those that
-     * don't.  See comment on ObfuscationCallback above.
-     *
-     * Arguments
-     *  Packet *
-     *   The Packet whose payload should be obfuscated
-     *  ObfuscationCallback
-     *   The function that will be called for each obfuscated and
-     *   non-obfuscated segment in the payload
-     *  void *
-     *   User data that will be passed to the callback
-     *
-     * Returns
-     *  OB_RET_SUCCESS  on sucess
-     *  OB_RET_ERROR  on error
-     */
-
-    ObRet (* obfuscatePacket)(Packet* p,
-        ObfuscationCallback callback, void* user_data);
-
-    /*
-     * Obfuscate the stream segments associated with the Packet.  Mainly for use
-     * by the output system to print or log the stream segments associated with
-     * a Packet that have been marked as needing obfuscation.  The callback will
-     * be called for both stream segments that need obfuscation and those that
-     * don't.  It will be called for all stream segments.  See comment on
-     * ObfuscationCallback above.
-     *
-     * Arguments
-     *  Packet *
-     *   The Packet whose stream segments should be obfuscated
-     *  ObfuscationCallback
-     *   The function that will be called for each obfuscated and
-     *   non-obfuscated part of the stream segments.
-     *  void *
-     *   User data that will be passed to the callback
-     *
-     * Returns
-     *  OB_RET_SUCCESS  on sucess
-     *  OB_RET_ERROR  on error
-     */
-
-    ObRet (* obfuscatePacketStreamSegments)(Packet* p,
-        ObfuscationCallback callback, void* user_data);
-
-    /*
-     * Obfuscates the Packet payload and returns payload and payload length
-     * in parameters
-     *
-     * NOTE
-     * *payload will be set to NULL, so don't pass in an already
-     *      allocated pointer.
-     * *payload_len will be zeroed.
-     *
-     * The payload returned is dynamically allocated and MUST be free'd.
-     *
-     * Arguments
-     *  Packet *
-     *   The Packet whose payload should be obfuscated
-     *  uint8_t **payload
-     *   A pointer to a payload pointer so it can be allocated, returned
-     *   and accessed.
-     *  ob_size_t *payload_len
-     *   A pointer to an ob_size_t so the length can be returned.
-     *
-     * Returns
-     *  OB_RET_ERROR  if the payload could not be obfuscated
-     *                the pointers to payload and payload_len will not be valid
-     *  OB_RET_SUCCESS  if the payload was obfuscated
-     *                  the pointers to payload and payload_len will be valid
-     */
-
-    ObRet (* getObfuscatedPayload)(Packet* p, uint8_t** payload,
-        ob_size_t* payload_len);
-
-    /*
-     * Prints the current obfuscation entries.
-     *
-     * Arguments
-     *  int sorted
-     *   Print the sorted entries and sort if necessary.
-     *
-     * Returns
-     *  None
-     */
-
-    void (* printObfuscationEntries)(int sorted);
-} ObfuscationApi;
-
-/* For access when including header */
-SO_PUBLIC extern ObfuscationApi* obApi;
-
-#endif
-
index eeac0241928002b95002a34ee77d6a51da65a104..c227084532187478b58823cff2859a07d63d4bac 100644 (file)
@@ -55,7 +55,6 @@
 #include "events/event.h"
 #include "utils/util.h"
 #include "utils/snort_bounds.h"
-#include "log/obfuscation.h"
 #include "packet_io/active.h"
 #include "packet_io/sfdaq.h"
 #include "stream/stream_api.h"
@@ -131,11 +130,6 @@ static void Unified2Write(uint8_t*, uint32_t, Unified2Config*);
 static void _AlertIP4_v2(Packet*, const char*, Unified2Config*, Event*);
 static void _AlertIP6_v2(Packet*, const char*, Unified2Config*, Event*);
 
-#ifdef BUILD_OBFUSCATION
-static ObRet Unified2LogObfuscationCallback(const DAQ_PktHdr_t* pkth,
-    const uint8_t* packet_data, ob_size_t length, ob_char_t ob_char, void* userdata);
-#endif
-
 static void AlertExtraData(Flow*, void* data, LogFunction* log_funcs, uint32_t max_count, uint32_t
     xtradata_mask, uint32_t event_id, uint32_t event_second);
 
@@ -560,27 +554,6 @@ static void _Unified2LogPacketAlert(
         logheader.event_second = 0;
     }
 
-#ifdef BUILD_OBFUSCATION
-    if ( p and p->pkth and obApi->payloadObfuscationRequired(p) )
-    {
-        Unified2LogCallbackData unifiedData;
-
-        unifiedData.logheader = &logheader;
-        unifiedData.config = config;
-        unifiedData.event = event;
-        unifiedData.num_bytes = 0;
-
-        if (obApi->obfuscatePacket(p, Unified2LogObfuscationCallback,
-            (void*)&unifiedData) == OB_RET_SUCCESS)
-        {
-            /* Write the last record */
-            if (unifiedData.num_bytes != 0)
-                Unified2Write(write_pkt_buffer, unifiedData.num_bytes, config);
-            return;
-        }
-    }
-#endif
-
     if ( p and p->pkth )
     {
         logheader.packet_second = htonl((uint32_t)p->pkth->ts.tv_sec);
@@ -636,97 +609,6 @@ static void _Unified2LogPacketAlert(
     Unified2Write(write_pkt_buffer, write_len, config);
 }
 
-#ifdef BUILD_OBFUSCATION
-static ObRet Unified2LogObfuscationCallback(const DAQ_PktHdr_t* pkth,
-    const uint8_t* packet_data, ob_size_t length,
-    ob_char_t ob_char, void* userdata)
-{
-    Unified2LogCallbackData* unifiedData = (Unified2LogCallbackData*)userdata;
-
-    if (userdata == NULL)
-        return OB_RET_ERROR;
-
-    if (pkth != NULL)
-    {
-        Serial_Unified2_Header hdr;
-        uint32_t record_len = (pkth->caplen + sizeof(Serial_Unified2_Header)
-            + (sizeof(Serial_Unified2Packet) - 4));
-
-        /* Write the last buffer if present.  Want to write an entire record
-         * at a time in case of failures, we don't corrupt the log file. */
-        if (unifiedData->num_bytes != 0)
-            Unified2Write(write_pkt_buffer, unifiedData->num_bytes, unifiedData->config);
-
-        if ((write_pkt_buffer + record_len) > write_pkt_end)
-        {
-            ErrorMessage("%s(%d) Too much data. Not writing unified2 event.\n",
-                __FILE__, __LINE__);
-            return OB_RET_ERROR;
-        }
-
-        if ( unifiedData->config->limit &&
-            (u2.current + record_len) > unifiedData->config->limit )
-            Unified2RotateFile(unifiedData->config);
-
-        hdr.type = htonl(UNIFIED2_PACKET);
-        hdr.length = htonl((sizeof(Serial_Unified2Packet) - 4) + pkth->caplen);
-
-        /* Event data will already be set */
-
-        unifiedData->logheader->packet_second = htonl((uint32_t)pkth->ts.tv_sec);
-        unifiedData->logheader->packet_microsecond = htonl((uint32_t)pkth->ts.tv_usec);
-        unifiedData->logheader->packet_length = htonl(pkth->caplen);
-
-        if (SafeMemcpy(write_pkt_buffer, &hdr, sizeof(Serial_Unified2_Header),
-            write_pkt_buffer, write_pkt_end) != SAFEMEM_SUCCESS)
-        {
-            ErrorMessage("%s(%d) Failed to copy Serial_Unified2_Header. "
-                "Not writing unified2 event.\n", __FILE__, __LINE__);
-            return OB_RET_ERROR;
-        }
-
-        if (SafeMemcpy(write_pkt_buffer + sizeof(Serial_Unified2_Header),
-            unifiedData->logheader, sizeof(Serial_Unified2Packet) - 4,
-            write_pkt_buffer, write_pkt_end) != SAFEMEM_SUCCESS)
-        {
-            ErrorMessage("%s(%d) Failed to copy Serial_Unified2Packet. "
-                "Not writing unified2 event.\n", __FILE__, __LINE__);
-            return OB_RET_ERROR;
-        }
-
-        /* Reset this for the new record */
-        unifiedData->num_bytes = (record_len - pkth->caplen);
-    }
-
-    if (packet_data != NULL)
-    {
-        if (SafeMemcpy(write_pkt_buffer + unifiedData->num_bytes,
-            packet_data, (size_t)length,
-            write_pkt_buffer, write_pkt_end) != SAFEMEM_SUCCESS)
-        {
-            ErrorMessage("%s(%d) Failed to copy packet data "
-                "Not writing unified2 event.\n", __FILE__, __LINE__);
-            return OB_RET_ERROR;
-        }
-    }
-    else
-    {
-        if (SafeMemset(write_pkt_buffer + unifiedData->num_bytes,
-            (uint8_t)ob_char, (size_t)length,
-            write_pkt_buffer, write_pkt_end) != SAFEMEM_SUCCESS)
-        {
-            ErrorMessage("%s(%d) Failed to obfuscate packet data "
-                "Not writing unified2 event.\n", __FILE__, __LINE__);
-            return OB_RET_ERROR;
-        }
-    }
-
-    unifiedData->num_bytes += length;
-
-    return OB_RET_SUCCESS;
-}
-#endif
-
 /******************************************************************************
  * Function: Unified2Write()
  *
index 0e12f22be9581cf236cf9587260af575d0d7c510..348b2ea82d91ad482379d4a7087c9f3fceafbd25 100644 (file)
@@ -31,7 +31,6 @@
 #include "flow/session.h"
 #include "framework/inspector.h"
 #include "detection/detection_util.h"
-#include "log/obfuscation.h"
 #include "log/messages.h"
 #include "packet_io/active.h"
 #include "target_based/snort_protocols.h"