diff options
Diffstat (limited to 'src/lib/protocols/ldap.c')
-rw-r--r-- | src/lib/protocols/ldap.c | 86 |
1 files changed, 28 insertions, 58 deletions
diff --git a/src/lib/protocols/ldap.c b/src/lib/protocols/ldap.c index 3462d07b8..70c9c072f 100644 --- a/src/lib/protocols/ldap.c +++ b/src/lib/protocols/ldap.c @@ -37,65 +37,35 @@ static void ndpi_int_ldap_add_connection(struct ndpi_detection_module_struct *nd void ndpi_search_ldap(struct ndpi_detection_module_struct *ndpi_struct, struct ndpi_flow_struct *flow) { - struct ndpi_packet_struct *packet = &ndpi_struct->packet; + struct ndpi_packet_struct *packet = &ndpi_struct->packet; + int length; + u_int16_t length_len = 0, msg_id_len; + u_int8_t op; - NDPI_LOG_DBG(ndpi_struct, "search ldap\n"); - - if (packet->payload_packet_len >= 14 && packet->payload[0] == 0x30) { - - // simple type - if (packet->payload[1] == 0x0c && packet->payload_packet_len == 14 && - packet->payload[packet->payload_packet_len - 1] == 0x00 && packet->payload[2] == 0x02) { - - if (packet->payload[3] == 0x01 && - (packet->payload[5] == 0x60 || packet->payload[5] == 0x61) && packet->payload[6] == 0x07) { - NDPI_LOG_INFO(ndpi_struct, "found ldap simple type 1\n"); - ndpi_int_ldap_add_connection(ndpi_struct, flow); - return; - } - - if (packet->payload[3] == 0x02 && - (packet->payload[6] == 0x60 || packet->payload[6] == 0x61) && packet->payload[7] == 0x07) { - NDPI_LOG_INFO(ndpi_struct, "found ldap simple type 2\n"); - ndpi_int_ldap_add_connection(ndpi_struct, flow); - return; - } - } - // normal type - if (packet->payload[1] == 0x84 && - packet->payload[2] == 0x00 && packet->payload[3] == 0x00 && packet->payload[6] == 0x02) { - - if (packet->payload[7] == 0x01 && - (packet->payload[9] == 0x60 || packet->payload[9] == 0x61 || packet->payload[9] == 0x63 || - packet->payload[9] == 0x64) && packet->payload[10] == 0x84) { - - NDPI_LOG_INFO(ndpi_struct, "found ldap type 1\n"); - ndpi_int_ldap_add_connection(ndpi_struct, flow); - return; - } - - if (packet->payload[7] == 0x02 && - (packet->payload[10] == 0x60 || packet->payload[10] == 0x61 || packet->payload[10] == 0x63 || - packet->payload[10] == 0x64) && packet->payload[11] == 0x84) { - - NDPI_LOG_INFO(ndpi_struct, "found ldap type 2\n"); - ndpi_int_ldap_add_connection(ndpi_struct, flow); - return; - } - - if (packet->payload[7] == 0x03 && - (packet->payload[11] == 0x60 || packet->payload[11] == 0x61 || packet->payload[11] == 0x63 || - packet->payload[11] == 0x64 || packet->payload[11] == 0x65) && packet->payload[12] == 0x84) { - - NDPI_LOG_INFO(ndpi_struct, "found ldap type 3\n"); - ndpi_int_ldap_add_connection(ndpi_struct, flow); - return; - } - } - } - - - NDPI_EXCLUDE_PROTO(ndpi_struct, flow); + NDPI_LOG_DBG(ndpi_struct, "search ldap\n"); + + if(packet->payload_packet_len > 1 && + packet->payload[0] == 0x30) { + length = ndpi_asn1_ber_decode_length(&packet->payload[1], packet->payload_packet_len - 1, &length_len); + NDPI_LOG_DBG(ndpi_struct, "length %d (%d bytes)\n", length, length_len); + if(length > 0 && + packet->payload_packet_len > 1 + length_len + 1 && + packet->payload[1 + length_len] == 0x02 /* Integer */) { + msg_id_len = packet->payload[1 + length_len + 1]; + if(packet->payload_packet_len > 1 + length_len + 1 + msg_id_len + 1) { + op = packet->payload[1 + length_len + 1 + msg_id_len + 1]; + NDPI_LOG_DBG(ndpi_struct, "Op 0x%x\n", op); + if((op & 0x60) == 0x60 && /* Application */ + (op & 0x1F) <= 25) { + NDPI_LOG_INFO(ndpi_struct, "found ldap\n"); + ndpi_int_ldap_add_connection(ndpi_struct, flow); + return; + } + } + } + } + + NDPI_EXCLUDE_PROTO(ndpi_struct, flow); } |