8 Commits

Author SHA1 Message Date
solusipse
68635bd0f5 Update README.md 2017-10-30 07:31:55 +01:00
solusipse
8e6cf66b3d Update README.md 2015-09-23 19:48:58 +02:00
solusipse
1a7d443843 mergerd renaudallard:master (#17) 2015-09-23 19:36:37 +02:00
solusipse
9b2f73678d Merge branch 'master' of git://github.com/renaudallard/fiche into renaudallard-master 2015-09-23 19:09:41 +02:00
solusipse
95f1cacfbe Merge branch 'master' of git://github.com/ALSchwalm/fiche into ALSchwalm-master 2015-09-23 18:27:18 +02:00
Renaud Allard
39aa6a7a53 Chnage the travis script so that it builds 2015-09-07 13:18:05 +02:00
Renaud Allard
6743d0e6b7 Use ./configure to detect arc4random and use it if present 2015-09-03 16:11:12 +02:00
Adam Schwalm
b6d1c91f71 Make file paths unpredictable 2015-09-02 18:16:23 -05:00
8 changed files with 4064 additions and 193 deletions

View File

@@ -1,2 +1,2 @@
language: c
script: make
script: ./configure && make

View File

@@ -5,12 +5,12 @@
# -----------------------------------
CFLAGS+=-pthread -O2
prefix=/usr/local
CFLAGS+=@LIBS@
all: fiche
install: fiche
install -m 0755 fiche $(prefix)/bin
install -m 0755 fiche ${PREFIX}/bin
clean:
rm -f fiche

View File

@@ -3,3 +3,7 @@
## Warning
Do not use code from this branch. Please use code from [master](https://github.com/solusipse/fiche) instead.
## Secure branch (legacy note)
This branch is the result of merging two pull requests: [#16](https://github.com/solusipse/fiche/pull/16) by [Adam Schwalm](https://github.com/ALSchwalm) and [#17](https://github.com/solusipse/fiche/pull/17) by [Renaud Allard](https://github.com/renaudallard), which contained some security-related improvements. It is recommended for `BSD` users or for those who would like to `arc4random`.

2
config.h.in Normal file
View File

@@ -0,0 +1,2 @@
#undef HAVE_ARC4RANDOM

3987
configure vendored Executable file

File diff suppressed because it is too large Load Diff

20
configure.in Normal file
View File

@@ -0,0 +1,20 @@
AC_INIT([fiche], [0.99])
AC_CONFIG_SRCDIR([fiche.c])
AC_CONFIG_HEADERS([config.h])
# Checks for programs.
AC_PROG_CC
# Function arc4random() is in BSD standard C or GNU systems -lbsd
AC_SEARCH_LIBS([arc4random], [bsd], [HAVE_ARC4RANDOM="yes"])
# Checks for library functions.
AC_CHECK_FUNCS([bzero arc4random])
AC_SUBST(HAVE_ARC4RANDOM)
AC_CONFIG_FILES([Makefile])
AC_OUTPUT

217
fiche.c
View File

@@ -29,23 +29,22 @@ $ cat fiche.c | nc localhost 9999
*/
#include <sys/param.h>
#include <stdio.h>
#include "config.h"
#include "fiche.h"
int main(int argc, char **argv)
{
time_seed = time(0);
parse_parameters(argc, argv);
set_domain_name();
if (getuid() == 0)
{
if (UID == -1)
error("user not set");
error("ERROR: user not set");
if (setgid(GID) != 0)
error("Unable to drop group privileges");
error("ERROR: Unable to drop group privileges");
if (setuid(UID) != 0)
error("Unable to drop user privileges");
error("ERROR: Unable to drop user privileges");
}
if (BASEDIR == NULL)
@@ -59,21 +58,8 @@ int main(int argc, char **argv)
listen_socket = create_socket();
setsockopt(listen_socket, SOL_SOCKET, SO_REUSEADDR, (const void *)&optval , sizeof(int));
#if (HAVE_INET6)
struct sockaddr_in6 server_address6;
if (IPv6)
{
server_address6 = set_address6(server_address6);
bind_to_port6(listen_socket, server_address6);
}
else
{
#else
if (1) {
#endif
server_address = set_address(server_address);
bind_to_port(listen_socket, server_address);
}
server_address = set_address(server_address);
bind_to_port(listen_socket, server_address);
if (DAEMON)
{
@@ -81,7 +67,7 @@ int main(int argc, char **argv)
pid = fork();
if (pid == -1)
error("Failed to fork");
error("ERROR: Failed to fork");
if (pid == 0)
while (1) perform_connection(listen_socket);
}
@@ -94,34 +80,19 @@ int main(int argc, char **argv)
void *thread_connection(void *args)
{
int connection_socket = ((struct thread_arguments *) args ) -> connection_socket;
struct sockaddr_in client_address;
struct client_data data;
#if (HAVE_INET6)
struct sockaddr_in6 client_address6;
if (IPv6)
{
client_address6 = ((struct thread_arguments *) args ) -> client_address6;
data = get_client_address6(client_address6);
}
else
{
#else
if (1) {
#endif
client_address = ((struct thread_arguments *) args ) -> client_address;
data = get_client_address(client_address);
}
struct sockaddr_in client_address = ((struct thread_arguments *) args ) -> client_address;
struct client_data data = get_client_address(client_address);
char buffer[BUFSIZE];
bzero(buffer, BUFSIZE);
int status = recv(connection_socket, buffer, BUFSIZE, MSG_WAITALL);
int status = recv(connection_socket, buffer, BUFSIZE, MSG_DONTWAIT);
if (WHITELIST != NULL && check_whitelist(data.ip_address) == NULL)
{
display_info(data, NULL, "Rejected connection from unknown user.");
save_log(NULL, data.ip_address, data.hostname);
if (write(connection_socket, "You are not whitelisted!\n", 26) < 0)
printf("Error writing on stream socket\n");
write(connection_socket, "You are not whitelisted!\n", 26);
close(connection_socket);
pthread_exit(NULL);
}
@@ -130,8 +101,7 @@ void *thread_connection(void *args)
{
display_info(data, NULL, "Rejected connection from banned user.");
save_log(NULL, data.ip_address, data.hostname);
if (write(connection_socket, "You are banned!\n", 17) < 0)
printf("Error writing on stream socket\n");
write(connection_socket, "You are banned!\n", 17);
close(connection_socket);
pthread_exit(NULL);
}
@@ -146,15 +116,13 @@ void *thread_connection(void *args)
save_log(slug, data.ip_address, data.hostname);
char response[strlen(slug) + strlen(DOMAIN) + 2];
snprintf(response, sizeof response, "%s%s\n", DOMAIN, slug);
if (write(connection_socket, response, strlen(response)) < 0)
printf("Error writing on stream socket\n");
write(connection_socket, response, strlen(response));
}
else
{
display_info(data, NULL, "Invalid connection.");
save_log(NULL, data.ip_address, data.hostname);
if (write(connection_socket, "Use netcat.\n", 12) < 0)
printf("Error writing on stream socket\n");
write(connection_socket, "Use netcat.\n", 12);
}
close(connection_socket);
@@ -166,45 +134,24 @@ void perform_connection(int listen_socket)
pthread_t thread_id;
struct sockaddr_in client_address;
int address_length;
int connection_socket;
#if (HAVE_INET6)
struct sockaddr_in6 client_address6;
if (IPv6)
{
address_length = sizeof(client_address6);
connection_socket = accept(listen_socket, (struct sockaddr *) &client_address6, (void *) &address_length);
}
else
{
#else
if (1) {
#endif
address_length = sizeof(client_address);
connection_socket = accept(listen_socket, (struct sockaddr *) &client_address, (void *) &address_length);
}
int address_length = sizeof(client_address);
int connection_socket = accept(listen_socket, (struct sockaddr *) &client_address, (void *) &address_length);
struct timeval timeout;
timeout.tv_sec = 5;
timeout.tv_usec = 0;
if (setsockopt (connection_socket, SOL_SOCKET, SO_RCVTIMEO, (char *)&timeout, sizeof(timeout)) < 0)
error("while setting setsockopt timeout");
error("ERROR while setting setsockopt timeout");
if (setsockopt (connection_socket, SOL_SOCKET, SO_SNDTIMEO, (char *)&timeout, sizeof(timeout)) < 0)
error("while setting setsockopt timeout");
error("ERROR while setting setsockopt timeout");
struct thread_arguments arguments;
arguments.connection_socket = connection_socket;
#if (HAVE_INET6)
if (IPv6)
arguments.client_address6 = client_address6;
else
#endif
arguments.client_address = client_address;
arguments.client_address = client_address;
if (pthread_create(&thread_id, NULL, &thread_connection, &arguments) != 0)
error("on thread creation");
error("ERROR on thread creation");
else
pthread_detach(thread_id);
}
@@ -250,36 +197,6 @@ struct client_data get_client_address(struct sockaddr_in client_address)
return data;
}
#if (HAVE_INET6)
struct client_data get_client_address6(struct sockaddr_in6 client_address6)
{
struct hostent *hostp;
struct client_data data;
static char hostaddrp[INET6_ADDRSTRLEN];
hostp = gethostbyaddr((const char *)&client_address6.sin6_addr, sizeof(client_address6.sin6_addr), AF_INET6);
if (hostp == NULL)
{
printf("WARNING: Couldn't obtain client's hostname\n");
data.hostname = "n/a";
}
else
data.hostname = hostp->h_name;
inet_ntop(AF_INET6, &(client_address6.sin6_addr), hostaddrp,
INET6_ADDRSTRLEN);
if (hostaddrp == NULL)
{
printf("WARNING: Couldn't obtain client's address\n");
data.ip_address = "n/a";
}
else
data.ip_address = hostaddrp;
return data;
}
#endif
void save_log(char *slug, char *hostaddrp, char *h_name)
{
if (LOG != NULL)
@@ -327,18 +244,13 @@ char *check_whitelist(char *ip_address)
void load_list(char *file_path, int type)
{
FILE *fp;
if (( fp = fopen(file_path, "r")) == NULL )
error("cannot load list");
FILE *fp = fopen(file_path, "r");
fseek(fp, 0, SEEK_END);
long fsize = ftell(fp);
fseek(fp, 0, SEEK_SET);
char *buffer = malloc(fsize + 1);
if (fread(buffer, fsize, 1, fp) != fsize)
error("reading list failed");
fread(buffer, fsize, 1, fp);
fclose(fp);
buffer[fsize] = 0;
@@ -353,16 +265,10 @@ void load_list(char *file_path, int type)
int create_socket()
{
int lsocket;
#if (HAVE_INET6)
if (IPv6)
lsocket = socket(AF_INET6, SOCK_STREAM, 0);
else
#endif
lsocket = socket(AF_INET, SOCK_STREAM, 0);
int lsocket = socket(AF_INET, SOCK_STREAM, 0);
if (lsocket < 0)
error("Couldn't open socket");
error("ERROR: Couldn't open socket");
return lsocket;
}
@@ -376,61 +282,48 @@ struct sockaddr_in set_address(struct sockaddr_in server_address)
return server_address;
}
#if (HAVE_INET6)
struct sockaddr_in6 set_address6(struct sockaddr_in6 server_address6)
{
bzero((char *) &server_address6, sizeof(server_address6));
server_address6.sin6_family = AF_INET6;
server_address6.sin6_addr = in6addr_any;
server_address6.sin6_port = htons((unsigned short)PORT);
return server_address6;
}
#endif
void bind_to_port(int listen_socket, struct sockaddr_in server_address)
{
if (bind(listen_socket, (struct sockaddr *) &server_address, sizeof(server_address)) < 0)
error("while binding to port");
if (bind(listen_socket, (struct sockaddr *) &server_address, sizeof(server_address)) < 0)
error("ERROR while binding to port");
if (listen(listen_socket, QUEUE_SIZE) < 0)
error("while starting listening");
error("ERROR while starting listening");
}
#if (HAVE_INET6)
void bind_to_port6(int listen_socket, struct sockaddr_in6 server_address6)
{
if (bind(listen_socket, (struct sockaddr *) &server_address6, sizeof(server_address6)) < 0)
error("while binding to port");
if (listen(listen_socket, QUEUE_SIZE) < 0)
error("while starting listening");
}
#endif
void generate_url(char *buffer, char *slug, size_t slug_length, struct client_data data)
{
int i;
memset(slug, '\0', slug_length);
#if !defined(BSD)
FILE* frandom = fopen("/dev/urandom", "r");
#endif
int symbol_id;
for (i = 0; i <= SLUG_SIZE - 1; i++)
{
#if defined(BSD)
#if defined(HAVE_ARC4RANDOM)
int symbol_id = arc4random() % strlen(symbols);
#else
int symbol_id = rand_r(&time_seed) % strlen(symbols);
fread(&symbol_id, sizeof(symbol_id), 1, frandom);
#endif
slug[i] = symbols[symbol_id];
slug[i] = symbols[symbol_id % strlen(symbols)];
}
while (create_directory(slug) == -1)
{
#if defined(BSD)
#if defined(HAVE_ARC4RANDOM)
int symbol_id = arc4random() % strlen(symbols);
#else
int symbol_id = rand_r(&time_seed) % strlen(symbols);
fread(&symbol_id, sizeof(symbol_id), 1, frandom);
#endif
slug[strlen(slug)] = symbols[symbol_id];
slug[strlen(slug)] = symbols[symbol_id % strlen(symbols)];
}
save_to_file(slug, buffer, data);
#if !defined(BSD)
fclose(frandom);
#endif
}
int create_directory(char *slug)
@@ -506,41 +399,25 @@ void startup_message()
void error(char *buffer)
{
printf("Error: %s\n", buffer);
printf("%s\n", buffer);
exit(1);
}
void set_domain_name() {
char b[128];
memcpy(b, DOMAIN, sizeof DOMAIN);
if (HTTPS)
snprintf(DOMAIN, sizeof DOMAIN, "%s%s", "https://", b);
else
snprintf(DOMAIN, sizeof DOMAIN, "%s%s", "http://", b);
}
void parse_parameters(int argc, char **argv)
{
int c;
while ((c = getopt (argc, argv, "D6eSp:b:s:d:o:l:B:u:w:")) != -1)
while ((c = getopt (argc, argv, "Dep:b:s:d:o:l:B:u:w:")) != -1)
switch (c)
{
case 'D':
DAEMON = 1;
break;
case '6':
IPv6 = 1;
break;
case 'e':
snprintf(symbols, sizeof symbols, "%s", "abcdefghijklmnopqrstuvwxyz0123456789-+_=.ABCDEFGHIJKLMNOPQRSTUVWXYZ");
break;
case 'S':
HTTPS = 1;
break;
case 'd':
snprintf(DOMAIN, sizeof DOMAIN, "%s%s", optarg, "/");
snprintf(DOMAIN, sizeof DOMAIN, "%s%s%s", "http://", optarg, "/");
break;
case 'p':
PORT = atoi(optarg);
@@ -569,7 +446,7 @@ void parse_parameters(int argc, char **argv)
load_list(WHITEFILE, 1);
break;
default:
printf("usage: fiche [-D6epbsdSolBuw].\n");
printf("usage: fiche [-pbsdolBuw].\n");
printf(" [-d domain] [-p port] [-s slug_size]\n");
printf(" [-o output directory] [-B buffer_size] [-u user name]\n");
printf(" [-l log file] [-b banlist] [-w whitelist]\n");

21
fiche.h
View File

@@ -31,10 +31,6 @@ $ cat fiche.c | nc localhost 9999
#ifndef FICHE_H
#define FICHE_H
#ifndef HAVE_INET6
#define HAVE_INET6 1
#endif
#include <pwd.h>
#include <time.h>
#include <netdb.h>
@@ -58,13 +54,11 @@ char *BANFILE;
char *WHITEFILE;
char *WHITELIST;
int DAEMON = 0;
int HTTPS = 0;
int PORT = 9999;
int IPv6 = 0;
int SLUG_SIZE = 4;
int BUFSIZE = 32768;
int QUEUE_SIZE = 500;
char DOMAIN[128] = "localhost/";
char DOMAIN[128] = "http://localhost/";
char symbols[67] = "abcdefghijklmnopqrstuvwxyz0123456789";
unsigned int time_seed;
@@ -73,9 +67,6 @@ struct thread_arguments
{
int connection_socket;
struct sockaddr_in client_address;
#if (HAVE_INET6)
struct sockaddr_in6 client_address6;
#endif
};
struct client_data
@@ -89,9 +80,6 @@ int create_directory(char *slug);
int check_protocol(char *buffer);
void bind_to_port(int listen_socket, struct sockaddr_in serveraddr);
#if (HAVE_INET6)
void bind_to_port6(int listen_socket, struct sockaddr_in6 serveraddr6);
#endif
void error(char *buffer);
void perform_connection(int listen_socket);
void generate_url(char *buffer, char *slug, size_t slug_length, struct client_data data);
@@ -99,7 +87,6 @@ void save_to_file(char *buffer, char *slug, struct client_data data);
void display_info(struct client_data data, char *slug, char *message);
void startup_message();
void set_basedir();
void set_domain_name();
void load_list(char *file_path, int type);
void parse_parameters(int argc, char **argv);
void save_log(char *slug, char *hostaddrp, char *h_name);
@@ -110,12 +97,6 @@ char *check_whitelist(char *ip_address);
char *get_date();
struct sockaddr_in set_address(struct sockaddr_in serveraddr);
#if (HAVE_INET6)
struct sockaddr_in6 set_address6(struct sockaddr_in6 serveraddr6);
#endif
struct client_data get_client_address(struct sockaddr_in client_address);
#if (HAVE_INET6)
struct client_data get_client_address6(struct sockaddr_in6 client_address6);
#endif
#endif