1,16 → 1,17 |
; |
; Automated dhcp client |
; v 1.3 |
; |
; v 1.1 |
; with thanks to authors of DHCP client for menuetos: Mike Hibbet |
; |
; by the hidden player |
; |
; by HidnPlayr & Derpenguin |
|
DEBUG equ 1 |
|
TIMEOUT equ 60 ; in seconds |
BUFFER equ 1024 |
__DEBUG__ equ 1 |
__DEBUG_LEVEL__ equ 1; 1 = all, 2 = errors |
|
use32 |
|
org 0x0 |
|
db 'MENUET01' ; 8 byte id |
21,13 → 22,33 |
dd I_END ; esp |
dd 0x0 , 0x0 ; I_Param , I_Icon |
|
include 'macros.inc' |
;include 'macros.inc' |
include 'eth.inc' |
include 'debug-fdo.inc' |
|
if DEBUG = 1 |
include 'debug.inc' |
end if |
|
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; |
; CONFIGURATION FOR LINK-LOCAL ; |
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; |
; ; |
PROBE_WAIT equ 1 ; second (initial random delay) ; |
PROBE_MIN equ 1 ; second (minimum delay till repeated probe) ; |
PROBE_MAX equ 2 ; seconds (maximum delay till repeated probe) ; |
PROBE_NUM equ 3 ; (number of probe packets) ; |
; ; |
ANNOUNCE_NUM equ 2 ; (number of announcement packets) ; |
ANNOUNCE_INTERVAL equ 2 ; seconds (time between announcement packets) ; |
ANNOUNCE_WAIT equ 2 ; seconds (delay before announcing) ; |
; ; |
MAX_CONFLICTS equ 10 ; (max conflicts before rate limiting) ; |
; ; |
RATE_LIMIT_INTERVAL equ 60 ; seconds (delay between successive attempts) ; |
; ; |
DEFEND_INTERVAL equ 10 ; seconds (min. wait between defensive ARPs) ; |
; ; |
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; |
|
|
START: ; start of execution |
|
mov eax,40 ; Report events |
34,61 → 55,69 |
mov ebx,10000000b ; Only Stack |
int 0x40 |
|
mov eax,52 ; first, enable the stack |
mov eax,52 ; first, enable the stack (packet driver) |
mov ebx,2 |
mov ecx,0x00000383 |
int 0x40 |
|
if DEBUG = 1 |
newline |
dps "DHCP: Stack Initialized" |
newline |
end if |
DEBUGF 1,"DHCP: Stack Initialized.\n" |
|
mov eax, 53 ; then, read in the status |
mov ebx, 255 |
mov ecx, 6 |
int 0x40 |
eth.status eax ; Read the Stack status |
test eax,eax ; if eax is zero, no driver was found |
jnz @f |
DEBUGF 1,"DHCP: No Card detected\n" |
jmp close |
|
cmp eax,0 ; if eax is zero, no driver was found |
jne @f |
@@: |
DEBUGF 1,"DHCP: Detected card: %x\n",eax |
@@: |
eth.check_cable eax |
test al,al |
jnz @f |
DEBUGF 1,"DHCP: Ethernet Cable not connected\n" |
|
if DEBUG = 1 |
dps "DHCP: No Card detected" |
newline |
end if |
mov eax,5 |
mov ebx,500 ; loop until cable is connected (check every 5 sec) |
int 0x40 |
|
jmp close |
jmp @r |
|
@@: |
if DEBUG = 1 |
dps "DHCP: Detected card: " |
dph eax |
newline |
end if |
DEBUGF 1,"DHCP: Ethernet Cable status: %d\n",al |
|
; now that the stack is running, lets start the dhcp request |
eth.read_mac MAC |
DEBUGF 1,"DHCP: MAC address: %x-%x-%x-%x-%x-%x\n",[MAC]:2,[MAC+1]:2,[MAC+2]:2,[MAC+3]:2,[MAC+4]:2,[MAC+5]:2 |
|
; First, open socket |
mov eax, 53 |
mov ebx, 0 |
mov ecx, 68 ; local port dhcp client |
mov edx, 67 ; remote port - dhcp server |
mov esi, -1 ; broadcast |
int 0x40 |
; jmp apipa ; comment this out if you want to skip DHCP and continue with link-local |
|
mov [socketNum], eax |
;*************************************************************************** |
; |
; DHCP rubish starts here |
; |
;*************************************************************************** |
|
if DEBUG = 1 |
dps "DHCP: Socket opened: " |
dpd eax |
newline |
end if |
|
|
eth.check_port 68,eax ; Check if port 68 is available |
cmp eax,1 |
je @f |
|
DEBUGF 1,"DHCP: Port 68 is already in use.\n" |
jmp close |
|
@@: |
eth.open_udp 68,67,-1,[socketNum] ; open socket (local,remote,ip,socket) |
DEBUGF 1,"DHCP: Socket opened: %d\n",eax |
; Setup the first msg we will send |
mov byte [dhcpMsgType], 0x01 ; DHCP discover |
mov dword [dhcpLease], esi ; esi is still -1 (-1 = forever) |
|
mov eax,26 |
mov ebx,9 |
int 0x40 |
imul eax,100 |
mov [currTime],eax |
|
;*************************************************************************** |
; Function |
; buildRequest |
98,10 → 127,9 |
; |
;*************************************************************************** |
buildRequest: |
; Clear dhcpMsg to all zeros |
xor eax,eax |
xor eax,eax ; Clear dhcpMsg to all zeros |
mov edi,dhcpMsg |
mov ecx,512 |
mov ecx,BUFFER |
cld |
rep stosb |
|
111,111 → 139,76 |
mov [edx+1], byte 0x01 ; Ethernet |
mov [edx+2], byte 0x06 ; Ethernet h/w len |
mov [edx+4], dword 0x11223344 ; xid |
mov eax,[currTime] |
mov [edx+8], eax ; secs, our uptime |
mov [edx+10], byte 0x80 ; broadcast flag set |
|
mov eax, dword [MAC] ; first 4 bytes of MAC |
mov [edx+28],dword eax |
mov ax, word [MAC+4] ; last 2 bytes of MAC |
mov [edx+32],word ax |
|
mov [edx+236], dword 0x63538263 ; magic number |
|
; option DHCP msg type |
mov [edx+240], word 0x0135 |
mov [edx+240], word 0x0135 ; option DHCP msg type |
mov al, [dhcpMsgType] |
mov [edx+240+2], al |
|
; option Lease time = infinity |
mov [edx+240+3], word 0x0433 |
mov [edx+240+3], word 0x0433 ; option Lease time = infinity |
mov eax, [dhcpLease] |
mov [edx+240+5], eax |
|
; ; option requested IP address |
mov [edx+240+9], word 0x0432 |
; mov eax, [dhcpClientIP] |
; mov [edx+240+11], eax |
mov [edx+240+9], word 0x0432 ; option requested IP address |
mov eax, [dhcpClientIP] |
mov [edx+240+11], eax |
|
; option request list |
mov [edx+240+15], word 0x0437 |
mov [edx+240+15], word 0x0437 ; option request list |
mov [edx+240+17], dword 0x0f060301 |
|
; Check which msg we are sending |
cmp [dhcpMsgType], byte 0x01 |
cmp [dhcpMsgType], byte 0x01 ; Check which msg we are sending |
jne br001 |
|
; "Discover" options |
; end of options marker |
mov [edx+240+21], byte 0xff |
mov [edx+240+21], byte 0xff ; "Discover" options |
|
mov [dhcpMsgLen], dword 262 |
mov [dhcpMsgLen], dword 262 ; end of options marker |
jmp ctr000 |
|
br001: |
; "Request" options |
br001: ; "Request" options |
|
; server IP |
mov [edx+240+21], word 0x0436 |
mov [edx+240+21], word 0x0436 ; server IP |
mov eax, [dhcpServerIP] |
mov [edx+240+23], eax |
|
; end of options marker |
mov [edx+240+27], byte 0xff |
mov [edx+240+27], byte 0xff ; end of options marker |
|
mov [dhcpMsgLen], dword 268 |
|
ctr000: |
|
; write to socket ( send broadcast request ) |
mov eax, 53 |
mov ebx, 4 |
mov ecx, [socketNum] |
mov edx, [dhcpMsgLen] |
mov esi, dhcpMsg |
int 0x40 |
eth.write_udp [socketNum],[dhcpMsgLen],dhcpMsg ; write to socket ( send broadcast request ) |
|
; Setup the DHCP buffer to receive response |
|
mov eax, dhcpMsg |
mov eax, dhcpMsg ; Setup the DHCP buffer to receive response |
mov [dhcpMsgLen], eax ; Used as a pointer to the data |
|
; now, we wait for data from remote |
|
wait_for_data: |
mov eax,23 ; wait here for event NOTE a TIME-OUT should be placed here |
mov ebx,TIMEOUT*100 |
mov eax,23 ; wait here for event (data from remote) |
mov ebx,TIMEOUT*10 |
int 0x40 |
|
; Any data in the UDP receive buffer? |
mov eax, 53 |
mov ebx, 2 |
mov ecx, [socketNum] |
int 0x40 |
eth.poll [socketNum] |
|
cmp eax, 0 |
jne ctr002 |
test eax,eax |
jnz ctr002 |
|
if DEBUG = 1 |
dps "DHCP: Timeout!" |
newline |
end if |
DEBUGF 2,"DHCP: Timeout!\n" |
eth.close_udp [socketNum] |
jmp apipa ; no server found, lets try zeroconf |
|
jmp close |
|
; we have data - this will be the response |
ctr002: |
ctr002: ; we have data - this will be the response |
eth.read_packet [socketNum], dhcpMsg, BUFFER |
mov [dhcpMsgLen], eax |
eth.close_udp [socketNum] |
|
mov eax, 53 |
mov ebx, 3 |
mov ecx, [socketNum] |
int 0x40 ; read byte - block (high byte) |
|
; Store the data in the response buffer |
mov eax, [dhcpMsgLen] |
mov [eax], bl |
inc dword [dhcpMsgLen] |
|
mov eax, 53 |
mov ebx, 2 |
mov ecx, [socketNum] |
int 0x40 ; any more data? |
|
cmp eax, 0 |
jne ctr002 ; yes, so get it |
|
; depending on which msg we sent, handle the response |
; accordingly. |
; If the response is to a dhcp discover, then: |
222,54 → 215,34 |
; 1) If response is DHCP OFFER then |
; 1.1) record server IP, lease time & IP address. |
; 1.2) send a request packet |
; 2) else exit ( display error ) |
; If the response is to a dhcp request, then: |
; 1) If the response is DHCP ACK then |
; 1.1) extract the DNS & subnet fields. Set them in the stack |
; 2) else exit ( display error ) |
|
|
cmp [dhcpMsgType], byte 0x01 ; did we send a discover? |
je discover |
cmp [dhcpMsgType], byte 0x03 ; did we send a request? |
je request |
|
; should never get here - we only send discover or request |
jmp close |
jmp close ; really unknown, what we did |
|
discover: |
|
call parseResponse |
|
; Was the response an offer? It should be |
cmp [dhcpMsgType], byte 0x02 |
jne close ; NO - so quit |
|
; send request |
cmp [dhcpMsgType], byte 0x02 ; Was the response an offer? |
jne apipa ; NO - so we do zeroconf |
mov [dhcpMsgType], byte 0x03 ; DHCP request |
jmp buildRequest |
|
request: |
|
call parseResponse |
|
; Was the response an ACK? It should be |
cmp [dhcpMsgType], byte 0x05 |
jne close ; NO - so quit |
cmp [dhcpMsgType], byte 0x05 ; Was the response an ACK? It should be |
jne apipa ; NO - so we do zeroconf |
|
close: |
DEBUGF 1,"DHCP: Exiting\n" |
|
; close socket |
mov eax, 53 |
mov ebx, 1 |
mov ecx, [socketNum] |
int 0x40 |
|
if DEBUG = 1 |
dps "DHCP: Exiting" |
newline |
end if |
|
mov eax,-1 ; at last, exit |
int 0x40 |
|
288,47 → 261,19 |
; |
;*************************************************************************** |
parseResponse: |
|
if DEBUG = 1 |
dps "DHCP: Data received, parsing response" |
newline |
end if |
|
DEBUGF 1,"DHCP: Data received, parsing response\n" |
mov edx, dhcpMsg |
|
pusha |
|
mov eax,52 ; Set Client IP |
mov ebx,3 |
mov ecx, [edx+16] |
int 0x40 |
|
if DEBUG = 1 |
dps "DHCP: Client: " |
|
xor esi,esi |
.loop: |
|
pusha |
movzx eax,byte[edx+esi+16] |
call debug_outdec |
eth.set_IP [edx+16] |
mov eax,[edx] |
mov [dhcpClientIP],eax |
DEBUGF 1,"DHCP: Client: %u.%u.%u.%u\n",[edx+16]:1,[edx+17]:1,[edx+18]:1,[edx+19]:1 |
popa |
|
inc esi |
cmp esi,4 |
jne .loop |
|
newline |
end if |
|
popa |
|
; Scan options |
|
add edx, 240 ; Point to first option |
|
pr001: |
; Get option id |
mov al, [edx] |
cmp al, 0xff ; End of options? |
je pr_exit |
342,7 → 287,6 |
jmp pr001 ; Get next option |
|
pr002: |
; All other (accepted) options are 4 bytes in length |
inc edx |
movzx ecx, byte [edx] |
inc edx ; point to data |
351,6 → 295,7 |
jne pr0021 |
mov eax, [edx] ; All options are 4 bytes, so get it |
mov [dhcpServerIP], eax |
DEBUGF 1,"DHCP: Server: %u.%u.%u.%u\n",[edx]:1,[edx+1]:1,[edx+2]:1,[edx+3]:1 |
jmp pr003 |
|
pr0021: |
357,20 → 302,19 |
cmp al, 51 ; lease |
jne pr0022 |
|
if DEBUG = 1 |
pusha |
dps "DHCP: lease: " |
|
cmp dword[edx],-1 |
DEBUGF 1,"DHCP: lease: " |
mov eax,[edx] |
bswap eax |
mov [dhcpLease],eax |
cmp dword[edx],-1 ; i really don't know, how to test it |
jne no_lease_forever |
dps "forever" |
jmp lease_newline |
DEBUGF 1,"forever\n" |
jmp @f |
no_lease_forever: |
dpd [edx] |
lease_newline: |
newline |
DEBUGF 1,"%d\n",eax |
@@: |
popa |
end if |
|
jmp pr003 |
|
379,123 → 323,145 |
jne pr0023 |
|
pusha |
mov eax,52 |
mov ebx,12 |
mov ecx,[edx] |
int 0x40 |
eth.set_SUBNET [edx] |
DEBUGF 1,"DHCP: Subnet: %u.%u.%u.%u\n",[edx]:1,[edx+1]:1,[edx+2]:1,[edx+3]:1 |
popa |
|
jmp pr003 |
|
if DEBUG = 1 |
dps "DHCP: Subnet: " |
pr0023: |
cmp al, 3 ; gateway ip |
jne pr0024 |
|
xor esi,esi |
.loop: |
|
pusha |
movzx eax,byte[edx+esi] |
call debug_outdec |
eth.set_GATEWAY [edx] |
DEBUGF 1,"DHCP: Gateway: %u.%u.%u.%u\n",[edx]:1,[edx+1]:1,[edx+2]:1,[edx+3]:1 |
popa |
|
inc esi |
cmp esi,4 |
jne .loop |
|
newline |
end if |
pr0024: |
cmp al, 6 ; dns ip |
jne pr003 |
|
pusha |
eth.set_DNS [edx] |
DEBUGF 1,"DHCP: DNS: %u.%u.%u.%u\n",[edx]:1,[edx+1]:1,[edx+2]:1,[edx+3]:1 |
popa |
|
jmp pr003 |
|
pr0023: |
cmp al, 6 ; dns ip |
jne pr0024 |
pr003: |
add edx, ecx |
jmp pr001 |
|
pusha |
pr_exit: |
|
mov eax,52 |
mov ebx,14 |
mov ecx,[edx] |
int 0x40 |
; DEBUGF 1,"DHCP: Sending ARP probe\n" |
; eth.ARP_ANNOUNCE [dhcpClientIP] ; send an ARP announc packet |
|
eth.get_GATEWAY eax ; if gateway was not set, set it to the DHCP SERVER IP |
test eax,eax |
jnz close |
eth.set_GATEWAY [dhcpServerIP] |
jmp close |
|
if DEBUG = 1 |
dps "DHCP: DNS IP: " |
apipa: |
call random |
mov ecx,0xfea9 ; IP 169.254.0.0 link local net, see RFC3927 |
mov cx,ax |
eth.set_IP ecx ; mask is 255.255.0.0 |
DEBUGF 1,"ZeroConf: Link Local IP assinged: 169.254.%u.%u\n",[generator+2]:1,[generator+3]:1 |
eth.set_SUBNET 0xffff |
eth.set_GATEWAY 0x0 |
eth.set_DNS 0x0 |
|
mov eax,5 |
mov ebx,PROBE_WAIT*100 |
int 0x40 |
|
xor esi,esi |
.loop: |
probe_loop: |
call random ; create a pseudo random number in eax (seeded by MAC) |
|
pusha |
movzx eax,byte[edx+esi] |
call debug_outdec |
popa |
cmp al,PROBE_MIN*100 ; check if al is bigger then PROBE_MIN |
jge @f ; all ok |
add al,(PROBE_MAX-PROBE_MIN)*100 ; al is too small |
@@: |
|
inc esi |
cmp esi,4 |
jne .loop |
cmp al,PROBE_MAX*100 |
jle @f |
sub al,(PROBE_MAX-PROBE_MIN)*100 |
@@: |
|
newline |
end if |
movzx ebx,al |
DEBUGF 1,"ZeroConf: Waiting %u0ms\n",ebx |
mov eax,5 |
int 0x40 |
|
popa |
DEBUGF 1,"ZeroConf: Sending Probe\n" |
; eth.ARP_PROBE MAC2 |
inc esi |
|
pr0024: |
cmp al, 3 ; gateway ip |
jne pr003 |
cmp esi,PROBE_NUM |
jl probe_loop |
|
pusha |
; now we wait further ANNOUNCE_WAIT seconds and send ANNOUNCE_NUM ARP announces. If any other host has assingnd |
; IP within this time, we should create another adress, that have to be done later |
|
mov eax,52 |
mov ebx,11 |
mov ecx,[edx] |
DEBUGF 1,"ZeroConf: Waiting %us\n",ANNOUNCE_WAIT |
mov eax,5 |
mov ebx,ANNOUNCE_WAIT*100 |
int 0x40 |
|
|
if DEBUG = 1 |
dps "DHCP: Gateway:" |
|
xor esi,esi |
.loop: |
announce_loop: |
|
pusha |
movzx eax,byte[edx+esi] |
call debug_outdec |
popa |
DEBUGF 1,"ZeroConf: Sending Announce\n" |
; eth.ARP_ANNOUNCE MAC2 |
|
inc esi |
cmp esi,4 |
jne .loop |
cmp esi,ANNOUNCE_NUM |
je @f |
|
newline |
end if |
DEBUGF 1,"ZeroConf: Waiting %us\n",ANNOUNCE_INTERVAL |
mov eax,5 |
mov ebx,ANNOUNCE_INTERVAL*100 |
int 0x40 |
|
popa |
jmp announce_loop |
@@: |
jmp close ; we should, instead of closing, detect ARP conflicts and detect if cable keeps connected ;) |
|
pr003: |
add edx, ecx |
jmp pr001 |
random: |
mov eax,[generator] |
add eax,-43ab45b5h |
ror eax,1 |
bswap eax |
xor eax,dword[MAC] |
ror eax,1 |
xor eax,dword[MAC+2] |
mov [generator],eax |
ret |
|
pr_exit: |
|
if DEBUG = 1 |
dps "DHCP: Done" |
newline |
end if |
|
jmp close |
; DATA AREA |
|
include_debug_strings ; ALWAYS present in data section |
|
; DATA AREA |
|
IM_END: |
|
dhcpMsgType: db 0 |
dhcpLease: dd 0 |
;dhcpClientIP: dd 0 |
dhcpServerIP: dd 0 |
dhcpClientIP dd 0 |
dhcpMsgType db 0 |
dhcpLease dd 0 |
dhcpServerIP dd 0 |
|
dhcpMsgLen: dd 0 |
socketNum: dd 0xFFFF |
dhcpMsg: rb 512 |
dhcpMsgLen dd 0 |
socketNum dd 0 |
|
MAC rb 6 |
currTime dd 0 |
renewTime dd 0 |
generator dd 0 |
|
dhcpMsg rb BUFFER |
I_END: |