-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathudpy_proto_scanner.py
1316 lines (1104 loc) · 64.6 KB
/
udpy_proto_scanner.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
#!/usr/bin/env python3
# udpy_proto_scanner - UDP Service Discovery Tool
# Copyright Cisco Systems, Inc. and its affiliates
#
# This tool may be used for legal purposes only. Users take full responsibility
# for any actions performed using this tool. The author accepts no liability
# for damage caused by this tool. If these terms are not acceptable to you, then
# you are not permitted to use this tool.
#
# In all other respects the GPL version 2 applies:
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License along
# with this program; if not, write to the Free Software Foundation, Inc.,
# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
#
import argparse
import collections
import ipaddress
import math
import os
import re
import select
import socket
import sys
import time
class ScannerBase(object):
def __init__(self):
self._sleep_total = 0
self.header = "Starting Scan"
self.sleep_multiplier = 1.87 # if we total up the time we sleep for, it doesn't match the time cProfile reports we spent in the sleep function, so we use this multiplier to adjust the estimate
self.reply_callback_function = None
self.bandwidth_bits_per_second = 32000
self.max_probes = 3
self.probes = [] # [(None, None, None),] # List of probe tuples
self.inter_packet_interval = None
self.inter_packet_interval_per_host = None
self.backoff = 1.5
self.rtt = 0.5 # https://www.nature.com/articles/s41598-019-46208-6
self.bytes_sent = 0
self.resolve_names = False # TODO not implemented yet
self.target_source = None
self.target_list_unprocessed = []
self.target_filename = None
self.scan_start_time_internal = None
self.scan_start_time = None
self.probes_sent_count = 0
self.replies = 0
self.packet_rate = None
self.packet_rate_per_host = None
self.probe_index_to_socket_dict = {}
self.host_count = 0
self.next_recv_time = time.time()
self.recv_interval = 0.1
self.debug = False
self.log_reply_tuples = []
self.debug_reply_log = "debug_reply_log.txt"
self.blocklist = []
self.count_in_queue = {} # how many probes are in the queue for each probe type
self.sleep_reasons = {}
#
# Properties
#
@property
def bytes_sent_target(self):
if self.scan_start_time_internal:
return self.bandwidth_bits_per_second * (time.time() - self.scan_start_time_internal) / 8
else:
return 0
@property
def probes_sent_target(self):
if self.scan_start_time_internal:
return self.packet_rate * (time.time() - self.scan_start_time_internal)
else:
return 0
@property
def sleep_total(self):
return self._sleep_total * self.sleep_multiplier
#
# Setters
#
def set_reply_callback(self, reply_callback):
self.reply_callback_function = reply_callback
def set_debug(self, debug):
self.debug = debug
# set max_probes
def set_max_probes(self, n): # int
self.max_probes = int(n)
def set_blocklist(self, blocklist_ips):
# check ips are valid
for ip in blocklist_ips:
self.add_to_blocklist(ip)
# set bandwidth
def set_bandwidth(self, bandwidth): # string like 250k, 1m, 1g
self.bandwidth_bits_per_second = expand_number(bandwidth)
if self.bandwidth_bits_per_second < 1:
print("[E] Bandwidth %s is too low" % self.bandwidth_bits_per_second)
sys.exit(0)
if self.bandwidth_bits_per_second > 1000000:
print("[W] Bandwidth %s is too high. Continuing anyway..." % self.bandwidth_bits_per_second)
self.set_inter_packet_interval()
def set_inter_packet_interval(self):
if self.packet_overhead is None or self.packet_overhead == 0:
print("[E] Code error: Packet overhead not set prior to calculating inter-packet interval")
sys.exit(0)
if self.bandwidth_bits_per_second is None or self.bandwidth_bits_per_second == 0:
print("[E] Code error: Bandwidth not set not set prior to calculating inter-packet interval")
sys.exit(0)
self.inter_packet_interval = 8 * (self.payload_len_estimate + self.packet_overhead) / float(self.bandwidth_bits_per_second)
def set_packet_rate(self, packet_rate):
self.packet_rate = expand_number(packet_rate)
def set_packet_rate_per_host(self, packet_rate_per_host):
self.packet_rate_per_host = packet_rate_per_host
self.inter_packet_interval_per_host = 1 / float(self.packet_rate_per_host)
def set_header(self, header):
self.header = header
def add_targets(self, targets): # list
self.target_source = "list"
self.target_list_unprocessed = targets
def add_targets_from_file(self, file): # str
self.target_source = "file"
self.target_filename = file
#
# Adders
#
def add_to_blocklist(self, ip):
try:
socket.inet_aton(ip)
except socket.error:
print("[E] Invalid IP address in blocklist: %s" % ip)
sys.exit(1)
if ip not in self.blocklist:
self.blocklist.append(ip)
#
# Getters
#
def get_probe_port(self, probe_index):
probe = self.probes[probe_index]
return int(probe[0])
def get_probe_payload_hex(self, probe_index):
probe = self.probes[probe_index]
return probe[2]
def get_probe_payload_bin(self, probe_index):
probe = self.probes[probe_index]
return probe[3]
def get_probe_name(self, probe_index):
probe = self.probes[probe_index]
return probe[1]
def get_probe_index_from_socket(self, s):
for probe_index, socket in self.probe_index_to_socket_dict.items():
if s == socket:
return probe_index
return None
def get_available_bandwidth_quota_packets(self):
packet_quota_left = None
# return 100 if there is no bandwidth quota
if self.bandwidth_bits_per_second is None:
packet_quota_left = 100
else:
# return 0 if we exceed our bandwidth quota
bytes_left = self.bytes_sent_target - self.bytes_sent
if bytes_left <= 0:
packet_quota_left = 0
else:
packet_quota_left = int(8 * bytes_left / float(self.packet_overhead))
# return the number of packets we can send
return packet_quota_left
def get_available_packet_rate_quota_packets(self):
packet_quota_left = None
# return 100 if there is no packet rate quota
if self.packet_rate is None or self.packet_rate == 0: # TODO messy
packet_quota_left = 100
else:
# return 0 if we exceed our packet rate quota
packets_left = self.probes_sent_target - self.probes_sent_count
if packets_left <= 0:
packet_quota_left = 0
else:
packet_quota_left = packets_left
# return the number of packets we can send
return packet_quota_left
def get_available_quota_packets(self):
return int(min(self.get_available_bandwidth_quota_packets(), self.get_available_packet_rate_quota_packets()))
#
# Debug
#
# Note that recording results in memory could use too much memory for large scans
# so is disabled by default. This feature is used for automated testing.
def debug_log_reply(self, probe_name, srcip, port, data):
self.log_reply_tuples.append((probe_name, srcip, port, data))
def debug_write_log(self):
with open(self.debug_reply_log, "w") as f:
for probe_name, srcip, port, data in self.log_reply_tuples:
f.write("%s,%s,%s,%s\n" % (probe_name, srcip, port, str_or_bytes_to_hex(data)))
print("[i] Wrote debug log to %s" % self.debug_reply_log)
def __repr__(self): # TODO
return "%s()" % type(self).__name__
def __str__(self): # TODO
return "%s()" % type(self).__name__
#
# Others
#
def wait_for_quotas(self):
bandwidth_quota_ok = False
packet_rate_quota_ok = False
probe_send_ok = False
bandwidth_quota_packets_left = 0
packet_quota_packets_left = 0
wait_time = 0
while not (packet_rate_quota_ok and bandwidth_quota_ok and probe_send_ok):
# check if we're within bandwidth quota
force_bandwidth_quota_wait = True
force_packet_quota_wait = True
force_probe_state_wait = True
bandwidth_quota_ok = False
packet_rate_quota_ok = False
probe_send_ok = False
wait_time = 0
bandwidth_quota_packets_left = self.get_available_bandwidth_quota_packets()
if bandwidth_quota_packets_left > 0:
bandwidth_quota_ok = True
force_bandwidth_quota_wait = False
# check if we're within packet rate quota
force_packet_quota_wait = False
packet_quota_packets_left = self.get_available_packet_rate_quota_packets()
if packet_quota_packets_left > 0:
packet_rate_quota_ok = True
force_packet_quota_wait = False
# Check all of the probe states to see if any are ready to send
# This is expesnive, so we only do it if we're within the other quotas
# if self.probe_state_ready():
# probe_send_ok = True
# force_probe_state_wait = False
if self.get_queue_length() > 0:
next_probe_state = self.queue_peek_first()
last_probe_time = next_probe_state.probe_sent_time
now = time.time()
if last_probe_time is None or now > last_probe_time + self.inter_packet_interval_per_host:
probe_send_ok = True
force_probe_state_wait = False
else:
wait_time = last_probe_time + self.inter_packet_interval_per_host - now
else:
self.probe_state_ready_last_result = True
return self.probe_state_ready_last_result
# update stats
if force_bandwidth_quota_wait:
self.sleep_reasons["bandwidth_quota"] += 1
elif force_packet_quota_wait:
self.sleep_reasons["packet_quota"] += 1
elif force_probe_state_wait:
self.sleep_reasons["port_states"] += 1
if not (packet_rate_quota_ok and bandwidth_quota_ok and probe_send_ok):
# sleep for self.inter_packet_interval seconds
wait_time = max(self.inter_packet_interval, wait_time)
# Do an extra receive if we have spare time
# we must not sleep for more than the receive interval or we won't check for reponses when we're supposed to
# Without this shorter sleep, very small scans tend to miss responses because they recv too quickly after sending and then wait for the next retry. Then the same problem occurs.
if wait_time > self.recv_interval:
self.receive_packets(self.get_socket_list())
self._sleep_total += self.recv_interval
time.sleep(self.recv_interval)
else:
self._sleep_total += wait_time
time.sleep(wait_time)
#
# Abstract methods # TODO is abc module portable?
#
def dump(self):
raise NotImplementedError
def set_rtt(self, rtt):
raise NotImplementedError
def set_probes(self, probes):
raise NotImplementedError
def start_scan(self):
raise NotImplementedError
def receive_packets(self, socket_list):
raise NotImplementedError
def inform_starting_probe_type(self, probe_index):
raise NotImplementedError
def decrease_count_in_queue(self):
raise NotImplementedError
def get_queue_length(self):
raise NotImplementedError
def queue_peek_first(self):
raise NotImplementedError
def get_socket_list(self):
raise NotImplementedError
ip_regex = r"(?:(?:[0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\.){3}(?:[0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])"
cidr_regex = r"(?:(?:[0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\.){3}(?:[0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])/([0-9]{1,2})$"
class TargetGenerator:
def __init__(self, make_probe_state_callback, list=None, filename=None, custom=False):
if list is None:
list = []
self.target_filename = filename
self.target_list_unprocessed = list
self.target_source = None
self.custom = custom
self.make_probe_state_callback = make_probe_state_callback
if len(self.target_list_unprocessed) > 0:
self.target_source = "list"
elif self.target_filename:
self.target_source = "file"
elif custom:
self.target_source = "custom"
else:
raise Exception("[E] __init__: No target source set")
def get_probe_state_generator(self, probes):
if self.custom: # format: (ip, port, name, payload_bin)
probe_index = 0
for probe_tuple in probes:
ip = probe_tuple[0]
port = probe_tuple[1]
name = probe_tuple[2]
payload_bin = probe_tuple[3]
cps = self.make_probe_state_callback(ip, probes, probe_index)
cps.payload_bin = payload_bin
yield cps
else:
for probe_index in range(len(probes)):
for target in self._get_targets():
yield self.make_probe_state_callback(target, probes, probe_index)
def get_generator(self):
return self._get_targets()
# generator in case we are passed more hosts than we can fit in memory
def _get_targets(self):
if self.target_source == "list":
for t in self._get_targets_from_list(self.target_list_unprocessed):
yield t
elif self.target_source == "file":
for t in self._get_targets_from_file(self.target_filename):
yield t
else:
raise Exception("[E] _get_targets: No target source set")
# unexpanded list like [ 10.0.0.1, 10.0.0.10-10.0.0.20, 10.0.2.0/24 ]
def _get_targets_from_list(self, targets): # list
for target in targets:
for t in self._get_targets_from_string(target):
yield t
def _get_targets_from_string(self, target): # str
if re.match(r"^%s-%s$" % (ip_regex, ip_regex), target):
for t in self._get_targets_from_ip_range(target):
yield t
elif re.match(r"^%s$" % ip_regex, target):
yield target
elif re.match(r"^%s$" % cidr_regex, target):
for t in self._get_target_ips_from_cidr(target):
yield t
else:
print("[E] %s is not a valid ip, ip range or cidr" % target)
sys.exit(0)
# add targets from file
def _get_targets_from_file(self, file): # str
if not os.path.isfile(file):
print("[E] File %s does not exist" % file)
sys.exit(0)
with open(file, 'r') as f:
for target in f:
# strip leading/trailing whitespace
target = target.strip()
# ignore comments
if target.startswith('#'):
continue
# ignore empty lines
if not target:
continue
# ignore lines with only whitespace
if re.match(r'^\s+$', target):
continue
# yield from self._get_targets_from_string(target)
for t in self._get_targets_from_string(target):
yield t
# add targets from ip range like 10.0.0.1-10.0.0.10
def _get_targets_from_ip_range(self, ip_range): # str
# check ip_range is in the right format
if not re.match(r"^%s-%s$" % (ip_regex, ip_regex), ip_range):
print("[E] IP range %s is not in the right format" % ip_range)
sys.exit(0)
# get ip range
ip_range = ip_range.split('-')
# get ip range start and end
start_ip = ip_range[0]
if sys.version_info.major == 2:
start_ip = start_ip.decode("utf8")
end_ip = ip_range[1]
if sys.version_info.major == 2:
end_ip = end_ip.decode("utf8")
ip_range_start = ipaddress.ip_address(start_ip)
ip_range_end = ipaddress.ip_address(end_ip)
# add targets
for ip_int in range(int(ip_range_start), int(ip_range_end) + 1):
yield str(ipaddress.ip_address(ip_int))
def _get_target_ips_from_cidr (self, cidr): # str
# check cidr is in the right format
m = re.match(cidr_regex, cidr)
if not m:
print("[E] CIDR %s is not in the right format" % cidr)
sys.exit(0)
if int(m.group(1)) > 32:
print("[E] Netmask for %s is > 32" % cidr)
sys.exit(0)
if int(m.group(1)) < 8:
print("[E] Netmask for %s is < 8" % cidr)
sys.exit(0)
# if running python2, cidr must be unicode, not str
if sys.version_info.major == 2:
cidr = cidr.decode("utf8")
ip_range = ipaddress.ip_network(cidr, False)
# add targets
for ip_int in range(int(ip_range.network_address), int(ip_range.broadcast_address) + 1):
yield str(ipaddress.ip_address(ip_int))
class ProbeStateUdp:
def __init__(self, target, probe_index):
self.target_ip = target
self.probe_index = probe_index
self.probe_sent_time = None
self.probes_sent = 0
def __repr__(self):
return "%s(%s, %s, %s)" % (type(self).__name__, self.target_ip, self.probe_sent_time, self.probes_sent)
# Each probe state can have a different probe
class ProbeStateUdpCustom(ProbeStateUdp):
def __init__(self, target, probe_index):
super().__init__(target, probe_index)
self.payload_bin = None
def __repr__(self):
return "%s(%s, %s, %s)" % (type(self).__name__, self.target, self.probe_sent_time, self.probes_sent)
class ScannerUDP(ScannerBase):
def __init__(self):
super(ScannerUDP, self).__init__()
#
# Specific to UDP
#
self.next_timer_adjust = None
self.custom_probes = None
self.probe_states_queue = collections.deque()
self.unexpected_replies = 0
self.send_buffer_warning_displayed = False
#
# Common to TCP and UDP, but set to different values
#
self.payload_len_estimate = 10 # a guess
self.packet_overhead = 42 # 14 bytes for ethernet frame + 20 bytes IP header + 8 bytes UDP header
self.host_count_high_water = 100000
self.host_count_low_water = 90000
#
# Methods that are implemented differently for TCP and UDP Scanners
#
def dump(self):
print("")
print_header(self.header)
if self.target_filename:
print("Targets file: ................ %s" % self.target_filename)
if self.target_list_unprocessed:
print("Targets: ..................... %s" % ", ".join(self.target_list_unprocessed))
if self.probes: # may not be used if caller is using custom probes
print("Probes: ...................... %s Probes: %s" % (len(self.probes), ", ".join([p[1] for p in self.probes])))
print("Retries: ..................... %s" % (self.max_probes - 1))
print("Bandwidth: ................... %s bits/second" % self.bandwidth_bits_per_second)
if self.packet_rate:
print("Packet rate: ................. %s packets/second" % self.packet_rate)
print("RTT: ......................... %s seconds" % self.rtt)
print("Interpacket Interval Per Host: %s seconds" % self.inter_packet_interval_per_host)
print("Inter-packet interval: ....... %s seconds" % self.inter_packet_interval)
print("Packet overhead: ............. %s" % self.packet_overhead)
# Note that we can't print targets / target_count here because we'd drain the generator (which could contain millions of targets)
print_footer()
def set_rtt(self, rtt):
self.rtt = float(rtt)
def set_probes(self, probes): # tuple of (port, probe_name, payload_hex)
self.probes = []
for probe in probes:
probe_bin = None
if probe[2] is not None:
probe_bin = bytes(bytearray.fromhex(probe[2]))
probe_with_bin = probe + (probe_bin,)
self.probes.append(probe_with_bin)
def start_scan(self):
# check we have probes
if not self.probes:
print("[E] No probes set. Call set_probes() method before starting scan.")
sys.exit(0)
# Convert payload hex into binary; calculate inter-packet interval
self.inter_packet_interval = 8 * (self.packet_overhead + self.payload_len_estimate) / float(self.bandwidth_bits_per_second)
def make_probe_state_callback(target, probes, probe_index):
if self.custom_probes:
return ProbeStateUdpCustom(target, probe_index)
else :
return ProbeStateUdp(target, probe_index)
# Set up target generator
target_generator = None
if self.target_source == "file":
target_generator = TargetGenerator(make_probe_state_callback, filename=self.target_filename)
elif self.target_source == "list":
target_generator = TargetGenerator(make_probe_state_callback, list=self.target_list_unprocessed)
elif self.target_source == "custom":
target_generator = TargetGenerator(make_probe_state_callback, custom=True)
else:
print("[E] Unknown target source: %s. Call add_targets_from_file() or add_targets() method before starting scan." % self.target_source)
sys.exit(0)
probes_state_generator_function = None
if self.target_source == "custom":
probes_state_generator_function = target_generator.get_probe_state_generator(self.custom_probes)
else:
probes_state_generator_function = target_generator.get_probe_state_generator(self.probes)
# Initialize stats for how many of each probe type are in the queue
for probe_index in range(len(self.probes)):
self.count_in_queue[probe_index] = 0
last_send_time = None
self.dump()
self.scan_start_time_internal = time.time() # used for user-facing stats
self.scan_start_time = time.time() # used for scanner timings only
scan_running = True
more_hosts = True
highest_probe_index_seen = -1
self.sleep_reasons["packet_quota"] = 0
self.sleep_reasons["bandwidth_quota"] = 0
self.sleep_reasons["port_states"] = 0
while scan_running:
#
# add probes to queue
#
# if queue has capacity, create more probestate objects for up to host_count_high_water hosts; add them to queue
if more_hosts and len(self.probe_states_queue) < self.host_count_low_water:
more_hosts = False # if we complete the for loop, there are no more probes to add
for ps in probes_state_generator_function:
# Don't add to queue if target is in blocklist
if ps.target_ip in self.blocklist:
print("[i] Skipping target %s because it is in the blocklist" % ps.target_ip)
continue
# Count the number of hosts we are scanning
if ps.probe_index == 0:
self.host_count += 1
# Inform user went we start scanning a new probe type
if ps.probe_index > highest_probe_index_seen:
self.inform_starting_probe_type(ps.probe_index)
highest_probe_index_seen = ps.probe_index
# Add to queue
self.probe_states_queue.append(ps)
# Increment count of probes of this type in queue
self.count_in_queue[ps.probe_index] += 1
# Create socket if needed
if ps.probe_index not in self.probe_index_to_socket_dict:
# Create socket to send packets from. All probes of the same type are sent from same source port.
# We don't use the same source port for all probes because if we have two DNS probes (for example)
# it will be difficult to match the replies to the probe.
sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
sock.setblocking(False)
# This should set buffer to 425984, but maybe some OS's have larger buffers.
# A large buffer is important if users scan locally attached networks. UDP packets
# will be buffered while ARP fails to resolve the MAC address of the target.
sock.setsockopt(socket.SOL_SOCKET, socket.SO_SNDBUF, int(1000000))
# Allow sending to broadcast addresses
sock.setsockopt(socket.SOL_SOCKET, socket.SO_BROADCAST, 1)
self.probe_index_to_socket_dict[ps.probe_index] = sock
# If we've reached the high watermark, exit the for loop
if len(self.probe_states_queue) >= self.host_count_high_water:
# If we exit the for loop early, there are more probes to add
more_hosts = True
break
# If we're not within quotas, wait until we are:
# * bandwidth quota
# * packet rate quota
# * probe state < at least one probe state is ready to send
self.wait_for_quotas() # TODO doesn't work properly unless inter_packet_interface_per_host is about 25% of rtt
# if queue has items, pop one off
packet_count_to_send = self.get_available_quota_packets()
# if sending a packet now won't exceed quotas, send a packet
for packet_counter in range(min(packet_count_to_send, len(self.probe_states_queue))):
now = time.time()
# if queue has items, pop one off
if len(self.probe_states_queue) > 0:
send_buffer_full = False
ps = self.probe_states_queue.popleft()
# Check if we already sent all probes to this host + we're past the RTT window
if ps.probes_sent >= self.max_probes:
if time.time() > ps.probe_sent_time + self.rtt:
# We've sent max probes to this host and we're past the RTT window, so we're done with this host
# we don't add this host back to the queue
# Decrement count of probes of this type in queue
self.decrease_count_in_queue(ps.probe_index)
else:
self.probe_states_queue.append(ps) # add back to queue, but don't send more probes to this host
# We need to send a packet. Also add back to queue so we can check for replies later
else:
self.probe_states_queue.append(ps) # add back to queue
# Check if probe is due for this host: i.e. if we're past the inter-packet interval for this host; or we never sent a probe; or no inter-packet interval is configured
if (ps.probe_sent_time is None) or (self.packet_rate_per_host and (time.time() > ps.probe_sent_time + self.inter_packet_interval_per_host)):
# Send probe
sent = False
remove_and_blacklist = False
payload_bin = self.get_probe_payload_bin(ps.probe_index)
if payload_bin is None: # It's a custom probe state
payload_bin = ps.payload_bin
while not sent and not remove_and_blacklist:
sock = self.probe_index_to_socket_dict[ps.probe_index]
port = self.get_probe_port(ps.probe_index)
# For the last few probes, start noting the time we send the last probe. For the stats.
#if more_hosts == 0 and ps.probes_sent == self.max_probes - 1: # This doesn't work if we get a reply before we send the last probe
if not more_hosts:
last_send_time = time.time()
# At around 16Mbit/s we get occassional errors on sendto: PermissionError: [Errno 1] Operation not permitted
# so we catch these errors and retry
try:
sock.sendto(payload_bin, (ps.target_ip, port))
sent = True
except socket.error as e:
# check if we're running on windows
if sys.platform == 'win32':
# The socket will no longer be usable
print("[E] %s: sending to %s:%s. Use -B to blocklist. Fatal error on Windows." % (e, ps.target_ip, port))
sys.exit(1)
else:
if "Errno 13" in str(e):
print("[W] %s: sending to %s:%s. Use -B to blocklist. Auto-adding to blocklist" % (e, ps.target_ip, port))
remove_and_blacklist = True
if "Errno 11" in str(e):
if not self.send_buffer_warning_displayed:
print("[W] %s: sending to %s:%s." % (e, ps.target_ip, port))
print("[I] Errno 11 means send buffer is full (SO_SNDBUF). This will slow the scan down.")
print("""
Cause: Scanning locally attached networks (i.e. not through a gateway). Loopback is not affected by this problem.
Buffers fill up while the kernel fails to resolve the MAC address of the target (using ARP).
Possible workarounds:
1) Scan only live hosts on the local network (do an ARP scan to find them)
2) Fix the code 1: use a pool of sockets for sending; or
3) Fix the code 2: check if target is local and skip it if there's no ARP cache entry
""")
print("[I] Attempting to auto-throttle scan (this is going to make it slow)")
self.send_buffer_warning_displayed = True
# Sleep to letter the buffer empty a bit
# We can't sleep too long or we might miss replies
time.sleep(0.1)
if self.next_timer_adjust is None or time.time() > self.next_timer_adjust:
# Intervals of 0.002 - 0.003 worked will during testing. So increments of
# 0.0003 should work to help us locate a suitable interval.
old_interval = self.inter_packet_interval
self.inter_packet_interval += 0.0003
# As we just slept, the scanner timers will be disrupted, so we need to reset
new_bandwidth_bits_per_second = int(8 * (self.payload_len_estimate + self.packet_overhead) / self.inter_packet_interval)
print("[I] Auto-adjusting bandwidth to %s bits per second" % new_bandwidth_bits_per_second)
self.set_bandwidth(new_bandwidth_bits_per_second)
self.scan_start_time_internal = time.time() # TODO need to track the real start time AND the start time used for timing.
# 0.9 seconds should be enough to let the buffer empty a bit
# after that we'll wait another 0.1 seconds to let the buffer empty a bit more
# This seems a slow way to adjust the timer, but if we go faster, we risk
# overshooting and the scan will run more slowly than necessary
self.next_timer_adjust = time.time() + 0.9
# We didn't send a packet, but we need to set this to avoid a retry
# Retrying is bad because we know the send buffer is full.
sent = True
send_buffer_full = True
if remove_and_blacklist:
print("[W] Target IP %s will be removed from scan queue and added to blocklist" % ps.target_ip)
self.add_to_blocklist(ps.target_ip)
try:
self.probe_states_queue.remove(ps)
except ValueError:
print("[W] Couldn't remove from queue")
print(self.probe_states_queue)
exit(1)
if send_buffer_full:
# Break out of the for-loop so we don't send any more packets right away
break
# Update stats
self.probes_sent_count += 1
ps.probes_sent += 1
ps.probe_sent_time = time.time()
self.bytes_sent += len(payload_bin) + self.packet_overhead
else:
# sleep for self.inter_packet_interval seconds
time.sleep(self.inter_packet_interval) # python might sleep for too long - e.g. minimum of 1-10ms. That's OK, we'll be less likely to sleep next time round the loop.
# recv some packets
# for efficiency we only receive after every 10 packets sent, or if we're past the next recv time
# whichever is sooner
now = time.time()
if self.probes_sent_count % 10 == 0 or self.next_recv_time < now:
self.next_recv_time = now + self.recv_interval
scan_running = self.receive_packets(self.get_socket_list()) or more_hosts
# recv any remaining packets
self.receive_packets(self.get_socket_list())
# self.scan_duration = time.time() - self.scan_start_time
self.scan_duration = last_send_time - self.scan_start_time
# scan_duration can be 0 for quick scans on windows
if self.scan_duration == 0:
self.scan_duration = 0.001
self.scan_rate_bits_per_second = int(8 * self.bytes_sent / self.scan_duration)
if self.debug:
self.debug_write_log()
def reset_scan_timers(self):
pass
# returns True if we have more targets to probe; False if not
def receive_packets(self, socket_list):
if socket_list:
# check if there are any packets to receive
readable, _, _ = select.select(socket_list, [], [], 0)
# recv if there are
for s in readable:
data, addr = (None, None)
try:
data, addr = s.recvfrom(1024) #
except socket.error as e:
continue
srcip = addr[0]
srcport = addr[1]
socket_probe_index = self.get_probe_index_from_socket(s)
if socket_probe_index is None:
print("[W] Received reply from %s:%s but don't know which probe it's for: %s" % (srcip, srcport, str_or_bytes_to_hex(data)))
continue
port = self.get_probe_port(socket_probe_index)
probe_name = self.get_probe_name(socket_probe_index)
found = False
# search for probe state
for probe_state in self.probe_states_queue:
if socket_probe_index == probe_state.probe_index and probe_state.target_ip == srcip and port == srcport:
if self.reply_callback_function:
self.reply_callback_function(probe_name, srcip, port, str_or_bytes_to_hex(data))
else:
print("Received reply to probe %s (target port %s) from %s:%s: %s" % (probe_name, port, srcip, srcport, str_or_bytes_to_hex(data)))
self.probe_states_queue.remove(probe_state)
self.decrease_count_in_queue(probe_state.probe_index)
found = True
self.replies += 1
if self.debug:
self.debug_log_reply(probe_name, srcip, port, data)
break
if not found:
print("[W] Received unexpected reply to probe %s (target port %s) reply from %s:%s: %s" % (probe_name, port, srcip, srcport, str_or_bytes_to_hex(data)))
self.unexpected_replies += 1
if len(self.probe_states_queue) == 0:
return False
return True
def inform_starting_probe_type(self, probe_index):
print("[i] Sending probe %s to targets on port %s..." % (self.get_probe_name(probe_index), self.get_probe_port(probe_index)))
def decrease_count_in_queue(self, probe_index):
self.count_in_queue[probe_index] -= 1
if self.count_in_queue[probe_index] == 0:
self.close_socket_for_probe_index(probe_index)
def get_queue_length(self):
return len(self.probe_states_queue)
def queue_peek_first(self):
return self.probe_states_queue[0]
def get_socket_list(self):
return list(self.probe_index_to_socket_dict.values())
#
# UDP Specific Methods
#
def set_custom_probes(self, probes): # tuple of (ip, port, probe_name, payload_bin)
self.custom_probes = probes
self.target_source = "custom"
def close_socket_for_probe_index(self, probe_index):
socket = self.probe_index_to_socket_dict[probe_index]
if self.debug:
print("[D] Closing socket for probe index %s (%s on port %s)" % (probe_index, self.get_probe_name(probe_index), self.get_probe_port(probe_index)))
socket.close()
del self.probe_index_to_socket_dict[probe_index]
#
# Helper functions
#
# recvfrom returns bytes in python3 and str in python3. This function converts either to hex string
def str_or_bytes_to_hex(str_or_bytes):
return "".join("{:02x}".format(c if type(c) is int else ord(c)) for c in str_or_bytes)
def get_time():
offset = time.timezone
if time.localtime().tm_isdst:
offset = time.altzone
offset = int(offset / 60 / 60 * -1)
if offset > 0:
offset = "+" + str(offset)
else:
offset = str(offset)
return time.strftime("%Y-%m-%d %H:%M:%S", time.localtime()) + " UTC" + offset
def round_pretty(x):
# avoid math errors
if x < 0.01:
x = 0.01
if x <= 100:
# round to 3 significant figures
return round(x, 2-int(math.floor(math.log10(abs(x)))))
else:
# Otherwise, just covert to int
return int(x)
def print_header(message, width=80):
message_len = len(message) + 2 # a space either side
pad_left = int((width - message_len) / 2)
pad_right = width - message_len - pad_left
print("%s %s %s" % ("=" * pad_left, message, "=" * pad_right))
def print_footer(width=80):
print("=" * width)
# Convert a string to a number, with support for K, M, G suffixes
def expand_number(number): # int or str
number_as_string = str(number)
if number_as_string.lower().endswith('k'):
return int(number_as_string[:-1]) * 1000
elif number_as_string.lower().endswith('m'):
return int(number_as_string[:-1]) * 1000000
elif number_as_string.lower().endswith('g'):
return int(number_as_string[:-1]) * 1000000000
else:
if not number_as_string.isdigit():
print("[E] %s should be an integer or an integer with k, m or g suffix" % number_as_string)
sys.exit(0)
else:
return int(number_as_string)
# return list of ports from a string like "1,2,3-5,6"
def expand_port_list(ports):
ports_list = []
for port in ports.split(','):
if '-' in port:
port_range = port.split('-')
if len(port_range) != 2:
print("[E] Port range %s is not in the right format" % port)
sys.exit(0)
for p in range(int(port_range[0]), int(port_range[1]) + 1):
if 0 < p < 65536:
ports_list.append(p)
else:
print("[E] Port %s is not in in range 1-65535" % p)
sys.exit(0)
else:
port = int(port)
if 0 < port < 65536:
ports_list.append(port)
else:
print("[E] Port %s is not in in range 1-65535" % port)
sys.exit(0)
return ports_list
# hex to bytes
def hex_decode(hex_string):