2 * Copyright (c) 2006, Andrea Bittau <a.bittau@cs.ucl.ac.uk>
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in the
12 * documentation and/or other materials provided with the distribution.
14 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
15 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
16 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
17 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
18 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
19 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
20 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
21 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
22 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
23 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26 * $FreeBSD: src/tools/tools/net80211/stumbler/stumbler.c,v 1.2 2009/07/24 15:31:22 sam Exp $
28 #include <sys/types.h>
29 #include <sys/socket.h>
30 #include <sys/ioctl.h>
31 #include <sys/select.h>
34 #include <net/if_media.h>
36 #include <netproto/802_11/ieee80211_ioctl.h>
37 #include <netproto/802_11/ieee80211.h>
38 #include <net/ethernet.h>
39 #include <netproto/802_11/ieee80211_radiotap.h>
40 #include <sys/endian.h>
51 //int hopfreq = 3*1000; // ms
52 int hopfreq = 500; // ms
53 int sig_reset = 1*1000; // ms
62 struct ieee80211req ireq;
63 struct timeval last_hop;
71 #define CRYPT_WPA1_TKIP 4
72 #define CRYPT_WPA1_TKIP_PSK 5
73 #define CRYPT_WPA1_CCMP 6
74 #define CRYPT_WPA1_CCMP_PSK 7
75 #define CRYPT_80211i 8
76 #define CRYPT_80211i_TKIP 9
77 #define CRYPT_80211i_TKIP_PSK 10
84 unsigned char ssid[256];
92 struct node_info* prev;
93 struct node_info* next;
97 struct node_info* next;
111 char* mac2str(unsigned char* mac) {
112 static char ret[6*3];
114 sprintf(ret, "%.2X:%.2X:%.2X:%.2X:%.2X:%.2X",
115 mac[0], mac[1], mac[2], mac[3], mac[4], mac[5]);
120 char* wep2str(int w) {
141 case CRYPT_WPA1_TKIP:
145 case CRYPT_WPA1_TKIP_PSK:
146 wep = "WPA1-TKIP-PSK";
149 case CRYPT_WPA1_CCMP:
153 case CRYPT_WPA1_CCMP_PSK:
154 wep = "WPA1-CCMP-PSK";
161 case CRYPT_80211i_TKIP:
165 case CRYPT_80211i_TKIP_PSK:
166 wep = "11i-TKIP-PSK";
174 memset(res, ' ', sizeof(res));
175 assert(strlen(wep) < sizeof(res));
176 memcpy(res, wep, strlen(wep));
177 res[sizeof(res)-1] = 0;
181 char* ssid2str(struct node_info* node) {
184 memset(res, ' ', sizeof(res));
186 strcpy(&res[sizeof(res)-2], "]");
189 int left = sizeof(res) - 3;
191 if (strlen(node->ssid) < left)
192 left = strlen(node->ssid);
193 memcpy(&res[1], node->ssid, left);
196 memcpy(&res[1], "<client>", 8);
203 struct node_info* node = nodes;
205 f = fopen("stumbler.log", "w");
215 t = localtime( (time_t*) &node->seen.tv_sec);
217 perror("localtime()");
221 strftime(tim, sizeof(tim), "%H:%M:%S", t);
223 fprintf(f, "%s %s %s %2d %s 0x%.2x\n", tim,
224 mac2str(node->mac), wep2str(node->wep),
225 node->chan, ssid2str(node), node->max);
233 void cleanup(int x) {
239 void die(int p, char* msg) {
249 void display_chan() {
256 snprintf(tmp, sizeof(tmp), "%.2d", chaninfo.chan);
261 void set_chan(int c) {
262 chaninfo.ireq.i_val = c;
264 if (ioctl(ioctl_s, SIOCS80211, &chaninfo.ireq) == -1)
265 die(1, "ioctl(SIOCS80211) [chan]");
269 if (gettimeofday(&chaninfo.last_hop, NULL) == -1)
270 die(1, "gettimeofday()");
275 void setup_if(char *dev) {
280 memset(&chaninfo.ireq, 0, sizeof(chaninfo.ireq));
281 strcpy(chaninfo.ireq.i_name, dev);
282 chaninfo.ireq.i_type = IEEE80211_IOC_CHANNEL;
286 // set iface up and promisc
287 memset(&ifr, 0, sizeof(ifr));
288 strcpy(ifr.ifr_name, dev);
289 if (ioctl(ioctl_s, SIOCGIFFLAGS, &ifr) == -1)
290 die(1, "ioctl(SIOCGIFFLAGS)");
292 flags = (ifr.ifr_flags & 0xffff) | (ifr.ifr_flagshigh << 16);
293 flags |= IFF_UP | IFF_PPROMISC;
295 memset(&ifr, 0, sizeof(ifr));
296 strcpy(ifr.ifr_name, dev);
297 ifr.ifr_flags = flags & 0xffff;
298 ifr.ifr_flagshigh = flags >> 16;
299 if (ioctl(ioctl_s, SIOCSIFFLAGS, &ifr) == -1)
300 die(1, "ioctl(SIOCSIFFLAGS)");
303 void open_bpf(char *dev, int dlt) {
309 for(i = 0;i < 16; i++) {
310 sprintf(buf, "/dev/bpf%d", i);
312 fd = open(buf, O_RDWR);
315 die(1,"can't open /dev/bpf");
323 die(1, "can't open /dev/bpf");
325 strncpy(ifr.ifr_name, dev, sizeof(ifr.ifr_name)-1);
326 ifr.ifr_name[sizeof(ifr.ifr_name)-1] = 0;
328 if(ioctl(fd, BIOCSETIF, &ifr) < 0)
329 die(1, "ioctl(BIOCSETIF)");
331 if (ioctl(fd, BIOCSDLT, &dlt) < 0)
332 die(1, "ioctl(BIOCSDLT)");
335 if(ioctl(fd, BIOCIMMEDIATE, &i) < 0)
336 die(1, "ioctl(BIOCIMMEDIATE)");
358 chaninfo.locked = !chaninfo.locked;
378 if (ch <= 11 && ch >= 1) {
379 set_chan(atoi(chan));
392 void display_node(struct node_info* node) {
398 int sig, max, left, noise;
402 if (y == -1) // offscreen
408 mvaddstr(y, x, mac2str(node->mac));
412 wep = wep2str(node->wep);
419 sprintf(chan, "%.2d", node->chan);
420 mvaddstr(y, x, chan);
424 ssid = ssid2str(node);
426 mvaddstr(y, x, ssid);
432 sig = (int) ( ((double)node->signal)*left/100.0 );
433 noise=(int) ( ((double)node->noise)*left/100.0 );
434 max = (int) ( ((double)node->max)*left/100.0 );
437 for (i = 0; i < noise; i++)
438 mvaddch(y, x++, 'N');
447 for (; x < COLS-1; x++)
453 void update_node(struct node_info* data) {
454 struct node_info* node;
457 assert(data->signal <= 100);
461 // first time [virgin]
463 node = (struct node_info*) malloc(sizeof(struct node_info));
467 memset(node, 0, sizeof(*node));
468 memcpy(node->mac, data->mac, 6);
474 if (memcmp(node->mac, data->mac, 6) == 0)
479 node->next = (struct node_info*)
480 malloc(sizeof(struct node_info));
484 memset(node->next, 0, sizeof(*node->next));
485 memcpy(node->next->mac, data->mac, 6);
486 node->next->prev = node;
487 node->next->pos = node->pos+1;
490 if (node->pos == LINES)
499 // too many nodes for screen
501 struct node_info* ni = nodes;
512 node->signal = data->signal;
513 if (data->signal > node->max)
514 node->max = data->signal;
516 if (gettimeofday(&node->seen, NULL) == -1)
517 die(1, "gettimeofday()");
519 if (data->ssid[0] != 0)
520 strcpy(node->ssid, data->ssid);
521 if (data->chan != -1)
522 node->chan = data->chan;
523 if (data->wep != -1) {
524 // XXX LAME --- won't detect if AP changes WEP mode in
526 if (node->wep != CRYPT_WEP &&
527 node->wep != CRYPT_NONE &&
528 data->wep == CRYPT_WEP) {
531 node->wep = data->wep;
540 void get_beacon_info(unsigned char* data, int rd,
541 struct node_info* node) {
543 int blen = 8 + 2 + 2;
545 strcpy(node->ssid, "<hidden>");
547 node->wep = CRYPT_NONE;
551 if (IEEE80211_BEACON_CAPABILITY(data) & IEEE80211_CAPINFO_PRIVACY)
552 node->wep = CRYPT_WEP;
573 if (elen == 1 && data[0] == 0) {
577 memcpy(node->ssid, data, elen);
578 node->ssid[elen] = 0;
590 else if (eid == 221 && node->wep == CRYPT_WEP) {
591 struct ieee80211_ie_wpa* wpa;
593 wpa = (struct ieee80211_ie_wpa*) data;
597 if (!memcmp(wpa->wpa_oui, "\x00\x50\xf2", 3)) {
598 // node->wep = CRYPT_WPA;
603 if (wpa->wpa_type == WPA_OUI_TYPE &&
604 le16toh(wpa->wpa_version) == WPA_VERSION) {
608 node->wep = CRYPT_WPA1;
613 cipher = ((unsigned char*) wpa->wpa_mcipher)[3];
615 ptr = (unsigned char*)wpa + 12 +
616 4 * le16toh(wpa->wpa_uciphercnt);
618 if (elen < (ptr - data + 6))
621 if ( *((unsigned short*) ptr) == 0)
627 if (cipher == WPA_CSE_TKIP) {
628 node->wep = CRYPT_WPA1_TKIP;
630 if (auth == WPA_ASE_8021X_PSK)
631 node->wep = CRYPT_WPA1_TKIP_PSK;
634 if (cipher == WPA_CSE_CCMP) {
635 node->wep = CRYPT_WPA1_CCMP;
637 if (auth == WPA_ASE_8021X_PSK)
638 node->wep = CRYPT_WPA1_CCMP_PSK;
642 else if (eid == 48 && node->wep == CRYPT_WEP) {
645 // XXX no bounds checking
648 if (ptr[0] == 1 && ptr[1] == 0) {
649 unsigned short* count;
653 node->wep = CRYPT_80211i;
655 if (!memcmp(ptr, "\x00\x0f\xac\x02", 4)) {
656 node->wep = CRYPT_80211i_TKIP;
661 count = (unsigned short*) ptr;
664 count = (unsigned short*) ptr;
668 if (!memcmp(ptr,"\x00\x0f\xac\x02", 4)) {
670 node->wep = CRYPT_80211i_TKIP_PSK;
682 int get_packet_info(struct ieee80211_frame* wh,
683 unsigned char* body, int bodylen,
684 struct node_info* node) {
688 node->chan = chaninfo.chan;
693 type = wh->i_fc[0] & IEEE80211_FC0_TYPE_MASK;
695 if (type == IEEE80211_FC0_TYPE_CTL)
698 if (wh->i_addr2[0] != 0) {
699 mvprintw(30,30,"%s %x",mac2str(wh->i_addr2), wh->i_fc[0]);
703 stype = wh->i_fc[0] & IEEE80211_FC0_SUBTYPE_MASK;
705 if (type == IEEE80211_FC0_TYPE_MGT &&
706 stype == IEEE80211_FC0_SUBTYPE_BEACON) {
707 get_beacon_info(body, bodylen, node);
711 else if (type == IEEE80211_FC0_TYPE_DATA &&
712 stype == IEEE80211_FC0_SUBTYPE_DATA) {
714 if (wh->i_fc[1] & IEEE80211_FC1_WEP) {
717 node->wep = CRYPT_WEP;
723 if (*iv & (1 << 1)) {
725 node->wep = CRYPT_WPA;
726 mvprintw(20,20, "shei");
732 if (wh->i_fc[1] & IEEE80211_FC1_DIR_FROMDS)
738 memcpy(node->mac, wh->i_addr2, 6);
742 void radiotap(unsigned char* data, int rd) {
743 struct ieee80211_radiotap_header* rth;
744 struct ieee80211_frame* wh;
746 struct node_info node;
747 int8_t signal_dbm, noise_dbm;
748 uint8_t signal_db, noise_db;
753 rd -= 4; // 802.11 CRC
756 rth = (struct ieee80211_radiotap_header*) data;
759 wh = (struct ieee80211_frame*)
760 ((char*)rth + rth->it_len);
766 body = (char*) wh + sizeof(*wh);
769 if (!get_packet_info(wh, body, rd, &node))
773 body = (char*) rth + sizeof(*rth);
774 signal_dbm = noise_dbm = signal_db = noise_db = 0;
776 for (i = IEEE80211_RADIOTAP_TSFT; i <= IEEE80211_RADIOTAP_EXT; i++) {
777 if (!(rth->it_present & (1 << i)))
781 case IEEE80211_RADIOTAP_TSFT:
782 body += sizeof(uint64_t);
785 case IEEE80211_RADIOTAP_FLAGS:
786 case IEEE80211_RADIOTAP_RATE:
787 body += sizeof(uint8_t);
790 case IEEE80211_RADIOTAP_CHANNEL:
791 body += sizeof(uint16_t)*2;
794 case IEEE80211_RADIOTAP_FHSS:
795 body += sizeof(uint16_t);
798 case IEEE80211_RADIOTAP_DBM_ANTSIGNAL:
804 case IEEE80211_RADIOTAP_DBM_ANTNOISE:
809 case IEEE80211_RADIOTAP_DB_ANTSIGNAL:
810 signal_db = *((unsigned char*)body);
814 case IEEE80211_RADIOTAP_DB_ANTNOISE:
815 noise_db = *((unsigned char*)body);
819 case IEEE80211_RADIOTAP_EXT:
825 signal = signal_dbm - noise_dbm;
828 signal = signal_db - noise_db;
833 node.signal = signal;
835 if (node.signal > 100 || node.signal < 0) {
836 mvprintw(25,25, "sig=%d", node.signal);
839 assert (node.signal <= 100 && node.signal >= 0);
846 static unsigned char buf[4096];
848 struct bpf_hdr* bpfh;
851 rd = read(bpf_s, buf, sizeof(buf));
855 bpfh = (struct bpf_hdr*) buf;
856 rd -= bpfh->bh_hdrlen;
858 if (rd != bpfh->bh_caplen) {
859 assert( rd > bpfh->bh_caplen);
860 rd = bpfh->bh_caplen;
863 data = (unsigned char*) bpfh + bpfh->bh_hdrlen;
867 unsigned long elapsed_ms(struct timeval* now, struct timeval* prev) {
868 unsigned long elapsed = 0;
870 if (now->tv_sec > prev->tv_sec)
871 elapsed = 1000*1000 - prev->tv_usec +
874 assert(now->tv_sec == prev->tv_sec);
875 elapsed = now->tv_usec - prev->tv_usec;
877 elapsed /= 1000; //ms
879 elapsed += (now->tv_sec - prev->tv_sec)*1000;
883 void chanhop(struct timeval* tv) {
884 unsigned long elapsed = 0;
886 if (gettimeofday(tv, NULL) == -1)
887 die(1, "gettimeofday()");
890 elapsed = elapsed_ms(tv, &chaninfo.last_hop);
893 if (elapsed >= hopfreq) {
896 c = chaninfo.chan + 1;
905 // how much can we sleep?
907 elapsed = hopfreq - elapsed;
910 // ok calculate sleeping time...
911 tv->tv_sec = elapsed/1000;
912 tv->tv_usec = (elapsed - tv->tv_sec*1000)*1000;
915 void check_seen(struct timeval* tv) {
916 unsigned long elapsed = 0;
918 int need_refresh = 0;
919 unsigned long min_wait = 0;
920 unsigned long will_wait;
922 will_wait = tv->tv_sec*1000+tv->tv_usec/1000;
923 min_wait = will_wait;
925 struct node_info* node = nodes;
927 if (gettimeofday(&now, NULL) == -1)
928 die(1, "gettimeofday()");
932 elapsed = elapsed_ms(&now, &node->seen);
935 if (elapsed >= sig_reset) {
941 // need to check soon possibly...
945 left = sig_reset - elapsed;
956 // need to sleep for less...
957 if (min_wait < will_wait) {
958 tv->tv_sec = min_wait/1000;
959 tv->tv_usec = (min_wait - tv->tv_sec*1000)*1000;
963 void own(char* ifname) {
967 int dlt = DLT_IEEE802_11_RADIO;
972 open_bpf(ifname, dlt);
975 // XXX innefficient all of this...
976 if (!chaninfo.locked)
983 // especially this...
990 rd = select(bpf_s+1, &fds,NULL , NULL, &tv);
993 if (FD_ISSET(0, &fds))
995 if (FD_ISSET(bpf_s, &fds))
1000 void init_globals() {
1001 ioctl_s = socket(PF_INET, SOCK_DGRAM, 0);
1002 if (ioctl_s == -1) {
1007 chaninfo.locked = 0;
1011 int main(int argc, char *argv[]) {
1015 printf("Usage: %s <iface>\n", argv[0]);
1021 initscr(); cbreak(); noecho();
1024 intrflush(stdscr, FALSE);
1025 keypad(stdscr, TRUE);
1032 signal(SIGINT, cleanup);
1033 signal(SIGTERM, cleanup);