1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
|
#include <sys/types.h>
#include <sys/socket.h>
#include <sys/wait.h>
#include <sys/ioctl.h>
#include <net/if.h>
#include <netinet/in.h>
#include <netdb.h>
#include <pcap.h>
#include <fcntl.h>
#include <stdio.h>
#include <stdlib.h>
#include <err.h>
#include <errno.h>
#include <unistd.h>
#include <signal.h>
#include <string.h>
#include <libglouglou.h>
#include <libggnet.h>
#include "gg_sniff.h"
#if defined(__OpenBSD__)
#include "pcap-int.h"
#endif
#define GG_SNIFF_USER "_gg_sniff"
#if defined(__OpenBSD__)
void __dead
#else
void
#endif
usage(void)
{
extern char *__progname;
fprintf(stderr, "usage: %s [-hv]", __progname);
exit(1);
}
static void
sig_handler(int sig, short why, void *data)
{
log_info("got signal %d", sig);
if (sig == SIGINT || sig == SIGTERM)
event_loopexit(NULL);
}
int
main(int argc, char **argv)
{
struct event_base *ev_base;
struct ggnet *net;
struct event ev_sigint, ev_sigterm, ev_sigchld, ev_sighup;
int pcap_init = 0;
int sniff_init = 0;
int loglevel = 0;
int op;
if (geteuid() != 0)
errx(1, "must be root");
while ((op = getopt(argc, argv, "hv")) != -1) {
switch (op) {
case 'h':
usage();
/* NOTREACHED */
case 'v':
loglevel++;
break;
default:
usage();
/* NOTREACHED */
}
}
gg_log_init(GG_SNIFF_LOGFILE, loglevel);
ev_base = event_base_new();
net = ggnet_new();
if (!net)
goto quit;
ggcli = gg_client_connect();
if (!ggcli)
goto quit;
pcap_init = ggsniff_pcap_init(ev_base);
if (!pcap_init)
goto quit;
sniff_init = ggsniff_dns_init(ev_base);
if (!sniff_init)
goto quit;
signal_set(&ev_sigint, SIGINT, sig_handler, NULL);
signal_set(&ev_sigterm, SIGTERM, sig_handler, NULL);
signal_set(&ev_sigchld, SIGCHLD, sig_handler, NULL);
signal_set(&ev_sighup, SIGHUP, sig_handler, NULL);
signal_add(&ev_sigint, NULL);
signal_add(&ev_sigterm, NULL);
signal_add(&ev_sigchld, NULL);
signal_add(&ev_sighup, NULL);
signal(SIGPIPE, SIG_IGN);
droppriv(GG_SNIFF_USER, 1, NULL);
log_info("entering event loop");
event_base_dispatch(ev_base);
quit:
if (dns_init)
ggsniff_dns_shutdown();
if (sniff_init)
ggsniff_pcap_shutdown();
if (ggcli)
gg_client_disconnect(ggcli);
if (net)
ggnet_free(net);
log_info("exiting");
gg_log_shutdown();
exit(0);
}
|