rename proto
This commit is contained in:
+44
-44
@@ -1,30 +1,30 @@
|
|||||||
-- Create a new protocol for your custom packets
|
-- Create a new protocol for your custom packets
|
||||||
my_protocol = Proto("myprotocol", "My Custom Protocol")
|
ilnk_proto = Proto("iLnkP2P", "iLnk")
|
||||||
|
|
||||||
-- Define the fields you want to display in Wireshark
|
-- Define the fields you want to display in Wireshark
|
||||||
my_protocol.fields = {}
|
ilnk_proto.fields = {}
|
||||||
my_protocol.fields.type = ProtoField.string("myprotocol.type", "Type")
|
ilnk_proto.fields.type = ProtoField.string("iLnkP2P.type", "Type")
|
||||||
my_protocol.fields.payload = ProtoField.bytes("myprotocol.payload", "Payload")
|
ilnk_proto.fields.payload = ProtoField.bytes("iLnkP2P.payload", "Payload")
|
||||||
my_protocol.fields.len = ProtoField.uint16("myprotocol.len", "Len", base.HEX)
|
ilnk_proto.fields.len = ProtoField.uint16("iLnkP2P.len", "Packet length", base.HEX)
|
||||||
|
|
||||||
my_protocol.fields.m_type = ProtoField.uint8("myprotocol.m_type", "Stream Type", base.HEX)
|
ilnk_proto.fields.m_type = ProtoField.uint8("iLnkP2P.m_type", "Stream type", base.HEX)
|
||||||
my_protocol.fields.m_stream_id = ProtoField.uint8("myprotocol.m_stream_id", "Stream ID", base.HEX)
|
ilnk_proto.fields.m_stream_id = ProtoField.uint8("iLnkP2P.m_stream_id", "Stream ID", base.HEX)
|
||||||
my_protocol.fields.pkt_seq = ProtoField.uint16("myprotocol.pkt_seq", "Packet ID", base.HEX)
|
ilnk_proto.fields.pkt_seq = ProtoField.uint16("iLnkP2P.pkt_seq", "Packet ID", base.HEX)
|
||||||
my_protocol.fields.elem_count = ProtoField.uint16("myprotocol.elem_count", "Elem count", base.DEC)
|
ilnk_proto.fields.elem_count = ProtoField.uint16("iLnkP2P.elem_count", "Elem count", base.DEC)
|
||||||
|
|
||||||
my_protocol.fields.cmd_payload_len = ProtoField.uint16("myprotocol.cmd_payload_len", "CMD Payload Len", base.HEX)
|
ilnk_proto.fields.cmd_payload_len = ProtoField.uint16("iLnkP2P.cmd_payload_len", "CMD Payload Len", base.HEX)
|
||||||
my_protocol.fields.cmd = ProtoField.uint16("myprotocol.cmd", "CMD", base.HEX)
|
ilnk_proto.fields.cmd = ProtoField.uint16("iLnkP2P.cmd", "CMD", base.HEX)
|
||||||
my_protocol.fields.start = ProtoField.uint16("myprotocol.start", "Start", base.HEX)
|
ilnk_proto.fields.start = ProtoField.uint16("iLnkP2P.start", "Start", base.HEX)
|
||||||
my_protocol.fields.cmd_dest = ProtoField.uint16("myprotocol.cmd_dest", "Dest", base.HEX)
|
ilnk_proto.fields.cmd_dest = ProtoField.uint16("iLnkP2P.cmd_dest", "Dest", base.HEX)
|
||||||
my_protocol.fields.auth_token = ProtoField.bytes("myprotocol.auth_token", "CMD auth token", base.DASH)
|
ilnk_proto.fields.auth_token = ProtoField.bytes("iLnkP2P.auth_token", "CMD auth token", base.DASH)
|
||||||
my_protocol.fields.cmd_payload = ProtoField.bytes("myprotocol.payload", "CMD Payload", base.DASH)
|
ilnk_proto.fields.cmd_payload = ProtoField.bytes("iLnkP2P.payload", "CMD Payload", base.DASH)
|
||||||
-- jpeg | audio | continuation type?
|
-- jpeg | audio | continuation type?
|
||||||
-- my_protocol.fields.cmd_payload = ProtoField.bytes("myprotocol.payload", "Payload", base.DASH)
|
-- ilnk_proto.fields.cmd_payload = ProtoField.bytes("iLnkP2P.payload", "Payload", base.DASH)
|
||||||
-- my_protocol.fields.cmd_payload = ProtoField.bytes("myprotocol.payload", "Payload", base.DASH)
|
-- ilnk_proto.fields.cmd_payload = ProtoField.bytes("iLnkP2P.payload", "Payload", base.DASH)
|
||||||
|
|
||||||
my_protocol.fields.encrypted = ProtoField.bool("myprotocol.encrypted", "Encrypted")
|
ilnk_proto.fields.encrypted = ProtoField.bool("iLnkP2P.encrypted", "Encrypted")
|
||||||
my_protocol.fields.cmd_type = ProtoField.string("myprotocol.cmd_type", "Cmd Pkt Type")
|
ilnk_proto.fields.cmd_type = ProtoField.string("iLnkP2P.cmd_type", "Cmd Pkt Type")
|
||||||
my_protocol.fields.decrypted_data = ProtoField.bytes("myprotocol.decrypted_data", "Decrypted data")
|
ilnk_proto.fields.decrypted_data = ProtoField.bytes("iLnkP2P.decrypted_data", "Decrypted data")
|
||||||
|
|
||||||
lut = {
|
lut = {
|
||||||
[0xf1f0] = "Close",
|
[0xf1f0] = "Close",
|
||||||
@@ -54,33 +54,33 @@ lut = {
|
|||||||
setmetatable(lut, lut)
|
setmetatable(lut, lut)
|
||||||
|
|
||||||
-- Define a function to dissect the packets
|
-- Define a function to dissect the packets
|
||||||
function my_protocol.dissector(buffer, pinfo, tree)
|
function ilnk_proto.dissector(buffer, pinfo, tree)
|
||||||
local packet_length = buffer:len()
|
local packet_length = buffer:len()
|
||||||
|
|
||||||
local subtree = tree:add(my_protocol, buffer(), "My Custom Protocol Data")
|
local subtree = tree:add(ilnk_proto, buffer(), "iLnkP2P")
|
||||||
|
|
||||||
-- Add the entire packet as a field
|
-- Add the entire packet as a field
|
||||||
local packetname = lut[buffer(0, 2):uint()]
|
local packetname = lut[buffer(0, 2):uint()]
|
||||||
subtree:add(my_protocol.fields.type, packetname)
|
subtree:add(ilnk_proto.fields.type, packetname)
|
||||||
|
|
||||||
-- Set the protocol description in the packet list
|
-- Set the protocol description in the packet list
|
||||||
pinfo.cols.protocol:set("myprotocol")
|
pinfo.cols.protocol:set("iLnkP2P")
|
||||||
if packetname == "DrwAck" then
|
if packetname == "DrwAck" then
|
||||||
subtree:add(my_protocol.fields.len, buffer(2, 2))
|
subtree:add(ilnk_proto.fields.len, buffer(2, 2))
|
||||||
subtree:add(my_protocol.fields.m_type, buffer(4, 1))
|
subtree:add(ilnk_proto.fields.m_type, buffer(4, 1))
|
||||||
subtree:add(my_protocol.fields.m_stream_id, buffer(5, 1))
|
subtree:add(ilnk_proto.fields.m_stream_id, buffer(5, 1))
|
||||||
subtree:add(my_protocol.fields.elem_count, buffer(6, 2))
|
subtree:add(ilnk_proto.fields.elem_count, buffer(6, 2))
|
||||||
|
|
||||||
end
|
end
|
||||||
if packetname == "Drw" then
|
if packetname == "Drw" then
|
||||||
local b_pkt_len = buffer(2, 2)
|
local b_pkt_len = buffer(2, 2)
|
||||||
local pkt_len = b_pkt_len:uint()
|
local pkt_len = b_pkt_len:uint()
|
||||||
subtree:add(my_protocol.fields.len, b_pkt_len)
|
subtree:add(ilnk_proto.fields.len, b_pkt_len)
|
||||||
subtree:add(my_protocol.fields.m_type, buffer(4, 1))
|
subtree:add(ilnk_proto.fields.m_type, buffer(4, 1))
|
||||||
subtree:add(my_protocol.fields.m_stream_id, buffer(5, 1))
|
subtree:add(ilnk_proto.fields.m_stream_id, buffer(5, 1))
|
||||||
subtree:add(my_protocol.fields.pkt_seq, buffer(6, 2))
|
subtree:add(ilnk_proto.fields.pkt_seq, buffer(6, 2))
|
||||||
subtree:add_le(my_protocol.fields.start, buffer(8, 2))
|
subtree:add_le(ilnk_proto.fields.start, buffer(8, 2))
|
||||||
subtree:add_le(my_protocol.fields.cmd, buffer(0xa, 2))
|
subtree:add_le(ilnk_proto.fields.cmd, buffer(0xa, 2))
|
||||||
local b_payload_len = buffer(0xc, 2)
|
local b_payload_len = buffer(0xc, 2)
|
||||||
local payload_len = buffer(0xc, 2):le_uint()
|
local payload_len = buffer(0xc, 2):le_uint()
|
||||||
|
|
||||||
@@ -90,13 +90,13 @@ function my_protocol.dissector(buffer, pinfo, tree)
|
|||||||
cmdtype = "cmd"
|
cmdtype = "cmd"
|
||||||
end
|
end
|
||||||
|
|
||||||
subtree:add_le(my_protocol.fields.cmd_payload_len, b_payload_len)
|
subtree:add_le(ilnk_proto.fields.cmd_payload_len, b_payload_len)
|
||||||
subtree:add_le(my_protocol.fields.cmd_dest, buffer(0xe, 2))
|
subtree:add_le(ilnk_proto.fields.cmd_dest, buffer(0xe, 2))
|
||||||
-- inline value for short-payload bytes
|
-- inline value for short-payload bytes
|
||||||
subtree:add(my_protocol.fields.auth_token, buffer(0x10, 4))
|
subtree:add(ilnk_proto.fields.auth_token, buffer(0x10, 4))
|
||||||
|
|
||||||
subtree:add(my_protocol.fields.cmd_type, cmdtype):set_generated()
|
subtree:add(ilnk_proto.fields.cmd_type, cmdtype):set_generated()
|
||||||
subtree:add(my_protocol.fields.encrypted, payload_len >= 5):set_generated()
|
subtree:add(ilnk_proto.fields.encrypted, payload_len >= 5):set_generated()
|
||||||
if payload_len >= 5 then
|
if payload_len >= 5 then
|
||||||
local payload = buffer(0x14, payload_len - 4)
|
local payload = buffer(0x14, payload_len - 4)
|
||||||
local dec_payload = ByteArray.new()
|
local dec_payload = ByteArray.new()
|
||||||
@@ -120,14 +120,14 @@ function my_protocol.dissector(buffer, pinfo, tree)
|
|||||||
dec_payload:set_index(i, v)
|
dec_payload:set_index(i, v)
|
||||||
end
|
end
|
||||||
local dec_tvb = ByteArray.tvb(dec_payload, "Decrypted payload")
|
local dec_tvb = ByteArray.tvb(dec_payload, "Decrypted payload")
|
||||||
subtree:add(my_protocol.fields.decrypted_data, dec_tvb:range(0, payload_len -4) ):set_generated()
|
subtree:add(ilnk_proto.fields.decrypted_data, dec_tvb:range(0, payload_len -4) ):set_generated()
|
||||||
|
|
||||||
local payload_tvb = ByteArray.tvb(buffer(0x14, payload_len -4):bytes(), "CMD Payload")
|
local payload_tvb = ByteArray.tvb(buffer(0x14, payload_len -4):bytes(), "CMD Payload")
|
||||||
subtree:add(my_protocol.fields.cmd_payload, payload_tvb:range(0, payload_len -4))
|
subtree:add(ilnk_proto.fields.cmd_payload, payload_tvb:range(0, payload_len -4))
|
||||||
end
|
end
|
||||||
|
|
||||||
--
|
--
|
||||||
-- subtree:add(my_protocol.fields.cmd, buffer(0xc, 2))
|
-- subtree:add(ilnk_proto.fields.cmd, buffer(0xc, 2))
|
||||||
|
|
||||||
end
|
end
|
||||||
-- AvcLIB = src/IpcSession.cpp, line 1113, CmdSndProc:BATC609531EXLVS[0:0:10] now CmdSend[start=a11,cmd=1032,len=4,dest=0]=12
|
-- AvcLIB = src/IpcSession.cpp, line 1113, CmdSndProc:BATC609531EXLVS[0:0:10] now CmdSend[start=a11,cmd=1032,len=4,dest=0]=12
|
||||||
@@ -136,7 +136,7 @@ function my_protocol.dissector(buffer, pinfo, tree)
|
|||||||
-- 00000000 f1 d0 00 10 d1 00 00 04 11 0a 32 10 04 00 00 00 ..........2.....
|
-- 00000000 f1 d0 00 10 d1 00 00 04 11 0a 32 10 04 00 00 00 ..........2.....
|
||||||
-- 00000010 50 70 77 35 Ppw5
|
-- 00000010 50 70 77 35 Ppw5
|
||||||
|
|
||||||
subtree:add(my_protocol.fields.payload, buffer(2, packet_length-2))
|
subtree:add(ilnk_proto.fields.payload, buffer(2, packet_length-2))
|
||||||
end
|
end
|
||||||
|
|
||||||
udp_table = DissectorTable.get("udp.port"):add(49512, my_protocol)
|
udp_table = DissectorTable.get("udp.port"):add(49512, ilnk_proto)
|
||||||
|
|||||||
Reference in New Issue
Block a user