*
* $Id$
*
- * Ethereal - Network traffic analyzer
- * By Gerald Combs <gerald@ethereal.com>
+ * Wireshark - Network traffic analyzer
+ * By Gerald Combs <gerald@wireshark.org>
* Copyright 1998 Gerald Combs
*
* This program is free software; you can redistribute it and/or
# include "config.h"
#endif
+/*
+ * Just make sure we include the prototype for strptime as well
+ * (needed for glibc 2.2) but make sure we do this only if not
+ * yet defined.
+ */
+#ifndef __USE_XOPEN
+# define __USE_XOPEN
+#endif
+#ifndef _XOPEN_SOURCE
+# define _XOPEN_SOURCE
+#endif
+
+/*
+ * Defining _XOPEN_SOURCE is needed on some platforms, e.g. platforms
+ * using glibc, to expand the set of things system header files define.
+ *
+ * Unfortunately, on other platforms, such as some versions of Solaris
+ * (including Solaris 10), it *reduces* that set as well, causing
+ * strptime() not to be declared, presumably because the version of the
+ * X/Open spec that _XOPEN_SOURCE implies doesn't include strptime() and
+ * blah blah blah namespace pollution blah blah blah.
+ *
+ * So we define __EXTENSIONS__ so that "strptime()" is declared.
+ */
+#ifndef __EXTENSIONS__
+# define __EXTENSIONS__
+#endif
+
#include <ctype.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
-
-/*
- * Just make sure we include the prototype for strptime as well
- * (needed for glibc 2.2)
- */
-#define __USE_XOPEN
+#include <wsutil/file_util.h>
#include <time.h>
#include <glib.h>
#include <errno.h>
#include <assert.h>
-#ifdef NEED_GETOPT_H
-# include "getopt.h"
+#ifdef HAVE_GETOPT_H
+#include <getopt.h>
+#else
+#include "wsgetopt.h"
#endif
#ifdef NEED_STRPTIME_H
static unsigned long num_packets_written = 0;
/* Time code of packet, derived from packet_preamble */
-static gint32 ts_sec = 0;
+static time_t ts_sec = 0;
static guint32 ts_usec = 0;
static char *ts_fmt = NULL;
+static struct tm timecode_default;
/* Input file */
static const char *input_filename;
/* "libpcap" record header. */
struct pcaprec_hdr {
- gint32 ts_sec; /* timestamp seconds */
+ guint32 ts_sec; /* timestamp seconds */
guint32 ts_usec; /* timestamp microseconds */
guint32 incl_len; /* number of octets of packet saved in file */
guint32 orig_len; /* actual length of packet */
}
}
- /* Write PCap header */
- ph.ts_sec = ts_sec;
+ /* Write PCAP header */
+ ph.ts_sec = (guint32)ts_sec;
ph.ts_usec = ts_usec;
if (ts_fmt == NULL) { ts_usec++; } /* fake packet counter */
ph.incl_len = length;
HDR_UDP.length = g_htons(proto_length);
HDR_UDP.checksum = 0;
- u = g_ntohs(in_checksum(&pseudoh, sizeof(pseudoh))) +
+ u = g_ntohs(in_checksum(&pseudoh, sizeof(pseudoh))) +
g_ntohs(in_checksum(&HDR_UDP, sizeof(HDR_UDP))) +
g_ntohs(in_checksum(packet_buf, curr_offset));
HDR_UDP.checksum = g_htons((u & 0xffff) + (u>>16));
HDR_TCP.window = g_htons(0x2000);
HDR_TCP.checksum = 0;
- u = g_ntohs(in_checksum(&pseudoh, sizeof(pseudoh))) +
+ u = g_ntohs(in_checksum(&pseudoh, sizeof(pseudoh))) +
g_ntohs(in_checksum(&HDR_TCP, sizeof(HDR_TCP))) +
g_ntohs(in_checksum(packet_buf, curr_offset));
HDR_TCP.checksum = g_htons((u & 0xffff) + (u>>16));
if (toklen != 0) {
if (packet_preamble_len + toklen > PACKET_PREAMBLE_MAX_LEN)
return; /* no room to add the token to the preamble */
- strcpy(&packet_preamble[packet_preamble_len], str);
- packet_preamble_len += toklen;
+ g_strlcpy(&packet_preamble[packet_preamble_len], str, PACKET_PREAMBLE_MAX_LEN);
+ packet_preamble_len += (int) toklen;
+ if (debug >= 2) {
+ char *c;
+ char xs[PACKET_PREAMBLE_MAX_LEN];
+ g_strlcpy(xs, packet_preamble, PACKET_PREAMBLE_MAX_LEN);
+ while ((c = strchr(xs, '\r')) != NULL) *c=' ';
+ fprintf (stderr, "[[append_to_preamble: \"%s\"]]", xs);
+ }
}
}
/*----------------------------------------------------------------------
* Parse the preamble to get the timecode.
*/
+
static void
parse_preamble (void)
{
if (ts_fmt == NULL)
return;
- ts_sec = 0;
+ /*
+ * Initialize to today localtime, just in case not all fields
+ * of the date and time are specified.
+ */
+
+ timecode = timecode_default;
ts_usec = 0;
/*
* This should cover line breaks etc that get counted.
*/
if ( strlen(packet_preamble) > 2 ) {
- /*
- * Initialize to the Epoch, just in case not all fields
- * of the date and time are specified.
- */
- timecode.tm_sec = 0;
- timecode.tm_min = 0;
- timecode.tm_hour = 0;
- timecode.tm_mday = 1;
- timecode.tm_mon = 0;
- timecode.tm_year = 70;
- timecode.tm_wday = 0;
- timecode.tm_yday = 0;
- timecode.tm_isdst = -1;
-
/* Get Time leaving subseconds */
subsecs = strptime( packet_preamble, ts_fmt, &timecode );
if (subsecs != NULL) {
/* Get the long time from the tm structure */
- ts_sec = (gint32)mktime( &timecode );
+ /* (will return -1 if failure) */
+ ts_sec = mktime( &timecode );
} else
ts_sec = -1; /* we failed to parse it */
/* This will ensure incorrectly parsed dates get set to zero */
if ( -1 == ts_sec )
{
- ts_sec = 0;
+ /* Sanitize - remove all '\r' */
+ char *c;
+ while ((c = strchr(packet_preamble, '\r')) != NULL) *c=' ';
+ fprintf (stderr, "Failure processing time \"%s\" using time format \"%s\"\n (defaulting to Jan 1,1970 00:00:00 GMT)\n",
+ packet_preamble, ts_fmt);
+ if (debug >= 2) {
+ fprintf(stderr, "timecode: %02d/%02d/%d %02d:%02d:%02d %d\n",
+ timecode.tm_mday, timecode.tm_mon, timecode.tm_year,
+ timecode.tm_hour, timecode.tm_min, timecode.tm_sec, timecode.tm_isdst);
+ }
+ ts_sec = 0; /* Jan 1,1970: 00:00 GMT; tshark/wireshark will display date/time as adjusted by timezone */
ts_usec = 0;
}
else
* 10^-6 seconds, we multiply by
* 10^(6-N).
*/
- subseclen = p - subsecs;
+ subseclen = (int) (p - subsecs);
if (subseclen > 6) {
/*
* *More* than 6 digits; 6-N is
}
}
}
+ if (debug >= 2) {
+ char *c;
+ while ((c = strchr(packet_preamble, '\r')) != NULL) *c=' ';
+ fprintf(stderr, "[[parse_preamble: \"%s\"]]\n", packet_preamble);
+ fprintf(stderr, "Format(%s), time(%u), subsecs(%u)\n", ts_fmt, (guint32)ts_sec, ts_usec);
+ }
- /*printf("Format(%s), time(%u), subsecs(%u)\n\n", ts_fmt, ts_sec, ts_usec);*/
-
/* Clear Preamble */
packet_preamble_len = 0;
}
fprintf(stderr,
"Text2pcap %s"
#ifdef SVNVERSION
- " (" SVNVERSION ")"
+ " (" SVNVERSION " from " SVNPATH ")"
#endif
"\n"
"Generate a capture file from an ASCII hexdump of packets.\n"
- "See http://www.ethereal.com for more information.\n"
+ "See http://www.wireshark.org for more information.\n"
"\n"
- "Usage: text2pcap [options] <input-filename> <output-filename>\n"
+ "Usage: text2pcap [options] <infile> <outfile>\n"
"\n"
- "where <input-filename> specifies input filename (use - for standard input)\n"
- " <output-filename> specifies output filename (use - for standard output)\n"
+ "where <infile> specifies input filename (use - for standard input)\n"
+ " <outfile> specifies output filename (use - for standard output)\n"
"\n"
"Input:\n"
- " -o hex|oct parse offsets as (h)ex or (o)ctal, default is hex\n"
- " -t <timefmt> treats the text before the packet as a date/time code;\n"
- " the specified argument is a format string of the sort \n"
+ " -o hex|oct|dec parse offsets as (h)ex, (o)ctal or (d)ecimal; default is hex.\n"
+ " -t <timefmt> treat the text before the packet as a date/time code;\n"
+ " the specified argument is a format string of the sort\n"
" supported by strptime.\n"
" Example: The time \"10:15:14.5476\" has the format code\n"
" \"%%H:%%M:%%S.\"\n"
" NOTE: The subsecond component delimiter must be given\n"
" (.) but no pattern is required; the remaining number\n"
" is assumed to be fractions of a second.\n"
+ " NOTE: Date/time fields from the current date/time are\n"
+ " used as the default for unspecified fields.\n"
"\n"
"Output:\n"
- " -l <typenum> link-layer type number. Default is 1 (Ethernet). \n"
+ " -l <typenum> link-layer type number; default is 1 (Ethernet).\n"
" See the file net/bpf.h for list of numbers.\n"
- " -m <max-packet> max packet length in output, default is %d\n"
+ " Use this option if your dump is a complete hex dump\n"
+ " of an encapsulated packet and you wish to specify\n"
+ " the exact type of encapsulation.\n"
+ " Example: -l 7 for ARCNet packets.\n"
+ " -m <max-packet> max packet length in output; default is %d\n"
"\n"
"Prepend dummy header:\n"
" -e <l3pid> prepend dummy Ethernet II header with specified L3PID\n"
- " (in HEX)\n"
- " Example: -e 0x800\n"
+ " (in HEX).\n"
+ " Example: -e 0x806 to specify an ARP packet.\n"
" -i <proto> prepend dummy IP header with specified IP protocol\n"
- " (in DECIMAL). \n"
+ " (in DECIMAL).\n"
" Automatically prepends Ethernet header as well.\n"
" Example: -i 46\n"
" -u <srcp>,<destp> prepend dummy UDP header with specified\n"
" dest and source ports (in DECIMAL).\n"
- " Automatically prepends Ethernet & IP headers as well\n"
- " Example: -u 30,40\n"
- " -T <srcp>,<destp> prepend dummy TCP header with specified \n"
+ " Automatically prepends Ethernet & IP headers as well.\n"
+ " Example: -u 1000 69 to make the packets look like TFTP/UDP packets.\n"
+ " -T <srcp>,<destp> prepend dummy TCP header with specified\n"
" dest and source ports (in DECIMAL).\n"
- " Automatically prepends Ethernet & IP headers as well\n"
+ " Automatically prepends Ethernet & IP headers as well.\n"
" Example: -T 50,60\n"
- " -s <srcp>,<dstp>,<tag> prepend dummy SCTP header with specified \n"
+ " -s <srcp>,<dstp>,<tag> prepend dummy SCTP header with specified\n"
" dest/source ports and verification tag (in DECIMAL).\n"
- " Automatically prepends Ethernet & IP headers as well\n"
+ " Automatically prepends Ethernet & IP headers as well.\n"
" Example: -s 30,40,34\n"
- " -S <srcp>,<dstp>,<ppi> prepend dummy SCTP header with specified \n"
- " dest/source ports and verification tag 0. \n"
- " It also prepends a dummy SCTP DATA \n"
+ " -S <srcp>,<dstp>,<ppi> prepend dummy SCTP header with specified\n"
+ " dest/source ports and verification tag 0.\n"
+ " Automatically prepends a dummy SCTP DATA\n"
" chunk header with payload protocol identifier ppi.\n"
" Example: -S 30,40,34\n"
"\n"
"Miscellaneous:\n"
- " -h display this help and exit\n"
- " -d detailed debug of parser states \n"
- " -q generate no output at all (automatically turns off -d)\n"
+ " -h display this help and exit.\n"
+ " -d show detailed debug of parser states.\n"
+ " -q generate no output at all (automatically turns off -d).\n"
"",
VERSION, MAX_PACKET);
case 'l': pcap_link_type = strtol(optarg, NULL, 0); break;
case 'm': max_offset = strtol(optarg, NULL, 0); break;
case 'o':
- if (optarg[0]!='h' && optarg[0] != 'o') {
- fprintf(stderr, "Bad argument for '-e': %s\n", optarg);
+ if (optarg[0]!='h' && optarg[0] != 'o' && optarg[0] != 'd') {
+ fprintf(stderr, "Bad argument for '-o': %s\n", optarg);
usage();
}
- offset_base = (optarg[0]=='o') ? 8 : 16;
+ switch(optarg[0]) {
+ case 'o': offset_base = 8; break;
+ case 'h': offset_base = 16; break;
+ case 'd': offset_base = 10; break;
+ }
break;
case 'e':
hdr_ethernet = TRUE;
}
if (strcmp(argv[optind], "-")) {
- input_filename = strdup(argv[optind]);
- input_file = fopen(input_filename, "rb");
+ input_filename = g_strdup(argv[optind]);
+ input_file = ws_fopen(input_filename, "rb");
if (!input_file) {
fprintf(stderr, "Cannot open file [%s] for reading: %s\n",
input_filename, strerror(errno));
}
if (strcmp(argv[optind+1], "-")) {
- output_filename = strdup(argv[optind+1]);
- output_file = fopen(output_filename, "wb");
+ output_filename = g_strdup(argv[optind+1]);
+ output_file = ws_fopen(output_filename, "wb");
if (!output_file) {
fprintf(stderr, "Cannot open file [%s] for writing: %s\n",
output_filename, strerror(errno));
}
ts_sec = time(0); /* initialize to current time */
+ timecode_default = *localtime(&ts_sec);
+ timecode_default.tm_isdst = -1; /* Unknown for now, depends on time given to the strptime() function */
/* Display summary of our state */
if (!quiet) {
if (debug)
fprintf(stderr, "\n-------------------------\n");
if (!quiet) {
- fprintf(stderr, "Read %ld potential packets, wrote %ld packets\n",
- num_packets_read, num_packets_written);
+ fprintf(stderr, "Read %ld potential packet%s, wrote %ld packet%s\n",
+ num_packets_read, (num_packets_read==1) ?"":"s",
+ num_packets_written, (num_packets_written==1)?"":"s");
}
return 0;
}