mirror of
https://github.com/ValdikSS/GoodbyeDPI.git
synced 2026-10-05 05:07:58 +03:00
231 lines
9.8 KiB
C
231 lines
9.8 KiB
C
#include <stdio.h>
|
|
#include <stdlib.h>
|
|
#include <ctype.h>
|
|
#include <unistd.h>
|
|
#include <in6addr.h>
|
|
#include <ws2tcpip.h>
|
|
#include "windivert.h"
|
|
#include "goodbyedpi.h"
|
|
|
|
static const unsigned char fake_http_request[] = "GET / HTTP/1.1\r\nHost: www.w3.org\r\n"
|
|
"User-Agent: curl/7.65.3\r\nAccept: */*\r\n"
|
|
"Accept-Encoding: deflate, gzip, br\r\n\r\n";
|
|
static const unsigned char fake_https_request[] = {
|
|
0x16, 0x03, 0x01, 0x02, 0x00, 0x01, 0x00, 0x01, /* ........ */
|
|
0xfc, 0x03, 0x03, 0xe4, 0x5d, 0x79, 0x60, 0xec, /* ....]y`. */
|
|
0x73, 0xa8, 0xaf, 0xc0, 0x1b, 0x6e, 0xba, 0x51, /* s....n.Q */
|
|
0xd4, 0x2f, 0x0c, 0xa9, 0xa3, 0xdf, 0xb0, 0xf4, /* ./...... */
|
|
0x1e, 0x60, 0x1b, 0x71, 0x09, 0xfd, 0xd4, 0x6a, /* .`.q...j */
|
|
0xca, 0x9f, 0xf6, 0x20, 0x3c, 0x6a, 0x0f, 0xfa, /* ... <j.. */
|
|
0x0b, 0x25, 0xda, 0x8f, 0x29, 0x1e, 0x93, 0xfa, /* .%..)... */
|
|
0x7c, 0x78, 0xf3, 0x3f, 0x5c, 0xbb, 0x16, 0x6e, /* |x.?\..n */
|
|
0xfa, 0xd0, 0x90, 0xdd, 0xac, 0x54, 0x39, 0x75, /* .....T9u */
|
|
0x10, 0xd6, 0xd7, 0xc5, 0x00, 0x48, 0x13, 0x02, /* .....H.. */
|
|
0x13, 0x03, 0x13, 0x01, 0x13, 0x04, 0xc0, 0x2c, /* ......., */
|
|
0xc0, 0x30, 0xcc, 0xa9, 0xcc, 0xa8, 0xc0, 0xad, /* .0...... */
|
|
0xc0, 0x2b, 0xc0, 0x2f, 0xc0, 0xac, 0xc0, 0x23, /* .+./...# */
|
|
0xc0, 0x27, 0xc0, 0x0a, 0xc0, 0x14, 0xc0, 0x09, /* .'...... */
|
|
0xc0, 0x13, 0x00, 0x9d, 0xc0, 0x9d, 0x00, 0x9c, /* ........ */
|
|
0xc0, 0x9c, 0x00, 0x3d, 0x00, 0x3c, 0x00, 0x35, /* ...=.<.5 */
|
|
0x00, 0x2f, 0x00, 0x9f, 0xcc, 0xaa, 0xc0, 0x9f, /* ./...... */
|
|
0x00, 0x9e, 0xc0, 0x9e, 0x00, 0x6b, 0x00, 0x67, /* .....k.g */
|
|
0x00, 0x39, 0x00, 0x33, 0x00, 0xff, 0x01, 0x00, /* .9.3.... */
|
|
0x01, 0x6b, 0x00, 0x00, 0x00, 0x12, 0x00, 0x10, /* .k...... */
|
|
0x00, 0x00, 0x0d, 0x77, 0x69, 0x6b, 0x69, 0x70, /* ...wikip */
|
|
0x65, 0x64, 0x69, 0x61, 0x2e, 0x6f, 0x72, 0x67, /* edia.org */
|
|
0x00, 0x0b, 0x00, 0x04, 0x03, 0x00, 0x01, 0x02, /* ........ */
|
|
0x00, 0x0a, 0x00, 0x16, 0x00, 0x14, 0x00, 0x1d, /* ........ */
|
|
0x00, 0x17, 0x00, 0x1e, 0x00, 0x19, 0x00, 0x18, /* ........ */
|
|
0x01, 0x00, 0x01, 0x01, 0x01, 0x02, 0x01, 0x03, /* ........ */
|
|
0x01, 0x04, 0x00, 0x10, 0x00, 0x0e, 0x00, 0x0c, /* ........ */
|
|
0x02, 0x68, 0x32, 0x08, 0x68, 0x74, 0x74, 0x70, /* .h2.http */
|
|
0x2f, 0x31, 0x2e, 0x31, 0x00, 0x16, 0x00, 0x00, /* /1.1.... */
|
|
0x00, 0x17, 0x00, 0x00, 0x00, 0x31, 0x00, 0x00, /* .....1.. */
|
|
0x00, 0x0d, 0x00, 0x22, 0x00, 0x20, 0x04, 0x03, /* ...". .. */
|
|
0x05, 0x03, 0x06, 0x03, 0x08, 0x07, 0x08, 0x08, /* ........ */
|
|
0x08, 0x09, 0x08, 0x0a, 0x08, 0x0b, 0x08, 0x04, /* ........ */
|
|
0x08, 0x05, 0x08, 0x06, 0x04, 0x01, 0x05, 0x01, /* ........ */
|
|
0x06, 0x01, 0x03, 0x03, 0x03, 0x01, 0x00, 0x2b, /* .......+ */
|
|
0x00, 0x05, 0x04, 0x03, 0x04, 0x03, 0x03, 0x00, /* ........ */
|
|
0x2d, 0x00, 0x02, 0x01, 0x01, 0x00, 0x33, 0x00, /* -.....3. */
|
|
0x26, 0x00, 0x24, 0x00, 0x1d, 0x00, 0x20, 0x86, /* &.$... . */
|
|
0x81, 0xce, 0x35, 0x01, 0x85, 0x6b, 0x1e, 0x0d, /* ..5..k.. */
|
|
0xbd, 0x92, 0xac, 0xf4, 0x9d, 0xcd, 0x5b, 0x1e, /* ......[. */
|
|
0x12, 0x57, 0x21, 0xc0, 0x0c, 0x59, 0xe9, 0x62, /* .W!..Y.b */
|
|
0xe3, 0xe2, 0xa4, 0x8d, 0xfa, 0x1b, 0x2e, 0x00, /* ........ */
|
|
0x15, 0x00, 0xb2, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, /* ........ */
|
|
0x00, 0x00, 0x00, 0x00, 0x00 /* ..... */
|
|
};
|
|
|
|
|
|
static int send_fake_data(const HANDLE w_filter,
|
|
const PWINDIVERT_ADDRESS addr,
|
|
const char *pkt,
|
|
const UINT packetLen,
|
|
const BOOL is_ipv6,
|
|
const BOOL is_https,
|
|
const BYTE set_ttl,
|
|
const BYTE set_checksum,
|
|
const BYTE set_seq
|
|
) {
|
|
char packet_fake[MAX_PACKET_SIZE];
|
|
WINDIVERT_ADDRESS addr_new;
|
|
PVOID packet_data;
|
|
UINT packet_dataLen;
|
|
UINT packetLen_new;
|
|
PWINDIVERT_IPHDR ppIpHdr;
|
|
PWINDIVERT_IPV6HDR ppIpV6Hdr;
|
|
PWINDIVERT_TCPHDR ppTcpHdr;
|
|
unsigned const char *fake_request_data = is_https ? fake_https_request : fake_http_request;
|
|
UINT fake_request_size = is_https ? sizeof(fake_https_request) : sizeof(fake_http_request) - 1;
|
|
|
|
memcpy(&addr_new, addr, sizeof(WINDIVERT_ADDRESS));
|
|
memcpy(packet_fake, pkt, packetLen);
|
|
|
|
addr_new.TCPChecksum = 0;
|
|
addr_new.IPChecksum = 0;
|
|
|
|
if (!is_ipv6) {
|
|
// IPv4 TCP Data packet
|
|
if (!WinDivertHelperParsePacket(packet_fake, packetLen, &ppIpHdr,
|
|
NULL, NULL, NULL, NULL, &ppTcpHdr, NULL, &packet_data, &packet_dataLen,
|
|
NULL, NULL))
|
|
return 1;
|
|
}
|
|
else {
|
|
// IPv6 TCP Data packet
|
|
if (!WinDivertHelperParsePacket(packet_fake, packetLen, NULL,
|
|
&ppIpV6Hdr, NULL, NULL, NULL, &ppTcpHdr, NULL, &packet_data, &packet_dataLen,
|
|
NULL, NULL))
|
|
return 1;
|
|
}
|
|
|
|
if (packetLen + fake_request_size + 1 > MAX_PACKET_SIZE)
|
|
return 2;
|
|
|
|
memcpy(packet_data, fake_request_data, fake_request_size);
|
|
packetLen_new = packetLen - packet_dataLen + fake_request_size;
|
|
|
|
if (!is_ipv6) {
|
|
ppIpHdr->Length = htons(
|
|
ntohs(ppIpHdr->Length) -
|
|
packet_dataLen + fake_request_size
|
|
);
|
|
|
|
if (set_ttl)
|
|
ppIpHdr->TTL = set_ttl;
|
|
}
|
|
else {
|
|
ppIpV6Hdr->Length = htons(
|
|
ntohs(ppIpV6Hdr->Length) -
|
|
packet_dataLen + fake_request_size
|
|
);
|
|
|
|
if (set_ttl)
|
|
ppIpV6Hdr->HopLimit = set_ttl;
|
|
}
|
|
|
|
if (set_seq) {
|
|
// This is the smallest ACK drift Linux can't handle already, since at least v2.6.18.
|
|
// https://github.com/torvalds/linux/blob/v2.6.18/net/netfilter/nf_conntrack_proto_tcp.c#L395
|
|
ppTcpHdr->AckNum = htonl(ntohl(ppTcpHdr->AckNum) - 66000);
|
|
// This is just random, no specifics about this value.
|
|
ppTcpHdr->SeqNum = htonl(ntohl(ppTcpHdr->SeqNum) - 10000);
|
|
}
|
|
|
|
// Recalculate the checksum
|
|
WinDivertHelperCalcChecksums(packet_fake, packetLen_new, &addr_new, 0ULL);
|
|
|
|
if (set_checksum) {
|
|
// ...and damage it
|
|
ppTcpHdr->Checksum = htons(ntohs(ppTcpHdr->Checksum) - 1);
|
|
}
|
|
//printf("Pseudo checksum: %d\n", addr_new.TCPChecksum);
|
|
|
|
WinDivertSend(
|
|
w_filter, packet_fake,
|
|
packetLen_new,
|
|
NULL, &addr_new
|
|
);
|
|
debug("Fake packet: OK");
|
|
|
|
return 0;
|
|
}
|
|
|
|
static int send_fake_request(const HANDLE w_filter,
|
|
const PWINDIVERT_ADDRESS addr,
|
|
const char *pkt,
|
|
const UINT packetLen,
|
|
const BOOL is_ipv6,
|
|
const BOOL is_https,
|
|
const BYTE set_ttl,
|
|
const BYTE set_checksum,
|
|
const BYTE set_seq
|
|
) {
|
|
if (set_ttl) {
|
|
send_fake_data(w_filter, addr, pkt, packetLen,
|
|
is_ipv6, is_https,
|
|
set_ttl, FALSE, FALSE);
|
|
}
|
|
if (set_checksum) {
|
|
send_fake_data(w_filter, addr, pkt, packetLen,
|
|
is_ipv6, is_https,
|
|
FALSE, set_checksum, FALSE);
|
|
}
|
|
if (set_seq) {
|
|
send_fake_data(w_filter, addr, pkt, packetLen,
|
|
is_ipv6, is_https,
|
|
FALSE, FALSE, set_seq);
|
|
}
|
|
return 0;
|
|
}
|
|
|
|
int send_fake_http_request(const HANDLE w_filter,
|
|
const PWINDIVERT_ADDRESS addr,
|
|
const char *pkt,
|
|
const UINT packetLen,
|
|
const BOOL is_ipv6,
|
|
const BYTE set_ttl,
|
|
const BYTE set_checksum,
|
|
const BYTE set_seq
|
|
) {
|
|
return send_fake_request(w_filter, addr, pkt, packetLen,
|
|
is_ipv6, FALSE,
|
|
set_ttl, set_checksum, set_seq);
|
|
}
|
|
|
|
int send_fake_https_request(const HANDLE w_filter,
|
|
const PWINDIVERT_ADDRESS addr,
|
|
const char *pkt,
|
|
const UINT packetLen,
|
|
const BOOL is_ipv6,
|
|
const BYTE set_ttl,
|
|
const BYTE set_checksum,
|
|
const BYTE set_seq
|
|
) {
|
|
return send_fake_request(w_filter, addr, pkt, packetLen,
|
|
is_ipv6, TRUE,
|
|
set_ttl, set_checksum, set_seq);
|
|
}
|