Adds a new SOCKET layer for monitoring socket events, such as BIND, LISTEN, CONNECT, and ACCEPT. These events occur before the flow is established (and unlike the FLOW layer) it is possible to block/drop SOCKET events. Otherwise, this layer is very similar to the FLOW layer, so the PID is available and injection is not possible. This commit should be considered to be a WIP. Other changes: - New socketdump.exe sample. Prints socket events. - Improve IPv6 address parsing. - New helper functions: * WinDivertHelperFormatIPv4Address * WinDivertHelperFormatIPv6Address - Fix REFLECT bugs. - The network 5-tuple can now be accessed at the NETWORK layer. - Various cleanups.
21 lines
530 B
Modula-2
21 lines
530 B
Modula-2
LIBRARY WinDivert
|
|
EXPORTS
|
|
WinDivertDllEntry
|
|
WinDivertOpen
|
|
WinDivertRecv
|
|
WinDivertRecvEx
|
|
WinDivertSend
|
|
WinDivertSendEx
|
|
WinDivertClose
|
|
WinDivertSetParam
|
|
WinDivertGetParam
|
|
WinDivertHelperCalcChecksums
|
|
WinDivertHelperParsePacket
|
|
WinDivertHelperParseIPv4Address
|
|
WinDivertHelperParseIPv6Address
|
|
WinDivertHelperFormatIPv4Address
|
|
WinDivertHelperFormatIPv6Address
|
|
WinDivertHelperCompileFilter
|
|
WinDivertHelperEvalFilter
|
|
WinDivertHelperFormatFilter
|