ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid-8/contrib/ip_cloaking.c
Revision: 1243
Committed: Fri Sep 30 10:47:53 2011 UTC (14 years, 10 months ago) by michael
Content type: text/x-csrc
File size: 14717 byte(s)
Log Message:
- move content of msg.h, ircd_handler.h and handlers.h into parse.h and
  remove headers accordingly
- killed common.h
- remove m_killhost.c and m_flags.c from contrib/
- sort out unused header includes here and there

File Contents

# User Rev Content
1 adx 30 /* MODULE CONFIGURATION FOLLOWS -- please read!! */
2    
3     /* Change these numbers to something else. Please
4     * make sure that they match on ALL servers
5     * to avoid problems!
6     */
7     #define KEY 23857
8     #define KEY2 38447
9     #define KEY3 64709
10    
11     /* END OF MODULE CONFIGURATION */
12    
13     /*
14     * ircd-hybrid: an advanced Internet Relay Chat Daemon (ircd).
15     * ip_cloaking.c: Provides hostname (partial) cloaking for clients.
16     *
17     * Copyright (c) 2005 by the past and present ircd coders, and others.
18     *
19     * This program is free software; you can redistribute it and/or modify
20     * it under the terms of the GNU General Public License as published by
21     * the Free Software Foundation; either version 2 of the License, or
22     * (at you option) any later version.
23     *
24     * This program is distributed in the hope that it will be useful,
25     * but WITHOUT ANY WARRANTY; without even the implied warranty of
26     * MERCHANTABILILTY or FITNESS FOR A PARTICULAR PURPOSE. See the
27     * GNU General Public License for more details.
28     *
29     * You should have recieved a copy of the GNU General Public License
30     * along with this program; if not, write to the Free Software
31     * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307
32     * USA
33     *
34 knight 31 * $Id$
35 adx 30 */
36    
37     /*
38     * Originally re-written from AustNet's VirtualWorld Code.
39     * Virtual World written by Roger 'RogerY' Yerramesetti <rogery@austnet.org>
40     *
41     * Re-written using the crc32 encryption implementation by //ylo based on the original
42     * implementation by Gary S. Brown.
43     *
44     * HiddenHost implementation based on the code from Unreal IRCd by
45     * RaYmAn, NiQuiL, narf, Griever (great thinking) eternal, bball, JK.@ roxnet.org
46     *
47     * Additional ideas and code by ShadowMaster, [-Th3Dud3-] (RageIRCd), Solaris @ Demonkarma.net,
48     * Alan 'knight-' LeVee of the ChatJunkies IRC Network and doughk_ff7.
49     */
50    
51     #include "stdinc.h"
52     #include "whowas.h"
53     #include "channel_mode.h"
54     #include "client.h"
55     #include "hash.h"
56     #include "hook.h"
57     #include "irc_string.h"
58     #include "ircd.h"
59     #include "ircd_defs.h"
60     #include "numeric.h"
61     #include "s_serv.h"
62     #include "s_user.h"
63     #include "send.h"
64     #include "s_conf.h"
65     #include "modules.h"
66     #include "memory.h"
67     #include "s_log.h"
68     #include "sprintf_irc.h"
69    
70     static unsigned int umode_vhost = 0;
71     static int vhost_ipv6_err;
72     static dlink_node *prev_enter_umode;
73     static dlink_node *prev_umode;
74    
75 knight 31 const char *_version = "$Revision$";
76 adx 30
77     static void *reset_ipv6err_flag(va_list);
78     static void *h_set_user_mode(va_list);
79    
80     void _modinit(void)
81     {
82     if (!user_modes['h'])
83     {
84     unsigned int all_umodes = 0, i;
85    
86     for (i = 0; i < 128; i++)
87     all_umodes |= user_modes[i];
88    
89     for (umode_vhost = 1; umode_vhost && (all_umodes & umode_vhost);
90     umode_vhost <<= 1);
91    
92     if (!umode_vhost)
93     {
94     ilog(L_ERROR, "You have more than 32 usermodes, "
95     "IP cloaking not installed");
96     sendto_realops_flags(UMODE_ALL, L_ALL, "You have more than "
97     "32 usermodes, IP cloaking not installed");
98     return;
99     }
100    
101     user_modes['h'] = umode_vhost;
102     assemble_umode_buffer();
103     }
104     else
105     {
106     ilog(L_ERROR, "Usermode +h already in use, IP cloaking not installed");
107     sendto_realops_flags(UMODE_ALL, L_ALL, "Usermode +h already in use, "
108     "IP cloaking not installed");
109     return;
110     }
111    
112     prev_enter_umode = install_hook(entering_umode_cb, reset_ipv6err_flag);
113     prev_umode = install_hook(umode_cb, h_set_user_mode);
114     }
115    
116     void _moddeinit(void)
117     {
118     if (umode_vhost)
119     {
120     dlink_node *ptr;
121    
122     DLINK_FOREACH(ptr, local_client_list.head)
123     {
124     struct Client *cptr = ptr->data;
125     cptr->umodes &= ~umode_vhost;
126     }
127    
128     user_modes['h'] = 0;
129     assemble_umode_buffer();
130    
131     uninstall_hook(entering_umode_cb, reset_ipv6err_flag);
132     uninstall_hook(umode_cb, h_set_user_mode);
133     }
134     }
135    
136     /*
137     * The implementation originally comes from Gary S. Brown. The tables
138     * are a direct transplant of his original concept and have been
139     * changed for randomization purposes. Minor changes were also made
140     * to the crc32-function by //ylo.
141     *
142     * knight-
143     */
144    
145     /* =============================================================
146     * COPYRIGHT (C) 1986 Gary S. Brown. You may use this program, or
147     * code or tables extracted from it, as desired without restriction.
148     *
149     * First, the polynomial itself and its stable of feedback terms. The
150     * polynomial is:
151     *
152     * X^32+X^26+X^23+X^22+X^16+X^12+X^11+X^10+X^8+X^7+X^5+X^4+X^2+X^1+X^0
153     *
154     * Note that we take it "backwards" and put the highest-order term in
155     * the lowest-order bit. The X^32 term is "implied"; the LSB is the
156     * X^31 term, etc. The X^0 term (usually shown as "+1") results in
157     * the MSB being 1.
158     *
159     * Note that the usual hardware shift register implementation, which
160     * is what we're using (we're merely optimizing it by doing eight-bit
161     * chunks at a time) shifts bits into the lowest-order term. In our
162     * implementation, that means shifting towards the right. Why do we
163     * do it this way? Because the calculated CRC must be transmitted in
164     * order from highest-order term to lowest-order term. UARTs transmit
165     * characters in order from LSB to MSB. By storing the CRC this way,
166     * we and it to the UART in the order low-byte to high-byte; the UART
167     * sends each low-bit to high-bit; and the result is transmission bit
168     * by bit from highest-order to lowest-order term without requiring any
169     * bit shuffling on our part. Reception works similarly.
170     *
171     * The feedback term table consists of 256, 32-bit entries. Notes:
172     *
173     * The table can be generated at runtime if desired; code to do so
174     * is shown later. It might not be obvious, but the feedback terms
175     * simply represent the results of eight shift/xor operations for
176     * all combinations of data and CRC register values.
177     *
178     * The values must be right shifted by eight bits by the "updcrc"
179     * logic; the shift must be unsigned (bring in zeroes). On some hardware
180     * you could probably optimize the shift in assembler by using byte-swap
181     * instructions.
182     *
183     * polynomial $edb88320
184     *
185     * --------------------------------------------------------------------
186     */
187    
188     static unsigned long crc32_tab[] = {
189     0x00000000L, 0x77073096L, 0xee0e612cL, 0x990951baL, 0x076dc419L,
190     0x706af48fL, 0xe963a535L, 0x9e6495a3L, 0x0edb8832L, 0x79dcb8a4L,
191     0xe0d5e91eL, 0x97d2d988L, 0x09b64c2bL, 0x7eb17cbdL, 0xe7b82d07L,
192     0x90bf1d91L, 0x1db71064L, 0x6ab020f2L, 0xf3b97148L, 0x84be41deL,
193     0x1adad47dL, 0x6ddde4ebL, 0xf4d4b551L, 0x83d385c7L, 0x136c9856L,
194     0x646ba8c0L, 0xfd62f97aL, 0x8a65c9ecL, 0x14015c4fL, 0x63066cd9L,
195     0xfa0f3d63L, 0x8d080df5L, 0x3b6e20c8L, 0x4c69105eL, 0xd56041e4L,
196     0xa2677172L, 0x3c03e4d1L, 0x4b04d447L, 0xd20d85fdL, 0xa50ab56bL,
197     0x35b5a8faL, 0x42b2986cL, 0xdbbbc9d6L, 0xacbcf940L, 0x32d86ce3L,
198     0x45df5c75L, 0xdcd60dcfL, 0xabd13d59L, 0x26d930acL, 0x51de003aL,
199     0xc8d75180L, 0xbfd06116L, 0x21b4f4b5L, 0x56b3c423L, 0xcfba9599L,
200     0xb8bda50fL, 0x2802b89eL, 0x5f058808L, 0xc60cd9b2L, 0xb10be924L,
201     0x2f6f7c87L, 0x58684c11L, 0xc1611dabL, 0xb6662d3dL, 0x76dc4190L,
202     0x01db7106L, 0x98d220bcL, 0xefd5102aL, 0x71b18589L, 0x06b6b51fL,
203     0x9fbfe4a5L, 0xe8b8d433L, 0x7807c9a2L, 0x0f00f934L, 0x9609a88eL,
204     0xe10e9818L, 0x7f6a0dbbL, 0x086d3d2dL, 0x91646c97L, 0xe6635c01L,
205     0x6b6b51f4L, 0x1c6c6162L, 0x856530d8L, 0xf262004eL, 0x6c0695edL,
206     0x1b01a57bL, 0x8208f4c1L, 0xf50fc457L, 0x65b0d9c6L, 0x12b7e950L,
207     0x8bbeb8eaL, 0xfcb9887cL, 0x62dd1ddfL, 0x15da2d49L, 0x8cd37cf3L,
208     0xfbd44c65L, 0x4db26158L, 0x3ab551ceL, 0xa3bc0074L, 0xd4bb30e2L,
209     0x4adfa541L, 0x3dd895d7L, 0xa4d1c46dL, 0xd3d6f4fbL, 0x4369e96aL,
210     0x346ed9fcL, 0xad678846L, 0xda60b8d0L, 0x44042d73L, 0x33031de5L,
211     0xaa0a4c5fL, 0xdd0d7cc9L, 0x5005713cL, 0x270241aaL, 0xbe0b1010L,
212     0xc90c2086L, 0x5768b525L, 0x206f85b3L, 0xb966d409L, 0xce61e49fL,
213     0x5edef90eL, 0x29d9c998L, 0xb0d09822L, 0xc7d7a8b4L, 0x59b33d17L,
214     0x2eb40d81L, 0xb7bd5c3bL, 0xc0ba6cadL, 0xedb88320L, 0x9abfb3b6L,
215     0x03b6e20cL, 0x74b1d29aL, 0xead54739L, 0x9dd277afL, 0x04db2615L,
216     0x73dc1683L, 0xe3630b12L, 0x94643b84L, 0x0d6d6a3eL, 0x7a6a5aa8L,
217     0xe40ecf0bL, 0x9309ff9dL, 0x0a00ae27L, 0x7d079eb1L, 0xf00f9344L,
218     0x8708a3d2L, 0x1e01f268L, 0x6906c2feL, 0xf762575dL, 0x806567cbL,
219     0x196c3671L, 0x6e6b06e7L, 0xfed41b76L, 0x89d32be0L, 0x10da7a5aL,
220     0x67dd4accL, 0xf9b9df6fL, 0x8ebeeff9L, 0x17b7be43L, 0x60b08ed5L,
221     0xd6d6a3e8L, 0xa1d1937eL, 0x38d8c2c4L, 0x4fdff252L, 0xd1bb67f1L,
222     0xa6bc5767L, 0x3fb506ddL, 0x48b2364bL, 0xd80d2bdaL, 0xaf0a1b4cL,
223     0x36034af6L, 0x41047a60L, 0xdf60efc3L, 0xa867df55L, 0x316e8eefL,
224     0x4669be79L, 0xcb61b38cL, 0xbc66831aL, 0x256fd2a0L, 0x5268e236L,
225     0xcc0c7795L, 0xbb0b4703L, 0x220216b9L, 0x5505262fL, 0xc5ba3bbeL,
226     0xb2bd0b28L, 0x2bb45a92L, 0x5cb36a04L, 0xc2d7ffa7L, 0xb5d0cf31L,
227     0x2cd99e8bL, 0x5bdeae1dL, 0x9b64c2b0L, 0xec63f226L, 0x756aa39cL,
228     0x026d930aL, 0x9c0906a9L, 0xeb0e363fL, 0x72076785L, 0x05005713L,
229     0x95bf4a82L, 0xe2b87a14L, 0x7bb12baeL, 0x0cb61b38L, 0x92d28e9bL,
230     0xe5d5be0dL, 0x7cdcefb7L, 0x0bdbdf21L, 0x86d3d2d4L, 0xf1d4e242L,
231     0x68ddb3f8L, 0x1fda836eL, 0x81be16cdL, 0xf6b9265bL, 0x6fb077e1L,
232     0x18b74777L, 0x88085ae6L, 0xff0f6a70L, 0x66063bcaL, 0x11010b5cL,
233     0x8f659effL, 0xf862ae69L, 0x616bffd3L, 0x166ccf45L, 0xa00ae278L,
234     0xd70dd2eeL, 0x4e048354L, 0x3903b3c2L, 0xa7672661L, 0xd06016f7L,
235     0x4969474dL, 0x3e6e77dbL, 0xaed16a4aL, 0xd9d65adcL, 0x40df0b66L,
236     0x37d83bf0L, 0xa9bcae53L, 0xdebb9ec5L, 0x47b2cf7fL, 0x30b5ffe9L,
237     0xbdbdf21cL, 0xcabac28aL, 0x53b39330L, 0x24b4a3a6L, 0xbad03605L,
238     0xcdd70693L, 0x54de5729L, 0x23d967bfL, 0xb3667a2eL, 0xc4614ab8L,
239     0x5d681b02L, 0x2a6f2b94L, 0xb40bbe37L, 0xc30c8ea1L, 0x5a05df1bL,
240     0x2d02ef8dL
241     };
242    
243     static unsigned long
244 michael 890 crc32(const char *s, unsigned int len)
245 adx 30 {
246     unsigned int i;
247 michael 885 unsigned long crc32val = 0;
248 adx 30
249     for (i = 0; i < len; i++)
250     crc32val = crc32_tab[(crc32val ^ s[i]) & 0xff] ^ (crc32val >> 8);
251 michael 885
252 adx 30 return crc32val;
253     }
254    
255     /*
256     * str2arr()
257     *
258     * converts IPv4 address segments into arrays
259     * for encryption
260     *
261     * inputs - address parvs, strings and deliminator
262     * outputs - array
263     * side effects - not IPv6 friendly
264     */
265     static int
266     str2arr (char **pparv, char *string, char *delim)
267     {
268     char *tok;
269     int pparc = 0;
270    
271     /* Diane had suggested to use this method rather than while() -- knight */
272     for (tok = strtok (string, delim); tok != NULL; tok = strtok (NULL, delim))
273     {
274     pparv[pparc++] = tok;
275     }
276    
277     return pparc;
278     }
279    
280     /*
281     * make_virthost()
282     *
283     * curr = current hostname/ip
284     * host = current host socket
285     * new = encrypted hostname/ip
286     */
287     static void
288 michael 890 make_virthost(char *curr, char *host, char *new)
289 adx 30 {
290 michael 890 char mask[HOSTLEN + 1];
291 adx 30 char *parv[HOSTLEN + 1], *parv2[HOSTLEN + 1], s[HOSTLEN + 1], s2[HOSTLEN + 1];
292     int parc = 0, parc2 = 0, len = 0;
293     unsigned long hash[8];
294    
295     strlcpy(s2, curr, HOSTLEN + 1);
296     strlcpy(s, host, HOSTLEN + 1);
297    
298     parc = str2arr(parv, s, ".");
299     parc2 = str2arr(parv2, s2, ".");
300    
301 michael 698 if (!parc2)
302     return;
303    
304 adx 30 hash[0] = ((crc32 (parv[3], strlen (parv[3])) + KEY) ^ KEY2) ^ KEY3;
305     hash[1] = ((KEY2 ^ crc32 (parv[2], strlen (parv[2]))) + KEY3) ^ KEY;
306     hash[2] = ((crc32 (parv[1], strlen (parv[1])) + KEY3) ^ KEY) ^ KEY2;
307     hash[3] = ((KEY3 ^ crc32 (parv[0], strlen (parv[0]))) + KEY2) ^ KEY;
308    
309     hash[0] <<= 2;
310     hash[0] >>= 2;
311     hash[0] &= 0x3FFFFFFF;
312     hash[0] &= 0xFFFFFFFF;
313     hash[1] <<= 2;
314     hash[1] >>= 2;
315     hash[1] &= 0x7FFFFFFF;
316     hash[1] &= 0x3FFFFFFF;
317     hash[2] <<= 2;
318     hash[2] >>= 2;
319     hash[2] &= 0x7FFFFFFF;
320     hash[2] &= 0xFFFFFFFF;
321     hash[3] <<= 2;
322     hash[3] >>= 2;
323     hash[3] &= 0x3FFFFFFF;
324     hash[3] &= 0x7FFFFFFF;
325    
326     /* IPv4 */
327     if (parc2 == 4 || parc2 < 2)
328     {
329     len = strlen (parv2[3]);
330    
331     if (strchr("0123456789", parv2[3][len - 1]) || parc2 < 2)
332     {
333     ircsprintf(mask, "%s.%s.%s.%lx",
334     parv2[parc2 - 4], parv2[parc2 - 3],
335     parv2[parc2 - 2], hash[3]);
336     }
337     else
338     {
339     /* isp.tld */
340     ircsprintf(mask, "%lx-%lx.%s.%s",
341     hash[0], hash[3], parv2[parc2 - 2], parv2[parc2 - 1]);
342     }
343     }
344     else
345     {
346     if (parc2 >= 4)
347     {
348     /* isp.sub.tld or district.isp.tld */
349     ircsprintf(mask, "%lx-%lx.%s.%s.%s",
350     hash[3], hash[1], parv2[parc2 - 3], parv2[parc2 - 2],
351     parv2[parc2 - 1]);
352     }
353     else
354     {
355     /* isp.tld */
356     ircsprintf(mask, "%lx-%lx.%s.%s",
357     hash[0], hash[3], parv2[parc2 - 2], parv2[parc2 - 1]);
358     }
359    
360     if (parc2 >= 5)
361     {
362     /* zone.district.isp.tld or district.isp.sub.tld */
363     ircsprintf(mask, "%lx-%lx.%s.%s.%s.%s",
364     hash[1], hash[0], parv2[parc2 - 4], parv2[parc2 - 3],
365     parv2[parc2 - 2], parv2[parc2 - 1]);
366     }
367     else
368     {
369     /* isp.tld */
370     ircsprintf(mask, "%lx-%lx.%s.%s",
371     hash[0], hash[3], parv2[parc2 - 2], parv2[parc2 - 1]);
372     }
373     }
374    
375     strlcpy(new, mask, HOSTLEN + 1);
376     }
377    
378     /*
379     * set_vhost()
380     *
381     * inputs - pointer to given client to set IP cloak.
382     * outputs - NONE
383     * side effects - NONE
384     */
385     static void
386     set_vhost(struct Client *client_p, struct Client *source_p,
387     struct Client *target_p)
388     {
389     target_p->umodes |= umode_vhost;
390     SetIPSpoof(target_p);
391     make_virthost(target_p->host, target_p->sockhost, target_p->host);
392    
393     if (IsClient(target_p))
394 michael 885 sendto_server(client_p, NULL, CAP_ENCAP, NOCAPS,
395 adx 30 ":%s ENCAP * CHGHOST %s %s",
396     me.name, target_p->name, target_p->host);
397    
398 michael 885 sendto_one(target_p, form_str(RPL_HOSTHIDDEN),
399     me.name, target_p->name, target_p->host);
400 adx 30 }
401    
402     static void *
403     reset_ipv6err_flag(va_list args)
404     {
405     struct Client *client_p = va_arg(args, struct Client *);
406     struct Client *source_p = va_arg(args, struct Client *);
407    
408     vhost_ipv6_err = NO;
409    
410     return pass_callback(prev_enter_umode, client_p, source_p);
411     }
412    
413     static void *
414     h_set_user_mode(va_list args)
415     {
416     struct Client *client_p = va_arg(args, struct Client *);
417     struct Client *target_p = va_arg(args, struct Client *);
418     int what = va_arg(args, int);
419     unsigned int flag = va_arg(args, unsigned int);
420    
421     if (flag == umode_vhost)
422     {
423     if (what == MODE_ADD)
424     {
425     /* Automatically break if any of these conditions are met. -- knight- */
426     if (!MyConnect(target_p))
427     return NULL;
428    
429     if (IsIPSpoof(target_p))
430     return NULL;
431    
432     /*
433     * IPv6 could potentially core the server if a user connected via IPv6 sets +h
434     * so we need to check and break before that happens. -- knight-
435     */
436     #ifdef IPV6
437     if (target_p->localClient->aftype == AF_INET6)
438     {
439     if (!vhost_ipv6_err)
440     {
441     sendto_one(target_p, ":%s NOTICE %s :*** Sorry, IP cloaking "
442     "does not support IPv6 users!", me.name, target_p->name);
443 michael 1243 vhost_ipv6_err = 1;
444 adx 30 }
445     }
446     else
447     #endif
448     set_vhost(client_p, target_p, target_p);
449     }
450    
451     return NULL;
452     }
453    
454     return pass_callback(prev_umode, client_p, target_p, what, flag);
455     }

Properties

Name Value
svn:eol-style native
svn:keywords Id Revision