190 lines
4.9 KiB
Diff
190 lines
4.9 KiB
Diff
--- apps/nc/netcat.c.orig 2017-07-07 00:10:09.009409624 +0900
|
|
+++ apps/nc/netcat.c 2017-07-07 00:30:32.380088772 +0900
|
|
@@ -66,7 +66,9 @@
|
|
#define POLL_NETIN 2
|
|
#define POLL_STDOUT 3
|
|
#define BUFSIZE 16384
|
|
+#ifndef DEFAULT_CA_FILE
|
|
#define DEFAULT_CA_FILE "/etc/ssl/cert.pem"
|
|
+#endif
|
|
|
|
#define TLS_ALL (1 << 1)
|
|
#define TLS_NOVERIFY (1 << 2)
|
|
@@ -94,9 +96,13 @@ int zflag; /* Port Scan Flag */
|
|
int Dflag; /* sodebug */
|
|
int Iflag; /* TCP receive buffer size */
|
|
int Oflag; /* TCP send buffer size */
|
|
+#ifdef TCP_MD5SIG
|
|
int Sflag; /* TCP MD5 signature option */
|
|
+#endif
|
|
int Tflag = -1; /* IP Type of Service */
|
|
+#ifdef SO_RTABLE
|
|
int rtableid = -1;
|
|
+#endif
|
|
|
|
int usetls; /* use TLS */
|
|
char *Cflag; /* Public cert file */
|
|
@@ -265,12 +271,14 @@ main(int argc, char *argv[])
|
|
case 'u':
|
|
uflag = 1;
|
|
break;
|
|
+#ifdef SO_RTABLE
|
|
case 'V':
|
|
rtableid = (int)strtonum(optarg, 0,
|
|
RT_TABLEID_MAX, &errstr);
|
|
if (errstr)
|
|
errx(1, "rtable %s: %s", errstr, optarg);
|
|
break;
|
|
+#endif
|
|
case 'v':
|
|
vflag = 1;
|
|
break;
|
|
@@ -317,9 +325,11 @@ main(int argc, char *argv[])
|
|
case 'o':
|
|
oflag = optarg;
|
|
break;
|
|
+#ifdef TCP_MD5SIG
|
|
case 'S':
|
|
Sflag = 1;
|
|
break;
|
|
+#endif
|
|
case 'T':
|
|
errstr = NULL;
|
|
errno = 0;
|
|
@@ -343,9 +353,11 @@ main(int argc, char *argv[])
|
|
argc -= optind;
|
|
argv += optind;
|
|
|
|
+#ifdef SO_RTABLE
|
|
if (rtableid >= 0)
|
|
if (setrtable(rtableid) == -1)
|
|
err(1, "setrtable");
|
|
+#endif
|
|
|
|
if (family == AF_UNIX) {
|
|
if (pledge("stdio rpath wpath cpath tmppath unix", NULL) == -1)
|
|
@@ -888,7 +900,10 @@ int
|
|
remote_connect(const char *host, const char *port, struct addrinfo hints)
|
|
{
|
|
struct addrinfo *res, *res0;
|
|
- int s = -1, error, on = 1, save_errno;
|
|
+ int s = -1, error, save_errno;
|
|
+#ifdef SO_BINDANY
|
|
+ int on = 1;
|
|
+#endif
|
|
|
|
if ((error = getaddrinfo(host, port, &hints, &res0)))
|
|
errx(1, "getaddrinfo for host \"%s\" port %s: %s", host,
|
|
@@ -903,8 +918,10 @@ remote_connect(const char *host, const c
|
|
if (sflag || pflag) {
|
|
struct addrinfo ahints, *ares;
|
|
|
|
+#ifdef SO_BINDANY
|
|
/* try SO_BINDANY, but don't insist */
|
|
setsockopt(s, SOL_SOCKET, SO_BINDANY, &on, sizeof(on));
|
|
+#endif
|
|
memset(&ahints, 0, sizeof(struct addrinfo));
|
|
ahints.ai_family = res->ai_family;
|
|
ahints.ai_socktype = uflag ? SOCK_DGRAM : SOCK_STREAM;
|
|
@@ -975,7 +992,10 @@ int
|
|
local_listen(char *host, char *port, struct addrinfo hints)
|
|
{
|
|
struct addrinfo *res, *res0;
|
|
- int s = -1, ret, x = 1, save_errno;
|
|
+ int s = -1, save_errno;
|
|
+#ifdef SO_REUSEPORT
|
|
+ int ret, x = 1;
|
|
+#endif
|
|
int error;
|
|
|
|
/* Allow nodename to be null. */
|
|
@@ -996,9 +1016,11 @@ local_listen(char *host, char *port, str
|
|
res->ai_protocol)) < 0)
|
|
continue;
|
|
|
|
+#ifdef SO_REUSEPORT
|
|
ret = setsockopt(s, SOL_SOCKET, SO_REUSEPORT, &x, sizeof(x));
|
|
if (ret == -1)
|
|
err(1, NULL);
|
|
+#endif
|
|
|
|
set_common_sockopts(s, res->ai_family);
|
|
|
|
@@ -1454,11 +1476,13 @@ set_common_sockopts(int s, int af)
|
|
{
|
|
int x = 1;
|
|
|
|
+#ifdef TCP_MD5SIG
|
|
if (Sflag) {
|
|
if (setsockopt(s, IPPROTO_TCP, TCP_MD5SIG,
|
|
&x, sizeof(x)) == -1)
|
|
err(1, NULL);
|
|
}
|
|
+#endif
|
|
if (Dflag) {
|
|
if (setsockopt(s, SOL_SOCKET, SO_DEBUG,
|
|
&x, sizeof(x)) == -1)
|
|
@@ -1469,9 +1493,16 @@ set_common_sockopts(int s, int af)
|
|
IP_TOS, &Tflag, sizeof(Tflag)) == -1)
|
|
err(1, "set IP ToS");
|
|
|
|
+#ifdef IPV6_TCLASS
|
|
else if (af == AF_INET6 && setsockopt(s, IPPROTO_IPV6,
|
|
IPV6_TCLASS, &Tflag, sizeof(Tflag)) == -1)
|
|
err(1, "set IPv6 traffic class");
|
|
+#else
|
|
+ else if (af == AF_INET6) {
|
|
+ errno = ENOPROTOOPT
|
|
+ err(1, "set IPv6 traffic class not supported");
|
|
+ }
|
|
+#endif
|
|
}
|
|
if (Iflag) {
|
|
if (setsockopt(s, SOL_SOCKET, SO_RCVBUF,
|
|
@@ -1495,13 +1526,17 @@ set_common_sockopts(int s, int af)
|
|
}
|
|
|
|
if (minttl != -1) {
|
|
+#ifdef IP_MINTTL
|
|
if (af == AF_INET && setsockopt(s, IPPROTO_IP,
|
|
IP_MINTTL, &minttl, sizeof(minttl)))
|
|
err(1, "set IP min TTL");
|
|
+#endif
|
|
|
|
- else if (af == AF_INET6 && setsockopt(s, IPPROTO_IPV6,
|
|
+#ifdef IPV6_MINHOPCOUNT
|
|
+ if (af == AF_INET6 && setsockopt(s, IPPROTO_IPV6,
|
|
IPV6_MINHOPCOUNT, &minttl, sizeof(minttl)))
|
|
err(1, "set IPv6 min hop count");
|
|
+#endif
|
|
}
|
|
}
|
|
|
|
@@ -1709,14 +1744,22 @@ help(void)
|
|
\t-P proxyuser\tUsername for proxy authentication\n\
|
|
\t-p port\t Specify local port for remote connects\n\
|
|
\t-R CAfile CA bundle\n\
|
|
- \t-r Randomize remote ports\n\
|
|
- \t-S Enable the TCP MD5 signature option\n\
|
|
+ \t-r Randomize remote ports\n"
|
|
+#ifdef TCP_MD5SIG
|
|
+ "\
|
|
+ \t-S Enable the TCP MD5 signature option\n"
|
|
+#endif
|
|
+ "\
|
|
\t-s source Local source address\n\
|
|
\t-T keyword TOS value or TLS options\n\
|
|
\t-t Answer TELNET negotiation\n\
|
|
\t-U Use UNIX domain socket\n\
|
|
- \t-u UDP mode\n\
|
|
- \t-V rtable Specify alternate routing table\n\
|
|
+ \t-u UDP mode\n"
|
|
+#ifdef SO_RTABLE
|
|
+ "\
|
|
+ \t-V rtable Specify alternate routing table\n"
|
|
+#endif
|
|
+ "\
|
|
\t-v Verbose\n\
|
|
\t-W recvlimit Terminate after receiving a number of packets\n\
|
|
\t-w timeout Timeout for connects and final net reads\n\
|