|
|
484378 |
--- arpwatch-2.1a15-dist/arpwatch.c 2012-07-23 09:55:35.832458313 +0200
|
|
|
484378 |
+++ arpwatch-2.1a15-new/arpwatch.c 2012-07-24 11:36:59.013953071 +0200
|
|
|
484378 |
@@ -161,15 +161,63 @@ void dropprivileges(const char* user)
|
|
|
484378 |
syslog(LOG_DEBUG, "Running as uid=%d gid=%d", getuid(), getgid());
|
|
|
484378 |
}
|
|
|
484378 |
|
|
|
484378 |
+char *
|
|
|
484378 |
+get_first_dev(pcap_t **pd, int *linktype, char *errbuf)
|
|
|
484378 |
+{
|
|
|
484378 |
+ static char interface[IF_NAMESIZE + 1];
|
|
|
484378 |
+ register int snaplen, timeout;
|
|
|
484378 |
+ pcap_if_t *alldevs;
|
|
|
484378 |
+ pcap_if_t *dev;
|
|
|
484378 |
+ char *ret = NULL;
|
|
|
484378 |
+
|
|
|
484378 |
+ snaplen = max(sizeof(struct ether_header),
|
|
|
484378 |
+ sizeof(struct fddi_header)) + sizeof(struct ether_arp);
|
|
|
484378 |
+ timeout = 1000;
|
|
|
484378 |
+
|
|
|
484378 |
+ if (pcap_findalldevs(&alldevs, errbuf) == -1) {
|
|
|
484378 |
+ (void)fprintf(stderr, "%s: lookup_device: %s\n",
|
|
|
484378 |
+ prog, errbuf);
|
|
|
484378 |
+ exit(1);
|
|
|
484378 |
+ }
|
|
|
484378 |
+
|
|
|
484378 |
+ for (dev = alldevs; dev; dev = dev->next) {
|
|
|
484378 |
+ strncpy(interface, dev->name, strlen(dev->name)+1);
|
|
|
484378 |
+
|
|
|
484378 |
+ *pd = pcap_open_live(interface, snaplen, 1, timeout, errbuf);
|
|
|
484378 |
+ if (*pd == NULL) {
|
|
|
484378 |
+ syslog(LOG_ERR, "pcap open %s: %s, trying next...", interface, errbuf);
|
|
|
484378 |
+ continue;
|
|
|
484378 |
+ /* exit(1); */
|
|
|
484378 |
+ }
|
|
|
484378 |
+
|
|
|
484378 |
+ *linktype = pcap_datalink(*pd);
|
|
|
484378 |
+ /* Must be ethernet or fddi */
|
|
|
484378 |
+ if (*linktype != DLT_EN10MB && *linktype != DLT_FDDI) {
|
|
|
484378 |
+ syslog(LOG_ERR, "(%s) Link layer type %d not ethernet or fddi, trying next...",
|
|
|
484378 |
+ interface, *linktype);
|
|
|
484378 |
+ pcap_close(*pd);
|
|
|
484378 |
+ }
|
|
|
484378 |
+ else {
|
|
|
484378 |
+ /* First match, use it */
|
|
|
484378 |
+ ret = interface;
|
|
|
484378 |
+ break;
|
|
|
484378 |
+ }
|
|
|
484378 |
+
|
|
|
484378 |
+ }
|
|
|
484378 |
+ pcap_freealldevs(alldevs);
|
|
|
484378 |
+ return (ret);
|
|
|
484378 |
+}
|
|
|
484378 |
+
|
|
|
484378 |
int
|
|
|
484378 |
main(int argc, char **argv)
|
|
|
484378 |
{
|
|
|
484378 |
register char *cp;
|
|
|
484378 |
- register int op, pid, snaplen, timeout, linktype, status;
|
|
|
484378 |
+ register int op, pid, status;
|
|
|
484378 |
+ int linktype;
|
|
|
484378 |
#ifdef TIOCNOTTY
|
|
|
484378 |
register int fd;
|
|
|
484378 |
#endif
|
|
|
484378 |
- register pcap_t *pd;
|
|
|
484378 |
+ pcap_t *pd;
|
|
|
484378 |
register char *interface, *rfilename;
|
|
|
484378 |
struct bpf_program code;
|
|
|
484378 |
char errbuf[PCAP_ERRBUF_SIZE];
|
|
|
484378 |
@@ -189,6 +237,7 @@ main(int argc, char **argv)
|
|
|
484378 |
|
|
|
484378 |
opterr = 0;
|
|
|
484378 |
interface = NULL;
|
|
|
484378 |
+ linktype = -1;
|
|
|
484378 |
rfilename = NULL;
|
|
|
484378 |
pd = NULL;
|
|
|
484378 |
while ((op = getopt(argc, argv, "df:i:n:Nr:u:e:s:")) != EOF)
|
|
|
484378 |
@@ -264,11 +313,12 @@ main(int argc, char **argv)
|
|
|
484378 |
net = 0;
|
|
|
484378 |
netmask = 0;
|
|
|
484378 |
} else {
|
|
|
484378 |
+
|
|
|
484378 |
/* Determine interface if not specified */
|
|
|
484378 |
if (interface == NULL &&
|
|
|
484378 |
- (interface = pcap_lookupdev(errbuf)) == NULL) {
|
|
|
484378 |
- (void)fprintf(stderr, "%s: lookup_device: %s\n",
|
|
|
484378 |
- prog, errbuf);
|
|
|
484378 |
+ (interface = get_first_dev(&pd, &linktype, errbuf)) == NULL) {
|
|
|
484378 |
+ (void)fprintf(stderr, "%s: lookup_device: no suitable interface found\n",
|
|
|
484378 |
+ prog);
|
|
|
484378 |
exit(1);
|
|
|
484378 |
}
|
|
|
484378 |
|
|
|
484378 |
@@ -317,10 +367,6 @@ main(int argc, char **argv)
|
|
|
484378 |
}
|
|
|
484378 |
swapped = pcap_is_swapped(pd);
|
|
|
484378 |
} else {
|
|
|
484378 |
- snaplen = max(sizeof(struct ether_header),
|
|
|
484378 |
- sizeof(struct fddi_header)) + sizeof(struct ether_arp);
|
|
|
484378 |
- timeout = 1000;
|
|
|
484378 |
- pd = pcap_open_live(interface, snaplen, 1, timeout, errbuf);
|
|
|
484378 |
if (pd == NULL) {
|
|
|
484378 |
syslog(LOG_ERR, "pcap open %s: %s", interface, errbuf);
|
|
|
484378 |
exit(1);
|
|
|
484378 |
@@ -340,14 +386,6 @@ main(int argc, char **argv)
|
|
|
484378 |
dropprivileges( serveruser );
|
|
|
484378 |
}
|
|
|
484378 |
|
|
|
484378 |
- /* Must be ethernet or fddi */
|
|
|
484378 |
- linktype = pcap_datalink(pd);
|
|
|
484378 |
- if (linktype != DLT_EN10MB && linktype != DLT_FDDI) {
|
|
|
484378 |
- syslog(LOG_ERR, "Link layer type %d not ethernet or fddi",
|
|
|
484378 |
- linktype);
|
|
|
484378 |
- exit(1);
|
|
|
484378 |
- }
|
|
|
484378 |
-
|
|
|
484378 |
/* Compile and install filter */
|
|
|
484378 |
if (pcap_compile(pd, &code, "arp or rarp", 1, netmask) < 0) {
|
|
|
484378 |
syslog(LOG_ERR, "pcap_compile: %s", pcap_geterr(pd));
|