1 1.1.1.4 christos # Copyright 2016-2018 The OpenSSL Project Authors. All Rights Reserved. 2 1.1 christos # 3 1.1.1.4 christos # Licensed under the Apache License 2.0 (the "License"). You may not use 4 1.1 christos # this file except in compliance with the License. You can obtain a copy 5 1.1 christos # in the file LICENSE in the source distribution or at 6 1.1 christos # https://www.openssl.org/source/license.html 7 1.1 christos 8 1.1 christos use strict; 9 1.1 christos 10 1.1 christos package TLSProxy::ServerHello; 11 1.1 christos 12 1.1 christos use vars '@ISA'; 13 1.1 christos push @ISA, 'TLSProxy::Message'; 14 1.1 christos 15 1.1.1.2 christos my $hrrrandom = pack("C*", 0xCF, 0x21, 0xAD, 0x74, 0xE5, 0x9A, 0x61, 0x11, 0xBE, 16 1.1.1.2 christos 0x1D, 0x8C, 0x02, 0x1E, 0x65, 0xB8, 0x91, 0xC2, 0xA2, 17 1.1.1.2 christos 0x11, 0x16, 0x7A, 0xBB, 0x8C, 0x5E, 0x07, 0x9E, 0x09, 18 1.1.1.2 christos 0xE2, 0xC8, 0xA8, 0x33, 0x9C); 19 1.1.1.2 christos 20 1.1 christos sub new 21 1.1 christos { 22 1.1 christos my $class = shift; 23 1.1 christos my ($server, 24 1.1 christos $data, 25 1.1 christos $records, 26 1.1 christos $startoffset, 27 1.1 christos $message_frag_lens) = @_; 28 1.1.1.3 christos 29 1.1 christos my $self = $class->SUPER::new( 30 1.1 christos $server, 31 1.1 christos TLSProxy::Message::MT_SERVER_HELLO, 32 1.1 christos $data, 33 1.1 christos $records, 34 1.1 christos $startoffset, 35 1.1 christos $message_frag_lens); 36 1.1 christos 37 1.1 christos $self->{server_version} = 0; 38 1.1 christos $self->{random} = []; 39 1.1 christos $self->{session_id_len} = 0; 40 1.1 christos $self->{session} = ""; 41 1.1 christos $self->{ciphersuite} = 0; 42 1.1 christos $self->{comp_meth} = 0; 43 1.1 christos $self->{extension_data} = ""; 44 1.1 christos 45 1.1 christos return $self; 46 1.1 christos } 47 1.1 christos 48 1.1 christos sub parse 49 1.1 christos { 50 1.1 christos my $self = shift; 51 1.1 christos my $ptr = 2; 52 1.1 christos my ($server_version) = unpack('n', $self->data); 53 1.1.1.2 christos my $neg_version = $server_version; 54 1.1.1.2 christos 55 1.1 christos my $random = substr($self->data, $ptr, 32); 56 1.1 christos $ptr += 32; 57 1.1.1.2 christos my $session_id_len = 0; 58 1.1.1.2 christos my $session = ""; 59 1.1.1.2 christos $session_id_len = unpack('C', substr($self->data, $ptr)); 60 1.1 christos $ptr++; 61 1.1.1.2 christos $session = substr($self->data, $ptr, $session_id_len); 62 1.1 christos $ptr += $session_id_len; 63 1.1.1.2 christos 64 1.1 christos my $ciphersuite = unpack('n', substr($self->data, $ptr)); 65 1.1 christos $ptr += 2; 66 1.1.1.2 christos my $comp_meth = 0; 67 1.1.1.2 christos $comp_meth = unpack('C', substr($self->data, $ptr)); 68 1.1 christos $ptr++; 69 1.1.1.2 christos 70 1.1 christos my $extensions_len = unpack('n', substr($self->data, $ptr)); 71 1.1 christos if (!defined $extensions_len) { 72 1.1 christos $extensions_len = 0; 73 1.1 christos } else { 74 1.1 christos $ptr += 2; 75 1.1 christos } 76 1.1 christos #For now we just deal with this as a block of data. In the future we will 77 1.1 christos #want to parse this 78 1.1 christos my $extension_data; 79 1.1 christos if ($extensions_len != 0) { 80 1.1 christos $extension_data = substr($self->data, $ptr); 81 1.1.1.3 christos 82 1.1 christos if (length($extension_data) != $extensions_len) { 83 1.1 christos die "Invalid extension length\n"; 84 1.1 christos } 85 1.1 christos } else { 86 1.1 christos if (length($self->data) != $ptr) { 87 1.1 christos die "Invalid extension length\n"; 88 1.1 christos } 89 1.1 christos $extension_data = ""; 90 1.1 christos } 91 1.1 christos my %extensions = (); 92 1.1 christos while (length($extension_data) >= 4) { 93 1.1 christos my ($type, $size) = unpack("nn", $extension_data); 94 1.1 christos my $extdata = substr($extension_data, 4, $size); 95 1.1 christos $extension_data = substr($extension_data, 4 + $size); 96 1.1 christos $extensions{$type} = $extdata; 97 1.1.1.2 christos if ($type == TLSProxy::Message::EXT_SUPPORTED_VERSIONS) { 98 1.1.1.2 christos $neg_version = unpack('n', $extdata); 99 1.1.1.2 christos } 100 1.1.1.2 christos } 101 1.1.1.2 christos 102 1.1.1.2 christos if ($random eq $hrrrandom) { 103 1.1.1.2 christos TLSProxy::Proxy->is_tls13(1); 104 1.1.1.2 christos } elsif ($neg_version == TLSProxy::Record::VERS_TLS_1_3) { 105 1.1.1.2 christos TLSProxy::Proxy->is_tls13(1); 106 1.1.1.2 christos 107 1.1.1.2 christos TLSProxy::Record->server_encrypting(1); 108 1.1.1.2 christos TLSProxy::Record->client_encrypting(1); 109 1.1 christos } 110 1.1 christos 111 1.1 christos $self->server_version($server_version); 112 1.1 christos $self->random($random); 113 1.1 christos $self->session_id_len($session_id_len); 114 1.1 christos $self->session($session); 115 1.1 christos $self->ciphersuite($ciphersuite); 116 1.1.1.2 christos TLSProxy::Proxy->ciphersuite($ciphersuite); 117 1.1 christos $self->comp_meth($comp_meth); 118 1.1 christos $self->extension_data(\%extensions); 119 1.1 christos 120 1.1 christos $self->process_data(); 121 1.1 christos 122 1.1.1.2 christos 123 1.1 christos print " Server Version:".$server_version."\n"; 124 1.1 christos print " Session ID Len:".$session_id_len."\n"; 125 1.1 christos print " Ciphersuite:".$ciphersuite."\n"; 126 1.1 christos print " Compression Method:".$comp_meth."\n"; 127 1.1 christos print " Extensions Len:".$extensions_len."\n"; 128 1.1 christos } 129 1.1 christos 130 1.1 christos #Perform any actions necessary based on the data we've seen 131 1.1 christos sub process_data 132 1.1 christos { 133 1.1 christos my $self = shift; 134 1.1 christos 135 1.1 christos TLSProxy::Message->ciphersuite($self->ciphersuite); 136 1.1 christos } 137 1.1 christos 138 1.1 christos #Reconstruct the on-the-wire message data following changes 139 1.1 christos sub set_message_contents 140 1.1 christos { 141 1.1 christos my $self = shift; 142 1.1 christos my $data; 143 1.1 christos my $extensions = ""; 144 1.1 christos 145 1.1 christos $data = pack('n', $self->server_version); 146 1.1 christos $data .= $self->random; 147 1.1 christos $data .= pack('C', $self->session_id_len); 148 1.1 christos $data .= $self->session; 149 1.1 christos $data .= pack('n', $self->ciphersuite); 150 1.1 christos $data .= pack('C', $self->comp_meth); 151 1.1 christos 152 1.1 christos foreach my $key (keys %{$self->extension_data}) { 153 1.1 christos my $extdata = ${$self->extension_data}{$key}; 154 1.1 christos $extensions .= pack("n", $key); 155 1.1 christos $extensions .= pack("n", length($extdata)); 156 1.1 christos $extensions .= $extdata; 157 1.1.1.3 christos if ($key == $self->dupext) { 158 1.1 christos $extensions .= pack("n", $key); 159 1.1 christos $extensions .= pack("n", length($extdata)); 160 1.1 christos $extensions .= $extdata; 161 1.1 christos } 162 1.1 christos } 163 1.1 christos 164 1.1 christos $data .= pack('n', length($extensions)); 165 1.1 christos $data .= $extensions; 166 1.1 christos $self->data($data); 167 1.1 christos } 168 1.1 christos 169 1.1 christos #Read/write accessors 170 1.1 christos sub server_version 171 1.1 christos { 172 1.1 christos my $self = shift; 173 1.1 christos if (@_) { 174 1.1.1.2 christos $self->{server_version} = shift; 175 1.1 christos } 176 1.1.1.2 christos return $self->{server_version}; 177 1.1 christos } 178 1.1 christos sub random 179 1.1 christos { 180 1.1 christos my $self = shift; 181 1.1 christos if (@_) { 182 1.1 christos $self->{random} = shift; 183 1.1 christos } 184 1.1 christos return $self->{random}; 185 1.1 christos } 186 1.1 christos sub session_id_len 187 1.1 christos { 188 1.1 christos my $self = shift; 189 1.1 christos if (@_) { 190 1.1 christos $self->{session_id_len} = shift; 191 1.1 christos } 192 1.1 christos return $self->{session_id_len}; 193 1.1 christos } 194 1.1 christos sub session 195 1.1 christos { 196 1.1 christos my $self = shift; 197 1.1 christos if (@_) { 198 1.1 christos $self->{session} = shift; 199 1.1 christos } 200 1.1 christos return $self->{session}; 201 1.1 christos } 202 1.1 christos sub ciphersuite 203 1.1 christos { 204 1.1 christos my $self = shift; 205 1.1 christos if (@_) { 206 1.1 christos $self->{ciphersuite} = shift; 207 1.1 christos } 208 1.1 christos return $self->{ciphersuite}; 209 1.1 christos } 210 1.1 christos sub comp_meth 211 1.1 christos { 212 1.1 christos my $self = shift; 213 1.1 christos if (@_) { 214 1.1 christos $self->{comp_meth} = shift; 215 1.1 christos } 216 1.1 christos return $self->{comp_meth}; 217 1.1 christos } 218 1.1 christos sub extension_data 219 1.1 christos { 220 1.1 christos my $self = shift; 221 1.1 christos if (@_) { 222 1.1 christos $self->{extension_data} = shift; 223 1.1 christos } 224 1.1 christos return $self->{extension_data}; 225 1.1 christos } 226 1.1 christos sub set_extension 227 1.1 christos { 228 1.1 christos my ($self, $ext_type, $ext_data) = @_; 229 1.1 christos $self->{extension_data}{$ext_type} = $ext_data; 230 1.1 christos } 231 1.1 christos sub delete_extension 232 1.1 christos { 233 1.1 christos my ($self, $ext_type) = @_; 234 1.1 christos delete $self->{extension_data}{$ext_type}; 235 1.1 christos } 236 1.1 christos 1; 237