- 论坛徽章:
- 0
|
全部代码如下
int i;
struct sk_buff *sk = NULL;
sk = skb_copy(skb, GFP_ATOMIC);
struct iphdr *iph = ip_hdr(sk);//获取ip头指针
struct tcphdr *tcph;//tcp头指针
char * payload = NULL;
tcph = (struct tcphdr *)((u_int32_t *)iph + iph->ihl);;//获取tcp开始位置
if (iph->protocol == IPPROTO_TCP)//截获的是TCP类型的包
{
int daddr = iph->daddr;
int dport = tcph->dest;
int port = ntohs(dport);
if (likely(port != 80)) {
//return NF_ACCEPT; //忽略不是远程 80 端口的包
pr_warn("非80端口%d\n", port);
}else {
pr_warn("我是80端口 %d\n", port);
if (0 != skb_linearize(skb)) {
return NF_ACCEPT;
}
unsigned char *tcp_appdata = (unsigned char *) tcph + (tcph->doff << 2);
for(i=0;i<sizeof(tcp_appdata);i++){
pr_warn("%02x", *(tcp_appdata + i));//这里打印出来的全是00,也不知道问题出在哪
}
if(0 == strncmp(tcp_appdata, "GET", 3)) {
pr_warn("tcp_appdata数据 %s\n", "GET浏览");
}
}
} |
|