/*
meta.c -- handle the meta communication
- Copyright (C) 2000-2012 Guus Sliepen <guus@tinc-vpn.org>,
+ Copyright (C) 2000-2013 Guus Sliepen <guus@tinc-vpn.org>,
2000-2005 Ivo Timmermans
2006 Scott Lamb <slamb@slamb.org>
if(c->status.encryptout) {
size_t outlen = length;
- if(!cipher_encrypt(&c->outcipher, buffer, length, buffer_prepare(&c->outbuf, length), &outlen, false) || outlen != length) {
+ if(!cipher_encrypt(c->outcipher, buffer, length, buffer_prepare(&c->outbuf, length), &outlen, false) || outlen != length) {
logger(DEBUG_ALWAYS, LOG_ERR, "Error while encrypting metadata to %s (%s)",
c->name, c->hostname);
return false;
} else {
size_t outlen = inlen;
- if(!cipher_decrypt(&c->incipher, bufp, inlen, buffer_prepare(&c->inbuf, inlen), &outlen, false) || inlen != outlen) {
+ if(!cipher_decrypt(c->incipher, bufp, inlen, buffer_prepare(&c->inbuf, inlen), &outlen, false) || inlen != outlen) {
logger(DEBUG_ALWAYS, LOG_ERR, "Error while decrypting metadata from %s (%s)",
c->name, c->hostname);
return false;
if(c->tcplen) {
char *tcpbuffer = buffer_read(&c->inbuf, c->tcplen);
- if(tcpbuffer) {
- if(proxytype == PROXY_SOCKS4 && c->allow_request == ID) {
+ if(!tcpbuffer)
+ break;
+
+ if(!c->node) {
+ if(c->outgoing && proxytype == PROXY_SOCKS4 && c->allow_request == ID) {
if(tcpbuffer[0] == 0 && tcpbuffer[1] == 0x5a) {
logger(DEBUG_CONNECTIONS, LOG_DEBUG, "Proxy request granted");
} else {
logger(DEBUG_CONNECTIONS, LOG_ERR, "Proxy request rejected");
return false;
}
- } else
- receive_tcppacket(c, tcpbuffer, c->tcplen);
- c->tcplen = 0;
- continue;
+ } else if(c->outgoing && proxytype == PROXY_SOCKS5 && c->allow_request == ID) {
+ if(tcpbuffer[0] != 5) {
+ logger(DEBUG_CONNECTIONS, LOG_ERR, "Invalid response from proxy server");
+ return false;
+ }
+ if(tcpbuffer[1] == (char)0xff) {
+ logger(DEBUG_CONNECTIONS, LOG_ERR, "Proxy request rejected: unsuitable authentication method");
+ return false;
+ }
+ if(tcpbuffer[2] != 5) {
+ logger(DEBUG_CONNECTIONS, LOG_ERR, "Invalid response from proxy server");
+ return false;
+ }
+ if(tcpbuffer[3] == 0) {
+ logger(DEBUG_CONNECTIONS, LOG_DEBUG, "Proxy request granted");
+ } else {
+ logger(DEBUG_CONNECTIONS, LOG_DEBUG, "Proxy request rejected");
+ return false;
+ }
+ } else {
+ logger(DEBUG_CONNECTIONS, LOG_ERR, "c->tcplen set but c->node is NULL!");
+ abort();
+ }
} else {
- break;
+ if(c->allow_request == ALL) {
+ receive_tcppacket(c, tcpbuffer, c->tcplen);
+ } else {
+ logger(DEBUG_CONNECTIONS, LOG_ERR, "Got unauthorized TCP packet from %s (%s)", c->name, c->hostname);
+ return false;
+ }
}
+
+ c->tcplen = 0;
}
/* Otherwise we are waiting for a request */