suricata
app-layer-htp-libhtp.h
Go to the documentation of this file.
1 /*
2  * We are using this file to hold APIs copied from libhtp 0.5.x.
3  */
4 
5 /***************************************************************************
6  * Copyright (c) 2009-2010 Open Information Security Foundation
7  * Copyright (c) 2010-2013 Qualys, Inc.
8  * All rights reserved.
9  *
10  * Redistribution and use in source and binary forms, with or without
11  * modification, are permitted provided that the following conditions are
12  * met:
13  *
14  * - Redistributions of source code must retain the above copyright
15  * notice, this list of conditions and the following disclaimer.
16  *
17  * - Redistributions in binary form must reproduce the above copyright
18  * notice, this list of conditions and the following disclaimer in the
19  * documentation and/or other materials provided with the distribution.
20  *
21  * - Neither the name of the Qualys, Inc. nor the names of its
22  * contributors may be used to endorse or promote products derived from
23  * this software without specific prior written permission.
24  *
25  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
26  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
27  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
28  * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
29  * HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
30  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
31  * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
32  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
33  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
34  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
35  * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
36  ***************************************************************************/
37 
38 /**
39  * \file
40  *
41  * \author Anoop Saldanha <anoopsaldanha@gmail.com>
42  *
43  * APIs from libhtp 0.5.x.
44  */
45 
46 #ifndef SURICATA_APP_LAYER_HTP_LIBHTP__H
47 #define SURICATA_APP_LAYER_HTP_LIBHTP__H
48 
49 #include "suricata-common.h"
50 
51 // Temporary alias definitions before switching to libhtp rust
52 #define HTP_STATUS_OK HTP_OK
53 #define HTP_STATUS_ERROR HTP_ERROR
54 
55 #define HTP_SERVER_PERSONALITY_APACHE_2 HTP_SERVER_APACHE_2
56 #define HTP_SERVER_PERSONALITY_MINIMAL HTP_SERVER_MINIMAL
57 #define HTP_SERVER_PERSONALITY_GENERIC HTP_SERVER_GENERIC
58 #define HTP_SERVER_PERSONALITY_IDS HTP_SERVER_IDS
59 #define HTP_SERVER_PERSONALITY_IIS_4_0 HTP_SERVER_IIS_4_0
60 #define HTP_SERVER_PERSONALITY_IIS_5_0 HTP_SERVER_IIS_5_0
61 #define HTP_SERVER_PERSONALITY_IIS_5_1 HTP_SERVER_IIS_5_1
62 #define HTP_SERVER_PERSONALITY_IIS_6_0 HTP_SERVER_IIS_6_0
63 #define HTP_SERVER_PERSONALITY_IIS_7_0 HTP_SERVER_IIS_7_0
64 #define HTP_SERVER_PERSONALITY_IIS_7_5 HTP_SERVER_IIS_7_5
65 
66 #define HTP_FLAGS_REQUEST_INVALID_T_E HTP_REQUEST_INVALID_T_E
67 #define HTP_FLAGS_REQUEST_INVALID_C_L HTP_REQUEST_INVALID_C_L
68 #define HTP_FLAGS_HOST_MISSING HTP_HOST_MISSING
69 #define HTP_FLAGS_HOST_AMBIGUOUS HTP_HOST_AMBIGUOUS
70 #define HTP_FLAGS_HOSTU_INVALID HTP_HOSTU_INVALID
71 #define HTP_FLAGS_HOSTH_INVALID HTP_HOSTH_INVALID
72 
73 #define HTP_AUTH_TYPE_UNRECOGNIZED HTP_AUTH_UNRECOGNIZED
74 
75 #define HTP_METHOD_UNKNOWN HTP_M_UNKNOWN
76 #define HTP_METHOD_GET HTP_M_GET
77 #define HTP_METHOD_POST HTP_M_POST
78 #define HTP_METHOD_PUT HTP_M_PUT
79 #define HTP_METHOD_CONNECT HTP_M_CONNECT
80 
81 #define HTP_STREAM_STATE_ERROR HTP_STREAM_ERROR
82 #define HTP_STREAM_STATE_TUNNEL HTP_STREAM_TUNNEL
83 
84 #define HTP_PROTOCOL_V1_1 HTP_PROTOCOL_1_1
85 #define HTP_PROTOCOL_V1_0 HTP_PROTOCOL_1_0
86 #define HTP_PROTOCOL_V0_9 HTP_PROTOCOL_0_9
87 
88 #define HTP_REQUEST_PROGRESS_LINE HTP_REQUEST_LINE
89 #define HTP_REQUEST_PROGRESS_HEADERS HTP_REQUEST_HEADERS
90 #define HTP_REQUEST_PROGRESS_BODY HTP_REQUEST_BODY
91 #define HTP_REQUEST_PROGRESS_TRAILER HTP_REQUEST_TRAILER
92 #define HTP_REQUEST_PROGRESS_COMPLETE HTP_REQUEST_COMPLETE
93 #define HTP_RESPONSE_PROGRESS_LINE HTP_RESPONSE_LINE
94 #define HTP_RESPONSE_PROGRESS_HEADERS HTP_RESPONSE_HEADERS
95 #define HTP_RESPONSE_PROGRESS_BODY HTP_RESPONSE_BODY
96 #define HTP_RESPONSE_PROGRESS_TRAILER HTP_RESPONSE_TRAILER
97 #define HTP_RESPONSE_PROGRESS_COMPLETE HTP_RESPONSE_COMPLETE
98 
99 #define HTP_LOG_CODE_UNKNOWN HTTP_DECODER_EVENT_UNKNOWN_ERROR
100 #define HTP_LOG_CODE_GZIP_DECOMPRESSION_FAILED HTTP_DECODER_EVENT_GZIP_DECOMPRESSION_FAILED
101 #define HTP_LOG_CODE_REQUEST_FIELD_MISSING_COLON HTTP_DECODER_EVENT_REQUEST_FIELD_MISSING_COLON
102 #define HTP_LOG_CODE_RESPONSE_FIELD_MISSING_COLON HTTP_DECODER_EVENT_RESPONSE_FIELD_MISSING_COLON
103 #define HTP_LOG_CODE_INVALID_REQUEST_CHUNK_LEN HTTP_DECODER_EVENT_INVALID_REQUEST_CHUNK_LEN
104 #define HTP_LOG_CODE_INVALID_RESPONSE_CHUNK_LEN HTTP_DECODER_EVENT_INVALID_RESPONSE_CHUNK_LEN
105 #define HTP_LOG_CODE_INVALID_TRANSFER_ENCODING_VALUE_IN_REQUEST \
106  HTTP_DECODER_EVENT_INVALID_TRANSFER_ENCODING_VALUE_IN_REQUEST
107 #define HTP_LOG_CODE_INVALID_TRANSFER_ENCODING_VALUE_IN_RESPONSE \
108  HTTP_DECODER_EVENT_INVALID_TRANSFER_ENCODING_VALUE_IN_RESPONSE
109 #define HTP_LOG_CODE_INVALID_CONTENT_LENGTH_FIELD_IN_REQUEST \
110  HTTP_DECODER_EVENT_INVALID_CONTENT_LENGTH_FIELD_IN_REQUEST
111 #define HTP_LOG_CODE_INVALID_CONTENT_LENGTH_FIELD_IN_RESPONSE \
112  HTTP_DECODER_EVENT_INVALID_CONTENT_LENGTH_FIELD_IN_RESPONSE
113 #define HTP_LOG_CODE_DUPLICATE_CONTENT_LENGTH_FIELD_IN_REQUEST \
114  HTTP_DECODER_EVENT_DUPLICATE_CONTENT_LENGTH_FIELD_IN_REQUEST
115 #define HTP_LOG_CODE_DUPLICATE_CONTENT_LENGTH_FIELD_IN_RESPONSE \
116  HTTP_DECODER_EVENT_DUPLICATE_CONTENT_LENGTH_FIELD_IN_RESPONSE
117 #define HTP_LOG_CODE_CONTINUE_ALREADY_SEEN HTTP_DECODER_EVENT_100_CONTINUE_ALREADY_SEEN
118 #define HTP_LOG_CODE_UNABLE_TO_MATCH_RESPONSE_TO_REQUEST \
119  HTTP_DECODER_EVENT_UNABLE_TO_MATCH_RESPONSE_TO_REQUEST
120 #define HTP_LOG_CODE_INVALID_SERVER_PORT_IN_REQUEST \
121  HTTP_DECODER_EVENT_INVALID_SERVER_PORT_IN_REQUEST
122 #define HTP_LOG_CODE_INVALID_AUTHORITY_PORT HTTP_DECODER_EVENT_INVALID_AUTHORITY_PORT
123 #define HTP_LOG_CODE_REQUEST_HEADER_INVALID HTTP_DECODER_EVENT_REQUEST_HEADER_INVALID
124 #define HTP_LOG_CODE_RESPONSE_HEADER_INVALID HTTP_DECODER_EVENT_RESPONSE_HEADER_INVALID
125 #define HTP_LOG_CODE_MISSING_HOST_HEADER HTTP_DECODER_EVENT_MISSING_HOST_HEADER
126 #define HTP_LOG_CODE_HOST_HEADER_AMBIGUOUS HTTP_DECODER_EVENT_HOST_HEADER_AMBIGUOUS
127 #define HTP_LOG_CODE_INVALID_REQUEST_FIELD_FOLDING HTTP_DECODER_EVENT_INVALID_REQUEST_FIELD_FOLDING
128 #define HTP_LOG_CODE_INVALID_RESPONSE_FIELD_FOLDING \
129  HTTP_DECODER_EVENT_INVALID_RESPONSE_FIELD_FOLDING
130 #define HTP_LOG_CODE_REQUEST_FIELD_TOO_LONG HTTP_DECODER_EVENT_REQUEST_FIELD_TOO_LONG
131 #define HTP_LOG_CODE_RESPONSE_FIELD_TOO_LONG HTTP_DECODER_EVENT_RESPONSE_FIELD_TOO_LONG
132 #define HTP_LOG_CODE_FILE_NAME_TOO_LONG HTTP_DECODER_EVENT_FILE_NAME_TOO_LONG
133 #define HTP_LOG_CODE_REQUEST_LINE_INVALID HTTP_DECODER_EVENT_REQUEST_LINE_INVALID
134 #define HTP_LOG_CODE_REQUEST_BODY_UNEXPECTED HTTP_DECODER_EVENT_REQUEST_BODY_UNEXPECTED
135 #define HTP_LOG_CODE_REQUEST_SERVER_PORT_TCP_PORT_MISMATCH \
136  HTTP_DECODER_EVENT_REQUEST_SERVER_PORT_TCP_PORT_MISMATCH
137 #define HTP_LOG_CODE_URI_HOST_INVALID HTTP_DECODER_EVENT_URI_HOST_INVALID
138 #define HTP_LOG_CODE_HEADER_HOST_INVALID HTTP_DECODER_EVENT_HEADER_HOST_INVALID
139 #define HTP_LOG_CODE_AUTH_UNRECOGNIZED HTTP_DECODER_EVENT_AUTH_UNRECOGNIZED
140 #define HTP_LOG_CODE_REQUEST_HEADER_REPETITION HTTP_DECODER_EVENT_REQUEST_HEADER_REPETITION
141 #define HTP_LOG_CODE_RESPONSE_HEADER_REPETITION HTTP_DECODER_EVENT_RESPONSE_HEADER_REPETITION
142 #define HTP_LOG_CODE_DOUBLE_ENCODED_URI HTTP_DECODER_EVENT_DOUBLE_ENCODED_URI
143 #define HTP_LOG_CODE_URI_DELIM_NON_COMPLIANT HTTP_DECODER_EVENT_URI_DELIM_NON_COMPLIANT
144 #define HTP_LOG_CODE_METHOD_DELIM_NON_COMPLIANT HTTP_DECODER_EVENT_METHOD_DELIM_NON_COMPLIANT
145 #define HTP_LOG_CODE_REQUEST_LINE_LEADING_WHITESPACE \
146  HTTP_DECODER_EVENT_REQUEST_LINE_LEADING_WHITESPACE
147 #define HTP_LOG_CODE_TOO_MANY_ENCODING_LAYERS HTTP_DECODER_EVENT_TOO_MANY_ENCODING_LAYERS
148 #define HTP_LOG_CODE_ABNORMAL_CE_HEADER HTTP_DECODER_EVENT_ABNORMAL_CE_HEADER
149 #define HTP_LOG_CODE_RESPONSE_MULTIPART_BYTERANGES HTTP_DECODER_EVENT_RESPONSE_MULTIPART_BYTERANGES
150 #define HTP_LOG_CODE_RESPONSE_ABNORMAL_TRANSFER_ENCODING \
151  HTTP_DECODER_EVENT_RESPONSE_ABNORMAL_TRANSFER_ENCODING
152 #define HTP_LOG_CODE_RESPONSE_CHUNKED_OLD_PROTO HTTP_DECODER_EVENT_RESPONSE_CHUNKED_OLD_PROTO
153 #define HTP_LOG_CODE_RESPONSE_INVALID_PROTOCOL HTTP_DECODER_EVENT_RESPONSE_INVALID_PROTOCOL
154 #define HTP_LOG_CODE_RESPONSE_INVALID_STATUS HTTP_DECODER_EVENT_RESPONSE_INVALID_STATUS
155 #define HTP_LOG_CODE_REQUEST_LINE_INCOMPLETE HTTP_DECODER_EVENT_REQUEST_LINE_INCOMPLETE
156 #define HTP_LOG_CODE_LZMA_MEMLIMIT_REACHED HTTP_DECODER_EVENT_LZMA_MEMLIMIT_REACHED
157 #define HTP_LOG_CODE_COMPRESSION_BOMB HTTP_DECODER_EVENT_COMPRESSION_BOMB
158 
159 // Functions introduced to handle opaque htp_tx_t
160 #define htp_tx_flags(tx) (tx)->flags
161 #define htp_tx_is_protocol_0_9(tx) (tx)->is_protocol_0_9
162 #define htp_tx_request_auth_type(tx) (tx)->request_auth_type
163 #define htp_tx_request_hostname(tx) (tx)->request_hostname
164 #define htp_tx_request_line(tx) (tx)->request_line
165 #define htp_tx_request_message_len(tx) (tx)->request_message_len
166 #define htp_tx_request_method(tx) (tx)->request_method
167 #define htp_tx_request_method_number(tx) tx->request_method_number
168 #define htp_tx_request_port_number(tx) (tx)->request_port_number
169 #define htp_tx_request_progress(tx) (tx)->request_progress
170 #define htp_tx_request_protocol(tx) (tx)->request_protocol
171 #define htp_tx_request_protocol_number(tx) (tx)->request_protocol_number
172 #define htp_tx_request_uri(tx) (tx)->request_uri
173 #define htp_tx_request_headers(tx) (tx)->request_headers
174 #define htp_tx_response_headers(tx) (tx)->response_headers
175 #define htp_tx_response_protocol(tx) (tx)->response_protocol
176 #define htp_tx_response_line(tx) (tx)->response_line
177 #define htp_tx_response_message(tx) (tx)->response_message
178 #define htp_tx_response_message_len(tx) (tx)->response_message_len
179 #define htp_tx_response_status(tx) (tx)->response_status
180 #define htp_tx_response_status_number(tx) (tx)->response_status_number
181 #define htp_tx_response_progress(tx) (tx)->response_progress
182 #define htp_tx_response_protocol_number(tx) (tx)->response_protocol_number
183 
184 #define htp_tx_request_header(tx, header) htp_table_get_c((tx)->request_headers, header)
185 #define htp_tx_response_header(tx, header) htp_table_get_c((tx)->response_headers, header)
186 
187 // Functions introduced to handle opaque htp_header_t
188 #define htp_header_name_len(h) bstr_len((h)->name)
189 #define htp_header_name_ptr(h) bstr_ptr((h)->name)
190 #define htp_header_name(h) (h)->name
191 #define htp_header_value_len(h) bstr_len((h)->value)
192 #define htp_header_value_ptr(h) bstr_ptr((h)->value)
193 #define htp_header_value(h) (h)->value
194 
195 // Functions introduced to handle opaque htp_headers_t:
196 #define htp_headers_size(headers) htp_table_size(headers)
197 #define htp_headers_get_index(headers, index) htp_table_get_index(headers, index, NULL)
198 #define htp_tx_request_headers_size(tx) htp_table_size((tx)->request_headers)
199 #define htp_tx_request_header_index(tx, i) htp_table_get_index((tx)->request_headers, i, NULL);
200 #define htp_headers_t htp_table_t
201 
202 // Functions introduced to handle opaque htp_tx_data_t:
203 #define htp_tx_data_len(d) (d)->len
204 #define htp_tx_data_data(d) (d)->data
205 #define htp_tx_data_tx(d) (d)->tx
206 
207 // Functions introduced to handle opaque htp_conn_t:
208 #define htp_conn_request_data_counter(c) (c)->in_data_counter
209 #define htp_conn_response_data_counter(c) (c)->out_data_counter
210 
211 bstr *SCHTPGenerateNormalizedUri(htp_tx_t *tx, htp_uri_t *uri, bool uri_include_all);
212 
213 #endif /* SURICATA_APP_LAYER_HTP_LIBHTP__H */
SCHTPGenerateNormalizedUri
bstr * SCHTPGenerateNormalizedUri(htp_tx_t *tx, htp_uri_t *uri, bool uri_include_all)
Generates the normalized uri.
Definition: app-layer-htp-libhtp.c:64
suricata-common.h