Go to the documentation of this file.
35 #include "htp/htp_rs.h"
39 #define XFF_DEFAULT "X-Forwarded-For"
41 static int HttpXFFGetIPFromTxAux(htp_tx_t *tx,
HttpXFFCfg *xff_cfg,
char *dstbuf,
int dstbuflen)
43 return htp_xff_get_ip(
54 const Flow *
f, uint64_t tx_id,
HttpXFFCfg *xff_cfg,
char *dstbuf,
int dstbuflen)
57 uint64_t total_txs = 0;
60 htp_state = (
HtpState *)FlowGetAppState(
f);
62 if (htp_state == NULL) {
63 SCLogDebug(
"no http state, XFF IP cannot be retrieved");
68 if (tx_id >= total_txs)
73 SCLogDebug(
"tx is NULL, XFF cannot be retrieved");
76 return HttpXFFGetIPFromTxAux(tx, xff_cfg, dstbuf, dstbuflen);
87 if (htp_state == NULL) {
88 SCLogDebug(
"no http state, XFF IP cannot be retrieved");
96 memset(&state, 0,
sizeof(state));
104 if (HttpXFFGetIPFromTxAux(ires.
tx_ptr, xff_cfg, dstbuf, dstbuflen) == 1)
107 tx_id = ires.
tx_id + 1;
129 if (xff_mode != NULL && strcasecmp(xff_mode,
"overwrite") == 0) {
132 if (xff_mode == NULL) {
133 SCLogWarning(
"The XFF mode hasn't been defined, falling back to extra-data mode");
135 else if (strcasecmp(xff_mode,
"extra-data") != 0) {
137 "The XFF mode %s is invalid, falling back to extra-data mode", xff_mode);
144 if (xff_deployment != NULL && strcasecmp(xff_deployment,
"forward") == 0) {
147 if (xff_deployment == NULL) {
148 SCLogWarning(
"The XFF deployment hasn't been defined, falling back to reverse "
151 else if (strcasecmp(xff_deployment,
"reverse") != 0) {
152 SCLogWarning(
"The XFF mode %s is invalid, falling back to reverse proxy deployment",
160 if (xff_header != NULL) {
161 result->
header = (
char *) xff_header;
void HttpXFFGetCfg(SCConfNode *conf, HttpXFFCfg *result)
Function to return XFF configuration from a configuration node.
AppLayerGetTxIteratorFunc AppLayerGetTxIterator(const uint8_t ipproto, const AppProto alproto)
int SCConfNodeChildValueIsTrue(const SCConfNode *node, const char *key)
Test if a configuration node has a true value.
const char * SCConfNodeLookupChildValue(const SCConfNode *node, const char *name)
Lookup the value of a child configuration node by name.
int HttpXFFGetIP(const Flow *f, HttpXFFCfg *xff_cfg, char *dstbuf, int dstbuflen)
Function to return XFF IP if any. The caller needs to lock the flow.
AppLayerParserState * alparser
#define SCLogWarning(...)
Macro used to log WARNING messages.
void * AppLayerParserGetTx(uint8_t ipproto, AppProto alproto, void *alstate, uint64_t tx_id)
SCConfNode * SCConfNodeLookupChild(const SCConfNode *node, const char *name)
Lookup a child configuration node by name.
AppLayerGetTxIterTuple(* AppLayerGetTxIteratorFunc)(const uint8_t ipproto, const AppProto alproto, void *alstate, uint64_t min_tx_id, uint64_t max_tx_id, AppLayerGetTxIterState *state)
tx iterator prototype
int HttpXFFGetIPFromTx(const Flow *f, uint64_t tx_id, HttpXFFCfg *xff_cfg, char *dstbuf, int dstbuflen)
Function to return XFF IP if any in the selected transaction. The caller needs to lock the flow.
uint64_t AppLayerParserGetMinId(AppLayerParserState *pstate)
AppProto alproto
application level protocol
uint64_t AppLayerParserGetTxCnt(const Flow *f, void *alstate)