suricata
app-layer-imap.c
Go to the documentation of this file.
1 /* Copyright (C) 2024 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Mahmoud Maatuq <mahmoudmatook.mm@gmail.com>
22  *
23  */
24 
25 #include "suricata-common.h"
26 #include "app-layer-detect-proto.h"
27 #include "app-layer-imap.h"
28 #include "app-layer-protos.h"
29 #include "rust.h"
30 #include "stream-tcp-private.h"
31 #include "stream-tcp-reassemble.h"
32 #include "util-debug.h"
33 
34 static AppProto ImapClientProbingParser(
35  const Flow *f, uint8_t direction, const uint8_t *input, uint32_t len, uint8_t *rdir)
36 {
37  // This is called after " CAPABILITY" pattern has been found
38  if (f->alproto_tc == ALPROTO_IMAP) {
39  // server was already recognised as IMAP, so ok
40  return ALPROTO_IMAP;
41  }
42  for (size_t i = 0; i < len; i++) {
43  if (input[i] >= '0' && input[i] <= '9') {
44  // We check if the tag at the beginning of the input contains a number
45  return ALPROTO_IMAP;
46  }
47  if (input[i] == ' ') {
48  break;
49  }
50  }
51 
53  if (ssn == NULL) {
54  return ALPROTO_FAILED;
55  }
56  const uint32_t size_tc = StreamDataAvailableForProtoDetect(&ssn->server);
57 
58  if (size_tc < 8 && f->alproto_tc == ALPROTO_UNKNOWN) {
59  // wait for another packet from server
60  return ALPROTO_UNKNOWN;
61  }
62  return ALPROTO_FAILED;
63 }
64 
65 static int IMAPRegisterPatternsForProtocolDetection(void)
66 {
68  IPPROTO_TCP, ALPROTO_IMAP, "* OK ", 5, 0, STREAM_TOCLIENT) < 0) {
69  return -1;
70  }
71 
73  IPPROTO_TCP, ALPROTO_IMAP, "* NO ", 5, 0, STREAM_TOCLIENT) < 0) {
74  return -1;
75  }
76 
78  IPPROTO_TCP, ALPROTO_IMAP, "* BAD ", 6, 0, STREAM_TOCLIENT) < 0) {
79  return -1;
80  }
81 
83  IPPROTO_TCP, ALPROTO_IMAP, "* LIST ", 7, 0, STREAM_TOCLIENT) < 0) {
84  return -1;
85  }
86 
88  IPPROTO_TCP, ALPROTO_IMAP, "* ESEARCH ", 10, 0, STREAM_TOCLIENT) < 0) {
89  return -1;
90  }
91 
93  IPPROTO_TCP, ALPROTO_IMAP, "* STATUS ", 9, 0, STREAM_TOCLIENT) < 0) {
94  return -1;
95  }
96 
98  IPPROTO_TCP, ALPROTO_IMAP, "* FLAGS ", 8, 0, STREAM_TOCLIENT) < 0) {
99  return -1;
100  }
101 
102  /**
103  * there is no official document that limits the length of the tag
104  * some practical implementations limit it to 20 characters
105  * but keeping depth equal to 31 fails unit tests such AppLayerTest10
106  * so keeping depth 17 for now to pass unit tests, that might miss some detections
107  * until we find a better solution for the unit tests.
108  *
109  * AppLayerTest10 fails because it expects protocol detection to be completed with only 17 bytes
110  * as input, and with this new pattern, we would need more bytes to finish protocol detection.
111  */
112  if (SCAppLayerProtoDetectPMRegisterPatternCIwPP(IPPROTO_TCP, ALPROTO_IMAP, " CAPABILITY",
113  17 /*6 for max tag len + space + len(CAPABILITY)*/, 0, STREAM_TOSERVER,
114  ImapClientProbingParser, 12, 17) < 0) {
115  return -1;
116  }
117 
118  return 0;
119 }
120 
122 {
123  const char *proto_name = "imap";
124 
125  if (SCAppLayerProtoDetectConfProtoDetectionEnabled("tcp", proto_name)) {
126  SCLogDebug("IMAP protocol detection is enabled.");
128  if (IMAPRegisterPatternsForProtocolDetection() < 0)
129  SCLogError("Failed to register IMAP protocol detection patterns.");
130  } else {
131  SCLogDebug("Protocol detector and parser disabled for IMAP.");
132  }
133 }
len
uint8_t len
Definition: app-layer-dnp3.h:2
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
AppProto
uint16_t AppProto
Definition: app-layer-protos.h:87
SCAppLayerProtoDetectPMRegisterPatternCI
int SCAppLayerProtoDetectPMRegisterPatternCI(uint8_t ipproto, AppProto alproto, const char *pattern, uint16_t depth, uint16_t offset, uint8_t direction)
Registers a case-insensitive pattern for protocol detection.
Definition: app-layer-detect-proto.c:1660
ssn
TcpSession ssn
Definition: fuzz_dataset.c:31
Flow_
Flow data structure.
Definition: flow.h:360
rust.h
stream-tcp-reassemble.h
Flow_::protoctx
void * protoctx
Definition: flow.h:439
SCAppLayerProtoDetectConfProtoDetectionEnabled
int SCAppLayerProtoDetectConfProtoDetectionEnabled(const char *ipproto, const char *alproto)
Given a protocol name, checks if proto detection is enabled in the conf file.
Definition: app-layer-detect-proto.c:1989
app-layer-detect-proto.h
util-debug.h
ALPROTO_IMAP
@ ALPROTO_IMAP
Definition: app-layer-protos.h:41
stream-tcp-private.h
StreamDataAvailableForProtoDetect
uint32_t StreamDataAvailableForProtoDetect(TcpStream *stream)
Definition: stream-tcp-reassemble.c:727
AppLayerProtoDetectRegisterProtocol
void AppLayerProtoDetectRegisterProtocol(AppProto alproto, const char *alproto_name)
Registers a protocol for protocol detection phase.
Definition: app-layer-detect-proto.c:1769
app-layer-imap.h
suricata-common.h
SCAppLayerProtoDetectPMRegisterPatternCIwPP
int SCAppLayerProtoDetectPMRegisterPatternCIwPP(uint8_t ipproto, AppProto alproto, const char *pattern, uint16_t depth, uint16_t offset, uint8_t direction, ProbingParserFPtr PPFunc, uint16_t pp_min_depth, uint16_t pp_max_depth)
Definition: app-layer-detect-proto.c:1650
RegisterIMAPParsers
void RegisterIMAPParsers(void)
Definition: app-layer-imap.c:121
TcpSession_::server
TcpStream server
Definition: stream-tcp-private.h:296
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
ALPROTO_UNKNOWN
@ ALPROTO_UNKNOWN
Definition: app-layer-protos.h:29
ALPROTO_FAILED
@ ALPROTO_FAILED
Definition: app-layer-protos.h:33
app-layer-protos.h
TcpSession_
Definition: stream-tcp-private.h:283
Flow_::alproto_tc
AppProto alproto_tc
Definition: flow.h:458
f
Flow f
Definition: fuzz_dataset.c:32