61 "client_handshake_done",
89 "server_handshake_done",
154 {
"CERTIFICATE_INVALID_ALGORITHMIDENTIFIER",
190 #define SSL_CONFIG_DEFAULT_JA3 0
192 #define SSL_CONFIG_DEFAULT_JA4 0
214 #define SSLV3_CHANGE_CIPHER_SPEC 20
215 #define SSLV3_ALERT_PROTOCOL 21
216 #define SSLV3_HANDSHAKE_PROTOCOL 22
217 #define SSLV3_APPLICATION_PROTOCOL 23
218 #define SSLV3_HEARTBEAT_PROTOCOL 24
221 #define SSLV3_HS_HELLO_REQUEST 0
222 #define SSLV3_HS_CLIENT_HELLO 1
223 #define SSLV3_HS_SERVER_HELLO 2
224 #define SSLV3_HS_NEW_SESSION_TICKET 4
225 #define SSLV3_HS_CERTIFICATE 11
226 #define SSLV3_HS_SERVER_KEY_EXCHANGE 12
227 #define SSLV3_HS_CERTIFICATE_REQUEST 13
228 #define SSLV3_HS_SERVER_HELLO_DONE 14
229 #define SSLV3_HS_CERTIFICATE_VERIFY 15
230 #define SSLV3_HS_CLIENT_KEY_EXCHANGE 16
231 #define SSLV3_HS_FINISHED 20
232 #define SSLV3_HS_CERTIFICATE_URL 21
233 #define SSLV3_HS_CERTIFICATE_STATUS 22
236 #define SSLV2_MT_ERROR 0
237 #define SSLV2_MT_CLIENT_HELLO 1
238 #define SSLV2_MT_CLIENT_MASTER_KEY 2
239 #define SSLV2_MT_CLIENT_FINISHED 3
240 #define SSLV2_MT_SERVER_HELLO 4
241 #define SSLV2_MT_SERVER_VERIFY 5
242 #define SSLV2_MT_SERVER_FINISHED 6
243 #define SSLV2_MT_REQUEST_CERTIFICATE 7
244 #define SSLV2_MT_CLIENT_CERTIFICATE 8
246 #define SSLV3_RECORD_HDR_LEN 5
248 #define SSLV3_RECORD_MAX_LEN ((1 << 14) + 1024)
250 #define SSLV3_CLIENT_HELLO_VERSION_LEN 2
251 #define SSLV3_CLIENT_HELLO_RANDOM_LEN 32
254 #define TLS_HB_REQUEST 1
255 #define TLS_HB_RESPONSE 2
257 #define SSL_RECORD_MINIMUM_LENGTH 6
259 #define SHA1_STRING_LENGTH 60
261 #define HAS_SPACE(n) ((uint64_t)(input - initial_input) + (uint64_t)(n) <= (uint64_t)(input_len))
267 #define SSL_DECODER_ERROR(e) \
268 (struct SSLDecoderResult) \
272 #define SSL_DECODER_OK(c) \
273 (struct SSLDecoderResult) \
277 #define SSL_DECODER_INCOMPLETE(c, n) \
278 (struct SSLDecoderResult) \
283 static inline int SafeMemcpy(
void *
dst,
size_t dst_offset,
size_t dst_size,
284 const void *
src,
size_t src_offset,
size_t src_size,
size_t src_tocopy)
WARN_UNUSED;
286 static inline int SafeMemcpy(
void *
dst,
size_t dst_offset,
size_t dst_size,
287 const void *
src,
size_t src_offset,
size_t src_size,
size_t src_tocopy)
294 if (dst_offset < dst_size && src_offset < src_size &&
295 src_tocopy <= (src_size - src_offset) &&
296 src_tocopy <= (dst_size - dst_offset)) {
297 memcpy(
dst + dst_offset,
src + src_offset, src_tocopy);
303 #ifdef DEBUG_VALIDATION
304 #define ValidateRecordState(connp) \
306 DEBUG_VALIDATE_BUG_ON(((connp)->record_length + SSLV3_RECORD_HDR_LEN) < \
307 (connp)->bytes_processed); \
310 #define ValidateRecordState(...)
313 #define SSLParserHSReset(connp) \
315 (connp)->handshake_type = 0; \
316 (connp)->message_length = 0; \
319 #define SSLParserReset(state) \
321 SCLogDebug("resetting state"); \
322 (state)->curr_connp->bytes_processed = 0; \
323 SSLParserHSReset((state)->curr_connp); \
326 #define SSLSetEvent(ssl_state, event) \
328 SCLogDebug("setting event %u", (event)); \
329 if ((ssl_state) == NULL) { \
330 SCLogDebug("could not set decoder event %u", event); \
332 SCAppLayerDecoderEventsSetEventRaw(&(ssl_state)->tx_data.events, (event)); \
333 (ssl_state)->events++; \
337 static void *SSLGetTx(
void *state, uint64_t tx_id)
343 static uint64_t SSLGetTxCnt(
void *state)
356 SCLogDebug(
"toserver: state updated to %u from %u", s, old);
367 SCLogDebug(
"toclient: state updated to %u from %u", s, old);
371 static int SSLGetAlstateProgress(
void *tx, uint8_t direction)
374 if (direction & STREAM_TOCLIENT) {
393 static void TlsDecodeHSCertificateErrSetEvent(
SSLState *ssl_state, uint32_t err)
436 static inline int TlsDecodeHSCertificateFingerprint(
437 SSLStateConnp *connp,
const uint8_t *input, uint32_t cert_len)
447 if (SCSha1HashBuffer(input, cert_len, hash,
sizeof(hash)) == 1) {
454 static inline int TlsDecodeHSCertificateAddCertToChain(
455 SSLStateConnp *connp,
const uint8_t *input, uint32_t cert_len)
469 const uint8_t *
const initial_input,
const uint32_t input_len,
const int certn)
471 const uint8_t *input = (uint8_t *)initial_input;
472 uint32_t err_code = 0;
479 uint32_t cert_len = *input << 16 | *(input + 1) << 8 | *(input + 2);
488 x509 = SCX509Decode(input, cert_len, &err_code);
490 TlsDecodeHSCertificateErrSetEvent(ssl_state, err_code);
516 SCX509GetSubjectAltNameAt(
535 rc = TlsDecodeHSCertificateFingerprint(connp, input, cert_len);
537 SCLogDebug(
"TlsDecodeHSCertificateFingerprint failed with %d", rc);
542 rc = TlsDecodeHSCertificateAddCertToChain(connp, input, cert_len);
544 SCLogDebug(
"TlsDecodeHSCertificateAddCertToChain failed with %d", rc);
550 return (
int)(input - initial_input);
554 TlsDecodeHSCertificateErrSetEvent(ssl_state, err_code);
572 const uint8_t *
const initial_input,
const uint32_t input_len)
574 const uint8_t *input = (uint8_t *)initial_input;
579 const uint32_t cert_chain_len = *input << 16 | *(input + 1) << 8 | *(input + 2);
598 uint32_t processed_len = 0;
600 while (processed_len < cert_chain_len) {
601 int rc = TlsDecodeHSCertificate(ssl_state, connp, connp->
certs_buffer + processed_len,
607 if (processed_len + (uint32_t)rc > cert_chain_len) {
611 processed_len += (uint32_t)rc;
614 return processed_len + 3;
628 static inline int TLSDecodeValueIsGREASE(
const uint16_t value)
654 static inline int TLSDecodeHSHelloVersion(
SSLState *ssl_state,
655 const uint8_t *
const initial_input,
656 const uint32_t input_len)
658 uint8_t *input = (uint8_t *)initial_input;
667 uint16_t
version = (uint16_t)(*input << 8) | *(input + 1);
709 return (
int)(input - initial_input);
712 static inline int TLSDecodeHSHelloRandom(
SSLState *ssl_state,
713 const uint8_t *
const initial_input,
714 const uint32_t input_len)
716 uint8_t *input = (uint8_t *)initial_input;
736 return (
int)(input - initial_input);
739 static inline int TLSDecodeHSHelloSessionID(
SSLState *ssl_state,
740 const uint8_t *
const initial_input,
741 const uint32_t input_len)
743 uint8_t *input = (uint8_t *)initial_input;
748 uint8_t session_id_length = *input;
762 input, 0, input_len, session_id_length) != 0) {
779 input += session_id_length;
781 return (
int)(input - initial_input);
790 static inline int TLSDecodeHSHelloCipherSuites(
SSLState *ssl_state,
791 const uint8_t *
const initial_input,
792 const uint32_t input_len)
794 const uint8_t *input = initial_input;
799 uint16_t cipher_suites_length;
802 cipher_suites_length = 2;
804 cipher_suites_length = (uint16_t)(*input << 8) | *(input + 1);
814 if ((cipher_suites_length % 2) != 0) {
818 const bool enable_ja3 =
825 if (ja3_cipher_suites == NULL)
829 uint16_t processed_len = 0;
831 while (processed_len < cipher_suites_length) {
839 uint16_t cipher_suite = (uint16_t)(*input << 8) | *(input + 1);
842 if (TLSDecodeValueIsGREASE(cipher_suite) != 1) {
845 SCTLSHandshakeAddCipher(ssl_state->
curr_connp->
hs, cipher_suite);
864 return (
int)(input - initial_input);
873 static inline int TLSDecodeHSHelloCompressionMethods(
SSLState *ssl_state,
874 const uint8_t *
const initial_input,
875 const uint32_t input_len)
877 const uint8_t *input = initial_input;
886 uint8_t compression_methods_length = *input;
889 if (!(
HAS_SPACE(compression_methods_length)))
892 input += compression_methods_length;
895 return (
int)(input - initial_input);
904 static inline int TLSDecodeHSHelloExtensionSni(
SSLState *ssl_state,
905 const uint8_t *
const initial_input,
906 const uint32_t input_len)
908 uint8_t *input = (uint8_t *)initial_input;
923 uint8_t sni_type = *input;
938 uint16_t sni_len = (uint16_t)(*input << 8) | *(input + 1);
944 if (!(
HAS_SPACE(sni_len)) || sni_len > 255 || sni_len == 0) {
957 return (
int)(input - initial_input);
965 const size_t consumed = input - initial_input;
966 if (SafeMemcpy(ssl_state->
curr_connp->
sni, 0, sni_len, initial_input, consumed, input_len,
974 return (
int)(input - initial_input);
985 static inline int TLSDecodeHSHelloExtensionSupportedVersions(
SSLState *ssl_state,
986 const uint8_t *
const initial_input,
987 const uint32_t input_len)
989 const uint8_t *input = initial_input;
999 uint8_t supported_ver_len = *input;
1002 if (supported_ver_len < 2)
1003 goto invalid_length;
1006 goto invalid_length;
1011 while (i + 1 < (uint16_t)supported_ver_len) {
1012 uint16_t ver = (uint16_t)(input[i] << 8) | input[i + 1];
1013 if (TLSVersionValid(ver)) {
1015 SCTLSHandshakeSetTLSVersion(ssl_state->
curr_connp->
hs, ver);
1024 input += supported_ver_len;
1028 goto invalid_length;
1030 uint16_t ver = (uint16_t)(*input << 8) | *(input + 1);
1033 (ver > TLS_VERSION_12)) {
1041 return (
int)(input - initial_input);
1051 static inline int TLSDecodeHSHelloExtensionEllipticCurves(
SSLState *ssl_state,
1052 const uint8_t *
const initial_input,
const uint32_t input_len,
1055 const uint8_t *input = initial_input;
1062 goto invalid_length;
1064 uint16_t elliptic_curves_len = (uint16_t)(*input << 8) | *(input + 1);
1068 goto invalid_length;
1071 *ja3_elliptic_curves != NULL) {
1072 uint16_t ec_processed_len = 0;
1074 while (ec_processed_len < elliptic_curves_len)
1077 goto invalid_length;
1079 uint16_t elliptic_curve = (uint16_t)(*input << 8) | *(input + 1);
1082 if (TLSDecodeValueIsGREASE(elliptic_curve) != 1) {
1088 ec_processed_len += 2;
1093 input += elliptic_curves_len;
1096 return (
int)(input - initial_input);
1106 static inline int TLSDecodeHSHelloExtensionEllipticCurvePF(
SSLState *ssl_state,
1107 const uint8_t *
const initial_input,
const uint32_t input_len,
1110 const uint8_t *input = initial_input;
1117 goto invalid_length;
1119 uint8_t ec_pf_len = *input;
1123 goto invalid_length;
1126 *ja3_elliptic_curves_pf != NULL) {
1127 uint8_t ec_pf_processed_len = 0;
1129 while (ec_pf_processed_len < ec_pf_len)
1131 uint8_t elliptic_curve_pf = *input;
1134 if (TLSDecodeValueIsGREASE(elliptic_curve_pf) != 1) {
1140 ec_pf_processed_len += 1;
1148 return (
int)(input - initial_input);
1158 static inline int TLSDecodeHSHelloExtensionSigAlgorithms(
1159 SSLState *ssl_state,
const uint8_t *
const initial_input,
const uint32_t input_len)
1161 const uint8_t *input = initial_input;
1168 goto invalid_length;
1170 uint16_t sigalgo_len = (uint16_t)(*input << 8) | *(input + 1);
1174 if ((sigalgo_len % 2) != 0) {
1175 goto invalid_length;
1179 goto invalid_length;
1182 uint16_t sigalgo_processed_len = 0;
1183 while (sigalgo_processed_len < sigalgo_len) {
1184 uint16_t sigalgo = (uint16_t)(*input << 8) | *(input + 1);
1186 sigalgo_processed_len += 2;
1188 SCTLSHandshakeAddSigAlgo(ssl_state->
curr_connp->
hs, sigalgo);
1192 input += sigalgo_len;
1195 return (
int)(input - initial_input);
1198 SCLogDebug(
"Signature algorithm list invalid length");
1204 static inline int TLSDecodeHSHelloExtensionALPN(
1205 SSLState *ssl_state,
const uint8_t *
const initial_input,
const uint32_t input_len)
1207 const uint8_t *input = initial_input;
1214 goto invalid_length;
1216 uint16_t alpn_len = (uint16_t)(*input << 8) | *(input + 1);
1220 goto invalid_length;
1224 uint32_t alpn_processed_len = 0;
1225 while (alpn_processed_len < alpn_len) {
1226 uint8_t protolen = *input;
1228 alpn_processed_len += 1;
1231 goto invalid_length;
1235 if (alpn_processed_len + protolen > ((uint32_t)alpn_len)) {
1236 input += alpn_len - alpn_processed_len;
1239 SCTLSHandshakeAddALPN(ssl_state->
curr_connp->
hs, (
const char *)input, protolen);
1241 alpn_processed_len += protolen;
1245 return (
int)(input - initial_input);
1254 static inline int TLSDecodeHSHelloExtensions(
SSLState *ssl_state,
1255 const uint8_t *
const initial_input,
1256 const uint32_t input_len)
1258 const uint8_t *input = initial_input;
1268 JA3Buffer *ja3_elliptic_curves_pf = NULL;
1272 if (ja3_extensions == NULL)
1277 if (ja3_elliptic_curves == NULL)
1281 if (ja3_elliptic_curves_pf == NULL)
1290 uint16_t extensions_len = (uint16_t)(*input << 8) | *(input + 1);
1294 goto invalid_length;
1296 uint32_t processed_len = 0;
1298 while (processed_len < (uint32_t)extensions_len) {
1300 goto invalid_length;
1302 uint16_t ext_type = (uint16_t)(*input << 8) | *(input + 1);
1306 goto invalid_length;
1308 uint16_t ext_len = (uint16_t)(*input << 8) | *(input + 1);
1312 goto invalid_length;
1314 if (processed_len + 4UL + (uint32_t)ext_len > (uint32_t)extensions_len)
1315 goto invalid_length;
1321 ret = TLSDecodeHSHelloExtensionSni(ssl_state, input,
1334 ret = TLSDecodeHSHelloExtensionEllipticCurves(
1335 ssl_state, input, ext_len, &ja3_elliptic_curves);
1347 ret = TLSDecodeHSHelloExtensionEllipticCurvePF(
1348 ssl_state, input, ext_len, &ja3_elliptic_curves_pf);
1359 ret = TLSDecodeHSHelloExtensionSigAlgorithms(ssl_state, input, ext_len);
1370 ret = TLSDecodeHSHelloExtensionALPN(ssl_state, input, ext_len);
1394 ret = TLSDecodeHSHelloExtensionSupportedVersions(ssl_state, input,
1425 if (TLSDecodeValueIsGREASE(ext_type) != 1) {
1434 if (TLSDecodeValueIsGREASE(ext_type) != 1) {
1435 SCTLSHandshakeAddExtension(ssl_state->
curr_connp->
hs, ext_type);
1439 processed_len += (uint32_t)ext_len + 4UL;
1451 &ja3_elliptic_curves);
1456 &ja3_elliptic_curves_pf);
1462 return (
int)(input - initial_input);
1470 if (ja3_extensions != NULL)
1472 if (ja3_elliptic_curves != NULL)
1474 if (ja3_elliptic_curves_pf != NULL)
1480 static int TLSDecodeHandshakeHello(
SSLState *ssl_state,
1481 const uint8_t *
const input,
1482 const uint32_t input_len)
1485 uint32_t parsed = 0;
1487 ret = TLSDecodeHSHelloVersion(ssl_state, input, input_len);
1493 ret = TLSDecodeHSHelloRandom(ssl_state, input + parsed, input_len - parsed);
1504 ret = TLSDecodeHSHelloSessionID(ssl_state, input + parsed,
1505 input_len - parsed);
1512 ret = TLSDecodeHSHelloCipherSuites(ssl_state, input + parsed,
1513 input_len - parsed);
1524 ret = TLSDecodeHSHelloCompressionMethods(ssl_state, input + parsed,
1525 input_len - parsed);
1532 ret = TLSDecodeHSHelloExtensions(ssl_state, input + parsed,
1533 input_len - parsed);
1550 #ifdef DEBUG_VALIDATION
1560 const uint8_t *
const initial_input,
const uint32_t input_len)
1562 int rc = TlsDecodeHSCertificates(ssl_state, connp, initial_input, input_len);
1567 }
else if (rc < 0) {
1568 SCLogDebug(
"error parsing cert, reset state");
1580 static int SupportedHandshakeType(
const uint8_t
type)
1610 static int SSLv3ParseHandshakeType(
SSLState *ssl_state,
const uint8_t *input,
1611 uint32_t input_len, uint8_t direction)
1613 const uint8_t *initial_input = input;
1625 rc = TLSDecodeHandshakeHello(ssl_state, input, input_len);
1637 rc = TLSDecodeHandshakeHello(ssl_state, input, input_len);
1651 rc = SSLv3ParseHandshakeTypeCertificate(ssl_state,
1691 static int SSLv3ParseHandshakeProtocol(
SSLState *ssl_state,
const uint8_t *input,
1692 uint32_t input_len, uint8_t direction)
1694 const uint8_t *initial_input = input;
1705 SCLogDebug(
"partial handshake record in place");
1708 const uint32_t add =
MIN(need, input_len);
1714 const uint32_t new_size = avail + (4096 - (avail % 4096));
1715 SCLogDebug(
"new_size %u, avail %u", new_size, avail);
1723 SCLogDebug(
"ssl_state->curr_connp->hs_buffer_offset %u "
1724 "ssl_state->curr_connp->hs_buffer_size %u",
1746 SCLogDebug(
"got all data now: handshake_type %u message_length %u",
1777 SCLogDebug(
"input %p input_len %u", input, input_len);
1779 if (input_len < 4) {
1786 SCLogDebug(
"handshake_type %u message len %u input %p input_len %u",
1796 SCLogDebug(
"supported_type %s handshake_type %u/%02x", supported_type ?
"true" :
"false",
1798 if (!supported_type) {
1799 uint32_t avail_record_len =
MIN(input_len, record_len);
1800 input += avail_record_len;
1801 input_len -= avail_record_len;
1815 if (record_len > input_len) {
1816 const uint32_t avail = input_len;
1817 const uint32_t size = avail + (4096 - (avail % 4096));
1818 SCLogDebug(
"initial buffer size %u, based on input %u", size, avail);
1827 if (input_len > 0) {
1835 SCLogDebug(
"opened record buffer %p size %u offset %u type %u msg_size %u",
1842 return (
int)(input - initial_input);
1846 int retval = SSLv3ParseHandshakeType(
1848 if (retval < 0 || retval > (
int)input_len) {
1852 SCLogDebug(
"retval %d input_len %u", retval, input_len);
1854 input_len -= retval;
1860 return (
int)(input - initial_input);
1874 static int SSLv3ParseAlertProtocol(
1875 SSLState *ssl_state,
const uint8_t *input, uint32_t input_len, uint8_t direction)
1877 if (input_len < 2) {
1883 if (input_len == 2) {
1884 uint8_t level = input[0];
1907 static int SSLv3ParseHeartbeatProtocol(
SSLState *ssl_state,
const uint8_t *input,
1908 uint32_t input_len, uint8_t direction)
1912 uint32_t padding_len;
1915 if (input_len < 3) {
1932 SCLogDebug(
"HeartBeat Record type sent in the toclient direction!");
1935 SCLogDebug(
"HeartBeat Record type sent in the toserver direction!");
1943 SCLogDebug(
"Encrypted HeartBeat Request In-flight. Storing len %u",
1948 payload_len = (uint16_t)(*input << 8) | *(input + 1);
1953 SCLogDebug(
"We have a short record in HeartBeat Request");
1961 if (padding_len < 16) {
1962 SCLogDebug(
"We have a short record in HeartBeat Request");
1976 SCLogDebug(
"Multiple in-flight server initiated HeartBeats");
1982 SCLogDebug(
"Multiple in-flight client initiated HeartBeats");
2000 SCLogDebug(
"My heart is bleeding.. OpenSSL HeartBleed response (%u)",
2019 static int SSLv3ParseRecord(uint8_t direction,
SSLState *ssl_state,
2020 const uint8_t *input, uint32_t input_len)
2022 const uint8_t *initial_input = input;
2024 if (input_len == 0) {
2028 uint8_t skip_version = 0;
2032 if (direction == 0) {
2046 if (input_len >= 5) {
2048 if (!skip_version) {
2057 if (--input_len == 0)
2063 if (!skip_version) {
2068 if (--input_len == 0)
2073 if (!skip_version) {
2078 if (--input_len == 0)
2084 if (--input_len == 0)
2090 if (--input_len == 0)
2098 return (
int)(input - initial_input);
2101 static int SSLv2ParseRecord(uint8_t direction,
SSLState *ssl_state,
2102 const uint8_t *input, uint32_t input_len)
2104 const uint8_t *initial_input = input;
2106 if (input_len == 0) {
2121 if (--input_len == 0)
2128 if (--input_len == 0)
2135 if (--input_len == 0)
2152 if (--input_len == 0)
2159 if (--input_len == 0)
2166 if (--input_len == 0)
2173 if (--input_len == 0)
2182 return (
int)(input - initial_input);
2189 const uint8_t *initial_input = input;
2191 if (ssl_state->curr_connp->bytes_processed == 0) {
2192 if (input[0] & 0x80) {
2193 ssl_state->curr_connp->record_lengths_length = 2;
2195 ssl_state->curr_connp->record_lengths_length = 3;
2203 SCLogDebug(
"direction %u ssl_state->curr_connp->record_lengths_length + 1 %u, "
2204 "ssl_state->curr_connp->bytes_processed %u",
2205 direction, ssl_state->curr_connp->record_lengths_length + 1,
2206 ssl_state->curr_connp->bytes_processed);
2209 if (ssl_state->curr_connp->bytes_processed <
2210 (ssl_state->curr_connp->record_lengths_length + 1)) {
2211 const int retval = SSLv2ParseRecord(direction, ssl_state, input, input_len);
2213 ssl_state->curr_connp->record_length);
2214 if (retval < 0 || retval > (
int)input_len) {
2221 ssl_state->curr_connp->record_lengths_length + ssl_state->curr_connp->record_length,
2230 if (ssl_state->curr_connp->record_lengths_length + ssl_state->curr_connp->record_length >
2231 input_len + ssl_state->curr_connp->bytes_processed) {
2232 uint32_t
needed = ssl_state->curr_connp->record_length;
2233 SCLogDebug(
"record len %u input_len %u parsed %u: need %u bytes more data",
2234 ssl_state->curr_connp->record_length, input_len, (uint32_t)(input - initial_input),
2239 if (input_len == 0) {
2244 if (ssl_state->curr_connp->record_length == 0) {
2251 if (ssl_state->curr_connp->record_lengths_length == 0) {
2252 SCLogDebug(
"SSLv2 record lengths length is zero");
2257 switch (ssl_state->curr_connp->content_type) {
2259 SCLogDebug(
"SSLV2_MT_ERROR msg_type received. Error encountered "
2260 "in establishing the sslv2 session, may be version");
2271 if (input_len < 6 || ssl_state->curr_connp->
record_length < 7) {
2280 const uint16_t
version = (uint16_t)(input[0] << 8) | input[1];
2282 ssl_state->curr_connp->version =
version;
2283 uint16_t session_id_length = (input[5]) | (uint16_t)(input[4] << 8);
2286 ssl_state->curr_connp->bytes_processed += 6;
2287 if (session_id_length == 0) {
2294 SCLogDebug(
"Client hello is not seen before master key "
2302 if (direction == 1) {
2303 SCLogDebug(
"Incorrect SSL Record type sent in the toclient "
2313 if (direction == 0 &&
2314 !(ssl_state->curr_connp->content_type &
2316 SCLogDebug(
"Incorrect SSL Record type sent in the toserver "
2327 if (direction == 0) {
2330 SCLogDebug(
"SSLv2 client side has started the encryption");
2333 SCLogDebug(
"SSLv2 client side has started the encryption");
2337 SCLogDebug(
"SSLv2 Server side has started the encryption");
2351 SCLogDebug(
"SSLv2 No reassembly & inspection has been set");
2365 ssl_state->flags |= ssl_state->current_flags;
2367 if (ssl_state->curr_connp->bytes_processed >
2368 ssl_state->curr_connp->record_length + ssl_state->curr_connp->record_lengths_length) {
2369 SCLogDebug(
"SSLv2 bytes_processed (%u) exceeds record+hdr "
2370 "len (record_length=%u, lengths_length=%u)",
2371 ssl_state->curr_connp->bytes_processed, ssl_state->curr_connp->record_length,
2372 ssl_state->curr_connp->record_lengths_length);
2377 if (input_len + ssl_state->curr_connp->bytes_processed >=
2378 (ssl_state->curr_connp->record_length +
2379 ssl_state->curr_connp->record_lengths_length)) {
2382 uint32_t diff = ssl_state->curr_connp->record_length +
2383 ssl_state->curr_connp->record_lengths_length + -
2384 ssl_state->curr_connp->bytes_processed;
2392 ssl_state->curr_connp->bytes_processed += input_len;
2401 uint32_t parsed = 0;
2402 uint32_t record_len;
2403 const bool first_call = (ssl_state->curr_connp->bytes_processed == 0);
2406 const uint16_t prev_version = ssl_state->curr_connp->version;
2408 int retval = SSLv3ParseRecord(direction, ssl_state, input, input_len);
2409 if (retval < 0 || retval > (
int)input_len) {
2417 SCLogDebug(
"%s input %p record_length %u", (direction == 0) ?
"toserver" :
"toclient",
2418 input, ssl_state->curr_connp->record_length);
2431 "incomplete header, return %u bytes consumed and wait for more data", parsed);
2438 record_len =
MIN(input_len - parsed, ssl_state->curr_connp->record_length);
2440 "record_len %u (input_len %u, parsed %u, ssl_state->curr_connp->record_length %u)",
2441 record_len, input_len, parsed, ssl_state->curr_connp->record_length);
2443 bool unknown_record =
false;
2444 switch (ssl_state->curr_connp->content_type) {
2452 unknown_record =
true;
2458 if (prev_version == TLS_VERSION_10 || prev_version == TLS_VERSION_11) {
2459 if (unknown_record) {
2463 ssl_state->curr_connp->bytes_processed = 0;
2464 ssl_state->curr_connp->content_type = 0;
2465 ssl_state->curr_connp->record_length = 0;
2467 ssl_state->curr_connp->version = prev_version;
2471 if (unknown_record) {
2479 if (ssl_state->curr_connp->record_length == 0) {
2485 if (!TLSVersionValid(ssl_state->curr_connp->version)) {
2486 SCLogDebug(
"ssl_state->curr_connp->version %04x", ssl_state->curr_connp->version);
2500 record_len = (ssl_state->curr_connp->record_length +
SSLV3_RECORD_HDR_LEN)- ssl_state->curr_connp->bytes_processed;
2501 record_len =
MIN(input_len, record_len);
2503 SCLogDebug(
"record length %u processed %u got %u",
2504 ssl_state->curr_connp->record_length, ssl_state->curr_connp->bytes_processed, record_len);
2507 if (ssl_state->curr_connp->record_length > input_len - parsed) {
2513 uint32_t
needed = ssl_state->curr_connp->record_length;
2514 SCLogDebug(
"record len %u input_len %u parsed %u: need %u bytes more data",
2515 ssl_state->curr_connp->record_length, input_len, parsed,
needed);
2521 if (record_len == 0) {
2526 ssl_state->curr_connp->record_length, direction,
TLS_FRAME_DATA);
2528 switch (ssl_state->curr_connp->content_type) {
2547 int retval = SSLv3ParseAlertProtocol(ssl_state, input + parsed, record_len, direction);
2565 if (ssl_state->curr_connp == &ssl_state->client_connp) {
2572 SCLogDebug(
"setting APP_LAYER_PARSER_NO_INSPECTION_PAYLOAD");
2579 SCLogDebug(
"setting APP_LAYER_PARSER_NO_REASSEMBLY");
2592 (ssl_state->client_connp.version > TLS_VERSION_12) &&
2601 if (ssl_state->curr_connp->record_length < 4) {
2604 SCLogDebug(
"record len < 4 => %u", ssl_state->curr_connp->record_length);
2608 int retval = SSLv3ParseHandshakeProtocol(ssl_state, input + parsed,
2609 record_len, direction);
2611 if (retval < 0 || retval > (
int)record_len) {
2623 int retval = SSLv3ParseHeartbeatProtocol(ssl_state, input + parsed,
2624 record_len, direction);
2638 parsed += record_len;
2639 ssl_state->curr_connp->bytes_processed += record_len;
2641 if (ssl_state->curr_connp->bytes_processed >=
2645 ssl_state->f, direction == 0 ? STREAM_TOSERVER : STREAM_TOCLIENT);
2682 uint32_t counter = 0;
2684 const uint8_t *input = StreamSliceGetData(&stream_slice);
2685 const uint8_t *init_input = input;
2686 int32_t input_len = (int32_t)StreamSliceGetDataLen(&stream_slice);
2688 if ((input == NULL || input_len == 0) &&
2698 }
else if (input == NULL || input_len == 0) {
2714 while (input_len > 0) {
2715 if (counter > max_records) {
2716 SCLogDebug(
"Looks like we have looped quite a bit. Reset state "
2717 "and get out of here");
2728 if ((input[0] & 0x80) || (input[0] & 0x40)) {
2737 SCLogDebug(
"record %u: bytes_processed %u, version %02X, input_len %u", counter,
2744 SCLogDebug(
"Continuing parsing SSLv2 record");
2747 SSLv2Decode(direction, ssl_state, pstate, input, input_len, stream_slice);
2750 SCLogDebug(
"Error parsing SSLv2. Resetting parser "
2751 "state. Let's get outta here");
2758 SCLogDebug(
"returning consumed %" PRIuMAX
" needed %u",
2759 (uintmax_t)(input - init_input), r.
needed);
2764 SCLogDebug(
"SSLv2 decoder consumed %d bytes: %u left", r.
retval, input_len);
2767 SCLogDebug(
"New TLS record: record_length %u",
2770 SCLogDebug(
"Continuing parsing TLS record: record_length %u, bytes_processed %u",
2774 SSLv3Decode(direction, ssl_state, pstate, input, input_len, stream_slice);
2777 SCLogDebug(
"Error parsing TLS. Resetting parser "
2778 "state. Let's get outta here");
2783 SCLogDebug(
"returning consumed %" PRIuMAX
" needed %u",
2784 (uintmax_t)(input - init_input), r.
needed);
2828 return SSLDecode(f, 0 , alstate, pstate, stream_slice);
2834 return SSLDecode(f, 1 , alstate, pstate, stream_slice);
2841 static void *SSLStateAlloc(
void *orig_state,
AppProto proto_orig)
2849 return (
void *)ssl_state;
2866 static void SSLStateFree(
void *
p)
2945 static void SSLStateTransactionFree(
void *state, uint64_t tx_id)
2951 const Flow *f, uint8_t direction,
const uint8_t *input, uint32_t ilen, uint8_t *rdir)
2959 if ((input[0] & 0x80) && (input[2] == 0x01)) {
2966 static int SSLStateGetStateIdByName(
const char *
name,
const uint8_t direction)
2969 direction == STREAM_TOSERVER ? tls_state_client_table : tls_state_server_table;
2978 static const char *SSLStateGetStateNameById(
const int id,
const uint8_t direction)
2981 direction == STREAM_TOSERVER ? tls_state_client_table : tls_state_server_table;
2986 static int SSLStateGetFrameIdByName(
const char *frame_name)
2995 static const char *SSLStateGetFrameNameById(
const uint8_t frame_id)
3001 static int SSLStateGetEventInfo(
3011 static int SSLStateGetEventInfoById(
3015 if (*event_name == NULL) {
3017 "ssl's enum map table.",
3028 static int SSLRegisterPatternsForProtocolDetection(
void)
3031 STREAM_TOSERVER, SSLProbingParser, 0, 3) < 0) {
3037 IPPROTO_TCP,
ALPROTO_TLS,
"|01 03 00|", 3, 0, STREAM_TOSERVER) < 0) {
3041 IPPROTO_TCP,
ALPROTO_TLS,
"|16 03 00|", 3, 0, STREAM_TOSERVER) < 0) {
3047 IPPROTO_TCP,
ALPROTO_TLS,
"|01 03 01|", 3, 0, STREAM_TOSERVER) < 0) {
3051 IPPROTO_TCP,
ALPROTO_TLS,
"|16 03 01|", 3, 0, STREAM_TOSERVER) < 0) {
3057 IPPROTO_TCP,
ALPROTO_TLS,
"|01 03 02|", 3, 0, STREAM_TOSERVER) < 0) {
3061 IPPROTO_TCP,
ALPROTO_TLS,
"|16 03 02|", 3, 0, STREAM_TOSERVER) < 0) {
3067 IPPROTO_TCP,
ALPROTO_TLS,
"|01 03 03|", 3, 0, STREAM_TOSERVER) < 0) {
3071 IPPROTO_TCP,
ALPROTO_TLS,
"|16 03 03|", 3, 0, STREAM_TOSERVER) < 0) {
3078 IPPROTO_TCP,
ALPROTO_TLS,
"|15 03 00|", 3, 0, STREAM_TOCLIENT) < 0) {
3082 IPPROTO_TCP,
ALPROTO_TLS,
"|16 03 00|", 3, 0, STREAM_TOCLIENT) < 0) {
3086 IPPROTO_TCP,
ALPROTO_TLS,
"|17 03 00|", 3, 0, STREAM_TOCLIENT) < 0) {
3092 IPPROTO_TCP,
ALPROTO_TLS,
"|15 03 01|", 3, 0, STREAM_TOCLIENT) < 0) {
3096 IPPROTO_TCP,
ALPROTO_TLS,
"|16 03 01|", 3, 0, STREAM_TOCLIENT) < 0) {
3100 IPPROTO_TCP,
ALPROTO_TLS,
"|17 03 01|", 3, 0, STREAM_TOCLIENT) < 0) {
3106 IPPROTO_TCP,
ALPROTO_TLS,
"|15 03 02|", 3, 0, STREAM_TOCLIENT) < 0) {
3110 IPPROTO_TCP,
ALPROTO_TLS,
"|16 03 02|", 3, 0, STREAM_TOCLIENT) < 0) {
3114 IPPROTO_TCP,
ALPROTO_TLS,
"|17 03 02|", 3, 0, STREAM_TOCLIENT) < 0) {
3120 IPPROTO_TCP,
ALPROTO_TLS,
"|15 03 03|", 3, 0, STREAM_TOCLIENT) < 0) {
3124 IPPROTO_TCP,
ALPROTO_TLS,
"|16 03 03|", 3, 0, STREAM_TOCLIENT) < 0) {
3128 IPPROTO_TCP,
ALPROTO_TLS,
"|17 03 03|", 3, 0, STREAM_TOCLIENT) < 0) {
3138 "|01 03 00|", 5, 2, STREAM_TOSERVER) < 0)
3143 "|00 02|", 7, 5, STREAM_TOCLIENT) < 0)
3153 static void CheckJA3Enabled(
void)
3155 const char *strval = NULL;
3158 if (
SCConfGetNonNull(
"app-layer.protocols.tls.ja3-fingerprints", &strval) != 1) {
3160 }
else if (strcmp(strval,
"auto") == 0) {
3178 static void CheckJA4Enabled(
void)
3180 const char *strval = NULL;
3182 int enable_ja4 = SSL_CONFIG_DEFAULT_JA4;
3183 if (
SCConfGetNonNull(
"app-layer.protocols.tls.ja4-fingerprints", &strval) != 1) {
3184 enable_ja4 = SSL_CONFIG_DEFAULT_JA4;
3185 }
else if (strcmp(strval,
"auto") == 0) {
3186 enable_ja4 = SSL_CONFIG_DEFAULT_JA4;
3207 const char *proto_name =
"tls";
3215 if (SSLRegisterPatternsForProtocolDetection() < 0)
3220 IPPROTO_TCP,
"443",
ALPROTO_TLS, 0, 3, STREAM_TOSERVER, SSLProbingParser, NULL);
3223 0, 3, SSLProbingParser, NULL) == 0) {
3225 "enabling TLS detection on port 443.");
3227 STREAM_TOSERVER, SSLProbingParser, NULL);
3231 SCLogConfig(
"Protocol detection and parser disabled for %s protocol",
3238 SSLParseClientRecord);
3241 SSLParseServerRecord);
3243 IPPROTO_TCP,
ALPROTO_TLS, SSLStateGetStateIdByName, SSLStateGetStateNameById);
3245 IPPROTO_TCP,
ALPROTO_TLS, SSLStateGetFrameIdByName, SSLStateGetFrameNameById);
3268 if (enc_handle != NULL && enc_handle->
val != NULL) {
3269 SCLogDebug(
"have app-layer.protocols.tls.encryption-handling = %s", enc_handle->
val);
3270 if (strcmp(enc_handle->
val,
"full") == 0) {
3272 }
else if (strcmp(enc_handle->
val,
"bypass") == 0) {
3274 }
else if (strcmp(enc_handle->
val,
"track-only") == 0) {
3276 }
else if (strcmp(enc_handle->
val,
"default") == 0) {
3277 SCLogWarning(
"app-layer.protocols.tls.encryption-handling = default is deprecated "
3278 "and will be removed in Suricata 9, use \"track-only\" instead, "
3279 "(see ticket #7642)");
3286 if (
SCConfGetNode(
"app-layer.protocols.tls.no-reassemble") == NULL) {
3288 if (
SCConfGetBool(
"tls.no-reassemble", &value) == 1 && value == 1)
3292 if (
SCConfGetBool(
"app-layer.protocols.tls.no-reassemble", &value) == 1 &&
3308 SCLogWarning(
"MD5 calculation has been disabled, disabling JA3");
3312 SCLogWarning(
"Hashing has been disabled, disabling JA4");
3326 SCLogConfig(
"Parser disabled for %s protocol. Protocol detection still on.", proto_name);