about summary refs log tree commit diff stats
diff options
context:
space:
mode:
authorStar Rauchenberger <fefferburbia@gmail.com>2025-06-30 15:38:12 -0400
committerStar Rauchenberger <fefferburbia@gmail.com>2025-06-30 15:38:12 -0400
commitf66fc94340bdf6a30260a1932e3f2f22d8822304 (patch)
tree76e660ad290ea210455d1b2e6faae60a7b6c3f9d
parent8163882a352c168b7b70ea883bb7a18a94a55456 (diff)
downloadgen4uploader-f66fc94340bdf6a30260a1932e3f2f22d8822304.tar.gz
gen4uploader-f66fc94340bdf6a30260a1932e3f2f22d8822304.tar.bz2
gen4uploader-f66fc94340bdf6a30260a1932e3f2f22d8822304.zip
Ok sending the auth packet sort of works
I need to set up retransmitting because the assoc request only happens
if I send the auth response twice apparently.
-rw-r--r--.gitignore1
-rw-r--r--CMakeLists.txt7
-rw-r--r--src/addr_list.c91
-rw-r--r--src/addr_list.h21
-rw-r--r--src/beacon_data.c (renamed from src/beacon_data.cpp)0
-rw-r--r--src/beacon_data.h5
-rw-r--r--src/main.c446
-rw-r--r--src/main.cpp210
8 files changed, 568 insertions, 213 deletions
diff --git a/.gitignore b/.gitignore index 567609b..6f31401 100644 --- a/.gitignore +++ b/.gitignore
@@ -1 +1,2 @@
1build/ 1build/
2.vscode/
diff --git a/CMakeLists.txt b/CMakeLists.txt index deefb21..d784ebc 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt
@@ -4,8 +4,9 @@ project (gen4uploader)
4add_subdirectory(vendor/libwifi) 4add_subdirectory(vendor/libwifi)
5 5
6set(SOURCE_FILES 6set(SOURCE_FILES
7 src/main.cpp 7 src/main.c
8 src/beacon_data.cpp 8 src/beacon_data.c
9 src/addr_list.c
9) 10)
10 11
11include_directories( 12include_directories(
@@ -13,4 +14,4 @@ include_directories(
13) 14)
14 15
15add_executable(gen4uploader ${SOURCE_FILES}) 16add_executable(gen4uploader ${SOURCE_FILES})
16target_link_libraries(gen4uploader wifi) 17target_link_libraries(gen4uploader wifi pcap)
diff --git a/src/addr_list.c b/src/addr_list.c new file mode 100644 index 0000000..759907e --- /dev/null +++ b/src/addr_list.c
@@ -0,0 +1,91 @@
1#include "addr_list.h"
2
3#include <stdbool.h>
4#include <stddef.h>
5#include <stdlib.h>
6#include <string.h>
7
8void addr_list_init(struct addr_list* list) {
9 list->top = NULL;
10}
11
12void addr_list_add(struct addr_list* list, unsigned char addr[6]) {
13 struct addr_list_node* cur = list->top;
14 struct addr_list_node* prev = NULL;
15
16 while (cur != NULL) {
17 if (!strncmp(cur->value, addr, 6)) {
18 return;
19 }
20
21 prev = cur;
22 cur = cur->next;
23 }
24
25 struct addr_list_node* next = (struct addr_list_node*)malloc(sizeof(struct addr_list_node));
26 next->next = NULL;
27 memcpy(next->value, addr, 6);
28
29 if (prev == NULL) {
30 list->top = next;
31 } else {
32 prev->next = next;
33 }
34}
35
36bool addr_list_contains(struct addr_list* list, unsigned char addr[6]) {
37 struct addr_list_node* cur = list->top;
38
39 while (cur != NULL) {
40 if (!strncmp(cur->value, addr, 6)) {
41 return true;
42 }
43
44 cur = cur->next;
45 }
46
47 return false;
48}
49
50void addr_list_remove(struct addr_list* list, unsigned char addr[6]) {
51 struct addr_list_node* cur = list->top;
52 struct addr_list_node* prev = NULL;
53
54 if (cur == NULL) {
55 return;
56 }
57
58 while (cur != NULL) {
59 if (!strncmp(cur->value, addr, 6)) {
60 break;
61 }
62
63 prev = cur;
64 cur = cur->next;
65
66 if (cur == NULL) {
67 return;
68 }
69 }
70
71 if (prev == NULL) {
72 list->top = cur->next;
73 } else {
74 prev->next = cur->next;
75 }
76
77 free(cur);
78}
79
80void addr_list_free(struct addr_list* list) {
81 struct addr_list_node* cur = list->top;
82
83 while (cur != NULL) {
84 struct addr_list_node* next = cur->next;
85 free(cur);
86
87 cur = next;
88 }
89
90 list->top = NULL;
91}
diff --git a/src/addr_list.h b/src/addr_list.h new file mode 100644 index 0000000..66e217e --- /dev/null +++ b/src/addr_list.h
@@ -0,0 +1,21 @@
1#ifndef G4U_ADDR_LIST_H
2#define G4U_ADDR_LIST_H
3
4#include <stdbool.h>
5
6struct addr_list_node {
7 unsigned char value[6];
8 struct addr_list_node* next;
9};
10
11struct addr_list {
12 struct addr_list_node* top;
13};
14
15void addr_list_init(struct addr_list* list);
16void addr_list_add(struct addr_list* list, unsigned char addr[6]);
17bool addr_list_contains(struct addr_list* list, unsigned char addr[6]);
18void addr_list_remove(struct addr_list* list, unsigned char addr[6]);
19void addr_list_free(struct addr_list* list);
20
21#endif /* G4U_ADDR_LIST_H */
diff --git a/src/beacon_data.cpp b/src/beacon_data.c index a93eb59..a93eb59 100644 --- a/src/beacon_data.cpp +++ b/src/beacon_data.c
diff --git a/src/beacon_data.h b/src/beacon_data.h index 25fd734..f9aaa17 100644 --- a/src/beacon_data.h +++ b/src/beacon_data.h
@@ -1,3 +1,8 @@
1#ifndef G4U_BEACON_DATA_H
2#define G4U_BEACON_DATA_H
3
1#define BEACON_PAYLOAD_LENGTH 128 4#define BEACON_PAYLOAD_LENGTH 128
2 5
3extern const unsigned char kBeaconPayloads[][128]; 6extern const unsigned char kBeaconPayloads[][128];
7
8#endif /* G4U_BEACON_DATA_H */
diff --git a/src/main.c b/src/main.c new file mode 100644 index 0000000..b74907d --- /dev/null +++ b/src/main.c
@@ -0,0 +1,446 @@
1#include <errno.h>
2#include <fcntl.h>
3#include <libwifi.h>
4#include <linux/if_packet.h>
5#include <net/if.h>
6#include <netinet/ether.h>
7#include <netinet/ip.h>
8#include <pcap/pcap.h>
9#include <poll.h>
10#include <pthread.h>
11#include <stdio.h>
12#include <sys/ioctl.h>
13#include <unistd.h>
14
15#include "addr_list.h"
16#include "beacon_data.h"
17
18static unsigned char kBroadcastAddress[] = "\xFF\xFF\xFF\xFF\xFF\xFF";
19
20static pthread_mutex_t socket_mutex = PTHREAD_MUTEX_INITIALIZER;
21
22static pthread_mutex_t seq_mutex = PTHREAD_MUTEX_INITIALIZER;
23static int seq_number = 0;
24
25int get_interface_mac_address(int sock, const char *interface, unsigned char *output)
26{
27 struct ifreq ifr = {0};
28 strncpy(ifr.ifr_name, interface, IFNAMSIZ - 1);
29
30 if (ioctl(sock, SIOCGIFHWADDR, &ifr) < 0)
31 {
32 return -1;
33 }
34
35 memcpy(output, ifr.ifr_hwaddr.sa_data, 6);
36 return 0;
37}
38
39int get_interface_index(int sock, const char *interface, int *index)
40{
41 struct ifreq ifr = {0};
42 strncpy(ifr.ifr_name, interface, IFNAMSIZ - 1);
43
44 if (ioctl(sock, SIOCGIFINDEX, &ifr) < 0)
45 {
46 return -1;
47 }
48
49 *index = ifr.ifr_ifindex;
50 return 0;
51}
52
53int get_next_seq_number() {
54 pthread_mutex_lock(&seq_mutex);
55 int next = seq_number++;
56 pthread_mutex_unlock(&seq_mutex);
57
58 return next;
59}
60
61int make_beacon_frame(int index, const unsigned char tx_addr[6], int seq_number, unsigned char **buf)
62{
63 struct libwifi_beacon beacon = {0};
64
65 if (libwifi_create_beacon(&beacon, kBroadcastAddress, tx_addr, tx_addr, NULL, 13))
66 {
67 printf("Could not create beacon frame.\n");
68 return -3;
69 }
70
71 beacon.frame_header.seq_control.sequence_number = seq_number;
72 beacon.fixed_parameters.capabilities_information = (1 << CAPABILITIES_ESS) | (1 << CAPABILITIES_SHORT_PREAMBLE) | (1 << CAPABILITIES_SHORT_SLOT);
73 beacon.fixed_parameters.beacon_interval = 200;
74
75 static const unsigned char supported_rates[] = {0x82, 0x84, 0x0b, 0x16, 0x24, 0x30, 0x48, 0x6c};
76 if (libwifi_quick_add_tag(&beacon.tags, TAG_SUPP_RATES, supported_rates, 8))
77 {
78 printf("Could not add supported rates tag.\n");
79 return -7;
80 }
81
82 static const unsigned char tim_bitmap[] = {0x01, 0x02, 0x00, 0x00};
83 if (libwifi_quick_add_tag(&beacon.tags, TAG_TIM, tim_bitmap, 4)) {
84 printf("Could not add TIM tag.\n");
85 return -7;
86 }
87
88 static const unsigned char nothing = 0;
89 libwifi_quick_add_tag(&beacon.tags, TAG_ERP, &nothing, 1);
90 libwifi_quick_add_tag(&beacon.tags, 47, &nothing, 1);
91
92 static const unsigned char extended_supported_rates[] = {0x0c, 0x12, 0x18, 0x60};
93 if (libwifi_quick_add_tag(&beacon.tags, TAG_EXTENDED_SUPPORTED_RATES, extended_supported_rates, 4))
94 {
95 printf("Could not add extended supported rates tag.\n");
96 return -7;
97 }
98
99 unsigned char payload_data[BEACON_PAYLOAD_LENGTH + 8];
100 payload_data[0] = 0x00;
101 payload_data[1] = 0x09;
102 payload_data[2] = 0xBF;
103 payload_data[3] = 0x00;
104 payload_data[4] = 0xFF;
105 payload_data[5] = 0xFF;
106 payload_data[6] = 0x00;
107 payload_data[7] = 0x00;
108 memcpy(payload_data + 8, kBeaconPayloads[index], BEACON_PAYLOAD_LENGTH);
109
110 if (libwifi_quick_add_tag(&beacon.tags, TAG_VENDOR_SPECIFIC, payload_data, BEACON_PAYLOAD_LENGTH + 8))
111 {
112 printf("Could not add beacon data tag.\n");
113 return -6;
114 }
115
116 size_t beacon_size = libwifi_get_beacon_length(&beacon);
117 unsigned char *beacon_output = (unsigned char *)malloc(beacon_size);
118 if (beacon_output == NULL)
119 {
120 printf("Could not allocate beacon output.\n");
121 return -4;
122 }
123
124 if (libwifi_dump_beacon(&beacon, beacon_output, beacon_size) < 0)
125 {
126 printf("Could not dump beacon.\n");
127 return -5;
128 }
129
130 libwifi_free_beacon(&beacon);
131
132 *buf = beacon_output;
133
134 return beacon_size;
135}
136
137int prepend_radiotap(const unsigned char *input, int input_size, unsigned char **output)
138{
139 static const unsigned char radiotap[] = "\x00\x00\x08\x00\x00\x00\x00\x00";
140 static const int radiotap_size = 8;
141
142 int output_size = input_size + radiotap_size;
143
144 unsigned char *buf = (unsigned char *)malloc(output_size);
145 if (buf == NULL)
146 {
147 return -1;
148 }
149
150 memcpy(buf, radiotap, radiotap_size);
151 memcpy(buf + radiotap_size, input, input_size);
152
153 *output = buf;
154
155 return output_size;
156}
157
158int send_packet(int sock, int device_index, const unsigned char dst_addr[6], const unsigned char *packet, int packet_size)
159{
160 struct sockaddr_ll socket_address;
161 socket_address.sll_ifindex = device_index;
162 socket_address.sll_halen = ETH_ALEN;
163 memcpy(socket_address.sll_addr, dst_addr, 6);
164
165 pthread_mutex_lock(&socket_mutex);
166
167 int ret = 0;
168 if (sendto(sock, packet, packet_size, 0, (struct sockaddr *)&socket_address, sizeof(struct sockaddr_ll)) < 0)
169 {
170 printf("Could not send packet: %d\n", errno);
171 ret = errno;
172 }
173
174 pthread_mutex_unlock(&socket_mutex);
175
176 return ret;
177}
178
179int send_packet_with_radiotap(int sock, int device_index, const unsigned char dst_addr[6], const unsigned char *packet, int packet_size)
180{
181 struct libwifi_radiotap_info radiotap_info = {0};
182 radiotap_info.present = (1 << IEEE80211_RADIOTAP_FLAGS) | (1 << IEEE80211_RADIOTAP_RATE);
183 radiotap_info.flags = IEEE80211_RADIOTAP_F_FCS | IEEE80211_RADIOTAP_F_SHORTPRE;
184 radiotap_info.rate_raw = 4;
185
186 unsigned char radiotap_buffer[256];
187 int radiotap_size = libwifi_create_radiotap(&radiotap_info, radiotap_buffer);
188
189 uint32_t fcs = libwifi_calculate_fcs(packet, packet_size);
190
191 int buffer_size = radiotap_size + packet_size + sizeof(uint32_t);
192 unsigned char *buffer = malloc(buffer_size);
193 if (buffer == NULL)
194 {
195 printf("Could not prepend radiotap.\n");
196 return -2;
197 }
198
199 memcpy(buffer, radiotap_buffer, radiotap_size);
200 memcpy(buffer + radiotap_size, packet, packet_size);
201 memcpy(buffer + radiotap_size + packet_size, (unsigned char*)&fcs, sizeof(uint32_t));
202
203 int ret = send_packet(sock, device_index, dst_addr, buffer, buffer_size);
204 free(buffer);
205
206 return ret;
207}
208
209int send_ack(int sock, int device_index, const unsigned char dst_addr[6])
210{
211 struct libwifi_cts ack_frame = {0};
212 if (libwifi_create_cts(&ack_frame, dst_addr, 0)) {
213 printf("Could not create ack packet.\n");
214 }
215
216 ack_frame.frame_header.frame_control.subtype = SUBTYPE_ACK;
217
218 int ret = send_packet_with_radiotap(sock, device_index, dst_addr, (unsigned char*)&ack_frame, sizeof(struct libwifi_cts));
219
220 return ret;
221}
222
223// output buffer size must be at least 18 bytes
224void format_mac_address(const unsigned char addr[6], char *output)
225{
226 sprintf(output, "%02X:%02X:%02X:%02X:%02X:%02X", addr[0], addr[1], addr[2], addr[3], addr[4], addr[5]);
227}
228
229struct thread_info
230{
231 pthread_t thread_id;
232 int sock;
233 unsigned char tx_addr[6];
234 int device_index;
235
236 struct addr_list authenticated;
237};
238
239void handle_incoming_packet(u_char *userdata, const struct pcap_pkthdr *h, const u_char *bytes)
240{
241 struct thread_info *tinfo = (struct thread_info *)userdata;
242
243 struct libwifi_frame frame = {0};
244 if (libwifi_get_wifi_frame(&frame, bytes, h->caplen, true))
245 {
246 printf("Could not parse frame.\n");
247 return;
248 }
249
250 if (frame.frame_control.type == TYPE_MANAGEMENT && frame.frame_control.subtype == SUBTYPE_AUTH)
251 {
252 if (strncmp(frame.header.data.addr1, tinfo->tx_addr, 6)) {
253 // This is not for me. Misdelivery.
254 return;
255 }
256
257 unsigned char in_addr[18];
258 format_mac_address(frame.header.data.addr2, in_addr);
259 printf("Authentication request from %s\n", in_addr);
260
261 if (addr_list_contains(&tinfo->authenticated, frame.header.data.addr2))
262 {
263 // Already authenticated.
264 return;
265 }
266
267 struct libwifi_auth_fixed_parameters *afp = (struct libwifi_auth_fixed_parameters *)frame.body;
268 if (afp->algorithm_number != AUTH_OPEN || afp->status_code != STATUS_SUCCESS || afp->transaction_sequence != 1)
269 {
270 // Incorrect auth details.
271 return;
272 }
273
274 //usleep(frame.header.ctrl.duration / 2 * 100);
275
276 send_ack(tinfo->sock, tinfo->device_index, frame.header.data.addr2);
277
278 addr_list_add(&tinfo->authenticated, frame.header.data.addr2);
279
280 struct libwifi_auth auth_resp = {0};
281 if (libwifi_create_auth(&auth_resp, frame.header.data.addr2, frame.header.data.addr1, frame.header.data.addr1, AUTH_OPEN, 2, STATUS_SUCCESS))
282 {
283 printf("Could not create auth response.\n");
284 return;
285 }
286
287 auth_resp.frame_header.duration = frame.header.ctrl.duration;
288 auth_resp.frame_header.seq_control.sequence_number = get_next_seq_number();
289
290 //static const unsigned char broadcom_tag_value[] = {0x00, 0x10, 0x18, 0x02, 0x00, 0xf0, 0x00, 0x00, 0x00};
291 //libwifi_quick_add_tag(&auth_resp.tags, TAG_VENDOR_SPECIFIC, broadcom_tag_value, 9);
292
293 size_t auth_resp_size = libwifi_get_auth_length(&auth_resp);
294 unsigned char *auth_resp_output = (unsigned char *)malloc(auth_resp_size);
295 if (auth_resp_output == NULL)
296 {
297 printf("Could not allocate auth response output.\n");
298 return;
299 }
300
301 if (libwifi_dump_auth(&auth_resp, auth_resp_output, auth_resp_size) < 0)
302 {
303 printf("Could not dump auth response.\n");
304 return;
305 }
306
307 libwifi_free_auth(&auth_resp);
308
309 //usleep(frame.header.ctrl.duration * 100);
310
311 if (send_packet_with_radiotap(tinfo->sock, tinfo->device_index, frame.header.data.addr2, auth_resp_output, auth_resp_size))
312 {
313 printf("Could not send auth response.\n");
314 return;
315 }
316
317 usleep(5000);
318
319 if (send_packet_with_radiotap(tinfo->sock, tinfo->device_index, frame.header.data.addr2, auth_resp_output, auth_resp_size))
320 {
321 printf("Could not send auth response.\n");
322 return;
323 }
324
325 printf("Successfully authenticated %s!\n", in_addr);
326 }
327}
328
329void *polling_thread(void *arg)
330{
331 struct thread_info *tinfo = (struct thread_info *)arg;
332
333 /*for (;;) {
334 struct pollfd pfd;
335 pfd.fd = tinfo->sock;
336 pfd.events = POLLIN;
337
338 if (poll(&pfd, 1, -1) < 0) {
339 printf("Error polling.\n");
340 } else {
341 if (pfd.revents & POLLIN) {
342 unsigned char message[1024];
343 int msglen = read(tinfo->sock, message, 1024);
344 if (msglen < 0) {
345 printf("Could not read from socket.\n");
346 } else {
347 struct libwifi_frame frame = {0};
348 if (libwifi_get_wifi_frame(&frame, message, msglen, true)) {
349 printf("Could not parse frame.\n");
350 } else {
351 printf("Frame type: %d:%d\n", frame.frame_control.type, frame.frame_control.subtype);
352 }
353 }
354 }
355 }
356 }*/
357
358 char errbuf[PCAP_ERRBUF_SIZE];
359 pcap_t *sniffer = pcap_create("mon0", errbuf);
360 if (sniffer == NULL)
361 {
362 printf("Could not open sniffer: %s\n", errbuf);
363 return NULL;
364 }
365
366 pcap_set_promisc(sniffer, 1);
367 pcap_set_immediate_mode(sniffer, 1);
368 pcap_activate(sniffer);
369 pcap_loop(sniffer, -1, handle_incoming_packet, (u_char *)tinfo);
370
371 return NULL;
372}
373
374int main(int argc, char **argv)
375{
376 static const char *interface_name = "mon0";
377
378 int sock = socket(AF_PACKET, SOCK_RAW, 0);
379 if (sock == -1)
380 {
381 printf("Could not open socket.\n");
382 return 1;
383 }
384
385 unsigned char tx_addr[6];
386 if (get_interface_mac_address(sock, interface_name, tx_addr))
387 {
388 printf("Could not get hardware address.\n");
389 return 2;
390 }
391
392 int device_index = 0;
393 if (get_interface_index(sock, interface_name, &device_index))
394 {
395 printf("Could not get device index.\n");
396 return 2;
397 }
398
399 struct thread_info *tinfo = (struct thread_info *)malloc(sizeof(struct thread_info *));
400 tinfo->sock = sock;
401 memcpy(tinfo->tx_addr, tx_addr, 6);
402 tinfo->device_index = device_index;
403 addr_list_init(&tinfo->authenticated);
404
405 pthread_attr_t thread_attr;
406 if (pthread_attr_init(&thread_attr))
407 {
408 printf("Could not initialize thread attr.\n");
409 return 6;
410 }
411
412 pthread_create(&tinfo->thread_id, &thread_attr, &polling_thread, tinfo);
413 pthread_attr_destroy(&thread_attr);
414
415 int beacon_index = 0;
416 for (;;)
417 {
418 unsigned char *beacon_output;
419 int beacon_size = make_beacon_frame(beacon_index, tx_addr, get_next_seq_number(), &beacon_output);
420 if (beacon_size < 0)
421 {
422 return 3;
423 }
424
425 if (send_packet_with_radiotap(sock, device_index, kBroadcastAddress, beacon_output, beacon_size))
426 {
427 return 4;
428 }
429
430 free(beacon_output);
431
432 beacon_index = (beacon_index + 1) % 10;
433
434 usleep(1024 * 200);
435 }
436
437 if (pthread_join(tinfo->thread_id, NULL))
438 {
439 printf("Could not join thread I guess.\n");
440 return 6;
441 }
442
443 free(tinfo);
444
445 return 0;
446}
diff --git a/src/main.cpp b/src/main.cpp deleted file mode 100644 index d34874c..0000000 --- a/src/main.cpp +++ /dev/null
@@ -1,210 +0,0 @@
1#include <errno.h>
2#include <fcntl.h>
3#include <libwifi.h>
4#include <linux/if_packet.h>
5#include <net/if.h>
6#include <netinet/ether.h>
7#include <netinet/ip.h>
8#include <pcap/pcap.h>
9#include <stdio.h>
10#include <sys/ioctl.h>
11#include <unistd.h>
12
13#include "beacon_data.h"
14
15static unsigned char kBroadcastAddress[] = "\xFF\xFF\xFF\xFF\xFF\xFF";
16
17int get_interface_mac_address(int sock, const char *interface, unsigned char *output)
18{
19 struct ifreq ifr = {0};
20 strncpy(ifr.ifr_name, interface, IFNAMSIZ - 1);
21
22 if (ioctl(sock, SIOCGIFHWADDR, &ifr) < 0)
23 {
24 return -1;
25 }
26
27 memcpy(output, ifr.ifr_hwaddr.sa_data, 6);
28 return 0;
29}
30
31int get_interface_index(int sock, const char *interface, int *index)
32{
33 struct ifreq ifr = {0};
34 strncpy(ifr.ifr_name, interface, IFNAMSIZ - 1);
35
36 if (ioctl(sock, SIOCGIFINDEX, &ifr) < 0)
37 {
38 return -1;
39 }
40
41 *index = ifr.ifr_ifindex;
42 return 0;
43}
44
45int make_beacon_frame(int index, const unsigned char tx_addr[6], int seq_number, unsigned char **buf)
46{
47 struct libwifi_beacon beacon = {0};
48
49 if (libwifi_create_beacon(&beacon, kBroadcastAddress, tx_addr, tx_addr, NULL, 7))
50 {
51 printf("Could not create beacon frame.\n");
52 return -3;
53 }
54
55 beacon.frame_header.seq_control.sequence_number = seq_number;
56
57 static const unsigned char supported_rates[] = {0x82, 0x84, 0x0b, 0x16, 0x24, 0x30, 0x48, 0x6c};
58 if (libwifi_quick_add_tag(&beacon.tags, TAG_SUPP_RATES, supported_rates, 8)) {
59 printf("Could not add supported rates tag.\n");
60 return -7;
61 }
62
63 static const unsigned char extended_supported_rates[] = {0x0c, 0x12, 0x18, 0x60};
64 if (libwifi_quick_add_tag(&beacon.tags, TAG_EXTENDED_SUPPORTED_RATES, extended_supported_rates, 4)) {
65 printf("Could not add extended supported rates tag.\n");
66 return -7;
67 }
68
69 unsigned char payload_data[BEACON_PAYLOAD_LENGTH + 8];
70 payload_data[0] = 0x00;
71 payload_data[1] = 0x09;
72 payload_data[2] = 0xBF;
73 payload_data[3] = 0x00;
74 payload_data[4] = 0xFF;
75 payload_data[5] = 0xFF;
76 payload_data[6] = 0x00;
77 payload_data[7] = 0x00;
78 memcpy(payload_data + 8, kBeaconPayloads[index], BEACON_PAYLOAD_LENGTH);
79
80 if (libwifi_quick_add_tag(&beacon.tags, TAG_VENDOR_SPECIFIC, payload_data, BEACON_PAYLOAD_LENGTH + 8))
81 {
82 printf("Could not add beacon data tag.\n");
83 return -6;
84 }
85
86 size_t beacon_size = libwifi_get_beacon_length(&beacon);
87 unsigned char *beacon_output = (unsigned char *)malloc(beacon_size);
88 if (beacon_output == NULL)
89 {
90 printf("Could not allocate beacon output.\n");
91 return -4;
92 }
93
94 if (libwifi_dump_beacon(&beacon, beacon_output, beacon_size) < 0)
95 {
96 printf("Could not dump beacon.\n");
97 return -5;
98 }
99
100 libwifi_free_beacon(&beacon);
101
102 *buf = beacon_output;
103
104 return beacon_size;
105}
106
107int prepend_radiotap(const unsigned char *input, int input_size, unsigned char **output)
108{
109 static const unsigned char radiotap[] = "\x00\x00\x08\x00\x00\x00\x00\x00";
110 static const int radiotap_size = 8;
111
112 int output_size = input_size + radiotap_size;
113
114 unsigned char *buf = (unsigned char *)malloc(output_size);
115 if (buf == NULL)
116 {
117 return -1;
118 }
119
120 memcpy(buf, radiotap, radiotap_size);
121 memcpy(buf + radiotap_size, input, input_size);
122
123 *output = buf;
124
125 return output_size;
126}
127
128int send_packet(int sock, int device_index, const unsigned char dst_addr[6], const unsigned char *packet, int packet_size)
129{
130 struct sockaddr_ll socket_address;
131 socket_address.sll_ifindex = device_index;
132 socket_address.sll_halen = ETH_ALEN;
133 memcpy(socket_address.sll_addr, dst_addr, 6);
134
135 if (sendto(sock, packet, packet_size, 0, (struct sockaddr *)&socket_address, sizeof(struct sockaddr_ll)) < 0)
136 {
137 printf("Could not send packet.\n");
138 return errno;
139 }
140
141 return 0;
142}
143
144int send_packet_with_radiotap(int sock, int device_index, const unsigned char dst_addr[6], const unsigned char *packet, int packet_size)
145{
146 unsigned char *buffer;
147 int buffer_size = prepend_radiotap(packet, packet_size, &buffer);
148 if (buffer_size < 0)
149 {
150 printf("Could not prepend radiotap.\n");
151 return -2;
152 }
153
154 int ret = send_packet(sock, device_index, dst_addr, buffer, buffer_size);
155 free(buffer);
156
157 return ret;
158}
159
160int main(int argc, char **argv)
161{
162 static const char *interface_name = "mon0";
163
164 int sock = socket(AF_PACKET, SOCK_RAW, 0);
165 if (sock == -1)
166 {
167 printf("Could not open socket.\n");
168 return 1;
169 }
170
171 unsigned char tx_addr[6];
172 if (get_interface_mac_address(sock, interface_name, tx_addr))
173 {
174 printf("Could not get hardware address.\n");
175 return 2;
176 }
177
178 int device_index = 0;
179 if (get_interface_index(sock, interface_name, &device_index))
180 {
181 printf("Could not get device index.\n");
182 return 2;
183 }
184
185 int beacon_index = 0;
186 int seq_number = 0;
187 for (;;)
188 {
189 unsigned char *beacon_output;
190 int beacon_size = make_beacon_frame(beacon_index, tx_addr, seq_number, &beacon_output);
191 if (beacon_size < 0)
192 {
193 return 3;
194 }
195
196 if (send_packet_with_radiotap(sock, device_index, kBroadcastAddress, beacon_output, beacon_size))
197 {
198 return 4;
199 }
200
201 free(beacon_output);
202
203 beacon_index = (beacon_index + 1) % 10;
204 seq_number++;
205
206 usleep(1024 * 100);
207 }
208
209 return 0;
210}