mirror of
https://github.com/lwthiker/curl-impersonate.git
synced 2026-10-11 11:56:33 +00:00
Handle curl_easy_reset() calls when impersonating (#44)
curl_easy_reset() may be used by an application to reset the options on a curl handle. If an app has the CURL_IMPERSONATE env var defined, then the impersonation options are automatically set in curl_easy_init() but will be cleared in a call to curl_easy_reset(). The desired behavior is for the impersonation options to be retained (as they are "transparent" to the user), which this commit takes care of. Note that this only has an effect when libcurl-impersonate is loaded and the CURL_IMPERSONATE env var is set. Otherwise the regular behavior of resetting all the handle options is retained. Test that the unique TLS signature of curl-impersonate is preserved after a call to curl_easy_reset() when libcurl-impersonate is loaded. For this purpose change the 'minicurl' testing util to support multiple URLs and launch it with 2 different URLs when testing the TLS signature.
This commit is contained in:
+70
-49
@@ -16,13 +16,15 @@
|
||||
|
||||
#include <curl/curl.h>
|
||||
|
||||
/* Support up to 16 URLs */
|
||||
#define MAX_URLS 16
|
||||
/* Command line options. */
|
||||
struct opts {
|
||||
char *outfile;
|
||||
uint16_t local_port_start;
|
||||
uint16_t local_port_end;
|
||||
bool insecure;
|
||||
char *url;
|
||||
char *urls[MAX_URLS];
|
||||
};
|
||||
|
||||
int parse_ports_range(char *str, uint16_t *start, uint16_t *end)
|
||||
@@ -60,6 +62,7 @@ int parse_opts(int argc, char **argv, struct opts *opts)
|
||||
{
|
||||
int c;
|
||||
int r;
|
||||
int i;
|
||||
|
||||
memset(opts, 0, sizeof(*opts));
|
||||
|
||||
@@ -94,17 +97,69 @@ int parse_opts(int argc, char **argv, struct opts *opts)
|
||||
}
|
||||
}
|
||||
|
||||
if (optind < argc) {
|
||||
opts->url = argv[optind++];
|
||||
} else {
|
||||
/* No URL supplied. */
|
||||
if (optind >= argc) {
|
||||
return 1;
|
||||
}
|
||||
|
||||
if (optind < argc) {
|
||||
/* Too many arguments. */
|
||||
/* The rest of the options are URLs */
|
||||
i = 0;
|
||||
while (optind < argc) {
|
||||
opts->urls[i++] = argv[optind++];
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Set all options except for the URL. */
|
||||
int set_opts(CURL *curl, struct opts *opts, FILE *file)
|
||||
{
|
||||
CURLcode c;
|
||||
|
||||
c = curl_easy_setopt(curl, CURLOPT_WRITEFUNCTION, fwrite);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_WRITEFUNCTION) failed\n");
|
||||
return 1;
|
||||
}
|
||||
|
||||
c = curl_easy_setopt(curl, CURLOPT_WRITEDATA, file);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_WRITEDATA) failed\n");
|
||||
return 1;
|
||||
}
|
||||
|
||||
if (opts->local_port_start && opts->local_port_end) {
|
||||
c = curl_easy_setopt(curl,
|
||||
CURLOPT_LOCALPORT,
|
||||
opts->local_port_start);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_LOCALPORT) failed\n");
|
||||
return 1;
|
||||
}
|
||||
|
||||
c = curl_easy_setopt(curl,
|
||||
CURLOPT_LOCALPORTRANGE,
|
||||
opts->local_port_end - opts->local_port_start);
|
||||
if (c) {
|
||||
fprintf(stderr,
|
||||
"curl_easy_setopt(CURLOPT_LOCALPORTRANGE) failed\n");
|
||||
return 1;
|
||||
}
|
||||
}
|
||||
|
||||
if (opts->insecure) {
|
||||
c = curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 0);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_SSL_VERIFYPEER) failed\n");
|
||||
return 1;
|
||||
}
|
||||
c = curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 0);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_SSL_VERIFYHOST) failed\n");
|
||||
return 1;
|
||||
}
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -114,6 +169,7 @@ int main(int argc, char *argv[])
|
||||
CURLcode c;
|
||||
CURL *curl = NULL;
|
||||
FILE *file;
|
||||
int i;
|
||||
|
||||
if (parse_opts(argc, argv, &opts)) {
|
||||
fprintf(stderr, "Invalid arguments\n");
|
||||
@@ -143,60 +199,25 @@ int main(int argc, char *argv[])
|
||||
goto out;
|
||||
}
|
||||
|
||||
c = curl_easy_setopt(curl, CURLOPT_WRITEFUNCTION, fwrite);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_WRITEFUNCTION) failed\n");
|
||||
goto out;
|
||||
}
|
||||
|
||||
c = curl_easy_setopt(curl, CURLOPT_WRITEDATA, file);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_WRITEDATA) failed\n");
|
||||
goto out;
|
||||
}
|
||||
|
||||
if (opts.local_port_start && opts.local_port_end) {
|
||||
c = curl_easy_setopt(curl,
|
||||
CURLOPT_LOCALPORT,
|
||||
opts.local_port_start);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_LOCALPORT) failed\n");
|
||||
for (i = 0; i <= MAX_URLS && opts.urls[i]; i++) {
|
||||
if (set_opts(curl, &opts, file)) {
|
||||
goto out;
|
||||
}
|
||||
|
||||
c = curl_easy_setopt(curl,
|
||||
CURLOPT_LOCALPORTRANGE,
|
||||
opts.local_port_end - opts.local_port_start);
|
||||
c = curl_easy_setopt(curl, CURLOPT_URL, opts.urls[i]);
|
||||
if (c) {
|
||||
fprintf(stderr,
|
||||
"curl_easy_setopt(CURLOPT_LOCALPORTRANGE) failed\n");
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_URL) failed\n");
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
|
||||
if (opts.insecure) {
|
||||
c = curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 0);
|
||||
c = curl_easy_perform(curl);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_SSL_VERIFYPEER) failed\n");
|
||||
fprintf(stderr, "curl_easy_perform() failed\n");
|
||||
goto out;
|
||||
}
|
||||
c = curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 0);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_SSL_VERIFYHOST) failed\n");
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
|
||||
c = curl_easy_setopt(curl, CURLOPT_URL, opts.url);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_setopt(CURLOPT_URL) failed\n");
|
||||
goto out;
|
||||
}
|
||||
|
||||
c = curl_easy_perform(curl);
|
||||
if (c) {
|
||||
fprintf(stderr, "curl_easy_perform() failed\n");
|
||||
goto out;
|
||||
/* Re-use the curl handle. */
|
||||
curl_easy_reset(curl);
|
||||
}
|
||||
|
||||
c = 0;
|
||||
|
||||
+28
-21
@@ -6,6 +6,7 @@ import asyncio
|
||||
import logging
|
||||
import subprocess
|
||||
import tempfile
|
||||
from typing import List
|
||||
|
||||
import yaml
|
||||
import dpkt
|
||||
@@ -124,7 +125,10 @@ class TestImpersonation:
|
||||
# This ensures we will capture the correct traffic in tcpdump.
|
||||
LOCAL_PORTS = (50000, 50100)
|
||||
|
||||
TEST_URL = "https://www.wikipedia.org"
|
||||
TEST_URLS = [
|
||||
"https://www.wikimedia.org",
|
||||
"https://www.wikipedia.org"
|
||||
]
|
||||
|
||||
# List of binaries and their expected signatures
|
||||
CURL_BINARIES_AND_SIGNATURES = [
|
||||
@@ -330,13 +334,13 @@ class TestImpersonation:
|
||||
elif sys.platform.startswith("darwin"):
|
||||
env_vars["DYLD_INSERT_LIBRARIES"] = lib + ".dylib"
|
||||
|
||||
def _run_curl(self, curl_binary, env_vars, extra_args, url,
|
||||
def _run_curl(self, curl_binary, env_vars, extra_args, urls,
|
||||
output="/dev/null"):
|
||||
env = os.environ.copy()
|
||||
if env_vars:
|
||||
env.update(env_vars)
|
||||
|
||||
logging.debug(f"Launching '{curl_binary}' to {url}")
|
||||
logging.debug(f"Launching '{curl_binary}' to {urls}")
|
||||
if env_vars:
|
||||
logging.debug("Environment variables: {}".format(
|
||||
" ".join([f"{k}={v}" for k, v in env_vars.items()])))
|
||||
@@ -348,17 +352,18 @@ class TestImpersonation:
|
||||
]
|
||||
if extra_args:
|
||||
args += extra_args
|
||||
args.append(url)
|
||||
args.extend(urls)
|
||||
|
||||
curl = subprocess.Popen(args, env=env)
|
||||
return curl.wait(timeout=10)
|
||||
|
||||
def _extract_client_hello(self, pcap: bytes) -> bytes:
|
||||
def _extract_client_hello(self, pcap: bytes) -> List[bytes]:
|
||||
"""Find and return the Client Hello TLS record from a pcap.
|
||||
|
||||
If there are multiple, returns the first.
|
||||
If there are none, returns None.
|
||||
"""
|
||||
client_hellos = []
|
||||
for ts, buf in dpkt.pcap.Reader(io.BytesIO(pcap)):
|
||||
eth = dpkt.ethernet.Ethernet(buf)
|
||||
if not isinstance(eth.data, dpkt.ip.IP) and not isinstance(eth.data, dpkt.ip6.IP6):
|
||||
@@ -380,9 +385,9 @@ class TestImpersonation:
|
||||
if handshake.type != 0x01:
|
||||
continue
|
||||
# Return the whole TLS record
|
||||
return tcp.data
|
||||
client_hellos.append(tcp.data)
|
||||
|
||||
return None
|
||||
return client_hellos
|
||||
|
||||
def _parse_nghttpd2_output(self, output):
|
||||
"""Parse the output of nghttpd2.
|
||||
@@ -456,7 +461,7 @@ class TestImpersonation:
|
||||
ret = self._run_curl(curl_binary,
|
||||
env_vars=env_vars,
|
||||
extra_args=None,
|
||||
url=self.TEST_URL)
|
||||
urls=self.TEST_URLS)
|
||||
assert ret == 0
|
||||
|
||||
try:
|
||||
@@ -474,21 +479,23 @@ class TestImpersonation:
|
||||
assert len(pcap) > 0
|
||||
logging.debug(f"Captured pcap of length {len(pcap)} bytes")
|
||||
|
||||
client_hello = self._extract_client_hello(pcap)
|
||||
assert client_hello is not None
|
||||
client_hellos = self._extract_client_hello(pcap)
|
||||
# A client hello message for each URL
|
||||
assert len(client_hellos) == len(self.TEST_URLS)
|
||||
|
||||
logging.debug(f"Found Client Hello, "
|
||||
logging.debug(f"Found {len(client_hellos)} Client Hello messages, "
|
||||
f"comparing to signature '{expected_signature}'")
|
||||
|
||||
sig = TLSClientHelloSignature.from_bytes(client_hello)
|
||||
expected_sig = TLSClientHelloSignature.from_dict(
|
||||
browser_signatures[expected_signature] \
|
||||
["signature"] \
|
||||
["tls_client_hello"]
|
||||
)
|
||||
for client_hello in client_hellos:
|
||||
sig = TLSClientHelloSignature.from_bytes(client_hello)
|
||||
expected_sig = TLSClientHelloSignature.from_dict(
|
||||
browser_signatures[expected_signature] \
|
||||
["signature"] \
|
||||
["tls_client_hello"]
|
||||
)
|
||||
|
||||
equals, msg = sig.equals(expected_sig, reason=True)
|
||||
assert equals, msg
|
||||
equals, msg = sig.equals(expected_sig, reason=True)
|
||||
assert equals, msg
|
||||
|
||||
@pytest.mark.asyncio
|
||||
@pytest.mark.parametrize(
|
||||
@@ -520,7 +527,7 @@ class TestImpersonation:
|
||||
ret = self._run_curl(curl_binary,
|
||||
env_vars=env_vars,
|
||||
extra_args=["-k"],
|
||||
url="https://localhost:8443")
|
||||
urls=["https://localhost:8443"])
|
||||
assert ret == 0
|
||||
|
||||
output = await self._read_proc_output(nghttpd, timeout=2)
|
||||
@@ -575,7 +582,7 @@ class TestImpersonation:
|
||||
ret = self._run_curl(curl_binary,
|
||||
env_vars=env_vars,
|
||||
extra_args=None,
|
||||
url=self.TEST_URL,
|
||||
urls=[self.TEST_URLS[0]],
|
||||
output=output)
|
||||
assert ret == 0
|
||||
|
||||
|
||||
Reference in New Issue
Block a user