[RELEASE] Step 1!!! NbIDS(2)
Hi everyone, remember that a long time ago I asked a question about how to read local port numbers? (Here)
I've done some research and I finaly have the first part of my IDS finished, so I thought it'd be nice if I'd released it here
But before I release the code let me explain some things
Overloading
Often you'll find that a function you wish to use uses other data types or uses the data you supplie in another way then you need
There's a way around this problem, and it's called Overloading
Say you have a function that looks like this:
But instead of using int's you want to use values of type double, you could just create another function, with another name. But what if this function is one of the standard libs?
So you're just going to overload the function!
Which is done like this:
Now if you call the function like this:
Now if you call it with type double the compiler will automaticly deside which of the functions to use based on it's parameter list, these list differ from each other in their types so the compiler can distinguish one from another
Summary:
You'd use overloading instead of using templates when overloading operators or Functions found in one of the Standard Library's or other important sources
You can have two functions with the same name, as long as their parameter lists have different data types
The compiler destinguishes two functions from one another when:
The number of parameters for each function is different
The number of parameters is the same, but at least one pair of corresponding parameters has different types
Headers used:
winsock2.h
iphlpapi.h
Library's used:
Standard library's used:
Namspaces used:
Source
Main.h
Main.cpp
On to step 2
Ok so now I've completed step 1, I'm going for step 2, I want to check on data flying in and out my system and prefroming scans on these chuncks of data, if you've any links to theory, source or tutorials on this topic please post them Thanks in advance
-SCHiM
I've done some research and I finaly have the first part of my IDS finished, so I thought it'd be nice if I'd released it here
But before I release the code let me explain some things
Overloading
Often you'll find that a function you wish to use uses other data types or uses the data you supplie in another way then you need
There's a way around this problem, and it's called Overloading
Say you have a function that looks like this:
Code:
int add(int a, int b){
return a + b;
}
So you're just going to overload the function!
Which is done like this:
Code:
int add(int a, int b){
return a + b;
}
double add(double a, double b){
return a + b;
}
Code:
int i = ( int x = 2, int z = 1 ) // the compiler choses to use the int version of add since it uses integer parameters (which are suplied here)
Summary:
You'd use overloading instead of using templates when overloading operators or Functions found in one of the Standard Library's or other important sources
You can have two functions with the same name, as long as their parameter lists have different data types
The compiler destinguishes two functions from one another when:
The number of parameters for each function is different
The number of parameters is the same, but at least one pair of corresponding parameters has different types
Headers used:
winsock2.h
iphlpapi.h
Library's used:
iphlpapi.lib
Standard library's used:
iostream
Namspaces used:
std
Source
Main.h
Code:
#pragma comment "Main.h" #include <iostream> #include <winsock2.h> #include <iphlpapi.h> #pragma comment(lib, "iphlpapi.lib") using namespace std;
Code:
#include "Main.h"
int GetTable() {
DWORD size = 0;
DWORD extdreturn = GetExtendedTcpTable(NULL, &size, TRUE, AF_INET, TCP_TABLE_OWNER_PID_ALL, NULL); //If a wrong buffer size is provided (DWORD size = 0) the value returned to this buffer equals the size of the current TCP structure
//we now know the table size so we can use that to create a new stucture containing all the information we need without hard-coding the structure size
PMIB_TCPTABLE_OWNER_PID NewTcpTable = (PMIB_TCPTABLE_OWNER_PID) new char[size]; // Dynamicly allocate a PMIB_TCPTABLE_OWNER_PID array with the obtained pTcpTable structere size
//We use a char for this because a char is exactly one byte big in memory so the array wil have exactly the right size (if we were using an integer for example the size of the array would be: size * 4 because an integer is 4 bytes long)
extdreturn = GetExtendedTcpTable(NewTcpTable, &size, TRUE, AF_INET, TCP_TABLE_OWNER_PID_ALL, NULL); //copy pTcpTable to a pTcpTable called table
if (extdreturn != NO_ERROR) { // Check for errors
cerr << "Error in GetTable: "<<extdreturn<< endl; // if errors spit them out
}
return (int)NewTcpTable; //return the table structure
}
ostream& operator<<(ostream& out, const in_addr& RoLIP) { // overloading the << operator, if the compiler sees that '<<' tries to output in_addr (the parameter) it choses this overloaded function/operator as the one to be executed
out << ( int)RoLIP.S_un.S_un_b.s_b1 << '.' // print the first 3 numbers of a ip addres and a '.'
<< ( int)RoLIP.S_un.S_un_b.s_b2 << '.' // the second 3 numbers and a '.'
<< ( int)RoLIP.S_un.S_un_b.s_b3 << '.' // the third 3 numbers and a '.'
<< ( int)RoLIP.S_un.S_un_b.s_b4; // the last 3 numbers
return out; //return execution
}
ostream& operator<<(ostream& out, const MIB_TCPROW_OWNER_PID& table) { //overloading the << operator again, if the compiler sees that '<<' tries to output MIB_TCPROW_OWNER_PID (the parameter) it choses this overloaded function/operator as the one to executed
out << "state: " << table.dwState << endl; //cout the size of a connection (listening, bound, waiting, etc, etc for more info look up on: port states)
in_addr LocalIp, RemoteIp; // Declare 2 in_addr types (used for IPv4 addresses in socket programming and stuff like that)
LocalIp.S_un.S_addr = table.dwLocalAddr; // initialize the local ip addres with our table addr
RemoteIp.S_un.S_addr = table.dwRemoteAddr; // do the same with the remote ip address
out << "local: " << LocalIp << ":" << table.dwLocalPort << endl; //print the local ip and local port numbers, remember the printing of the local ip is done in the other overloaded function
out << "remote: " << RemoteIp << ":" << table.dwRemotePort << endl; // do the same for the remote ip and port numbers
out << "Owner: " << table.dwOwningPid << endl; // print the Process id of the process owning the connection
return out; //return exectution
}
int main(){
DWORD NewTSize = 0; // Using the same trick as before to get the table size
MIB_TCPTABLE_OWNER_PID *IP4Tables; // declare our pTCPtable
IP4Tables = (MIB_TCPTABLE_OWNER_PID *)GetTable(); // initilize our Table->table
cout<<"There are: " << IP4Tables->dwNumEntries <<" Connections"<< endl << endl; //Tell the user all connections
DWORD Stat = GetExtendedTcpTable(IP4Tables, &NewTSize, TRUE, AF_INET, TCP_TABLE_OWNER_PID_ALL, NULL); //Shove all data to the TPCTABLE IP4Tables
if (Stat == ERROR_INVALID_PARAMETER ) { // Check for errors
cerr << "Error in Main: "<<Stat<< endl; // if there are errors spit them out
}
for(int i = 0; i != IP4Tables->dwNumEntries; i++){ // loop through all entries
cout << IP4Tables->table[i] << endl; //spit them out using our overloaded operators (<< was overloaded remember?)
}
ZeroMemory((void *)IP4Tables, sizeof(IP4Tables)); //When we're done change all data to '0'
delete[] IP4Tables; // delte the buffer
cin.ignore(); // wait for imput and then close
}
Ok so now I've completed step 1, I'm going for step 2, I want to check on data flying in and out my system and prefroming scans on these chuncks of data, if you've any links to theory, source or tutorials on this topic please post them Thanks in advance
-SCHiM



) just like you'd do it inside a dll