Netfilter内核态修改TTL
#myhook.c
#include <linux/kernel.h>
#include <linux/module.h>
#include <linux/ip.h>
#include <linux/tcp.h>
#include <linux/udp.h>
#include <linux/icmp.h>
#include <asm/atomic.h>
#include <linux/version.h>
#include <linux/skbuff.h>
#include <linux/netfilter.h>
#include <linux/netfilter_ipv4.h>
#include <linux/moduleparam.h>
#include <linux/netfilter_ipv4/ip_tables.h>
#include <linux/netfilter_bridge.h>
MODULE_LICENSE("GPL");
MODULE_AUTHOR("zhanghc");
MODULE_DESCRIPTION("Myhook");
#define CHECKSUM_HW 1 /* 由硬件计算报头和首部的校验和 */
static int pktcnt = 0;
//我们自己定义的hook回调函数
static unsigned int myhook_func(unsigned int hooknum, struct sk_buff *skb, const struct net_device *in, const struct net_device *out, int (*okfn)(struct sk_buff *))
{
struct iphdr *iph=ip_hdr(skb);
struct icmphdr *icmph;
int i=0;
int header=0;
int index=0;
unsigned char *data=NULL;
int length=0;
if(likely(iph->protocol==IPPROTO_ICMP))
{
icmph=icmp_hdr(skb);
data=skb->data+iph->ihl*4+sizeof(struct icmphdr);
header=iph->ihl*4+sizeof(struct icmphdr);
length=ntohs(iph->tot_len)-iph->ihl*4-sizeof(struct icmphdr);
if(skb->len-header>0)
{
if(skb->data_len!=0)
{
if(skb_linearize(skb))
{
return NF_DROP;
}
}
//修改TTL值
iph->ttl=255;
iph->check=0;
//重新计算校验和
iph->check=ip_fast_csum((unsigned char*)iph, iph->ihl);
}
}
return NF_ACCEPT;
}
static struct nf_hook_ops nfho =
{
.hook=(nf_hookfn *)myhook_func, //回调函数是myhook_func
.pf=PF_INET, //协议类型
.hooknum=NF_BR_POST_ROUTING,//挂载点
.priority=NF_IP_PRI_FIRST,//优先级
};
static int __init myhook_init(void)
{
return nf_register_hook(&nfho);
}
static void __exit myhook_fini(void)
{
nf_unregister_hook(&nfho);
}
module_init(myhook_init);
module_exit(myhook_fini);
#Makefile
obj-m := myhook.o
all:
$(MAKE) -C /lib/modules/$(shell uname -r)/build M=$(PWD) modules
clean:
$(MAKE) -C /lib/modules/$(shell uname -r)/build M=$(PWD) clean