2015-09-07 11:12:31 -04:00
|
|
|
// Package socks contains protocol definition and io lib for SOCKS5 protocol
|
|
|
|
package socks
|
|
|
|
|
|
|
|
import (
|
2015-09-07 16:26:37 -04:00
|
|
|
"encoding/binary"
|
2015-09-07 11:16:30 -04:00
|
|
|
"fmt"
|
|
|
|
"io"
|
2015-09-07 11:12:31 -04:00
|
|
|
)
|
|
|
|
|
|
|
|
const (
|
2015-09-07 11:16:30 -04:00
|
|
|
socksVersion = uint8(5)
|
2015-09-09 06:13:52 -04:00
|
|
|
|
|
|
|
AuthNotRequired = byte(0x00)
|
|
|
|
AuthGssApi = byte(0x01)
|
|
|
|
AuthUserPass = byte(0x02)
|
2015-09-07 11:12:31 -04:00
|
|
|
)
|
|
|
|
|
|
|
|
// Authentication request header of Socks5 protocol
|
|
|
|
type Socks5AuthenticationRequest struct {
|
2015-09-07 11:16:30 -04:00
|
|
|
version byte
|
2015-09-07 16:26:37 -04:00
|
|
|
nMethods byte
|
2015-09-07 11:16:30 -04:00
|
|
|
authMethods [256]byte
|
2015-09-07 11:12:31 -04:00
|
|
|
}
|
|
|
|
|
2015-09-09 06:13:52 -04:00
|
|
|
func (request *Socks5AuthenticationRequest) HasAuthMethod(method byte) bool {
|
|
|
|
for i := byte(0); i < request.nMethods; i++ {
|
|
|
|
if request.authMethods[i] == method {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
2015-09-07 11:12:31 -04:00
|
|
|
func ReadAuthentication(reader io.Reader) (auth Socks5AuthenticationRequest, err error) {
|
2015-09-07 11:16:30 -04:00
|
|
|
buffer := make([]byte, 2)
|
|
|
|
nBytes, err := reader.Read(buffer)
|
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
if nBytes < 2 {
|
|
|
|
err = fmt.Errorf("Expected 2 bytes read, but actaully %d bytes read", nBytes)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
auth.version = buffer[0]
|
|
|
|
if auth.version != socksVersion {
|
|
|
|
err = fmt.Errorf("Unknown SOCKS version %d", auth.version)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2015-09-07 16:26:37 -04:00
|
|
|
auth.nMethods = buffer[1]
|
|
|
|
if auth.nMethods <= 0 {
|
2015-09-07 11:16:30 -04:00
|
|
|
err = fmt.Errorf("Zero length of authentication methods")
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2015-09-07 16:26:37 -04:00
|
|
|
buffer = make([]byte, auth.nMethods)
|
2015-09-07 11:16:30 -04:00
|
|
|
nBytes, err = reader.Read(buffer)
|
2015-09-07 16:26:37 -04:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
if nBytes != int(auth.nMethods) {
|
|
|
|
err = fmt.Errorf("Unmatching number of auth methods, expecting %d, but got %d", auth.nMethods, nBytes)
|
|
|
|
return
|
|
|
|
}
|
2015-09-07 11:16:30 -04:00
|
|
|
copy(auth.authMethods[:nBytes], buffer)
|
|
|
|
return
|
2015-09-07 11:12:31 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
type Socks5AuthenticationResponse struct {
|
2015-09-07 11:16:30 -04:00
|
|
|
version byte
|
|
|
|
authMethod byte
|
2015-09-07 11:12:31 -04:00
|
|
|
}
|
|
|
|
|
2015-09-09 06:13:52 -04:00
|
|
|
func NewAuthenticationResponse(authMethod byte) *Socks5AuthenticationResponse {
|
|
|
|
response := new(Socks5AuthenticationResponse)
|
|
|
|
response.version = socksVersion
|
|
|
|
response.authMethod = authMethod
|
|
|
|
return response
|
|
|
|
}
|
|
|
|
|
2015-09-07 11:12:31 -04:00
|
|
|
func (r *Socks5AuthenticationResponse) ToBytes() []byte {
|
2015-09-07 11:16:30 -04:00
|
|
|
buffer := make([]byte, 2 /* size of Socks5AuthenticationResponse */)
|
|
|
|
buffer[0] = r.version
|
|
|
|
buffer[1] = r.authMethod
|
|
|
|
return buffer
|
2015-09-07 11:12:31 -04:00
|
|
|
}
|
|
|
|
|
2015-09-09 06:13:52 -04:00
|
|
|
func WriteAuthentication(writer io.Writer, response *Socks5AuthenticationResponse) error {
|
2015-09-07 11:16:30 -04:00
|
|
|
_, err := writer.Write(response.ToBytes())
|
2015-09-08 07:18:55 -04:00
|
|
|
return err
|
2015-09-07 11:12:31 -04:00
|
|
|
}
|
2015-09-07 16:26:37 -04:00
|
|
|
|
2015-09-08 07:18:55 -04:00
|
|
|
const (
|
|
|
|
AddrTypeIPv4 = byte(0x01)
|
|
|
|
AddrTypeIPv6 = byte(0x04)
|
|
|
|
AddrTypeDomain = byte(0x03)
|
2015-09-09 06:13:52 -04:00
|
|
|
|
|
|
|
CmdConnect = byte(0x01)
|
|
|
|
CmdBind = byte(0x02)
|
|
|
|
CmdUdpAssociate = byte(0x03)
|
2015-09-08 07:18:55 -04:00
|
|
|
)
|
|
|
|
|
2015-09-07 16:26:37 -04:00
|
|
|
type Socks5Request struct {
|
2015-09-09 06:13:52 -04:00
|
|
|
Version byte
|
|
|
|
Command byte
|
|
|
|
AddrType byte
|
|
|
|
IPv4 [4]byte
|
|
|
|
Domain string
|
|
|
|
IPv6 [16]byte
|
|
|
|
Port uint16
|
2015-09-07 16:26:37 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
func ReadRequest(reader io.Reader) (request *Socks5Request, err error) {
|
|
|
|
request = new(Socks5Request)
|
|
|
|
buffer := make([]byte, 4)
|
|
|
|
nBytes, err := reader.Read(buffer)
|
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
if nBytes < len(buffer) {
|
|
|
|
err = fmt.Errorf("Unable to read request.")
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2015-09-09 06:13:52 -04:00
|
|
|
request.Version = buffer[0]
|
|
|
|
request.Command = buffer[1]
|
2015-09-07 16:26:37 -04:00
|
|
|
// buffer[2] is a reserved field
|
2015-09-09 06:13:52 -04:00
|
|
|
request.AddrType = buffer[3]
|
|
|
|
switch request.AddrType {
|
2015-09-07 16:26:37 -04:00
|
|
|
case 0x01:
|
2015-09-09 06:13:52 -04:00
|
|
|
nBytes, err = reader.Read(request.IPv4[:])
|
2015-09-07 16:26:37 -04:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
if nBytes != 4 {
|
|
|
|
err = fmt.Errorf("Unable to read IPv4 address.")
|
|
|
|
return
|
|
|
|
}
|
|
|
|
case 0x03:
|
|
|
|
buffer = make([]byte, 257)
|
|
|
|
nBytes, err = reader.Read(buffer)
|
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
domainLength := buffer[0]
|
|
|
|
if nBytes != int(domainLength)+1 {
|
|
|
|
err = fmt.Errorf("Unable to read domain")
|
|
|
|
return
|
|
|
|
}
|
2015-09-09 06:13:52 -04:00
|
|
|
request.Domain = string(buffer[1 : domainLength+1])
|
2015-09-07 16:26:37 -04:00
|
|
|
case 0x04:
|
2015-09-09 06:13:52 -04:00
|
|
|
nBytes, err = reader.Read(request.IPv6[:])
|
2015-09-07 16:26:37 -04:00
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
if nBytes != 16 {
|
|
|
|
err = fmt.Errorf("Unable to read IPv4 address.")
|
|
|
|
return
|
|
|
|
}
|
|
|
|
default:
|
2015-09-09 06:13:52 -04:00
|
|
|
err = fmt.Errorf("Unexpected address type %d", request.AddrType)
|
2015-09-07 16:26:37 -04:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
buffer = make([]byte, 2)
|
|
|
|
nBytes, err = reader.Read(buffer)
|
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
if nBytes != 2 {
|
|
|
|
err = fmt.Errorf("Unable to read port.")
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2015-09-09 06:13:52 -04:00
|
|
|
request.Port = binary.BigEndian.Uint16(buffer)
|
2015-09-07 16:26:37 -04:00
|
|
|
return
|
|
|
|
}
|
2015-09-08 07:18:55 -04:00
|
|
|
|
|
|
|
const (
|
|
|
|
ErrorSuccess = byte(0x00)
|
|
|
|
ErrorGeneralFailure = byte(0x01)
|
|
|
|
ErrorConnectionNotAllowed = byte(0x02)
|
|
|
|
ErrorNetworkUnreachable = byte(0x03)
|
|
|
|
ErrorHostUnUnreachable = byte(0x04)
|
|
|
|
ErrorConnectionRefused = byte(0x05)
|
|
|
|
ErrorTTLExpired = byte(0x06)
|
|
|
|
ErrorCommandNotSupported = byte(0x07)
|
|
|
|
ErrorAddressTypeNotSupported = byte(0x08)
|
|
|
|
)
|
|
|
|
|
|
|
|
type Socks5Response struct {
|
|
|
|
Version byte
|
|
|
|
Error byte
|
|
|
|
AddrType byte
|
|
|
|
IPv4 [4]byte
|
|
|
|
Domain string
|
|
|
|
IPv6 [16]byte
|
|
|
|
Port uint16
|
|
|
|
}
|
|
|
|
|
2015-09-09 06:13:52 -04:00
|
|
|
func NewSocks5Response() *Socks5Response {
|
|
|
|
response := new(Socks5Response)
|
|
|
|
response.Version = socksVersion
|
|
|
|
return response
|
|
|
|
}
|
|
|
|
|
|
|
|
func (r *Socks5Response) SetIPv4(ipv4 []byte) {
|
|
|
|
r.AddrType = AddrTypeIPv4
|
|
|
|
copy(r.IPv4[:], ipv4)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (r *Socks5Response) SetIPv6(ipv6 []byte) {
|
|
|
|
r.AddrType = AddrTypeIPv6
|
|
|
|
copy(r.IPv6[:], ipv6)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (r *Socks5Response) SetDomain(domain string) {
|
|
|
|
r.AddrType = AddrTypeDomain
|
|
|
|
r.Domain = domain
|
|
|
|
}
|
|
|
|
|
|
|
|
func (r *Socks5Response) toBytes() []byte {
|
2015-09-08 07:18:55 -04:00
|
|
|
buffer := make([]byte, 0, 300)
|
|
|
|
buffer = append(buffer, r.Version)
|
|
|
|
buffer = append(buffer, r.Error)
|
|
|
|
buffer = append(buffer, 0x00) // reserved
|
|
|
|
buffer = append(buffer, r.AddrType)
|
|
|
|
switch r.AddrType {
|
|
|
|
case 0x01:
|
|
|
|
buffer = append(buffer, r.IPv4[:]...)
|
|
|
|
case 0x03:
|
|
|
|
buffer = append(buffer, byte(len(r.Domain)))
|
|
|
|
buffer = append(buffer, []byte(r.Domain)...)
|
|
|
|
case 0x04:
|
|
|
|
buffer = append(buffer, r.IPv6[:]...)
|
|
|
|
}
|
|
|
|
portBuffer := make([]byte, 2)
|
|
|
|
binary.BigEndian.PutUint16(portBuffer, r.Port)
|
|
|
|
buffer = append(buffer, portBuffer...)
|
|
|
|
return buffer
|
|
|
|
}
|
|
|
|
|
2015-09-09 06:13:52 -04:00
|
|
|
func WriteResponse(writer io.Writer, response *Socks5Response) error {
|
2015-09-08 07:18:55 -04:00
|
|
|
_, err := writer.Write(response.toBytes())
|
|
|
|
return err
|
|
|
|
}
|