I was about to show some new employees how to use raw sockets in C. When preparing for materials, I came across this code by Silver Moon on www.binarytides.com:

Warning: 300+ lines
#include<stdio.h>	//For standard things
#include<stdlib.h>	//malloc
#include<string.h>	//strlen

#include<netinet/ip_icmp.h>	//Provides declarations for icmp header
#include<netinet/udp.h>	//Provides declarations for udp header
#include<netinet/tcp.h>	//Provides declarations for tcp header
#include<netinet/ip.h>	//Provides declarations for ip header
#include<netinet/if_ether.h>	//For ETH_P_ALL
#include<net/ethernet.h>	//For ether_header

void ProcessPacket(unsigned char* , int);
void print_ip_header(unsigned char* , int);
void print_tcp_packet(unsigned char * , int );
void print_udp_packet(unsigned char * , int );
void print_icmp_packet(unsigned char* , int );
void PrintData (unsigned char* , int);

FILE *logfile;
struct sockaddr_in source,dest;
int tcp=0,udp=0,icmp=0,others=0,igmp=0,total=0,i,j;	

int main()
	int saddr_size , data_size;
	struct sockaddr saddr;
	unsigned char *buffer = (unsigned char *) malloc(65536); //Its Big!
		printf("Unable to create log.txt file.");
	int sock_raw = socket( AF_PACKET , SOCK_RAW , htons(ETH_P_ALL)) ;
	//setsockopt(sock_raw , SOL_SOCKET , SO_BINDTODEVICE , "eth0" , strlen("eth0")+ 1 );
	if(sock_raw < 0)
		//Print the error with proper message
		perror("Socket Error");
		return 1;
		saddr_size = sizeof saddr;
		//Receive a packet
		data_size = recvfrom(sock_raw , buffer , 65536 , 0 , &saddr , (socklen_t*)&saddr_size);
		if(data_size <0 )
			printf("Recvfrom error , failed to get packets\n");
			return 1;
		//Now process the packet
		ProcessPacket(buffer , data_size);
	return 0;

void ProcessPacket(unsigned char* buffer, int size)
	//Get the IP Header part of this packet , excluding the ethernet header
	struct iphdr *iph = (struct iphdr*)(buffer + sizeof(struct ethhdr));
	switch (iph->protocol) //Check the Protocol and do accordingly...
		case 1:  //ICMP Protocol
			print_icmp_packet( buffer , size);
		case 2:  //IGMP Protocol
		case 6:  //TCP Protocol
			print_tcp_packet(buffer , size);
		case 17: //UDP Protocol
			print_udp_packet(buffer , size);
		default: //Some Other Protocol like ARP etc.
	printf("TCP : %d   UDP : %d   ICMP : %d   IGMP : %d   Others : %d   Total : %d\r", tcp , udp , icmp , igmp , others , total);

void print_ethernet_header(unsigned char* Buffer, int Size)
	struct ethhdr *eth = (struct ethhdr *)Buffer;
	fprintf(logfile , "\n");
	fprintf(logfile , "Ethernet Header\n");
	fprintf(logfile , "   |-Destination Address : %.2X-%.2X-%.2X-%.2X-%.2X-%.2X \n", eth->h_dest[0] , eth->h_dest[1] , eth->h_dest[2] , eth->h_dest[3] , eth->h_dest[4] , eth->h_dest[5] );
	fprintf(logfile , "   |-Source Address      : %.2X-%.2X-%.2X-%.2X-%.2X-%.2X \n", eth->h_source[0] , eth->h_source[1] , eth->h_source[2] , eth->h_source[3] , eth->h_source[4] , eth->h_source[5] );
	fprintf(logfile , "   |-Protocol            : %u \n",(unsigned short)eth->h_proto);

void print_ip_header(unsigned char* Buffer, int Size)
	print_ethernet_header(Buffer , Size);
	unsigned short iphdrlen;
	struct iphdr *iph = (struct iphdr *)(Buffer  + sizeof(struct ethhdr) );
	iphdrlen =iph->ihl*4;
	memset(&source, 0, sizeof(source));
	source.sin_addr.s_addr = iph->saddr;
	memset(&dest, 0, sizeof(dest));
	dest.sin_addr.s_addr = iph->daddr;
	fprintf(logfile , "\n");
	fprintf(logfile , "IP Header\n");
	fprintf(logfile , "   |-IP Version        : %d\n",(unsigned int)iph->version);
	fprintf(logfile , "   |-IP Header Length  : %d DWORDS or %d Bytes\n",(unsigned int)iph->ihl,((unsigned int)(iph->ihl))*4);
	fprintf(logfile , "   |-Type Of Service   : %d\n",(unsigned int)iph->tos);
	fprintf(logfile , "   |-IP Total Length   : %d  Bytes(Size of Packet)\n",ntohs(iph->tot_len));
	fprintf(logfile , "   |-Identification    : %d\n",ntohs(iph->id));
	//fprintf(logfile , "   |-Reserved ZERO Field   : %d\n",(unsigned int)iphdr->ip_reserved_zero);
	//fprintf(logfile , "   |-Dont Fragment Field   : %d\n",(unsigned int)iphdr->ip_dont_fragment);
	//fprintf(logfile , "   |-More Fragment Field   : %d\n",(unsigned int)iphdr->ip_more_fragment);
	fprintf(logfile , "   |-TTL      : %d\n",(unsigned int)iph->ttl);
	fprintf(logfile , "   |-Protocol : %d\n",(unsigned int)iph->protocol);
	fprintf(logfile , "   |-Checksum : %d\n",ntohs(iph->check));
	fprintf(logfile , "   |-Source IP        : %s\n",inet_ntoa(source.sin_addr));
	fprintf(logfile , "   |-Destination IP   : %s\n",inet_ntoa(dest.sin_addr));

void print_tcp_packet(unsigned char* Buffer, int Size)
	unsigned short iphdrlen;
	struct iphdr *iph = (struct iphdr *)( Buffer  + sizeof(struct ethhdr) );
	iphdrlen = iph->ihl*4;
	struct tcphdr *tcph=(struct tcphdr*)(Buffer + iphdrlen + sizeof(struct ethhdr));
	int header_size =  sizeof(struct ethhdr) + iphdrlen + tcph->doff*4;
	fprintf(logfile , "\n\n***********************TCP Packet*************************\n");	
	fprintf(logfile , "\n");
	fprintf(logfile , "TCP Header\n");
	fprintf(logfile , "   |-Source Port      : %u\n",ntohs(tcph->source));
	fprintf(logfile , "   |-Destination Port : %u\n",ntohs(tcph->dest));
	fprintf(logfile , "   |-Sequence Number    : %u\n",ntohl(tcph->seq));
	fprintf(logfile , "   |-Acknowledge Number : %u\n",ntohl(tcph->ack_seq));
	fprintf(logfile , "   |-Header Length      : %d DWORDS or %d BYTES\n" ,(unsigned int)tcph->doff,(unsigned int)tcph->doff*4);
	//fprintf(logfile , "   |-CWR Flag : %d\n",(unsigned int)tcph->cwr);
	//fprintf(logfile , "   |-ECN Flag : %d\n",(unsigned int)tcph->ece);
	fprintf(logfile , "   |-Urgent Flag          : %d\n",(unsigned int)tcph->urg);
	fprintf(logfile , "   |-Acknowledgement Flag : %d\n",(unsigned int)tcph->ack);
	fprintf(logfile , "   |-Push Flag            : %d\n",(unsigned int)tcph->psh);
	fprintf(logfile , "   |-Reset Flag           : %d\n",(unsigned int)tcph->rst);
	fprintf(logfile , "   |-Synchronise Flag     : %d\n",(unsigned int)tcph->syn);
	fprintf(logfile , "   |-Finish Flag          : %d\n",(unsigned int)tcph->fin);
	fprintf(logfile , "   |-Window         : %d\n",ntohs(tcph->window));
	fprintf(logfile , "   |-Checksum       : %d\n",ntohs(tcph->check));
	fprintf(logfile , "   |-Urgent Pointer : %d\n",tcph->urg_ptr);
	fprintf(logfile , "\n");
	fprintf(logfile , "                        DATA Dump                         ");
	fprintf(logfile , "\n");
	fprintf(logfile , "IP Header\n");
	fprintf(logfile , "TCP Header\n");
	fprintf(logfile , "Data Payload\n");	
	PrintData(Buffer + header_size , Size - header_size );
	fprintf(logfile , "\n###########################################################");

void print_udp_packet(unsigned char *Buffer , int Size)
	unsigned short iphdrlen;
	struct iphdr *iph = (struct iphdr *)(Buffer +  sizeof(struct ethhdr));
	iphdrlen = iph->ihl*4;
	struct udphdr *udph = (struct udphdr*)(Buffer + iphdrlen  + sizeof(struct ethhdr));
	int header_size =  sizeof(struct ethhdr) + iphdrlen + sizeof udph;
	fprintf(logfile , "\n\n***********************UDP Packet*************************\n");
	fprintf(logfile , "\nUDP Header\n");
	fprintf(logfile , "   |-Source Port      : %d\n" , ntohs(udph->source));
	fprintf(logfile , "   |-Destination Port : %d\n" , ntohs(udph->dest));
	fprintf(logfile , "   |-UDP Length       : %d\n" , ntohs(udph->len));
	fprintf(logfile , "   |-UDP Checksum     : %d\n" , ntohs(udph->check));
	fprintf(logfile , "\n");
	fprintf(logfile , "IP Header\n");
	PrintData(Buffer , iphdrlen);
	fprintf(logfile , "UDP Header\n");
	PrintData(Buffer+iphdrlen , sizeof udph);
	fprintf(logfile , "Data Payload\n");	
	//Move the pointer ahead and reduce the size of string
	PrintData(Buffer + header_size , Size - header_size);
	fprintf(logfile , "\n###########################################################");

void print_icmp_packet(unsigned char* Buffer , int Size)
	unsigned short iphdrlen;
	struct iphdr *iph = (struct iphdr *)(Buffer  + sizeof(struct ethhdr));
	iphdrlen = iph->ihl * 4;
	struct icmphdr *icmph = (struct icmphdr *)(Buffer + iphdrlen  + sizeof(struct ethhdr));
	int header_size =  sizeof(struct ethhdr) + iphdrlen + sizeof icmph;
	fprintf(logfile , "\n\n***********************ICMP Packet*************************\n");	
	print_ip_header(Buffer , Size);
	fprintf(logfile , "\n");
	fprintf(logfile , "ICMP Header\n");
	fprintf(logfile , "   |-Type : %d",(unsigned int)(icmph->type));
	if((unsigned int)(icmph->type) == 11)
		fprintf(logfile , "  (TTL Expired)\n");
	else if((unsigned int)(icmph->type) == ICMP_ECHOREPLY)
		fprintf(logfile , "  (ICMP Echo Reply)\n");
	fprintf(logfile , "   |-Code : %d\n",(unsigned int)(icmph->code));
	fprintf(logfile , "   |-Checksum : %d\n",ntohs(icmph->checksum));
	//fprintf(logfile , "   |-ID       : %d\n",ntohs(icmph->id));
	//fprintf(logfile , "   |-Sequence : %d\n",ntohs(icmph->sequence));
	fprintf(logfile , "\n");

	fprintf(logfile , "IP Header\n");
	fprintf(logfile , "UDP Header\n");
	PrintData(Buffer + iphdrlen , sizeof icmph);
	fprintf(logfile , "Data Payload\n");	
	//Move the pointer ahead and reduce the size of string
	PrintData(Buffer + header_size , (Size - header_size) );
	fprintf(logfile , "\n###########################################################");

void PrintData (unsigned char* data , int Size)
	int i , j;
	for(i=0 ; i < Size ; i++)
		if( i!=0 && i%16==0)   //if one line of hex printing is complete...
			fprintf(logfile , "         ");
			for(j=i-16 ; j<i ; j++)
				if(data[j]>=32 && data[j]<=128)
					fprintf(logfile , "%c",(unsigned char)data[j]); //if its a number or alphabet
				else fprintf(logfile , "."); //otherwise print a dot
			fprintf(logfile , "\n");
		if(i%16==0) fprintf(logfile , "   ");
			fprintf(logfile , " %02X",(unsigned int)data[i]);
		if( i==Size-1)  //print the last spaces
			  fprintf(logfile , "   "); //extra spaces
			fprintf(logfile , "         ");
			for(j=i-i%16 ; j<=i ; j++)
				if(data[j]>=32 && data[j]<=128) 
				  fprintf(logfile , "%c",(unsigned char)data[j]);
				  fprintf(logfile , ".");
			fprintf(logfile ,  "\n" );

The code does exactly what’s expected. I’ve in fact studied another code snippet by the same author, albeit written in Python, so I should be familiar with everything I see here(at least that’s what I thought),untill I saw the following:

void ProcessPacket(unsigned char* buffer, int size)
	//Get the IP Header part of this packet , excluding the ethernet header
	struct iphdr *iph = (struct iphdr*)(buffer + sizeof(struct ethhdr));

Here buffer points to the raw data received from the socket, which is a byte array. We then moved the pointer to the right of sizeof(struct ethhdr) bytes, and cast it to a pointer of struct iphdr* type. Everything seems normal, right? Well, not if you account for struct alignment in C.

I won’t go into details about struct alignment in C, other than pointing you to The Lost Art of Structure Packing. Maybe a small example.

// A program to print the nth byte of p
void PrintByteAsChar(void* p, int n){
    printf("The %dth byte is %c\n", n, ((unsigned char*)p)[n]);

struct Dummy{
    char a;
    int b;
    char c;

#include <stdio.h>
int main(){
    char buffer[20] = "abbbbc";
    struct Dummy* p = (struct Dummy*)buffer;
    for(int i=0; i<6; i++){
        PrintByteAsChar(p, i);  // You can see abbbbc as its first 6 bytes

    printf("%c\n", p->c);   // Ha! This prints nothing!
    printf("%lu\n", sizeof(struct Dummy));     // 12!
    return 0;

As you can see here, casting to a struct could be dangerous. Why is the aforementioned code working properly then? To find out, I looked into the header files defined in /user/include/netinet/ip.h, and found the following definition.

struct iphdr {
    #if defined(__LITTLE_ENDIAN_BITFIELD)
        __u8    ihl:4,
    #elif defined (__BIG_ENDIAN_BITFIELD)
        __u8    version:4,
        #error  "Please fix <asm/byteorder.h>"
         __u8   tos;
         __u16  tot_len;
         __u16  id;
         __u16  frag_off;
         __u8   ttl;
         __u8   protocol;
         __u16  check;
         __u32  saddr;
         __u32  daddr;
         /*The options start here. */

To my surprise, there is no #pragma pack anywhere. That means casting to the structure is potentially dangerous. But how? I was completely lost, untill a colleague reminded me that the fileds in IP header are already perfectly aligned by design, with paddings included as part of the protocol. A pictures helps illustrate the idea.

IP Header

I’ve always wondered why the order of subfields in a protocol is a bit random, turns out this is why.