Menu ▾ ▴

#8 unhide-tcp lists all ports in ss as "hidden" because of a pattern matching issue

v1.0_(example)
open
nobody
None
5
2020-01-18
2020-01-11
Hoot
No

I'm running Archlinux.
With iproute2-5.4.0-1 and later, unhide-tcp lists all open ports as hidden (regardless of whether ss shows them).
With iproute2-5.3.0-2 and earlier this doesn't happen.

This doesn't happen when I employ -n to use netstat, and it appears to be because the sed script at unhide-tcp.c:73-74 doesn't yield a newline when isolating the port number. My best reckoning says this is likeley because of https://git.kernel.org/pub/scm/network/iproute2/iproute2.git/commit/misc/ss.c?id=5883c6eba5173745eeb4e5467c59dd34d415bd7e

Steps to reproduce:
Using iproute2-5.4.0-1 or later open some UDP or TCP connections through a method of your choosing, then run unhide-tcp, it prints all those connections as hidden.

Other details:
While I have only tested arch, it's likely that this affects any system with iproute2-5.4.0-1 or later.
Arch bug report: https://bugs.archlinux.org/task/64712

Discussion

  • Hoot

    Hoot - 2020-01-11

    It's also important that I've been using unhide 20130526-3 for all testing.

     
  • Patrick G.

    Patrick G. - 2020-01-18

    Hi Hoot,
    Thanks for reporting.
    I also discovered two weeks ago that ss has changed its output (unneeded spaces added at end of lines).
    It's maybe due to the commit you indicate, as the process header is added even if not asked to. It could be that all the process column is added.
    It's already corrected in my own version.
    I will try to make a new version of unhide in the coming weeks but no promise :)

    In the meantime, if you're not afraid by builds :), you can replace the routine checkoneport() in unhide-tcp.c by this one:

     #define STR_PORT_LENGTH  6   // with ending null char
    int checkoneport(int port, char command[], enum Proto proto)
    {
       int ok = 0;
    
       FILE *fich_tmp ;
    
       if (NULL != (fich_tmp=popen (command, "r")))
       {
          char ports[2 * STR_PORT_LENGTH];    // port number reported by ss or netstat
          char compare[2 * STR_PORT_LENGTH];  // port number to verify.
          char *port_p ;
    
          sprintf(compare,"%i",port);
          while ((NULL != fgets(ports, 2 * STR_PORT_LENGTH - 2, fich_tmp)) && ok == 0) {
             ports[2 * STR_PORT_LENGTH - 1] = 0 ;   // force string terminaison
             port_p = ports + strlen(ports) ;
             while ((port_p > ports) && !isdigit(*port_p))
             {
                *port_p = 0 ; // replace all non numerical char by end of string !
                port_p--;
             } 
             if (strcmp(ports, compare) == 0) {ok = 1;}
          }
          pclose(fich_tmp);
       }
       else
       {
          die(unlog, "Couldn't execute command : %s while checking port %d", command, port) ;
       }
       return(ok) ;
    }
    

    and compile by using :
    gcc -Wall -O2 --static unhide-tcp.c unhide-tcp-fast.c unhide-output.c -o unhide-tcp

     
  • Hoot

    Hoot - 2020-01-18

    The arch folks were kind enough to add a patch for this in iproute2.

    That patch can be found here:
    https://git.archlinux.org/svntogit/packages.git/diff/trunk/0002-ss-fix-end-of-line-printing.patch?h=packages/iproute2&id=a9936a43c59bd756f0971a0a9c1938239b7425c5

    --but this doesn't seem like a global or long term upstream solution.

    I appreciate that you've made suitable changes to the upstream code for yourself.

    Even though I am no longer experiencing an issue, I'm going to try to test your changes anyway, against both versions of iproute2 (unpatched 5.4.0-1 and patched 5.4.0-2). More information is always good.

    Since you're just replacing the end characters with the NUL character I expect it will work fine.

     

Log in to post a comment.