porthack.c 2.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139
  1. #include <sys/types.h>
  2. #include <sys/socket.h>
  3. #include <sys/un.h>
  4. #include <netinet/in.h>
  5. #include <arpa/inet.h>
  6. #include <sys/time.h>
  7. #include <sys/uio.h>
  8. #include <unistd.h>
  9. #include <string.h>
  10. #include <stdio.h>
  11. #include <stdlib.h>
  12. #include <errno.h>
  13. #include <android/log.h>
  14. #define LOG_TAG "hostage: p"
  15. #define LOGI(...) __android_log_print(ANDROID_LOG_INFO,LOG_TAG,__VA_ARGS__)
  16. #define LOGW(...) __android_log_print(ANDROID_LOG_WARN,LOG_TAG,__VA_ARGS__)
  17. #define LOGE(...) __android_log_print(ANDROID_LOG_ERROR,LOG_TAG,__VA_ARGS__)
  18. #define CONTROLLEN CMSG_LEN(sizeof(int))
  19. char *socket_path = "\0hostage";
  20. int ipc_sock() {
  21. int fd;
  22. struct sockaddr_un addr;
  23. if ((fd = socket(AF_UNIX, SOCK_STREAM, 0)) == -1) {
  24. LOGE("Unable to create local socket: %d", errno);
  25. return -1;
  26. }
  27. memset(&addr, 0, sizeof(addr));
  28. addr.sun_family = AF_UNIX;
  29. strncpy(addr.sun_path, socket_path, sizeof(addr.sun_path) - 1);
  30. if (connect(fd, (struct sockaddr*) &addr, sizeof(addr)) == -1) {
  31. LOGE("Unable to connect local socket: %d", errno);
  32. return -1;
  33. }
  34. return fd;
  35. }
  36. int net_sock(int port) {
  37. int fd;
  38. struct sockaddr_in addr;
  39. if ((fd = socket(AF_INET, SOCK_STREAM, 0)) == -1) {
  40. LOGE("Unable to create net socket: %d", errno);
  41. return -1;
  42. }
  43. memset(&addr, 0, sizeof(addr));
  44. addr.sin_family = AF_INET;
  45. addr.sin_addr.s_addr = INADDR_ANY;
  46. addr.sin_port = htons(port);
  47. if (bind(fd, (struct sockaddr *) &addr, sizeof(addr)) == -1) {
  48. LOGE("Unable to bind net socket: %d", errno);
  49. return -1;
  50. }
  51. if (listen(fd, 5) == -1) {
  52. LOGE("Unable to listen net socket: %d", errno);
  53. return -1;
  54. }
  55. return fd;
  56. }
  57. int send_fd(int fd, int fd_to_send) {
  58. struct iovec iov[1];
  59. struct cmsghdr *cmptr;
  60. struct msghdr msg;
  61. char buf[2] = "FD";
  62. iov[0].iov_base = buf;
  63. iov[0].iov_len = 2;
  64. cmptr = malloc(CONTROLLEN);
  65. cmptr->cmsg_level = SOL_SOCKET;
  66. cmptr->cmsg_type = SCM_RIGHTS;
  67. cmptr->cmsg_len = CONTROLLEN;
  68. msg.msg_iov = iov;
  69. msg.msg_iovlen = 1;
  70. msg.msg_name = NULL;
  71. msg.msg_namelen = 0;
  72. msg.msg_control = cmptr;
  73. msg.msg_controllen = CONTROLLEN;
  74. *(int *) CMSG_DATA(cmptr) = fd_to_send;
  75. if (sendmsg(fd, &msg, 0) == -1) {
  76. LOGE("sendmsg failed: %d", errno);
  77. }
  78. return 0;
  79. }
  80. int main(int argc, char *argv[]) {
  81. int port;
  82. int ipc_fd, net_fd;
  83. if (argc < 2) {
  84. exit(EXIT_FAILURE);
  85. }
  86. if ((port = atoi(argv[1])) < 1 || (port = atoi(argv[1])) > 65535) {
  87. exit(EXIT_FAILURE);
  88. }
  89. if ((ipc_fd = ipc_sock()) == -1) {
  90. close(ipc_fd);
  91. exit(EXIT_FAILURE);
  92. }
  93. LOGI("ipc_fd: %d", ipc_fd);
  94. if ((net_fd = net_sock(port)) == -1) {
  95. close(ipc_fd);
  96. close(net_fd);
  97. exit(EXIT_FAILURE);
  98. }
  99. LOGI("net_fd: %d", net_fd);
  100. int status;
  101. status = send_fd(ipc_fd, net_fd);
  102. LOGI("send_fd: %d", status);
  103. close(ipc_fd);
  104. close(net_fd);
  105. if (status == -1) {
  106. return (EXIT_FAILURE);
  107. }
  108. return EXIT_SUCCESS;
  109. }