4 |
|
|
5 |
use strict; |
use strict; |
6 |
use POSIX; |
use POSIX; |
7 |
use IO::Socket::SSL; |
use IO::Socket::SSL qw(debug3); |
8 |
|
$Net::SSLeay::trace = 4; |
9 |
use Getopt::Long; |
use Getopt::Long; |
10 |
|
use Time::HiRes qw(time); |
11 |
|
|
12 |
|
my $laddr = "127.0.0.1"; |
13 |
|
my $lport = 8080; |
14 |
|
my $raddr = "127.0.0.1"; |
15 |
|
my $rport = 80; |
16 |
|
my $logdir = "$laddr:$lport-$raddr:$rport"; |
17 |
|
|
|
my $localport; |
|
|
my $localaddr; |
|
18 |
my $help; |
my $help; |
|
my $host; |
|
|
my $port; |
|
19 |
my $daemon; |
my $daemon; |
20 |
my $buffersize = 2048; |
my $buffersize = 2048; |
21 |
my $logtype; |
my $logtype; |
|
my $logdir; |
|
22 |
my $daemon; |
my $daemon; |
23 |
my $serverkey; |
my $serverkey = "$logdir/ssl.key"; |
24 |
my $servercert; |
my $servercert = "$logdir/ssl.cert"; |
25 |
my $serverdh; |
my $serverdh; |
26 |
|
|
27 |
$| = 1; |
$| = 1; |
28 |
|
|
29 |
my $goresult = GetOptions( |
my $goresult = GetOptions( |
30 |
"lport=i" => \$localport, |
"lport=i" => \$lport, |
31 |
"laddr=s" => \$localaddr, |
"laddr=s" => \$laddr, |
32 |
"rport=i" => \$port, |
"rport=i" => \$rport, |
33 |
"raddr=s" => \$host, |
"raddr=s" => \$raddr, |
34 |
"logtype=i" => \$logtype, |
"logtype=i" => \$logtype, |
35 |
"logdir=s" => \$logdir, |
"logdir=s" => \$logdir, |
36 |
"daemon" => \$daemon, |
"daemon" => \$daemon, |
62 |
exit; |
exit; |
63 |
} |
} |
64 |
|
|
65 |
# set default values |
mkdir $logdir; |
66 |
$localport = 8080 unless ($localport); |
|
67 |
$localaddr = "127.0.0.1" unless ($localaddr); |
system "openssl req -new -x509 -days 365 -nodes -out $servercert -keyout $serverkey" |
68 |
$port = 80 unless ($port); |
if ! -e $serverkey && ! -e $servercert; |
69 |
$host = "127.0.0.1" unless ($host); |
|
|
$logdir = "." unless ($logdir); |
|
|
|
|
|
my %o = ( |
|
|
'dir' => $logdir, |
|
|
'port' => $localport, |
|
|
'toport' => $port, |
|
|
'tohost' => $host |
|
|
); |
|
70 |
|
|
71 |
if ($daemon) { |
if ($daemon) { |
72 |
my $pid = fork; |
my $pid = fork; |
76 |
} |
} |
77 |
|
|
78 |
my $ah = IO::Socket::SSL->new( |
my $ah = IO::Socket::SSL->new( |
79 |
'LocalPort' => $localport, |
'LocalPort' => $lport, |
80 |
'LocalAddr' => $localaddr, |
'LocalAddr' => $laddr, |
81 |
'Reuse' => 1, |
'Reuse' => 1, |
82 |
'Proto' => 'tcp', |
'Proto' => 'tcp', |
83 |
'SSL_verify_mode' => '0', |
'SSL_verify_mode' => '0', |
84 |
'SSLdhfile' => $serverdh, |
'SSLdhfile' => $serverdh, |
85 |
'SSL_cert_file' => $servercert, |
'SSL_cert_file' => $servercert, |
86 |
'SSL_key_file' => $serverkey, |
'SSL_key_file' => $serverkey, |
87 |
'Listen' => 10 |
'Listen' => 10, |
88 |
|
# 'SSL_version' => 'SSLv3', # SSLv3, SSLv2, TLSv1 |
89 |
|
# 'SSL_cipher_list' => 'RC4-MD5', |
90 |
) || die "$!"; |
) || die "$!"; |
91 |
|
|
92 |
$SIG{'CHLD'} = 'IGNORE'; |
$SIG{'CHLD'} = 'IGNORE'; |
105 |
if ( !defined($pid) ) { print STDERR "cannot fork while(1) $!\n"; } |
if ( !defined($pid) ) { print STDERR "cannot fork while(1) $!\n"; } |
106 |
elsif ( $pid == 0 ) { |
elsif ( $pid == 0 ) { |
107 |
$ah->close( SSL_no_shutdown => 1 ); |
$ah->close( SSL_no_shutdown => 1 ); |
108 |
Run( \%o, $ch, $num ); |
Run( $ch, $num ); |
109 |
} else { |
} else { |
110 |
$ch->close( SSL_no_shutdown => 1 ); |
$ch->close( SSL_no_shutdown => 1 ); |
111 |
} |
} |
112 |
} |
} |
113 |
|
|
114 |
sub Run { |
sub Run { |
115 |
my ( $o, $ch, $num ) = @_; |
my ( $ch, $num ) = @_; |
116 |
my $th = IO::Socket::SSL->new( |
my $th = IO::Socket::SSL->new( |
117 |
'PeerAddr' => $o->{'tohost'}, |
'PeerAddr' => $raddr, |
118 |
'PeerPort' => $o->{'toport'}, |
'PeerPort' => $rport, |
119 |
'SSL_use_cert' => '0', |
# 'SSL_use_cert' => '0', |
120 |
'SSL_verify_mode' => '0', |
# 'SSL_verify_mode' => '0', |
121 |
|
|
|
# 'SSL_cipher_list' => 'NUL:LOW:EXP:ADH', |
|
122 |
'SSL_version' => 'SSLv3', # SSLv3, SSLv2, TLSv1 |
'SSL_version' => 'SSLv3', # SSLv3, SSLv2, TLSv1 |
123 |
|
'SSL_cipher_list' => 'RC4-MD5', |
124 |
'Proto' => 'tcp' |
'Proto' => 'tcp' |
125 |
); |
); |
126 |
if ( !$th ) { print "cannot connect th: $!"; exit 0; } |
if ( !$th ) { print "cannot connect $raddr:$rport th: $!"; exit 0; } |
127 |
else { print "connected!"; } |
else { print "connected to $raddr:$rport\n"; } |
128 |
my $fh; |
my $fh; |
129 |
if ( $o->{'dir'} ) { |
if ( -d $logdir ) { |
130 |
$fh = Symbol::gensym(); |
$fh = Symbol::gensym(); |
131 |
open( $fh, ">$o->{'dir'}/tunnel$num.log" ) or die "$!"; |
my $path = $logdir . Time::HiRes::time(); |
132 |
|
open( $fh, '>', $path ) or die "$!"; |
133 |
} |
} |
134 |
$ch->autoflush(); |
$ch->autoflush(); |
135 |
$th->autoflush(); |
$th->autoflush(); |