From ffeede9b39c8d269766fd56d02eb7e78d8d13bb2 Mon Sep 17 00:00:00 2001 From: Ivaylo Popov Date: Mon, 27 May 2013 23:09:42 -0400 Subject: [PATCH] Use lsof instead of pfctl to find target host on OSX in transparent mode. --- libmproxy/platform/{pf.py => lsof.py} | 9 +++++---- libmproxy/platform/osx.py | 8 ++++---- 2 files changed, 9 insertions(+), 8 deletions(-) rename libmproxy/platform/{pf.py => lsof.py} (68%) diff --git a/libmproxy/platform/pf.py b/libmproxy/platform/lsof.py similarity index 68% rename from libmproxy/platform/pf.py rename to libmproxy/platform/lsof.py index 062d33113..25c0e33f4 100644 --- a/libmproxy/platform/pf.py +++ b/libmproxy/platform/lsof.py @@ -1,3 +1,4 @@ +import re def lookup(address, port, s): """ @@ -8,9 +9,9 @@ def lookup(address, port, s): """ spec = "%s:%s"%(address, port) for i in s.split("\n"): - if "ESTABLISHED:ESTABLISHED" in i and spec in i: - s = i.split() - if len(s) > 4: - s = s[4].split(":") + if "ESTABLISHED" in i and spec in i: + m = re.match(".* (\S*)->%s" % spec, i) + if m: + s = m.group(1).split(":") if len(s) == 2: return s[0], int(s[1]) diff --git a/libmproxy/platform/osx.py b/libmproxy/platform/osx.py index dda5d9afc..1a474e946 100644 --- a/libmproxy/platform/osx.py +++ b/libmproxy/platform/osx.py @@ -1,16 +1,16 @@ import subprocess -import pf +import lsof """ Doing this the "right" way by using DIOCNATLOOK on the pf device turns out to be a pain. Apple has made a number of modifications to the data structures returned, and compiling userspace tools to test and work with - this turns out to be a pain in the ass. Parsing pfctl output is short, + this turns out to be a pain in the ass. Parsing lsof output is short, simple, and works. """ class Resolver: - STATECMD = ("sudo", "-n", "/sbin/pfctl", "-s", "state") + STATECMD = ("sudo", "-n", "/usr/sbin/lsof", "-n", "-P", "-i", "TCP") def __init__(self): pass @@ -20,4 +20,4 @@ class Resolver: stxt = subprocess.check_output(self.STATECMD, stderr=subprocess.STDOUT) except subprocess.CalledProcessError: return None - return pf.lookup(peer[0], peer[1], stxt) + return lsof.lookup(peer[0], peer[1], stxt)