262 lines
8.5 KiB
C
262 lines
8.5 KiB
C
#include "mbedtls/platform.h"
|
|
#include "mbedtls/build_info.h"
|
|
#include "mbedtls/net_sockets.h"
|
|
#include "mbedtls/ssl.h"
|
|
#include "mbedtls/debug.h"
|
|
#include "mbedtls/error.h"
|
|
#include "mbedtls/x509_crt.h"
|
|
|
|
#include <string.h>
|
|
#include <stdio.h>
|
|
#include <unistd.h>
|
|
#include <ctype.h>
|
|
|
|
#define SERVER_PORT "443"
|
|
#define SERVER_NAME "en.wikipedia.org"
|
|
#define GET_REQUEST_SEARCH "GET /w/api.php?action=query&list=search&srsearch=Operating%20systems&format=json HTTP/1.1\r\n" \
|
|
"Host: en.wikipedia.org\r\n" \
|
|
"User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36\r\n" \
|
|
"Accept: application/json\r\n" \
|
|
"Accept-Language: en-US,en;q=0.9\r\n" \
|
|
"Accept-Encoding: identity\r\n" \
|
|
"Connection: close\r\n\r\n"
|
|
|
|
#define GET_REQUEST_EXTRACT "GET /w/api.php?action=query&prop=extracts&exintro&explaintext&titles=One%20Piece&format=json HTTP/1.1\r\n" \
|
|
"Host: en.wikipedia.org\r\n" \
|
|
"User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36\r\n" \
|
|
"Accept: application/json\r\n" \
|
|
"Accept-Language: en-US,en;q=0.9\r\n" \
|
|
"Accept-Encoding: identity\r\n" \
|
|
"Connection: close\r\n\r\n"
|
|
|
|
#define GET_REQUEST_PAGEIMAGE "GET /w/api.php?action=query&prop=pageimages&titles=Cat&pithumbsize=500&format=json HTTP/1.1\r\n" \
|
|
"Host: en.wikipedia.org\r\n" \
|
|
"User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36\r\n" \
|
|
"Accept: application/json\r\n" \
|
|
"Accept-Language: en-US,en;q=0.9\r\n" \
|
|
"Accept-Encoding: identity\r\n" \
|
|
"Connection: close\r\n\r\n"
|
|
|
|
#define DEBUG_LEVEL 0
|
|
#define CA_CERT_PATH "/etc/ssl/certs/ca-certificates.crt" // most distros use this path for CA certs, adjust if needed
|
|
|
|
static void my_debug(void *ctx, int level,
|
|
const char *file, int line, const char *str)
|
|
{
|
|
((void) level);
|
|
mbedtls_fprintf((FILE *) ctx, "%s:%04d: %s", file, line, str);
|
|
fflush((FILE *) ctx);
|
|
}
|
|
|
|
static int response_handler(mbedtls_ssl_context *ssl, unsigned char *buf,
|
|
ssize_t initial_bytes)
|
|
{
|
|
ssize_t bytes_read = initial_bytes;
|
|
int total_bytes = initial_bytes;
|
|
|
|
buf[bytes_read] = '\0';
|
|
|
|
char *body_start = strstr((char *)buf, "\r\n\r\n");
|
|
if (body_start) {
|
|
body_start += 4;
|
|
mbedtls_printf("%.*s\n", (int)(body_start - (char *)buf - 4), (char *)buf);
|
|
mbedtls_printf("\n--- Response Body ---\n%s\n", body_start);
|
|
} else {
|
|
mbedtls_printf("%s", (char *)buf);
|
|
}
|
|
|
|
|
|
while ((bytes_read = mbedtls_ssl_read(ssl, buf, 8192 - 1)) > 0) {
|
|
buf[bytes_read] = '\0';
|
|
char *start = (char *)buf;
|
|
|
|
|
|
if (isxdigit(buf[0]) && strchr((char *)buf, '\r')) {
|
|
char *newline = strchr((char *)buf, '\n');
|
|
if (newline) {
|
|
start = newline + 1;
|
|
if (start[0] == '\r') start++;
|
|
}
|
|
}
|
|
|
|
if (bytes_read > 2 && buf[0] != '0') {
|
|
mbedtls_printf("%s", start);
|
|
}
|
|
|
|
total_bytes += bytes_read;
|
|
}
|
|
|
|
mbedtls_printf("\n\nReceived %d bytes\n\n", total_bytes);
|
|
return total_bytes;
|
|
}
|
|
|
|
int main(void) {
|
|
int ret;
|
|
ssize_t bytes_read;
|
|
unsigned char buf[8192];
|
|
|
|
mbedtls_net_context server_fd;
|
|
mbedtls_ssl_context ssl;
|
|
mbedtls_ssl_config conf;
|
|
// mbedtls_x509_crt cacert;
|
|
|
|
mbedtls_printf("Initializing TLS structures...");
|
|
fflush(stdout);
|
|
|
|
mbedtls_net_init(&server_fd);
|
|
mbedtls_ssl_init(&ssl);
|
|
mbedtls_ssl_config_init(&conf);
|
|
// mbedtls_x509_crt_init(&cacert);
|
|
|
|
mbedtls_printf(" ok\n");
|
|
|
|
mbedtls_printf("Initializing PSA Crypto...");
|
|
fflush(stdout);
|
|
|
|
psa_status_t psa_status = psa_crypto_init();
|
|
if (psa_status != PSA_SUCCESS) {
|
|
mbedtls_printf(" failed\n ! psa_crypto_init failed: %d\n\n", (int)psa_status);
|
|
ret = -1;
|
|
goto exit;
|
|
}
|
|
|
|
mbedtls_printf(" ok\n");
|
|
|
|
mbedtls_printf("Connecting to %s:%s...", SERVER_NAME, SERVER_PORT);
|
|
fflush(stdout);
|
|
|
|
if ((ret = mbedtls_net_connect(&server_fd, SERVER_NAME,
|
|
SERVER_PORT, MBEDTLS_NET_PROTO_TCP)) != 0) {
|
|
mbedtls_printf(" failed\n ! mbedtls_net_connect returned -0x%x\n\n", -ret);
|
|
goto exit;
|
|
}
|
|
|
|
if ((ret = mbedtls_net_set_block(&server_fd)) != 0) {
|
|
mbedtls_printf(" failed\n ! mbedtls_net_set_block returned %d\n\n", ret);
|
|
goto exit;
|
|
}
|
|
|
|
mbedtls_printf(" ok\n");
|
|
|
|
mbedtls_printf("Configuring SSL/TLS...");
|
|
fflush(stdout);
|
|
|
|
if ((ret = mbedtls_ssl_config_defaults(&conf,
|
|
MBEDTLS_SSL_IS_CLIENT,
|
|
MBEDTLS_SSL_TRANSPORT_STREAM,
|
|
MBEDTLS_SSL_PRESET_DEFAULT)) != 0) {
|
|
mbedtls_printf(" failed\n ! mbedtls_ssl_config_defaults returned %d\n\n", ret);
|
|
goto exit;
|
|
}
|
|
|
|
// mbedtls_printf("Loading CA certificate from %s...", CA_CERT_PATH);
|
|
// fflush(stdout);
|
|
|
|
// ret = mbedtls_x509_crt_parse_file(&cacert, CA_CERT_PATH);
|
|
// if (ret != 0) {
|
|
// mbedtls_printf(" failed\n ! mbedtls_x509_crt_parse_file returned -0x%x\n", -ret);
|
|
// goto exit;
|
|
// }
|
|
// mbedtls_printf(" ok\n");
|
|
|
|
|
|
// mbedtls_ssl_conf_ca_chain(&conf, &cacert, NULL);
|
|
// mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_REQUIRED);
|
|
|
|
mbedtls_ssl_conf_authmode(&conf, MBEDTLS_SSL_VERIFY_NONE); // not good for prod
|
|
|
|
mbedtls_debug_set_threshold(DEBUG_LEVEL);
|
|
mbedtls_ssl_conf_dbg(&conf, my_debug, stdout);
|
|
|
|
mbedtls_printf(" ok\n");
|
|
|
|
mbedtls_printf("Setting up SSL context...");
|
|
fflush(stdout);
|
|
|
|
if ((ret = mbedtls_ssl_setup(&ssl, &conf)) != 0) {
|
|
mbedtls_printf(" failed\n ! mbedtls_ssl_setup returned %d\n\n", ret);
|
|
goto exit;
|
|
}
|
|
|
|
if ((ret = mbedtls_ssl_set_hostname(&ssl, SERVER_NAME)) != 0) {
|
|
mbedtls_printf(" failed\n ! mbedtls_ssl_set_hostname returned %d\n\n", ret);
|
|
goto exit;
|
|
}
|
|
|
|
mbedtls_printf(" ok\n");
|
|
|
|
mbedtls_printf("Binding socket to TLS...");
|
|
fflush(stdout);
|
|
|
|
mbedtls_ssl_set_bio(&ssl, &server_fd, mbedtls_net_send, mbedtls_net_recv, NULL);
|
|
|
|
mbedtls_printf(" ok\n");
|
|
|
|
mbedtls_printf("Performing TLS handshake...");
|
|
fflush(stdout);
|
|
|
|
while ((ret = mbedtls_ssl_handshake(&ssl)) != 0) {
|
|
if (ret != MBEDTLS_ERR_SSL_WANT_READ && ret != MBEDTLS_ERR_SSL_WANT_WRITE) {
|
|
mbedtls_printf(" failed\n ! mbedtls_ssl_handshake returned -0x%x\n\n", -ret);
|
|
goto exit;
|
|
}
|
|
}
|
|
|
|
mbedtls_printf(" ok\n");
|
|
mbedtls_printf(" TLS version: %s\n", mbedtls_ssl_get_version(&ssl));
|
|
mbedtls_printf(" Cipher: %s\n\n", mbedtls_ssl_get_ciphersuite(&ssl));
|
|
|
|
mbedtls_printf("Sending HTTP request...");
|
|
fflush(stdout);
|
|
|
|
size_t request_len = strlen(GET_REQUEST_EXTRACT);
|
|
if ((ret = mbedtls_ssl_write(&ssl, (const unsigned char*)GET_REQUEST_EXTRACT, request_len)) < 0) {
|
|
mbedtls_printf(" failed\n ! mbedtls_ssl_write returned %d\n\n", ret);
|
|
goto exit;
|
|
}
|
|
|
|
mbedtls_printf(" ok (%d bytes)\n\n", ret);
|
|
|
|
mbedtls_printf("Receiving response...\n");
|
|
|
|
bytes_read = mbedtls_ssl_read(&ssl, buf, sizeof(buf) - 1);
|
|
|
|
if (bytes_read > 0) {
|
|
response_handler(&ssl, buf, bytes_read);
|
|
|
|
} else if (bytes_read < 0) {
|
|
mbedtls_printf("Server delay detected, retrying with timeouts...\n");
|
|
|
|
for (int timeout_ms = 100; timeout_ms <= 5000; timeout_ms *= 2) {
|
|
mbedtls_printf(" Trying %dms timeout...", timeout_ms);
|
|
fflush(stdout);
|
|
|
|
bytes_read = mbedtls_ssl_read(&ssl, buf, sizeof(buf) - 1);
|
|
if (bytes_read > 0) {
|
|
mbedtls_printf(" SUCCESS!\n\n");
|
|
response_handler(&ssl, buf, bytes_read);
|
|
goto exit;
|
|
}
|
|
}
|
|
|
|
mbedtls_printf(" FAILED\n");
|
|
mbedtls_printf("\nError: Server did not respond\n");
|
|
} else {
|
|
mbedtls_printf("\nConnection closed by server\n");
|
|
}
|
|
|
|
exit:
|
|
mbedtls_printf("Closing TLS connection...");
|
|
fflush(stdout);
|
|
|
|
mbedtls_ssl_close_notify(&ssl);
|
|
mbedtls_net_free(&server_fd);
|
|
mbedtls_ssl_free(&ssl);
|
|
mbedtls_ssl_config_free(&conf);
|
|
// mbedtls_x509_crt_free(&cacert);
|
|
|
|
mbedtls_printf(" ok\n\n");
|
|
|
|
return ret;
|
|
}
|