2012-04-03 18:37:24 +02:00
|
|
|
|
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
struct thread_data
|
|
|
|
rb 1024
|
|
|
|
stack rb 0
|
|
|
|
|
|
|
|
home_dir rb 1024
|
|
|
|
work_dir rb 1024
|
2012-04-10 21:44:51 +02:00
|
|
|
fpath rb 1024*3 ; Will also be used to temporarily store username
|
2012-04-06 20:37:00 +02:00
|
|
|
|
|
|
|
type db ? ; ASCII/EBDIC/IMAGE/..
|
|
|
|
mode db ? ; active/passive
|
|
|
|
socketnum dd ? ; Commands socket
|
|
|
|
state dd ? ; disconnected/logging in/logged in/..
|
|
|
|
passivesocknum dd ? ; when in passive mode, this is the listening socket
|
|
|
|
datasocketnum dd ? ; socket used for data transfers
|
2012-04-10 21:44:51 +02:00
|
|
|
permissions dd ?
|
|
|
|
buffer_ptr dd ?
|
2012-04-06 20:37:00 +02:00
|
|
|
|
|
|
|
datasock sockaddr_in
|
|
|
|
|
|
|
|
buffer rb BUFFERSIZE
|
|
|
|
ends
|
|
|
|
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
macro sendFTP str {
|
|
|
|
local .string, .length, .label
|
|
|
|
xor edi, edi
|
|
|
|
mcall send, [edx + thread_data.socketnum], .string, .length
|
|
|
|
jmp @f
|
|
|
|
.string db str, 13, 10
|
|
|
|
.length = $ - .string
|
|
|
|
@@:
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
;------------------------------------------------
|
|
|
|
; parse_cmd
|
|
|
|
;
|
|
|
|
; Internal function wich uses the 'commands'
|
|
|
|
; table to call an appropriate cmd_xx function.
|
|
|
|
;
|
|
|
|
; input: esi = ptr to ascii commands
|
|
|
|
; ecx = number of bytes input
|
|
|
|
; edx = pointer to thread_data structure
|
|
|
|
;
|
|
|
|
; output: none
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
parse_cmd: ; esi must point to command
|
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
cmp byte [esi], 0x20 ; skip all leading characters
|
|
|
|
ja .ok
|
|
|
|
inc esi
|
|
|
|
dec ecx
|
|
|
|
cmp ecx, 3
|
2012-04-10 21:44:51 +02:00
|
|
|
jb .error
|
|
|
|
jmp parse_cmd
|
2012-04-06 20:37:00 +02:00
|
|
|
.ok:
|
2012-04-03 22:28:26 +02:00
|
|
|
cmp byte [esi+3], 0x20
|
2012-04-10 21:44:51 +02:00
|
|
|
ja @f
|
2012-04-03 22:28:26 +02:00
|
|
|
mov byte [esi+3], 0
|
|
|
|
@@:
|
|
|
|
|
2012-04-03 18:37:24 +02:00
|
|
|
mov eax, [esi]
|
|
|
|
and eax, not 0x20202020 ; convert to upper case
|
|
|
|
mov edi, commands ; list of commands to scan
|
|
|
|
.scanloop:
|
|
|
|
cmp eax, [edi]
|
2012-04-10 21:44:51 +02:00
|
|
|
je .got_it
|
2012-04-03 18:37:24 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
add edi, 4+4*4
|
2012-04-03 18:37:24 +02:00
|
|
|
cmp byte [edi], 0
|
|
|
|
jne .scanloop
|
|
|
|
|
|
|
|
.error:
|
2012-04-10 21:44:51 +02:00
|
|
|
cmp [edx + thread_data.state], STATE_ACTIVE
|
|
|
|
jb login_first
|
|
|
|
sendFTP "500 Unsupported command"
|
2012-04-03 18:37:24 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
.got_it:
|
|
|
|
mov eax, [edx + thread_data.state]
|
|
|
|
jmp dword [edi + 4 + eax]
|
|
|
|
|
2012-04-03 18:37:24 +02:00
|
|
|
|
|
|
|
align 4
|
2012-04-04 15:08:07 +02:00
|
|
|
commands: ; all commands must be in uppercase
|
2012-04-03 18:37:24 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
dd 'ABOR'
|
|
|
|
dd login_first, login_first, login_first, cmdABOR
|
|
|
|
; dd 'ACCT
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_ACCT
|
2012-04-10 21:44:51 +02:00
|
|
|
; dd 'APPE'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_APPE
|
2012-04-10 21:44:51 +02:00
|
|
|
dd 'CDUP'
|
|
|
|
dd login_first, login_first, login_first, cmdCDUP
|
|
|
|
dd 'CWD'
|
|
|
|
dd login_first, login_first, login_first, cmdCWD
|
|
|
|
dd 'DELE'
|
|
|
|
dd login_first, login_first, login_first, cmdDELE
|
|
|
|
; dd 'HELP'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_HELP
|
2012-04-10 21:44:51 +02:00
|
|
|
dd 'LIST'
|
|
|
|
dd login_first, login_first, login_first, cmdLIST
|
|
|
|
; dd 'MDTM'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_MDTM
|
2012-04-10 21:44:51 +02:00
|
|
|
; dd 'MKD'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_MKD
|
2012-04-10 21:44:51 +02:00
|
|
|
; dd 'MODE'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_MODE
|
2012-04-10 21:44:51 +02:00
|
|
|
dd 'NLST'
|
|
|
|
dd login_first, login_first, login_first, cmdNLST
|
|
|
|
dd 'NOOP'
|
|
|
|
dd login_first, login_first, login_first, cmdNOOP
|
|
|
|
dd 'PASS'
|
|
|
|
dd cmdPASS.0, cmdPASS , cmdPASS.2, cmdPASS.3
|
|
|
|
dd 'PASV'
|
|
|
|
dd login_first, login_first, login_first, cmdPASV
|
|
|
|
dd 'PORT'
|
|
|
|
dd login_first, login_first, login_first, cmdPORT
|
|
|
|
dd 'PWD'
|
|
|
|
dd login_first, login_first, login_first, cmdPWD
|
|
|
|
dd 'QUIT'
|
|
|
|
dd cmdQUIT, cmdQUIT, cmdQUIT, cmdQUIT
|
|
|
|
; dd 'REIN'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_REIN
|
2012-04-10 21:44:51 +02:00
|
|
|
; dd 'REST'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_REST
|
2012-04-10 21:44:51 +02:00
|
|
|
dd 'RETR'
|
|
|
|
dd login_first, login_first, login_first, cmdRETR
|
|
|
|
; dd 'RMD'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_RMD
|
2012-04-10 21:44:51 +02:00
|
|
|
; dd 'RNFR'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_RNFR
|
2012-04-10 21:44:51 +02:00
|
|
|
; dd 'RNTO'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_RNTO
|
2012-04-10 21:44:51 +02:00
|
|
|
; dd 'SITE'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_SITE
|
2012-04-10 21:44:51 +02:00
|
|
|
; dd 'SIZE'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_SIZE
|
2012-04-10 21:44:51 +02:00
|
|
|
; dd 'STAT'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_STAT
|
2012-04-10 21:44:51 +02:00
|
|
|
dd 'STOR'
|
|
|
|
dd login_first, login_first, login_first, cmdSTOR
|
|
|
|
; dd 'STOU'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_STOU
|
2012-04-10 21:44:51 +02:00
|
|
|
; dd 'STRU'
|
2012-04-12 11:58:58 +02:00
|
|
|
; dd login_first, login_first, login_first, cmd_STRU
|
2012-04-10 21:44:51 +02:00
|
|
|
dd 'SYST'
|
|
|
|
dd login_first, login_first, login_first, cmdSYST
|
|
|
|
dd 'TYPE'
|
|
|
|
dd login_first, login_first, login_first, cmdTYPE
|
|
|
|
dd 'USER'
|
|
|
|
dd cmdUSER, cmdUSER, cmdUSER, cmdUSER.2
|
|
|
|
db 0 ; end marker
|
2012-04-03 18:37:24 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
align 4
|
|
|
|
login_first:
|
|
|
|
sendFTP "530 Please login with USER and PASS"
|
|
|
|
ret
|
2012-04-03 18:37:24 +02:00
|
|
|
|
|
|
|
align 4
|
2012-04-10 21:44:51 +02:00
|
|
|
permission_denied:
|
|
|
|
sendFTP "550 Permission denied"
|
|
|
|
ret
|
2012-04-03 18:37:24 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
align 4
|
|
|
|
socketerror:
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke con_set_flags, 0x0c
|
|
|
|
invoke con_write_asciiz, str_sockerr
|
|
|
|
invoke con_set_flags, 0x07
|
2012-04-06 20:37:00 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "425 Can't open data connection"
|
2012-04-03 18:37:24 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
align 4
|
|
|
|
abort_transfer:
|
|
|
|
and [edx + thread_data.permissions], not ABORT
|
|
|
|
mov [edx + thread_data.mode], MODE_NOTREADY
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke file.close, ebx
|
2012-04-10 21:44:51 +02:00
|
|
|
mcall close, [edx + thread_data.datasocketnum]
|
2012-04-12 11:58:58 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
mov edx, [ebp]
|
|
|
|
sendFTP "530 Transfer aborted"
|
|
|
|
ret
|
|
|
|
|
|
|
|
align 4
|
|
|
|
ip_to_dword: ; esi = ptr to str, cl = separator ('.', ',')
|
|
|
|
|
|
|
|
call ascii_to_byte
|
2012-04-12 11:58:58 +02:00
|
|
|
mov bl, al
|
2012-04-10 21:44:51 +02:00
|
|
|
cmp byte [esi], cl
|
|
|
|
jne .err
|
2012-04-12 11:58:58 +02:00
|
|
|
inc esi
|
2012-04-10 21:44:51 +02:00
|
|
|
|
|
|
|
call ascii_to_byte
|
|
|
|
mov bh, al
|
|
|
|
cmp byte [esi], cl
|
|
|
|
jne .err
|
2012-04-12 11:58:58 +02:00
|
|
|
inc esi
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
shl ebx, 16
|
|
|
|
|
|
|
|
call ascii_to_byte
|
2012-04-12 11:58:58 +02:00
|
|
|
mov bl, al
|
2012-04-10 21:44:51 +02:00
|
|
|
cmp byte [esi], cl
|
|
|
|
jne .err
|
2012-04-12 11:58:58 +02:00
|
|
|
inc esi
|
2012-04-10 21:44:51 +02:00
|
|
|
|
|
|
|
call ascii_to_byte
|
|
|
|
mov bh, al
|
|
|
|
|
|
|
|
ror ebx, 16
|
|
|
|
ret
|
|
|
|
|
|
|
|
.err:
|
|
|
|
xor ebx, ebx
|
|
|
|
ret
|
|
|
|
|
|
|
|
align 4 ; esi = ptr to str, output in eax
|
|
|
|
ascii_to_byte:
|
|
|
|
|
|
|
|
xor eax, eax
|
|
|
|
push ebx
|
|
|
|
|
|
|
|
.loop:
|
|
|
|
movzx ebx, byte[esi]
|
|
|
|
sub bl, '0'
|
|
|
|
jb .done
|
|
|
|
cmp bl, 9
|
|
|
|
ja .done
|
|
|
|
lea eax, [eax*4 + eax] ;
|
|
|
|
shl eax, 1 ; eax = eax * 10
|
|
|
|
add eax, ebx
|
|
|
|
inc esi
|
|
|
|
|
|
|
|
jmp .loop
|
|
|
|
|
|
|
|
.done:
|
|
|
|
pop ebx
|
|
|
|
ret
|
|
|
|
|
|
|
|
align 4
|
|
|
|
dword_to_ascii: ; edi = ptr where to write, eax is number
|
|
|
|
|
|
|
|
push edx ebx ecx
|
|
|
|
mov ebx, 10
|
|
|
|
xor ecx, ecx
|
|
|
|
|
|
|
|
@@:
|
|
|
|
xor edx, edx
|
|
|
|
div ebx
|
|
|
|
add edx, '0'
|
|
|
|
pushw dx
|
|
|
|
inc ecx
|
|
|
|
test eax, eax
|
|
|
|
jnz @r
|
|
|
|
|
|
|
|
@@:
|
|
|
|
popw ax
|
|
|
|
stosb
|
|
|
|
dec ecx
|
|
|
|
jnz @r
|
|
|
|
|
|
|
|
pop ecx ebx edx
|
|
|
|
ret
|
|
|
|
|
|
|
|
align 4
|
|
|
|
create_path: ; combine home_dir and work_dir strings into fpath
|
|
|
|
|
|
|
|
mov edx, [ebp]
|
|
|
|
lea edi, [edx + thread_data.fpath]
|
|
|
|
lea esi, [edx + thread_data.home_dir]
|
|
|
|
mov ecx, 1024
|
|
|
|
.loop1:
|
|
|
|
lodsb
|
2012-04-12 11:58:58 +02:00
|
|
|
cmp al, 0x20
|
|
|
|
jb .next
|
2012-04-10 21:44:51 +02:00
|
|
|
stosb
|
|
|
|
loop .loop1
|
|
|
|
.next:
|
|
|
|
|
|
|
|
cmp byte[edi-1], '/'
|
|
|
|
jne @f
|
|
|
|
dec edi
|
|
|
|
@@:
|
|
|
|
|
|
|
|
lea esi, [edx + thread_data.work_dir]
|
|
|
|
mov ecx, 1024
|
|
|
|
.loop2:
|
|
|
|
lodsb
|
2012-04-12 11:58:58 +02:00
|
|
|
cmp al, 0x20
|
|
|
|
jb .done
|
2012-04-10 21:44:51 +02:00
|
|
|
stosb
|
|
|
|
loop .loop2
|
|
|
|
|
|
|
|
.done:
|
2012-04-12 11:58:58 +02:00
|
|
|
xor al, al
|
2012-04-10 21:44:51 +02:00
|
|
|
stosb
|
|
|
|
ret
|
|
|
|
|
|
|
|
;------------------------------------------------
|
|
|
|
; "ABOR"
|
|
|
|
;
|
|
|
|
; This command aborts the current filetransfer.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
|
|
|
align 4
|
|
|
|
cmdABOR:
|
|
|
|
|
|
|
|
or [edx + thread_data.permissions], ABORT
|
|
|
|
sendFTP "250 Command succesul"
|
|
|
|
ret
|
|
|
|
|
|
|
|
;------------------------------------------------
|
|
|
|
; "CDUP"
|
|
|
|
;
|
|
|
|
; Change the directory to move up one level.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-05 15:00:39 +02:00
|
|
|
align 4
|
|
|
|
cmdCDUP:
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
test [edx + thread_data.permissions], PERMISSION_CD
|
|
|
|
jz permission_denied
|
|
|
|
|
2012-04-07 20:42:58 +02:00
|
|
|
cmp byte [edx + thread_data.work_dir+1], 0 ; are we in "/" ?
|
2012-04-05 15:00:39 +02:00
|
|
|
je .done
|
|
|
|
|
|
|
|
mov ecx, 1024
|
|
|
|
xor al, al
|
2012-04-07 20:42:58 +02:00
|
|
|
lea edi, [edx + thread_data.work_dir]
|
2012-04-05 15:00:39 +02:00
|
|
|
repne scasb
|
|
|
|
std
|
|
|
|
dec edi
|
2012-04-07 20:42:58 +02:00
|
|
|
dec edi
|
|
|
|
dec edi
|
2012-04-05 15:00:39 +02:00
|
|
|
mov al,'/'
|
2012-04-07 20:42:58 +02:00
|
|
|
repne scasb
|
2012-04-05 15:00:39 +02:00
|
|
|
cld
|
2012-04-07 20:42:58 +02:00
|
|
|
mov byte[edi+1], 0
|
2012-04-05 15:00:39 +02:00
|
|
|
|
|
|
|
.done:
|
2012-04-07 20:42:58 +02:00
|
|
|
; Print the new working dir on the console
|
|
|
|
lea eax, [edx + thread_data.work_dir]
|
|
|
|
push eax
|
|
|
|
call [con_write_asciiz]
|
|
|
|
push str_newline
|
|
|
|
call [con_write_asciiz]
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "250 Command succesul"
|
2012-04-05 15:00:39 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "CWD"
|
|
|
|
;
|
|
|
|
; Change Working Directory.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
2012-04-10 21:44:51 +02:00
|
|
|
cmdCWD:
|
|
|
|
|
|
|
|
test [edx + thread_data.permissions], PERMISSION_CD
|
|
|
|
jz permission_denied
|
2012-04-04 19:19:00 +02:00
|
|
|
|
|
|
|
sub ecx, 4
|
|
|
|
jb .err
|
|
|
|
add esi, 4
|
2012-04-05 15:00:39 +02:00
|
|
|
|
|
|
|
.scan:
|
2012-04-06 20:37:00 +02:00
|
|
|
lea edi, [edx + thread_data.work_dir + 1]
|
|
|
|
push ecx
|
|
|
|
mov ecx, 1024
|
|
|
|
.find_zero:
|
|
|
|
cmp byte [edi], 0
|
|
|
|
je .found_zero
|
|
|
|
inc edi
|
|
|
|
loop .find_zero
|
|
|
|
.found_zero:
|
|
|
|
pop ecx
|
2012-04-07 13:36:00 +02:00
|
|
|
.scan2:
|
2012-04-04 19:19:00 +02:00
|
|
|
|
|
|
|
cmp byte [esi], '/'
|
|
|
|
jne @f
|
|
|
|
inc esi
|
|
|
|
dec ecx
|
|
|
|
jz .done
|
|
|
|
@@:
|
|
|
|
|
|
|
|
.loop:
|
|
|
|
lodsb
|
|
|
|
cmp al, 0x20
|
|
|
|
jb .done
|
2012-04-05 15:00:39 +02:00
|
|
|
cmp al, '.'
|
|
|
|
je .up
|
|
|
|
.continue:
|
2012-04-04 19:19:00 +02:00
|
|
|
stosb
|
|
|
|
loop .loop
|
|
|
|
.done:
|
|
|
|
cmp byte [edi-1], '/'
|
|
|
|
je @f
|
|
|
|
mov byte [edi], '/'
|
|
|
|
inc edi
|
|
|
|
@@:
|
|
|
|
mov byte [edi], 0
|
|
|
|
|
2012-04-07 20:42:58 +02:00
|
|
|
; Print the new working dir on the console
|
|
|
|
lea eax, [edx + thread_data.work_dir]
|
|
|
|
push eax
|
|
|
|
call [con_write_asciiz]
|
|
|
|
push str_newline
|
|
|
|
call [con_write_asciiz]
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "250 Command succesful"
|
2012-04-04 19:19:00 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-05 15:00:39 +02:00
|
|
|
.up:
|
|
|
|
lodsb
|
|
|
|
cmp al, '.'
|
|
|
|
jne .continue
|
|
|
|
|
2012-04-07 13:36:00 +02:00
|
|
|
;;;; TODO: find second last '\' in work_dir and make next char zero
|
|
|
|
;;;; point edi to that 0
|
|
|
|
|
|
|
|
jmp .scan2
|
2012-04-05 15:00:39 +02:00
|
|
|
|
2012-04-04 19:19:00 +02:00
|
|
|
.err:
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "550 Directory does not exist"
|
2012-04-03 18:37:24 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "DELE"
|
|
|
|
;
|
|
|
|
; Delete a file from the server.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
cmdDELE:
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
test [edx + thread_data.permissions], PERMISSION_DELETE
|
|
|
|
jz permission_denied
|
2012-04-03 18:37:24 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
ret
|
2012-04-07 20:42:58 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "LIST"
|
|
|
|
;
|
|
|
|
; List the files in the current working directory.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
cmdLIST:
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
test [edx + thread_data.permissions], PERMISSION_EXEC
|
|
|
|
jz permission_denied
|
|
|
|
|
2012-04-04 19:19:00 +02:00
|
|
|
; If we are in active mode, it's time to open a data socket..
|
2012-04-06 20:37:00 +02:00
|
|
|
cmp [edx + thread_data.mode], MODE_ACTIVE
|
2012-04-04 15:08:07 +02:00
|
|
|
jne @f
|
2012-04-06 20:37:00 +02:00
|
|
|
mov ecx, [edx + thread_data.datasocketnum]
|
|
|
|
lea edx, [edx + thread_data.datasock]
|
|
|
|
mov esi, sizeof.thread_data.datasock
|
|
|
|
mcall connect
|
2012-04-04 15:08:07 +02:00
|
|
|
cmp eax, -1
|
2012-04-05 15:00:39 +02:00
|
|
|
je socketerror
|
2012-04-04 15:08:07 +02:00
|
|
|
@@:
|
2012-04-12 11:58:58 +02:00
|
|
|
mov edx, [ebp]
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-04 19:19:00 +02:00
|
|
|
; Create fpath from home_dir and work_dir
|
|
|
|
call create_path
|
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
lea ebx, [edx + thread_data.fpath]
|
|
|
|
invoke con_write_asciiz, ebx
|
|
|
|
invoke con_write_asciiz, str_newline
|
2012-04-05 15:00:39 +02:00
|
|
|
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
mov edx, [ebp] ;;;
|
|
|
|
lea ebx, [edx + thread_data.fpath] ;;;;
|
|
|
|
; Start the search
|
|
|
|
invoke file.find.first, ebx, str_mask, FA_ANY
|
2012-04-06 20:37:00 +02:00
|
|
|
test eax, eax
|
|
|
|
jz .nosuchdir
|
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
mov edx, [ebp] ;;;
|
2012-04-06 20:37:00 +02:00
|
|
|
lea edi, [edx + thread_data.buffer]
|
2012-04-10 21:44:51 +02:00
|
|
|
.parse_file:
|
2012-04-04 19:19:00 +02:00
|
|
|
test eax, eax ; did we find a file?
|
2012-04-04 15:08:07 +02:00
|
|
|
jz .done
|
2012-04-06 20:37:00 +02:00
|
|
|
mov ebx, eax ; yes, save the descripter in ebx
|
2012-04-04 15:08:07 +02:00
|
|
|
|
|
|
|
; first, convert the attributes
|
2012-04-06 20:37:00 +02:00
|
|
|
test [ebx + FileInfoA.Attributes], FA_FOLDER
|
2012-04-04 15:08:07 +02:00
|
|
|
jnz .folder
|
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
test [ebx + FileInfoA.Attributes], FA_READONLY
|
2012-04-04 15:08:07 +02:00
|
|
|
jnz .readonly
|
|
|
|
|
|
|
|
mov eax, '-rw-'
|
|
|
|
stosd
|
|
|
|
jmp .attr
|
|
|
|
|
|
|
|
.folder:
|
|
|
|
mov eax, 'drwx'
|
2012-04-04 19:19:00 +02:00
|
|
|
stosd
|
2012-04-04 15:08:07 +02:00
|
|
|
jmp .attr
|
|
|
|
|
|
|
|
.readonly:
|
|
|
|
mov eax, '-r--'
|
|
|
|
stosd
|
|
|
|
|
|
|
|
.attr:
|
|
|
|
mov eax, 'rw-r'
|
|
|
|
stosd
|
|
|
|
mov ax, 'w-'
|
|
|
|
stosw
|
|
|
|
mov al, ' '
|
|
|
|
stosb
|
|
|
|
|
|
|
|
; now..
|
|
|
|
mov ax, '1 '
|
|
|
|
stosw
|
|
|
|
|
|
|
|
; now write owner, everything is owned by FTP, woohoo!
|
|
|
|
mov eax, 'FTP '
|
|
|
|
stosd
|
|
|
|
stosd
|
|
|
|
|
|
|
|
; now the filesize in ascii
|
2012-04-06 20:37:00 +02:00
|
|
|
mov eax, [ebx + FileInfoA.FileSizeLow]
|
2012-04-04 15:08:07 +02:00
|
|
|
call dword_to_ascii
|
|
|
|
mov al, ' '
|
|
|
|
stosb
|
|
|
|
|
|
|
|
; then date (month/day/year)
|
2012-04-06 20:37:00 +02:00
|
|
|
movzx eax, [ebx + FileInfoA.DateModify + FileDateTime.month]
|
2012-04-12 11:58:58 +02:00
|
|
|
cmp eax, 12
|
|
|
|
ja @f
|
|
|
|
mov eax, [months - 4 + 4*eax]
|
2012-04-04 15:08:07 +02:00
|
|
|
stosd
|
2012-04-12 11:58:58 +02:00
|
|
|
@@:
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
movzx eax, [ebx + FileInfoA.DateModify + FileDateTime.day]
|
2012-04-04 15:08:07 +02:00
|
|
|
call dword_to_ascii
|
|
|
|
mov al, ' '
|
|
|
|
stosb
|
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
movzx eax, [ebx + FileInfoA.DateModify + FileDateTime.year]
|
2012-04-04 15:08:07 +02:00
|
|
|
call dword_to_ascii
|
|
|
|
mov al, ' '
|
|
|
|
stosb
|
|
|
|
|
|
|
|
; and last but not least, filename
|
2012-04-06 20:37:00 +02:00
|
|
|
lea esi, [ebx + FileInfoA.FileName]
|
|
|
|
mov ecx, 264
|
2012-04-04 15:08:07 +02:00
|
|
|
.nameloop:
|
|
|
|
lodsb
|
|
|
|
test al, al
|
|
|
|
jz .namedone
|
|
|
|
stosb
|
|
|
|
loop .nameloop
|
|
|
|
|
2012-04-04 19:19:00 +02:00
|
|
|
; insert a cr lf
|
2012-04-04 15:08:07 +02:00
|
|
|
.namedone:
|
2012-04-05 15:00:39 +02:00
|
|
|
mov ax, 0x0a0d
|
2012-04-04 15:08:07 +02:00
|
|
|
stosw
|
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
test [edx + thread_data.permissions], ABORT ; Did we receive ABOR command from client?
|
|
|
|
;;; jnz .abort ; TODO
|
2012-04-10 21:44:51 +02:00
|
|
|
|
2012-04-04 19:19:00 +02:00
|
|
|
; check next file
|
2012-04-12 11:58:58 +02:00
|
|
|
;;; invoke file.find.next, ebx
|
|
|
|
;;; jmp .parse_file
|
|
|
|
mov eax, ebx ;;;;;
|
2012-04-04 19:19:00 +02:00
|
|
|
|
|
|
|
; close file desc
|
2012-04-04 15:08:07 +02:00
|
|
|
.done:
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke file.find.close, eax ; file discriptor is still in eax at this point!
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-04 19:19:00 +02:00
|
|
|
; append the string with a 0
|
2012-04-04 15:08:07 +02:00
|
|
|
xor al, al
|
|
|
|
stosb
|
|
|
|
|
2012-04-05 15:00:39 +02:00
|
|
|
; Warn the client we're about to send the data
|
2012-04-10 21:44:51 +02:00
|
|
|
push edi
|
2012-04-12 11:58:58 +02:00
|
|
|
mov edx, [ebp] ;;;;;;;
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "150 Here it comes.."
|
|
|
|
pop esi
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-04 19:19:00 +02:00
|
|
|
; and send it to the client
|
2012-04-10 21:44:51 +02:00
|
|
|
mov edx, [ebp]
|
2012-04-06 20:37:00 +02:00
|
|
|
mov ecx, [edx + thread_data.datasocketnum]
|
|
|
|
lea edx, [edx + thread_data.buffer]
|
|
|
|
sub esi, edx
|
|
|
|
xor edi, edi
|
|
|
|
mcall send
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-04 19:19:00 +02:00
|
|
|
; close the data socket..
|
2012-04-10 21:44:51 +02:00
|
|
|
mov edx, [ebp] ; thread_data pointer
|
2012-04-06 20:37:00 +02:00
|
|
|
mov [edx + thread_data.mode], MODE_NOTREADY
|
2012-04-12 11:58:58 +02:00
|
|
|
mcall close, [edx + thread_data.datasocketnum]
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "226 Transfer OK"
|
2012-04-06 20:37:00 +02:00
|
|
|
ret
|
|
|
|
|
|
|
|
.nosuchdir:
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "550 Directory does not exist"
|
2012-04-04 15:08:07 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "NLST"
|
|
|
|
;
|
|
|
|
; List the filenames of the files in the current working directory.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
cmdNLST:
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
test [edx + thread_data.permissions], PERMISSION_EXEC
|
|
|
|
jz permission_denied
|
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
; TODO: same as list but simpler output format
|
|
|
|
|
2012-04-03 18:37:24 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "NOOP"
|
|
|
|
;
|
|
|
|
; No operation, just keep the connection alive.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
cmdNOOP:
|
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
sendFTP "200 Command OK"
|
2012-04-03 18:37:24 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "PASS"
|
|
|
|
;
|
|
|
|
; Second phase of login process, client provides password.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 22:28:26 +02:00
|
|
|
align 4
|
|
|
|
cmdPASS:
|
2012-04-10 21:44:51 +02:00
|
|
|
lea esi, [esi + 5]
|
2012-04-12 11:58:58 +02:00
|
|
|
|
|
|
|
; read the password from users.ini
|
2012-04-10 21:44:51 +02:00
|
|
|
lea edi, [edx + thread_data.buffer + 512] ; temp pass
|
2012-04-12 11:58:58 +02:00
|
|
|
lea ebx, [edx + thread_data.fpath] ; temp username
|
|
|
|
invoke ini.get_str, path2, ebx, str_pass, edi, 512, str_infinity
|
2012-04-10 21:44:51 +02:00
|
|
|
test eax, eax
|
|
|
|
jnz .incorrect
|
2012-04-12 11:58:58 +02:00
|
|
|
cmp dword [edi], -1
|
|
|
|
je .incorrect
|
|
|
|
cmp byte[edi], 0
|
|
|
|
je .pass_ok
|
2012-04-10 21:44:51 +02:00
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
; compare with received password
|
2012-04-10 21:44:51 +02:00
|
|
|
repe cmpsb
|
|
|
|
cmp byte [esi], 0x20
|
|
|
|
jae .incorrect
|
|
|
|
cmp byte [edi], 0
|
|
|
|
jne .incorrect
|
|
|
|
|
|
|
|
.pass_ok:
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke ini.get_int, path2, ebx, str_mode, 0
|
|
|
|
mov edx, [ebp] ; because libini destroys edx!
|
2012-04-10 21:44:51 +02:00
|
|
|
mov [edx + thread_data.permissions], eax
|
2012-04-04 11:24:08 +02:00
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke con_write_asciiz, str_pass_ok
|
2012-04-06 20:37:00 +02:00
|
|
|
mov [edx + thread_data.state], STATE_ACTIVE
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "230 You are now logged in"
|
|
|
|
ret
|
|
|
|
|
|
|
|
.2:
|
|
|
|
.incorrect:
|
|
|
|
mov [edx + thread_data.state], STATE_CONNECTED
|
|
|
|
sendFTP "530 Login incorrect"
|
|
|
|
ret
|
|
|
|
|
|
|
|
align 4
|
|
|
|
.0:
|
|
|
|
sendFTP "503 Login with USER first"
|
|
|
|
ret
|
2012-04-03 22:28:26 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
align 4
|
|
|
|
.3:
|
|
|
|
sendFTP "230 Already logged in"
|
2012-04-03 22:28:26 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "PASV"
|
|
|
|
;
|
|
|
|
; Initiate a passive dataconnection.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-04 11:24:08 +02:00
|
|
|
align 4
|
|
|
|
cmdPASV:
|
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
; Open a new TCP socket
|
2012-04-04 15:08:07 +02:00
|
|
|
mcall socket, AF_INET4, SOCK_STREAM, 0
|
|
|
|
cmp eax, -1
|
2012-04-06 20:37:00 +02:00
|
|
|
je socketerror
|
2012-04-10 21:44:51 +02:00
|
|
|
mov edx, [ebp] ; thread_data pointer
|
2012-04-06 20:37:00 +02:00
|
|
|
mov [edx + thread_data.passivesocknum], eax
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
; Bind it to a known local port
|
|
|
|
mov [edx + thread_data.datasock.sin_family], AF_INET4
|
|
|
|
mov [edx + thread_data.datasock.sin_port], 2000
|
|
|
|
mov [edx + thread_data.datasock.sin_addr], 0
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
mov ecx, eax ; passivesocketnum
|
2012-04-06 20:37:00 +02:00
|
|
|
lea edx, [edx + thread_data.datasock]
|
2012-04-07 13:36:00 +02:00
|
|
|
mov esi, sizeof.thread_data.datasock
|
|
|
|
mcall bind
|
2012-04-04 15:08:07 +02:00
|
|
|
cmp eax, -1
|
2012-04-12 11:58:58 +02:00
|
|
|
; je bind_err ; TODO
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
; And set it to listen!
|
2012-04-10 21:44:51 +02:00
|
|
|
mcall listen, , 1
|
|
|
|
cmp eax, -1
|
2012-04-12 11:58:58 +02:00
|
|
|
; je listen_err ; TODO
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
; Tell our thread we are ready to accept incoming calls
|
2012-04-10 21:44:51 +02:00
|
|
|
mov edx, [ebp] ; thread_data pointer
|
2012-04-06 20:37:00 +02:00
|
|
|
mov [edx + thread_data.mode], MODE_PASSIVE_WAIT
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
; Now tell the client where to connect to in this format:
|
|
|
|
; 227 Entering Passive Mode (a1,a2,a3,a4,p1,p2)
|
|
|
|
; where a1.a2.a3.a4 is the IP address and p1*256+p2 is the port number.
|
2012-04-10 21:44:51 +02:00
|
|
|
|
|
|
|
; '227 ('
|
2012-04-06 20:37:00 +02:00
|
|
|
lea edi, [edx + thread_data.buffer]
|
2012-04-04 15:08:07 +02:00
|
|
|
mov eax, '227 ' ; FIXME (now hardcoded to 127.0.0.1:2000)
|
|
|
|
stosd
|
2012-04-10 21:44:51 +02:00
|
|
|
mov al, '('
|
2012-04-04 15:08:07 +02:00
|
|
|
stosb
|
2012-04-10 21:44:51 +02:00
|
|
|
; ip
|
|
|
|
mov eax, 127
|
|
|
|
call dword_to_ascii
|
|
|
|
mov al, ','
|
|
|
|
stosb
|
|
|
|
mov eax, 0
|
|
|
|
call dword_to_ascii
|
|
|
|
mov al, ','
|
|
|
|
stosb
|
|
|
|
mov eax, 0
|
|
|
|
call dword_to_ascii
|
|
|
|
mov al, ','
|
|
|
|
stosb
|
|
|
|
mov eax, 1
|
|
|
|
call dword_to_ascii
|
|
|
|
mov al, ','
|
2012-04-04 15:08:07 +02:00
|
|
|
stosb
|
2012-04-10 21:44:51 +02:00
|
|
|
; port
|
|
|
|
mov eax, 7
|
|
|
|
call dword_to_ascii
|
|
|
|
mov al, ','
|
|
|
|
stosb
|
|
|
|
mov eax, 208
|
|
|
|
call dword_to_ascii
|
|
|
|
; ')', 13, 10, 0
|
|
|
|
mov eax, ')' + 0x000a0d00
|
|
|
|
stosd
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
lea esi, [edi - thread_data.buffer]
|
|
|
|
sub esi, edx
|
|
|
|
mov ecx, [edx + thread_data.socketnum]
|
|
|
|
lea edx, [edx + thread_data.buffer]
|
2012-04-12 11:58:58 +02:00
|
|
|
xor edi, edi
|
2012-04-07 13:36:00 +02:00
|
|
|
mcall send
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-04 11:24:08 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "PWD"
|
|
|
|
;
|
|
|
|
; Print the current working directory.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
2012-04-10 21:44:51 +02:00
|
|
|
cmdPWD:
|
2012-04-03 18:37:24 +02:00
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
mov dword [edx + thread_data.buffer], '257 '
|
|
|
|
mov byte [edx + thread_data.buffer+4], '"'
|
2012-04-04 11:24:08 +02:00
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
lea edi, [edx + thread_data.buffer+5]
|
|
|
|
lea esi, [edx + thread_data.work_dir]
|
2012-04-04 11:24:08 +02:00
|
|
|
mov ecx, 1024
|
|
|
|
.loop:
|
|
|
|
lodsb
|
|
|
|
or al, al
|
|
|
|
jz .ok
|
|
|
|
stosb
|
|
|
|
dec ecx
|
|
|
|
jnz .loop
|
|
|
|
|
|
|
|
.ok:
|
2012-04-06 20:37:00 +02:00
|
|
|
mov dword [edi], '"' + 0x000a0d00 ; '"',13,10,0
|
|
|
|
lea esi, [edi - thread_data.buffer + 4]
|
|
|
|
sub esi, edx
|
|
|
|
mov ecx, [edx + thread_data.socketnum]
|
|
|
|
lea edx, [edx + thread_data.buffer]
|
2012-04-07 20:42:58 +02:00
|
|
|
xor edi, edi
|
|
|
|
mcall send
|
2012-04-04 11:24:08 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
mov edx, [ebp]
|
2012-04-07 20:42:58 +02:00
|
|
|
; Print the new working dir on the console
|
|
|
|
lea eax, [edx + thread_data.work_dir]
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke con_write_asciiz, eax
|
|
|
|
invoke con_write_asciiz, str_newline
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-03 18:37:24 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "PORT"
|
|
|
|
;
|
|
|
|
; Initiate an active dataconnection.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
cmdPORT:
|
|
|
|
|
2012-04-04 11:24:08 +02:00
|
|
|
; PORT a1,a2,a3,a4,p1,p2
|
|
|
|
; IP address a1.a2.a3.a4, port p1*256+p2
|
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
; Convert the IP
|
2012-04-10 21:44:51 +02:00
|
|
|
lea esi, [esi+5]
|
|
|
|
mov cl, ','
|
|
|
|
call ip_to_dword
|
2012-04-06 20:37:00 +02:00
|
|
|
; And put it in datasock
|
2012-04-12 11:58:58 +02:00
|
|
|
;;; mov edx, [ebp]
|
2012-04-06 20:37:00 +02:00
|
|
|
mov [edx + thread_data.datasock.sin_addr], ebx
|
2012-04-04 11:24:08 +02:00
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
; Now the same with portnumber
|
2012-04-12 11:58:58 +02:00
|
|
|
inc esi
|
2012-04-04 11:24:08 +02:00
|
|
|
call ascii_to_byte
|
2012-04-06 20:37:00 +02:00
|
|
|
mov bh, al
|
2012-04-04 11:24:08 +02:00
|
|
|
inc esi
|
|
|
|
call ascii_to_byte
|
2012-04-06 20:37:00 +02:00
|
|
|
mov bl, al
|
2012-04-04 11:24:08 +02:00
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
; Save it in datasock too
|
|
|
|
mov [edx + thread_data.datasock.sin_port], bx
|
2012-04-04 11:24:08 +02:00
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
; We will open the socket, but do not connect yet!
|
|
|
|
mov [edx + thread_data.datasock.sin_family], AF_INET4
|
2012-04-04 15:08:07 +02:00
|
|
|
mcall socket, AF_INET4, SOCK_STREAM, 0
|
2012-04-04 11:24:08 +02:00
|
|
|
cmp eax, -1
|
2012-04-06 20:37:00 +02:00
|
|
|
je socketerror
|
2012-04-10 21:44:51 +02:00
|
|
|
|
|
|
|
mov edx, [ebp] ; thread_data pointer
|
2012-04-06 20:37:00 +02:00
|
|
|
mov [edx + thread_data.datasocketnum], eax
|
2012-04-10 21:44:51 +02:00
|
|
|
mov [edx + thread_data.mode], MODE_ACTIVE
|
2012-04-04 11:24:08 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "225 Data connection open"
|
2012-04-04 11:24:08 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "QUIT"
|
|
|
|
;
|
|
|
|
; Close the connection with client.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
cmdQUIT:
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "221 Bye!"
|
2012-04-12 11:58:58 +02:00
|
|
|
mov edx, [ebp]
|
|
|
|
mcall close, [edx + thread_data.datasocketnum]
|
2012-04-10 21:44:51 +02:00
|
|
|
mcall close, [edx + thread_data.socketnum]
|
2012-04-03 22:28:26 +02:00
|
|
|
|
2012-04-07 13:36:00 +02:00
|
|
|
add esp, 4 ; get rid of call return address
|
|
|
|
jmp thread_exit ; now close this thread
|
2012-04-03 18:37:24 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
|
|
|
|
;------------------------------------------------
|
|
|
|
; "RETR"
|
|
|
|
;
|
|
|
|
; Retrieve a file from the ftp server.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
cmdRETR:
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
test [edx + thread_data.permissions], PERMISSION_READ
|
|
|
|
jz permission_denied
|
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
cmp ecx, 1024 + 5
|
|
|
|
jae .cannot_open
|
|
|
|
|
2012-04-05 15:00:39 +02:00
|
|
|
sub ecx, 5
|
|
|
|
jb .cannot_open
|
|
|
|
|
2012-04-06 20:37:00 +02:00
|
|
|
cmp [edx + thread_data.mode], MODE_ACTIVE
|
2012-04-04 19:19:00 +02:00
|
|
|
jne @f
|
2012-04-12 11:58:58 +02:00
|
|
|
push ecx esi
|
2012-04-06 20:37:00 +02:00
|
|
|
mov ecx, [edx + thread_data.datasocketnum]
|
|
|
|
lea edx, [edx + thread_data.datasock]
|
2012-04-07 13:36:00 +02:00
|
|
|
mov esi, sizeof.thread_data.datasock
|
|
|
|
mcall connect
|
2012-04-12 11:58:58 +02:00
|
|
|
pop esi ecx
|
2012-04-05 15:00:39 +02:00
|
|
|
cmp eax, -1
|
|
|
|
je socketerror
|
2012-04-04 19:19:00 +02:00
|
|
|
@@:
|
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
push ecx esi
|
2012-04-05 15:00:39 +02:00
|
|
|
call create_path
|
2012-04-12 11:58:58 +02:00
|
|
|
pop esi ecx
|
2012-04-05 15:00:39 +02:00
|
|
|
dec edi
|
|
|
|
add esi, 5
|
2012-04-12 11:58:58 +02:00
|
|
|
|
2012-04-05 15:00:39 +02:00
|
|
|
.loop:
|
|
|
|
lodsb
|
|
|
|
cmp al, 0x20
|
|
|
|
jl .done
|
|
|
|
stosb
|
|
|
|
loop .loop
|
|
|
|
.done:
|
|
|
|
xor al, al
|
|
|
|
stosb
|
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
lea ebx, [edx + thread_data.fpath]
|
|
|
|
invoke con_write_asciiz, ebx
|
|
|
|
invoke con_write_asciiz, str_newline
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke file.open, ebx, O_READ
|
2012-04-05 15:00:39 +02:00
|
|
|
test eax, eax
|
|
|
|
jz .cannot_open
|
2012-04-04 19:19:00 +02:00
|
|
|
|
2012-04-05 15:00:39 +02:00
|
|
|
push eax
|
2012-04-12 11:58:58 +02:00
|
|
|
mov edx, [ebp]
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "150 Here it comes.."
|
2012-04-05 15:00:39 +02:00
|
|
|
pop ebx
|
2012-04-04 19:19:00 +02:00
|
|
|
|
|
|
|
.read_more:
|
2012-04-10 21:44:51 +02:00
|
|
|
mov edx, [ebp]
|
|
|
|
test [edx + thread_data.permissions], ABORT
|
|
|
|
jnz abort_transfer
|
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
lea eax, [edx + thread_data.buffer] ; FIXME: use another buffer!! if we receive something on control connection now, we screw up!
|
|
|
|
invoke file.read, ebx, eax, BUFFERSIZE
|
2012-04-05 15:00:39 +02:00
|
|
|
cmp eax, -1
|
2012-04-12 11:58:58 +02:00
|
|
|
je .cannot_open ; FIXME: this is not the correct error
|
2012-04-04 19:19:00 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
push eax ebx
|
2012-04-04 19:19:00 +02:00
|
|
|
mov esi, eax
|
2012-04-06 20:37:00 +02:00
|
|
|
mov ecx, [edx + thread_data.datasocketnum]
|
|
|
|
lea edx, [edx + thread_data.buffer]
|
2012-04-07 13:36:00 +02:00
|
|
|
xor esi, esi
|
|
|
|
mcall send
|
2012-04-10 21:44:51 +02:00
|
|
|
pop ebx ecx
|
2012-04-05 15:00:39 +02:00
|
|
|
cmp eax, -1
|
|
|
|
je socketerror
|
2012-04-04 19:19:00 +02:00
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
; cmp eax, ecx
|
|
|
|
; jne not_all_byes_sent ; TODO
|
|
|
|
|
2012-04-04 19:19:00 +02:00
|
|
|
cmp ecx, BUFFERSIZE
|
|
|
|
je .read_more
|
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke file.close, ebx
|
2012-04-04 19:19:00 +02:00
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
mov edx, [ebp]
|
|
|
|
mov [edx + thread_data.mode], MODE_NOTREADY
|
|
|
|
mcall close, [edx + thread_data.datasocketnum]
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
mov edx, [ebp]
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "226 Transfer OK, closing connection"
|
2012-04-03 18:37:24 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-05 15:00:39 +02:00
|
|
|
.cannot_open:
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke con_set_flags, 0x0c
|
|
|
|
invoke con_write_asciiz, str_notfound
|
|
|
|
invoke con_set_flags, 0x07
|
2012-04-05 15:00:39 +02:00
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
mov edx, [ebp]
|
|
|
|
sendFTP "550 No such file"
|
2012-04-05 15:00:39 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
|
|
|
|
|
|
|
|
;------------------------------------------------
|
|
|
|
; "STOR"
|
|
|
|
;
|
|
|
|
; Store a file on the server.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
cmdSTOR:
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
test [edx + thread_data.permissions], PERMISSION_WRITE
|
|
|
|
jz permission_denied
|
|
|
|
|
|
|
|
|
|
|
|
;;;;
|
|
|
|
test [edx + thread_data.permissions], ABORT
|
|
|
|
jnz abort_transfer
|
|
|
|
|
|
|
|
;;;;
|
2012-04-06 20:37:00 +02:00
|
|
|
|
2012-04-03 18:37:24 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "SYST"
|
|
|
|
;
|
|
|
|
; Send information about the system.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
cmdSYST:
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "215 UNIX type: L8"
|
2012-04-03 18:37:24 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "TYPE"
|
|
|
|
;
|
|
|
|
; Choose the file transfer type.
|
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
cmdTYPE:
|
|
|
|
|
2012-04-04 11:24:08 +02:00
|
|
|
cmp ecx, 6
|
|
|
|
jb parse_cmd.error
|
|
|
|
|
|
|
|
mov al, byte[esi+5]
|
|
|
|
and al, not 0x20
|
|
|
|
|
|
|
|
cmp al, 'A'
|
|
|
|
je .ascii
|
|
|
|
cmp al, 'E'
|
|
|
|
je .ebdic
|
|
|
|
cmp al, 'I'
|
|
|
|
je .image
|
|
|
|
cmp al, 'L'
|
|
|
|
je .local
|
|
|
|
|
|
|
|
jmp parse_cmd.error
|
|
|
|
|
|
|
|
.ascii:
|
2012-04-06 20:37:00 +02:00
|
|
|
mov [edx + thread_data.type], TYPE_ASCII
|
2012-04-04 11:24:08 +02:00
|
|
|
jmp .subtype
|
|
|
|
|
|
|
|
.ebdic:
|
2012-04-06 20:37:00 +02:00
|
|
|
mov [edx + thread_data.type], TYPE_EBDIC
|
2012-04-04 11:24:08 +02:00
|
|
|
|
|
|
|
.subtype:
|
|
|
|
cmp ecx, 8
|
|
|
|
jb .non_print
|
|
|
|
|
|
|
|
mov al, byte[esi+7]
|
|
|
|
and al, not 0x20
|
|
|
|
|
|
|
|
cmp al, 'N'
|
|
|
|
je .non_print
|
|
|
|
cmp al, 'T'
|
|
|
|
je .telnet
|
|
|
|
cmp al, 'C'
|
|
|
|
je .asacc
|
|
|
|
|
|
|
|
jmp parse_cmd.error
|
|
|
|
|
|
|
|
.non_print:
|
2012-04-06 20:37:00 +02:00
|
|
|
or [edx + thread_data.type], TYPE_NP
|
2012-04-04 11:24:08 +02:00
|
|
|
jmp .ok
|
|
|
|
|
|
|
|
.telnet:
|
2012-04-06 20:37:00 +02:00
|
|
|
or [edx + thread_data.type], TYPE_TELNET
|
2012-04-04 11:24:08 +02:00
|
|
|
jmp .ok
|
|
|
|
|
|
|
|
.asacc:
|
2012-04-06 20:37:00 +02:00
|
|
|
or [edx + thread_data.type], TYPE_ASA
|
2012-04-04 11:24:08 +02:00
|
|
|
jmp .ok
|
|
|
|
|
|
|
|
.image:
|
2012-04-06 20:37:00 +02:00
|
|
|
mov [edx + thread_data.type], TYPE_IMAGE
|
2012-04-04 11:24:08 +02:00
|
|
|
jmp .ok
|
|
|
|
|
|
|
|
.local:
|
|
|
|
cmp ecx, 8
|
|
|
|
jb parse_cmd.error
|
|
|
|
|
|
|
|
mov al, byte[esi+7]
|
|
|
|
sub al, '0'
|
2012-04-12 11:58:58 +02:00
|
|
|
jb parse_cmd.error ; FIXME: this is not the correct errormessage
|
2012-04-04 11:24:08 +02:00
|
|
|
cmp al, 9
|
2012-04-12 11:58:58 +02:00
|
|
|
ja parse_cmd.error ; FIXME
|
2012-04-04 11:24:08 +02:00
|
|
|
or al, TYPE_LOCAL
|
2012-04-06 20:37:00 +02:00
|
|
|
mov [edx + thread_data.type], al
|
2012-04-04 11:24:08 +02:00
|
|
|
|
|
|
|
.ok:
|
2012-04-10 21:44:51 +02:00
|
|
|
sendFTP "200 Command ok"
|
2012-04-03 18:37:24 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
;------------------------------------------------
|
|
|
|
; "USER"
|
|
|
|
;
|
2012-04-12 11:58:58 +02:00
|
|
|
; Login to the server, step one of two. ;;; TODO: prevent buffer overflow!
|
2012-04-10 21:44:51 +02:00
|
|
|
;
|
|
|
|
;------------------------------------------------
|
2012-04-03 18:37:24 +02:00
|
|
|
align 4
|
|
|
|
cmdUSER:
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
lea esi, [esi + 5]
|
2012-04-12 11:58:58 +02:00
|
|
|
lea edi, [edx + thread_data.fpath] ; temp buffer for username
|
|
|
|
.loop:
|
2012-04-10 21:44:51 +02:00
|
|
|
lodsb
|
|
|
|
stosb
|
|
|
|
cmp al, 0x20
|
|
|
|
jae .loop
|
|
|
|
mov byte [edi-1], 0
|
|
|
|
|
|
|
|
lea esi, [edx + thread_data.fpath]
|
|
|
|
lea eax, [edx + thread_data.home_dir]
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke ini.get_str, path2, esi, str_home, eax, 1024, str_infinity
|
2012-04-10 21:44:51 +02:00
|
|
|
cmp eax, -1
|
|
|
|
je .login_fail
|
2012-04-12 11:58:58 +02:00
|
|
|
cmp dword [esi], -1
|
|
|
|
je .login_fail
|
2012-04-03 22:28:26 +02:00
|
|
|
|
2012-04-07 20:42:58 +02:00
|
|
|
mov word [edx + thread_data.work_dir], "/" ; "/", 0
|
2012-04-04 11:24:08 +02:00
|
|
|
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke con_write_asciiz, str_logged_in
|
2012-04-10 21:44:51 +02:00
|
|
|
mov [edx + thread_data.state], STATE_LOGIN
|
|
|
|
.sendstr:
|
|
|
|
sendFTP "331 Please specify the password"
|
2012-04-04 11:24:08 +02:00
|
|
|
ret
|
|
|
|
|
2012-04-10 21:44:51 +02:00
|
|
|
.login_fail:
|
2012-04-12 11:58:58 +02:00
|
|
|
invoke con_write_asciiz, str_login_invalid
|
2012-04-10 21:44:51 +02:00
|
|
|
mov [edx + thread_data.state], STATE_LOGIN_FAIL
|
|
|
|
jmp .sendstr
|
2012-04-04 15:08:07 +02:00
|
|
|
|
2012-04-04 19:19:00 +02:00
|
|
|
align 4
|
2012-04-10 21:44:51 +02:00
|
|
|
.2:
|
|
|
|
sendFTP "530 Can't change to another user"
|
2012-04-04 19:19:00 +02:00
|
|
|
ret
|