1 | #include "globals.h"
|
---|
2 |
|
---|
3 | //CMD00 - ECM (request)
|
---|
4 | //CMD01 - ECM (response)
|
---|
5 | //CMD02 - EMM (in clientmode - set EMM, in server mode - EMM data) - obsolete
|
---|
6 | //CMD03 - ECM (cascading request)
|
---|
7 | //CMD04 - ECM (cascading response)
|
---|
8 | //CMD05 - EMM (emm request) send cardata/cardinfo to client
|
---|
9 | //CMD06 - EMM (incomming EMM in server mode)
|
---|
10 | //CMD19 - EMM (incomming EMM in server mode) only seen with caid 0x1830
|
---|
11 | //CMD08 - Stop sending requests to the server for current srvid,prvid,caid
|
---|
12 | //CMD44 - MPCS/OScam internal error notification
|
---|
13 |
|
---|
14 | #define REQ_SIZE 328 // 256 + 20 + 0x34
|
---|
15 |
|
---|
16 | static int camd35_send(uchar *buf)
|
---|
17 | {
|
---|
18 | int l;
|
---|
19 | unsigned char rbuf[REQ_SIZE+15+4], *sbuf = rbuf + 4;
|
---|
20 | struct s_client *cl = cur_client();
|
---|
21 |
|
---|
22 | if (!cl->udp_fd) return(-1);
|
---|
23 | l = 20 + buf[1] + (((buf[0] == 3) || (buf[0] == 4)) ? 0x34 : 0);
|
---|
24 | memcpy(rbuf, cl->ucrc, 4);
|
---|
25 | memcpy(sbuf, buf, l);
|
---|
26 | memset(sbuf + l, 0xff, 15); // set unused space to 0xff for newer camd3's
|
---|
27 | memcpy(sbuf + 4, i2b(4, crc32(0L, sbuf+20, sbuf[1])), 4);
|
---|
28 | l = boundary(4, l);
|
---|
29 | cs_ddump_mask(D_CLIENT, sbuf, l, "send %d bytes to %s", l, remote_txt());
|
---|
30 | aes_encrypt(sbuf, l);
|
---|
31 |
|
---|
32 | int status;
|
---|
33 | if (cl->is_udp) {
|
---|
34 | status = sendto(cl->udp_fd, rbuf, l+4, 0,
|
---|
35 | (struct sockaddr *)&cl->udp_sa,
|
---|
36 | sizeof(cl->udp_sa));
|
---|
37 | if (status == -1) cl->udp_sa.sin_addr.s_addr = 0;
|
---|
38 | }
|
---|
39 | else {
|
---|
40 | status = send(cl->udp_fd, rbuf, l + 4, 0);
|
---|
41 | if (status == -1) network_tcp_connection_close(cl, cl->pfd);
|
---|
42 | }
|
---|
43 | return status;
|
---|
44 | }
|
---|
45 |
|
---|
46 | static int camd35_auth_client(uchar *ucrc)
|
---|
47 | {
|
---|
48 | int rc=1;
|
---|
49 | ulong crc;
|
---|
50 | struct s_auth *account;
|
---|
51 | struct s_client *cl = cur_client();
|
---|
52 |
|
---|
53 | if (cl->upwd[0])
|
---|
54 | return(memcmp(cl->ucrc, ucrc, 4) ? 1 : 0);
|
---|
55 | cl->crypted=1;
|
---|
56 | crc=(((ucrc[0]<<24) | (ucrc[1]<<16) | (ucrc[2]<<8) | ucrc[3]) & 0xffffffffL);
|
---|
57 | for (account=cfg.account; (account) && (!cl->upwd[0]); account=account->next)
|
---|
58 | if (crc==crc32(0L, MD5((unsigned char *)account->usr, strlen(account->usr), cl->dump), 16))
|
---|
59 | {
|
---|
60 | memcpy(cl->ucrc, ucrc, 4);
|
---|
61 | strcpy((char *)cl->upwd, account->pwd);
|
---|
62 | aes_set_key((char *) MD5(cl->upwd, strlen((char *)cl->upwd), cl->dump));
|
---|
63 | rc=cs_auth_client(cl, account, NULL);
|
---|
64 | }
|
---|
65 | return(rc);
|
---|
66 | }
|
---|
67 |
|
---|
68 | static int camd35_recv(struct s_client *client, uchar *buf, int l)
|
---|
69 | {
|
---|
70 | int rc, s, rs, n=0;
|
---|
71 | unsigned char recrc[4];
|
---|
72 | for (rc=rs=s=0; !rc; s++) switch(s)
|
---|
73 | {
|
---|
74 | case 0:
|
---|
75 | if (client->typ == 'c')
|
---|
76 | {
|
---|
77 | if (!client->udp_fd) return(-9);
|
---|
78 | if (client->is_udp)
|
---|
79 | rs=recv_from_udpipe(buf);
|
---|
80 | else
|
---|
81 | rs=recv(client->udp_fd, buf, l, 0);
|
---|
82 | }
|
---|
83 | else
|
---|
84 | {
|
---|
85 | if (!client->udp_fd) return(-9);
|
---|
86 | rs = recv(client->udp_fd, buf, l, 0);
|
---|
87 | }
|
---|
88 | if (rs < 24) rc = -1;
|
---|
89 | break;
|
---|
90 | case 1:
|
---|
91 | memcpy(recrc, buf, 4);
|
---|
92 | memmove(buf, buf+4, rs-=4);
|
---|
93 | switch (camd35_auth_client(recrc))
|
---|
94 | {
|
---|
95 | case 0: break; // ok
|
---|
96 | case 1: rc=-2; break; // unknown user
|
---|
97 | default: rc=-9; break; // error's from cs_auth()
|
---|
98 | }
|
---|
99 | break;
|
---|
100 | case 2:
|
---|
101 | aes_decrypt(buf, rs);
|
---|
102 | cs_ddump_mask(D_CLIENT, buf, rs, "received %d bytes from %s", rs, remote_txt());
|
---|
103 | if (rs!=boundary(4, rs))
|
---|
104 | {
|
---|
105 | cs_debug_mask(D_CLIENT, "WARNING: packet size has wrong decryption boundary");
|
---|
106 | }
|
---|
107 | //n=(buf[0]==3) ? n=0x34 : 0; this was original, but statement below seems more logical -- dingo35
|
---|
108 | n=(buf[0]==3) ? 0x34 : 0;
|
---|
109 | n=boundary(4, n+20+buf[1]);
|
---|
110 | if (n<rs)
|
---|
111 | {
|
---|
112 | cs_debug_mask(D_CLIENT, "ignoring %d bytes of garbage", rs-n);
|
---|
113 | }
|
---|
114 | else
|
---|
115 | if (n>rs) rc=-3;
|
---|
116 | break;
|
---|
117 | case 3:
|
---|
118 | if (crc32(0L, buf+20, buf[1])!=b2i(4, buf+4)) rc=-4;
|
---|
119 | if (!rc) rc=n;
|
---|
120 | break;
|
---|
121 | }
|
---|
122 | if ((rs>0) && ((rc==-1)||(rc==-2)))
|
---|
123 | {
|
---|
124 | cs_ddump_mask(D_CLIENT, buf, rs, "received %d bytes from %s (native)", rs, remote_txt);
|
---|
125 | }
|
---|
126 | client->last=time((time_t *) 0);
|
---|
127 | switch(rc)
|
---|
128 | {
|
---|
129 | case -1: cs_log("packet to small (%d bytes)", rs);
|
---|
130 | break;
|
---|
131 | case -2: cs_auth_client(client, 0, "unknown user");
|
---|
132 | break;
|
---|
133 | case -3: cs_log("incomplete request !");
|
---|
134 | break;
|
---|
135 | case -4: cs_log("checksum error (wrong password ?)");
|
---|
136 | break;
|
---|
137 | }
|
---|
138 | return(rc);
|
---|
139 | }
|
---|
140 |
|
---|
141 | /*
|
---|
142 | * server functions
|
---|
143 | */
|
---|
144 |
|
---|
145 | static void camd35_request_emm(ECM_REQUEST *er)
|
---|
146 | {
|
---|
147 | int i;
|
---|
148 | time_t now;
|
---|
149 | uchar mbuf[1024];
|
---|
150 | struct s_client *cl = cur_client();
|
---|
151 | struct s_reader *aureader = NULL, *rdr = NULL;
|
---|
152 |
|
---|
153 | LL_ITER *itr = ll_iter_create(cl->aureader_list);
|
---|
154 | while ((rdr = ll_iter_next(itr))) {
|
---|
155 | if (!(rdr->typ & R_IS_CASCADING) && rdr->caid == er->caid) {
|
---|
156 | aureader=rdr;
|
---|
157 | break;
|
---|
158 | }
|
---|
159 | }
|
---|
160 | ll_iter_release(itr);
|
---|
161 |
|
---|
162 | if (!aureader)
|
---|
163 | return; // TODO
|
---|
164 |
|
---|
165 | time(&now);
|
---|
166 | if (!memcmp(cl->lastserial, aureader->hexserial, 8))
|
---|
167 | if (abs(now-cl->last) < 180) return;
|
---|
168 |
|
---|
169 | memcpy(cl->lastserial, aureader->hexserial, 8);
|
---|
170 | cl->last = now;
|
---|
171 |
|
---|
172 | if (aureader->caid)
|
---|
173 | {
|
---|
174 | cl->disable_counter = 0;
|
---|
175 | log_emm_request(aureader);
|
---|
176 | }
|
---|
177 | else
|
---|
178 | if (cl->disable_counter > 2)
|
---|
179 | return;
|
---|
180 | else
|
---|
181 | cl->disable_counter++;
|
---|
182 |
|
---|
183 | memset(mbuf, 0, sizeof(mbuf));
|
---|
184 | mbuf[2] = mbuf[3] = 0xff; // must not be zero
|
---|
185 | memcpy(mbuf + 8, i2b(2, er->srvid), 2);
|
---|
186 |
|
---|
187 | //override request provid with auprovid if set in CMD05
|
---|
188 | if(aureader->auprovid) {
|
---|
189 | if(aureader->auprovid != er->prid)
|
---|
190 | memcpy(mbuf + 12, i2b(4, aureader->auprovid), 4);
|
---|
191 | else
|
---|
192 | memcpy(mbuf + 12, i2b(4, er->prid), 4);
|
---|
193 | } else {
|
---|
194 | memcpy(mbuf + 12, i2b(4, er->prid), 4);
|
---|
195 | }
|
---|
196 |
|
---|
197 | memcpy(mbuf + 16, i2b(2, er->pid), 2);
|
---|
198 | mbuf[0] = 5;
|
---|
199 | mbuf[1] = 111;
|
---|
200 | if (aureader->caid)
|
---|
201 | {
|
---|
202 | mbuf[39] = 1; // no. caids
|
---|
203 | mbuf[20] = aureader->caid>>8; // caid's (max 8)
|
---|
204 | mbuf[21] = aureader->caid&0xff;
|
---|
205 | memcpy(mbuf + 40, aureader->hexserial, 6); // serial now 6 bytes
|
---|
206 | mbuf[47] = aureader->nprov;
|
---|
207 | for (i = 0; i < aureader->nprov; i++)
|
---|
208 | {
|
---|
209 | if (((aureader->caid >= 0x1700) && (aureader->caid <= 0x1799)) || // Betacrypt
|
---|
210 | ((aureader->caid >= 0x0600) && (aureader->caid <= 0x0699))) // Irdeto (don't know if this is correct, cause I don't own a IRDETO-Card)
|
---|
211 | {
|
---|
212 | mbuf[48 + (i*5)] = aureader->prid[i][0];
|
---|
213 | memcpy(&mbuf[50 + (i*5)], &aureader->prid[i][1], 3);
|
---|
214 | }
|
---|
215 | else
|
---|
216 | {
|
---|
217 | mbuf[48 + (i * 5)] = aureader->prid[i][2];
|
---|
218 | mbuf[49 + (i * 5)] =aureader->prid[i][3];
|
---|
219 | memcpy(&mbuf[50 + (i * 5)], &aureader->sa[i][0],4); // for conax we need at least 4 Bytes
|
---|
220 | }
|
---|
221 | }
|
---|
222 | //we think client/server protocols should deliver all information, and only readers should discard EMM
|
---|
223 | mbuf[128] = (aureader->blockemm_g == 1) ? 0: 1;
|
---|
224 | mbuf[129] = (aureader->blockemm_s == 1) ? 0: 1;
|
---|
225 | mbuf[130] = (aureader->blockemm_u == 1) ? 0: 1;
|
---|
226 | //mbuf[131] = aureader->card_system; //Cardsystem for Oscam client
|
---|
227 | }
|
---|
228 | else // disable emm
|
---|
229 | mbuf[20] = mbuf[39] = mbuf[40] = mbuf[47] = mbuf[49] = 1;
|
---|
230 |
|
---|
231 | memcpy(mbuf + 10, mbuf + 20, 2);
|
---|
232 | cs_sleepms(500);
|
---|
233 | camd35_send(mbuf); // send with data-len 111 for camd3 > 3.890
|
---|
234 | mbuf[1]++;
|
---|
235 | cs_sleepms(500);
|
---|
236 | camd35_send(mbuf); // send with data-len 112 for camd3 < 3.890
|
---|
237 | }
|
---|
238 |
|
---|
239 | static void camd35_send_dcw(struct s_client *client, ECM_REQUEST *er)
|
---|
240 | {
|
---|
241 | uchar *buf;
|
---|
242 | buf = client->req + (er->cpti * REQ_SIZE); // get orig request
|
---|
243 |
|
---|
244 | if (((er->rcEx > 0) || (er->rc == E_INVALID)) && !client->c35_suppresscmd08)
|
---|
245 | {
|
---|
246 | buf[0] = 0x08;
|
---|
247 | buf[1] = 2;
|
---|
248 | memset(buf + 20, 0, buf[1]);
|
---|
249 | buf[22] = er->rc; //put rc in byte 22 - hopefully don't break legacy camd3
|
---|
250 | }
|
---|
251 | else if (er->rc == E_STOPPED)
|
---|
252 | {
|
---|
253 | buf[0] = 0x08;
|
---|
254 | buf[1] = 2;
|
---|
255 | buf[20] = 0;
|
---|
256 | /*
|
---|
257 | * the second Databyte should be forseen for a sleeptime in minutes
|
---|
258 | * whoever knows the camd3 protocol related to CMD08 - please help!
|
---|
259 | * on tests this don't work with native camd3
|
---|
260 | */
|
---|
261 | buf[21] = client->c35_sleepsend;
|
---|
262 | cs_log("%s stop request send", client->account->usr);
|
---|
263 | }
|
---|
264 | else
|
---|
265 | {
|
---|
266 | // Send CW
|
---|
267 | if ((er->rc < E_NOTFOUND) || (er->rc == E_FAKE))
|
---|
268 | {
|
---|
269 | if (buf[0]==3)
|
---|
270 | memmove(buf + 20 + 16, buf + 20 + buf[1], 0x34);
|
---|
271 | buf[0]++;
|
---|
272 | buf[1] = 16;
|
---|
273 | memcpy(buf+20, er->cw, buf[1]);
|
---|
274 | }
|
---|
275 | else
|
---|
276 | {
|
---|
277 | // Send old CMD44 to prevent cascading problems with older mpcs/oscam versions
|
---|
278 | buf[0] = 0x44;
|
---|
279 | buf[1] = 0;
|
---|
280 | }
|
---|
281 | }
|
---|
282 | camd35_send(buf);
|
---|
283 | camd35_request_emm(er);
|
---|
284 | }
|
---|
285 |
|
---|
286 | static void camd35_process_ecm(uchar *buf)
|
---|
287 | {
|
---|
288 | ECM_REQUEST *er;
|
---|
289 | if (!(er = get_ecmtask()))
|
---|
290 | return;
|
---|
291 | er->l = buf[1];
|
---|
292 | memcpy(cur_client()->req + (er->cpti*REQ_SIZE), buf, 0x34 + 20 + er->l); // save request
|
---|
293 | er->srvid = b2i(2, buf+ 8);
|
---|
294 | er->caid = b2i(2, buf+10);
|
---|
295 | er->prid = b2i(4, buf+12);
|
---|
296 | er->pid = b2i(2, buf+16);
|
---|
297 | memcpy(er->ecm, buf + 20, er->l);
|
---|
298 | get_cw(cur_client(), er);
|
---|
299 | }
|
---|
300 |
|
---|
301 | static void camd35_process_emm(uchar *buf)
|
---|
302 | {
|
---|
303 | EMM_PACKET epg;
|
---|
304 | memset(&epg, 0, sizeof(epg));
|
---|
305 | epg.l = buf[1];
|
---|
306 | memcpy(epg.caid, buf + 10, 2);
|
---|
307 | memcpy(epg.provid, buf + 12 , 4);
|
---|
308 | memcpy(epg.emm, buf + 20, epg.l);
|
---|
309 | do_emm(cur_client(), &epg);
|
---|
310 | }
|
---|
311 |
|
---|
312 | static void * camd35_server(void *cli)
|
---|
313 | {
|
---|
314 | int n;
|
---|
315 | uchar mbuf[1024];
|
---|
316 |
|
---|
317 | struct s_client * client = (struct s_client *) cli;
|
---|
318 | client->thread=pthread_self();
|
---|
319 | pthread_setspecific(getclient, cli);
|
---|
320 |
|
---|
321 | client->req=(uchar *)malloc(CS_MAXPENDING*REQ_SIZE);
|
---|
322 | if (!client->req)
|
---|
323 | {
|
---|
324 | cs_log("Cannot allocate memory (errno=%d)", errno);
|
---|
325 | cs_exit(1);
|
---|
326 | }
|
---|
327 | memset(client->req, 0, CS_MAXPENDING*REQ_SIZE);
|
---|
328 |
|
---|
329 | client->is_udp = (ph[client->ctyp].type == MOD_CONN_UDP);
|
---|
330 |
|
---|
331 | while ((n=process_input(mbuf, sizeof(mbuf), cfg.cmaxidle))>0)
|
---|
332 | {
|
---|
333 | switch(mbuf[0])
|
---|
334 | {
|
---|
335 | case 0: // ECM
|
---|
336 | case 3: // ECM (cascading)
|
---|
337 | camd35_process_ecm(mbuf);
|
---|
338 | break;
|
---|
339 | case 6: // EMM
|
---|
340 | case 19: // EMM
|
---|
341 | camd35_process_emm(mbuf);
|
---|
342 | break;
|
---|
343 | default:
|
---|
344 | cs_log("unknown camd35 command! (%d)", mbuf[0]);
|
---|
345 | }
|
---|
346 | }
|
---|
347 |
|
---|
348 | NULLFREE(client->req);
|
---|
349 |
|
---|
350 | cs_disconnect_client(client);
|
---|
351 | return NULL; //to prevent compiler message
|
---|
352 | }
|
---|
353 |
|
---|
354 | /*
|
---|
355 | * client functions
|
---|
356 | */
|
---|
357 |
|
---|
358 | static void casc_set_account()
|
---|
359 | {
|
---|
360 | struct s_client *cl = cur_client();
|
---|
361 | strcpy((char *)cl->upwd, cl->reader->r_pwd);
|
---|
362 | memcpy(cl->ucrc, i2b(4, crc32(0L, MD5((unsigned char *)cl->reader->r_usr, strlen(cl->reader->r_usr), cl->dump), 16)), 4);
|
---|
363 | aes_set_key((char *)MD5(cl->upwd, strlen((char *)cl->upwd), cl->dump));
|
---|
364 | cl->crypted=1;
|
---|
365 | }
|
---|
366 |
|
---|
367 | int camd35_client_init(struct s_client *client)
|
---|
368 | {
|
---|
369 | struct sockaddr_in loc_sa;
|
---|
370 | struct protoent *ptrp;
|
---|
371 | int p_proto;//, sock_type;
|
---|
372 | char ptxt[16];
|
---|
373 |
|
---|
374 | client->pfd=0;
|
---|
375 | if (client->reader->r_port<=0)
|
---|
376 | {
|
---|
377 | cs_log("invalid port %d for server %s", client->reader->r_port, client->reader->device);
|
---|
378 | return(1);
|
---|
379 | }
|
---|
380 | client->is_udp=(client->reader->typ==R_CAMD35);
|
---|
381 | if( (ptrp=getprotobyname(client->is_udp ? "udp" : "tcp")) )
|
---|
382 | p_proto=ptrp->p_proto;
|
---|
383 | else
|
---|
384 | p_proto=(client->is_udp) ? 17 : 6; // use defaults on error
|
---|
385 |
|
---|
386 | client->ip=0;
|
---|
387 | memset((char *)&loc_sa,0,sizeof(loc_sa));
|
---|
388 | loc_sa.sin_family = AF_INET;
|
---|
389 | #ifdef LALL
|
---|
390 | if (cfg.serverip[0])
|
---|
391 | loc_sa.sin_addr.s_addr = inet_addr(cfg.serverip);
|
---|
392 | else
|
---|
393 | #endif
|
---|
394 | loc_sa.sin_addr.s_addr = INADDR_ANY;
|
---|
395 | loc_sa.sin_port = htons(client->reader->l_port);
|
---|
396 |
|
---|
397 | if ((client->udp_fd=socket(PF_INET, client->is_udp ? SOCK_DGRAM : SOCK_STREAM, p_proto))<0)
|
---|
398 | {
|
---|
399 | cs_log("Socket creation failed (errno=%d)", errno);
|
---|
400 | cs_exit(1);
|
---|
401 | }
|
---|
402 |
|
---|
403 | #ifdef SO_PRIORITY
|
---|
404 | if (cfg.netprio)
|
---|
405 | setsockopt(client->udp_fd, SOL_SOCKET, SO_PRIORITY, (void *)&cfg.netprio, sizeof(ulong));
|
---|
406 | #endif
|
---|
407 |
|
---|
408 | if (client->reader->l_port>0)
|
---|
409 | {
|
---|
410 | if (bind(client->udp_fd, (struct sockaddr *)&loc_sa, sizeof (loc_sa))<0)
|
---|
411 | {
|
---|
412 | cs_log("bind failed (errno=%d)", errno);
|
---|
413 | close(client->udp_fd);
|
---|
414 | return(1);
|
---|
415 | }
|
---|
416 | sprintf(ptxt, ", port=%d", client->reader->l_port);
|
---|
417 | }
|
---|
418 | else
|
---|
419 | ptxt[0]='\0';
|
---|
420 |
|
---|
421 | casc_set_account();
|
---|
422 | memset((char *)&client->udp_sa, 0, sizeof(client->udp_sa));
|
---|
423 | client->udp_sa.sin_family=AF_INET;
|
---|
424 | client->udp_sa.sin_port=htons((u_short)client->reader->r_port);
|
---|
425 |
|
---|
426 | cs_log("proxy %s:%d (fd=%d%s)",
|
---|
427 | client->reader->device, client->reader->r_port,
|
---|
428 | client->udp_fd, ptxt);
|
---|
429 |
|
---|
430 | if (client->is_udp) {
|
---|
431 | client->pfd=client->udp_fd;
|
---|
432 | }
|
---|
433 |
|
---|
434 | return(0);
|
---|
435 | }
|
---|
436 |
|
---|
437 | int camd35_client_init_log()
|
---|
438 | {
|
---|
439 | struct sockaddr_in loc_sa;
|
---|
440 | struct protoent *ptrp;
|
---|
441 | int p_proto;
|
---|
442 | struct s_client *cl = cur_client();
|
---|
443 |
|
---|
444 | if (cl->reader->log_port<=0)
|
---|
445 | {
|
---|
446 | cs_log("invalid port %d for camd3-loghost", cl->reader->log_port);
|
---|
447 | return(1);
|
---|
448 | }
|
---|
449 |
|
---|
450 | ptrp=getprotobyname("udp");
|
---|
451 | if (ptrp)
|
---|
452 | p_proto=ptrp->p_proto;
|
---|
453 | else
|
---|
454 | p_proto=17; // use defaults on error
|
---|
455 |
|
---|
456 | memset((char *)&loc_sa,0,sizeof(loc_sa));
|
---|
457 | loc_sa.sin_family = AF_INET;
|
---|
458 | loc_sa.sin_addr.s_addr = INADDR_ANY;
|
---|
459 | loc_sa.sin_port = htons(cl->reader->log_port);
|
---|
460 |
|
---|
461 | if ((logfd=socket(PF_INET, SOCK_DGRAM, p_proto))<0)
|
---|
462 | {
|
---|
463 | cs_log("Socket creation failed (errno=%d)", errno);
|
---|
464 | return(1);
|
---|
465 | }
|
---|
466 |
|
---|
467 | if (bind(logfd, (struct sockaddr *)&loc_sa, sizeof(loc_sa))<0)
|
---|
468 | {
|
---|
469 | cs_log("bind failed (errno=%d)", errno);
|
---|
470 | close(logfd);
|
---|
471 | return(1);
|
---|
472 | }
|
---|
473 |
|
---|
474 | cs_log("camd3 loghost initialized (fd=%d, port=%d)",
|
---|
475 | logfd, cl->reader->log_port);
|
---|
476 |
|
---|
477 | return(0);
|
---|
478 | }
|
---|
479 |
|
---|
480 | static int tcp_connect()
|
---|
481 | {
|
---|
482 | struct s_client *cl = cur_client();
|
---|
483 | if (!cl->reader->tcp_connected)
|
---|
484 | {
|
---|
485 | int handle=0;
|
---|
486 | handle = network_tcp_connection_open();
|
---|
487 | if (handle<0) return(0);
|
---|
488 |
|
---|
489 | cl->reader->tcp_connected = 1;
|
---|
490 | cl->reader->card_status = CARD_INSERTED;
|
---|
491 | cl->reader->last_s = cl->reader->last_g = time((time_t *)0);
|
---|
492 | cl->pfd = cl->udp_fd = handle;
|
---|
493 | }
|
---|
494 | if (!cl->udp_fd) return(0);
|
---|
495 | return(1);
|
---|
496 | }
|
---|
497 |
|
---|
498 | static int camd35_send_ecm(struct s_client *client, ECM_REQUEST *er, uchar *buf)
|
---|
499 | {
|
---|
500 | static const char *typtext[]={"ok", "invalid", "sleeping"};
|
---|
501 |
|
---|
502 | if (client->stopped) {
|
---|
503 | if (er->srvid == client->lastsrvid && er->caid == client->lastcaid && er->pid == client->lastpid){
|
---|
504 | cs_log("%s is stopped - requested by server (%s)",
|
---|
505 | client->reader->label, typtext[client->stopped]);
|
---|
506 | return(-1);
|
---|
507 | }
|
---|
508 | else {
|
---|
509 | client->stopped = 0;
|
---|
510 | }
|
---|
511 | }
|
---|
512 |
|
---|
513 | client->lastsrvid = er->srvid;
|
---|
514 | client->lastcaid = er->caid;
|
---|
515 | client->lastpid = er->pid;
|
---|
516 |
|
---|
517 | if (client->is_udp) {
|
---|
518 | if (!client->udp_sa.sin_addr.s_addr || client->reader->last_s-client->reader->last_g > client->reader->tcp_rto)
|
---|
519 | if (!hostResolve(client->reader)) return -1;
|
---|
520 | }
|
---|
521 | else {
|
---|
522 | if (!tcp_connect()) return -1;
|
---|
523 | }
|
---|
524 |
|
---|
525 | client->reader->card_status = CARD_INSERTED; //for udp
|
---|
526 |
|
---|
527 | memset(buf, 0, 20);
|
---|
528 | memset(buf + 20, 0xff, er->l+15);
|
---|
529 | buf[1]=er->l;
|
---|
530 | memcpy(buf + 8, i2b(2, er->srvid), 2);
|
---|
531 | memcpy(buf + 10, i2b(2, er->caid ), 2);
|
---|
532 | memcpy(buf + 12, i2b(4, er->prid ), 4);
|
---|
533 | // memcpy(buf+16, i2b(2, er->pid ), 2);
|
---|
534 | // memcpy(buf+16, &er->idx , 2);
|
---|
535 | memcpy(buf + 16, i2b(2, er->idx ), 2);
|
---|
536 | buf[18] = 0xff;
|
---|
537 | buf[19] = 0xff;
|
---|
538 | memcpy(buf + 20, er->ecm , er->l);
|
---|
539 | return((camd35_send(buf) < 1) ? (-1) : 0);
|
---|
540 | }
|
---|
541 |
|
---|
542 | static int camd35_send_emm(EMM_PACKET *ep)
|
---|
543 | {
|
---|
544 | uchar buf[512];
|
---|
545 | struct s_client *cl = cur_client();
|
---|
546 |
|
---|
547 | if (cl->is_udp) {
|
---|
548 | if (!cl->udp_sa.sin_addr.s_addr || cl->reader->last_s-cl->reader->last_g > cl->reader->tcp_rto)
|
---|
549 | if (!hostResolve(cl->reader)) return -1;
|
---|
550 | }
|
---|
551 | else {
|
---|
552 | if (!tcp_connect()) return -1;
|
---|
553 | }
|
---|
554 |
|
---|
555 | memset(buf, 0, 20);
|
---|
556 | memset(buf+20, 0xff, ep->l+15);
|
---|
557 |
|
---|
558 | buf[0]=0x06;
|
---|
559 | buf[1]=ep->l;
|
---|
560 | memcpy(buf+10, ep->caid, 2);
|
---|
561 | memcpy(buf+12, ep->provid, 4);
|
---|
562 | memcpy(buf+20, ep->emm, ep->l);
|
---|
563 |
|
---|
564 | return((camd35_send(buf)<1) ? 0 : 1);
|
---|
565 | }
|
---|
566 |
|
---|
567 | static int camd35_recv_chk(struct s_client *client, uchar *dcw, int *rc, uchar *buf, int UNUSED(n))
|
---|
568 | {
|
---|
569 | ushort idx;
|
---|
570 | static const char *typtext[]={"ok", "invalid", "sleeping"};
|
---|
571 | struct s_reader *rdr = client->reader;
|
---|
572 |
|
---|
573 | // reading CMD05 Emm request and set serial
|
---|
574 | if (buf[0] == 0x05 && buf[1] == 111) {
|
---|
575 |
|
---|
576 | //cs_log("CMD05: %s", cs_hexdump(1, buf, buf[1]));
|
---|
577 | rdr->nprov = 0; //reset if number changes on reader change
|
---|
578 | rdr->nprov = buf[47];
|
---|
579 | rdr->caid = b2i(2, buf + 20);
|
---|
580 | rdr->auprovid = b2i(4, buf + 12);
|
---|
581 |
|
---|
582 | int i;
|
---|
583 | for (i=0; i<rdr->nprov; i++) {
|
---|
584 | if (((rdr->caid >= 0x1700) && (rdr->caid <= 0x1799)) || // Betacrypt
|
---|
585 | ((rdr->caid >= 0x0600) && (rdr->caid <= 0x0699))) // Irdeto (don't know if this is correct, cause I don't own a IRDETO-Card)
|
---|
586 | {
|
---|
587 | rdr->prid[i][0] = buf[48 + (i*5)];
|
---|
588 | memcpy(&rdr->prid[i][1], &buf[50 + (i * 5)], 3);
|
---|
589 | } else {
|
---|
590 | rdr->prid[i][2] = buf[48 + (i * 5)];
|
---|
591 | rdr->prid[i][3] = buf[49+ (i * 5)];
|
---|
592 | memcpy(&rdr->sa[i][0], &buf[50 + (i * 5)], 4);
|
---|
593 | }
|
---|
594 | }
|
---|
595 |
|
---|
596 | memcpy(rdr->hexserial, buf + 40, 6);
|
---|
597 | rdr->hexserial[6] = 0;
|
---|
598 | rdr->hexserial[7] = 0;
|
---|
599 |
|
---|
600 | rdr->blockemm_g = (buf[128]==1) ? 0: 1;
|
---|
601 | rdr->blockemm_s = (buf[129]==1) ? 0: 1;
|
---|
602 | rdr->blockemm_u = (buf[130]==1) ? 0: 1;
|
---|
603 | cs_log("%s CMD05 AU request for caid: %04X auprovid: %06lX",
|
---|
604 | rdr->label,
|
---|
605 | rdr->caid,
|
---|
606 | rdr->auprovid);
|
---|
607 | }
|
---|
608 |
|
---|
609 | if (buf[0] == 0x08 && !cfg.c35_suppresscmd08) {
|
---|
610 | if(buf[21] == 0xFF) {
|
---|
611 | client->stopped = 2; // server says sleep
|
---|
612 | rdr->card_status = NO_CARD;
|
---|
613 | } else {
|
---|
614 | if (!cfg.lb_mode) {
|
---|
615 | client->stopped = 1; // server says invalid
|
---|
616 | rdr->card_status = CARD_FAILURE;
|
---|
617 | }
|
---|
618 |
|
---|
619 | ECM_REQUEST *er_failed = malloc(sizeof(ECM_REQUEST));
|
---|
620 | memset(er_failed, 0, sizeof(ECM_REQUEST));
|
---|
621 | er_failed->srvid = b2i(2, buf + 8);
|
---|
622 | er_failed->caid = b2i(2, buf + 10);
|
---|
623 | er_failed->prid = b2i(4, buf + 12);
|
---|
624 | add_stat(rdr, er_failed, -1, 4);
|
---|
625 | free(er_failed);
|
---|
626 | }
|
---|
627 |
|
---|
628 | cs_log("%s CMD08 (%02X - %d) stop request by server (%s)",
|
---|
629 | rdr->label, buf[21], buf[21], typtext[client->stopped]);
|
---|
630 | }
|
---|
631 |
|
---|
632 | // CMD44: old reject command introduced in mpcs
|
---|
633 | // keeping this for backward compatibility
|
---|
634 | if ((buf[0] != 1) && (buf[0] != 0x44) && (buf[0] != 0x08))
|
---|
635 | return(-1);
|
---|
636 |
|
---|
637 | idx = b2i(2, buf+16);
|
---|
638 |
|
---|
639 | *rc = ((buf[0] != 0x44) && (buf[0] != 0x08));
|
---|
640 |
|
---|
641 | memcpy(dcw, buf+20, 16);
|
---|
642 | return(idx);
|
---|
643 | }
|
---|
644 |
|
---|
645 | static int camd35_recv_log(ushort *caid, ulong *provid, ushort *srvid)
|
---|
646 | {
|
---|
647 | int i;
|
---|
648 | uchar buf[512], *ptr, *ptr2;
|
---|
649 | ushort idx=0;
|
---|
650 | if (!logfd) return(-1);
|
---|
651 | if ((i=recv(logfd, buf, sizeof(buf), 0))<=0) return(-1);
|
---|
652 | buf[i]=0;
|
---|
653 |
|
---|
654 | if (!(ptr=(uchar *)strstr((char *)buf, " -> "))) return(-1);
|
---|
655 | ptr+=4;
|
---|
656 | if (strstr((char *)ptr, " decoded ")) return(-1); // skip "found"s
|
---|
657 | if (!(ptr2=(uchar *)strchr((char *)ptr, ' '))) return(-1); // corrupt
|
---|
658 | *ptr2=0;
|
---|
659 |
|
---|
660 | for (i=0, ptr2=(uchar *)strtok((char *)ptr, ":"); ptr2; i++, ptr2=(uchar *)strtok(NULL, ":"))
|
---|
661 | {
|
---|
662 | trim((char *)ptr2);
|
---|
663 | switch(i)
|
---|
664 | {
|
---|
665 | case 0: *caid =cs_atoi((char *)ptr2, strlen((char *)ptr2)>>1, 0); break;
|
---|
666 | case 1: *provid=cs_atoi((char *)ptr2, strlen((char *)ptr2)>>1, 0); break;
|
---|
667 | case 2: *srvid =cs_atoi((char *)ptr2, strlen((char *)ptr2)>>1, 0); break;
|
---|
668 | case 3: idx =cs_atoi((char *)ptr2, strlen((char *)ptr2)>>1, 0); break;
|
---|
669 | }
|
---|
670 | if (errno) return(-1);
|
---|
671 | }
|
---|
672 | return(idx&0x1FFF);
|
---|
673 | }
|
---|
674 |
|
---|
675 | /*
|
---|
676 | * module definitions
|
---|
677 | */
|
---|
678 |
|
---|
679 | void module_camd35(struct s_module *ph)
|
---|
680 | {
|
---|
681 | static PTAB ptab; //since there is always only 1 camd35 server running, this is threadsafe
|
---|
682 | ptab.ports[0].s_port = cfg.c35_port;
|
---|
683 | ph->ptab = &ptab;
|
---|
684 | ph->ptab->nports = 1;
|
---|
685 |
|
---|
686 | strcpy(ph->desc, "camd35");
|
---|
687 | ph->type=MOD_CONN_UDP;
|
---|
688 | ph->multi=1;
|
---|
689 | ph->watchdog=1;
|
---|
690 | ph->s_ip=cfg.c35_srvip;
|
---|
691 | ph->s_handler=camd35_server;
|
---|
692 | ph->recv=camd35_recv;
|
---|
693 | ph->send_dcw=camd35_send_dcw;
|
---|
694 | ph->c_multi=1;
|
---|
695 | ph->c_init=camd35_client_init;
|
---|
696 | ph->c_recv_chk=camd35_recv_chk;
|
---|
697 | ph->c_send_ecm=camd35_send_ecm;
|
---|
698 | ph->c_send_emm=camd35_send_emm;
|
---|
699 | ph->c_init_log=camd35_client_init_log;
|
---|
700 | ph->c_recv_log=camd35_recv_log;
|
---|
701 | ph->num=R_CAMD35;
|
---|
702 | }
|
---|
703 |
|
---|
704 | void module_camd35_tcp(struct s_module *ph)
|
---|
705 | {
|
---|
706 | strcpy(ph->desc, "cs378x");
|
---|
707 | ph->type=MOD_CONN_TCP;
|
---|
708 | ph->multi=1;
|
---|
709 | ph->watchdog=1;
|
---|
710 | ph->ptab=&cfg.c35_tcp_ptab;
|
---|
711 | if (ph->ptab->nports==0)
|
---|
712 | ph->ptab->nports=1; // show disabled in log
|
---|
713 | ph->s_ip=cfg.c35_tcp_srvip;
|
---|
714 | ph->s_handler=camd35_server;
|
---|
715 | ph->recv=camd35_recv;
|
---|
716 | ph->send_dcw=camd35_send_dcw;
|
---|
717 | ph->c_multi=1;
|
---|
718 | ph->c_init=camd35_client_init;
|
---|
719 | ph->c_recv_chk=camd35_recv_chk;
|
---|
720 | ph->c_send_ecm=camd35_send_ecm;
|
---|
721 | ph->c_send_emm=camd35_send_emm;
|
---|
722 | ph->c_init_log=camd35_client_init_log;
|
---|
723 | ph->c_recv_log=camd35_recv_log;
|
---|
724 | ph->num=R_CS378X;
|
---|
725 | }
|
---|