Windows System Software -- Consulting, Training, Development -- Unique Expertise, Guaranteed Results

Home NTDEV

Before Posting...

Please check out the Community Guidelines in the Announcements and Administration Category.

More Info on Driver Writing and Debugging


The free OSR Learning Library has more than 50 articles on a wide variety of topics about writing and debugging device drivers and Minifilters. From introductory level to advanced. All the articles have been recently reviewed and updated, and are written using the clear and definitive style you've come to expect from OSR over the years.


Check out The OSR Learning Library at: https://www.osr.com/osr-learning-library/


Facing problem in wfp local proxy

v_kalv_kal Member Posts: 6

Hello experts,
I am writing a local proxy. I am getting responce from the server to the socket in the proxy and also I have send the response to the client socket. But it loads the website sometimes and sometime it just buffering or show can't reach the website. what am I missing in this proxy application.

In this I have redirected the traffic from WFP at FWPM_LAYER_ALE_AUTH_CONNECT_REDIRECT_V4 layer to my proxy.
In the proxy I have created a listening socket, bind it, listen on it and accept connection in a loop. And called the following function in loop.

`

#define CONTEXT_SIZE 2048
#define RECORDS_SIZE 4096
#define BUFFER_SIZE 20480

void proxyClientToServer(SOCKET clientSock)
{
    // Retrieve the redirect context
    BYTE redirectContext[CONTEXT_SIZE];
    BYTE redirectRecords[RECORDS_SIZE];
    DWORD bytesReturned;
    memset(redirectContext, 0, CONTEXT_SIZE);

WSAIoctl(clientSock, SIO_QUERY_WFP_CONNECTION_REDIRECT_CONTEXT, NULL, 0, redirectContext, CONTEXT_SIZE, &bytesReturned, NULL, NULL);

// Extract original destination IP and port from the context
SOCKADDR_IN originalDestAddr;
memcpy(&originalDestAddr.sin_port, redirectContext + sizeof(USHORT), sizeof(USHORT));
memcpy(&originalDestAddr.sin_addr, redirectContext + sizeof(ULONG), sizeof(ULONG));

// Retrieve the existing redirect records
WSAIoctl(clientSock, SIO_QUERY_WFP_CONNECTION_REDIRECT_RECORDS, NULL, 0, redirectRecords, RECORDS_SIZE, &bytesReturned, NULL, NULL);

// Create a socket for the server
SOCKET serverSock = WSASocket(AF_INET, SOCK_STREAM, 0, NULL, 0, WSA_FLAG_OVERLAPPED); // socket(AF_INET, SOCK_STREAM, 0);

// Set the redirect records on the socket
WSAIoctl(serverSock, SIO_SET_WFP_CONNECTION_REDIRECT_RECORDS, redirectRecords, sizeof(redirectRecords), NULL, 0, &bytesReturned, NULL, NULL);

// Connect to the server
SOCKADDR_IN serverAddr;
serverAddr.sin_family = AF_INET;
serverAddr.sin_addr = originalDestAddr.sin_addr; 
serverAddr.sin_port = originalDestAddr.sin_port; 

connect(serverSock, (SOCKADDR*)&serverAddr, sizeof(serverAddr));

int time = 5000;
setsockopt(clientSock, SOL_SOCKET, SO_RCVTIMEO, (char*)&time, sizeof(time)) ;

// Proxy data from client to server
char buffer[BUFFER_SIZE];
int bytesRead;
while ((bytesRead = recv(clientSock, buffer, BUFFER_SIZE, 0)) > 0)
{
    printf("Received request to client:\n");
    send(serverSock, buffer, bytesRead, 0);    //Send reques to the server

    // Receive the response from the server
    char buff[BUFFER_SIZE];
    int bytesReceived = recv(serverSock, buff, BUFFER_SIZE, 0);
    if (bytesReceived > 0)
    {
        // Forward the response back to the client
        if (send(clientSock, buff, bytesReceived, 0) == SOCKET_ERROR)
        {
            printf("Failed to send response to client: %ld\n", WSAGetLastError());
            break;
        }
    }
}
closesocket(serverSock);

}`

I have did all the error handlings but to reduce the code I removed it.

Sign In or Register to comment.

Howdy, Stranger!

It looks like you're new here. Sign in or register to get started.

Upcoming OSR Seminars
OSR has suspended in-person seminars due to the Covid-19 outbreak. But, don't miss your training! Attend via the internet instead!
Internals & Software Drivers 19-23 June 2023 Live, Online
Writing WDF Drivers 10-14 July 2023 Live, Online
Kernel Debugging 16-20 October 2023 Live, Online
Developing Minifilters 13-17 November 2023 Live, Online