Where communities thrive

  • Join over 1.5M+ people
  • Join over 100K+ communities
  • Free without limits
  • Create your own community
Repo info
    .encode incorrectly changes the intended stream bytes
    \xaa \xaa
    You are missing the b'' !!!!
    You are converting a wrong string to wrong bytes
    this is python 3
    it's working just fine
    In [9]: stream
    Out[9]: '\xaa\xaa\x03\x00\x00\x00\x08\x00E\x00\x00T\x00\x00@\x00@\x01\xf0;\xc0\xa8d\x88\xc0\xa8d\x94\x08\x00\x9de\xc7\x06\x00\x00\x9c\xd9\xf6\xb9\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
    In [10]: stream.encode()
    UnicodeDecodeError                        Traceback (most recent call last)
    <ipython-input-10-db32f268970b> in <module>()
    ----> 1 stream.encode()
    UnicodeDecodeError: 'ascii' codec can't decode byte 0xaa in position 0: ordinal not in range(128)
    I also cannot use "bytes" with respect to WEP or WPA decryption, at least not using the methods and techniques I did with Python2.
    Yes you should use bytes. You cannot not use bytes on Python 3
    Alright, I'll read it.

    Hmm. I'd go so far as to say this is a deeper issue

    >>> print(chr(0xaa).encode())

    At least now I understand why Python2 and Python3 have differences with hexstr()

    This explains where the extra chars come in at...:
    hexstr(x, onlyhex = 1)                                                                                                                                                                                     
    Out[8]: 'C2 AA C2
    So yes, I will agree scapy is doing what Python3 is instructing it to do, which sadly means there is no PEP style fix for this =(
    However, some hackery based off hexstr itself and we've fixed the flaw
    newStream = []
    newStream.append(" ".join(map(lambda stream:"%02x"%ord(stream), stream)))
    newStream = "  ".join(newStream)
    Anywho, I'll be quiet now and let that soak, cheers!
    Scapy can't process 802.11ax frames when radiotap header has HE_MU field.
    pkt.show() function returns raw bytes, we can't access layers or fields since no layer defined for that frame. Is there a way to access some fields when this is the case?
    2 replies
    Would anyone here be interested in a workshop on how to leverage scapy for 802.11 concepts? Encryption/Decryption/etc.
    Leonard Crestez
    Gentle ping for secdev/scapy#3358 again? It's fully tested but did not receive any review comments
    Eyni, Kave

    Decrypt SSL/TSL with specific Private Key

    I have the original certificate, and I want to show HTTPS sniffed traffic in plaint UTF-8 text

    For example, in HTTP traffic we can use this code:
    readable_payload = bytes(packet[TCP].payload).decode('UTF8','replace')

    But for HTTPS this just show unreadable random characters.

    I was read ant test below resources, But not useful:

    I want a clean solution like this article that use TSHARK , But I must use SCAPY because I spent too much time on develop my firewall with scapy:

    Hi people, around possible ways to do pcap file parsing speed improvements: is there a way to unload L2 protocol types? so capture only focus on applying parsers to the packet, that are known before hand that are applicable? (so instead of checking for ethernet, 802.11, BLE, etc it only applies 802.11 and everything else is returned as RAW)
    Hello @jacontre-c -- Here is an example where I do what you speak of, but not necessarily L2; you'll have to trace and replace accordingly.
    2 replies
    Hi all, looking at the _IP6PrefixField class in layers.inet6 I noticed the field length gets calculated as the length of the remainder of the packet. Am I reading this correctly, or is there another way of indicating this fields length? If not, this behaviour might fail in situations where this field is not the last field in the packet
    Leonard Crestez
    how do I make p.sprintf("%IPv6.nh%") appear as numeric?
    type(p[IPV6].nh) is a number nut I don't understand how sprintf is different
    apparently p.sprintf("%r,IPV6.nh%") does the job but not p.sprintf("%d,IPV6.nh%")
    Sabry Tarek
    Hello folks, I want to save all domains that the user opened in the web browser. I tried to use Scapy but I get only HTTP requests.
    Hi peeps how do we sniff eapol frames? I tried sniffing and set lfilter to lambda x: EAPOL in x
    1 reply
    And used my android phone to disconnect and reconnect
    But nothing captured
    Matt Keeter
    Weird question for folks: should I expect Scapy to detect UDP echo messages that have raw data attached to them?
    If I do something like sr(IPv6(dst="fe80::4:6ff:fe08:a0c") / UDP(dport=7)), then I get a packet back immediately (and see the whole thing in tcpdump)
    However, sr(IPv6(dst="fe80::4:6ff:fe08:a0c") / UDP(dport=7) / Raw("hello, world")) hangs forever
    despite seeing the reply come in in tcpdump:
    tcpdump: listening on enp0s25, link-type EN10MB (Ethernet), capture size 262144 bytes
    22:40:05.414261 94:c6:91:15:77:b9 > 02:04:06:08:0a:0c, ethertype IPv6 (0x86dd), length 74: (hlim 64, next-header UDP (17) payload length: 20) fe80::96c6:91ff:fe15:77b9.53 > fe80::4:6ff:fe08:a0c.7: [udp sum ok] 26725 updateMA [b2&3=0x6c6c] [8311a] [28460q] [28530n] [27748au][|domain]
        0x0000:  6000 0000 0014 1140 fe80 0000 0000 0000  `......@........
        0x0010:  96c6 91ff fe15 77b9 fe80 0000 0000 0000  ......w.........
        0x0020:  0004 06ff fe08 0a0c 0035 0007 0014 148f  .........5......
        0x0030:  6865 6c6c 6f2c 2077 6f72 6c64            hello,.world
    22:40:05.446570 02:04:06:08:0a:0c > 94:c6:91:15:77:b9, ethertype IPv6 (0x86dd), length 74: (hlim 64, next-header UDP (17) payload length: 20) fe80::4:6ff:fe08:a0c.7 > fe80::96c6:91ff:fe15:77b9.53: [udp sum ok] 26725 updateMA [b2&3=0x6c6c] [8311a] [28460q] [28530n] [27748au][|domain]
        0x0000:  6000 0000 0014 1140 fe80 0000 0000 0000  `......@........
        0x0010:  0004 06ff fe08 0a0c fe80 0000 0000 0000  ................
        0x0020:  96c6 91ff fe15 77b9 0007 0035 0014 148f  ......w....5....
        0x0030:  6865 6c6c 6f2c 2077 6f72 6c64            hello,.world
    Oh, I wonder if it's because it's using port 53 by default, which may be... special (since that's the port for DNS)
    Yeah, using sport=2000 seems to work
    hi there im new to scappy and had a conceptual question about layer binding
    i want to add a layer beneath USBPcap. for example sake lets just have one field as a byte. later based on that byte i will bind layers below that. but how do i bind that first layer to the upper layer? i want to be greedy and bind any USBPCap.function ==9, but i cant just say bind_layer(USBPcap,DAP_CMD,function==9) becasue its not in scope
    or i could reread the documentation and notice its a single = not a ==
    ok still churning away at this but not getting very far. ive narrowed it down to a minimal working example that i think should disect as a DAP_CMD but still is decoded as RAW.
    from scapy.all import PcapReader,Packet,bind_layers,ByteField
    from scapy.layers.usb import USBpcap
    class DAP_CMD(Packet):
        name = "DapCMD "
        field_desc= [ByteField("cmd",0)]
    bind_layers(USBpcap,DAP_CMD, endpoint=2)    
    p = b'\x1b\x00\xa0\t\xd6\xe2\x88\xb6\xff\xff\x00\x00\x00\x00\t\x00\x00\x01\x00\x0b\x00\x02\x01@\x00\x00\x00\x00\x03\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
    pak = USBpcap(p)
    ###[ USBpcap URB ]### 
      headerLen = 27
      res       = 0
      irpId     = 0xffffb688e2d609a0
      usbd_status= Success
      info      = 0x0
      bus       = 1
      device    = 11
      endpoint  = 0x2
      transfer  = Interrupt
      dataLength= 64
    ###[ Raw ]###
         load      = '\x00\x03\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
    am i using bind_layers incorrectly?
    hey lately im diving deep into the scapy automaton class and i found something i dont know how to use it. The "state_output" varibales (or return vales in "@ATMT.state" marked functions. What was the idea behind implementing it? Im trying to think of a good use case where i can use this instead of directly handling the event (which leads to the return value) in the state itself
    i've got a pcapng file with a single TCP stream captured mid-stream. I'm wondering if I can use scapy to create a PCAP with a faked-out 3-way handshake prior to the rest of the packets to make it look like i've got the beginning of the connection. any reason this shouldn't be possible?
    1 reply

    I'm getting an error when trying to read a pcap, alter source and destination IP and mac addresses, then write the altered packets into a new PCAP.
    When just doing IP it generates ok, but fails to parse properly in wireshark (I suspect because of the mac addresses still being tied to localhost, need to prove this out).
    When I attempt to set the MAC addresses too, I get the error:

    Traceback (most recent call last):
      File "/usr/local/lib/python3.10/site-packages/scapy/fields.py", line 758, in h2i
    OSError: illegal IP address string passed to inet_aton
    During handling of the above exception, another exception occurred:
    socket.gaierror: [Errno 8] nodename nor servname provided, or not known

    The code I'm using to try this is here:

    packets = rdpcap("./baddcode-csirtFlag.pcapng")
    for pkt in packets:
        if pkt[TCP].dport == 12345:
            pkt[IP].dst = ""
            pkt[IP].src = ""
            pkt[0].src = '3c:22:fb:94:02:9e' # pretty sure this changes the ethernet address
            pkt[0].dst = 'e4:8d:8c:2b:2:ab' # pretty sure this changes the ethernet address
            pkt[IP].dst = ""
            pkt[IP].src = ""
            pkt[0].dst = '3c:22:fb:94:02:9e' # pretty sure this changes the ethernet address
            pkt[0].src = 'e4:8d:8c:2b:2:ab' # pretty sure this changes the ethernet address
    wrpcap("./baddcode-CSIRT-ipFix.pcap", packets)
    wireshark("./baddcode-CSIRT-ipFix.pcap", packets)

    Code and sample pcaps are here:

    complete error is:

    luke.pearson@lukepearso-ltm BADDEC0DE % python3 scapyFix.py
    WARNING: No IPv4 address found on en5 !
    WARNING: No IPv4 address found on ap1 !
    WARNING: more No IPv4 address found on awdl0 !
    Traceback (most recent call last):
      File "/usr/local/lib/python3.10/site-packages/scapy/fields.py", line 758, in h2i
    OSError: illegal IP address string passed to inet_aton
    During handling of the above exception, another exception occurred:
    Traceback (most recent call last):
      File "/Users/luke.pearson/Library/CloudStorage/OneDrive-Personal/BADDEC0DE/scapyFix.py", line 14, in <module>
        pkt[0].src = '3c:22:fb:94:02:9e'
      File "/usr/local/lib/python3.10/site-packages/scapy/packet.py", line 463, in __setattr__
        return self.setfieldval(attr, val)
      File "/usr/local/lib/python3.10/site-packages/scapy/packet.py", line 454, in setfieldval
        self.payload.setfieldval(attr, val)
      File "/usr/local/lib/python3.10/site-packages/scapy/packet.py", line 445, in setfieldval
        self.fields[attr] = any2i(self, val)
      File "/usr/local/lib/python3.10/site-packages/scapy/fields.py", line 793, in any2i
        return self.h2i(pkt, x)
      File "/usr/local/lib/python3.10/site-packages/scapy/fields.py", line 760, in h2i
        return Net(x)
      File "/usr/local/lib/python3.10/site-packages/scapy/base_classes.py", line 162, in __init__
        self.start = self.ip2int(net) >> inv_mask << inv_mask
      File "/usr/local/lib/python3.10/site-packages/scapy/base_classes.py", line 140, in ip2int
        "!I", socket.inet_aton(cls.name2addr(addr))
      File "/usr/local/lib/python3.10/site-packages/scapy/base_classes.py", line 127, in name2addr
        socket.getaddrinfo(name, None, cls.family)
      File "/usr/local/Cellar/python@3.10/3.10.1/Frameworks/Python.framework/Versions/3.10/lib/python3.10/socket.py", line 955, in getaddrinfo
        for res in _socket.getaddrinfo(host, port, family, type, proto, flags):
    socket.gaierror: [Errno 8] nodename nor servname provided, or not known

    Grateful for any help you can offer, completely accept I've probably missed something obvious, but I did try google first, I promise.

    1 reply
    Hi everyone :)
    I try to use the scapy DSL as a manipulable developpement model