Adds WinDivert support to Windows builds #3402
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Make sure these boxes are signed before submitting your Pull Request -- thank you.
Link to redmine ticket: https://redmine.openinfosecfoundation.org/issues/2455
Describe changes:
Enables IPS functionality on Windows using the open-source
(LGPLv3/GPLv2) WinDivert driver and API. Special thanks to @basil00
for dual-licensing WinDivert for this project.
From https://www.reqrypt.org/windivert-doc.html : "WinDivert is a
user-mode capture/sniffing/modification/blocking/re-injection package
for Windows Vista, Windows Server 2008, Windows 7, and Windows 8.
WinDivert can be used to implement user-mode packet filters, packet
sniffers, firewalls, NAT, VPNs, tunneling applications, etc., without
the need to write kernel-mode code."
--windivert [filter string]
and--windivert-forward [filter string]
command-line options to enable WinDivert IPS mode.--windivert[-forward] true
will open a filter for all traffic. Seehttps://www.reqrypt.org/windivert-doc.html#filter_language for more
information.
Limitation: currently limited to
autofp
runmode.Additionally:
tmm_modules
now zeroed duringRegisterAllModules
inet_ntop
call inPrintInet
GetRandom
bug (nonexistent keys) on fresh Windows installsRandomGetClock
building on Windows buildsThis is a replacement for #3374