Class: BetterCap::Parsers::Wol

Inherits:
Base
  • Object
show all
Defined in:
lib/bettercap/sniffer/parsers/wol.rb

Overview

Instance Method Summary collapse

Methods inherited from Base

available, from_cmdline, from_exclusion_list, inherited, load_by_names, load_custom, #match_port?

Constructor Details

#initialize ⇒ Wol

Returns a new instance of Wol.



31
32
33
# File 'lib/bettercap/sniffer/parsers/wol.rb', line 31

def initialize
  @name = 'WOL'
end

Instance Method Details

#on_packet(pkt) ⇒ Object



35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
# File 'lib/bettercap/sniffer/parsers/wol.rb', line 35

def on_packet( pkt )
  return unless is_wol? pkt

  # Split packet into chunks of 6 bytes each.
  data = pkt.payload.to_s.unpack('H*').first.chars.each_slice(12).map(&:join)

  # The Synchronization Stream field is 6 bytes of FF
  # sync_stream = data[0]

  # The Target MAC block contains the target's MAC address
  # repeated 16 times (96 bytes)
  return unless data[1..16].uniq.size == 1

  # Format MAC address for output
  mac = data[1].upcase.scan(/\w{2}/).join(':')

  # The Password field is optional (0, 4 or 6 bytes).
  password = data[17] || 'none'

  StreamLogger.log_raw( pkt, @name, "#{'mac'.blue}=#{mac} #{'password'.blue}=#{password}" )
rescue
end