Scapy: how do I get the full IP packet header?

Viewed 10320

In Scapy, I want to manually match packets with their corresponding ICMP time-exceeded messages.

I need to match:

  • IP-in-ICMP field of ICMP packet
  • IP header and first 8 bytes of my data packet The ICMP packet isn't a problem:

    icmpPayload = str(icmpPacket[ICMP].payload)

As for the first 8 bytes of the data packet, I just need to do:

str(myPacket[IP].payload)[:8]

I don't know how to get only the IP header of myPacket. All I do now is replace the payload in the whole packet with its first 8 bytes. This search and replace, if applied to thousands of packets, might take too long, I'm afraid:

 strOfMyPacket = str(myPacket[IP])
 strOfMyPacket.replace(str(myPacket[IP].payload),str(myPacket[IP].payload)[:8],1)

Any faster way that will let me do simply the following?

 partOfPayload = str(myPacket[IP].payload)[:8]
 fullHeader = _______
 stringToCompare = fullHeader + partOfPayload
3 Answers

by :

hex_string = linehexdump(paket,onlyhex=1,dump=True)
tokens = hex_string.split(' ')
hex  = ''.join(tokens[20:24])

, we can get the hex string and parse it manually. In my case, I have patched 4 bytes of data to the options field on the switch. I knew that it was in bytes 20 to 24. After parsing we can get the value.

Related