[C#] Capture loopback packets

Joined
Feb 22, 2008
Messages
2,427
Reaction score
757
I spent a lot of time searching about it and couldnt find anything. Tried every solution I've found to Winpcap but it didnt work, found one exe named RawCap but I can not "inherit" it in my app so I can filter packets, decrypt them and show it.

Is there any other library for this purpose that I am missing?
 
No. There is no API in windows that permits you to capture loopback traffic.

You would have to make a winsock layered service provider, give it the highest priority, then listen to traffic that way, or do something in kernel mode or by instrumenting the software to dump the data from send/recv calls.

Layered Service Provider - Wikipedia, the free encyclopedia

I made a LSP once but I'm not sure if it can monitor loopback traffic (though it should).
 
what about hooking the winsock functions of the process? I tried a long time ago to create hooks in c# but I couldnt manage them to work. found several libraries, but they didnt work properly. I can do in C++ but I'd have to translate all the decrypt packets function to c++ and I'm not that good with c++. can you guide me in c# hooks?
 
what about hooking the winsock functions of the process? I tried a long time ago to create hooks in c# but I couldnt manage them to work. found several libraries, but they didnt work properly. I can do in C++ but I'd have to translate all the decrypt packets function to c++ and I'm not that good with c++. can you guide me in c# hooks?

You'd need to have hooks go to a marshalling function for calls back into C# to work properly. Hooking in a non-native language has issues, since hooking in C (hotpatching and other methods) require massive assumptions about both the caller, the callee, and the structure of the function to receive control.

I'm working on a framework that will allow REPL hooking via Javascript using a basic hook-based binary instrumentation toolkit I'm also developing (along with a very basic generic binary instrumentation framework for real-time taint tracing both forwards and backwards). It's a lot of work.
 
I just found out that you can use 'localhost.' instead of 'localhost' and the system will route the traffic through the regular network stack rather than the special loopback interface. Raw sniffing looks like it should work, too. So if you want to use Wireshark, you can probably use that localhost trick.
 
The mysteries of the windows TCP/IP stack. Nobody really knows.

I'm getting the impression Microsoft developers aren't required to document anything they do. Between undocumented socket options, LSPs and PE structures, it seems as if consulting OllyDbg would be faster than finding answers on MSDN.
 
Back