rockbox/utils/nwztools/upgtools/mg.cpp
Amaury Pouly 37f95f67fe nwztools/upgtools: rewrite keysig brute force search
The new search has two new features:
- it takes advantage of the fact that DES keys are only 56-bit long (and not 64)
- it is now multithreaded
As a proof of concept, I ran it on the A10 series firmware upgrade and was able
to find the key in a few seconds using 4 threads. The search is still limited
to ascii hex passwords (seems to work on all devices I have tried thus far).

Change-Id: Ied080286d2bbdc493a6ceaecaaadba802b429666
2016-10-27 23:06:16 +02:00

70 lines
2.1 KiB
C++

/***************************************************************************
* __________ __ ___.
* Open \______ \ ____ ____ | | _\_ |__ _______ ___
* Source | _// _ \_/ ___\| |/ /| __ \ / _ \ \/ /
* Jukebox | | ( <_> ) \___| < | \_\ ( <_> > < <
* Firmware |____|_ /\____/ \___ >__|_ \|___ /\____/__/\_ \
* \/ \/ \/ \/ \/
* $Id$
*
* Copyright (C) 2012 Amaury Pouly
*
* This program is free software; you can redistribute it and/or
* modify it under the terms of the GNU General Public License
* as published by the Free Software Foundation; either version 2
* of the License, or (at your option) any later version.
*
* This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
* KIND, either express or implied.
*
****************************************************************************/
#include "mg.h"
#include <crypto++/cryptlib.h>
#include <crypto++/modes.h>
#include <crypto++/des.h>
#include <crypto++/aes.h>
#include <stdio.h>
using namespace CryptoPP;
namespace
{
inline int dec_des_ecb(void *in, int size, void *out, uint8_t *key)
{
ECB_Mode< DES >::Decryption dec;
if(size % 8)
return 42;
dec.SetKey(key, 8);
dec.ProcessData((byte*)out, (byte*)in, size);
return 0;
}
inline int enc_des_ecb(void *in, int size, void *out, uint8_t *key)
{
ECB_Mode< DES >::Encryption enc;
if(size % 8)
return 42;
enc.SetKey(key, 8);
enc.ProcessData((byte*)out, (byte*)in, size);
return 0;
}
}
int mg_decrypt_fw(void *in, int size, void *out, uint8_t *key)
{
return dec_des_ecb(in, size, out, key);
}
int mg_encrypt_fw(void *in, int size, void *out, uint8_t *key)
{
return enc_des_ecb(in, size, out, key);
}
int mg_decrypt_pass(void *in, int size, void *out, uint8_t *key)
{
return dec_des_ecb(in, size, out, key);
}
int mg_encrypt_pass(void *in, int size, void *out, uint8_t *key)
{
return enc_des_ecb(in, size, out, key);
}