// Ghidra headless Java script: Decompile nflxDhDerive and related functions // @category Analysis import ghidra.app.decompiler.DecompInterface; import ghidra.app.decompiler.DecompileResults; import ghidra.app.script.GhidraScript; import ghidra.program.model.address.Address; import ghidra.program.model.listing.Function; import ghidra.program.model.listing.FunctionManager; import java.io.FileWriter; import java.io.PrintWriter; public class DecompileNflxDhDerive extends GhidraScript { @Override protected void run() throws Exception { String outputPath = "/tmp/nflxDhDerive_decompiled.c"; long[] addresses = { 0x0000FEECL, 0x0000FDE8L, 0x0000D7E0L }; String[] descriptions = { "nflxDhDerive (main, vector variant)", "nflxDhDerive (DataBuffer variant)", "AppleNativeKey::getBytes()" }; DecompInterface decomp = new DecompInterface(); decomp.openProgram(currentProgram); FunctionManager fm = currentProgram.getFunctionManager(); PrintWriter out = new PrintWriter(new FileWriter(outputPath)); out.println("// NFWebCrypto nflxDhDerive decompiled pseudocode"); out.println("// Binary: NFWebCrypto.framework/NFWebCrypto (arm64)"); out.println("// Generated by Ghidra headless decompiler"); out.println(); for (int i = 0; i < addresses.length; i++) { Address addr = currentProgram.getAddressFactory() .getDefaultAddressSpace().getAddress(addresses[i]); Function func = fm.getFunctionAt(addr); if (func == null) { func = fm.getFunctionContaining(addr); } if (func == null) { out.printf("// Function not found at 0x%08x (%s)%n%n", addresses[i], descriptions[i]); println("WARNING: Function not found at 0x" + Long.toHexString(addresses[i])); continue; } DecompileResults result = decomp.decompileFunction(func, 120, monitor); if (result.decompileCompleted()) { String code = result.getDecompiledFunction().getC(); out.printf("// === %s ===%n", descriptions[i]); out.printf("// Address: 0x%08x%n", addresses[i]); out.printf("// Function: %s%n", func.getName()); out.println(code); out.println(); println("OK: Decompiled " + func.getName() + " at 0x" + Long.toHexString(addresses[i])); } else { out.printf("// FAILED to decompile at 0x%08x (%s)%n%n", addresses[i], descriptions[i]); println("FAILED: Could not decompile at 0x" + Long.toHexString(addresses[i])); } } out.close(); decomp.dispose(); println("Output written to: " + outputPath); } }