mirror of
https://github.com/qtmleap/revkit.git
synced 2026-09-30 23:11:51 +02:00
SHA384(native_key_bytes) → 48B鍵 → HMAC-SHA384(key, 0x00||DH_shared) → enc/sign/wrap鍵分割 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
70 lines
2.8 KiB
Java
70 lines
2.8 KiB
Java
// Ghidra headless Java script: Decompile nflxDhDerive and related functions
|
|
// @category Analysis
|
|
|
|
import ghidra.app.decompiler.DecompInterface;
|
|
import ghidra.app.decompiler.DecompileResults;
|
|
import ghidra.app.script.GhidraScript;
|
|
import ghidra.program.model.address.Address;
|
|
import ghidra.program.model.listing.Function;
|
|
import ghidra.program.model.listing.FunctionManager;
|
|
|
|
import java.io.FileWriter;
|
|
import java.io.PrintWriter;
|
|
|
|
public class DecompileNflxDhDerive extends GhidraScript {
|
|
|
|
@Override
|
|
protected void run() throws Exception {
|
|
String outputPath = "/tmp/nflxDhDerive_decompiled.c";
|
|
|
|
long[] addresses = { 0x0000FEECL, 0x0000FDE8L, 0x0000D7E0L };
|
|
String[] descriptions = {
|
|
"nflxDhDerive (main, vector variant)",
|
|
"nflxDhDerive (DataBuffer variant)",
|
|
"AppleNativeKey::getBytes()"
|
|
};
|
|
|
|
DecompInterface decomp = new DecompInterface();
|
|
decomp.openProgram(currentProgram);
|
|
FunctionManager fm = currentProgram.getFunctionManager();
|
|
|
|
PrintWriter out = new PrintWriter(new FileWriter(outputPath));
|
|
out.println("// NFWebCrypto nflxDhDerive decompiled pseudocode");
|
|
out.println("// Binary: NFWebCrypto.framework/NFWebCrypto (arm64)");
|
|
out.println("// Generated by Ghidra headless decompiler");
|
|
out.println();
|
|
|
|
for (int i = 0; i < addresses.length; i++) {
|
|
Address addr = currentProgram.getAddressFactory()
|
|
.getDefaultAddressSpace().getAddress(addresses[i]);
|
|
Function func = fm.getFunctionAt(addr);
|
|
if (func == null) {
|
|
func = fm.getFunctionContaining(addr);
|
|
}
|
|
if (func == null) {
|
|
out.printf("// Function not found at 0x%08x (%s)%n%n", addresses[i], descriptions[i]);
|
|
println("WARNING: Function not found at 0x" + Long.toHexString(addresses[i]));
|
|
continue;
|
|
}
|
|
|
|
DecompileResults result = decomp.decompileFunction(func, 120, monitor);
|
|
if (result.decompileCompleted()) {
|
|
String code = result.getDecompiledFunction().getC();
|
|
out.printf("// === %s ===%n", descriptions[i]);
|
|
out.printf("// Address: 0x%08x%n", addresses[i]);
|
|
out.printf("// Function: %s%n", func.getName());
|
|
out.println(code);
|
|
out.println();
|
|
println("OK: Decompiled " + func.getName() + " at 0x" + Long.toHexString(addresses[i]));
|
|
} else {
|
|
out.printf("// FAILED to decompile at 0x%08x (%s)%n%n", addresses[i], descriptions[i]);
|
|
println("FAILED: Could not decompile at 0x" + Long.toHexString(addresses[i]));
|
|
}
|
|
}
|
|
|
|
out.close();
|
|
decomp.dispose();
|
|
println("Output written to: " + outputPath);
|
|
}
|
|
}
|