Files
revkit/tools/re/DecompileNflxDhDerive.java
T
tkgstratorandClaude Opus 4.6 a9cb32b8e5 docs(spec): nflxDhDerive静的解析で48B HMAC鍵の導出チェーンを特定
SHA384(native_key_bytes) → 48B鍵 → HMAC-SHA384(key, 0x00||DH_shared) → enc/sign/wrap鍵分割

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-08 18:09:29 +00:00

70 lines
2.8 KiB
Java

// Ghidra headless Java script: Decompile nflxDhDerive and related functions
// @category Analysis
import ghidra.app.decompiler.DecompInterface;
import ghidra.app.decompiler.DecompileResults;
import ghidra.app.script.GhidraScript;
import ghidra.program.model.address.Address;
import ghidra.program.model.listing.Function;
import ghidra.program.model.listing.FunctionManager;
import java.io.FileWriter;
import java.io.PrintWriter;
public class DecompileNflxDhDerive extends GhidraScript {
@Override
protected void run() throws Exception {
String outputPath = "/tmp/nflxDhDerive_decompiled.c";
long[] addresses = { 0x0000FEECL, 0x0000FDE8L, 0x0000D7E0L };
String[] descriptions = {
"nflxDhDerive (main, vector variant)",
"nflxDhDerive (DataBuffer variant)",
"AppleNativeKey::getBytes()"
};
DecompInterface decomp = new DecompInterface();
decomp.openProgram(currentProgram);
FunctionManager fm = currentProgram.getFunctionManager();
PrintWriter out = new PrintWriter(new FileWriter(outputPath));
out.println("// NFWebCrypto nflxDhDerive decompiled pseudocode");
out.println("// Binary: NFWebCrypto.framework/NFWebCrypto (arm64)");
out.println("// Generated by Ghidra headless decompiler");
out.println();
for (int i = 0; i < addresses.length; i++) {
Address addr = currentProgram.getAddressFactory()
.getDefaultAddressSpace().getAddress(addresses[i]);
Function func = fm.getFunctionAt(addr);
if (func == null) {
func = fm.getFunctionContaining(addr);
}
if (func == null) {
out.printf("// Function not found at 0x%08x (%s)%n%n", addresses[i], descriptions[i]);
println("WARNING: Function not found at 0x" + Long.toHexString(addresses[i]));
continue;
}
DecompileResults result = decomp.decompileFunction(func, 120, monitor);
if (result.decompileCompleted()) {
String code = result.getDecompiledFunction().getC();
out.printf("// === %s ===%n", descriptions[i]);
out.printf("// Address: 0x%08x%n", addresses[i]);
out.printf("// Function: %s%n", func.getName());
out.println(code);
out.println();
println("OK: Decompiled " + func.getName() + " at 0x" + Long.toHexString(addresses[i]));
} else {
out.printf("// FAILED to decompile at 0x%08x (%s)%n%n", addresses[i], descriptions[i]);
println("FAILED: Could not decompile at 0x" + Long.toHexString(addresses[i]));
}
}
out.close();
decomp.dispose();
println("Output written to: " + outputPath);
}
}