-
Notifications
You must be signed in to change notification settings - Fork 15
/
keygen.py
102 lines (65 loc) · 24 KB
/
keygen.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
# coding: utf-8
# In[58]:
rawBuffer = bytearray.fromhex("")
# In[61]:
import struct
def getUint32(index):
# print(rawBuffer[index:index+4])
return struct.unpack(">I", rawBuffer[index:index+4])[0]
def setUint32(index, val):
rawBuffer[index:index+4] = bytearray(struct.pack(">I", val))
# print(getUint32(11228))
# setUint32(11228, 1233423588)
print(getUint32(11148))
# In[75]:
desired
key = bytearray(b'abcdefgh')
# First byte
# Set index 8 to be
index8 = (3989547399 ^ key[0]) & 0xff
index0 = getUint32(10188 + (index8 * 4)) ^ 15584169
print(index0)
setUint32(11228, index0)
index8 = (getUint32(11228) ^ key[1]) & 0xff
shift = getUint32(11228) >> 8
index0 = getUint32(10188 + index8*4) ^ shift
print(index0)
setUint32(11228, index0)
# Third byte
index8 = (getUint32(11228) ^ key[2]) & 0xff
shift = getUint32(11228) >> 8
index0 = getUint32(10188 + index8*4) ^ shift
print(index0)
setUint32(11228, index0)
# 4th byte
index8 = (getUint32(11228) ^ key[3]) & 0xff
shift = getUint32(11228) >> 8
index0 = getUint32(10188 + index8*4) ^ shift
print(index0)
setUint32(11228, index0)
# 5th byte
index8 = (getUint32(11228) ^ key[4]) & 0xff
shift = getUint32(11228) >> 8
index0 = getUint32(10188 + index8*4) ^ shift
print(index0)
setUint32(11228, index0)
# 6th byte
index8 = (getUint32(11228) ^ key[5]) & 0xff
shift = getUint32(11228) >> 8
index0 = getUint32(10188 + index8*4) ^ shift
print(index0)
setUint32(11228, index0)
# 7th byte
index8 = (getUint32(11228) ^ key[6]) & 0xff
shift = getUint32(11228) >> 8
index0 = getUint32(10188 + index8*4) ^ shift
print(index0)
setUint32(11228, index0)
# 8th byte
index8 = (getUint32(11228) ^ key[7]) & 0xff
shift = getUint32(11228) >> 8
index0 = getUint32(10188 + index8*4) ^ shift
print(index0)
setUint32(11228, index0)
# Final pass
getUint32(11228) ^ 0xffffffff