feature: randomize anti-tamper key-derivation rotation shifts (#69) - #108
Merged
Merged
Conversation
The anti-tamper key-derivation mixer rotates its four state registers by the fixed amounts 5/3/7/11 on both the obfuscator (mode DeriveKey) and the injected runtime (Initialize), across all three modes (Normal, Anti, JIT). de4dot/AV pattern-match these fixed shifts. The four amounts are now chosen distinct per module and injected into the runtime via mutation keys (KeyI6..KeyI9); the runtime forms each rotation as (r >> amount) | (r << (32 - amount)). Both sides share the amounts, so the round-trip holds. Unlike the xorshift/prime constants, a bit rotation is a bijection for any amount in 1..31, so no curated set is required -- the shared RotationKey helper just picks four distinct non-trivial amounts. Validated by AntiTamper.Test (normal + anti pass; jit stays skipped as it is a pre-existing known-broken/untested mode -- its change mirrors the two validated modes and is compile-checked only).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Level 2 constant randomization — Anti-tamper rotation shifts (#69)
Removes the fixed
5/3/7/11rotation amounts from the anti-tamper key-derivation mixer. The mixer rotates its four state registers over 16 iterations to expand the key, identically on the obfuscator (*Mode.DeriveKey) and the injected runtime (AntiTamper*.Initialize), in all three modes (Normal, Anti, JIT). The fixed shifts let de4dot/AV pattern-match the stub.Change
Mutation.KeyI6..KeyI9(slots 6–9 were free; modes use 0–5).(r >> amount) | (r << (32 - amount)); obfuscatorDeriveKeyuses the same amounts, so the round-trip holds.RotationKey.PickShiftshelper picks the four amounts.No curated set needed (unlike xorshift/primes)
A bit rotation is a bijection for any amount in 1..31 — there's no full-period/primality validity constraint like the xorshift (#107) or compressor primes (#106). So the amounts are simply picked distinct and non-trivial at obfuscation time; no baked table or generator script is required. ~4 distinct amounts from 1..31 → several bits of per-module identity.
Validation
AntiTamper.Test: normal + anti pass (obfuscate → run → the self-check decrypts its section with the randomized rotations and the app runs).jitstays skipped — it is a pre-existing known-broken/untested mode (Skip = "Runtime Component of the JIT AntiTamper protection is broken."). The JIT change mirrors the two validated modes and is compile-checked only.Remaining on #69 (follow-ups)
counterrotation (>>5|<<27) and feedback0x3dbb2819— grouped with the JIT-hook hard-fingerprint concerns..sh).Part of #69. Related: #106 (compressor moduli), #107 (constants xorshift).