Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 13 additions & 6 deletions Confuser.Protections/AntiTamper/AntiMode.cs
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ internal class AntiMode : IModeHandler {
List<MethodDef> methods;
uint name1, name2;
RandomGenerator random;
int[] rotShifts;
uint v;
uint x;
uint z;
Expand All @@ -35,6 +36,9 @@ public void HandleInject(AntiTamperProtection parent, ConfuserContext context, P
feedback = random.NextUInt32();
name1 = random.NextUInt32() & 0x7f7f7f7f;
name2 = random.NextUInt32() & 0x7f7f7f7f;
// Randomize the key-derivation rotation amounts (were the fixed 5/3/7/11); the same
// amounts are injected into the runtime (Mutation.KeyI6..KeyI9) below.
rotShifts = RotationKey.PickShifts(random);

switch (parameters.GetParameter(context, context.CurrentModule, "key", Mode.Normal)) {
case Mode.Normal:
Expand Down Expand Up @@ -79,8 +83,11 @@ public void HandleInject(AntiTamperProtection parent, ConfuserContext context, P
initMethod.Body.Instructions.Add(instr);

MutationHelper.InjectKeys(initMethod,
new[] { 0, 1, 2, 3, 4, 5 },
new[] { (int)(name1 * name2), (int)z, (int)x, (int)c, (int)v, (int)feedback });
new[] { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9 },
new[] {
(int)(name1 * name2), (int)z, (int)x, (int)c, (int)v, (int)feedback,
rotShifts[0], rotShifts[1], rotShifts[2], rotShifts[3]
});

var name = context.Registry.GetService<INameService>();
var marker = context.Registry.GetService<IMarkerService>();
Expand Down Expand Up @@ -249,10 +256,10 @@ uint[] DeriveKey() {
for (int i = 0; i < 0x10; i++) {
dst[i] = v;
src[i] = x;
z = (x >> 5) | (x << 27);
x = (c >> 3) | (c << 29);
c = (v >> 7) | (v << 25);
v = (z >> 11) | (z << 21);
z = (x >> rotShifts[0]) | (x << (32 - rotShifts[0]));
x = (c >> rotShifts[1]) | (c << (32 - rotShifts[1]));
c = (v >> rotShifts[2]) | (v << (32 - rotShifts[2]));
v = (z >> rotShifts[3]) | (z << (32 - rotShifts[3]));
}
return deriver.DeriveKey(dst, src);
}
Expand Down
19 changes: 13 additions & 6 deletions Confuser.Protections/AntiTamper/JITMode.cs
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ internal class JITMode : IModeHandler {
List<MethodDef> methods;
uint name1, name2;
RandomGenerator random;
int[] rotShifts;
uint v;
uint x;
uint z;
Expand All @@ -49,6 +50,9 @@ public void HandleInject(AntiTamperProtection parent, ConfuserContext context, P
name1 = random.NextUInt32() & 0x7f7f7f7f;
name2 = random.NextUInt32() & 0x7f7f7f7f;
key = random.NextUInt32();
// Randomize the key-derivation rotation amounts (were the fixed 5/3/7/11); the same
// amounts are injected into the runtime (Mutation.KeyI6..KeyI9) below.
rotShifts = RotationKey.PickShifts(random);

fieldLayout = new byte[6];
for (int i = 0; i < 6; i++) {
Expand Down Expand Up @@ -101,8 +105,11 @@ public void HandleInject(AntiTamperProtection parent, ConfuserContext context, P
initMethod.Body.Instructions.Add(instr);

MutationHelper.InjectKeys(initMethod,
new[] { 0, 1, 2, 3, 4 },
new[] { (int)(name1 * name2), (int)z, (int)x, (int)c, (int)v });
new[] { 0, 1, 2, 3, 4, 6, 7, 8, 9 },
new[] {
(int)(name1 * name2), (int)z, (int)x, (int)c, (int)v,
rotShifts[0], rotShifts[1], rotShifts[2], rotShifts[3]
});

var name = context.Registry.GetService<INameService>();
var marker = context.Registry.GetService<IMarkerService>();
Expand Down Expand Up @@ -316,10 +323,10 @@ uint[] DeriveKey() {
for (int i = 0; i < 0x10; i++) {
dst[i] = v;
src[i] = x;
z = (x >> 5) | (x << 27);
x = (c >> 3) | (c << 29);
c = (v >> 7) | (v << 25);
v = (z >> 11) | (z << 21);
z = (x >> rotShifts[0]) | (x << (32 - rotShifts[0]));
x = (c >> rotShifts[1]) | (c << (32 - rotShifts[1]));
c = (v >> rotShifts[2]) | (v << (32 - rotShifts[2]));
v = (z >> rotShifts[3]) | (z << (32 - rotShifts[3]));
}
return deriver.DeriveKey(dst, src);
}
Expand Down
19 changes: 13 additions & 6 deletions Confuser.Protections/AntiTamper/NormalMode.cs
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ internal class NormalMode : IModeHandler {
List<MethodDef> methods;
uint name1, name2;
RandomGenerator random;
int[] rotShifts;
uint v;
uint x;
uint z;
Expand All @@ -35,6 +36,9 @@ public void HandleInject(AntiTamperProtection parent, ConfuserContext context, P
feedback = random.NextUInt32();
name1 = random.NextUInt32() & 0x7f7f7f7f;
name2 = random.NextUInt32() & 0x7f7f7f7f;
// Randomize the key-derivation rotation amounts (were the fixed 5/3/7/11); the same
// amounts are injected into the runtime (Mutation.KeyI6..KeyI9) below.
rotShifts = RotationKey.PickShifts(random);

switch (parameters.GetParameter(context, context.CurrentModule, "key", Mode.Normal)) {
case Mode.Normal:
Expand Down Expand Up @@ -79,8 +83,11 @@ public void HandleInject(AntiTamperProtection parent, ConfuserContext context, P
initMethod.Body.Instructions.Add(instr);

MutationHelper.InjectKeys(initMethod,
new[] { 0, 1, 2, 3, 4, 5 },
new[] { (int)(name1 * name2), (int)z, (int)x, (int)c, (int)v, (int)feedback });
new[] { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9 },
new[] {
(int)(name1 * name2), (int)z, (int)x, (int)c, (int)v, (int)feedback,
rotShifts[0], rotShifts[1], rotShifts[2], rotShifts[3]
});

var name = context.Registry.GetService<INameService>();
var marker = context.Registry.GetService<IMarkerService>();
Expand Down Expand Up @@ -250,10 +257,10 @@ uint[] DeriveKey() {
for (int i = 0; i < 0x10; i++) {
dst[i] = v;
src[i] = x;
z = (x >> 5) | (x << 27);
x = (c >> 3) | (c << 29);
c = (v >> 7) | (v << 25);
v = (z >> 11) | (z << 21);
z = (x >> rotShifts[0]) | (x << (32 - rotShifts[0]));
x = (c >> rotShifts[1]) | (c << (32 - rotShifts[1]));
c = (v >> rotShifts[2]) | (v << (32 - rotShifts[2]));
v = (z >> rotShifts[3]) | (z << (32 - rotShifts[3]));
}
return deriver.DeriveKey(dst, src);
}
Expand Down
26 changes: 26 additions & 0 deletions Confuser.Protections/AntiTamper/RotationKey.cs
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
using System;
using Confuser.Core.Services;

namespace Confuser.Protections.AntiTamper {
/// <summary>
/// Picks the rotation amounts for the anti-tamper key-derivation mixer, replacing the fixed
/// 5 / 3 / 7 / 11 that de4dot/AV pattern-match. A bit rotation is a bijection for any amount
/// in 1..31, so -- unlike the xorshift/prime constants -- no curated set is required; the
/// four amounts are simply chosen distinct per module to keep the 16-word key expansion
/// spread. The same amounts are injected into the runtime (Mutation.KeyI6..KeyI9), which
/// forms each rotation as (r >> amount) | (r << (32 - amount)).
/// </summary>
internal static class RotationKey {
internal static int[] PickShifts(RandomGenerator random) {
var shifts = new int[4];
for (int i = 0; i < shifts.Length; i++) {
int s;
do {
s = random.NextInt32(1, 32);
} while (Array.IndexOf(shifts, s, 0, i) != -1);
shifts[i] = s;
}
return shifts;
}
}
}
8 changes: 4 additions & 4 deletions Confuser.Runtime/AntiTamper.Anti.cs
Original file line number Diff line number Diff line change
Expand Up @@ -61,14 +61,14 @@ static unsafe void Initialize() {
for (int i = 0; i < 0x10; i++) {
y[i] = v;
d[i] = x;
z = (x >> 5) | (x << 27);
x = (c >> 3) | (c << 29);
z = (x >> Mutation.KeyI6) | (x << (32 - Mutation.KeyI6));
x = (c >> Mutation.KeyI7) | (c << (32 - Mutation.KeyI7));

CheckRemoteDebuggerPresent(Process.GetCurrentProcess().Handle, ref isDebuggerPresent);
if (isDebuggerPresent) Environment.FailFast(null);

c = (v >> 7) | (v << 25);
v = (z >> 11) | (z << 21);
c = (v >> Mutation.KeyI8) | (v << (32 - Mutation.KeyI8));
v = (z >> Mutation.KeyI9) | (z << (32 - Mutation.KeyI9));
}
Mutation.Crypt(y, d);

Expand Down
8 changes: 4 additions & 4 deletions Confuser.Runtime/AntiTamper.JIT.cs
Original file line number Diff line number Diff line change
Expand Up @@ -52,10 +52,10 @@ public static void Initialize() {
for (int i = 0; i < 0x10; i++) {
y[i] = v;
d[i] = x;
z = (x >> 5) | (x << 27);
x = (c >> 3) | (c << 29);
c = (v >> 7) | (v << 25);
v = (z >> 11) | (z << 21);
z = (x >> Mutation.KeyI6) | (x << (32 - Mutation.KeyI6));
x = (c >> Mutation.KeyI7) | (c << (32 - Mutation.KeyI7));
c = (v >> Mutation.KeyI8) | (v << (32 - Mutation.KeyI8));
v = (z >> Mutation.KeyI9) | (z << (32 - Mutation.KeyI9));
}
Mutation.Crypt(y, d);

Expand Down
8 changes: 4 additions & 4 deletions Confuser.Runtime/AntiTamper.Normal.cs
Original file line number Diff line number Diff line change
Expand Up @@ -45,10 +45,10 @@ static unsafe void Initialize() {
for (int i = 0; i < 0x10; i++) {
y[i] = v;
d[i] = x;
z = (x >> 5) | (x << 27);
x = (c >> 3) | (c << 29);
c = (v >> 7) | (v << 25);
v = (z >> 11) | (z << 21);
z = (x >> Mutation.KeyI6) | (x << (32 - Mutation.KeyI6));
x = (c >> Mutation.KeyI7) | (c << (32 - Mutation.KeyI7));
c = (v >> Mutation.KeyI8) | (v << (32 - Mutation.KeyI8));
v = (z >> Mutation.KeyI9) | (z << (32 - Mutation.KeyI9));
}
Mutation.Crypt(y, d);

Expand Down