4 static BYTE reverse
[0x100], table
[0x100] =
6 0x33, 0x73, 0x3B, 0x26, 0x63, 0x23, 0x6B, 0x76, 0x3E, 0x7E, 0x36, 0x2B, 0x6E, 0x2E, 0x66, 0x7B,
7 0xD3, 0x93, 0xDB, 0x06, 0x43, 0x03, 0x4B, 0x96, 0xDE, 0x9E, 0xD6, 0x0B, 0x4E, 0x0E, 0x46, 0x9B,
8 0x57, 0x17, 0x5F, 0x82, 0xC7, 0x87, 0xCF, 0x12, 0x5A, 0x1A, 0x52, 0x8F, 0xCA, 0x8A, 0xC2, 0x1F,
9 0xD9, 0x99, 0xD1, 0x00, 0x49, 0x09, 0x41, 0x90, 0xD8, 0x98, 0xD0, 0x01, 0x48, 0x08, 0x40, 0x91,
10 0x3D, 0x7D, 0x35, 0x24, 0x6D, 0x2D, 0x65, 0x74, 0x3C, 0x7C, 0x34, 0x25, 0x6C, 0x2C, 0x64, 0x75,
11 0xDD, 0x9D, 0xD5, 0x04, 0x4D, 0x0D, 0x45, 0x94, 0xDC, 0x9C, 0xD4, 0x05, 0x4C, 0x0C, 0x44, 0x95,
12 0x59, 0x19, 0x51, 0x80, 0xC9, 0x89, 0xC1, 0x10, 0x58, 0x18, 0x50, 0x81, 0xC8, 0x88, 0xC0, 0x11,
13 0xD7, 0x97, 0xDF, 0x02, 0x47, 0x07, 0x4F, 0x92, 0xDA, 0x9A, 0xD2, 0x0F, 0x4A, 0x0A, 0x42, 0x9F,
14 0x53, 0x13, 0x5B, 0x86, 0xC3, 0x83, 0xCB, 0x16, 0x5E, 0x1E, 0x56, 0x8B, 0xCE, 0x8E, 0xC6, 0x1B,
15 0xB3, 0xF3, 0xBB, 0xA6, 0xE3, 0xA3, 0xEB, 0xF6, 0xBE, 0xFE, 0xB6, 0xAB, 0xEE, 0xAE, 0xE6, 0xFB,
16 0x37, 0x77, 0x3F, 0x22, 0x67, 0x27, 0x6F, 0x72, 0x3A, 0x7A, 0x32, 0x2F, 0x6A, 0x2A, 0x62, 0x7F,
17 0xB9, 0xF9, 0xB1, 0xA0, 0xE9, 0xA9, 0xE1, 0xF0, 0xB8, 0xF8, 0xB0, 0xA1, 0xE8, 0xA8, 0xE0, 0xF1,
18 0x5D, 0x1D, 0x55, 0x84, 0xCD, 0x8D, 0xC5, 0x14, 0x5C, 0x1C, 0x54, 0x85, 0xCC, 0x8C, 0xC4, 0x15,
19 0xBD, 0xFD, 0xB5, 0xA4, 0xED, 0xAD, 0xE5, 0xF4, 0xBC, 0xFC, 0xB4, 0xA5, 0xEC, 0xAC, 0xE4, 0xF5,
20 0x39, 0x79, 0x31, 0x20, 0x69, 0x29, 0x61, 0x70, 0x38, 0x78, 0x30, 0x21, 0x68, 0x28, 0x60, 0x71,
21 0xB7, 0xF7, 0xBF, 0xA2, 0xE7, 0xA7, 0xEF, 0xF2, 0xBA, 0xFA, 0xB2, 0xAF, 0xEA, 0xAA, 0xE2, 0xFF,
28 for(DWORD loop0
= 0; loop0
< 0x100; loop0
++)
32 for(DWORD loop1
= 0; loop1
< 8; loop1
++)
34 value
|= ((loop0
>> loop1
) & 1) << (7 - loop1
);
37 reverse
[loop0
] = value
;
46 void CVobDec::ClockLfsr0Forward(int &lfsr0
)
48 int temp
= (lfsr0
<< 3) | (lfsr0
>> 14);
49 lfsr0
= (lfsr0
>> 8) | ((((((temp
<< 3) ^ temp
) << 3) ^ temp
^ lfsr0
) & 0xFF) << 9);
52 void CVobDec::ClockLfsr1Forward(int &lfsr1
)
54 lfsr1
= (lfsr1
>> 8) | ((((((((lfsr1
>> 8) ^ lfsr1
) >> 1) ^ lfsr1
) >> 3) ^ lfsr1
) & 0xFF) << 17);
57 void CVobDec::ClockBackward(int &lfsr0
, int &lfsr1
)
61 lfsr0
= ((lfsr0
<< 8) ^ ((((lfsr0
>> 3) ^ lfsr0
) >> 6) & 0xFF)) & ((1 << 17) - 1);
62 temp0
= ((lfsr1
>> 17) ^ (lfsr1
>> 4)) & 0xFF;
63 temp1
= (lfsr1
<< 5) | (temp0
>> 3);
64 temp1
= ((temp1
>> 1) ^ temp1
) & 0xFF;
65 lfsr1
= ((lfsr1
<< 8) | ((((((temp1
>> 2) ^ temp1
) >> 1) ^ temp1
) >> 3) ^ temp1
^ temp0
)) & ((1 << 25) - 1);
68 void CVobDec::Salt(const BYTE salt
[5], int &lfsr0
, int &lfsr1
)
70 lfsr0
^= (reverse
[salt
[0]] << 9) | reverse
[salt
[1]];
71 lfsr1
^= ((reverse
[salt
[2]] & 0xE0) << 17) | ((reverse
[salt
[2]] & 0x1F) << 16) | (reverse
[salt
[3]] << 8) | reverse
[salt
[4]];
74 int CVobDec::FindLfsr(const BYTE
*crypt
, int offset
, const BYTE
*plain
)
76 int loop0
, loop1
, lfsr0
, lfsr1
, carry
, count
;
78 for(loop0
= count
= 0; loop0
!= (1 << 18); loop0
++)
83 for(loop1
= lfsr1
= 0; loop1
!= 4; loop1
++)
85 ClockLfsr0Forward(lfsr0
);
86 carry
= (table
[crypt
[offset
+ loop1
]] ^ plain
[loop1
]) - ((lfsr0
>> 9) ^ 0xFF) - carry
;
87 lfsr1
= (lfsr1
>> 8) | ((carry
& 0xFF) << 17);
88 carry
= (carry
>> 8) & 0x01;
90 for( ; loop1
!= 7; loop1
++)
92 ClockLfsr0Forward(lfsr0
);
93 ClockLfsr1Forward(lfsr1
);
94 carry
+= ((lfsr0
>> 9) ^ 0xFF) + (lfsr1
>> 17);
95 if((carry
& 0xFF) != (table
[crypt
[offset
+ loop1
]] ^ plain
[loop1
]))
103 for(loop1
= 0; loop1
!= 6; loop1
++)
105 ClockBackward(lfsr0
, lfsr1
);
107 carry
= ((lfsr0
>> 9) ^ 0xFF) + (lfsr1
>> 17) + (loop0
& 0x01);
108 if((carry
& 0xFF) == (table
[crypt
[offset
]] ^ plain
[0]))
110 for(loop1
= 0; loop1
!= offset
+ 1; loop1
++)
112 ClockBackward(lfsr0
, lfsr1
);
114 if(lfsr0
& 0x100 && lfsr1
& 0x200000)
127 bool CVobDec::FindKey(BYTE
* buff
)
129 BYTE plain
[7] = {0x00, 0x00, 0x01, 0xBE, 0x00, 0x00, 0xFF};
130 int offset
, left
, flag
= 0, block
= 0, count
, maxblock
= 20000;
134 if(buff
[0x14] & 0x30)
138 if(*(DWORD
*)&buff
[0x00] == 0xba010000 && (*(DWORD
*)&buff
[0x0e] & 0xffffff) == 0x010000)
140 offset
= 0x14 + (buff
[0x12] << 8) + buff
[0x13];
141 if(0x80 <= offset
&& offset
<= 0x7F9)
144 left
= 0x800 - offset
- 6;
145 plain
[4] = (char)(left
>> 8);
146 plain
[5] = (char)left
;
147 if((count
= FindLfsr(buff
+ 0x80, offset
- 0x80, plain
)) == 1)
149 Salt(buff
+ 0x54, m_lfsr0
, m_lfsr1
);
154 // printf(_T("\rblock %d reported %d possible keys, skipping\n"), block, count);
163 void CVobDec::Decrypt(BYTE
* buff
)
165 if(buff
[0x14] & 0x30)
169 int lfsr0
= m_lfsr0
, lfsr1
= m_lfsr1
;
171 Salt(buff
+ 0x54, lfsr0
, lfsr1
);
175 for(int loop0
= 0, carry
= 0; loop0
!= 0x800 - 0x80; loop0
++, buff
++)
177 ClockLfsr0Forward(lfsr0
);
178 ClockLfsr1Forward(lfsr1
);
179 carry
+= ((lfsr0
>> 9) ^ 0xFF) + (lfsr1
>> 17);
180 *buff
= BYTE(table
[*buff
] ^ carry
);