1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108
|
#include <arpa/inet.h>
#include <assert.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <zlib.h>
int
main (int argc, char **argv)
{
u_int32_t i;
unsigned char qvm[1024] = { 0 };
u_int32_t target = strtoul (argv[1], NULL, 0);
char *subdir = "";
size_t fixed_len;
u_int32_t crc;
if (argc > 3) {
subdir = argv[3];
}
fixed_len = strlen (subdir) + 8;
snprintf ((char *) qvm, sizeof (qvm) - 1, "NTVE%s%c%c%c%cCCCCXXXX",
subdir, 0, 0, 0, 0);
crc = crc32 (crc32 (0, NULL, 0), qvm, fixed_len);
qvm[fixed_len + 0] = ~(crc & 0xFF);
qvm[fixed_len + 1] = ~((crc >> 8) & 0xFF);
qvm[fixed_len + 2] = ~((crc >> 16) & 0xFF);
qvm[fixed_len + 3] = ~((crc >> 24) & 0xFF);
crc = crc32 (crc32 (0, NULL, 0), qvm, fixed_len + 4);
assert (crc == 0xFFFFFFFF);
printf ("searching for suffix that turns CRC32 from FFFFFFFF to 0x%.8x\n",
target);
for (i = 0; ; i++) {
if (i % 0x10000 == 0) {
printf ("%.8x\r", i);
}
if (crc32(0xFFFFFFFF, (const unsigned char *) &i, sizeof (i)) == target) {
printf ("suffix found: 0x%.8x (in this machine's endianness)\n",
i);
break;
}
if (i == 0xFFFFFFFF) {
printf ("collision not found within 4 bytes\n");
return 1;
}
}
memcpy (qvm + fixed_len + 4, &i, 4);
crc = crc32 (crc32 (0, NULL, 0), qvm, fixed_len + 8);
assert (crc == target);
printf ("crc32(\"NTVE%s\" 00000000 %.8x %.8x) == 0x%.8x\n",
subdir,
ntohl(*((u_int32_t *) (qvm + fixed_len))),
ntohl(*((u_int32_t *) (qvm + fixed_len + 4))),
crc);
if (argc > 2) {
FILE *f;
printf ("writing to file %s\n", argv[2]);
f = fopen (argv[2], "w");
if (f == NULL ||
fwrite (qvm, fixed_len + 8, 1, f) < 1 ||
fclose (f) < 0) {
perror ("writing fake QVM");
return 1;
}
}
return 0;
}
|