PPaste!

33C3 CTF Mario

Home - All the pastes - Authored by Thooms

Raw version

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
#include <stddef.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>

typedef unsigned __int128 u128;
#define U128(HIGH, LOW) ((u128) (HIGH) << 64 | (u128) (LOW))

void encrypt(uint8_t *input, uint8_t *key) {
    for(size_t k = 0 ; k < 0x20 ; k += 3) {
        uint8_t carry = 0;
        for(size_t i = 0 ; i < 8 && k + i < 0x20 ; i++) {
            uint8_t val = input[k + i];
            uint16_t tmp = val + key[i] + carry;
            carry = tmp > 0xFF ? 1 : 0;
            input[k + i] = tmp & 0xFF;
        }
    }
}

void u128_pshuflw(uint8_t order, u128 src, u128 *dst) {
    *dst = (src & ((u128) UINT64_MAX << 64));
    for(size_t i = 0 ; i < 4 ; i++) {
        u128 shift = ((order >> (2 * i)) & 3) * 16;
        *dst |= ((src >> shift) & 0xFFFF) << i * 16;
    }
}

void u128_pshufhw(uint8_t order, u128 src, u128 *dst) {
    *dst = (src & (u128) UINT64_MAX);
    for(size_t i = 0 ; i < 4 ; i++) {
        u128 shift = ((order >> (2 * i)) & 3) * 16 + 64;
        *dst |= ((src >> shift) & 0xFFFF) << ((i * 16) + 64);
    }
}

void u128_psllq(uint8_t shift, u128 *val) {
    uint64_t high = (*val >> 64) << shift;
    uint64_t low = (*val & UINT64_MAX) << shift;
    *val = (u128) high << 64 | low;
}

void u128_psrlq(uint8_t shift, u128 *val) {
    uint64_t high = (*val >> 64) >> shift;
    uint64_t low = (*val & UINT64_MAX) >> shift;
    *val = (u128) high << 64 | low;
}

int main() {
    u128 xmm1, xmm2, xmm3, xmm4;
    xmm1 = U128(0xaf7aea900f7d0218, 0x8a76639879e2196c);
    xmm2 = U128(0x74c0a7f29ff2fc80, 0xc23662b9aefabdb2);
    xmm4 = U128(0x33c300133700c4fe, 0xb4be00d34d00c0d3);

    for(size_t i = 0 ; i < 0x2a ; i++) {
        xmm2 ^= xmm4;
        xmm3 = xmm2;
        u128_psrlq(0x2f, &xmm2);
        u128_psllq(0x11, &xmm3);
        xmm2 ^= xmm3;
        xmm1 ^= xmm4;
        xmm3 = xmm1;
        u128_psllq(0x33, &xmm1);
        u128_psrlq(0xd, &xmm3);
        xmm1 ^= xmm3;
        u128_pshufhw(0x36, xmm2, &xmm2);
        u128_pshufhw(0xc9, xmm1, &xmm1);
        u128_pshuflw(0x93, xmm2, &xmm2);
        u128_pshuflw(0x72, xmm1, &xmm1);
        xmm3 = xmm1;
        xmm1 = (xmm2 >> 64) | (xmm1 << 64);
        xmm2 = (xmm3 & ((u128) UINT64_MAX << 64)) | (xmm2 & (u128) UINT64_MAX);
    }

    uint8_t expected[32] = {0};
    memcpy(expected, &xmm1, 16);
    memcpy(expected + 16, &xmm2, 16);

    uint8_t key[] = {0x5F, 0x38, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00};
    uint8_t found[33] = {0};
    uint8_t try[32] = {0};
    for(size_t i = 0 ; i < 32 ; i++) {
        for(size_t j = 0 ; j < 255 ; j++) {
            memcpy(try, found, 32);
            try[i] = j;
            encrypt(try, key);
            if(try[i] == expected[i]) {
                found[i] = j;
                break;
            }
        }
    }
    printf("%s\n", found);

    return EXIT_SUCCESS;
}