diff --git a/BurnOutSharp/ExecutableType/Microsoft/PortableExecutable.cs b/BurnOutSharp/ExecutableType/Microsoft/PortableExecutable.cs
index f41efd4f..b660be0a 100644
--- a/BurnOutSharp/ExecutableType/Microsoft/PortableExecutable.cs
+++ b/BurnOutSharp/ExecutableType/Microsoft/PortableExecutable.cs
@@ -83,24 +83,24 @@ namespace BurnOutSharp.ExecutableType.Microsoft
// https://docs.microsoft.com/en-us/windows/win32/debug/pe-format#special-sections
// Here is a list of standard sections that are used in various protections:
// - .bss *1 protection Uninitialized data (free format)
- // - .data 14 protections Initialized data (free format)
+ // X - .data 14 protections Initialized data (free format)
// - .edata *1 protection Export tables
// - .idata 2 protections Import tables
- // - .rdata 11 protections Read-only initialized data
+ // X - .rdata 11 protections Read-only initialized data
// - .rsrc *1 protection Resource directory [Mostly taken care of, last protection needs research]
- // - .text 6 protections Executable code (free format)
+ // X - .text 6 protections Executable code (free format)
// - .tls *1 protection Thread-local storage (object only)
//
// Here is a list of non-standard sections whose contents are read by various protections:
- // - CODE *1 protection WTM CD Protect
- // - .grand *1 protection CD-Cops / DVD-Cops
- // - .init *1 protection SolidShield
- // - .NOS0 *1 protection UPX (NOS Variant)
- // - .NOS1 *1 protection UPX (NOS Variant)
+ // X - CODE *1 protection WTM CD Protect
+ // X - .grand *1 protection CD-Cops / DVD-Cops
+ // X - .init *1 protection SolidShield
+ // - .NOS0 *1 protection UPX (NOS Variant) [Used as endpoint]
+ // - .NOS1 *1 protection UPX (NOS Variant) [Used as endpoint]
// - .pec2 *1 protection PE Compact [Unconfirmed]
- // - .txt2 *1 protection SafeDisc
- // - .UPX0 *1 protection UPX
- // - .UPX1 *1 protection UPX
+ // X - .txt2 *1 protection SafeDisc
+ // - .UPX0 *1 protection UPX [Used as endpoint]
+ // - .UPX1 *1 protection UPX [Used as endpoint]
//
// Here is a list of non-standard sections whose existence are checked by various protections:
// - .brick 1 protection StarForce
@@ -112,8 +112,8 @@ namespace BurnOutSharp.ExecutableType.Microsoft
// - .pec1 1 protection PE Compact
// - .securom 1 protection SecuROM
// - .sforce 1 protection StarForce
- // - .stxt371 1 protection SafeDisc
- // - .stxt774 1 protection SafeDisc
+ // - stxt371 1 protection SafeDisc
+ // - stxt774 1 protection SafeDisc
// - .vob.pcd 1 protection VOB ProtectCD
// - _winzip_ 1 protection WinZip SFX
//
@@ -238,13 +238,13 @@ namespace BurnOutSharp.ExecutableType.Microsoft
///
/// Get the raw bytes from a section, if possible
///
- public byte[] ReadRawSection(byte[] content, ref int offset, string sectionName, bool first = true)
+ public byte[] ReadRawSection(byte[] content, string sectionName, bool first = true)
{
var section = first ? GetFirstSection(sectionName, true) : GetLastSection(sectionName, true);
if (section == null)
return null;
- offset = (int)section.PointerToRawData;
+ int offset = (int)section.PointerToRawData;
return content.ReadBytes(ref offset, (int)section.VirtualSize);
}
@@ -340,13 +340,13 @@ namespace BurnOutSharp.ExecutableType.Microsoft
#region Freeform Sections
// Data Section
- pex.DataSectionRaw = pex.ReadRawSection(stream, ".data", true) ?? pex.ReadRawSection(stream, "DATA", true);
+ pex.DataSectionRaw = pex.ReadRawSection(stream, ".data", false) ?? pex.ReadRawSection(stream, "DATA", false);
// Resource Data Section
- pex.ResourceDataSectionRaw = pex.ReadRawSection(stream, ".rdata", true);
+ pex.ResourceDataSectionRaw = pex.ReadRawSection(stream, ".rdata", false);
// Text Section
- pex.TextSectionRaw = pex.ReadRawSection(stream, ".text", true);
+ pex.TextSectionRaw = pex.ReadRawSection(stream, ".text", false);
#endregion
}
@@ -422,13 +422,13 @@ namespace BurnOutSharp.ExecutableType.Microsoft
#region Freeform Sections
// Data Section
- pex.DataSectionRaw = pex.ReadRawSection(content, ref offset, ".data", true) ?? pex.ReadRawSection(content, ref offset, "DATA", true);
+ pex.DataSectionRaw = pex.ReadRawSection(content, ".data", false) ?? pex.ReadRawSection(content, "DATA", false);
// Resource Data Section
- pex.ResourceDataSectionRaw = pex.ReadRawSection(content, ref offset, ".rdata", true);
+ pex.ResourceDataSectionRaw = pex.ReadRawSection(content, ".rdata", false);
// Text Section
- pex.TextSectionRaw = pex.ReadRawSection(content, ref offset, ".text", true);
+ pex.TextSectionRaw = pex.ReadRawSection(content, ".text", false);
#endregion
}
diff --git a/BurnOutSharp/PackerType/Armadillo.cs b/BurnOutSharp/PackerType/Armadillo.cs
index e210c16f..504336ab 100644
--- a/BurnOutSharp/PackerType/Armadillo.cs
+++ b/BurnOutSharp/PackerType/Armadillo.cs
@@ -18,8 +18,8 @@ namespace BurnOutSharp.PackerType
return null;
// Get the .nicode section, if it exists
- var nicodeSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".nicode"));
- if (nicodeSection != null)
+ bool nicodeSection = pex.ContainsSection(".nicode", exact: true);
+ if (nicodeSection)
return "Armadillo";
// Loop through all "extension" sections
diff --git a/BurnOutSharp/PackerType/PECompact.cs b/BurnOutSharp/PackerType/PECompact.cs
index 5435ea6e..557532c1 100644
--- a/BurnOutSharp/PackerType/PECompact.cs
+++ b/BurnOutSharp/PackerType/PECompact.cs
@@ -1,6 +1,4 @@
-using System.Linq;
-using System.Text;
-using BurnOutSharp.ExecutableType.Microsoft;
+using BurnOutSharp.ExecutableType.Microsoft;
namespace BurnOutSharp.PackerType
@@ -24,12 +22,12 @@ namespace BurnOutSharp.PackerType
// on the data in the file. This may be related to information in other fields
// Get the pec1 section, if it exists
- var pec1Section = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith("pec1"));
- if (pec1Section != null)
+ bool pec1Section = pex.ContainsSection("pec1", exact: true);
+ if (pec1Section)
return "PE Compact v1.x";
// Get the PEC2 section, if it exists -- TODO: Verify this comment since it's pulling the .text section
- var textSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".text"));
+ var textSection = pex.GetFirstSection(".text", exact: true);
if (textSection != null && textSection.PointerToRelocations == 0x32434550)
{
if (textSection.PointerToLinenumbers != 0)
diff --git a/BurnOutSharp/PackerType/UPX.cs b/BurnOutSharp/PackerType/UPX.cs
index 74236655..e2c71ba5 100644
--- a/BurnOutSharp/PackerType/UPX.cs
+++ b/BurnOutSharp/PackerType/UPX.cs
@@ -1,8 +1,6 @@
using System.Collections.Generic;
-using System.Linq;
using System.Text;
using BurnOutSharp.ExecutableType.Microsoft;
-using BurnOutSharp.ExecutableType.Microsoft.Headers;
using BurnOutSharp.Matching;
namespace BurnOutSharp.PackerType
@@ -18,7 +16,7 @@ namespace BurnOutSharp.PackerType
return null;
// Standard UPX
- int foundPosition = FindData(fileContent, sections, "UPX");
+ int foundPosition = FindData(pex, "UPX");
if (foundPosition > -1)
{
var matchers = new List
@@ -34,7 +32,7 @@ namespace BurnOutSharp.PackerType
}
// NOS Variant
- foundPosition = FindData(fileContent, sections, "NOS");
+ foundPosition = FindData(pex, "NOS");
if (foundPosition > -1)
{
var matchers = new List
@@ -84,15 +82,14 @@ namespace BurnOutSharp.PackerType
///
/// Find the location of the first matched section, if possible
///
- /// Byte array representing the file contents
- /// Array of sections to check against
+ /// PortableExecutable representing the read-in file
/// Prefix of the sections to check for
/// Real address of the section data, -1 on error
- private int FindData(byte[] fileContent, SectionHeader[] sections, string sectionPrefix)
+ private int FindData(PortableExecutable pex, string sectionPrefix)
{
// Get the two matching sections, if possible
- var firstSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith($"{sectionPrefix}0"));
- var secondSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith($"{sectionPrefix}1"));
+ var firstSection = pex.GetFirstSection($"{sectionPrefix}0", exact: true);
+ var secondSection = pex.GetFirstSection($"{sectionPrefix}1", exact: true);
// If either section is null, we can't do anything
if (firstSection == null || secondSection == null)
diff --git a/BurnOutSharp/PackerType/WinZipSFX.cs b/BurnOutSharp/PackerType/WinZipSFX.cs
index b8de0ef1..cb235ba4 100644
--- a/BurnOutSharp/PackerType/WinZipSFX.cs
+++ b/BurnOutSharp/PackerType/WinZipSFX.cs
@@ -2,8 +2,6 @@ using System;
using System.Collections.Concurrent;
using System.Collections.Generic;
using System.IO;
-using System.Linq;
-using System.Text;
using BurnOutSharp.ExecutableType.Microsoft;
using BurnOutSharp.Matching;
using BurnOutSharp.Tools;
@@ -36,8 +34,8 @@ namespace BurnOutSharp.PackerType
}
// Get the _winzip_ section, if it exists
- var winzipSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith("_winzip_"));
- if (winzipSection != null)
+ bool winzipSection = pex.ContainsSection("_winzip_", exact: true);
+ if (winzipSection)
{
string version = GetPEHeaderVersion(pex);
if (!string.IsNullOrWhiteSpace(version))
diff --git a/BurnOutSharp/ProtectionType/ActiveMARK.cs b/BurnOutSharp/ProtectionType/ActiveMARK.cs
index 367d4e03..a9438c56 100644
--- a/BurnOutSharp/ProtectionType/ActiveMARK.cs
+++ b/BurnOutSharp/ProtectionType/ActiveMARK.cs
@@ -1,6 +1,5 @@
using System.Collections.Generic;
using System.Linq;
-using System.Text;
using BurnOutSharp.ExecutableType.Microsoft;
using BurnOutSharp.Matching;
@@ -34,7 +33,7 @@ namespace BurnOutSharp.ProtectionType
return null;
// Get the last .bss section, if it exists
- var bssSection = sections.LastOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".bss"));
+ var bssSection = pex.GetLastSection(".bss", exact: true);
if (bssSection != null)
{
int sectionAddr = (int)bssSection.PointerToRawData;
diff --git a/BurnOutSharp/ProtectionType/CDDVDCops.cs b/BurnOutSharp/ProtectionType/CDDVDCops.cs
index 602482d7..542a394b 100644
--- a/BurnOutSharp/ProtectionType/CDDVDCops.cs
+++ b/BurnOutSharp/ProtectionType/CDDVDCops.cs
@@ -2,7 +2,6 @@
using System.Collections.Concurrent;
using System.Collections.Generic;
using System.Linq;
-using System.Text;
using BurnOutSharp.ExecutableType.Microsoft;
using BurnOutSharp.Matching;
@@ -41,33 +40,27 @@ namespace BurnOutSharp.ProtectionType
return null;
// Get the .grand section, if it exists
- var grandSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".grand"));
- if (grandSection != null)
+ var grandSectionRaw = pex.ReadRawSection(fileContent, ".grand", true);
+ if (grandSectionRaw != null)
{
- int sectionAddr = (int)grandSection.PointerToRawData;
- int sectionEnd = sectionAddr + (int)grandSection.VirtualSize;
var matchers = new List
{
// CD-Cops, ver.
- new ContentMatchSet(
- new ContentMatch(new byte?[]
- {
- 0x43, 0x44, 0x2D, 0x43, 0x6F, 0x70, 0x73, 0x2C,
- 0x20, 0x20, 0x76, 0x65, 0x72, 0x2E, 0x20
- }, start: sectionAddr, end: sectionEnd),
- GetVersion, "CD-Cops"),
+ new ContentMatchSet(new byte?[]
+ {
+ 0x43, 0x44, 0x2D, 0x43, 0x6F, 0x70, 0x73, 0x2C,
+ 0x20, 0x20, 0x76, 0x65, 0x72, 0x2E, 0x20
+ }, GetVersion, "CD-Cops"),
// DVD-Cops, ver.
- new ContentMatchSet(
- new ContentMatch(new byte?[]
- {
- 0x44, 0x56, 0x44, 0x2D, 0x43, 0x6F, 0x70, 0x73,
- 0x2C, 0x20, 0x20, 0x76, 0x65, 0x72, 0x2E, 0x20
- }, start: sectionAddr, end: sectionEnd),
- GetVersion, "DVD-Cops"),
+ new ContentMatchSet(new byte?[]
+ {
+ 0x44, 0x56, 0x44, 0x2D, 0x43, 0x6F, 0x70, 0x73,
+ 0x2C, 0x20, 0x20, 0x76, 0x65, 0x72, 0x2E, 0x20
+ }, GetVersion, "DVD-Cops"),
};
- string match = MatchUtil.GetFirstMatch(file, fileContent, matchers, includeDebug);
+ string match = MatchUtil.GetFirstMatch(file, grandSectionRaw, matchers, includeDebug);
if (!string.IsNullOrWhiteSpace(match))
return match;
diff --git a/BurnOutSharp/ProtectionType/CenegaProtectDVD.cs b/BurnOutSharp/ProtectionType/CenegaProtectDVD.cs
index 6ad4bfbc..97660d90 100644
--- a/BurnOutSharp/ProtectionType/CenegaProtectDVD.cs
+++ b/BurnOutSharp/ProtectionType/CenegaProtectDVD.cs
@@ -1,6 +1,4 @@
-using System.Linq;
-using System.Text;
-using BurnOutSharp.ExecutableType.Microsoft;
+using BurnOutSharp.ExecutableType.Microsoft;
namespace BurnOutSharp.ProtectionType
{
@@ -15,8 +13,8 @@ namespace BurnOutSharp.ProtectionType
return null;
// Get the .cenega section, if it exists
- var cenegaSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".cenega"));
- if (cenegaSection != null)
+ bool cenegaSection = pex.ContainsSection(".cenega", exact: true);
+ if (cenegaSection)
return "Cenega ProtectDVD";
return null;
diff --git a/BurnOutSharp/ProtectionType/ProtectDisc.cs b/BurnOutSharp/ProtectionType/ProtectDisc.cs
index 78ec29d5..25305203 100644
--- a/BurnOutSharp/ProtectionType/ProtectDisc.cs
+++ b/BurnOutSharp/ProtectionType/ProtectDisc.cs
@@ -1,7 +1,6 @@
using System;
using System.Collections.Generic;
using System.Linq;
-using System.Text;
using BurnOutSharp.ExecutableType.Microsoft;
using BurnOutSharp.Matching;
@@ -99,8 +98,8 @@ namespace BurnOutSharp.ProtectionType
}
// Get the .vob.pcd section, if it exists
- var vobpcdSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".vob.pcd"));
- if (vobpcdSection != null)
+ bool vobpcdSection = pex.ContainsSection(".vob.pcd", exact: true);
+ if (vobpcdSection)
return "VOB ProtectCD";
return null;
diff --git a/BurnOutSharp/ProtectionType/SafeDisc.cs b/BurnOutSharp/ProtectionType/SafeDisc.cs
index b69467d6..e603fcbe 100644
--- a/BurnOutSharp/ProtectionType/SafeDisc.cs
+++ b/BurnOutSharp/ProtectionType/SafeDisc.cs
@@ -1,8 +1,6 @@
using System.Collections.Concurrent;
using System.Collections.Generic;
using System.IO;
-using System.Linq;
-using System.Text;
using BurnOutSharp.ExecutableType.Microsoft;
using BurnOutSharp.Matching;
using BurnOutSharp.Tools;
@@ -48,7 +46,7 @@ namespace BurnOutSharp.ProtectionType
return null;
// Get the .text section, if it exists -- TODO: Figure out how to capture this automatically
- var textSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".text"));
+ var textSection = pex.GetFirstSection(".text", exact: true);
if (textSection != null)
{
// This subtract is needed because BoG_ starts before the .text section
@@ -78,7 +76,7 @@ namespace BurnOutSharp.ProtectionType
}
// Get the .txt2 section, if it exists
- var txt2Section = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".txt2"));
+ var txt2Section = pex.GetFirstSection(".txt2", exact: true);
if (txt2Section != null)
{
// This subtract is needed because BoG_ starts before the .txt2 section
@@ -107,6 +105,36 @@ namespace BurnOutSharp.ProtectionType
return match;
}
+ // Get the CODE section, if it exists
+ var codeSection = pex.GetFirstSection("CODE", exact: true);
+ if (codeSection != null)
+ {
+ // This subtract is needed because BoG_ starts before the CODE section
+ int sectionAddr = (int)codeSection.PointerToRawData - 64;
+ int sectionEnd = sectionAddr + (int)codeSection.VirtualSize;
+ var matchers = new List
+ {
+ // BoG_ *90.0&!! Yy>
+ new ContentMatchSet(
+ new ContentMatch(new byte?[]
+ {
+ 0x42, 0x6F, 0x47, 0x5F, 0x20, 0x2A, 0x39, 0x30,
+ 0x2E, 0x30, 0x26, 0x21, 0x21, 0x20, 0x20, 0x59,
+ 0x79, 0x3E
+ }, start: sectionAddr, end: sectionEnd),
+ GetVersion, "SafeDisc"),
+
+ // (char)0x00 + (char)0x00 + BoG_
+ new ContentMatchSet(
+ new ContentMatch(new byte?[] { 0x00, 0x00, 0x42, 0x6F, 0x47, 0x5F }, start: sectionAddr, end: sectionEnd),
+ Get320to4xVersion, "SafeDisc"),
+ };
+
+ string match = MatchUtil.GetFirstMatch(file, fileContent, matchers, includeDebug);
+ if (!string.IsNullOrWhiteSpace(match))
+ return match;
+ }
+
// Get the .data section, if it exists
if (pex.DataSectionRaw != null)
{
@@ -130,9 +158,9 @@ namespace BurnOutSharp.ProtectionType
}
// Get the stxt371 and stxt774 sections, if they exist -- TODO: Confirm if both are needed or either/or is fine
- var stxt371Section = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith("stxt371"));
- var stxt774Section = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith("stxt774"));
- if (stxt371Section != null || stxt774Section != null)
+ bool stxt371Section = pex.ContainsSection("stxt371", exact: true);
+ bool stxt774Section = pex.ContainsSection("stxt774", exact: true);
+ if (stxt371Section || stxt774Section)
return $"SafeDisc {Get320to4xVersion(file, fileContent, null)}";
return null;
diff --git a/BurnOutSharp/ProtectionType/SecuROM.cs b/BurnOutSharp/ProtectionType/SecuROM.cs
index a556426f..bbb506fd 100644
--- a/BurnOutSharp/ProtectionType/SecuROM.cs
+++ b/BurnOutSharp/ProtectionType/SecuROM.cs
@@ -23,8 +23,8 @@ namespace BurnOutSharp.ProtectionType
return null;
// Get the .securom section, if it exists
- var securomSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".securom"));
- if (securomSection != null)
+ bool securomSection = pex.ContainsSection(".securom", exact: true);
+ if (securomSection)
return $"SecuROM {GetV7Version(fileContent)}";
// Search after the last section
@@ -97,9 +97,9 @@ namespace BurnOutSharp.ProtectionType
}
// Get the .cms_d and .cms_t sections, if they exist -- TODO: Confirm if both are needed or either/or is fine
- var cmsdSection = pex.GetFirstSection(".cmd_d", true);
- var cmstSection = pex.GetFirstSection(".cms_t", true);
- if (cmsdSection != null || cmstSection != null)
+ bool cmsdSection = pex.ContainsSection(".cmd_d", true);
+ bool cmstSection = pex.ContainsSection(".cms_t", true);
+ if (cmsdSection || cmstSection)
return $"SecuROM 1-3";
return null;
diff --git a/BurnOutSharp/ProtectionType/SmartE.cs b/BurnOutSharp/ProtectionType/SmartE.cs
index 5632da58..65eff0fd 100644
--- a/BurnOutSharp/ProtectionType/SmartE.cs
+++ b/BurnOutSharp/ProtectionType/SmartE.cs
@@ -1,8 +1,6 @@
using System.Collections.Concurrent;
using System.Collections.Generic;
using System.IO;
-using System.Linq;
-using System.Text;
using BurnOutSharp.ExecutableType.Microsoft;
using BurnOutSharp.ExecutableType.Microsoft.Headers;
using BurnOutSharp.Matching;
@@ -20,13 +18,13 @@ namespace BurnOutSharp.ProtectionType
return null;
// Get the .edata section, if it exists
- var edataSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".edata"));
+ var edataSection = pex.GetLastSection(".edata", exact: true);
string match = GetMatchForSection(edataSection, file, fileContent, includeDebug);
if (!string.IsNullOrWhiteSpace(match))
return match;
// Get the .idata section, if it exists
- var idataSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".idata"));
+ var idataSection = pex.GetLastSection(".idata", exact: true);
match = GetMatchForSection(idataSection, file, fileContent, includeDebug);
if (!string.IsNullOrWhiteSpace(match))
return match;
@@ -37,7 +35,7 @@ namespace BurnOutSharp.ProtectionType
return match;
// Get the .tls section, if it exists
- var tlsSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".tls"));
+ var tlsSection = pex.GetLastSection(".tls", exact: true);
match = GetMatchForSection(tlsSection, file, fileContent, includeDebug);
if (!string.IsNullOrWhiteSpace(match))
return match;
diff --git a/BurnOutSharp/ProtectionType/SolidShield.cs b/BurnOutSharp/ProtectionType/SolidShield.cs
index a5703871..97bb9010 100644
--- a/BurnOutSharp/ProtectionType/SolidShield.cs
+++ b/BurnOutSharp/ProtectionType/SolidShield.cs
@@ -2,7 +2,6 @@
using System.Collections.Concurrent;
using System.Collections.Generic;
using System.Linq;
-using System.Text;
using BurnOutSharp.ExecutableType.Microsoft;
using BurnOutSharp.Matching;
using BurnOutSharp.Tools;
@@ -67,26 +66,20 @@ namespace BurnOutSharp.ProtectionType
else if (!string.IsNullOrWhiteSpace(name) && name.StartsWith("Activation Manager", StringComparison.OrdinalIgnoreCase))
return $"SolidShield Activation Manager Module {GetFileVersion(pex)}";
- // Get the .init section, if it exists
- var initSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".init"));
- if (initSection != null)
+ // Get the .init section, if it exists
+ var initSectionRaw = pex.ReadRawSection(fileContent, ".init", true);
+ if (initSectionRaw != null)
{
- int sectionAddr = (int)initSection.PointerToRawData;
- int sectionEnd = sectionAddr + (int)initSection.VirtualSize;
var matchers = new List
{
// (char)0xEF + (char)0xBE + (char)0xAD + (char)0xDE
- new ContentMatchSet(
- new ContentMatch(new byte?[] { 0xEF, 0xBE, 0xAD, 0xDE }, start: sectionAddr, end: sectionEnd),
- GetExeWrapperVersion, "SolidShield EXE Wrapper"),
+ new ContentMatchSet(new byte?[] { 0xEF, 0xBE, 0xAD, 0xDE }, GetExeWrapperVersion, "SolidShield EXE Wrapper"),
// dvm.dll
- new ContentMatchSet(
- new ContentMatch(new byte?[] { 0x64, 0x76, 0x6D, 0x2E, 0x64, 0x6C, 0x6C }, start: sectionAddr, end: sectionEnd),
- "SolidShield EXE Wrapper v1"),
+ new ContentMatchSet(new byte?[] { 0x64, 0x76, 0x6D, 0x2E, 0x64, 0x6C, 0x6C }, "SolidShield EXE Wrapper v1"),
};
- string match = MatchUtil.GetFirstMatch(file, fileContent, matchers, includeDebug);
+ string match = MatchUtil.GetFirstMatch(file, initSectionRaw, matchers, includeDebug);
if (!string.IsNullOrWhiteSpace(match))
return match;
}
diff --git a/BurnOutSharp/ProtectionType/StarForce.cs b/BurnOutSharp/ProtectionType/StarForce.cs
index 43de09fa..d7a9a369 100644
--- a/BurnOutSharp/ProtectionType/StarForce.cs
+++ b/BurnOutSharp/ProtectionType/StarForce.cs
@@ -1,7 +1,5 @@
using System.Collections.Concurrent;
using System.Collections.Generic;
-using System.Linq;
-using System.Text;
using BurnOutSharp.ExecutableType.Microsoft;
using BurnOutSharp.Matching;
using BurnOutSharp.Tools;
@@ -29,7 +27,7 @@ namespace BurnOutSharp.ProtectionType
// TODO: Find this inside of the .rsrc section using the executable header
// Get the .rsrc section, if it exists
- var rsrcSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".rsrc"));
+ var rsrcSection = pex.GetLastSection(".rsrc", exact: true);
if (rsrcSection != null)
{
int sectionAddr = (int)rsrcSection.PointerToRawData;
@@ -54,13 +52,13 @@ namespace BurnOutSharp.ProtectionType
}
// Get the .brick section, if it exists
- var brickSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".brick"));
- if (brickSection != null)
+ bool brickSection = pex.ContainsSection(".brick", exact: true);
+ if (brickSection)
return "StarForce 3-5";
// Get the .sforce* section, if it exists
- var sforceSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".sforce"));
- if (sforceSection != null)
+ bool sforceSection = pex.ContainsSection(".sforce", exact: false);
+ if (sforceSection)
return "StarForce 3-5";
return null;
diff --git a/BurnOutSharp/ProtectionType/ThreePLock.cs b/BurnOutSharp/ProtectionType/ThreePLock.cs
index 03c179aa..f7833d29 100644
--- a/BurnOutSharp/ProtectionType/ThreePLock.cs
+++ b/BurnOutSharp/ProtectionType/ThreePLock.cs
@@ -1,6 +1,4 @@
-using System.Linq;
-using System.Text;
-using BurnOutSharp.ExecutableType.Microsoft;
+using BurnOutSharp.ExecutableType.Microsoft;
namespace BurnOutSharp.ProtectionType
{
@@ -18,9 +16,9 @@ namespace BurnOutSharp.ProtectionType
//"Y" + (char)0xC3 + "U" + (char)0x8B + (char)0xEC + (char)0x83 + (char)0xEC + "0SVW"
// Get the .ldr and .ldt sections, if they exist -- TODO: Confirm if both are needed or either/or is fine
- var cmsdSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".ldr"));
- var cmstSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith(".ldt"));
- if (cmsdSection != null || cmstSection != null)
+ bool cmsdSection = pex.ContainsSection(".ldr", exact: true);
+ bool cmstSection = pex.ContainsSection(".ldt", exact: true);
+ if (cmsdSection || cmstSection)
return $"3PLock";
return null;
diff --git a/BurnOutSharp/ProtectionType/WTMCDProtect.cs b/BurnOutSharp/ProtectionType/WTMCDProtect.cs
index 84887b84..a2d43f01 100644
--- a/BurnOutSharp/ProtectionType/WTMCDProtect.cs
+++ b/BurnOutSharp/ProtectionType/WTMCDProtect.cs
@@ -1,7 +1,5 @@
using System.Collections.Concurrent;
using System.Collections.Generic;
-using System.Linq;
-using System.Text;
using BurnOutSharp.ExecutableType.Microsoft;
using BurnOutSharp.Matching;
@@ -18,24 +16,20 @@ namespace BurnOutSharp.ProtectionType
return null;
// Get the CODE section, if it exists
- var codeSection = sections.FirstOrDefault(s => Encoding.ASCII.GetString(s.Name).StartsWith("CODE"));
- if (codeSection != null)
+ var codeSectionRaw = pex.ReadRawSection(fileContent, "CODE", true);
+ if (codeSectionRaw != null)
{
- int sectionAddr = (int)codeSection.PointerToRawData;
- int sectionEnd = sectionAddr + (int)codeSection.VirtualSize;
var matchers = new List
{
// wtmdum.imp
- new ContentMatchSet(
- new ContentMatch(new byte?[]
- {
- 0x77, 0x74, 0x6D, 0x64, 0x75, 0x6D, 0x2E, 0x69,
- 0x6D, 0x70
- }, start: sectionAddr, end: sectionEnd),
- "WTM CD Protect"),
+ new ContentMatchSet(new byte?[]
+ {
+ 0x77, 0x74, 0x6D, 0x64, 0x75, 0x6D, 0x2E, 0x69,
+ 0x6D, 0x70
+ }, "WTM CD Protect"),
};
- string match = MatchUtil.GetFirstMatch(file, fileContent, matchers, includeDebug);
+ string match = MatchUtil.GetFirstMatch(file, codeSectionRaw, matchers, includeDebug);
if (!string.IsNullOrWhiteSpace(match))
return match;
}