From c64abc15c940d5ba50151599d4a4777c909348cc Mon Sep 17 00:00:00 2001 From: Matt Nadareski Date: Sun, 4 Dec 2022 23:00:30 -0800 Subject: [PATCH] Move .rsrc StarForce checks to new file --- BurnOutSharp/ProtectionType/StarForce.cs | 67 --------------- BurnOutSharp/ProtectionType/StarForceRSRC.cs | 88 ++++++++++++++++++++ 2 files changed, 88 insertions(+), 67 deletions(-) create mode 100644 BurnOutSharp/ProtectionType/StarForceRSRC.cs diff --git a/BurnOutSharp/ProtectionType/StarForce.cs b/BurnOutSharp/ProtectionType/StarForce.cs index bdb2af64..8b9ab205 100644 --- a/BurnOutSharp/ProtectionType/StarForce.cs +++ b/BurnOutSharp/ProtectionType/StarForce.cs @@ -2,7 +2,6 @@ using System.Collections.Concurrent; using System.Collections.Generic; using BurnOutSharp.Interfaces; -using BurnOutSharp.Matching; using BurnOutSharp.Tools; using BurnOutSharp.Wrappers; @@ -36,34 +35,6 @@ namespace BurnOutSharp.ProtectionType // TODO: Check to see if there are any missing checks // https://github.com/horsicq/Detect-It-Easy/blob/master/db/PE/StarForce.2.sg - // TODO: Find this inside of the .rsrc section using the executable header - // Get the .rsrc section, if it exists - var rsrcSection = pex.GetLastSection(".rsrc", exact: true); - if (rsrcSection != null) - { - var rsrcSectionData = pex.GetLastSectionData(".rsrc"); - if (rsrcSectionData != null) - { - var matchers = new List - { - // P + (char)0x00 + r + (char)0x00 + o + (char)0x00 + t + (char)0x00 + e + (char)0x00 + c + (char)0x00 + t + (char)0x00 + e + (char)0x00 + d + (char)0x00 + + (char)0x00 + M + (char)0x00 + o + (char)0x00 + d + (char)0x00 + u + (char)0x00 + l + (char)0x00 + e + (char)0x00 - new ContentMatchSet( - new byte?[] - { - 0x50, 0x00, 0x72, 0x00, 0x6f, 0x00, 0x74, 0x00, - 0x65, 0x00, 0x63, 0x00, 0x74, 0x00, 0x65, 0x00, - 0x64, 0x00, 0x20, 0x00, 0x4d, 0x00, 0x6f, 0x00, - 0x64, 0x00, 0x75, 0x00, 0x6c, 0x00, 0x65, 0x00 - }, - "StarForce 5 [Protected Module]"), - }; - - string match = MatchUtil.GetFirstMatch(file, rsrcSectionData, matchers, includeDebug); - if (!string.IsNullOrWhiteSpace(match)) - return match; - } - } - // Get the .brick section, if it exists bool brickSection = pex.ContainsSection(".brick", exact: true); if (brickSection) @@ -106,43 +77,5 @@ namespace BurnOutSharp.ProtectionType // return MatchUtil.GetFirstMatch(path, matchers, any: true); return null; } - - // This section contains extraneous checks in the .rsrc section that have not been confirmed - // new ContentMatchSet(new List - // { - // // P + (char)0x00 + r + (char)0x00 + o + (char)0x00 + t + (char)0x00 + e + (char)0x00 + c + (char)0x00 + t + (char)0x00 + i + (char)0x00 + o + (char)0x00 + n + (char)0x00 + + (char)0x00 + T + (char)0x00 + e + (char)0x00 + c + (char)0x00 + h + (char)0x00 + n + (char)0x00 + o + (char)0x00 + l + (char)0x00 + o + (char)0x00 + g + (char)0x00 + y + (char)0x00 - // new ContentMatch(new byte?[] - // { - // 0x50, 0x00, 0x72, 0x00, 0x6F, 0x00, 0x74, 0x00, - // 0x65, 0x00, 0x63, 0x00, 0x74, 0x00, 0x69, 0x00, - // 0x6F, 0x00, 0x6E, 0x00, 0x20, 0x00, 0x54, 0x00, - // 0x65, 0x00, 0x63, 0x00, 0x68, 0x00, 0x6E, 0x00, - // 0x6F, 0x00, 0x6C, 0x00, 0x6F, 0x00, 0x67, 0x00, - // 0x79, 0x00 - // }, start: sectionAddr, end: sectionEnd), - - // // // PSA_GetDiscLabel - // // new ContentMatch(new byte?[] - // // { - // // 0x50, 0x53, 0x41, 0x5F, 0x47, 0x65, 0x74, 0x44, - // // 0x69, 0x73, 0x63, 0x4C, 0x61, 0x62, 0x65, 0x6C - // // }, start: sectionAddr, end: sectionEnd), - - // // (c) Protection Technology - // // new ContentMatch(new byte?[] - // // { - // // 0x28, 0x63, 0x29, 0x20, 0x50, 0x72, 0x6F, 0x74, - // // 0x65, 0x63, 0x74, 0x69, 0x6F, 0x6E, 0x20, 0x54, - // // 0x65, 0x63, 0x68, 0x6E, 0x6F, 0x6C, 0x6F, 0x67, - // // 0x79 - // // }, start: sectionAddr, end: sectionEnd), - - // // TradeName - // new ContentMatch(new byte?[] { 0x54, 0x72, 0x61, 0x64, 0x65, 0x4E, 0x61, 0x6D, 0x65 }, start: sectionAddr, end: sectionEnd), - // }, GetVersion, "StarForce"), - // public static string GetVersion(string file, byte[] fileContent, List positions) - // { - // return $"{Utilities.GetInternalVersion(fileContent)} ({fileContent.Skip(positions[1] + 22).TakeWhile(c => c != 0x00)})"; - // } } } diff --git a/BurnOutSharp/ProtectionType/StarForceRSRC.cs b/BurnOutSharp/ProtectionType/StarForceRSRC.cs new file mode 100644 index 00000000..9a456f14 --- /dev/null +++ b/BurnOutSharp/ProtectionType/StarForceRSRC.cs @@ -0,0 +1,88 @@ +using System.Collections.Generic; +using System.Linq; +using BurnOutSharp.Interfaces; +using BurnOutSharp.Matching; +using BurnOutSharp.Tools; +using BurnOutSharp.Wrappers; + +namespace BurnOutSharp.ProtectionType +{ + public class StarForceRSRC : IPortableExecutableCheck + { + /// + public string CheckPortableExecutable(string file, PortableExecutable pex, bool includeDebug) + { + // Get the sections from the executable, if possible + var sections = pex?.SectionTable; + if (sections == null) + return null; + + // Get the .rsrc section, if it exists + var rsrcSection = pex.GetLastSection(".rsrc", exact: true); + if (rsrcSection != null) + { + var rsrcSectionData = pex.GetLastSectionData(".rsrc"); + if (rsrcSectionData != null) + { + var matchers = new List + { + // P + (char)0x00 + r + (char)0x00 + o + (char)0x00 + t + (char)0x00 + e + (char)0x00 + c + (char)0x00 + t + (char)0x00 + e + (char)0x00 + d + (char)0x00 + + (char)0x00 + M + (char)0x00 + o + (char)0x00 + d + (char)0x00 + u + (char)0x00 + l + (char)0x00 + e + (char)0x00 + new ContentMatchSet( + new byte?[] + { + 0x50, 0x00, 0x72, 0x00, 0x6f, 0x00, 0x74, 0x00, + 0x65, 0x00, 0x63, 0x00, 0x74, 0x00, 0x65, 0x00, + 0x64, 0x00, 0x20, 0x00, 0x4d, 0x00, 0x6f, 0x00, + 0x64, 0x00, 0x75, 0x00, 0x6c, 0x00, 0x65, 0x00 + }, + "StarForce 5 [**Protected Module**] (Unconfirmed - Please report to us on Github)"), + + new ContentMatchSet(new List + { + // P + (char)0x00 + r + (char)0x00 + o + (char)0x00 + t + (char)0x00 + e + (char)0x00 + c + (char)0x00 + t + (char)0x00 + i + (char)0x00 + o + (char)0x00 + n + (char)0x00 + + (char)0x00 + T + (char)0x00 + e + (char)0x00 + c + (char)0x00 + h + (char)0x00 + n + (char)0x00 + o + (char)0x00 + l + (char)0x00 + o + (char)0x00 + g + (char)0x00 + y + (char)0x00 + new ContentMatch(new byte?[] + { + 0x50, 0x00, 0x72, 0x00, 0x6F, 0x00, 0x74, 0x00, + 0x65, 0x00, 0x63, 0x00, 0x74, 0x00, 0x69, 0x00, + 0x6F, 0x00, 0x6E, 0x00, 0x20, 0x00, 0x54, 0x00, + 0x65, 0x00, 0x63, 0x00, 0x68, 0x00, 0x6E, 0x00, + 0x6F, 0x00, 0x6C, 0x00, 0x6F, 0x00, 0x67, 0x00, + 0x79, 0x00 + }), + + // // PSA_GetDiscLabel + new ContentMatch(new byte?[] + { + 0x50, 0x53, 0x41, 0x5F, 0x47, 0x65, 0x74, 0x44, + 0x69, 0x73, 0x63, 0x4C, 0x61, 0x62, 0x65, 0x6C + }), + + // (c) Protection Technology + new ContentMatch(new byte?[] + { + 0x28, 0x63, 0x29, 0x20, 0x50, 0x72, 0x6F, 0x74, + 0x65, 0x63, 0x74, 0x69, 0x6F, 0x6E, 0x20, 0x54, + 0x65, 0x63, 0x68, 0x6E, 0x6F, 0x6C, 0x6F, 0x67, + 0x79 + }), + + // TradeName + new ContentMatch(new byte?[] { 0x54, 0x72, 0x61, 0x64, 0x65, 0x4E, 0x61, 0x6D, 0x65 }), + }, GetVersion, "StarForce [**Large Combined Check**] (Unconfirmed - Please report to us on Github)"), + }; + + string match = string.Join(", ", MatchUtil.GetAllMatches(file, rsrcSectionData, matchers, includeDebug)); + if (!string.IsNullOrWhiteSpace(match)) + return match; + } + } + + return null; + } + + public static string GetVersion(string file, byte[] fileContent, List positions) + { + return $"{Utilities.GetInternalVersion(file)} ({fileContent.Skip(positions[1] + 22).TakeWhile(c => c != 0x00)})"; + } + } +}