Image From Clipboard (original) (raw)

/�������css_descramble.c������������Released�under�the�version�2�of�the�GPL.������������Copyright�1999�Derek�Fawcus������������This�file�contains�functions�to�descramble�CSS�encrypted�DVD�conten t����������/��������/�������Still�in�progress:��Remove�the�use�of�the�bit_reverse[]�table�by�recoding���������������������������the�generation�of�LFSR1.��Finish�combining�this�with���������������� �����������the�css�authentication�code.����������/��������#include�(stdio.h)����#include�(string.h)����#include�"css-descramble.h"��������typedef�unsigned�char�byte;��������/������������some�tables �used�for�descrambling�sectors�and/or�decrypting�title�keys����������*/��������static�byte�csstab1[256]=����{�����0x33,0x73,0x3b,0x26,0x63,0x23,0x6b,0x76,0x3e,0x7e,0x36,0x2b,0x6e,0x2e,0x66,0x7b,�����0x d3,0x93,0xdb,0x06,0x43,0x03,0x4b,0x96,0xde,0x9e,0xd6,0x0b,0x4e,0x0e,0x46,0x9b,�����0x57,0x17,0x5f,0x82,0xc7,0x87,0xcf,0x12,0x5a,0x1a,0x52,0x8f,0xca,0x8a,0xc2,0x1f,�����0xd9,0x99,0xd1,0x00,0x49,0x09,0x41 ,0x90,0xd8,0x98,0xd0,0x01,0x48,0x08,0x40,0x91,�����0x3d,0x7d,0x35,0x24,0x6d,0x2d,0x65,0x74,0x3c,0x7c,0x34,0x25,0x6c,0x2c,0x64,0x75,�����0xdd,0x9d,0xd5,0x04,0x4d,0x0d,0x45,0x94,0xdc,0x9c,0xd4,0x05,0x4c,0 x0c,0x44,0x95,�����0x59,0x19,0x51,0x80,0xc9,0x89,0xc1,0x10,0x58,0x18,0x50,0x81,0xc8,0x88,0xc0,0x11,�����0xd7,0x97,0xdf,0x02,0x47,0x07,0x4f,0x92,0xda,0x9a,0xd2,0x0f,0x4a,0x0a,0x42,0x9f,�����0x53,0x13,0x5 b,0x86,0xc3,0x83,0xcb,0x16,0x5e,0x1e,0x56,0x8b,0xce,0x8e,0xc6,0x1b,�����0xb3,0xf3,0xbb,0xa6,0xe3,0xa3,0xeb,0xf6,0xbe,0xfe,0xb6,0xab,0xee,0xae,0xe6,0xfb,�����0x37,0x77,0x3f,0x22,0x67,0x27,0x6f,0x72,0x3a, 0x7a,0x32,0x2f,0x6a,0x2a,0x62,0x7f,�����0xb9,0xf9,0xb1,0xa0,0xe9,0xa9,0xe1,0xf0,0xb8,0xf8,0xb0,0xa1,0xe8,0xa8,0xe0,0xf1,�����0x5d,0x1d,0x55,0x84,0xcd,0x8d,0xc5,0x14,0x5c,0x1c,0x54,0x85,0xcc,0x8c,0xc4,0x 15,�����0xbd,0xfd,0xb5,0xa4,0xed,0xad,0xe5,0xf4,0xbc,0xfc,0xb4,0xa5,0xec,0xac,0xe4,0xf5,�����0x39,0x79,0x31,0x20,0x69,0x29,0x61,0x70,0x38,0x78,0x30,0x21,0x68,0x28,0x60,0x71,�����0xb7,0xf7,0xbf,0xa2,0xe7 ,0xa7,0xef,0xf2,0xba,0xfa,0xb2,0xaf,0xea,0xaa,0xe2,0xff����};��������static�byte�lfsr1_bits0[256]=����{�����0x00,0x01,0x02,0x03,0x04,0x05,0x06,0x07,0x09,0x08,0x0b,0x0a,0x0d,0x0c,0x0f,0x0e,�����0x12,0x13 ,0x10,0x11,0x16,0x17,0x14,0x15,0x1b,0x1a,0x19,0x18,0x1f,0x1e,0x1d,0x1c,�����0x24,0x25,0x26,0x27,0x20,0x21,0x22,0x23,0x2d,0x2c,0x2f,0x2e,0x29,0x28,0x2b,0x2a,�����0x36,0x37,0x34,0x35,0x32,0x33,0x30,0x31,0 x3f,0x3e,0x3d,0x3c,0x3b,0x3a,0x39,0x38,�����0x49,0x48,0x4b,0x4a,0x4d,0x4c,0x4f,0x4e,0x40,0x41,0x42,0x43,0x44,0x45,0x46,0x47,�����0x5b,0x5a,0x59,0x58,0x5f,0x5e,0x5d,0x5c,0x52,0x53,0x50,0x51,0x56,0x57,0x5 4,0x55,�����0x6d,0x6c,0x6f,0x6e,0x69,0x68,0x6b,0x6a,0x64,0x65,0x66,0x67,0x60,0x61,0x62,0x63,�����0x7f,0x7e,0x7d,0x7c,0x7b,0x7a,0x79,0x78,0x76,0x77,0x74,0x75,0x72,0x73,0x70,0x71,�����0x92,0x93,0x90,0x91, 0x96,0x97,0x94,0x95,0x9b,0x9a,0x99,0x98,0x9f,0x9e,0x9d,0x9c,�����0x80,0x81,0x82,0x83,0x84,0x85,0x86,0x87,0x89,0x88,0x8b,0x8a,0x8d,0x8c,0x8f,0x8e,�����0xb6,0xb7,0xb4,0xb5,0xb2,0xb3,0xb0,0xb1,0xbf,0xbe,0x bd,0xbc,0xbb,0xba,0xb9,0xb8,�����0xa4,0xa5,0xa6,0xa7,0xa0,0xa1,0xa2,0xa3,0xad,0xac,0xaf,0xae,0xa9,0xa8,0xab,0xaa,�����0xdb,0xda,0xd9,0xd8,0xdf,0xde,0xdd,0xdc,0xd2,0xd3,0xd0,0xd1,0xd6,0xd7,0xd4,0xd5,���� �0xc9,0xc8,0xcb,0xca,0xcd,0xcc,0xcf,0xce,0xc0,0xc1,0xc2,0xc3,0xc4,0xc5,0xc6,0xc7,�����0xff,0xfe,0xfd,0xfc,0xfb,0xfa,0xf9,0xf8,0xf6,0xf7,0xf4,0xf5,0xf2,0xf3,0xf0,0xf1,�����0xed,0xec,0xef,0xee,0xe9,0xe8,0 xeb,0xea,0xe4,0xe5,0xe6,0xe7,0xe0,0xe1,0xe2,0xe3����};��������static�byte�lfsr1_bits1[512]=����{�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0 x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x2 4,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff, �����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0x b6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d ,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0 x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xf f,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6, 0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x 6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24 ,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,� ����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb 6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d, 0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,�����0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff,0x00,0x24,0x49,0x6d,0x92,0xb6,0xdb,0xff����};������� �/�Reverse�the�order�of�the�bits�within�a�byte.�����/����static�byte�bit_reverse[256]=����{�����0x00,0x80,0x40,0xc0,0x20,0xa0,0x60,0xe0,0x10,0x90,0x50,0xd0,0x30,0xb0,0x70,0xf0,�����0x08,0x88,0x48,0xc8 ,0x28,0xa8,0x68,0xe8,0x18,0x98,0x58,0xd8,0x38,0xb8,0x78,0xf8,�����0x04,0x84,0x44,0xc4,0x24,0xa4,0x64,0xe4,0x14,0x94,0x54,0xd4,0x34,0xb4,0x74,0xf4,�����0x0c,0x8c,0x4c,0xcc,0x2c,0xac,0x6c,0xec,0x1c,0x9c,0 x5c,0xdc,0x3c,0xbc,0x7c,0xfc,�����0x02,0x82,0x42,0xc2,0x22,0xa2,0x62,0xe2,0x12,0x92,0x52,0xd2,0x32,0xb2,0x72,0xf2,�����0x0a,0x8a,0x4a,0xca,0x2a,0xaa,0x6a,0xea,0x1a,0x9a,0x5a,0xda,0x3a,0xba,0x7a,0xfa,��� ��0x06,0x86,0x46,0xc6,0x26,0xa6,0x66,0xe6,0x16,0x96,0x56,0xd6,0x36,0xb6,0x76,0xf6,�����0x0e,0x8e,0x4e,0xce,0x2e,0xae,0x6e,0xee,0x1e,0x9e,0x5e,0xde,0x3e,0xbe,0x7e,0xfe,�����0x01,0x81,0x41,0xc1,0x21,0xa1, 0x61,0xe1,0x11,0x91,0x51,0xd1,0x31,0xb1,0x71,0xf1,�����0x09,0x89,0x49,0xc9,0x29,0xa9,0x69,0xe9,0x19,0x99,0x59,0xd9,0x39,0xb9,0x79,0xf9,�����0x05,0x85,0x45,0xc5,0x25,0xa5,0x65,0xe5,0x15,0x95,0x55,0xd5,0x 35,0xb5,0x75,0xf5,�����0x0d,0x8d,0x4d,0xcd,0x2d,0xad,0x6d,0xed,0x1d,0x9d,0x5d,0xdd,0x3d,0xbd,0x7d,0xfd,�����0x03,0x83,0x43,0xc3,0x23,0xa3,0x63,0xe3,0x13,0x93,0x53,0xd3,0x33,0xb3,0x73,0xf3,�����0x0b,0x8b ,0x4b,0xcb,0x2b,0xab,0x6b,0xeb,0x1b,0x9b,0x5b,0xdb,0x3b,0xbb,0x7b,0xfb,�����0x07,0x87,0x47,0xc7,0x27,0xa7,0x67,0xe7,0x17,0x97,0x57,0xd7,0x37,0xb7,0x77,0xf7,�����0x0f,0x8f,0x4f,0xcf,0x2f,0xaf,0x6f,0xef,0 x1f,0x9f,0x5f,0xdf,0x3f,0xbf,0x7f,0xff����};��������/�����������this�function�is�only�used�internally�when�decrypting�title�key����������*/����static�void�css_titlekey(byte�key,�byte�im,�byte�inve rt)����{�����unsigned�int�lfsr1_lo,lfsr1_hi,lfsr0,combined;�����byte�o_lfsr0,�o_lfsr1;�����byte�k[5];�����int�i;���������lfsr1_lo�=�im[0]�|�0x100;�����lfsr1_hi�=�im[1];���������lfsr0�=�((im[4]�((�17)�|� (im[3]�((�9)�|�(im[2]�((�1))�+�8�-�(im[2]&7);�����lfsr0�=�(bit_reverselfsr0&0xff&0xff]�((�16)��������|�(bit_reverse(lfsr0))16)&0xff24)&0xff] ;���������combined�=�0;�����for�(i�=�0;�i�(�5;�++i)�{������o_lfsr1��=�lfsr1_bits0[lfsr1_hi]�^�lfsr1_bits1[lfsr1_lo];��������lfsr1_hi�=�lfsr1_lo))1;��������lfsr1_lo�=�((lfsr1_lo&1)((8)�^�o_lfsr1;������o_ lfsr1��=�bit_reverse[o_lfsr1];����������/o_lfsr0�=�(lfsr0))7)^(lfsr0))10)^(lfsr0))11)^(lfsr0))19);/������o_lfsr0�=�(((((((lfsr0))8)^lfsr0)))1)^lfsr0)))3)^lfsr0)))7);��������lfsr0�=�(lfsr0))8)|(o_lfsr0 ((24);����������combined�+=�(o_lfsr0�^�invert)�+�o_lfsr1;������k[i]�=�combined�&�0xff;������combined�))=�8;�����}���������key[4]=k[4]^csstab1[key[4]]^key[3];�����key[3]=k[3]^csstab1[key[3]]^key[2];����� key[2]=k[2]^csstab1[key[2]]^key[1];�����key[1]=k[1]^csstab1[key[1]]^key[0];�����key[0]=k[0]^csstab1[key[0]]^key[4];���������key[4]=k[4]^csstab1[key[4]]^key[3];�����key[3]=k[3]^csstab1[key[3]]^key[2];��� ��key[2]=k[2]^csstab1[key[2]]^key[1];�����key[1]=k[1]^csstab1[key[1]]^key[0];�����key[0]=k[0]^csstab1[key[0]];����}��������/�����������this�function�decrypts�a�title�key�with�the�specified�disk�key�� ���������tkey:�the�unobfuscated�title�key�(XORed�with�BusKey)������dkey:�the�unobfuscated�disk�key�(XORed�with�BusKey)������������2048�bytes�in�length�(though�only�5�bytes�are�needed,�see�below)���� ��pkey:�array�of�pointers�to�player�keys�and�disk�key�offsets����������������use�the�result�returned�in�tkey�with�css_descramble����������*/��������int�css_decrypttitlekey(byte�tkey,�byte�dkey,�s truct�playkey�*pkey)����{�����byte�test[5],�pretkey[5];�����int�i�=�0;���������for�(;�pkey;�++pkey,�++i)�{������memcpy(pretkey,�dkey�+�(pkey)-)offset,�5);������css_titlekey(pretkey,�(pkey)-)key,�0); ����������memcpy(test,�dkey,�5);������css_titlekey(test,�pretkey,�0);����������if�(memcmp(test,�pretkey,�5)�==�0)�{�������fprintf(stderr,�"Using�Key�%d\n",�i+1);�������break;������}�����}���������if�(! pkey)�{������fprintf(stderr,�"Shit�-�Need�Key�%d\n",�i+1);������return�0;�����}���������css_titlekey(tkey,�pretkey,�0xff);���������return�1;����}��������/�����������this�function�does�the�actual�desc rambling�����������sec:�encrypted�sector�(2048�bytes)������key:�decrypted�title�key�obtained�from�css_decrypttitlekey����������*/����void�css_descramble(byte�sec,byte�key)����{�����unsigned�int�lf sr1_lo,lfsr1_hi,lfsr0,combined;�����unsigned�char�o_lfsr0,�o_lfsr1;�����unsigned�char�end�=�sec�+�0x800;����#define�SALTED(i)�(key[i]�^�sec[0x54�+�(i)])���������lfsr1_lo�=�SALTED(0)�|�0x100;�����lfsr1_ hi�=�SALTED(1);���������lfsr0�=�((SALTED(4)�((�17)�|�(SALTED(3)�((�9)�|�(SALTED(2)�((�1))�+�8�-�(SALTED(2)&7);�����lfsr0�=�(bit_reverselfsr0&0xff&0xff]�((�16)��������|�( bit_reverse(lfsr0))16)&0xff24)&0xff];���������sec+=0x80;�����combined�=�0;�����while�(sec�!=�end)�{������o_lfsr1��=�lfsr1_bits0[lfsr1_hi]�^�lfsr1_bits1[lfsr1_lo];��������lfs r1_hi�=�lfsr1_lo))1;��������lfsr1_lo�=�((lfsr1_lo&1)((8)�^�o_lfsr1;������o_lfsr1��=�bit_reverse[o_lfsr1];����������/o_lfsr0�=�(lfsr0))7)^(lfsr0))10)^(lfsr0))11)^(lfsr0))19);/������o_lfsr0�=�(((((((lfs r0))8)^lfsr0)))1)^lfsr0)))3)^lfsr0)))7);��������lfsr0�=�(lfsr0))8)|(o_lfsr0((24);����������combined�+=�o_lfsr0�+�(byte)~o_lfsr1;������sec++�=�csstab1[*sec]�^�(combined&0xff);������combined�))=�8;�����} ����}/�###############################################################################################################################################################################################�/