{"id":357671,"date":"2024-05-20T23:55:32","date_gmt":"2024-05-20T23:55:32","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=357671"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=357671","title":{"rendered":"<span>\u0414\u0435\u043b\u0430\u0435\u043c crackme. \u0427\u0430\u0441\u0442\u044c \u0432\u0442\u043e\u0440\u0430\u044f: \u0448\u0438\u0444\u0440\u0443\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u0438<\/span>"},"content":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>\u042d\u0442\u0430 \u0441\u0442\u0430\u0442\u044c\u044f \u0432\u0442\u043e\u0440\u0430\u044f \u0432 \u0446\u0438\u043a\u043b\u0435 \u043f\u043e \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044e crackme \u043f\u043e\u0434 linux amd64. \u0412 \u044d\u0442\u043e\u0439 \u0447\u0430\u0441\u0442\u0438 \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043a\u0430\u0436\u0434\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u0431\u0443\u0434\u0435\u0442 \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0430 \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u043c \u043a\u043b\u044e\u0447\u043e\u043c, \u0438 \u0431\u0443\u0434\u0435\u0442 \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u0442\u044c\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0430 \u0432\u0440\u0435\u043c\u044f \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f. \u041f\u0440\u043e\u0446\u0435\u0441\u0441 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0431\u0443\u0434\u0435\u0442 \u043f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d, \u0442\u043e \u0435\u0441\u0442\u044c \u043f\u0440\u0438 \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0438\u0438 \u043d\u043e\u0432\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0438\u043b\u0438 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0438 \u0441\u0442\u0430\u0440\u043e\u0433\u043e \u043d\u0438\u043a\u0430\u043a\u0438\u0445 \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0445 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0439 \u0434\u0435\u043b\u0430\u0442\u044c \u0431\u0443\u0434\u0435\u0442 \u043d\u0435 \u043d\u0443\u0436\u043d\u043e. \u041a\u043e\u0434 \u0432\u0441\u0435\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0432 <a href=\"https:\/\/github.com\/cyberfined\/nanomites\" rel=\"noopener noreferrer nofollow\"><u>\u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438<\/u><\/a> \u043d\u0430 github.<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/articles\/760672\/\" rel=\"noopener noreferrer nofollow\"><u>\u041f\u0435\u0440\u0432\u0430\u044f \u0447\u0430\u0441\u0442\u044c<\/u><\/a>.<\/p>\n<\/li>\n<li>\n<p>\u0412\u0442\u043e\u0440\u0430\u044f \u0447\u0430\u0441\u0442\u044c.<\/p>\n<\/li>\n<\/ul>\n<h2>\u0410\u043b\u0433\u043e\u0440\u0438\u0442\u043c<\/h2>\n<p>\u0410\u043b\u0433\u043e\u0440\u0438\u0442\u043c \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0442\u0430\u043a\u043e\u0433\u043e \u0431\u0438\u043d\u0430\u0440\u043d\u0438\u043a\u0430 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043f\u0440\u043e\u0441\u0442, \u0440\u0430\u0441\u043f\u0438\u0448\u0435\u043c \u0435\u0433\u043e \u043f\u043e \u0448\u0430\u0433\u0430\u043c:<\/p>\n<ol>\n<li>\n<p>\u0421\u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043a\u043e\u0434 \u0432 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b \u0442\u0430\u043a, \u0447\u0442\u043e\u0431\u044b \u043a\u0430\u0436\u0434\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u0438\u043c\u0435\u043b\u0430 \u0440\u0430\u0437\u043c\u0435\u0440 \u043a\u0440\u0430\u0442\u043d\u044b\u0439 16. \u042d\u0442\u043e \u0443\u0441\u043b\u043e\u0432\u0438\u0435 \u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u0438\u0437 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 CBC \u043c\u043e\u0436\u043d\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0442\u043e\u043b\u044c\u043a\u043e \u0441 \u0431\u0443\u0444\u0435\u0440\u0430\u043c\u0438, \u0440\u0430\u0437\u043c\u0435\u0440 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043a\u0440\u0430\u0442\u0435\u043d \u0440\u0430\u0437\u043c\u0435\u0440\u0443 \u0431\u043b\u043e\u043a\u0430, \u0442\u043e \u0435\u0441\u0442\u044c 16.<\/p>\n<\/li>\n<li>\n<p>\u0421\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043a\u043b\u044e\u0447 \u0438 \u0432\u0435\u043a\u0442\u043e\u0440 \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0434\u043b\u044f \u043a\u0430\u0436\u0434\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u0437\u0430\u0442\u0435\u043c \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u0442\u044c \u0438\u0445. \u041f\u043e\u0441\u043b\u0435 \u044d\u0442\u043e\u0433\u043e \u043f\u0435\u0440\u0435\u0434\u0430\u0442\u044c \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e \u0444\u0443\u043d\u043a\u0446\u0438\u044f\u0445 (\u0430\u0434\u0440\u0435\u0441 \u0438 \u0440\u0430\u0437\u043c\u0435\u0440), \u0430 \u0442\u0430\u043a\u0436\u0435 \u043a\u043b\u044e\u0447\u0438 \u0438 \u0432\u0435\u043a\u0442\u043e\u0440\u044b \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0435 \u0434\u043b\u044f \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 AddRoundKey \u0438 get_iv, \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u044f \u043e\u043f\u0438\u0441\u0430\u043b \u0432 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0447\u0430\u0441\u0442\u0438. \u041f\u043e\u0441\u043b\u0435 \u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0448\u0430\u0433\u0430 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b \u0438\u0437\u043c\u0435\u043d\u0438\u0442\u0441\u044f \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c:<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/d9c\/ea4\/829\/d9cea4829f4243d788e71e8a50523970.png\" alt=\"img\" title=\"\u0428\u0430\u0433 2\" width=\"241\" height=\"371\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/d9c\/ea4\/829\/d9cea4829f4243d788e71e8a50523970.png\"\/><\/p>\n<div><figcaption>\u0428\u0430\u0433 2<\/figcaption><\/div>\n<\/figure>\n<\/li>\n<li>\n<p>\u0421\u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043a\u043e\u0434 \u0434\u0432\u0438\u0436\u043a\u0430, \u043e\u0442\u0432\u0435\u0447\u0430\u044e\u0449\u0435\u0433\u043e \u0437\u0430 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0438 \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u043d\u0438\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0439. \u041e\u043d \u043a\u0430\u043a \u0440\u0430\u0437 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u043a\u043e\u0434, \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043d\u0430 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u043c \u0448\u0430\u0433\u0435. \u0427\u0442\u043e\u0431\u044b \u0441\u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043a\u043e\u0434 \u0434\u0432\u0438\u0436\u043a\u0430 \u043c\u043e\u0436\u043d\u043e \u0431\u044b\u043b\u043e \u0432\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0432 \u043d\u0430\u0448 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b, \u043d\u0443\u0436\u043d\u043e \u043f\u0435\u0440\u0435\u0434\u0430\u0442\u044c \u043a\u043e\u043c\u043f\u0438\u043b\u044f\u0442\u043e\u0440\u0443 \u0444\u043b\u0430\u0433 <code>-fPIC<\/code>, \u0447\u0442\u043e\u0431\u044b \u043a\u043e\u0434 \u0431\u044b\u043b \u043f\u043e\u0437\u0438\u0446\u0438\u043e\u043d\u043d\u043e-\u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u044b\u043c.<\/p>\n<\/li>\n<li>\n<p>\u0412\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u043a\u043e\u0434 \u0434\u0432\u0438\u0436\u043a\u0430 \u0432 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b, \u0432\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0432 \u043d\u0430\u0447\u0430\u043b\u043e \u043a\u0430\u0436\u0434\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044e call \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043a\u043e\u0434\u0430 \u0434\u0432\u0438\u0436\u043a\u0430. \u0417\u0434\u0435\u0441\u044c \u043f\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u0430\u044f \u0441 \u0442\u0435\u043c, \u0447\u0442\u043e \u043c\u044b \u043d\u0435 \u043c\u043e\u0436\u0435\u043c \u043c\u0435\u043d\u044f\u0442\u044c \u0440\u0430\u0437\u043c\u0435\u0440 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0442\u043e\u0433\u0434\u0430 \u0443 \u0434\u0440\u0443\u0433\u0438\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 \u043f\u043e\u043c\u0435\u043d\u044f\u044e\u0442\u0441\u044f \u0430\u0434\u0440\u0435\u0441\u0430, \u0447\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0439, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043e\u0431\u0440\u0430\u0449\u0430\u044e\u0442\u0441\u044f \u043a \u043f\u0430\u043c\u044f\u0442\u0438. \u041f\u043e\u044d\u0442\u043e\u043c\u0443 \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0437\u0430\u043c\u0435\u043d\u044f\u0442\u044c \u043f\u0435\u0440\u0432\u044b\u0435 5 \u0431\u0430\u0439\u0442 \u043a\u0430\u0436\u0434\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u043d\u0430 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044e call, \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b\u044c\u043d\u044b\u0435 \u0436\u0435 5 \u0431\u0430\u0439\u0442 \u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0432 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0443 \u0438 \u043f\u0440\u0438 \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u043d\u0438\u0438 \u0431\u0443\u0434\u0435\u043c \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0438\u0445 \u0438\u0437 \u043d\u0435\u0451 \u043e\u0431\u0440\u0430\u0442\u043d\u043e \u0432 \u043d\u0430\u0447\u0430\u043b\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0438. \u041f\u043e\u0441\u043b\u0435 \u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0448\u0430\u0433\u0430 \u043d\u0430\u0448 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b \u0431\u0443\u0434\u0435\u0442 \u0432\u044b\u0433\u043b\u044f\u0434\u0435\u0442\u044c \u0442\u0430\u043a:<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/7b7\/c43\/27c\/7b7c4327c685e8f1acd27d85e7c9e1e9.png\" alt=\"img\" title=\"\u0428\u0430\u0433 4\" width=\"371\" height=\"531\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/7b7\/c43\/27c\/7b7c4327c685e8f1acd27d85e7c9e1e9.png\"\/><\/p>\n<div><figcaption>\u0428\u0430\u0433 4<\/figcaption><\/div>\n<\/figure>\n<\/li>\n<\/ol>\n<h2>\u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f<\/h2>\n<h3>\u0421\u043e\u0437\u0434\u0430\u0451\u043c \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b<\/h3>\n<p>\u041a\u0430\u043a\u00a0\u044f \u043f\u0438\u0441\u0430\u043b \u0432\u044b\u0448\u0435, \u043d\u0430\u043c \u043d\u0443\u0436\u043d\u043e \u0441\u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043a\u043e\u0434 \u0442\u0430\u043a, \u0447\u0442\u043e\u0431\u044b \u0440\u0430\u0437\u043c\u0435\u0440\u044b \u0432\u0441\u0435\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0439\u00a0\u0431\u044b\u043b\u0438 \u043a\u0440\u0430\u0442\u043d\u044b 16. \u0414\u043b\u044f\u00a0\u043d\u0430\u0447\u0430\u043b\u0430 \u043d\u0430\u043f\u0438\u0448\u0435\u043c \u043f\u0440\u043e\u0441\u0442\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430\u00a0\u0441\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0438 \u0431\u0443\u0434\u0435\u043c \u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c. \u041c\u044b \u043d\u0435\u00a0\u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u0443\u044e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0443, \u0442\u0430\u043a \u043a\u0430\u043a\u00a0\u0438\u043d\u0430\u0447\u0435 \u0443\u00a0\u043d\u0430\u0441 \u0431\u0443\u0434\u0435\u0442 \u0441\u043b\u0438\u0448\u043a\u043e\u043c \u043c\u043d\u043e\u0433\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0439, \u0430\u00a0\u043a\u0430\u043a\u00a0\u043c\u044b \u0432\u044b\u044f\u0441\u043d\u0438\u043b\u0438 \u0432\u00a0\u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u0433\u043b\u0430\u0432\u0435, \u0447\u0435\u043c \u0431\u043e\u043b\u044c\u0448\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0439, \u0442\u0435\u043c \u0431\u043e\u043b\u044c\u0448\u0435 \u0440\u0430\u0437\u043c\u0435\u0440 AddRoundKey, \u0442\u0435\u043c \u043c\u0435\u0434\u043b\u0435\u043d\u043d\u0435\u0435 \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0438 \u043a\u043e\u043c\u043f\u0438\u043b\u044f\u0446\u0438\u044f. \u0421\u0430\u043c \u043a\u043e\u0434 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u043d\u0438\u0436\u0435:<\/p>\n<p>start.s:<\/p>\n<pre><code class=\"assembly\">.text .globl _start .type _start,@function .section .text._start _start:     # Call main     movq (%rsp), %rdi     leaq 8(%rsp), %rsi     callq main      # Exit     movq %rax, %rdi     movq $60, %rax     syscall .size _start,.-_start<\/code><\/pre>\n<p>crackme.c:<\/p>\n<pre><code class=\"cpp\">#define write(fd, buf, count) syscall3(1, fd, (long)buf, count)  __attribute__((always_inline)) static inline long syscall3(long n, long a1, long a2, long a3) {   unsigned long ret;   __asm__ __volatile__ (\"syscall\" : \"=a\"(ret) : \"a\"(n), \"D\"(a1), \"S\"(a2),                                             \"d\"(a3) : \"rcx\", \"r11\", \"memory\");   return ret; }  static int calc_hash(unsigned char *pass) {   int hash = 0;   while(*pass) {     hash += (*pass + 11) % 23;     pass++;   }   return hash; }  \/\/ \u041f\u0430\u0440\u043e\u043b\u044c - Hello Habr!? int main(int argc, char **argv) {   if(argc != 2)     return 1;    int hash = calc_hash((unsigned char*)argv[1]);   if(hash != 152) {     char failure[] = \"Password is wrong\\n\";     write(1, failure, sizeof(failure));     return 1;   }    char success[] = \"Password is right!\\n\";   write(1, success, sizeof(success)); }<\/code><\/pre>\n<p>\u0415\u0441\u0442\u044c \u043e\u0434\u0438\u043d \u043f\u0440\u043e\u0441\u0442\u043e\u0439 \u0441\u043f\u043e\u0441\u043e\u0431, \u043a\u0430\u043a\u00a0\u0441\u0434\u0435\u043b\u0430\u0442\u044c \u0440\u0430\u0437\u043c\u0435\u0440\u044b \u0432\u0441\u0435\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 \u043a\u0440\u0430\u0442\u043d\u044b\u043c\u0438 16\u00a0\u2014 \u043f\u043e\u043c\u0435\u0441\u0442\u0438\u0442\u044c \u043a\u0430\u0436\u0434\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044e \u0432\u00a0\u043e\u0442\u0434\u0435\u043b\u044c\u043d\u0443\u044e \u0441\u0435\u043a\u0446\u0438\u044e \u0438 \u0437\u0430\u0434\u0430\u0442\u044c \u0432\u00a0\u0441\u043a\u0440\u0438\u043f\u0442\u0435 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0430 \u0432\u044b\u0440\u0430\u0432\u043d\u0438\u0432\u0430\u043d\u0438\u0435 \u0434\u043b\u044f\u00a0\u043a\u0430\u0436\u0434\u043e\u0439 \u0442\u0430\u043a\u043e\u0439 \u0441\u0435\u043a\u0446\u0438\u0438. \u041f\u0435\u0440\u0432\u0430\u044f \u0437\u0430\u0434\u0430\u0447\u0430 \u0440\u0435\u0448\u0430\u0435\u0442\u0441\u044f \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0435\u0439 \u0444\u043b\u0430\u0433\u0430 <code>-ffunction-sections<\/code> \u043a\u043e\u043c\u043f\u0438\u043b\u044f\u0442\u043e\u0440\u0443 gcc, \u0432\u0442\u043e\u0440\u0430\u044f\u00a0\u2014 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0435\u0439 \u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0430. \u0414\u043b\u044f\u00a0\u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u044f \u0440\u0435\u0448\u0438\u043b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0435 \u043a\u043e\u043d\u0441\u043e\u043b\u044c\u043d\u044b\u0435 \u0443\u0442\u0438\u043b\u0438\u0442\u044b\u00a0\u2014 readelf \u0438 awk. \u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u0441\u00a0\u043f\u043e\u043c\u043e\u0449\u044c\u044e readelf \u043f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0438\u0437\u00a0\u043e\u0431\u044a\u0435\u043a\u0442\u043d\u044b\u0445 \u0444\u0430\u0439\u043b\u043e\u0432 \u0438\u043c\u0435\u043d\u0430 \u0441\u0435\u043a\u0446\u0438\u0439, \u0437\u0430\u0442\u0435\u043c \u0441\u00a0\u043f\u043e\u043c\u043e\u0449\u044c\u044e awk \u043d\u0430\u00a0\u0438\u0445 \u043e\u0441\u043d\u043e\u0432\u0435 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c \u0441\u043a\u0440\u0438\u043f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0430. \u0422\u0435\u043a\u0441\u0442 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b \u043d\u0430\u00a0awk \u043f\u0440\u0438\u0432\u0435\u0434\u0451\u043d \u043d\u0438\u0436\u0435.<\/p>\n<p>create_linker_script.awk:<\/p>\n<pre><code>BEGIN {   print \"ENTRY(_start)\\nSECTIONS {\\n    . = 0x400000;\\n\" \\         \"    .text : {\\n        * (.data)\\n        * (.rodata)\" }  {   if($2 ~ \/^\\.text\\..*\/)       matched=$2;   else if($3 ~ \/^\\.text\\..*\/)       matched=$3;   else       next;    print \"\\n        . = ALIGN(16);\\n        * (\"matched\")\\n        . = ALIGN(16);\" }  END {   print \"    }\\n}\" }<\/code><\/pre>\n<p>\u041c\u044b \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c, \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u0442\u0441\u044f \u043b\u0438 \u0432\u0442\u043e\u0440\u043e\u0439 \u0438\u043b\u0438 \u0442\u0440\u0435\u0442\u0438\u0439 \u0441\u0442\u043e\u043b\u0431\u0435\u0446 \u0441 .text, \u0435\u0441\u043b\u0438 \u043d\u0435\u0442, \u0442\u043e \u043f\u0440\u043e\u043f\u0443\u0441\u043a\u0430\u0435\u043c \u0441\u0442\u0440\u043e\u043a\u0443, \u0438\u043d\u0430\u0447\u0435 \u043f\u0435\u0447\u0430\u0442\u0430\u0435\u043c \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u0441\u0435\u043a\u0446\u0438\u0438 \u0432\u043c\u0435\u0441\u0442\u0435 \u0441 ALIGN(16). \u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0434\u0432\u0443\u0445 \u0441\u0442\u043e\u043b\u0431\u0446\u043e\u0432 \u0441\u0432\u044f\u0437\u0430\u043d\u0430 \u0441 \u0442\u0435\u043c, \u0447\u0442\u043e readelf \u0432\u044b\u0440\u0430\u0432\u043d\u0438\u0432\u0430\u0435\u0442 \u043d\u043e\u043c\u0435\u0440\u0430 \u0441\u0435\u043a\u0446\u0438\u0439, \u0434\u043b\u044f \u0441\u0435\u043a\u0446\u0438\u0439 \u0441 \u043e\u0434\u043d\u043e\u0437\u043d\u0430\u0447\u043d\u044b\u043c\u0438 \u043d\u043e\u043c\u0435\u0440\u0430\u043c\u0438 \u0438\u043c\u044f \u0431\u0443\u0434\u0435\u0442 \u0432 \u0442\u0440\u0435\u0442\u044c\u0435\u043c \u0441\u0442\u043e\u043b\u0431\u0446\u0435, \u0430 \u0434\u043b\u044f \u0441\u0435\u043a\u0446\u0438\u0439 \u0441 \u0434\u0432\u0443\u0445\u0437\u043d\u0430\u0447\u043d\u044b\u043c\u0438 \u043d\u043e\u043c\u0435\u0440\u0430\u043c\u0438 &#8212; \u0432\u043e \u0432\u0442\u043e\u0440\u043e\u043c. \u041f\u0440\u0438\u043c\u0435\u0440 \u0432\u044b\u0432\u043e\u0434\u0430 readelf \u0434\u043b\u044f \u043b\u0443\u0447\u0448\u0435\u0433\u043e \u043f\u043e\u043d\u0438\u043c\u0430\u043d\u0438\u044f:<\/p>\n<pre><code>There are 32 section headers, starting at offset 0x22258:  Section Headers:   [Nr] Name              Type            Address          Off    Size   ES Flg Lk Inf Al   [ 0]                   NULL            0000000000000000 000000 000000 00      0   0  0   [ 1] .interp           PROGBITS        0000000000000318 000318 00001c 00   A  0   0  1   [ 2] .note.gnu.property NOTE            0000000000000338 000338 000050 00   A  0   0  8   [ 3] .note.gnu.build-id NOTE            0000000000000388 000388 000024 00   A  0   0  4   [ 4] .note.ABI-tag     NOTE            00000000000003ac 0003ac 000020 00   A  0   0  4   [ 5] .note.package     NOTE            00000000000003cc 0003cc 00008c 00   A  0   0  4   [ 6] .gnu.hash         GNU_HASH        0000000000000458 000458 000040 00   A  7   0  8   [ 7] .dynsym           DYNSYM          0000000000000498 000498 000c48 18   A  8   1  8   [ 8] .dynstr           STRTAB          00000000000010e0 0010e0 000625 00   A  0   0  1   [ 9] .gnu.version      VERSYM          0000000000001706 001706 000106 02   A  7   0  2   [10] .gnu.version_r    VERNEED         0000000000001810 001810 0000d0 00   A  8   2  8 <\/code><\/pre>\n<p>\u041f\u043e\u0447\u0435\u043c\u0443 \u043c\u044b \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c, \u0447\u0442\u043e \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u0441\u0435\u043a\u0446\u0438\u0438 \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u0442\u0441\u044f \u0441 .text? \u041f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u043f\u0440\u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0435 \u0444\u043b\u0430\u0433\u0430 <code>-ffunction-sections<\/code> gcc \u043a\u043b\u0430\u0434\u0451\u0442 \u043a\u0430\u0436\u0434\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044e \u0432 \u0441\u0432\u043e\u044e \u0441\u0435\u043a\u0446\u0438\u044e \u0441 \u0438\u043c\u0435\u043d\u0435\u043c, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u043c \u0448\u0430\u0431\u043b\u043e\u043d\u0443 .text.\u0438\u043c\u044f_\u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u0438\u043c\u0435\u043d\u043d\u043e \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0440\u0430\u043d\u0435\u0435 \u043c\u044b \u044f\u0432\u043d\u043e \u0443\u043a\u0430\u0437\u0430\u043b\u0438 <code>.section .text._start<\/code> \u0434\u043b\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u0438 _start. \u0422\u0435\u043f\u0435\u0440\u044c \u043d\u0430\u043f\u0438\u0448\u0435\u043c Makefile \u0434\u043b\u044f \u0441\u0431\u043e\u0440\u043a\u0438 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430:<\/p>\n<pre><code>CC=gcc CFLAGS=-Wall -std=c11 -fno-stack-protector -Wno-builtin-declaration-mismatch \\        -fno-stack-protector -ffunction-sections -O0 LDFLAGS=-nostdlib -nostartfiles -nodefaultlibs -static -z noexecstack \\         -Wl,-z,noseparate-code AS=as  .PHONY: all clean all: crackme-unencrypted crackme-unencrypted: linker.ld start.o crackme.o         $(CC) $(LDFLAGS) -T linker.ld start.o crackme.o -o crackme-unencrypted linker.ld: start.o crackme.o         readelf --wide -S start.o crackme.o | awk -f create_linker_script.awk > linker.ld crackme.o: crackme.c         $(CC) $(CFLAGS) -c crackme.c -o crackme.o start.o: start.s         $(AS) -c start.s -o start.o clean:         rm -f start.o crackme.o linker.ld crackme-unencrypted<\/code><\/pre>\n<p>\u041a\u0430\u043a \u043c\u043e\u0436\u043d\u043e \u0432\u0438\u0434\u0435\u0442\u044c \u043f\u043e \u0444\u043b\u0430\u0433\u0430\u043c \u043a\u043e\u043c\u043f\u0438\u043b\u044f\u0446\u0438\u0438 &#8212; \u043c\u044b \u0441\u043e\u0431\u0438\u0440\u0430\u0435\u043c \u0441\u0442\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b \u0431\u0435\u0437 \u043b\u0438\u043d\u043a\u043e\u0432\u043a\u0438 \u0441\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e\u0439 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u043e\u0439. \u0421\u0442\u043e\u0438\u0442 \u0442\u0430\u043a\u0436\u0435 \u043e\u0431\u0440\u0430\u0442\u0438\u0442\u044c \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e readelf \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0441 \u0444\u043b\u0430\u0433\u043e\u043c <code>--wide<\/code>, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0438\u043d\u0430\u0447\u0435 \u0438\u043c\u0435\u043d\u0430 \u0441\u0435\u043a\u0446\u0438\u0439 \u043c\u043e\u0433\u0443\u0442 \u0432\u044b\u0432\u043e\u0434\u0438\u0442\u0441\u044f \u043d\u0435 \u043f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e. \u0414\u043b\u044f \u043d\u0430\u0433\u043b\u044f\u0434\u043d\u043e\u0441\u0442\u0438 \u0434\u0430\u043b\u0435\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0451\u043d \u0442\u0435\u043a\u0441\u0442 \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0430:<\/p>\n<pre><code>ENTRY(_start) SECTIONS {     . = 0x400000;     .text : {         * (.data)         * (.rodata)          . = ALIGN(16);         * (.text._start)         . = ALIGN(16);          . = ALIGN(16);         * (.text.calc_hash)         . = ALIGN(16);          . = ALIGN(16);         * (.text.main)         . = ALIGN(16);     } }<\/code><\/pre>\n<h3>\u0428\u0438\u0444\u0440\u0443\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u0438<\/h3>\n<p>\u0421\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e .\/utils\/patcher, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0431\u0443\u0434\u0435\u0442 \u0445\u0440\u0430\u043d\u0438\u0442\u0441\u044f \u043a\u043e\u0434 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u0443\u0434\u0435\u0442 \u043c\u043e\u0434\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043d\u0430\u0448 \u0431\u0438\u043d\u0430\u0440\u043d\u0438\u043a, \u0438 \u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0442\u0443\u0434\u0430 \u0444\u0430\u0439\u043b\u044b <a href=\"https:\/\/github.com\/cyberfined\/nanomites\/blob\/master\/utils\/patcher\/aes.h\" rel=\"noopener noreferrer nofollow\">aes.h<\/a>, <a href=\"https:\/\/github.com\/cyberfined\/nanomites\/blob\/master\/utils\/patcher\/aes.c\" rel=\"noopener noreferrer nofollow\">aes.c<\/a>, \u044f\u0432\u043b\u044f\u044e\u0449\u0438\u0435\u0441\u044f \u043c\u043e\u0434\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c\u0438 \u0444\u0430\u0439\u043b\u0430\u043c\u0438 \u0438\u0437 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 <a href=\"https:\/\/github.com\/kokke\/tiny-AES-c\" rel=\"noopener noreferrer nofollow\">tiny-AES-c<\/a>. \u0414\u043b\u044f \u043b\u0443\u0447\u0448\u0435\u0433\u043e \u043f\u043e\u043d\u0438\u043c\u0430\u043d\u0438\u044f \u043a\u043e\u0434\u0430, \u0434\u0430\u043b\u0435\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d\u0430 \u0441\u0438\u0433\u043d\u0430\u0442\u0443\u0440\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u043a\u043e\u0442\u043e\u0440\u043e\u044e \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f:<\/p>\n<pre><code class=\"cpp\">struct AES_ctx {   uint8_t *RoundKey;   uint8_t *Iv; };  void AES_CBC_encrypt_buffer(struct AES_ctx *ctx, uint8_t* buf, size_t length);<\/code><\/pre>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u043f\u0440\u0438\u0441\u0442\u0443\u043f\u0438\u043c \u043a \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044e \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043b\u044c\u0449\u0438\u043a\u0430. \u041d\u0430\u0447\u043d\u0451\u043c \u0441 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0438\u044f \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u0434\u043b\u044f \u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u043e\u0431 ELF \u0444\u0430\u0439\u043b\u0435 \u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0441\u0447\u0438\u0442\u044b\u0432\u0430\u0435\u0442 ELF \u0444\u0430\u0439\u043b \u0432 \u0434\u0430\u043d\u043d\u0443\u044e \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443:<\/p>\n<pre><code class=\"cpp\">typedef struct {   const char *filepath;   uint8_t    *mem;   size_t     size;   Elf64_Ehdr *ehdr;   Elf64_Phdr *phdrs;   Elf64_Shdr *shdrs;   Elf64_Sym  *symbols;   size_t     num_symbols;   char       *sh_names;   char       *sym_names; } elf_t;  \/\/ \u042d\u0442\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u043d\u0430\u0445\u043e\u0434\u0438\u0442 \u0441\u0435\u043a\u0446\u0438\u044e \u0441 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u043c \u0442\u0438\u043f\u043e\u043c. static Elf64_Shdr* section_by_type(elf_t *elf, uint32_t sh_type) {   for(size_t i = 0; i &lt; elf->ehdr->e_shnum; i++) {     if(elf->shdrs[i].sh_type == sh_type)       return &amp;elf->shdrs[i];   }   return NULL; }  static bool open_elf(const char *filepath, elf_t *elf) {   elf->mem = MAP_FAILED;    int fd = open(filepath, O_RDONLY);   if(fd &lt; 0) {     perror(\"open_elf (open)\");     goto error;   }    struct stat statbuf;   if(fstat(fd, &amp;statbuf) &lt; 0) {     perror(\"open_elf (fstat)\");     goto error;   }    elf->filepath = filepath;   elf->size = statbuf.st_size;   elf->mem = mmap(NULL, elf->size, PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0);   if(elf->mem == MAP_FAILED) {     perror(\"open_elf (mmap)\");     goto error;   }    elf->ehdr = (Elf64_Ehdr*)elf->mem;   elf->phdrs = (Elf64_Phdr*)(elf->mem + elf->ehdr->e_phoff);   elf->shdrs = (Elf64_Shdr*)(elf->mem + elf->ehdr->e_shoff);    if(elf->ehdr->e_shnum != 0) {     \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u043e\u0431\u043b\u0430\u0441\u0442\u044c \u043f\u0430\u043c\u044f\u0442\u0438 \u0441 \u0438\u043c\u0435\u043d\u0430\u043c\u0438 \u0441\u0435\u043a\u0446\u0438\u0439.     elf->sh_names = (char*)elf->mem + elf->shdrs[elf->ehdr->e_shstrndx].sh_offset;      \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043e\u043a \u0441\u0435\u043a\u0446\u0438\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0445\u0440\u0430\u043d\u044f\u0442\u0441\u044f     \/\/ \u0438\u043c\u0435\u043d\u0430 \u0441\u0438\u043c\u0432\u043e\u043b\u043e\u0432.     Elf64_Shdr *sh_strtab = section_by_name(elf, \".strtab\");     if(!sh_strtab) {       fputs(\"Failed to find strtab section\\n\", stderr);       goto error;     }     \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u043e\u0431\u043b\u0430\u0441\u0442\u044c \u043f\u0430\u043c\u044f\u0442\u0438 \u0441 \u0438\u043c\u0435\u043d\u0430\u043c\u0438 \u0441\u0438\u043c\u0432\u043e\u043b\u043e\u0432.     elf->sym_names = (char*)elf->mem + sh_strtab->sh_offset;      \/\/ \u041d\u0430\u0445\u043e\u0434\u0438\u043c \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043e\u043a \u0441\u0435\u043a\u0446\u0438\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0445\u0440\u0430\u043d\u044f\u0442\u0441\u044f \u0441\u0438\u043c\u0432\u043e\u043b\u044b.     Elf64_Shdr *sym_shdr = section_by_type(elf, SHT_SYMTAB);     if(!sym_shdr) {       fputs(\"Executable does not have a symtab\\n\", stderr);       goto error;     }     \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u043e\u0431\u043b\u0430\u0441\u0442\u044c \u043f\u0430\u043c\u044f\u0442\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439     \/\/ \u043b\u0435\u0436\u0430\u0442 \u0441\u0438\u043c\u0432\u043e\u043b\u044b.     elf->symbols = (void*)elf->mem + sym_shdr->sh_offset;     \/\/ \u0412\u044b\u0447\u0438\u0441\u043b\u044f\u0435\u043c \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u0441\u0438\u043c\u0432\u043e\u043b\u043e\u0432, \u0440\u0430\u0437\u0434\u0435\u043b\u0438\u0432 \u0440\u0430\u0437\u043c\u0435\u0440 \u0441\u0435\u043a\u0446\u0438\u0438     \/\/ \u0441 \u0441\u0438\u043c\u0432\u043e\u043b\u0430\u043c\u0438 \u043d\u0430 \u0440\u0430\u0437\u043c\u0435\u0440 \u043e\u0434\u043d\u043e\u0433\u043e \u0441\u0438\u043c\u0432\u043e\u043b\u0430.     elf->num_symbols = sym_shdr->sh_size \/ sizeof(Elf64_Sym);   }    close(fd);   return true; error:   if(fd >= 0) close(fd);   if(elf->mem != MAP_FAILED) munmap(elf->mem, elf->size);   return false; }<\/code><\/pre>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u043d\u0430\u043f\u0438\u0448\u0435\u043c \u043f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0443 \u0434\u043b\u044f \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043e\u0434\u043d\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438:<\/p>\n<pre><code class=\"cpp\">typedef struct {   uint64_t addr;   uint32_t size;   uint8_t  iv[16];   uint8_t  key[240]; } func_data;  \/\/ \u0414\u0430\u043d\u043d\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u043e\u043a\u0440\u0443\u0433\u043b\u044f\u0435\u0442 x \u0432\u0432\u0435\u0440\u0445 \u0434\u043e align, \u043f\u0440\u0438 \u0443\u0441\u043b\u043e\u0432\u0438\u0438, \u0447\u0442\u043e \/\/ align \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0441\u0442\u0435\u043f\u0435\u043d\u044c\u044e \u0434\u0432\u043e\u0439\u043a\u0438. static inline uint32_t roundup(uint32_t x, uint32_t align) {   return (x + align - 1) &amp; (~(align - 1)); }  \/\/ elf - ELF \u0444\u0430\u0439\u043b, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u0448\u0438\u0444\u0440\u0443\u044e\u0442\u0441\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u0438. \/\/ func - \u0441\u0438\u043c\u0432\u043e\u043b, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u0445\u0440\u0430\u043d\u0438\u0442\u0441\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0438. \/\/ data - \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443, \u0432 \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0437\u0430\u043d\u043e\u0441\u0438\u0442\u044c \u043d\u0443\u0436\u043d\u0443\u044e \u043d\u0430\u043c \/\/ \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0432\u043c\u0435\u0441\u0442\u0435 \u0441 \u043a\u043b\u044e\u0447\u043e\u043c \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0432\u0435\u043a\u0442\u043e\u0440\u043e\u043c \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438. \/\/ \u041a\u043b\u044e\u0447 \u0438 \u0432\u0435\u043a\u0442\u043e\u0440 \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u044f\u0442\u0441\u044f \u043d\u0430\u043c \u043f\u043e\u0437\u0436\u0435 \u0434\u043b\u044f \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u043a\u043e\u0434\u0430 \/\/ AddRoundKey, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043c\u044b \u0438 \u0441\u043e\u0445\u0440\u0430\u043d\u044f\u0435\u043c \u0438\u0445 \u0432 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443. static void encrypt_function(elf_t *elf, Elf64_Sym *func, func_data *data) {   \/\/ \u0418\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u0435\u043c \u043a\u043b\u044e\u0447 \u0438 \u0432\u0435\u043a\u0442\u043e\u0440 \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u044b\u043c\u0438 \u0434\u0430\u043d\u043d\u044b\u043c\u0438   \/\/ \u0438\u0437 \/dev\/urandom.   getrandom(data->key, sizeof(data->key), 0);   getrandom(data->iv, sizeof(data->iv), 0);    \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0430\u0434\u0440\u0435\u0441 \u0444\u0443\u043d\u043a\u0446\u0438\u0438.   data->addr = func->st_value;    \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0440\u0430\u0437\u043c\u0435\u0440 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u043e\u043a\u0440\u0443\u0433\u043b\u0451\u043d\u043d\u044b\u0439 \u0432 \u0431\u043e\u043b\u044c\u0448\u0443\u044e \u0441\u0442\u043e\u0440\u043e\u043d\u0443 \u0434\u043e   \/\/ \u0440\u0430\u0437\u043c\u0435\u0440\u043e\u0432 \u0431\u043b\u043e\u043a\u0430. \u0420\u0430\u043d\u0435\u0435 \u043c\u044b \u0441\u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u043b\u0438 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b \u0442\u0430\u043a,   \/\/ \u0447\u0442\u043e\u0431\u044b \u0440\u0430\u0437\u043c\u0435\u0440 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 \u0431\u044b\u043b \u043a\u0440\u0430\u0442\u0435\u043d 16. \u0415\u0441\u043b\u0438 \u0440\u0430\u0437\u043c\u0435\u0440 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u043d\u0435 \u043a\u0440\u0430\u0442\u0435\u043d   \/\/ 16, \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a \u0437\u0430\u043f\u043e\u043b\u043d\u0438\u0442 \u043d\u0443\u0436\u043d\u043e\u0435 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u043e \u043d\u0443\u043b\u044f\u043c\u0438, \u043e\u0434\u043d\u0430\u043a\u043e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f   \/\/ \u043e \u0440\u0430\u0437\u043c\u0435\u0440\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0432 ELF \u0444\u0430\u0439\u043b\u0435 \u043d\u0435 \u043f\u043e\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0440\u0430\u0437\u043c\u0435\u0440 \u043f\u0440\u0438\u0445\u043e\u0434\u0438\u0442\u0441\u044f   \/\/ \u043e\u043a\u0440\u0443\u0433\u043b\u044f\u0442\u044c.   data->size = roundup(func->st_size, AES_BLOCKLEN);    \/\/ \u0417\u0430\u0433\u043e\u043b\u043e\u0432\u043e\u043a \u0441\u0435\u043a\u0446\u0438\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0448\u0438\u0444\u0440\u0443\u0435\u043c\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044f.   Elf64_Shdr *func_shdr = &amp;elf->shdrs[func->st_shndx];    \/\/ \u0423\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u0442\u0435\u043b\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0438.   \/\/ st_value - \u0430\u0434\u0440\u0435\u0441 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0432 \u043f\u0430\u043c\u044f\u0442\u0438, sh_addr - \u0430\u0434\u0440\u0435\u0441 \u0441\u0435\u043a\u0446\u0438\u0438 \u0432 \u043f\u0430\u043c\u044f\u0442\u0438,   \/\/ \u0442\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c st_value - sh_addr - \u0441\u043c\u0435\u0449\u0435\u043d\u0438\u0435 \u043d\u0430\u0447\u0430\u043b\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u043e\u0442 \u043d\u0430\u0447\u0430\u043b\u0430   \/\/ \u0441\u0435\u043a\u0446\u0438\u0438. sh_offset - \u0441\u043c\u0435\u0449\u0435\u043d\u0438\u0435 \u0441\u0435\u043a\u0446\u0438\u0438 \u043e\u0442 \u043d\u0430\u0447\u0430\u043b\u0430 \u0444\u0430\u0439\u043b\u0430, \u043f\u043e\u044d\u0442\u043e\u043c\u0443   \/\/ sh_offset + st_value - sh_adrr - \u0441\u043c\u0435\u0449\u0435\u043d\u0438\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u043e\u0442 \u043d\u0430\u0447\u0430\u043b\u0430 \u0444\u0430\u0439\u043b\u0430.   uint8_t *func_start = elf->mem + func_shdr->sh_offset +                         func->st_value - func_shdr->sh_addr;    \/\/ \u0428\u0438\u0444\u0440\u0443\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u044e.   struct AES_ctx ctx = (struct AES_ctx) { .RoundKey = data->key, .Iv = data->iv };   AES_CBC_encrypt_buffer(&amp;ctx, func_start, data->size); }<\/code><\/pre>\n<p>\u0414\u0430\u043b\u0435\u0435 \u0441\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u043f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0443, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u0443\u0434\u0435\u0442 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u0442\u044c \u0432\u0441\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0438:<\/p>\n<pre><code class=\"cpp\">\/\/ \u041f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0430, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0439. static size_t count_functions(elf_t *elf) {   size_t num_functions = 0;   for(size_t i = 0; i &lt; elf->num_symbols; i++) {     if(ELF64_ST_TYPE(elf->symbols[i].st_info) != STT_FUNC)       continue;      num_functions++;   }    return num_functions; }  static bool encrypt_and_generate_add_round_key(   \/\/ ELF \u0444\u0430\u0439\u043b.   elf_t *elf,   \/\/ \u041a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0439 \u0432 \u043d\u0451\u043c.   size_t num_functions,   \/\/ \u041f\u0443\u0442\u044c \u0434\u043e \u0444\u0430\u0439\u043b\u0430, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043c\u044b \u043f\u043e\u043c\u0435\u0441\u0442\u0438\u043c \u043a\u043e\u0434 AddRoundKey.   const char* addr_round_key ) {   bool result = false;   func_data *funcs_data = malloc(sizeof(func_data) * num_functions);   if(!funcs_data) {       perror(\"encrypt_and_generate_add_round_key (malloc)\");       goto exit;   }    size_t func_idx = 0;   \/\/ \u041f\u0440\u043e\u0445\u043e\u0434\u0438\u043c\u0441\u044f \u043f\u043e \u0432\u0441\u0435\u043c \u0441\u0438\u043c\u0432\u043e\u043b\u0430\u043c.   for(size_t i = 0; i &lt; elf->num_symbols; i++) {       \/\/ \u0415\u0441\u043b\u0438 \u0441\u0438\u043c\u0432\u043e\u043b \u043d\u0435 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u0435\u0439, \u043d\u0438\u0447\u0435\u0433\u043e \u043d\u0435 \u0434\u0435\u043b\u0430\u0435\u043c.       if(ELF64_ST_TYPE(elf->symbols[i].st_info) != STT_FUNC)           continue;       \/\/ \u0418\u043d\u0430\u0447\u0435 \u0448\u0438\u0444\u0440\u0443\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u044e.       encrypt_function(elf, &amp;elf->symbols[i], &amp;funcs_data[func_idx++]);   }    \/\/ \u042d\u0442\u0443 \u043f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0443 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0434\u0430\u043b\u0435\u0435, \u0432 \u043d\u0435\u0439 \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430   \/\/ gen-add-round-key, \u0441\u043e\u0437\u0434\u0430\u043d\u043d\u0430\u044f \u0432 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435.   if(!generate_add_round_key(funcs_data, num_functions, addr_round_key))       goto exit;    result = true; exit:   if(funcs_data) free(funcs_data);   return result; }<\/code><\/pre>\n<p>\u041f\u0440\u0438\u0441\u0442\u0443\u043f\u0438\u043c \u043a \u043f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0435 generate_add_round_key. \u041f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430 gen-add-round-key \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0435\u0442 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442\u044b \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438: <code>-a<\/code>, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043f\u0435\u0440\u0435\u0434\u0430\u0451\u0442\u0441\u044f \u0430\u0434\u0440\u0435\u0441 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u0438 <code>-s<\/code>, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043f\u0435\u0440\u0435\u0434\u0430\u0451\u0442\u0441\u044f \u0440\u0430\u0437\u043c\u0435\u0440 \u0444\u0443\u043d\u043a\u0446\u0438\u0438. \u0412\u0435\u043a\u0442\u043e\u0440 \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0438 \u043a\u043b\u044e\u0447 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430 \u0441\u0447\u0438\u0442\u044b\u0432\u0430\u0435\u0442 \u0438\u0437 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e\u0433\u043e \u0432\u0432\u043e\u0434\u0430. \u041a\u043e\u0434 \u043f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u044b generate_add_round_key \u0438\u043c\u0435\u0435\u0442 \u0432\u0438\u0434:<\/p>\n<pre><code class=\"cpp\">\/\/ \u041c\u0430\u043a\u0441\u0438\u043c\u0430\u043b\u044c\u043d\u044b\u0439 \u0440\u0430\u0437\u043c\u0435\u0440 \u0441\u0442\u0440\u043e\u043a\u0438, \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u0439 64-\u0431\u0438\u0442\u043d\u043e\u0435 \u0447\u0438\u0441\u043b\u043e. #define UINT64_MAX_STRING_SIZE 20 \/\/ \u041c\u0430\u043a\u0441\u0438\u043c\u0430\u043b\u044c\u043d\u044b\u0439 \u0440\u0430\u0437\u043c\u0435\u0440 \u0441\u0442\u0440\u043e\u043a\u0438, \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u0439 32-\u0431\u0438\u0442\u043d\u043e\u0435 \u0447\u0438\u0441\u043b\u043e. #define UINT32_MAX_STRING_SIZE 10 \/\/ \u0420\u0430\u0437\u043c\u0435\u0440 \u0441\u0442\u0440\u043e\u043a\u0438, \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u0439 \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442 -a \u0438\u043b\u0438 -s. #define OPT_SIZE 2  \/\/ \u0414\u0430\u043d\u043d\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u043f\u043e\u0434\u0433\u043e\u0442\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442 \u043c\u0430\u0441\u0441\u0438\u0432 argv \u0434\u043b\u044f execvp. static char** prepare_generate_add_round_key_argv(   func_data *funcs_data,   size_t num_functions ) {   char **argv = NULL, *strings = NULL;   \/\/ \u0420\u0430\u0437\u043c\u0435\u0440 \u043c\u0430\u0441\u0441\u0438\u0432\u0430 argv. \u041d\u0430 \u043a\u0430\u0436\u0434\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044e   \/\/ \u043d\u0443\u0436\u0435\u043d \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0439 \u043d\u0430\u0431\u043e\u0440 \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442\u043e\u0432: -a addr -s size,   \/\/ \u043e\u0442\u0441\u044e\u0434\u0430 \u0431\u0435\u0440\u0451\u0442\u0441\u044f 4 * num_functions. \u0421\u043b\u0430\u0433\u0430\u0435\u043c\u043e\u0435 1   \/\/ \u043d\u0443\u0436\u043d\u043e \u0442\u0430\u043a \u043a\u0430\u043a \u0432 \u043d\u0430\u0447\u0430\u043b\u0435 argv \u0434\u043e\u043b\u0436\u043d\u044b \u0431\u044b\u0442\u044c \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0441\u0442\u0440\u043e\u043a\u0438:   \/\/ cabal exec gen-add-round-key --   size_t argc = 4 * (num_functions + 1);    argv = malloc(sizeof(char*) * (argc + 1));   if(!argv)     goto error;    \/\/ \u0412\u044b\u0434\u0435\u043b\u044f\u0435\u043c \u0443\u0447\u0430\u0441\u0442\u043e\u043a \u043f\u0430\u043c\u044f\u0442\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u0431\u0443\u0434\u0443\u0442 \u0445\u0440\u0430\u043d\u0438\u0442\u044c\u0441\u044f \u0432\u0441\u0435 \u0441\u0442\u0440\u043e\u043a\u0438,   \/\/ \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0435 \u0432 argv. \u041d\u0430 \u043a\u0430\u0436\u0434\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044e \u043f\u0440\u0438\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0434\u0432\u0435 \u0441\u0442\u0440\u043e\u043a\u0438   \/\/ \u0441 \u0438\u043c\u0435\u043d\u0430\u043c\u0438 \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442\u043e\u0432 2*(OPT_SIZE + 1), \u043e\u0434\u043d\u0430 \u0441\u0442\u0440\u043e\u043a\u0430 \u0441 \u0430\u0434\u0440\u0435\u0441\u043e\u043c -   \/\/ UINT64_MAX_STRING_SIZE + 1 \u0438 \u043e\u0434\u043d\u0430 \u0441\u0442\u0440\u043e\u043a\u0430 \u0441 \u0440\u0430\u0437\u043c\u0435\u0440\u043e\u043c -   \/\/ UINT32_MAX_STRING_SIZE + 1.   size_t strings_size = num_functions * (UINT64_MAX_STRING_SIZE + 1 +                                          UINT32_MAX_STRING_SIZE + 1 +                                          2*(OPT_SIZE + 1));   strings = malloc(strings_size);   if(!strings)       goto error;    argv[0] = \"cabal\";   argv[1] = \"exec\";   argv[2] = \"gen-add-round-key\";   argv[3] = \"--\";   argv[argc] = NULL;    \/\/ \u0417\u0430\u043f\u043e\u043b\u043d\u044f\u0435\u043c \u043c\u0430\u0441\u0441\u0438\u0432 argv.   size_t strings_offset = 0, argv_offset = 4;   for(size_t i = 0; i &lt; num_functions; i++) {     argv[argv_offset++] = &amp;strings[strings_offset];     memcpy(&amp;strings[strings_offset], \"-a\", 3);     strings_offset += 3;     argv[argv_offset++] = &amp;strings[strings_offset];     strings_offset += sprintf(&amp;strings[strings_offset], \"%lu\", funcs_data[i].addr);     strings_offset++;     argv[argv_offset++] = &amp;strings[strings_offset];     memcpy(&amp;strings[strings_offset], \"-s\", 3);     strings_offset += 3;     argv[argv_offset++] = &amp;strings[strings_offset];     strings_offset += sprintf(&amp;strings[strings_offset], \"%u\", funcs_data[i].size);     strings_offset++;   }    return argv; error:   perror(\"prepare_generate_add_round_key_argv (malloc)\");   if(argv) free(argv);   if(strings) free(strings);   return NULL; }  static bool generate_add_round_key(   func_data *funcs_data,   size_t num_functions,   const char *addr_round_key ) {   \/\/ \u0421\u043e\u0437\u0434\u0430\u0451\u043c \u043a\u0430\u043d\u0430\u043b.   int pipefd[2];   if(pipe(pipefd) &lt; 0) {     perror(\"generate_add_round_key (pipe)\");     return false;   }    \/\/ \u0421\u043e\u0437\u0434\u0430\u0451\u043c \u0434\u043e\u0447\u0435\u0440\u043d\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441.   pid_t pid = fork();   if(pid == 0) {     \/\/ \u0412 \u0434\u043e\u0447\u0435\u0440\u043d\u0435\u043c \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0435 \u043f\u043e\u0434\u0433\u043e\u0442\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c argv \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 gen-add-round-key.     char **argv = NULL;     argv = prepare_generate_add_round_key_argv(funcs_data, num_functions);     if(!argv)         exit(EXIT_FAILURE);      \/\/ \u041f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c pipefd[0] \u0432 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0439 \u0432\u0432\u043e\u0434 \u0434\u043e\u0447\u0435\u0440\u043d\u0435\u0433\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430.     if(dup2(pipefd[0], 0) &lt; 0) {         perror(\"generate_add_round_key (dup2)\");         exit(EXIT_FAILURE);     }     close(pipefd[0]);     close(pipefd[1]);      \/\/ \u041e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u043c \u0444\u0430\u0439\u043b, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043f\u043e\u043c\u0435\u0441\u0442\u0438\u043c \u043a\u043e\u0434 AddRoundKey.     int fd = open(addr_round_key, O_CREAT | O_WRONLY | O_TRUNC, 0644);     if(fd &lt; 0) {       perror(\"generate_add_round_key (open)\");       exit(EXIT_FAILURE);     }     \/\/ \u041f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u043b\u044f\u0435\u043c \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0439 \u0432\u044b\u0432\u043e\u0434 \u0432 \u044d\u0442\u043e\u0442 \u0444\u0430\u0439\u043b.     if(dup2(fd, 1) &lt; 0) {       perror(\"generate_add_round_key (dup2)\");       exit(EXIT_FAILURE);     }      \/\/ \u0417\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c gen-add-round-key.     if(execvp(\"cabal\", argv) &lt; 0) {       perror(\"generate_add_round_key (execvp)\");       exit(EXIT_FAILURE);     }   } else if(pid &lt; 0) {     perror(\"generate_add_round_key (fork)\");     return false;   }    close(pipefd[0]);    \/\/ \u041f\u0438\u0448\u0435\u043c \u0432 \u043a\u0430\u043d\u0430\u043b \u0432\u0435\u043a\u0442\u043e\u0440 \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0438 \u043a\u043b\u044e\u0447 \u0434\u043b\u044f \u043a\u0430\u0436\u0434\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438.   for(size_t i = 0; i &lt; num_functions; i++) {     if(!write_all(pipefd[1], funcs_data[i].iv, sizeof(funcs_data[i].iv)))       return false;     if(!write_all(pipefd[1], funcs_data[i].key, sizeof(funcs_data[i].key)))       return false;   }   close(pipefd[1]);    \/\/ \u0416\u0434\u0451\u043c \u043f\u043e\u043a\u0430 gen-add-round-key \u043d\u0435 \u0437\u0430\u0432\u0435\u0440\u0448\u0438\u0442\u044c\u0441\u044f.   int wstatus;   if(waitpid(pid, &amp;wstatus, 0) &lt; 0) {     perror(\"generate_add_round_key (waitpid)\");     return false;   }   \/\/ \u0415\u0441\u043b\u0438 gen-add-round-key \u0437\u0430\u0432\u0435\u0440\u0448\u0438\u043b\u0430\u0441\u044c \u0441 \u043e\u0448\u0438\u0431\u043a\u043e\u0439, \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u043c false.   if(WEXITSTATUS(wstatus) != 0) {     return false;   }   return true; }<\/code><\/pre>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0442\u043e\u0433\u043e, \u043a\u0430\u043a \u043c\u044b \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043b\u0438 \u0432\u0441\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u043d\u0430\u043c \u043d\u0430\u0434\u043e \u0441\u043e\u0445\u0440\u0430\u043d\u0438\u0442\u044c \u043d\u043e\u0432\u044b\u0439 ELF \u0444\u0430\u0439\u043b. \u0417\u0430 \u044d\u0442\u043e \u043e\u0442\u0432\u0435\u0447\u0430\u0435\u0442 \u043f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0430 write_encrypted_exec:<\/p>\n<pre><code class=\"cpp\">static bool write_encrypted_exec(elf_t *elf, const char *patched_executable) {   int fd = open(patched_executable, O_WRONLY | O_CREAT | O_TRUNC, 0755);   bool result = true;    if(fd &lt; 0) {     perror(\"write_encrypted_exec (open)\");     return false;   }    if(!write_all(fd, elf->mem, elf->size)) {     result = false;   }    close(fd);   return result; }<\/code><\/pre>\n<p>\u041a\u0440\u043e\u043c\u0435 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 AddRoundKey \u043d\u0430\u043c \u043d\u0443\u0436\u043d\u043e \u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0432 \u0444\u0430\u0439\u043b table.inc \u0440\u0430\u0437\u043c\u0435\u0440 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u044b, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0431\u0443\u0434\u0443\u0442 \u0445\u0440\u0430\u043d\u0438\u0442\u044c\u0441\u044f \u043f\u0435\u0440\u0432\u044b\u0435 \u043f\u044f\u0442\u044c \u0431\u0430\u0439\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u0439, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0437\u0430\u043c\u0435\u043d\u044f\u0442\u044c \u043d\u0430 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044e call. \u0412 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u0438 utils\/patcher \u043b\u0435\u0436\u0430\u0442 \u0444\u0430\u0439\u043b\u044b <a href=\"https:\/\/github.com\/cyberfined\/nanomites\/blob\/master\/utils\/patcher\/funcs_table.h\" rel=\"noopener noreferrer nofollow\">funcs_table.h<\/a> \u0438 <a href=\"https:\/\/github.com\/cyberfined\/nanomites\/blob\/master\/utils\/patcher\/funcs_table.c\" rel=\"noopener noreferrer nofollow\">funcs_table.c<\/a>, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0438\u043c\u043f\u043b\u0435\u043c\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043f\u0440\u043e\u0441\u0442\u0430\u044f \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0430 \u0441 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0430\u0434\u0440\u0435\u0441\u0430\u0446\u0438\u0435\u0439, \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0432\u044b\u0433\u043b\u044f\u0434\u0438\u0442 \u0442\u0430\u043a:<\/p>\n<pre><code class=\"cpp\">#pragma once  #include &lt;stdint.h> #include &lt;stdbool.h> #include &lt;stddef.h>  typedef struct {   \/\/ \u0430\u0434\u0440\u0435\u0441 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043a\u043b\u044e\u0447\u043e\u043c \u0432 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0435.   uint64_t addr;   \/\/ \u041d\u0435 \u043f\u043e\u043c\u043d\u044e, \u043f\u043e\u0447\u0435\u043c\u0443 \u0441\u0434\u0435\u043b\u0430\u043b 8 \u0431\u0430\u0439\u0442, \u0430 \u043d\u0435 5. \u0412 \u043b\u044e\u0431\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435,   \/\/ \u0432\u0441\u0451 \u0432\u044b\u0440\u043e\u0432\u043d\u044f\u0435\u0442\u0441\u044f \u0434\u043e 8.   uint8_t  data[8]; } func_node;  typedef struct {   func_node *nodes;   size_t    num_nodes;   size_t    max_nodes;   int       size_ind; } funcs_table;  funcs_table* funcs_create(size_t max_nodes); \/\/ \u0420\u0430\u0437\u043c\u0435\u0440 \u0442\u0430\u0431\u043b\u0438\u0446\u044b - \u043f\u0440\u043e\u0441\u0442\u043e\u0435 \u0447\u0438\u0441\u043b\u043e, \u044d\u0442\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \/\/ \u043f\u0440\u043e\u0441\u0442\u043e\u0435 \u0447\u0438\u0441\u043b\u043e >= max_nodes. size_t get_func_table_size(size_t max_nodes); bool funcs_insert(funcs_table *funcs, uint64_t addr, void *data); void funcs_free(funcs_table *funcs);<\/code><\/pre>\n<p>\u041f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0430 \u0434\u043b\u044f \u0437\u0430\u043f\u0438\u0441\u0438 \u0440\u0430\u0437\u043c\u0435\u0440\u0430 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u044b \u0432\u044b\u0433\u043b\u044f\u0434\u0438\u0442 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c:<\/p>\n<pre><code class=\"cpp\">static bool write_table_inc(const char *table, size_t hash_table_size) {   FILE *f = fopen(table, \"w\");   if(!f) {     perror(\"write_table_inc (fopen)\");     return false;   }   fprintf(f, \"#define FUNCS_TABLE_SIZE %lu\\n\", hash_table_size);   fclose(f);   return true; }<\/code><\/pre>\n<p>\u041d\u0430\u043a\u043e\u043d\u0435\u0446 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u044e main:<\/p>\n<pre><code class=\"cpp\">typedef enum {   ENCRYPT,   HELP } action_t;  int main(int argc, char **argv) {   int result = EXIT_FAILURE;   elf_t elf;   action_t action = HELP;   char *executable, *table, *addr_round_key, *patched_executable;    if(argc == 6 &amp;&amp; !strcmp(argv[1], \"-e\")) {     \/\/ ELF \u0444\u0430\u0439\u043b, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u0442\u044c \u0444\u0443\u043d\u043a\u0446\u0438\u0438.     executable = argv[2];     \/\/ \u0424\u0430\u0439\u043b table.inc, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043c\u044b \u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0440\u0430\u0437\u043c\u0435\u0440 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u044b.     table = argv[3];     \/\/ \u0424\u0430\u0439\u043b, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043c\u044b \u043f\u043e\u043b\u043e\u0436\u0438\u043c \u043a\u043e\u0434 AddRoundKey.     addr_round_key = argv[4];     \/\/ \u041f\u0443\u0442\u044c \u0434\u043e \u043d\u043e\u0432\u043e\u0433\u043e \u0431\u0438\u043d\u0430\u0440\u043d\u0438\u043a\u0430 \u0441 \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c\u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u044f\u043c\u0438.     patched_executable = argv[5];     action = ENCRYPT;   }    if(action == HELP) {     fprintf(       stderr,       \"Usage:\\n\\t%s -e &lt;executable> &lt;table.inc> &lt;add_round_key.c> \"       \"&lt;patched_executable>\\n\",       argv[0]     );     return EXIT_FAILURE;   }    if(!open_elf(executable, &amp;elf))     goto exit;    if(action == ENCRYPT) {     \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0439 \u0432 ELF \u0444\u0430\u0439\u043b\u0435.     size_t num_functions = count_functions(&amp;elf);     \/\/ \u0428\u0438\u0444\u0440\u0443\u0435\u043c \u0438\u0445 \u0438 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c \u043a\u043e\u0434 AddRoundKey.     if(!encrypt_and_generate_add_round_key(&amp;elf, num_functions, addr_round_key))       goto exit;     \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0440\u0430\u0437\u043c\u0435\u0440 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u044b.     num_functions = get_func_table_size(num_functions);     \/\/ \u041f\u0438\u0448\u0435\u043c \u0435\u0433\u043e \u0432 \u0444\u0430\u0439\u043b.     if(!write_table_inc(table, num_functions))       goto exit;     \/\/ \u041f\u0438\u0448\u0435\u043c \u0432 \u0444\u0430\u0439\u043b \u0431\u0438\u043d\u0430\u0440\u043d\u0438\u043a \u0441 \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c\u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u044f\u043c\u0438.     if(!write_encrypted_exec(&amp;elf, patched_executable))       goto exit;   }    result = EXIT_SUCCESS; exit:   if(elf.mem != MAP_FAILED) close_elf(&amp;elf);   return result; }<\/code><\/pre>\n<p>Makefile \u0434\u043b\u044f \u0441\u0431\u043e\u0440\u043a\u0438 patcher \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u043f\u0440\u043e\u0441\u0442\u043e\u0439, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0437\u0434\u0435\u0441\u044c \u043d\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0451\u043d. \u0421\u0435\u0439\u0447\u0430\u0441 \u043d\u0430\u043c \u043d\u0443\u0436\u043d\u043e \u0438\u043d\u0442\u0435\u0433\u0440\u0438\u0440\u043e\u0432\u0430\u0442\u044c patcher \u0432 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0441\u0431\u043e\u0440\u043a\u0438, \u0434\u043b\u044f \u043d\u0430\u0447\u0430\u043b\u0430 \u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0432 utils \u043a\u043e\u0434 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b gen-add-round-key \u0438 \u0441\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e engine, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0431\u0443\u0434\u0435\u0442 \u043b\u0435\u0436\u0430\u0442\u044c \u043a\u043e\u0434 \u0434\u0432\u0438\u0436\u043a\u0430 \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u043a\u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u0439. \u0418\u043c\u0435\u043d\u043d\u043e \u0432 \u043d\u0435\u0451 \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0441\u043e\u0445\u0440\u0430\u043d\u044f\u0442\u044c \u043a\u043e\u0434 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 AddRoundKey \u0438 \u0444\u0430\u0439\u043b table.inc \u0441 \u0440\u0430\u0437\u043c\u0435\u0440\u043e\u043c \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u044b. \u0421\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u043d\u0430 \u0434\u0430\u043d\u043d\u043e\u043c \u044d\u0442\u0430\u043f\u0435 \u0432\u044b\u0433\u043b\u044f\u0434\u0438\u0442 \u0442\u0430\u043a:<\/p>\n<pre><code>. \u251c\u2500\u2500 engine \u251c\u2500\u2500 utils \u2502   \u251c\u2500\u2500 gen-add-round-key \u2502   \u2514\u2500\u2500 patcher \u251c\u2500\u2500 crackme.c \u251c\u2500\u2500 create_linker_script.awk \u251c\u2500\u2500 Makefile \u2514\u2500\u2500 start.s<\/code><\/pre>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u0434\u043e\u0431\u0430\u0432\u0438\u043c \u0432 \u043d\u0430\u0448 Makefile \u0432\u044b\u0437\u043e\u0432 patcher:<\/p>\n<pre><code>CC=gcc CFLAGS=-Wall -std=c11 -fno-stack-protector -Wno-builtin-declaration-mismatch \\        -fno-stack-protector -ffunction-sections -O0 LDFLAGS=-nostdlib -nostartfiles -nodefaultlibs -static -z noexecstack \\         -Wl,-z,noseparate-code AS=as  .PHONY: all clean all: crackme-encrypted crackme-encrypted: crackme-unencrypted utils\/patcher\/patcher \\         utils\/gen-add-round-key\/build         # \u0422\u0430\u043a \u043a\u0430\u043a patcher \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442 cabal \u0432 \u0441\u0432\u043e\u0435\u0439 \u0440\u0430\u0431\u043e\u0447\u0435\u0439 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u0438,         # \u0441\u043d\u0430\u0447\u0430\u043b\u0430 \u043c\u0435\u043d\u044f\u0435\u043c \u0435\u0451 \u043d\u0430 utils\/gen-add-round-key. \u041f\u043e\u0441\u043b\u0435 \u0441\u0432\u043e\u0435\u0439 \u0440\u0430\u0431\u043e\u0442\u044b         # \u0432 \u043a\u043e\u0440\u043d\u0435\u0432\u043e\u0439 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0431\u0443\u0434\u0435\u0442 \u0441\u043e\u0437\u0434\u0430\u043d \u0444\u0430\u0439\u043b crackme-encrypted, \u0430 \u0432         # \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u0438 engine \u0431\u0443\u0434\u0443\u0442 \u0441\u043e\u0437\u0434\u0430\u043d\u044b \u0444\u0430\u0439\u043b\u044b AddRoundKey.c \u0438 table.inc         cd utils\/gen-add-round-key &amp;&amp; ..\/patcher\/patcher -e ..\/..\/crackme-unencrypted \\                 ..\/..\/engine\/table.inc ..\/..\/engine\/AddRoundKey.c ..\/..\/crackme-encrypted crackme-unencrypted: linker.ld start.o crackme.o         $(CC) $(LDFLAGS) -T linker.ld start.o crackme.o -o crackme-unencrypted linker.ld: start.o crackme.o         readelf --wide -S start.o crackme.o | awk -f create_linker_script.awk > linker.ld crackme.o: crackme.c         $(CC) $(CFLAGS) -c crackme.c -o crackme.o start.o: start.s         $(AS) -c start.s -o start.o utils\/patcher\/patcher: FORCE         # \u041a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u0443\u0435\u043c patcher         $(MAKE) $(MFLAGS) -C utils\/patcher utils\/gen-add-round-key\/build: FORCE         # \u041a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u0443\u0435\u043c gen-add-round-key. \u0415\u0441\u043b\u0438 \u043d\u0438\u0447\u0435\u0433\u043e \u043d\u0435 \u043f\u043e\u043c\u0435\u043d\u044f\u043b\u043e\u0441\u044c,         # cabal \u0432\u044b\u0432\u0435\u0434\u0435\u0442 \u0432 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0439 \u0432\u044b\u0432\u043e\u0434 \"Up to date\", \u0432 \u0442\u0430\u043a\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435         # \u043d\u0438\u0447\u0435\u0433\u043e \u043d\u0435 \u0434\u0435\u043b\u0430\u0435\u043c, \u0438\u043d\u0430\u0447\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u044f\u0435\u043c \u0432\u0440\u0435\u043c\u044f \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0444\u0430\u0439\u043b\u0430 utils\/gen-add-round-key\/build.         @test \"$(shell cd utils\/gen-add-round-key &amp;&amp; cabal build | tee \/dev\/fd\/2)\" = \"Up to date\" \\                 || { touch utils\/gen-add-round-key\/build; } \\                 &amp;&amp; { test -f utils\/gen-add-round-key\/build || \\                 touch utils\/gen-add-round-key\/build; } FORCE:  clean:         $(MAKE) -C utils\/patcher clean         rm -f start.o crackme.o linker.ld utils\/gen-add-round-key\/build \\                 crackme-unencrypted crackme-encrypted<\/code><\/pre>\n<h3>\u0421\u043e\u0437\u0434\u0430\u0451\u043c \u0434\u0432\u0438\u0436\u043e\u043a<\/h3>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u043f\u0440\u0438\u0441\u0442\u0443\u043f\u0438\u043c \u043a \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044e \u0434\u0432\u0438\u0436\u043a\u0430. \u0410\u043b\u0433\u043e\u0440\u0438\u0442\u043c \u0435\u0433\u043e \u0440\u0430\u0431\u043e\u0442\u044b \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043f\u0440\u043e\u0441\u0442:<\/p>\n<ol>\n<li>\n<p>\u0415\u0441\u043b\u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u043c\u044b \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u0435\u043c (\u0434\u0430\u043b\u0435\u0435 caller), \u0431\u044b\u043b\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u0438\u0437 \u0434\u0440\u0443\u0433\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 (\u0434\u0430\u043b\u0435\u0435 prev_caller), \u0448\u0438\u0444\u0440\u0443\u0435\u043c prev_caller, \u0438\u043d\u0430\u0447\u0435 \u0441\u0440\u0430\u0437\u0443 \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u0438\u043c \u043a \u0448\u0430\u0433\u0443 2. \u042d\u0442\u043e \u0443\u0441\u043b\u043e\u0432\u0438\u0435 \u043d\u0443\u0436\u043d\u043e, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u043c\u044b \u0442\u0430\u043a\u0436\u0435 \u0448\u0438\u0444\u0440\u0443\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u044e _start, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043d\u0438 \u043e\u0442\u043a\u0443\u0434\u0430 \u043d\u0435 \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f.<\/p>\n<\/li>\n<li>\n<p>\u0421\u043e\u0445\u0440\u0430\u043d\u044f\u0435\u043c \u0430\u0434\u0440\u0435\u0441 \u0432\u043e\u0437\u0432\u0440\u0430\u0442\u0430 caller, \u0442.\u0435. \u0430\u0434\u0440\u0435\u0441, \u0441 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u0442\u0441\u044f \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043f\u043e\u0441\u043b\u0435 \u0432\u044b\u0445\u043e\u0434\u0430 \u0438\u0437 caller.<\/p>\n<\/li>\n<li>\n<p>\u0420\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u0435\u043c caller.<\/p>\n<\/li>\n<li>\n<p>\u0412\u044b\u0437\u044b\u0432\u0430\u0435\u043c caller \u0438 \u0437\u0430\u043f\u043e\u043c\u0438\u043d\u0430\u0435\u043c \u0432\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u043c\u043e\u0435 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435.<\/p>\n<\/li>\n<li>\n<p>\u0428\u0438\u0444\u0440\u0443\u0435\u043c caller.<\/p>\n<\/li>\n<li>\n<p>\u0415\u0441\u043b\u0438 \u043d\u0430 \u0448\u0430\u0433\u0435 1 \u043c\u044b \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043b\u0438 prev_caller, \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u0435\u043c \u0435\u0433\u043e \u043e\u0431\u0440\u0430\u0442\u043d\u043e.<\/p>\n<\/li>\n<li>\n<p>\u041a\u043b\u0430\u0434\u0451\u043c \u0430\u0434\u0440\u0435\u0441 \u0432\u043e\u0437\u0432\u0440\u0430\u0442\u0430 \u0432 \u0441\u0442\u0435\u043a, \u0442\u0430\u043a \u0447\u0442\u043e\u0431\u044b \u043f\u043e\u0441\u043b\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438 <code>ret<\/code> \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u043b\u043e\u0441\u044c \u0441 \u043d\u0435\u0433\u043e.<\/p>\n<\/li>\n<li>\n<p>\u041a\u043b\u0430\u0434\u0451\u043c \u0432 \u0440\u0435\u0433\u0438\u0441\u0442\u0440 <code>rax<\/code> \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435, \u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u043c\u044b \u0437\u0430\u043f\u043e\u043c\u043d\u0438\u043b\u0438 \u043d\u0430 4 \u0448\u0430\u0433\u0435 \u0438 \u0432\u044b\u0445\u043e\u0434\u0438\u043c \u0438\u0437 \u0434\u0432\u0438\u0436\u043a\u0430.<\/p>\n<\/li>\n<\/ol>\n<p>\u041f\u0435\u0440\u0435\u0445\u043e\u0434\u0438\u043c \u043a \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438. \u0421\u043e\u0437\u0434\u0430\u0451\u043c \u0432 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u0438 engine \u0444\u0430\u0439\u043b engine.c \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u044b\u043c:<\/p>\n<pre><code class=\"cpp\">\/\/ \u0422\u0430\u043a \u043a\u0430\u043a \u043a\u043e\u0434 \u0434\u0432\u0438\u0436\u043a\u0430 \u0431\u0443\u0434\u0435\u0442 \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c\u0441\u044f \u0432 \u043d\u0430\u0448 \u0431\u0438\u043d\u0430\u0440\u043d\u0438\u043a \/\/ \u043c\u044b \u043d\u0435 \u043c\u043e\u0436\u0435\u043c \u0437\u0430\u0432\u0438\u0441\u0435\u0442\u044c \u043e\u0442 libc. #define NULL ((void*)0) typedef unsigned long size_t; typedef unsigned char uint8_t; typedef unsigned int uint32_t; typedef long int64_t; typedef unsigned long uint64_t;  \/\/ \u042d\u0442\u043e\u0442 \u043c\u0430\u043a\u0440\u043e\u0441 \u043d\u0443\u0436\u0435\u043d \u0434\u043b\u044f \u043e\u0442\u043b\u0430\u0434\u043a\u0438 \u0441 \u0440\u0430\u0437\u043d\u044b\u043c\u0438 \/\/ \u0443\u0440\u043e\u0432\u043d\u044f\u043c\u0438 \u043e\u043f\u0442\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u0438. \u0415\u0441\u043b\u0438 \u043d\u0430 -O0 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0435\u0433\u043e \/\/ \u043a\u0430\u043a always_inline, \u0442\u043e \u0432\u0441\u0435 inline \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0431\u0443\u0434\u0443\u0442 \u0437\u0430\u0438\u043d\u043b\u0430\u0439\u043d\u0435\u043d\u044b, \/\/ \u0438\u043d\u0430\u0447\u0435 \u043e\u043d\u0438 \u0431\u0443\u0434\u0443\u0442 \u0432\u044b\u0437\u044b\u0432\u0430\u0442\u044c\u0441\u044f \u043a\u0430\u043a \u043e\u0431\u044b\u0447\u043d\u043e. #define INLINE __attribute__((always_inline)) \/\/#define INLINE  \/\/ #define FUNCS_TABLE_SIZE \u0440\u0430\u0437\u043c\u0435\u0440_\u0445\u044d\u0448_\u0442\u0430\u0431\u043b\u0438\u0446\u044b #include \"table.inc\"  #define Nb 4 #define Nk 8 #define Nr 14 #define AES_BLOCKLEN 16 #define CHAR_BIT 8  typedef uint8_t state_t[4][4];  \/\/ \u0424\u0443\u043d\u043a\u0446\u0438\u0438 AddRoundKey \u0438 get_iv #include \"AddRoundKey.c\"<\/code><\/pre>\n<p>\u0414\u0430\u043b\u0435\u0435 \u0438\u0434\u0443\u0442 \u0432\u0441\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0438\u0437 tiny-AES-c \u043d\u0443\u0436\u043d\u044b\u0435 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b AES_CBC_decrypt_buffer \u0438 AES_CBC_encrypt_buffer \u0443 \u0431\u043e\u043b\u044c\u0448\u0435\u0439 \u0447\u0430\u0441\u0442\u0438 \u0438\u0437 \u043d\u0438\u0445 \u043f\u043e\u043c\u0435\u043d\u044f\u043b\u043e\u0441\u044c \u043b\u0438\u0448\u044c \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u0435: \u044f \u0437\u0430\u043c\u0435\u043d\u0438\u043b <code>static<\/code> \u043d\u0430 <code>INLINE static inline<\/code>, \u044d\u0442\u043e \u043d\u0443\u0436\u043d\u043e, \u0447\u0442\u043e\u0431\u044b \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u0434\u0432\u0438\u0436\u043e\u043a \u0431\u044b\u043b \u043e\u0434\u043d\u043e\u0439 \u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0435\u0439, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0447\u0451\u0440\u0442 \u043d\u043e\u0433\u0443 \u0441\u043b\u043e\u043c\u0438\u0442. \u0414\u0430\u043b\u0435\u0435 \u0440\u0430\u0437\u0431\u0435\u0440\u0451\u043c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u044f\u0445 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u0423 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 InvCipher \u0438 Cipher \u0438\u0441\u0447\u0435\u0437 \u0437\u0430 \u043d\u0435\u043d\u0430\u0434\u043e\u0431\u043d\u043e\u0441\u0442\u044c\u044e \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440 <code>const uint8_t* RoundKey<\/code>:<\/p>\n<pre><code class=\"cpp\">INLINE static inline void InvCipher(state_t* state) {   uint8_t round = 0;    AddRoundKey(state, Nr);    for (round = (Nr - 1); ; --round)   {     InvShiftRows(state);     InvSubBytes(state);     AddRoundKey(state, round);     if (round == 0) {       break;     }     InvMixColumns(state);   }  }  INLINE static inline void Cipher(state_t* state) {   uint8_t round = 0;    AddRoundKey(state, 0);    for (round = 1; ; ++round)   {     SubBytes(state);     ShiftRows(state);     if (round == Nr) {       break;     }     MixColumns(state);     AddRoundKey(state, round);   }   AddRoundKey(state, Nr); }<\/code><\/pre>\n<p>\u0423 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 AES_CBC_encrypt_buffer \u0438 AES_CBC_decrypt_buffer \u0443\u0448\u043b\u0438 \u0437\u0430 \u043d\u0435\u043d\u0430\u0434\u043e\u0431\u043d\u043e\u0441\u0442\u044c\u044e \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u044b <code>struct AES_ctx *ctx<\/code> \u0438 <code>size_t length<\/code>:<\/p>\n<pre><code class=\"cpp\">INLINE static inline void AES_CBC_encrypt_buffer(uint8_t* buf) {   size_t i;   uint8_t initIv[AES_BLOCKLEN];   \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0440\u0430\u0437\u043c\u0435\u0440 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0438 \u0432\u0435\u043a\u0442\u043e\u0440 \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438.   \/\/ \u0430\u0434\u0440\u0435\u0441 \u0431\u0443\u0444\u0435\u0440\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u0438\u0445 \u0432\u044b\u0447\u0438\u0441\u043b\u0435\u043d\u0438\u0438.   size_t length = get_iv(initIv, (uint64_t)buf);   uint8_t *Iv = initIv;   for (i = 0; i &lt; length; i += AES_BLOCKLEN)   {     XorWithIv(buf, Iv);     Cipher((state_t*)buf);     Iv = buf;     buf += AES_BLOCKLEN;   } }  \/\/ \u0422\u0430\u043a \u043a\u0430\u043a \u043c\u044b \u043d\u0435 \u043c\u043e\u0436\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c memcpy, \/\/ \u043f\u0438\u0448\u0435\u043c \u0441\u0432\u043e\u044e \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044e. INLINE static inline void ivcpy(uint8_t *dst, uint8_t *src) {   *(uint64_t*)dst = *(uint64_t*)src;   *(uint64_t*)(dst + 8) = *(uint64_t*)(src + 8); }  INLINE static inline void AES_CBC_decrypt_buffer(uint8_t *buf) {   size_t i;   uint8_t storeNextIv[AES_BLOCKLEN];   uint8_t curIv[AES_BLOCKLEN];   \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0440\u0430\u0437\u043c\u0435\u0440 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0438 \u0432\u0435\u043a\u0442\u043e\u0440 \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438.   \/\/ \u0430\u0434\u0440\u0435\u0441 \u0431\u0443\u0444\u0435\u0440\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432 \u0438\u0445 \u0432\u044b\u0447\u0438\u0441\u043b\u0435\u043d\u0438\u0438.   size_t length = get_iv(curIv, (uint64_t)buf);    for (i = 0; i &lt; length; i += AES_BLOCKLEN)   {     ivcpy(storeNextIv, buf);     InvCipher((state_t*)buf);     XorWithIv(buf, curIv);     ivcpy(curIv, storeNextIv);     buf += AES_BLOCKLEN;   } }<\/code><\/pre>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u043f\u0435\u0440\u0435\u0439\u0434\u0451\u043c \u043a \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0430\u043c\u043e\u0433\u043e \u0434\u0432\u0438\u0436\u043a\u0430. \u0414\u043b\u044f \u043d\u0430\u0447\u0430\u043b\u0430 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0432\u0441\u043f\u043e\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c\u043d\u044b\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0435\u0439:<\/p>\n<pre><code class=\"cpp\">typedef struct {   uint64_t addr;   uint8_t  data[8]; } func_node;  \/\/ \u041f\u043e\u043c\u0435\u0449\u0430\u0435\u043c \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0443 \u0432 \u0441\u0435\u043a\u0446\u0438\u044e .data, \u0447\u0442\u043e\u0431\u044b \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a \/\/ \u043d\u0435 \u043f\u043e\u043c\u0435\u0441\u0442\u0438\u043b \u0435\u0451 \u0432 .bss, \u044d\u0442\u043e \u043d\u0443\u0436\u043d\u043e, \u0447\u0442\u043e\u0431\u044b \u0432 \u043d\u0430\u0448\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u043c \u0444\u0430\u0439\u043b\u0435 \/\/ \u0431\u044b\u043b\u0430 \u043e\u0431\u043b\u0430\u0441\u0442\u044c \u043d\u0443\u0436\u043d\u043e\u0433\u043e \u0440\u0430\u0437\u043c\u0435\u0440\u0430, \u0437\u0430\u043f\u043e\u043b\u043d\u0435\u043d\u043d\u0430\u044f \u043d\u0443\u043b\u044f\u043c\u0438 \/\/ (\u043d\u0443\u0436\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u043d\u0435\u0451 \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u043f\u043e\u043c\u0435\u0449\u0430\u0442\u044c \u043d\u0430 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u043c \u0448\u0430\u0433\u0435 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u0430). __attribute__((section(\".data\"))) static func_node funcs_table[FUNCS_TABLE_SIZE];  \/\/ \u041c\u044b \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u043c \u0442\u043e\u043b\u044c\u043a\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0441 \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442\u0430\u043c\u0438 \u0432 \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0430\u0445, \/\/ \u0442.\u0435. \u0442\u0435, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0442 \u0434\u043e 6 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u043e\u0432. typedef void* (generic_func)(void*,void*,void*,void*,void*,void*);  \/\/ \u0413\u043b\u043e\u0431\u0430\u043b\u044c\u043d\u0430\u044f \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u0430\u044f, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0431\u0443\u0434\u0435\u0442 \u0445\u0440\u0430\u043d\u0438\u0442\u044c\u0441\u044f \u0430\u0434\u0440\u0435\u0441 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438. __attribute__((section(\".data\"))) static generic_func *prev_caller = NULL;  \/\/ \u0423\u0436\u0435 \u0437\u043d\u0430\u043a\u043e\u043c\u044b\u0435 \u043d\u0430\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0441 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0435\u0439. INLINE static inline uint32_t jenkins_hash_func(uint64_t addr) {   size_t i = 0;   uint32_t hash = 0;   uint8_t *key = (uint8_t*)&amp;addr;   while (i != sizeof(addr)) {     hash += key[i++];     hash += hash &lt;&lt; 10;     hash ^= hash >> 6;   }   hash += hash &lt;&lt; 3;   hash ^= hash >> 11;   hash += hash &lt;&lt; 15;   return hash; }  INLINE static inline func_node* func_lookup(uint64_t addr) {   uint32_t hash = jenkins_hash_func(addr);   int cur = hash % FUNCS_TABLE_SIZE;   int step = hash % (FUNCS_TABLE_SIZE - 2) + 1;   int nstep = step;    for(size_t i = 0; i &lt; FUNCS_TABLE_SIZE; i++) {     func_node *cur_node = &amp;funcs_table[cur];     if(!cur_node->addr)       break;     if(cur_node->addr == addr)       return cur_node;     cur = (hash + nstep) % FUNCS_TABLE_SIZE;     nstep += step;   }    return NULL; }<\/code><\/pre>\n<p>\u041d\u0430\u043a\u043e\u043d\u0435\u0446, \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u043a\u043e\u0434 \u0441\u0430\u043c\u043e\u0433\u043e \u0434\u0432\u0438\u0436\u043a\u0430:<\/p>\n<pre><code class=\"cpp\">\/\/ \u041f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0430 \u0434\u043b\u044f \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u0438. INLINE static inline void encrypt_function(func_node *func) {   \/\/ \u0428\u0438\u0444\u0440\u0443\u0435\u043c \u0442\u0435\u043b\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0438.   uint8_t *data = (uint8_t*)func->addr;   AES_CBC_encrypt_buffer(data);    \/\/ \u041e\u0431\u043c\u0435\u043d\u0438\u0432\u0430\u0435\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043f\u0435\u0440\u0432\u044b\u0445 \u043f\u044f\u0442\u0438 \u0431\u0430\u0439\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0438 \u0431\u0443\u0444\u0435\u0440\u0430   \/\/ \u0438\u0437 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u044b. \u0412 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0435 \u043d\u0430 \u0434\u0430\u043d\u043d\u044b\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u043b\u0435\u0436\u0438\u0442 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f call,   \/\/ \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u0434\u0432\u0438\u0436\u043a\u0430.   uint64_t tmp;   tmp = *(uint64_t*)data;   *(uint32_t*)data = *(uint32_t*)func->data;   data[4] = func->data[4];   *(uint64_t*)func->data = tmp; }  \/\/ \u041f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u043d\u0438\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u0438. INLINE static inline void decrypt_function(func_node *func) {   \/\/ \u041e\u0431\u043c\u0435\u043d\u0438\u0432\u0430\u0435\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043f\u0435\u0440\u0432\u044b\u0445 \u043f\u044f\u0442\u0438 \u0431\u0430\u0439\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0438 \u0431\u0443\u0444\u0435\u0440\u0430   \/\/ \u0438\u0437 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u044b. \u0412 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0435 \u043d\u0430 \u0434\u0430\u043d\u043d\u044b\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u043b\u0435\u0436\u0430\u0442 \u043f\u044f\u0442\u044c   \/\/ \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0431\u0430\u0439\u0442 \u0438\u0437 \u0442\u0435\u043b\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u0430 \u043f\u0435\u0440\u0432\u044b\u0435 \u043f\u044f\u0442\u044c \u0431\u0430\u0439\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u0438   \/\/ \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044e call \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u0434\u0432\u0438\u0436\u043a\u0430.   uint8_t *data = (uint8_t*)func->addr;   uint64_t tmp;   tmp = *(uint64_t*)data;   *(uint32_t*)data = *(uint32_t*)func->data;   data[4] = func->data[4];   *(uint64_t*)func->data = tmp;    \/\/ \u0420\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u0435\u043c \u0442\u0435\u043b\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0438.   AES_CBC_decrypt_buffer(data); }  \/\/ \u0422\u0430\u043a \u043a\u0430\u043a \u043c\u044b \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u043c \u0434\u0432\u0438\u0436\u043e\u043a \u0432 \u043f\u0435\u0440\u0432\u043e\u0439 \u0436\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438 \u043a\u0430\u0436\u0434\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \/\/ \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442\u044b \u044d\u0442\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u044e\u0442\u0441\u044f \u0432 \u043d\u0435\u0433\u043e. void* engine(void *a1, void *a2, void *a3, void *a4, void *a5, void *a6) {   void *ret_addr;   \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0430\u0434\u0440\u0435\u0441 \u0432\u043e\u0437\u0432\u0440\u0430\u0442\u0430.   __asm__ __volatile__ (\"mov 16(%%rbp), %%rax\" : \"=a\"(ret_addr) : : \"memory\");    \/\/ \u0410\u0434\u0440\u0435\u0441 \u043d\u0430\u0447\u0430\u043b\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u0442\u044c   \/\/ \u0440\u0430\u0432\u0435\u043d \u0430\u0434\u0440\u0435\u0441\u0443 \u0432\u043e\u0437\u0432\u0440\u0430\u0442\u0430 - \u043c\u0438\u043d\u0443\u0441 \u043f\u044f\u0442\u044c \u0431\u0430\u0439\u0442, \u0442\u0430\u043a \u043a\u0430\u043a \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f   \/\/ call \u0437\u0430\u043d\u0438\u043c\u0430\u0435\u0442 \u0440\u043e\u0432\u043d\u043e \u043f\u044f\u0442\u044c \u0431\u0430\u0439\u0442.   generic_func *caller = __builtin_return_address(0) - 5;   func_node *prev_caller_info = NULL;   if(prev_caller != NULL) {     \/\/ \u0415\u0441\u043b\u0438 caller \u0431\u044b\u043b \u0432\u044b\u0437\u0432\u0430\u043d \u0438\u0437 \u0434\u0440\u0443\u0433\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 (prev_caller),     \/\/ \u0448\u0438\u0444\u0440\u0443\u0435\u043c prev_caller.     prev_caller_info = func_lookup((uint64_t)prev_caller);     encrypt_function(prev_caller_info);   }    \/\/ \u0420\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u0435\u043c caller.   func_node *caller_info = func_lookup((uint64_t)caller);   decrypt_function(caller_info);    \/\/ \u0421\u043e\u0445\u0440\u0430\u043d\u044f\u0435\u043c \u0442\u0435\u043a\u0443\u0449\u0435\u0435 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 prev_caller \u0438 \u0437\u0430\u043c\u0435\u043d\u044f\u0435\u043c \u0435\u0433\u043e \u043d\u0430 caller.   void *prev_caller_bak = prev_caller;   prev_caller = caller;    \/\/ \u0412\u044b\u0437\u044b\u0432\u0430\u0435\u043c \u0442\u043e\u043b\u044c\u043a\u043e \u0447\u0442\u043e \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u043d\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044e.   void *res = caller(a1, a2, a3, a4, a5, a6);    \/\/ \u0417\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u0435\u043c \u0435\u0451 \u043e\u0431\u0440\u0430\u0442\u043d\u043e.   encrypt_function(caller_info);    \/\/ \u0412\u043e\u0441\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c prev_caller.   prev_caller = prev_caller_bak;   if(prev_caller_info != NULL)     \/\/ \u0415\u0441\u043b\u0438 \u043c\u044b \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043b\u0438 prev_caller \u0440\u0430\u043d\u0435\u0435,     \/\/ \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u0435\u043c \u043e\u0431\u0440\u0430\u0442\u043d\u043e.     decrypt_function(prev_caller_info);    \/\/ \u041a\u043b\u0430\u0434\u0451\u043c \u0430\u0434\u0440\u0435\u0441 \u0432\u043e\u0437\u0432\u0440\u0430\u0442\u0430 \u0432 \u0441\u0442\u0435\u043a.   __asm__ __volatile__ (\"mov %%rax, 8(%%rbp)\" : : \"a\"(ret_addr) : \"memory\");   \/\/ \u0412\u043e\u0437\u0432\u0440\u0430\u0449\u0430\u0435\u043c \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442.   return res; }<\/code><\/pre>\n<p>\u0420\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0441\u0442\u0440\u043e\u0447\u043a\u0443, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043c\u044b \u043f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0430\u0434\u0440\u0435\u0441 \u0432\u043e\u0437\u0432\u0440\u0430\u0442\u0430:<\/p>\n<pre><code class=\"cpp\">__asm__ __volatile__ (\"mov 16(%%rbp), %%rax\" : \"=a\"(ret_addr) : : \"memory\");<\/code><\/pre>\n<p>\u041d\u0430 \u0438\u043b\u043b\u044e\u0441\u0442\u0440\u0430\u0446\u0438\u0438 \u043f\u043e\u043a\u0430\u0437\u0430\u043d\u043e \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435 \u0441\u0442\u0435\u043a\u0430 \u0434\u043b\u044f \u043a\u0430\u0436\u0434\u043e\u0439 \u0438\u0437 \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0439, \u043a\u0430\u043a \u043c\u043e\u0436\u043d\u043e \u0432\u0438\u0434\u0435\u0442\u044c \u043d\u0443\u0436\u043d\u044b\u0439 \u043d\u0430\u043c \u0430\u0434\u0440\u0435\u0441 \u0432\u043e\u0437\u0432\u0440\u0430\u0442\u0430 \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0438\u043c\u0435\u043d\u043d\u043e \u043f\u043e \u0430\u0434\u0440\u0435\u0441\u0443 <code>rbp + 16<\/code>.<\/p>\n<p><a class=\"anchor\" name=\"engine_stack\" id=\"engine_stack\"><\/a><\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/0a9\/b99\/a34\/0a9b99a34bd5590fd27a789bd2146526.png\" alt=\"img\" title=\"\u0421\u0442\u0435\u043a \u043f\u0440\u0438 \u0432\u044b\u0437\u043e\u0432\u0435 \u0434\u0432\u0438\u0436\u043a\u0430\" width=\"716\" height=\"291\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/0a9\/b99\/a34\/0a9b99a34bd5590fd27a789bd2146526.png\"\/><\/p>\n<div><figcaption>\u0421\u0442\u0435\u043a \u043f\u0440\u0438 \u0432\u044b\u0437\u043e\u0432\u0435 \u0434\u0432\u0438\u0436\u043a\u0430<\/figcaption><\/div>\n<\/figure>\n<p>\u041e\u0434\u043d\u0430\u043a\u043e, \u0447\u0442\u043e\u0431\u044b \u044d\u0442\u0430 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u0440\u0430\u0431\u043e\u0442\u0430\u043b\u0430 \u0442\u0430\u043a, \u043a\u0430\u043a \u043d\u0430\u043c \u043d\u0443\u0436\u043d\u043e, \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0434\u0432\u0438\u0436\u043e\u043a \u0441 \u0444\u043b\u0430\u0433\u043e\u043c <code>-fno-omit-frame-pointer<\/code>, \u0447\u0442\u043e\u0431\u044b gcc \u043e\u0441\u0442\u0430\u0432\u043b\u044f\u043b \u043d\u0438\u0436\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0451\u043d\u043d\u044b\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438:<\/p>\n<pre><code class=\"assembly\">pushq %rbp movq %rsp, %rbp<\/code><\/pre>\n<p>\u041a\u043e\u0434 \u0434\u0432\u0438\u0436\u043a\u0430 \u043d\u0430 \u044d\u0442\u043e\u043c \u0437\u0430\u0432\u0435\u0440\u0448\u0451\u043d, \u0442\u0435\u043f\u0435\u0440\u044c \u0434\u043e\u0431\u0430\u0432\u0438\u043c \u0432 Makefile \u0446\u0435\u043b\u0438 \u0434\u043b\u044f \u0435\u0433\u043e \u043a\u043e\u043c\u043f\u0438\u043b\u044f\u0446\u0438\u0438. \u041d\u043e \u0434\u043b\u044f \u043d\u0430\u0447\u0430\u043b\u0430 \u043d\u0430\u043f\u0438\u0448\u0435\u043c \u043f\u0440\u043e\u0441\u0442\u043e\u0439 \u0441\u043a\u0440\u0438\u043f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0430, \u0447\u0442\u043e\u0431\u044b \u043a\u043e\u0434 \u0438 \u0434\u0430\u043d\u043d\u044b\u0435 \u043b\u0435\u0436\u0430\u043b\u0438 \u0432 \u043e\u0434\u043d\u043e\u0439 \u0441\u0435\u043a\u0446\u0438\u0438, \u0438 \u043c\u044b \u043c\u043e\u0433\u043b\u0438 \u043b\u0435\u0433\u043a\u043e \u0438\u0445 \u0432\u044b\u0440\u0435\u0437\u0430\u0442\u044c \u0438 \u0432\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0432 \u043d\u0430\u0448 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b. \u0421\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0444\u0430\u0439\u043b engine\/linker.ld \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u044b\u043c:<\/p>\n<pre><code>ENTRY(engine) SECTIONS {     .text : {         * (.text)         * (.data)         * (.rodata)     } }<\/code><\/pre>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u0434\u043e\u043f\u0438\u0448\u0435\u043c \u043f\u0430\u0440\u0443 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0439 \u0432 \u043d\u0430\u0448 Makefile:<\/p>\n<pre><code>CC=gcc CFLAGS=-Wall -std=c11 -fno-stack-protector -Wno-builtin-declaration-mismatch \\        -fno-stack-protector -ffunction-sections -O0 LDFLAGS=-nostdlib -nostartfiles -nodefaultlibs -static -z noexecstack \\         -Wl,-z,noseparate-code AS=as  .PHONY: all clean all: crackme-unencrypted engine\/engine engine\/engine: engine\/engine.o         $(CC) $(LDFLAGS) -T engine\/linker.ld -pie -Xlinker --no-dynamic-linker \\                 engine\/engine.o -o engine\/engine engine\/engine.o: crackme-encrypted engine\/engine.c         # \u041e\u0431\u044f\u0437\u0430\u0442\u0435\u043b\u044c\u043d\u043e \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c -fno-omit-frame-pointer \u0438 -fPIC (\u0447\u0442\u043e\u0431\u044b \u043a\u043e\u0434 \u0431\u044b\u043b \u043f\u043e\u0437\u0438\u0446\u0438\u043e\u043d\u043d\u043e-\u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u044b\u043c).         # \u0422\u0430\u043a\u0436\u0435 \u044f \u0434\u043e\u0431\u0430\u0432\u0438\u043b -Wno-overflow, \u0442\u0430\u043a \u043a\u0430\u043a \u0432 \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043a\u043e\u0434\u0435 AddRoundKey \u0447\u0430\u0441\u0442\u043e \u0432\u0441\u0442\u0440\u0435\u0447\u0430\u044e\u0442\u0441\u044f \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f,         # \u0442\u0430\u043a \u0438 \u0431\u044b\u043b\u043e \u0437\u0430\u0434\u0443\u043c\u0430\u043d\u043e, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u044d\u0442\u043e\u043c \u043d\u0430\u043c \u043d\u0435 \u043d\u0443\u0436\u043d\u044b. \u0424\u043b\u0430\u0433 -fno-function-sections         # \u044f \u0434\u043e\u0431\u0430\u0432\u0438\u043b, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0432 \u0434\u0430\u043d\u043d\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435 \u043d\u0430\u043c \u043d\u0435 \u043d\u0443\u0436\u043d\u043e \u043a\u043b\u0430\u0441\u0442\u044c \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0432 \u0440\u0430\u0437\u0434\u0435\u043b\u044c\u043d\u044b\u0435 \u0441\u0435\u043a\u0446\u0438\u0438. \u0418 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0439         # \u0444\u043b\u0430\u0433 -mno-sse \u044f \u0434\u043e\u0431\u0430\u0432\u0438\u043b, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0438\u043d\u0430\u0447\u0435 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u043e\u0448\u0438\u0431\u043a\u0430 segmentation fault \u043a\u0430\u043a \u0440\u0430\u0437         # \u043d\u0430 sse \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438.         $(CC) $(CFLAGS) -fno-function-sections -O3 -mno-sse -fno-omit-frame-pointer -Wno-overflow -fPIC -c \\                 engine\/engine.c -o engine\/engine.o crackme-encrypted: crackme-unencrypted utils\/patcher\/patcher \\         utils\/gen-add-round-key\/build         cd utils\/gen-add-round-key &amp;&amp; ..\/patcher\/patcher -e ..\/..\/crackme-unencrypted \\                 ..\/..\/engine\/table.inc ..\/..\/engine\/AddRoundKey.c ..\/..\/crackme-encrypted crackme-unencrypted: linker.ld start.o crackme.o         $(CC) $(LDFLAGS) -T linker.ld start.o crackme.o -o crackme-unencrypted linker.ld: start.o crackme.o         readelf --wide -S start.o crackme.o | awk -f create_linker_script.awk > linker.ld crackme.o: crackme.c         $(CC) $(CFLAGS) -c crackme.c -o crackme.o start.o: start.s         $(AS) -c start.s -o start.o utils\/patcher\/patcher: FORCE         $(MAKE) $(MFLAGS) -C utils\/patcher utils\/gen-add-round-key\/build: FORCE         @test \"$(shell cd utils\/gen-add-round-key &amp;&amp; cabal build | tee \/dev\/fd\/2)\" = \"Up to date\" \\                 || { touch utils\/gen-add-round-key\/build; } \\                 &amp;&amp; { test -f utils\/gen-add-round-key\/build || \\                 touch utils\/gen-add-round-key\/build; } FORCE:  clean:         $(MAKE) -C utils\/patcher clean         rm -f start.o crackme.o linker.ld utils\/gen-add-round-key\/build \\                 engine\/table.inc engine\/AddRoundKey.c engine\/engine.o engine\/engine \\                 crackme-unencrypted crackme-encrypted<\/code><\/pre>\n<p>\u041d\u0430 \u044d\u0442\u043e\u043c \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0435\u043d\u0438\u0435 \u0440\u0430\u0431\u043e\u0442\u044b \u0434\u0432\u0438\u0436\u043a\u0430 \u043e\u043a\u043e\u043d\u0447\u0435\u043d\u043e, \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u0438\u043c \u043a \u0447\u0435\u0442\u0432\u0451\u0440\u0442\u043e\u043c\u0443 \u0448\u0430\u0433\u0443 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u0430.<\/p>\n<h3>\u0412\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c \u0434\u0432\u0438\u0436\u043e\u043a \u0432 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b<\/h3>\n<h4>Reverse text infection<\/h4>\n<p>\u0417\u0434\u0435\u0441\u044c \u0431\u0443\u0434\u0435\u0442 \u043e\u043f\u0438\u0441\u0430\u043d\u0430 \u0434\u0430\u043d\u043d\u0430\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u043d\u0438\u044f \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 \u0443\u0436\u0435 \u0433\u043e\u0442\u043e\u0432\u044b\u0439 \u0431\u0438\u043d\u0430\u0440\u043d\u0438\u043a, \u0435\u0441\u043b\u0438 \u0432\u044b \u0441 \u043d\u0435\u0439 \u0437\u043d\u0430\u043a\u043e\u043c\u044b, \u0441\u043c\u0435\u043b\u043e \u043f\u0440\u043e\u043f\u0443\u0441\u043a\u0430\u0439\u0442\u0435 \u044d\u0442\u043e \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0435. \u042d\u0442\u0430 \u0442\u0435\u0445\u043d\u0438\u043a\u0430 \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u044b\u0439 \u043a\u043e\u0434 \u0431\u0443\u0434\u0435\u0442 \u0440\u0430\u0441\u043f\u043e\u043b\u0430\u0433\u0430\u0442\u044c\u0441\u044f \u0434\u043e \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430, \u0442\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c \u043c\u044b \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u043c \u0441\u0435\u0433\u043c\u0435\u043d\u0442 \u0441 \u043a\u043e\u0434\u043e\u043c (text segment) \u0432 \u043e\u0431\u0440\u0430\u0442\u043d\u0443\u044e \u0441\u0442\u043e\u0440\u043e\u043d\u0443:<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/a6e\/1e7\/692\/a6e1e7692db7c8e402a589ed1cd90ffa.png\" alt=\"img\" title=\"Reverse text infection\" width=\"551\" height=\"391\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a6e\/1e7\/692\/a6e1e7692db7c8e402a589ed1cd90ffa.png\"\/><\/p>\n<div><figcaption>Reverse text infection<\/figcaption><\/div>\n<\/figure>\n<p>\u041a\u0430\u043a \u0432\u0438\u0434\u043d\u043e \u0438\u0437 \u0438\u043b\u043b\u044e\u0441\u0442\u0440\u0430\u0446\u0438\u0438, \u043f\u0440\u0438 \u0442\u0430\u043a\u043e\u043c \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u043d\u0438\u0438 \u0430\u0434\u0440\u0435\u0441\u0430 \u0432\u0441\u0435\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 \u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u043d\u0435\u0438\u0437\u043c\u0435\u043d\u043d\u044b\u043c\u0438. \u0422\u0430\u043a\u0436\u0435 \u043c\u043e\u0436\u043d\u043e \u0437\u0430\u043c\u0435\u043d\u0438\u0442\u044c, \u0447\u0442\u043e \u043c\u044b \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u043c \u0440\u0430\u0437\u043c\u0435\u0440 \u0441\u0435\u0433\u043c\u0435\u043d\u0442\u0430 \u043d\u0430 \u0440\u0430\u0437\u043c\u0435\u0440 \u043d\u0430\u0448\u0435\u0433\u043e \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u043e\u0433\u043e \u043a\u043e\u0434\u0430, \u043e\u043a\u0440\u0443\u0433\u043b\u0451\u043d\u043d\u044b\u0439 \u0434\u043e \u0440\u0430\u0437\u043c\u0435\u0440\u0430 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b. \u0414\u0435\u043b\u043e \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e \u0430\u0434\u0440\u0435\u0441 \u043d\u0430\u0447\u0430\u043b\u0430 \u0441\u0435\u0433\u043c\u0435\u043d\u0442\u0430 \u0434\u043e\u043b\u0436\u0435\u043d \u0431\u044b\u0442\u044c \u043a\u0440\u0430\u0442\u0435\u043d \u0440\u0430\u0437\u043c\u0435\u0440\u0443 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b (4096 \u0431\u0430\u0439\u0442), \u0435\u0441\u043b\u0438 \u043d\u0430\u0448 \u043a\u043e\u0434 \u043d\u0435 \u043a\u0440\u0430\u0442\u0435\u043d \u0435\u043c\u0443, \u043c\u044b \u0432\u044b\u043d\u0443\u0436\u0434\u0435\u043d\u044b \u0437\u0430\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043e\u0441\u0442\u0430\u0432\u0448\u0435\u0435\u0441\u044f \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u043e \u043d\u0443\u043b\u044f\u043c\u0438 (padding \u043d\u0430 \u0438\u043b\u043b\u044e\u0441\u0442\u0440\u0430\u0446\u0438\u0438).<\/p>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u043c\u043e\u0436\u043d\u043e \u043e\u043f\u0438\u0441\u0430\u0442\u044c \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c:<\/p>\n<ol>\n<li>\n<p>\u0412\u044b\u0447\u0438\u0441\u043b\u044f\u0435\u043c \u043e\u043a\u0440\u0443\u0433\u043b\u0451\u043d\u043d\u0443\u044e \u0434\u043e \u0440\u0430\u0437\u043c\u0435\u0440\u0430 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b \u0434\u043b\u0438\u043d\u0443 \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u043e\u0433\u043e \u043a\u043e\u0434\u0430, \u0434\u0430\u043b\u0435\u0435 rounded_size.<\/p>\n<\/li>\n<li>\n<p>\u041f\u0440\u043e\u0445\u043e\u0434\u0438\u043c\u0441\u044f \u043f\u043e \u0432\u0441\u0435\u043c \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0430\u043c \u0441\u0435\u043a\u0446\u0438\u0439, \u0435\u0441\u043b\u0438 \u0441\u0435\u043a\u0446\u0438\u044f \u0440\u0430\u0441\u043f\u043e\u043b\u043e\u0436\u0435\u043d\u0430 \u043f\u043e\u0441\u043b\u0435 \u0441\u0435\u0433\u043c\u0435\u043d\u0442\u0430 \u0441 \u043a\u043e\u0434\u043e\u043c (<code>shdr->sh_offset >= text_phdr.p_offset + text_phdr.p_filesz<\/code>), \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u043c \u0435\u0451 \u0441\u043c\u0435\u0449\u0435\u043d\u0438\u0435 \u043d\u0430 <code>rounded_size<\/code>: <code>shdr->sh_offset += round_size<\/code>. \u041d\u0430\u0445\u043e\u0434\u0438\u043c \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043e\u043a .text \u0441\u0435\u043a\u0446\u0438\u0438, \u0443\u043c\u0435\u043d\u044c\u0448\u0430\u0435\u043c \u0430\u0434\u0440\u0435\u0441 \u043d\u0430 <code>rounded_size<\/code> \u0438 \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u043c \u0440\u0430\u0437\u043c\u0435\u0440 \u043d\u0430 <code>rounded_size<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u041d\u0430\u0445\u043e\u0434\u0438\u043c \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043e\u043a \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0441\u0435\u0433\u043c\u0435\u043d\u0442\u0430, \u0443\u043c\u0435\u043d\u044c\u0448\u0430\u0435\u043c <code>p_vaddr<\/code> \u0438 <code>p_paddr<\/code> \u043d\u0430 <code>rounded_size<\/code>, \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u043c <code>p_filesz<\/code> \u0438 <code>p_memsz<\/code> \u043d\u0430 <code>rounded_size<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u041f\u0440\u043e\u0445\u043e\u0434\u0438\u043c\u0441\u044f \u043f\u043e \u0432\u0441\u0435\u043c \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0430\u043c \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b, \u0435\u0441\u043b\u0438 \u0441\u0435\u0433\u043c\u0435\u043d\u0442 \u0440\u0430\u0441\u043f\u043e\u043b\u043e\u0436\u0435\u043d \u043f\u043e\u0441\u043b\u0435 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0433\u043e, \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u043c \u0435\u0433\u043e \u0441\u043c\u0435\u0449\u0435\u043d\u0438\u0435 \u043e\u0442\u043d\u043e\u0441\u0438\u0442\u0435\u043b\u044c\u043d\u043e \u043d\u0430\u0447\u0430\u043b\u0430 \u0444\u0430\u0439\u043b\u0430 (<code>p_offset<\/code>) \u043d\u0430 <code>rounded_size<\/code>.<\/p>\n<\/li>\n<li>\n<p>\u0421\u043e\u0445\u0440\u0430\u043d\u044f\u0435\u043c \u043d\u0430 \u0434\u0438\u0441\u043a \u043d\u043e\u0432\u044b\u0439 ELF \u0444\u0430\u0439\u043b: <\/p>\n<ol>\n<li>\n<p>\u0441\u043d\u0430\u0447\u0430\u043b\u0430 \u043f\u0438\u0448\u0435\u043c \u0432\u0441\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0434\u043e \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u043e\u0432 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u043e,<\/p>\n<\/li>\n<li>\n<p>\u043f\u043e\u0442\u043e\u043c \u043f\u0438\u0448\u0435\u043c \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u044b\u0439 \u043a\u043e\u0434,<\/p>\n<\/li>\n<li>\n<p>\u0434\u0430\u043b\u0435\u0435 \u043d\u0443\u043b\u0438, \u0447\u0442\u043e\u0431\u044b \u0441\u0434\u0435\u043b\u0430\u0442\u044c \u0440\u0430\u0437\u043c\u0435\u0440 \u043a\u0440\u0430\u0442\u043d\u044b\u043c \u0440\u0430\u0437\u043c\u0435\u0440\u0443 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b,<\/p>\n<\/li>\n<li>\n<p>\u043d\u0430\u043a\u043e\u043d\u0435\u0446 \u043f\u0438\u0448\u0435\u043c \u0432\u0441\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u043f\u043e\u0441\u043b\u0435 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u043e\u0432 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b \u0438\u0437 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430.<\/p>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<h4>\u0410\u043b\u0433\u043e\u0440\u0438\u0442\u043c \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u043d\u0438\u044f \u0434\u0432\u0438\u0436\u043a\u0430<\/h4>\n<p>\u041c\u044b \u043f\u043e\u0434\u043e\u0448\u043b\u0438 \u043a \u0444\u0438\u043d\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u0448\u0430\u0433\u0443, \u0434\u043b\u044f \u043d\u0430\u0447\u0430\u043b\u0430 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u043d\u0438\u044f \u0434\u0432\u0438\u0436\u043a\u0430:<\/p>\n<ol>\n<li>\n<p>\u0412\u044b\u0447\u0438\u0441\u043b\u044f\u0435\u043c \u0430\u0434\u0440\u0435\u0441 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u0432\u0438\u0436\u043a\u0430 \u0432 \u043d\u0430\u0448\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u043c \u0444\u0430\u0439\u043b\u0435.<\/p>\n<\/li>\n<li>\n<p>\u0421\u043e\u0437\u0434\u0430\u0451\u043c \u043f\u0443\u0441\u0442\u0443\u044e \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0443, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0431\u0443\u0434\u0443\u0442 \u043b\u0435\u0436\u0430\u0442\u044c \u043f\u0435\u0440\u0432\u044b\u0435 \u043f\u044f\u0442\u044c \u0431\u0430\u0439\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u0439.<\/p>\n<\/li>\n<li>\n<p>\u041f\u0440\u043e\u0445\u043e\u0434\u0438\u043c\u0441\u044f \u043f\u043e \u0432\u0441\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u044f\u043c, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c \u043f\u0435\u0440\u0432\u044b\u0435 \u043f\u044f\u0442\u044c \u0431\u0430\u0439\u0442 \u0432 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0443, \u0437\u0430\u043c\u0435\u043d\u044f\u0435\u043c \u0438\u0445 \u043d\u0430 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044e <code>call<\/code> \u0441 \u0432\u044b\u0437\u043e\u0432\u043e\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u0432\u0438\u0436\u043a\u0430, \u0434\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c \u0430\u0434\u0440\u0435\u0441 \u0438\u0437 \u043f\u0435\u0440\u0432\u043e\u0433\u043e \u0448\u0430\u0433\u0430.<\/p>\n<\/li>\n<li>\n<p>\u041d\u0430\u0445\u043e\u0434\u0438\u043c \u0441\u0438\u043c\u0432\u043e\u043b funcs_table \u0432 \u0434\u0432\u0438\u0436\u043a\u0435, \u043a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0432 \u043d\u0435\u0433\u043e \u043d\u0430\u0448\u0443 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0443.<\/p>\n<\/li>\n<li>\n<p>\u0412\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c \u043a\u043e\u0434 \u0434\u0432\u0438\u0436\u043a\u0430 \u0432 \u043d\u0430\u0448 \u0444\u0430\u0439\u043b \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e reverse text infection.<\/p>\n<\/li>\n<\/ol>\n<p>\u0412\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u043d\u0438\u0435\u043c \u0431\u0443\u0434\u0435\u0442 \u0437\u0430\u043d\u0438\u043c\u0430\u0442\u044c\u0441\u044f patcher, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043f\u0438\u0448\u0435\u043c \u043a\u043e\u0434 \u0432 utils\/patcher\/patcher.c. \u0414\u043b\u044f \u043d\u0430\u0447\u0430\u043b\u0430 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0434\u0432\u0435 \u0432\u0441\u043f\u043e\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c\u043d\u044b\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0438:<\/p>\n<pre><code class=\"cpp\">\/\/ \u042d\u0442\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u043d\u0430\u0445\u043e\u0434\u0438\u0442 \u0441\u0435\u043a\u0446\u0438\u044e \u0432 ELF \u0444\u0430\u0439\u043b\u0435 \u043f\u043e \u0438\u043c\u0435\u043d\u0438. static Elf64_Shdr* section_by_name(elf_t *elf, const char *name) {   for(size_t i = 0; i &lt; elf->ehdr->e_shnum; i++) {     char *sh_name = &amp;elf->sh_names[elf->shdrs[i].sh_name];     if(!strcmp(sh_name, name))       return &amp;elf->shdrs[i];   }   return NULL; }  \/\/ \u042d\u0442\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u043d\u0430\u0445\u043e\u0434\u0438\u0442 \u0441\u0438\u043c\u0432\u043e\u043b \u0432 ELF \u0444\u0430\u0439\u043b\u0435 \u043f\u043e \u0438\u043c\u0435\u043d\u0438. static Elf64_Sym* symbol_by_name(elf_t *elf, const char *name) {   for(size_t i = 0; i &lt; elf->num_symbols; i++) {     char *sym_name = &amp;elf->sym_names[elf->symbols[i].st_name];     if(!strcmp(sym_name, name))       return &amp;elf->symbols[i];   }   return NULL; }<\/code><\/pre>\n<p>\u0410 \u0442\u0435\u043f\u0435\u0440\u044c \u043f\u0440\u0438\u0441\u0442\u0443\u043f\u0438\u043c \u043a \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u043c\u0443 \u043a\u043e\u0434\u0443:<\/p>\n<pre><code class=\"cpp\">#define PAGE_ALIGN 4096  static const uint8_t call_opcode[] = {0xe8,0x00,0x00,0x00,0x00}; static const uint8_t zeros[PAGE_ALIGN] = {0};  \/\/ \u0414\u0430\u043d\u043d\u0430\u044f \u043f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0430 \u0432\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u0432 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0443 \u043f\u0435\u0440\u0432\u044b\u0435 \u043f\u044f\u0442\u044c \u0431\u0430\u0439\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \/\/ \u0438 \u0437\u0430\u043c\u0435\u043d\u044f\u0435\u0442 \u0438\u0445 \u043d\u0430 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044e call. static bool jump_to_engine(   elf_t *elf,   funcs_table *funcs,   Elf64_Sym *func,   uint64_t engine_func_addr ) {   Elf64_Shdr *func_shdr = &amp;elf->shdrs[func->st_shndx];   uint8_t *func_start = elf->mem + func_shdr->sh_offset +                         func->st_value - func_shdr->sh_addr;    if(!funcs_insert(funcs, func->st_value, func_start))     return false;    memcpy(func_start, call_opcode, sizeof(call_opcode));   int32_t jump_diff = engine_func_addr - func->st_value - sizeof(call_opcode);   memcpy(&amp;func_start[1], &amp;jump_diff, sizeof(jump_diff));    return true; }  \/\/ \u041f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0430 \u0434\u043b\u044f \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0434\u0432\u0438\u0436\u043a\u0430 \u0438 \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0435\u0433\u043e\u0441\u044f ELF \u0444\u0430\u0439\u043b\u0430. \/\/ elf - \u043d\u0430\u0448 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b. \/\/ engine - ELF \u0444\u0430\u0439\u043b \u0441 \u0434\u0432\u0438\u0436\u043a\u043e\u043c. \/\/ patched_executable - \u043f\u0443\u0442\u044c \u0434\u043e \u043d\u043e\u0432\u043e\u0433\u043e ELF \u0444\u0430\u0439\u043b\u0430. static bool infect_engine(elf_t *elf, elf_t *engine, const char *patched_executable) {   bool result = false;   funcs_table *funcs = NULL;   int fd = -1;    \/\/ \u041d\u0430\u0445\u043e\u0434\u0438\u043c .text \u0441\u0435\u043a\u0446\u0438\u044e \u0434\u0432\u0438\u0436\u043a\u0430, \u0438\u043c\u0435\u043d\u043d\u043e \u0435\u0451 \u043c\u044b \u0438 \u0431\u0443\u0434\u0435\u043c \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c   \/\/ \u0432 \u043d\u0430\u0448 \u0431\u0438\u043d\u0430\u0440\u043d\u0438\u043a.   Elf64_Shdr *engine_text = section_by_name(engine, \".text\");   if(!engine_text) {     fputs(\"engine has not .text section\\n\", stderr);     goto exit;   }    \/\/ \u041d\u0430\u0445\u043e\u0434\u0438\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u044e engine.   Elf64_Sym *engine_func = symbol_by_name(engine, \"engine\");   if(!engine_func) {     fputs(\"engine has not engine function\\n\", stderr);     goto exit;   }    \/\/ \u041d\u0430\u0445\u043e\u0434\u0438\u043c \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0443 funcs_table.   Elf64_Sym *engine_funcs_table = symbol_by_name(engine, \"funcs_table\");   if(!engine_funcs_table) {     fputs(\"engine has not funcs_table\\n\", stderr);     goto exit;   }    \/\/ \u0421\u043e\u0437\u0434\u0430\u0451\u043c \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0443 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0433\u043e \u0440\u0430\u0437\u043c\u0435\u0440\u0430.   size_t num_functions = engine_funcs_table->st_size \/ sizeof(func_node);   funcs = funcs_create(num_functions);   if(!funcs)     goto exit;    \/\/ \u0412\u044b\u0447\u0438\u0441\u043b\u044f\u0435\u043c \u0430\u0434\u0440\u0435\u0441 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 engine. \u0422\u0430\u043a \u043a\u0430\u043a \u043a\u043e\u0434 \u0434\u0432\u0438\u0436\u043a\u0430 \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u0442\u0441\u044f   \/\/ \u0432 \u0441\u0430\u043c\u043e\u0435 \u043d\u0430\u0447\u0430\u043b\u043e \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0441\u0435\u0433\u043c\u0435\u043d\u0442\u0430, \u0430\u0434\u0440\u0435\u0441 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 engine \u0440\u0430\u0432\u0435\u043d   \/\/ \u043d\u043e\u0432\u043e\u043c\u0443 \u043d\u0430\u0447\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u0430\u0434\u0440\u0435\u0441\u0443 \u0441\u0435\u0433\u043c\u0435\u043d\u0442\u0430 (orig_p_vaddr - rounded_size)   \/\/ \u043f\u043b\u044e\u0441 \u0441\u043c\u0435\u0449\u0435\u043d\u0438\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u0438 engine \u043e\u0442\u043d\u043e\u0441\u0438\u0442\u0435\u043b\u044c\u043d\u043e \u0435\u0451 .text \u0441\u0435\u043a\u0446\u0438\u0438.   Elf64_Addr orig_p_vaddr = elf->phdrs[0].p_vaddr;   size_t rounded_size = roundup(engine_text->sh_size, PAGE_ALIGN);   uint64_t new_base_addr = orig_p_vaddr - rounded_size;   uint64_t engine_func_addr = new_base_addr +                               engine_func->st_value - engine_text->sh_addr;    \/\/ \u041f\u0440\u043e\u0445\u043e\u0434\u0438\u043c\u0441\u044f \u043f\u043e \u0432\u0441\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u044f\u043c, \u0437\u0430\u043c\u0435\u043d\u044f\u0435\u043c \u043f\u0435\u0440\u0432\u044b\u0435 \u043f\u044f\u0442\u044c \u0431\u0430\u0439\u0442 \u043d\u0430 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044e call   \/\/ \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 engine, \u043e\u0431\u043d\u043e\u0432\u043b\u044f\u0435\u043c \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0443.   for(size_t i = 0; i &lt; elf->num_symbols; i++) {     if(ELF64_ST_TYPE(elf->symbols[i].st_info) != STT_FUNC)       continue;      if(!jump_to_engine(elf, funcs, &amp;elf->symbols[i], engine_func_addr))       goto exit;   }    \/\/ \u0412\u044b\u0447\u0438\u0441\u043b\u044f\u0435\u043c \u0441\u043c\u0435\u0449\u0435\u043d\u0438\u0435 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u044b \u043e\u0442\u043d\u043e\u0441\u0438\u0442\u0435\u043b\u044c\u043d\u043e .text \u0441\u0435\u043a\u0446\u0438\u0438 \u0438   \/\/ \u043a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0442\u0443\u0434\u0430 \u0442\u043e\u043b\u044c\u043a\u043e \u0447\u0442\u043e \u0441\u043e\u0437\u0434\u0430\u043d\u043d\u0443\u044e \u043d\u0430\u043c\u0438.   uint8_t *funcs_table_start = engine->mem + engine_text->sh_offset +                                engine_funcs_table->st_value -                                engine_text->sh_addr;   memcpy(funcs_table_start, funcs->nodes, engine_funcs_table->st_size);    \/\/ Reverse text infection    \/\/ \u041e\u0431\u043d\u043e\u0432\u043b\u044f\u0435\u043c \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0438 \u0441\u0435\u043a\u0446\u0438\u0439   \/\/ (\u043d\u0435 \u043e\u0431\u044f\u0437\u0430\u0442\u0435\u043b\u044c\u043d\u0430\u044f \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u044f, \u043e\u0434\u043d\u0430\u043a\u043e \u043f\u043e\u043c\u043e\u0433\u0430\u0435\u0442 \u043f\u043e\u0442\u043e\u043c \u043f\u0440\u0438 \u043e\u0442\u043b\u0430\u0434\u043a\u0435)   elf->ehdr->e_shoff += rounded_size;   for(size_t i = 0; i &lt; elf->ehdr->e_shnum; i++) {     if(elf->shdrs[i].sh_offset >=         elf->phdrs[0].p_offset + elf->phdrs[0].p_filesz)       elf->shdrs[i].sh_offset += rounded_size;   }   Elf64_Shdr *text_section = section_by_name(elf, \".text\");   if(text_section) {     text_section->sh_addr -= rounded_size;     text_section->sh_size += rounded_size;   }    \/\/ \u0414\u0435\u043b\u0430\u0435\u043c \u043d\u0430\u0448 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0441\u0435\u0433\u043c\u0435\u043d\u0442 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u043c \u0434\u043b\u044f \u0437\u0430\u043f\u0438\u0441\u0438,   \/\/ \u0438\u043d\u0430\u0447\u0435 \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u043a\u0430 \u0443\u043f\u0430\u0434\u0451\u0442 \u0441 \u043e\u0448\u0438\u0431\u043a\u043e\u0439.   elf->phdrs[0].p_flags = PF_X | PF_W | PF_R;   \/\/ \u0423\u043c\u0435\u043d\u044c\u0448\u0430\u0435\u043c \u043d\u0430\u0447\u0430\u043b\u044c\u043d\u044b\u0439 \u0430\u0434\u0440\u0435\u0441 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0441\u0435\u0433\u043c\u0435\u043d\u0442\u0430 \u043d\u0430 rounded_size,   \/\/ \u0443\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u043c \u0435\u0433\u043e \u0440\u0430\u0437\u043c\u0435\u0440 \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u0438 \u0432 \u0444\u0430\u0439\u043b\u0435 \u043d\u0430 rounded_size.   elf->phdrs[0].p_vaddr -= rounded_size;   elf->phdrs[0].p_paddr -= rounded_size;   elf->phdrs[0].p_filesz += rounded_size;   elf->phdrs[0].p_memsz += rounded_size;    \/\/ \u0423\u0432\u0435\u043b\u0438\u0447\u0438\u0432\u0430\u0435\u043c \u0441\u043c\u0435\u0449\u0435\u043d\u0438\u0435 \u0432\u0441\u0435\u0445 \u0441\u0435\u0433\u043c\u0435\u043d\u0442\u043e\u0432, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0438\u0434\u0443\u0442   \/\/ \u043f\u043e\u0441\u043b\u0435 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u043d\u0430 rounded_size.   for(size_t i = 1; i &lt; elf->ehdr->e_phnum; i++) {     if(elf->phdrs[i].p_offset > elf->phdrs[0].p_offset)       elf->phdrs[i].p_offset += rounded_size;   }    \/\/ \u0421\u043e\u0437\u0434\u0430\u0451\u043c \u043d\u043e\u0432\u044b\u0439 \u0444\u0430\u0439\u043b.   fd = open(patched_executable, O_CREAT | O_TRUNC | O_WRONLY, 0755);   if(fd &lt; 0) {     perror(\"infect_engine (open)\");     goto exit;   }    \/\/ \u041f\u0438\u0448\u0435\u043c \u0432 \u043d\u0435\u0433\u043e \u0432\u0441\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0434\u043e \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u043e\u0432 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b \u0432\u043a\u043b\u044e\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u043e.   size_t to_program_headers = elf->phdrs[0].p_offset;   if(!write_all(fd, elf->mem, to_program_headers))     goto exit;   \/\/ \u041f\u0438\u0448\u0435\u043c .text \u0441\u0435\u043a\u0446\u0438\u044e \u0434\u0432\u0438\u0436\u043a\u0430.   if(!write_all(fd, engine->mem + engine_text->sh_offset, engine_text->sh_size))     goto exit;   \/\/ \u041f\u0438\u0448\u0435\u043c \u043d\u0443\u043b\u0438, \u0447\u0442\u043e\u0431\u044b \u0440\u0430\u0437\u043c\u0435\u0440 \u0431\u044b\u043b \u043a\u0440\u0430\u0442\u0435\u043d \u0440\u0430\u0437\u043c\u0435\u0440\u0443 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b.   size_t num_zeros = rounded_size - engine_text->sh_size;   if(num_zeros != 0) {     if(!write_all(fd, zeros, num_zeros))       goto exit;   }   \/\/ \u041f\u0438\u0448\u0435\u043c \u043e\u0441\u0442\u0430\u043b\u044c\u043d\u0443\u044e \u0447\u0430\u0441\u0442\u044c \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b\u044c\u043d\u043e\u0433\u043e ELF \u0444\u0430\u0439\u043b\u0430.   if(!write_all(fd, &amp;elf->mem[to_program_headers], elf->size - to_program_headers))     goto exit;    result = true; exit:   if(funcs) funcs_free(funcs);   if(fd >= 0) close(fd);   return result; }<\/code><\/pre>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u0434\u043e\u0431\u0430\u0432\u0438\u043c \u0432 main \u043d\u043e\u0432\u044b\u0439 \u0430\u0440\u0433\u0443\u043c\u0435\u043d\u0442 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438 <code>-p<\/code>:<\/p>\n<pre><code class=\"cpp\">typedef enum {   ENCRYPT,   INFECT,   HELP } action_t;  int main(int argc, char **argv) {   int result = EXIT_FAILURE;   elf_t elf, engine;   action_t action = HELP;   char *executable, *table, *addr_round_key, *patched_executable, *engine_path;    engine.mem = MAP_FAILED;     if(argc == 6 &amp;&amp; !strcmp(argv[1], \"-e\")) {     executable = argv[2];     table = argv[3];     addr_round_key = argv[4];     patched_executable = argv[5];     action = ENCRYPT;   } else if(argc == 5 &amp;&amp; !strcmp(argv[1], \"-p\")) {     executable = argv[2];     patched_executable = argv[3];     engine_path = argv[4];     action = INFECT;   }    if(action == HELP) {     fprintf(       stderr,       \"Usage:\\n\\t%s -e &lt;executable> &lt;table.inc> &lt;add_round_key.c> \"       \"&lt;patched_executable>\\n\"       \"\\t%s -p &lt;executable> &lt;patched_executable> &lt;engine>\\n\",       argv[0],       argv[0]     );     return EXIT_FAILURE;   }    if(!open_elf(executable, &amp;elf))     goto exit;    if(action == ENCRYPT) {     size_t num_functions = count_functions(&amp;elf);     if(!encrypt_and_generate_add_round_key(&amp;elf, num_functions, addr_round_key))       goto exit;     num_functions = get_func_table_size(num_functions);     if(!write_table_inc(table, num_functions))       goto exit;     if(!write_encrypted_exec(&amp;elf, patched_executable))       goto exit;   } else if(action == INFECT) {     if(!open_elf(engine_path, &amp;engine))       goto exit;     if(!infect_engine(&amp;elf, &amp;engine, patched_executable))       goto exit;   }    result = EXIT_SUCCESS; exit:   if(elf.mem != MAP_FAILED) close_elf(&amp;elf);   if(engine.mem != MAP_FAILED) close_elf(&amp;engine);   return result; }<\/code><\/pre>\n<p>\u041e\u0441\u0442\u0430\u043b\u043e\u0441\u044c \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u043d\u043e\u0432\u0443\u044e \u0446\u0435\u043b\u044c \u0432 Makefile \u0438 \u0433\u043e\u0442\u043e\u0432\u043e:<\/p>\n<pre><code>CC=gcc CFLAGS=-Wall -std=c11 -fno-stack-protector -Wno-builtin-declaration-mismatch \\        -fno-stack-protector -ffunction-sections -O0 LDFLAGS=-nostdlib -nostartfiles -nodefaultlibs -static -z noexecstack \\         -Wl,-z,noseparate-code AS=as  .PHONY: all clean all: crackme crackme: crackme-encrypted engine\/engine utils\/patcher\/patcher         .\/utils\/patcher\/patcher -p crackme-encrypted crackme engine\/engine engine\/engine: engine\/engine.o         $(CC) $(LDFLAGS) -T engine\/linker.ld -pie -Xlinker --no-dynamic-linker \\                 engine\/engine.o -o engine\/engine engine\/engine.o: crackme-encrypted engine\/engine.c         $(CC) $(CFLAGS) -fno-function-sections -O3 -mno-sse -fno-omit-frame-pointer -Wno-overflow -fPIC -c \\                 engine\/engine.c -o engine\/engine.o crackme-encrypted: crackme-unencrypted utils\/patcher\/patcher \\         utils\/gen-add-round-key\/build         cd utils\/gen-add-round-key &amp;&amp; ..\/patcher\/patcher -e ..\/..\/crackme-unencrypted \\                 ..\/..\/engine\/table.inc ..\/..\/engine\/AddRoundKey.c ..\/..\/crackme-encrypted crackme-unencrypted: linker.ld start.o crackme.o         $(CC) $(LDFLAGS) -T linker.ld start.o crackme.o -o crackme-unencrypted linker.ld: start.o crackme.o         readelf --wide -S start.o crackme.o | awk -f create_linker_script.awk > linker.ld crackme.o: crackme.c         $(CC) $(CFLAGS) -c crackme.c -o crackme.o start.o: start.s         $(AS) -c start.s -o start.o utils\/patcher\/patcher: FORCE         $(MAKE) $(MFLAGS) -C utils\/patcher utils\/gen-add-round-key\/build: FORCE         @test \"$(shell cd utils\/gen-add-round-key &amp;&amp; cabal build | tee \/dev\/fd\/2)\" = \"Up to date\" \\                 || { touch utils\/gen-add-round-key\/build; } \\                 &amp;&amp; { test -f utils\/gen-add-round-key\/build || \\                 touch utils\/gen-add-round-key\/build; } FORCE:  clean:         $(MAKE) -C utils\/patcher clean         rm -f start.o crackme.o linker.ld utils\/gen-add-round-key\/build \\                 engine\/table.inc engine\/AddRoundKey.c engine\/engine.o engine\/engine \\                 crackme-unencrypted crackme-encrypted crackme<\/code><\/pre>\n<p>\u0417\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c \u043d\u0430\u0448 crackme: <code>.\/crackme \"Hello Habr!?\"<\/code> \u0438 \u043d\u0438\u0447\u0435\u0433\u043e \u043d\u0435 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442, \u043a\u0430\u043a \u0436\u0435 \u0442\u0430\u043a? \u0412\u0441\u043f\u043e\u043c\u0438\u043d\u0430\u0435\u043c \u044d\u0442\u0443 <a href=\"#engine_stack\" rel=\"noopener noreferrer nofollow\">\u0438\u043b\u043b\u044e\u0441\u0442\u0440\u0430\u0446\u0438\u044e<\/a> \u0438 \u043f\u043e\u043d\u0438\u043c\u0430\u0435\u043c, \u0447\u0442\u043e \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 _start \u043d\u0443\u0436\u043d\u043e \u043f\u043e\u043c\u0435\u043d\u044f\u0442\u044c \u043a\u043e\u0434, \u043e\u0442\u0432\u0435\u0447\u0430\u044e\u0449\u0438\u0439 \u0437\u0430 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0443 argc \u0438 argv:<\/p>\n<pre><code class=\"assembly\">.text .globl _start .type _start,@function .section .text._start _start:     # Call main     movq 16(%rbp), %rdi     leaq 24(%rbp), %rsi     callq main      # Exit     movq %rax, %rdi     movq $60, %rax     syscall .size _start,.-_start <\/code><\/pre>\n<p>\u041a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u0443\u0435\u043c \u0432\u0441\u0451 \u0441\u043d\u043e\u0432\u0430, \u0438 \u043e\u043d\u043e \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u0442 \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c.<\/p>\n<h2>\u0417\u0430\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435<\/h2>\n<p>\u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044f \u043f\u043e\u043a\u0430\u0437\u0430\u043b \u043f\u0440\u043e\u0441\u0442\u043e\u0439 \u0441\u043f\u043e\u0441\u043e\u0431 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0432\u0441\u0435\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 \u0432 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u043c \u0444\u0430\u0439\u043b\u0435 \u0441 \u043f\u043e\u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0439 \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u043a\u043e\u0439 \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0430 \u0432\u0440\u0435\u043c\u044f \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f. \u041e\u0447\u0435\u0432\u0438\u0434\u043d\u043e, \u044d\u0442\u043e \u0441\u0430\u043c\u044b\u0439 \u043f\u0440\u043e\u0441\u0442\u043e\u0439 \u0438 \u043d\u0435 \u0441\u0430\u043c\u044b\u0439 \u043b\u0443\u0447\u0448\u0438\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0432 \u0438\u0442\u043e\u0433\u0435 \u0438\u0437 \u0432\u0441\u0435\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 \u043f\u0443\u0442\u044c \u0432\u0435\u0434\u0451\u0442 \u0432 \u043e\u0434\u043d\u043e \u0438 \u0442\u043e \u0436\u0435 \u043c\u0435\u0441\u0442\u043e &#8212; \u0432 \u0434\u0432\u0438\u0436\u043e\u043a. \u0412\u043e\u0437\u043c\u043e\u0436\u043d\u043e, \u043a\u043e\u0433\u0434\u0430-\u043d\u0438\u0431\u0443\u0434\u044c \u043f\u043e\u0437\u0436\u0435 \u044f \u043f\u0440\u0438\u0434\u0443\u043c\u0430\u044e, \u0447\u0442\u043e \u043f\u043e\u0441\u043b\u043e\u0436\u043d\u0435\u0435, \u043d\u043e \u043f\u043e\u043a\u0430 \u0436\u0438\u0432\u0451\u043c \u0441 \u0442\u0435\u043c, \u0447\u0442\u043e \u0438\u043c\u0435\u0435\u043c. \u0412 \u0437\u0430\u043a\u043b\u044e\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0439 \u0442\u0440\u0435\u0442\u044c\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u0440\u0435\u0447\u044c \u043f\u043e\u0439\u0434\u0451\u0442 \u043f\u0440\u043e \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043d\u0430\u043d\u043e\u043c\u0438\u0442\u043e\u0432 \u0432 \u043d\u0430\u0448 crackme \u0434\u043b\u044f \u0443\u0441\u043b\u043e\u0436\u043d\u0435\u043d\u0438\u044f \u043e\u0442\u043b\u0430\u0434\u043a\u0438. \u041d\u0430\u0434\u0435\u044e\u0441\u044c, \u0432\u0430\u043c \u0431\u044b\u043b\u043e \u0432\u0435\u0441\u0435\u043b\u043e.<\/p>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><!----><!----><\/div>\n<p><!----><!----><br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/articles\/767900\/\"> https:\/\/habr.com\/ru\/articles\/767900\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>\u042d\u0442\u0430 \u0441\u0442\u0430\u0442\u044c\u044f \u0432\u0442\u043e\u0440\u0430\u044f \u0432 \u0446\u0438\u043a\u043b\u0435 \u043f\u043e \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044e crackme \u043f\u043e\u0434 linux amd64. \u0412 \u044d\u0442\u043e\u0439 \u0447\u0430\u0441\u0442\u0438 \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043a\u0430\u0436\u0434\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u0431\u0443\u0434\u0435\u0442 \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0430 \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u043c \u043a\u043b\u044e\u0447\u043e\u043c, \u0438 \u0431\u0443\u0434\u0435\u0442 \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u0442\u044c\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0430 \u0432\u0440\u0435\u043c\u044f \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f. \u041f\u0440\u043e\u0446\u0435\u0441\u0441 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0431\u0443\u0434\u0435\u0442 \u043f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d, \u0442\u043e \u0435\u0441\u0442\u044c \u043f\u0440\u0438 \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0438\u0438 \u043d\u043e\u0432\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0438\u043b\u0438 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0438 \u0441\u0442\u0430\u0440\u043e\u0433\u043e \u043d\u0438\u043a\u0430\u043a\u0438\u0445 \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0445 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0439 \u0434\u0435\u043b\u0430\u0442\u044c \u0431\u0443\u0434\u0435\u0442 \u043d\u0435 \u043d\u0443\u0436\u043d\u043e. \u041a\u043e\u0434 \u0432\u0441\u0435\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0432 <a href=\"https:\/\/github.com\/cyberfined\/nanomites\" rel=\"noopener noreferrer nofollow\"><u>\u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438<\/u><\/a> \u043d\u0430 github.<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/articles\/760672\/\" rel=\"noopener noreferrer nofollow\"><u>\u041f\u0435\u0440\u0432\u0430\u044f \u0447\u0430\u0441\u0442\u044c<\/u><\/a>.<\/p>\n<\/li>\n<li>\n<p>\u0412\u0442\u043e\u0440\u0430\u044f \u0447\u0430\u0441\u0442\u044c.<\/p>\n<\/li>\n<\/ul>\n<h2>\u0410\u043b\u0433\u043e\u0440\u0438\u0442\u043c<\/h2>\n<p>\u0410\u043b\u0433\u043e\u0440\u0438\u0442\u043c \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0442\u0430\u043a\u043e\u0433\u043e \u0431\u0438\u043d\u0430\u0440\u043d\u0438\u043a\u0430 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043f\u0440\u043e\u0441\u0442, \u0440\u0430\u0441\u043f\u0438\u0448\u0435\u043c \u0435\u0433\u043e \u043f\u043e \u0448\u0430\u0433\u0430\u043c:<\/p>\n<ol>\n<li>\n<p>\u0421\u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043a\u043e\u0434 \u0432 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b \u0442\u0430\u043a, \u0447\u0442\u043e\u0431\u044b \u043a\u0430\u0436\u0434\u0430\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u0438\u043c\u0435\u043b\u0430 \u0440\u0430\u0437\u043c\u0435\u0440 \u043a\u0440\u0430\u0442\u043d\u044b\u0439 16. \u042d\u0442\u043e \u0443\u0441\u043b\u043e\u0432\u0438\u0435 \u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u0438\u0437 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 CBC \u043c\u043e\u0436\u043d\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0442\u043e\u043b\u044c\u043a\u043e \u0441 \u0431\u0443\u0444\u0435\u0440\u0430\u043c\u0438, \u0440\u0430\u0437\u043c\u0435\u0440 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043a\u0440\u0430\u0442\u0435\u043d \u0440\u0430\u0437\u043c\u0435\u0440\u0443 \u0431\u043b\u043e\u043a\u0430, \u0442\u043e \u0435\u0441\u0442\u044c 16.<\/p>\n<\/li>\n<li>\n<p>\u0421\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043a\u043b\u044e\u0447 \u0438 \u0432\u0435\u043a\u0442\u043e\u0440 \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0434\u043b\u044f \u043a\u0430\u0436\u0434\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u0437\u0430\u0442\u0435\u043c \u0437\u0430\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u0442\u044c \u0438\u0445. \u041f\u043e\u0441\u043b\u0435 \u044d\u0442\u043e\u0433\u043e \u043f\u0435\u0440\u0435\u0434\u0430\u0442\u044c \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e \u0444\u0443\u043d\u043a\u0446\u0438\u044f\u0445 (\u0430\u0434\u0440\u0435\u0441 \u0438 \u0440\u0430\u0437\u043c\u0435\u0440), \u0430 \u0442\u0430\u043a\u0436\u0435 \u043a\u043b\u044e\u0447\u0438 \u0438 \u0432\u0435\u043a\u0442\u043e\u0440\u044b \u0438\u043d\u0438\u0446\u0438\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0435 \u0434\u043b\u044f \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 AddRoundKey \u0438 get_iv, \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u044f \u043e\u043f\u0438\u0441\u0430\u043b \u0432 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0447\u0430\u0441\u0442\u0438. \u041f\u043e\u0441\u043b\u0435 \u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0448\u0430\u0433\u0430 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b \u0438\u0437\u043c\u0435\u043d\u0438\u0442\u0441\u044f \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c:<\/p>\n<figure class=\"\">\n<div><figcaption>\u0428\u0430\u0433 2<\/figcaption><\/div>\n<\/figure>\n<\/li>\n<li>\n<p>\u0421\u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043a\u043e\u0434 \u0434\u0432\u0438\u0436\u043a\u0430, \u043e\u0442\u0432\u0435\u0447\u0430\u044e\u0449\u0435\u0433\u043e \u0437\u0430 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0438 \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u043d\u0438\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0439. \u041e\u043d \u043a\u0430\u043a \u0440\u0430\u0437 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u043a\u043e\u0434, \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043d\u0430 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u043c \u0448\u0430\u0433\u0435. \u0427\u0442\u043e\u0431\u044b \u0441\u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043a\u043e\u0434 \u0434\u0432\u0438\u0436\u043a\u0430 \u043c\u043e\u0436\u043d\u043e \u0431\u044b\u043b\u043e \u0432\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0432 \u043d\u0430\u0448 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b, \u043d\u0443\u0436\u043d\u043e \u043f\u0435\u0440\u0435\u0434\u0430\u0442\u044c \u043a\u043e\u043c\u043f\u0438\u043b\u044f\u0442\u043e\u0440\u0443 \u0444\u043b\u0430\u0433 <code>-fPIC<\/code>, \u0447\u0442\u043e\u0431\u044b \u043a\u043e\u0434 \u0431\u044b\u043b \u043f\u043e\u0437\u0438\u0446\u0438\u043e\u043d\u043d\u043e-\u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u044b\u043c.<\/p>\n<\/li>\n<li>\n<p>\u0412\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u043a\u043e\u0434 \u0434\u0432\u0438\u0436\u043a\u0430 \u0432 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b, \u0432\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0432 \u043d\u0430\u0447\u0430\u043b\u043e \u043a\u0430\u0436\u0434\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044e call \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043a\u043e\u0434\u0430 \u0434\u0432\u0438\u0436\u043a\u0430. \u0417\u0434\u0435\u0441\u044c \u043f\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u0430\u044f \u0441 \u0442\u0435\u043c, \u0447\u0442\u043e \u043c\u044b \u043d\u0435 \u043c\u043e\u0436\u0435\u043c \u043c\u0435\u043d\u044f\u0442\u044c \u0440\u0430\u0437\u043c\u0435\u0440 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0442\u043e\u0433\u0434\u0430 \u0443 \u0434\u0440\u0443\u0433\u0438\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 \u043f\u043e\u043c\u0435\u043d\u044f\u044e\u0442\u0441\u044f \u0430\u0434\u0440\u0435\u0441\u0430, \u0447\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0439, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043e\u0431\u0440\u0430\u0449\u0430\u044e\u0442\u0441\u044f \u043a \u043f\u0430\u043c\u044f\u0442\u0438. \u041f\u043e\u044d\u0442\u043e\u043c\u0443 \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0437\u0430\u043c\u0435\u043d\u044f\u0442\u044c \u043f\u0435\u0440\u0432\u044b\u0435 5 \u0431\u0430\u0439\u0442 \u043a\u0430\u0436\u0434\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u043d\u0430 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044e call, \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b\u044c\u043d\u044b\u0435 \u0436\u0435 5 \u0431\u0430\u0439\u0442 \u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0432 \u0445\u044d\u0448-\u0442\u0430\u0431\u043b\u0438\u0446\u0443 \u0438 \u043f\u0440\u0438 \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u044b\u0432\u0430\u043d\u0438\u0438 \u0431\u0443\u0434\u0435\u043c \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0438\u0445 \u0438\u0437 \u043d\u0435\u0451 \u043e\u0431\u0440\u0430\u0442\u043d\u043e \u0432 \u043d\u0430\u0447\u0430\u043b\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0438. \u041f\u043e\u0441\u043b\u0435 \u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0448\u0430\u0433\u0430 \u043d\u0430\u0448 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b \u0431\u0443\u0434\u0435\u0442 \u0432\u044b\u0433\u043b\u044f\u0434\u0435\u0442\u044c \u0442\u0430\u043a:<\/p>\n<figure class=\"\">\n<div><figcaption>\u0428\u0430\u0433 4<\/figcaption><\/div>\n<\/figure>\n<\/li>\n<\/ol>\n<h2>\u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f<\/h2>\n<h3>\u0421\u043e\u0437\u0434\u0430\u0451\u043c \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b<\/h3>\n<p>\u041a\u0430\u043a\u00a0\u044f \u043f\u0438\u0441\u0430\u043b \u0432\u044b\u0448\u0435, \u043d\u0430\u043c \u043d\u0443\u0436\u043d\u043e \u0441\u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043a\u043e\u0434 \u0442\u0430\u043a, \u0447\u0442\u043e\u0431\u044b \u0440\u0430\u0437\u043c\u0435\u0440\u044b \u0432\u0441\u0435\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0439\u00a0\u0431\u044b\u043b\u0438 \u043a\u0440\u0430\u0442\u043d\u044b 16. \u0414\u043b\u044f\u00a0\u043d\u0430\u0447\u0430\u043b\u0430 \u043d\u0430\u043f\u0438\u0448\u0435\u043c \u043f\u0440\u043e\u0441\u0442\u043e\u0439 \u043a\u043e\u0434 \u043d\u0430\u00a0\u0441\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0438 \u0431\u0443\u0434\u0435\u043c \u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c. \u041c\u044b \u043d\u0435\u00a0\u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u0443\u044e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0443, \u0442\u0430\u043a \u043a\u0430\u043a\u00a0\u0438\u043d\u0430\u0447\u0435 \u0443\u00a0\u043d\u0430\u0441 \u0431\u0443\u0434\u0435\u0442 \u0441\u043b\u0438\u0448\u043a\u043e\u043c \u043c\u043d\u043e\u0433\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u0439, \u0430\u00a0\u043a\u0430\u043a\u00a0\u043c\u044b \u0432\u044b\u044f\u0441\u043d\u0438\u043b\u0438 \u0432\u00a0\u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u0433\u043b\u0430\u0432\u0435, \u0447\u0435\u043c \u0431\u043e\u043b\u044c\u0448\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0439, \u0442\u0435\u043c \u0431\u043e\u043b\u044c\u0448\u0435 \u0440\u0430\u0437\u043c\u0435\u0440 AddRoundKey, \u0442\u0435\u043c \u043c\u0435\u0434\u043b\u0435\u043d\u043d\u0435\u0435 \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0438 \u043a\u043e\u043c\u043f\u0438\u043b\u044f\u0446\u0438\u044f. \u0421\u0430\u043c \u043a\u043e\u0434 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u043d\u0438\u0436\u0435:<\/p>\n<p>start.s:<\/p>\n<pre><code class=\"assembly\">.text .globl _start .type _start,@function .section .text._start _start:     # Call main     movq (%rsp), %rdi     leaq 8(%rsp), %rsi     callq main      # Exit     movq %rax, %rdi     movq $60, %rax     syscall .size _start,.-_start<\/code><\/pre>\n<p>crackme.c:<\/p>\n<pre><code class=\"cpp\">#define write(fd, buf, count) syscall3(1, fd, (long)buf, count)  __attribute__((always_inline)) static inline long syscall3(long n, long a1, long a2, long a3) {   unsigned long ret;   __asm__ __volatile__ (\"syscall\" : \"=a\"(ret) : \"a\"(n), \"D\"(a1), \"S\"(a2),                                             \"d\"(a3) : \"rcx\", \"r11\", \"memory\");   return ret; }  static int calc_hash(unsigned char *pass) {   int hash = 0;   while(*pass) {     hash += (*pass + 11) % 23;     pass++;   }   return hash; }  \/\/ \u041f\u0430\u0440\u043e\u043b\u044c - Hello Habr!? int main(int argc, char **argv) {   if(argc != 2)     return 1;    int hash = calc_hash((unsigned char*)argv[1]);   if(hash != 152) {     char failure[] = \"Password is wrong\\n\";     write(1, failure, sizeof(failure));     return 1;   }    char success[] = \"Password is right!\\n\";   write(1, success, sizeof(success)); }<\/code><\/pre>\n<p>\u0415\u0441\u0442\u044c \u043e\u0434\u0438\u043d \u043f\u0440\u043e\u0441\u0442\u043e\u0439 \u0441\u043f\u043e\u0441\u043e\u0431, \u043a\u0430\u043a\u00a0\u0441\u0434\u0435\u043b\u0430\u0442\u044c \u0440\u0430\u0437\u043c\u0435\u0440\u044b \u0432\u0441\u0435\u0445 \u0444\u0443\u043d\u043a\u0446\u0438\u0439 \u043a\u0440\u0430\u0442\u043d\u044b\u043c\u0438 16\u00a0\u2014 \u043f\u043e\u043c\u0435\u0441\u0442\u0438\u0442\u044c \u043a\u0430\u0436\u0434\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044e \u0432\u00a0\u043e\u0442\u0434\u0435\u043b\u044c\u043d\u0443\u044e \u0441\u0435\u043a\u0446\u0438\u044e \u0438 \u0437\u0430\u0434\u0430\u0442\u044c \u0432\u00a0\u0441\u043a\u0440\u0438\u043f\u0442\u0435 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0430 \u0432\u044b\u0440\u0430\u0432\u043d\u0438\u0432\u0430\u043d\u0438\u0435 \u0434\u043b\u044f\u00a0\u043a\u0430\u0436\u0434\u043e\u0439 \u0442\u0430\u043a\u043e\u0439 \u0441\u0435\u043a\u0446\u0438\u0438. \u041f\u0435\u0440\u0432\u0430\u044f \u0437\u0430\u0434\u0430\u0447\u0430 \u0440\u0435\u0448\u0430\u0435\u0442\u0441\u044f \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0435\u0439 \u0444\u043b\u0430\u0433\u0430 <code>-ffunction-sections<\/code> \u043a\u043e\u043c\u043f\u0438\u043b\u044f\u0442\u043e\u0440\u0443 gcc, \u0432\u0442\u043e\u0440\u0430\u044f\u00a0\u2014 \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0435\u0439 \u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0430. \u0414\u043b\u044f\u00a0\u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u044f \u0440\u0435\u0448\u0438\u043b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0435 \u043a\u043e\u043d\u0441\u043e\u043b\u044c\u043d\u044b\u0435 \u0443\u0442\u0438\u043b\u0438\u0442\u044b\u00a0\u2014 readelf \u0438 awk. \u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u0441\u00a0\u043f\u043e\u043c\u043e\u0449\u044c\u044e readelf \u043f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0438\u0437\u00a0\u043e\u0431\u044a\u0435\u043a\u0442\u043d\u044b\u0445 \u0444\u0430\u0439\u043b\u043e\u0432 \u0438\u043c\u0435\u043d\u0430 \u0441\u0435\u043a\u0446\u0438\u0439, \u0437\u0430\u0442\u0435\u043c \u0441\u00a0\u043f\u043e\u043c\u043e\u0449\u044c\u044e awk \u043d\u0430\u00a0\u0438\u0445 \u043e\u0441\u043d\u043e\u0432\u0435 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c \u0441\u043a\u0440\u0438\u043f\u0442 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0430. \u0422\u0435\u043a\u0441\u0442 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b \u043d\u0430\u00a0awk \u043f\u0440\u0438\u0432\u0435\u0434\u0451\u043d \u043d\u0438\u0436\u0435.<\/p>\n<p>create_linker_script.awk:<\/p>\n<pre><code>BEGIN {   print \"ENTRY(_start)\\nSECTIONS {\\n    . = 0x400000;\\n\" \\         \"    .text : {\\n        * (.data)\\n        * (.rodata)\" }  {   if($2 ~ \/^\\.text\\..*\/)       matched=$2;   else if($3 ~ \/^\\.text\\..*\/)       matched=$3;   else       next;    print \"\\n        . = ALIGN(16);\\n        * (\"matched\")\\n        . = ALIGN(16);\" }  END {   print \"    }\\n}\" }<\/code><\/pre>\n<p>\u041c\u044b \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c, \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u0442\u0441\u044f \u043b\u0438 \u0432\u0442\u043e\u0440\u043e\u0439 \u0438\u043b\u0438 \u0442\u0440\u0435\u0442\u0438\u0439 \u0441\u0442\u043e\u043b\u0431\u0435\u0446 \u0441 .text, \u0435\u0441\u043b\u0438 \u043d\u0435\u0442, \u0442\u043e \u043f\u0440\u043e\u043f\u0443\u0441\u043a\u0430\u0435\u043c \u0441\u0442\u0440\u043e\u043a\u0443, \u0438\u043d\u0430\u0447\u0435 \u043f\u0435\u0447\u0430\u0442\u0430\u0435\u043c \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u0441\u0435\u043a\u0446\u0438\u0438 \u0432\u043c\u0435\u0441\u0442\u0435 \u0441 ALIGN(16). \u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0434\u0432\u0443\u0445 \u0441\u0442\u043e\u043b\u0431\u0446\u043e\u0432 \u0441\u0432\u044f\u0437\u0430\u043d\u0430 \u0441 \u0442\u0435\u043c, \u0447\u0442\u043e readelf \u0432\u044b\u0440\u0430\u0432\u043d\u0438\u0432\u0430\u0435\u0442 \u043d\u043e\u043c\u0435\u0440\u0430 \u0441\u0435\u043a\u0446\u0438\u0439, \u0434\u043b\u044f \u0441\u0435\u043a\u0446\u0438\u0439 \u0441 \u043e\u0434\u043d\u043e\u0437\u043d\u0430\u0447\u043d\u044b\u043c\u0438 \u043d\u043e\u043c\u0435\u0440\u0430\u043c\u0438 \u0438\u043c\u044f \u0431\u0443\u0434\u0435\u0442 \u0432 \u0442\u0440\u0435\u0442\u044c\u0435\u043c \u0441\u0442\u043e\u043b\u0431\u0446\u0435, \u0430 \u0434\u043b\u044f \u0441\u0435\u043a\u0446\u0438\u0439 \u0441 \u0434\u0432\u0443\u0445\u0437\u043d\u0430\u0447\u043d\u044b\u043c\u0438 \u043d\u043e\u043c\u0435\u0440\u0430\u043c\u0438 &#8212; \u0432\u043e \u0432\u0442\u043e\u0440\u043e\u043c. \u041f\u0440\u0438\u043c\u0435\u0440 \u0432\u044b\u0432\u043e\u0434\u0430 readelf \u0434\u043b\u044f \u043b\u0443\u0447\u0448\u0435\u0433\u043e \u043f\u043e\u043d\u0438\u043c\u0430\u043d\u0438\u044f:<\/p>\n<pre><code>There are 32 section headers, starting at offset 0x22258:  Section Headers:   [Nr] Name              Type            Address          Off    Size   ES Flg Lk Inf Al   [ 0]                   NULL            0000000000000000 000000 000000 00      0   0  0   [ 1] .interp           PROGBITS        0000000000000318 000318 00001c 00   A  0   0  1   [ 2] .note.gnu.property NOTE            0000000000000338 000338 000050 00   A  0   0  8   [ 3] .note.gnu.build-id NOTE            0000000000000388 000388 000024 00   A  0   0  4   [ 4] .note.ABI-tag     NOTE            00000000000003ac 0003ac 000020 00   A  0   0  4   [ 5] .note.package     NOTE            00000000000003cc 0003cc 00008c 00   A  0   0  4   [ 6] .gnu.hash         GNU_HASH        0000000000000458 000458 000040 00   A  7   0  8   [ 7] .dynsym           DYNSYM          0000000000000498 000498 000c48 18   A  8   1  8   [ 8] .dynstr           STRTAB          00000000000010e0 0010e0 000625 00   A  0   0  1   [ 9] .gnu.version      VERSYM          0000000000001706 001706 000106 02   A  7   0  2   [10] .gnu.version_r    VERNEED         0000000000001810 001810 0000d0 00   A  8   2  8 <\/code><\/pre>\n<p>\u041f\u043e\u0447\u0435\u043c\u0443 \u043c\u044b \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c, \u0447\u0442\u043e \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u0441\u0435\u043a\u0446\u0438\u0438 \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u0442\u0441\u044f \u0441 .text? \u041f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u043f\u0440\u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0435 \u0444\u043b\u0430\u0433\u0430 <code>-ffunction-sections<\/code> gcc \u043a\u043b\u0430\u0434\u0451\u0442 \u043a\u0430\u0436\u0434\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044e \u0432 \u0441\u0432\u043e\u044e \u0441\u0435\u043a\u0446\u0438\u044e \u0441 \u0438\u043c\u0435\u043d\u0435\u043c, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u043c \u0448\u0430\u0431\u043b\u043e\u043d\u0443 .text.\u0438\u043c\u044f_\u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u0438\u043c\u0435\u043d\u043d\u043e \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0440\u0430\u043d\u0435\u0435 \u043c\u044b \u044f\u0432\u043d\u043e \u0443\u043a\u0430\u0437\u0430\u043b\u0438 <code>.section .text._start<\/code> \u0434\u043b\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u0438 _start. \u0422\u0435\u043f\u0435\u0440\u044c \u043d\u0430\u043f\u0438\u0448\u0435\u043c Makefile \u0434\u043b\u044f \u0441\u0431\u043e\u0440\u043a\u0438 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430:<\/p>\n<pre><code>CC=gcc CFLAGS=-Wall -std=c11 -fno-stack-protector -Wno-builtin-declaration-mismatch \\        -fno-stack-protector -ffunction-sections -O0 LDFLAGS=-nostdlib -nostartfiles -nodefaultlibs -static -z noexecstack \\         -Wl,-z,noseparate-code AS=as  .PHONY: all clean all: crackme-unencrypted crackme-unencrypted: linker.ld start.o crackme.o         $(CC) $(LDFLAGS) -T linker.ld start.o crackme.o -o crackme-unencrypted linker.ld: start.o crackme.o         readelf --wide -S start.o crackme.o | awk -f create_linker_script.awk > linker.ld crackme.o: crackme.c         $(CC) $(CFLAGS) -c crackme.c -o crackme.o start.o: start.s         $(AS) -c start.s -o start.o clean:         rm -f start.o crackme.o linker.ld crackme-unencrypted<\/code><\/pre>\n<p>\u041a\u0430\u043a \u043c\u043e\u0436\u043d\u043e \u0432\u0438\u0434\u0435\u0442\u044c \u043f\u043e \u0444\u043b\u0430\u0433\u0430\u043c \u043a\u043e\u043c\u043f\u0438\u043b\u044f\u0446\u0438\u0438 &#8212; \u043c\u044b \u0441\u043e\u0431\u0438\u0440\u0430\u0435\u043c \u0441\u0442\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0444\u0430\u0439\u043b \u0431\u0435\u0437 \u043b\u0438\u043d\u043a\u043e\u0432\u043a\u0438 \u0441\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e\u0439 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u043e\u0439. \u0421\u0442\u043e\u0438\u0442 \u0442\u0430\u043a\u0436\u0435 \u043e\u0431\u0440\u0430\u0442\u0438\u0442\u044c \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0430 \u0442\u043e, \u0447\u0442\u043e readelf \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0441 \u0444\u043b\u0430\u0433\u043e\u043c <code>--wide<\/code>, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0438\u043d\u0430\u0447\u0435 \u0438\u043c\u0435\u043d\u0430 \u0441\u0435\u043a\u0446\u0438\u0439 \u043c\u043e\u0433\u0443\u0442 \u0432\u044b\u0432\u043e\u0434\u0438\u0442\u0441\u044f \u043d\u0435 \u043f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e. \u0414\u043b\u044f \u043d\u0430\u0433\u043b\u044f\u0434\u043d\u043e\u0441\u0442\u0438 \u0434\u0430\u043b\u0435\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0451\u043d \u0442\u0435\u043a\u0441\u0442 \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0430:<\/p>\n<pre><code>ENTRY(_start) SECTIONS {     . = 0x400000;     .text : {         * (.data)         * (.rodata)          . = ALIGN(16);         * (.text._start)         . = ALIGN(16);          . = ALIGN(16);         * (.text.calc_hash)         . = ALIGN(16);          . = ALIGN(16);         * (.text.main)         . = ALIGN(16);     } }<\/code><\/pre>\n<h3>\u0428\u0438\u0444\u0440\u0443\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u0438<\/h3>\n<p>\u0421\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e .\/utils\/patcher, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0431\u0443\u0434\u0435\u0442 \u0445\u0440\u0430\u043d\u0438\u0442\u0441\u044f \u043a\u043e\u0434 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u0443\u0434\u0435\u0442 \u043c\u043e\u0434\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043d\u0430\u0448 \u0431\u0438\u043d\u0430\u0440\u043d\u0438\u043a, \u0438 \u043f\u043e\u043b\u043e\u0436\u0438\u043c \u0442\u0443\u0434\u0430 \u0444\u0430\u0439\u043b\u044b <a href=\"https:\/\/github.com\/cyberfined\/nanomites\/blob\/master\/utils\/patcher\/aes.h\" rel=\"noopener noreferrer nofollow\">aes.h<\/a>, <a href=\"https:\/\/github.com\/cyberfined\/nanomites\/blob\/master\/utils\/patcher\/aes.c\" rel=\"noopener noreferrer nofollow\">aes.c<\/a>, \u044f\u0432\u043b\u044f\u044e\u0449\u0438\u0435\u0441\u044f \u043c\u043e\u0434\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c\u0438 \u0444\u0430\u0439\u043b\u0430\u043c\u0438 \u0438\u0437 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 <a href=\"https:\/\/github.com\/kokke\/tiny-AES-c\" rel=\"noopener noreferrer nofollow\">tiny-AES-c<\/a>. \u0414\u043b\u044f \u043b\u0443\u0447\u0448\u0435\u0433\u043e \u043f\u043e\u043d\u0438\u043c\u0430\u043d\u0438\u044f \u043a\u043e\u0434\u0430, \u0434\u0430\u043b\u0435\u0435 \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d\u0430 \u0441\u0438\u0433\u043d\u0430\u0442\u0443\u0440\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u043a\u043e\u0442\u043e\u0440\u043e\u044e \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f:<\/p>\n<pre><code class=\"cpp\">struct AES_ctx {   uint8_t *RoundKey;   uint8_t *Iv; };  void AES_CBC_encrypt_buffer(struct AES_ctx *ctx, uint8_t* buf, size_t length);<\/code><\/pre>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u043f\u0440\u0438\u0441\u0442\u0443\u043f\u0438\u043c \u043a \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044e \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043b\u044c\u0449\u0438\u043a\u0430. \u041d\u0430\u0447\u043d\u0451\u043c \u0441 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0438\u044f \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u0434\u043b\u044f \u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u043e\u0431 ELF \u0444\u0430\u0439\u043b\u0435 \u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u0438, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0441\u0447\u0438\u0442\u044b\u0432\u0430\u0435\u0442 ELF \u0444\u0430\u0439\u043b \u0432 \u0434\u0430\u043d\u043d\u0443\u044e \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443:<\/p>\n<pre><code class=\"cpp\">typedef struct {   const char *filepath;   uint8_t    *mem;   size_t     size;   Elf64_Ehdr *ehdr;   Elf64_Phdr *phdrs;   Elf64_Shdr *shdrs;   Elf64_Sym  *symbols;   size_t     num_symbols;   char       *sh_names;   char       *sym_names; } elf_t;  \/\/ \u042d\u0442\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f \u043d\u0430\u0445\u043e\u0434\u0438\u0442 \u0441\u0435\u043a\u0446\u0438\u044e \u0441 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u043c \u0442\u0438\u043f\u043e\u043c. static Elf64_Shdr* section_by_type(elf_t *elf, uint32_t sh_type) {   for(size_t i = 0; i &lt; elf->ehdr->e_shnum; i++) {     if(elf->shdrs[i].sh_type == sh_type)       return &amp;elf->shdrs[i];   }   return NULL; }  static bool open_elf(const char *filepath, elf_t *elf) {   elf->mem = MAP_FAILED;    int fd = open(filepath, O_RDONLY);   if(fd &lt; 0) {     perror(\"open_elf (open)\");     goto error;   }    struct stat statbuf;   if(fstat(fd, &amp;statbuf) &lt; 0) {     perror(\"open_elf (fstat)\");     goto error;   }    elf->filepath = filepath;   elf->size = statbuf.st_size;   elf->mem = mmap(NULL, elf->size, PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0);   if(elf->mem == MAP_FAILED) {     perror(\"open_elf (mmap)\");     goto error;   }    elf->ehdr = (Elf64_Ehdr*)elf->mem;   elf->phdrs = (Elf64_Phdr*)(elf->mem + elf->ehdr->e_phoff);   elf->shdrs = (Elf64_Shdr*)(elf->mem + elf->ehdr->e_shoff);    if(elf->ehdr->e_shnum != 0) {     \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u043e\u0431\u043b\u0430\u0441\u0442\u044c \u043f\u0430\u043c\u044f\u0442\u0438 \u0441 \u0438\u043c\u0435\u043d\u0430\u043c\u0438 \u0441\u0435\u043a\u0446\u0438\u0439.     elf->sh_names = (char*)elf->mem + elf->shdrs[elf->ehdr->e_shstrndx].sh_offset;      \/\/ \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043e\u043a \u0441\u0435\u043a\u0446\u0438\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0445\u0440\u0430\u043d\u044f\u0442\u0441\u044f     \/\/ \u0438\u043c\u0435\u043d\u0430 \u0441\u0438\u043c\u0432\u043e\u043b\u043e\u0432.     Elf64_Shdr *sh_strtab = section_by_name(elf, \".strtab\");<\/code><\/pre>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-357671","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/357671","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=357671"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/357671\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=357671"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=357671"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=357671"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}