From abd4549da3f36715fb87c789c8ae4099ad8d910d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E9=B2=81=E6=A0=91=E4=BA=BA?= Date: Sat, 14 Sep 2024 15:22:43 +0100 Subject: [PATCH] fix: ncm decryption --- um_crypto/ncm/src/header.rs | 86 +++++++++++++++++++++++++---------- um_crypto/ncm/src/lib.rs | 2 + um_crypto/ncm/src/metadata.rs | 8 +++- 3 files changed, 70 insertions(+), 26 deletions(-) diff --git a/um_crypto/ncm/src/header.rs b/um_crypto/ncm/src/header.rs index 28e7e67..a17e0e6 100644 --- a/um_crypto/ncm/src/header.rs +++ b/um_crypto/ncm/src/header.rs @@ -1,20 +1,24 @@ -use crate::{content_key, NetEaseCryptoError as Error}; +use crate::{content_key, metadata, NetEaseCryptoError as Error}; use byteorder::{ByteOrder, LE}; const CRC32: crc::Crc = crc::Crc::::new(&crc::CRC_32_ISO_HDLC); -struct NCMFile { +#[derive(Debug, PartialEq, Clone)] +pub struct NCMFile { + audio_rc4_key_stream: [u8; 256], + + /// NCM File format version, 0x01 pub ncm_version: u8, + /// CloudMusic client version (guess) pub client_version: u8, - /// Encrypted content key + /// Encrypted content key. pub content_key: Vec, /// Encrypted metadata. pub metadata: Vec, - /// Cover image 1 + /// Cover image 1, usually jpg. pub image1: Option>, /// Cover image 2, format unknown pub image2: Option>, - audio_rc4_key_stream: [u8; 256], pub audio_data_offset: usize, } @@ -34,6 +38,7 @@ fn build_audio_rc4_key_stream(enciphered_content_key: &[u8]) -> Result<[u8; 256] let mut key = [0u8; 256]; for (i, k) in key.iter_mut().enumerate() { + let i = (i + 1) & 0xff; let j = s[i].wrapping_add(i as u8); let idx = s[i].wrapping_add(s[j as usize]); *k = s[idx as usize]; @@ -129,35 +134,66 @@ impl NCMFile { audio_data_offset: offset, }) } + + pub fn get_metadata(&self) -> Result, Error> { + metadata::decrypt(&self.metadata) + } + + /// Decrypt audio data. + /// + /// # Arguments + /// + /// * `data`: The data to decrypt + /// * `offset`: Offset of the data in file, subtract `self.audio_data_offset` + /// + /// returns: Result<(), NetEaseCryptoError> + pub fn decrypt(&self, data: &mut T, offset: usize) -> Result<(), Error> + where + T: AsMut<[u8]>, + { + let key_stream = self.audio_rc4_key_stream.iter().cycle().skip(offset & 0xff); + for (datum, &key) in data.as_mut().iter_mut().zip(key_stream) { + *datum ^= key; + } + + Ok(()) + } } #[test] fn test_load_ncm() -> Result<(), Error> { let ncm_header = include_bytes!("__fixture__/ncm_test1.bin"); let ncm = NCMFile::new(ncm_header)?; - let sbox = [ - 0x08, 0x67, 0x20, 0xF0, 0x5C, 0xAC, 0xAF, 0x1B, 0x74, 0x0D, 0x26, 0x40, 0xBE, 0x85, 0x61, - 0x45, 0x0D, 0xA8, 0x69, 0xAE, 0x78, 0xEC, 0xB8, 0x14, 0x79, 0x53, 0xC4, 0x74, 0xF2, 0x9F, - 0xE1, 0x18, 0xE2, 0xF9, 0xC0, 0x7D, 0x1E, 0x5A, 0xBA, 0x4A, 0xB3, 0x11, 0x36, 0xD9, 0xAA, - 0xD2, 0x13, 0xEE, 0x92, 0x45, 0x4B, 0x57, 0xE6, 0xF1, 0x13, 0x90, 0xE9, 0xE5, 0x2F, 0xBE, - 0x6E, 0x16, 0x01, 0xBF, 0x10, 0x81, 0x5C, 0x68, 0x1C, 0xE3, 0xEB, 0xDF, 0x5A, 0xC7, 0xC3, - 0x3F, 0x9C, 0xD7, 0x28, 0x3A, 0x81, 0x2B, 0x1F, 0xF3, 0x6F, 0x27, 0x15, 0x7E, 0x53, 0xD3, - 0xF0, 0xFA, 0x50, 0x9F, 0xC7, 0xF0, 0x7F, 0xA6, 0xA7, 0x24, 0x80, 0x87, 0x39, 0x55, 0xA5, - 0x0B, 0x2B, 0x8B, 0x00, 0x19, 0x82, 0xA8, 0x40, 0xA5, 0x77, 0x9C, 0x93, 0x3B, 0xEE, 0x27, - 0x70, 0x0F, 0xA2, 0xEB, 0xA5, 0x6F, 0x58, 0xFB, 0xEB, 0x57, 0x1B, 0xC3, 0x61, 0x10, 0x6D, - 0x95, 0x2C, 0xAA, 0xC6, 0x58, 0x88, 0xD5, 0x9E, 0x33, 0x9A, 0x5A, 0xD1, 0xB5, 0xD2, 0x17, - 0x44, 0xD6, 0xDB, 0xAB, 0xED, 0x7C, 0xFC, 0x5C, 0x37, 0xB9, 0x16, 0xB8, 0xA5, 0x77, 0xFB, - 0x58, 0x35, 0x36, 0xE7, 0x51, 0xD0, 0x03, 0xBB, 0x2A, 0x88, 0x24, 0x84, 0x1D, 0x28, 0xB1, - 0xE1, 0xA0, 0xA5, 0xA0, 0xDD, 0x15, 0x66, 0xBB, 0x4F, 0x7E, 0xBC, 0x99, 0x76, 0x1A, 0xD2, - 0xEF, 0xBE, 0xD9, 0x79, 0xA0, 0x33, 0xD5, 0x96, 0x6C, 0xD9, 0xEF, 0x42, 0x7E, 0x11, 0x45, - 0x1F, 0x99, 0x96, 0x1A, 0x90, 0x0C, 0x75, 0xBC, 0x01, 0xE2, 0xC8, 0xEF, 0x16, 0x98, 0x9A, - 0x09, 0xEB, 0xD8, 0xA1, 0xEA, 0x62, 0xE7, 0x92, 0x20, 0x8F, 0x6F, 0x72, 0xDE, 0x14, 0xFE, - 0xBF, 0xCD, 0xBA, 0x97, 0xDE, 0xA3, 0x3B, 0x67, 0xD4, 0x0B, 0xF4, 0xD3, 0x97, 0x25, 0xBA, - 0xCA, + let key_stream = [ + 0x67, 0x20, 0xF0, 0x5C, 0xAC, 0xAF, 0x1B, 0x74, 0x0D, 0x26, 0x40, 0xBE, 0x85, 0x61, 0x45, + 0x0D, 0xA8, 0x69, 0xAE, 0x78, 0xEC, 0xB8, 0x14, 0x79, 0x53, 0xC4, 0x74, 0xF2, 0x9F, 0xE1, + 0x18, 0xE2, 0xF9, 0xC0, 0x7D, 0x1E, 0x5A, 0xBA, 0x4A, 0xB3, 0x11, 0x36, 0xD9, 0xAA, 0xD2, + 0x13, 0xEE, 0x92, 0x45, 0x4B, 0x57, 0xE6, 0xF1, 0x13, 0x90, 0xE9, 0xE5, 0x2F, 0xBE, 0x6E, + 0x16, 0x01, 0xBF, 0x10, 0x81, 0x5C, 0x68, 0x1C, 0xE3, 0xEB, 0xDF, 0x5A, 0xC7, 0xC3, 0x3F, + 0x9C, 0xD7, 0x28, 0x3A, 0x81, 0x2B, 0x1F, 0xF3, 0x6F, 0x27, 0x15, 0x7E, 0x53, 0xD3, 0xF0, + 0xFA, 0x50, 0x9F, 0xC7, 0xF0, 0x7F, 0xA6, 0xA7, 0x24, 0x80, 0x87, 0x39, 0x55, 0xA5, 0x0B, + 0x2B, 0x8B, 0x00, 0x19, 0x82, 0xA8, 0x40, 0xA5, 0x77, 0x9C, 0x93, 0x3B, 0xEE, 0x27, 0x70, + 0x0F, 0xA2, 0xEB, 0xA5, 0x6F, 0x58, 0xFB, 0xEB, 0x57, 0x1B, 0xC3, 0x61, 0x10, 0x6D, 0x95, + 0x2C, 0xAA, 0xC6, 0x58, 0x88, 0xD5, 0x9E, 0x33, 0x9A, 0x5A, 0xD1, 0xB5, 0xD2, 0x17, 0x44, + 0xD6, 0xDB, 0xAB, 0xED, 0x7C, 0xFC, 0x5C, 0x37, 0xB9, 0x16, 0xB8, 0xA5, 0x77, 0xFB, 0x58, + 0x35, 0x36, 0xE7, 0x51, 0xD0, 0x03, 0xBB, 0x2A, 0x88, 0x24, 0x84, 0x1D, 0x28, 0xB1, 0xE1, + 0xA0, 0xA5, 0xA0, 0xDD, 0x15, 0x66, 0xBB, 0x4F, 0x7E, 0xBC, 0x99, 0x76, 0x1A, 0xD2, 0xEF, + 0xBE, 0xD9, 0x79, 0xA0, 0x33, 0xD5, 0x96, 0x6C, 0xD9, 0xEF, 0x42, 0x7E, 0x11, 0x45, 0x1F, + 0x99, 0x96, 0x1A, 0x90, 0x0C, 0x75, 0xBC, 0x01, 0xE2, 0xC8, 0xEF, 0x16, 0x98, 0x9A, 0x09, + 0xEB, 0xD8, 0xA1, 0xEA, 0x62, 0xE7, 0x92, 0x20, 0x8F, 0x6F, 0x72, 0xDE, 0x14, 0xFE, 0xBF, + 0xCD, 0xBA, 0x97, 0xDE, 0xA3, 0x3B, 0x67, 0xD4, 0x0B, 0xF4, 0xD3, 0x97, 0x25, 0xBA, 0xCA, + 0x08, ]; - assert_eq!(ncm.audio_rc4_key_stream, sbox); + assert_eq!(ncm.audio_rc4_key_stream, key_stream); assert_eq!(ncm.image1, Some(b"img#1".to_vec())); assert_eq!(ncm.image2, Some(b"IMAGE#2".to_vec())); + let mut audio_data = ncm_header[ncm.audio_data_offset..].to_vec(); + ncm.decrypt(&mut audio_data, 0)?; + let actual = vec![ + 0x49, 0x44, 0x33, 0x03, 0x00, 0x00, 0x00, 0x00, 0x01, 0x73, 0x54, 0x50, 0x45, 0x31, 0x00, + ]; + assert_eq!(audio_data, actual); + Ok(()) } diff --git a/um_crypto/ncm/src/lib.rs b/um_crypto/ncm/src/lib.rs index c0ff899..c3b3811 100644 --- a/um_crypto/ncm/src/lib.rs +++ b/um_crypto/ncm/src/lib.rs @@ -34,4 +34,6 @@ pub enum NetEaseCryptoError { MetadataDecryptError(UnpadError), #[error("Metadata: Decode metadata failed: {0}")] MetadataDecodeError(base64::DecodeError), + #[error("Metadata: Invalid prefix on final json: {0}")] + MetadataInvalidJsonPrefix(String), } diff --git a/um_crypto/ncm/src/metadata.rs b/um_crypto/ncm/src/metadata.rs index e3aad2f..ab8e25e 100644 --- a/um_crypto/ncm/src/metadata.rs +++ b/um_crypto/ncm/src/metadata.rs @@ -35,6 +35,12 @@ where let metadata = aes .decrypt_padded::(&mut data[..]) .map_err(NetEaseCryptoError::MetadataDecryptError)?; + let metadata = match metadata.strip_prefix(b"music:") { + None => Err(NetEaseCryptoError::MetadataInvalidJsonPrefix( + String::from_utf8_lossy(metadata).to_string(), + ))?, + Some(stripped) => stripped, + }; Ok(Vec::from(metadata)) } @@ -100,6 +106,6 @@ fn test_decrypt_metadata() -> Result<(), NetEaseCryptoError> { 0x25, 0x1B, 0x37, 0x48, 0x57, 0x53, 0x2A, 0x22, 0x3A, 0x00, 0x34, 0x53, 0x24, 0x12, ]; let key = decrypt(enciphered_metadata)?; - assert_eq!(&key[..6], b"music:"); + assert_eq!(key[0], b'{'); Ok(()) }