breakwa11
10 years ago
7 changed files with 516 additions and 22 deletions
@ -0,0 +1,135 @@ |
|||||
|
#!/usr/bin/env python |
||||
|
|
||||
|
# Copyright (c) 2014 clowwindy |
||||
|
# |
||||
|
# Permission is hereby granted, free of charge, to any person obtaining a copy |
||||
|
# of this software and associated documentation files (the "Software"), to deal |
||||
|
# in the Software without restriction, including without limitation the rights |
||||
|
# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
||||
|
# copies of the Software, and to permit persons to whom the Software is |
||||
|
# furnished to do so, subject to the following conditions: |
||||
|
# |
||||
|
# The above copyright notice and this permission notice shall be included in |
||||
|
# all copies or substantial portions of the Software. |
||||
|
# |
||||
|
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
||||
|
# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
||||
|
# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
||||
|
# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
||||
|
# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
||||
|
# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE |
||||
|
# SOFTWARE. |
||||
|
|
||||
|
from __future__ import absolute_import, division, print_function, \ |
||||
|
with_statement |
||||
|
|
||||
|
import logging |
||||
|
from ctypes import CDLL, c_char_p, c_int, c_ulonglong, byref, \ |
||||
|
create_string_buffer, c_void_p |
||||
|
|
||||
|
__all__ = ['ciphers'] |
||||
|
|
||||
|
libsodium = None |
||||
|
loaded = False |
||||
|
|
||||
|
buf_size = 2048 |
||||
|
|
||||
|
# for salsa20 and chacha20 |
||||
|
BLOCK_SIZE = 64 |
||||
|
|
||||
|
|
||||
|
def load_libsodium(): |
||||
|
global loaded, libsodium, buf |
||||
|
|
||||
|
from ctypes.util import find_library |
||||
|
for p in ('sodium',): |
||||
|
libsodium_path = find_library(p) |
||||
|
if libsodium_path: |
||||
|
break |
||||
|
else: |
||||
|
raise Exception('libsodium not found') |
||||
|
logging.info('loading libsodium from %s', libsodium_path) |
||||
|
libsodium = CDLL(libsodium_path) |
||||
|
libsodium.sodium_init.restype = c_int |
||||
|
libsodium.crypto_stream_salsa20_xor_ic.restype = c_int |
||||
|
libsodium.crypto_stream_salsa20_xor_ic.argtypes = (c_void_p, c_char_p, |
||||
|
c_ulonglong, |
||||
|
c_char_p, c_ulonglong, |
||||
|
c_char_p) |
||||
|
libsodium.crypto_stream_chacha20_xor_ic.restype = c_int |
||||
|
libsodium.crypto_stream_chacha20_xor_ic.argtypes = (c_void_p, c_char_p, |
||||
|
c_ulonglong, |
||||
|
c_char_p, c_ulonglong, |
||||
|
c_char_p) |
||||
|
|
||||
|
libsodium.sodium_init() |
||||
|
|
||||
|
buf = create_string_buffer(buf_size) |
||||
|
loaded = True |
||||
|
|
||||
|
|
||||
|
class Salsa20Crypto(object): |
||||
|
def __init__(self, cipher_name, key, iv, op): |
||||
|
if not loaded: |
||||
|
load_libsodium() |
||||
|
self.key = key |
||||
|
self.iv = iv |
||||
|
self.key_ptr = c_char_p(key) |
||||
|
self.iv_ptr = c_char_p(iv) |
||||
|
if cipher_name == b'salsa20': |
||||
|
self.cipher = libsodium.crypto_stream_salsa20_xor_ic |
||||
|
elif cipher_name == b'chacha20': |
||||
|
self.cipher = libsodium.crypto_stream_chacha20_xor_ic |
||||
|
else: |
||||
|
raise Exception('Unknown cipher') |
||||
|
# byte counter, not block counter |
||||
|
self.counter = 0 |
||||
|
|
||||
|
def update(self, data): |
||||
|
global buf_size, buf |
||||
|
l = len(data) |
||||
|
|
||||
|
# we can only prepend some padding to make the encryption align to |
||||
|
# blocks |
||||
|
padding = self.counter % BLOCK_SIZE |
||||
|
if buf_size < padding + l: |
||||
|
buf_size = (padding + l) * 2 |
||||
|
buf = create_string_buffer(buf_size) |
||||
|
|
||||
|
if padding: |
||||
|
data = (b'\0' * padding) + data |
||||
|
self.cipher(byref(buf), c_char_p(data), padding + l, |
||||
|
self.iv_ptr, int(self.counter / BLOCK_SIZE), self.key_ptr) |
||||
|
self.counter += l |
||||
|
# buf is copied to a str object when we access buf.raw |
||||
|
# strip off the padding |
||||
|
return buf.raw[padding:padding + l] |
||||
|
|
||||
|
|
||||
|
ciphers = { |
||||
|
b'salsa20': (32, 8, Salsa20Crypto), |
||||
|
b'chacha20': (32, 8, Salsa20Crypto), |
||||
|
} |
||||
|
|
||||
|
|
||||
|
def test_salsa20(): |
||||
|
from shadowsocks.crypto import util |
||||
|
|
||||
|
cipher = Salsa20Crypto(b'salsa20', b'k' * 32, b'i' * 16, 1) |
||||
|
decipher = Salsa20Crypto(b'salsa20', b'k' * 32, b'i' * 16, 0) |
||||
|
|
||||
|
util.run_cipher(cipher, decipher) |
||||
|
|
||||
|
|
||||
|
def test_chacha20(): |
||||
|
from shadowsocks.crypto import util |
||||
|
|
||||
|
cipher = Salsa20Crypto(b'chacha20', b'k' * 32, b'i' * 16, 1) |
||||
|
decipher = Salsa20Crypto(b'chacha20', b'k' * 32, b'i' * 16, 0) |
||||
|
|
||||
|
util.run_cipher(cipher, decipher) |
||||
|
|
||||
|
|
||||
|
if __name__ == '__main__': |
||||
|
test_chacha20() |
||||
|
test_salsa20() |
@ -0,0 +1,188 @@ |
|||||
|
#!/usr/bin/env python |
||||
|
|
||||
|
# Copyright (c) 2014 clowwindy |
||||
|
# |
||||
|
# Permission is hereby granted, free of charge, to any person obtaining a copy |
||||
|
# of this software and associated documentation files (the "Software"), to deal |
||||
|
# in the Software without restriction, including without limitation the rights |
||||
|
# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
||||
|
# copies of the Software, and to permit persons to whom the Software is |
||||
|
# furnished to do so, subject to the following conditions: |
||||
|
# |
||||
|
# The above copyright notice and this permission notice shall be included in |
||||
|
# all copies or substantial portions of the Software. |
||||
|
# |
||||
|
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
||||
|
# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
||||
|
# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
||||
|
# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
||||
|
# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
||||
|
# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE |
||||
|
# SOFTWARE. |
||||
|
|
||||
|
from __future__ import absolute_import, division, print_function, \ |
||||
|
with_statement |
||||
|
|
||||
|
import logging |
||||
|
from ctypes import CDLL, c_char_p, c_int, c_long, byref,\ |
||||
|
create_string_buffer, c_void_p |
||||
|
|
||||
|
__all__ = ['ciphers'] |
||||
|
|
||||
|
libcrypto = None |
||||
|
loaded = False |
||||
|
|
||||
|
buf_size = 2048 |
||||
|
|
||||
|
|
||||
|
def load_openssl(): |
||||
|
global loaded, libcrypto, buf |
||||
|
|
||||
|
from ctypes.util import find_library |
||||
|
for p in ('crypto', 'eay32', 'libeay32'): |
||||
|
libcrypto_path = find_library(p) |
||||
|
if libcrypto_path: |
||||
|
break |
||||
|
else: |
||||
|
raise Exception('libcrypto(OpenSSL) not found') |
||||
|
logging.info('loading libcrypto from %s', libcrypto_path) |
||||
|
libcrypto = CDLL(libcrypto_path) |
||||
|
libcrypto.EVP_get_cipherbyname.restype = c_void_p |
||||
|
libcrypto.EVP_CIPHER_CTX_new.restype = c_void_p |
||||
|
|
||||
|
libcrypto.EVP_CipherInit_ex.argtypes = (c_void_p, c_void_p, c_char_p, |
||||
|
c_char_p, c_char_p, c_int) |
||||
|
|
||||
|
libcrypto.EVP_CipherUpdate.argtypes = (c_void_p, c_void_p, c_void_p, |
||||
|
c_char_p, c_int) |
||||
|
|
||||
|
libcrypto.EVP_CIPHER_CTX_cleanup.argtypes = (c_void_p,) |
||||
|
libcrypto.EVP_CIPHER_CTX_free.argtypes = (c_void_p,) |
||||
|
if hasattr(libcrypto, 'OpenSSL_add_all_ciphers'): |
||||
|
libcrypto.OpenSSL_add_all_ciphers() |
||||
|
|
||||
|
buf = create_string_buffer(buf_size) |
||||
|
loaded = True |
||||
|
|
||||
|
|
||||
|
def load_cipher(cipher_name): |
||||
|
func_name = b'EVP_' + cipher_name.replace(b'-', b'_') |
||||
|
if bytes != str: |
||||
|
func_name = str(func_name, 'utf-8') |
||||
|
cipher = getattr(libcrypto, func_name, None) |
||||
|
if cipher: |
||||
|
cipher.restype = c_void_p |
||||
|
return cipher() |
||||
|
return None |
||||
|
|
||||
|
|
||||
|
class CtypesCrypto(object): |
||||
|
def __init__(self, cipher_name, key, iv, op): |
||||
|
if not loaded: |
||||
|
load_openssl() |
||||
|
self._ctx = None |
||||
|
cipher = libcrypto.EVP_get_cipherbyname(cipher_name) |
||||
|
if not cipher: |
||||
|
cipher = load_cipher(cipher_name) |
||||
|
if not cipher: |
||||
|
raise Exception('cipher %s not found in libcrypto' % cipher_name) |
||||
|
key_ptr = c_char_p(key) |
||||
|
iv_ptr = c_char_p(iv) |
||||
|
self._ctx = libcrypto.EVP_CIPHER_CTX_new() |
||||
|
if not self._ctx: |
||||
|
raise Exception('can not create cipher context') |
||||
|
r = libcrypto.EVP_CipherInit_ex(self._ctx, cipher, None, |
||||
|
key_ptr, iv_ptr, c_int(op)) |
||||
|
if not r: |
||||
|
self.clean() |
||||
|
raise Exception('can not initialize cipher context') |
||||
|
|
||||
|
def update(self, data): |
||||
|
global buf_size, buf |
||||
|
cipher_out_len = c_long(0) |
||||
|
l = len(data) |
||||
|
if buf_size < l: |
||||
|
buf_size = l * 2 |
||||
|
buf = create_string_buffer(buf_size) |
||||
|
libcrypto.EVP_CipherUpdate(self._ctx, byref(buf), |
||||
|
byref(cipher_out_len), c_char_p(data), l) |
||||
|
# buf is copied to a str object when we access buf.raw |
||||
|
return buf.raw[:cipher_out_len.value] |
||||
|
|
||||
|
def __del__(self): |
||||
|
self.clean() |
||||
|
|
||||
|
def clean(self): |
||||
|
if self._ctx: |
||||
|
libcrypto.EVP_CIPHER_CTX_cleanup(self._ctx) |
||||
|
libcrypto.EVP_CIPHER_CTX_free(self._ctx) |
||||
|
|
||||
|
|
||||
|
ciphers = { |
||||
|
b'aes-128-cfb': (16, 16, CtypesCrypto), |
||||
|
b'aes-192-cfb': (24, 16, CtypesCrypto), |
||||
|
b'aes-256-cfb': (32, 16, CtypesCrypto), |
||||
|
b'aes-128-ofb': (16, 16, CtypesCrypto), |
||||
|
b'aes-192-ofb': (24, 16, CtypesCrypto), |
||||
|
b'aes-256-ofb': (32, 16, CtypesCrypto), |
||||
|
b'aes-128-ctr': (16, 16, CtypesCrypto), |
||||
|
b'aes-192-ctr': (24, 16, CtypesCrypto), |
||||
|
b'aes-256-ctr': (32, 16, CtypesCrypto), |
||||
|
b'aes-128-cfb8': (16, 16, CtypesCrypto), |
||||
|
b'aes-192-cfb8': (24, 16, CtypesCrypto), |
||||
|
b'aes-256-cfb8': (32, 16, CtypesCrypto), |
||||
|
b'aes-128-cfb1': (16, 16, CtypesCrypto), |
||||
|
b'aes-192-cfb1': (24, 16, CtypesCrypto), |
||||
|
b'aes-256-cfb1': (32, 16, CtypesCrypto), |
||||
|
b'bf-cfb': (16, 8, CtypesCrypto), |
||||
|
b'camellia-128-cfb': (16, 16, CtypesCrypto), |
||||
|
b'camellia-192-cfb': (24, 16, CtypesCrypto), |
||||
|
b'camellia-256-cfb': (32, 16, CtypesCrypto), |
||||
|
b'cast5-cfb': (16, 8, CtypesCrypto), |
||||
|
b'des-cfb': (8, 8, CtypesCrypto), |
||||
|
b'idea-cfb': (16, 8, CtypesCrypto), |
||||
|
b'rc2-cfb': (16, 8, CtypesCrypto), |
||||
|
b'rc4': (16, 0, CtypesCrypto), |
||||
|
b'seed-cfb': (16, 16, CtypesCrypto), |
||||
|
} |
||||
|
|
||||
|
|
||||
|
def run_method(method): |
||||
|
from shadowsocks.crypto import util |
||||
|
|
||||
|
cipher = CtypesCrypto(method, b'k' * 32, b'i' * 16, 1) |
||||
|
decipher = CtypesCrypto(method, b'k' * 32, b'i' * 16, 0) |
||||
|
|
||||
|
util.run_cipher(cipher, decipher) |
||||
|
|
||||
|
|
||||
|
def test_aes_128_cfb(): |
||||
|
run_method(b'aes-128-cfb') |
||||
|
|
||||
|
|
||||
|
def test_aes_256_cfb(): |
||||
|
run_method(b'aes-256-cfb') |
||||
|
|
||||
|
|
||||
|
def test_aes_128_cfb8(): |
||||
|
run_method(b'aes-128-cfb8') |
||||
|
|
||||
|
|
||||
|
def test_aes_256_ofb(): |
||||
|
run_method(b'aes-256-ofb') |
||||
|
|
||||
|
|
||||
|
def test_aes_256_ctr(): |
||||
|
run_method(b'aes-256-ctr') |
||||
|
|
||||
|
|
||||
|
def test_bf_cfb(): |
||||
|
run_method(b'bf-cfb') |
||||
|
|
||||
|
|
||||
|
def test_rc4(): |
||||
|
run_method(b'rc4') |
||||
|
|
||||
|
|
||||
|
if __name__ == '__main__': |
||||
|
test_aes_128_cfb() |
@ -0,0 +1,117 @@ |
|||||
|
#!/usr/bin/env python |
||||
|
|
||||
|
# Copyright (c) 2014 clowwindy |
||||
|
# |
||||
|
# Permission is hereby granted, free of charge, to any person obtaining a copy |
||||
|
# of this software and associated documentation files (the "Software"), to deal |
||||
|
# in the Software without restriction, including without limitation the rights |
||||
|
# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
||||
|
# copies of the Software, and to permit persons to whom the Software is |
||||
|
# furnished to do so, subject to the following conditions: |
||||
|
# |
||||
|
# The above copyright notice and this permission notice shall be included in |
||||
|
# all copies or substantial portions of the Software. |
||||
|
# |
||||
|
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
||||
|
# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
||||
|
# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
||||
|
# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
||||
|
# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
||||
|
# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE |
||||
|
# SOFTWARE. |
||||
|
|
||||
|
from __future__ import absolute_import, division, print_function, \ |
||||
|
with_statement |
||||
|
|
||||
|
import sys |
||||
|
import logging |
||||
|
|
||||
|
__all__ = ['ciphers'] |
||||
|
|
||||
|
has_m2 = True |
||||
|
try: |
||||
|
__import__('M2Crypto') |
||||
|
except ImportError: |
||||
|
has_m2 = False |
||||
|
|
||||
|
|
||||
|
def create_cipher(alg, key, iv, op, key_as_bytes=0, d=None, salt=None, i=1, |
||||
|
padding=1): |
||||
|
|
||||
|
import M2Crypto.EVP |
||||
|
return M2Crypto.EVP.Cipher(alg.replace('-', '_'), key, iv, op, |
||||
|
key_as_bytes=0, d='md5', salt=None, i=1, |
||||
|
padding=1) |
||||
|
|
||||
|
|
||||
|
def err(alg, key, iv, op, key_as_bytes=0, d=None, salt=None, i=1, padding=1): |
||||
|
logging.error(('M2Crypto is required to use %s, please run' |
||||
|
' `apt-get install python-m2crypto`') % alg) |
||||
|
sys.exit(1) |
||||
|
|
||||
|
|
||||
|
if has_m2: |
||||
|
ciphers = { |
||||
|
b'aes-128-cfb': (16, 16, create_cipher), |
||||
|
b'aes-192-cfb': (24, 16, create_cipher), |
||||
|
b'aes-256-cfb': (32, 16, create_cipher), |
||||
|
b'bf-cfb': (16, 8, create_cipher), |
||||
|
b'camellia-128-cfb': (16, 16, create_cipher), |
||||
|
b'camellia-192-cfb': (24, 16, create_cipher), |
||||
|
b'camellia-256-cfb': (32, 16, create_cipher), |
||||
|
b'cast5-cfb': (16, 8, create_cipher), |
||||
|
b'des-cfb': (8, 8, create_cipher), |
||||
|
b'idea-cfb': (16, 8, create_cipher), |
||||
|
b'rc2-cfb': (16, 8, create_cipher), |
||||
|
b'rc4': (16, 0, create_cipher), |
||||
|
b'seed-cfb': (16, 16, create_cipher), |
||||
|
} |
||||
|
else: |
||||
|
ciphers = {} |
||||
|
|
||||
|
|
||||
|
def run_method(method): |
||||
|
from shadowsocks.crypto import util |
||||
|
|
||||
|
cipher = create_cipher(method, b'k' * 32, b'i' * 16, 1) |
||||
|
decipher = create_cipher(method, b'k' * 32, b'i' * 16, 0) |
||||
|
|
||||
|
util.run_cipher(cipher, decipher) |
||||
|
|
||||
|
|
||||
|
def check_env(): |
||||
|
# skip this test on pypy and Python 3 |
||||
|
try: |
||||
|
import __pypy__ |
||||
|
del __pypy__ |
||||
|
from nose.plugins.skip import SkipTest |
||||
|
raise SkipTest |
||||
|
except ImportError: |
||||
|
pass |
||||
|
if bytes != str: |
||||
|
from nose.plugins.skip import SkipTest |
||||
|
raise SkipTest |
||||
|
|
||||
|
|
||||
|
def test_aes_128_cfb(): |
||||
|
check_env() |
||||
|
run_method(b'aes-128-cfb') |
||||
|
|
||||
|
|
||||
|
def test_aes_256_cfb(): |
||||
|
check_env() |
||||
|
run_method(b'aes-256-cfb') |
||||
|
|
||||
|
|
||||
|
def test_bf_cfb(): |
||||
|
check_env() |
||||
|
run_method(b'bf-cfb') |
||||
|
|
||||
|
|
||||
|
def test_rc4(): |
||||
|
check_env() |
||||
|
run_method(b'rc4') |
||||
|
|
||||
|
|
||||
|
if __name__ == '__main__': |
||||
|
test_aes_128_cfb() |
Loading…
Reference in new issue