breakwa11
10 years ago
7 changed files with 516 additions and 22 deletions
@ -0,0 +1,135 @@ |
|||
#!/usr/bin/env python |
|||
|
|||
# Copyright (c) 2014 clowwindy |
|||
# |
|||
# Permission is hereby granted, free of charge, to any person obtaining a copy |
|||
# of this software and associated documentation files (the "Software"), to deal |
|||
# in the Software without restriction, including without limitation the rights |
|||
# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
|||
# copies of the Software, and to permit persons to whom the Software is |
|||
# furnished to do so, subject to the following conditions: |
|||
# |
|||
# The above copyright notice and this permission notice shall be included in |
|||
# all copies or substantial portions of the Software. |
|||
# |
|||
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
|||
# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
|||
# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
|||
# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
|||
# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
|||
# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE |
|||
# SOFTWARE. |
|||
|
|||
from __future__ import absolute_import, division, print_function, \ |
|||
with_statement |
|||
|
|||
import logging |
|||
from ctypes import CDLL, c_char_p, c_int, c_ulonglong, byref, \ |
|||
create_string_buffer, c_void_p |
|||
|
|||
__all__ = ['ciphers'] |
|||
|
|||
libsodium = None |
|||
loaded = False |
|||
|
|||
buf_size = 2048 |
|||
|
|||
# for salsa20 and chacha20 |
|||
BLOCK_SIZE = 64 |
|||
|
|||
|
|||
def load_libsodium(): |
|||
global loaded, libsodium, buf |
|||
|
|||
from ctypes.util import find_library |
|||
for p in ('sodium',): |
|||
libsodium_path = find_library(p) |
|||
if libsodium_path: |
|||
break |
|||
else: |
|||
raise Exception('libsodium not found') |
|||
logging.info('loading libsodium from %s', libsodium_path) |
|||
libsodium = CDLL(libsodium_path) |
|||
libsodium.sodium_init.restype = c_int |
|||
libsodium.crypto_stream_salsa20_xor_ic.restype = c_int |
|||
libsodium.crypto_stream_salsa20_xor_ic.argtypes = (c_void_p, c_char_p, |
|||
c_ulonglong, |
|||
c_char_p, c_ulonglong, |
|||
c_char_p) |
|||
libsodium.crypto_stream_chacha20_xor_ic.restype = c_int |
|||
libsodium.crypto_stream_chacha20_xor_ic.argtypes = (c_void_p, c_char_p, |
|||
c_ulonglong, |
|||
c_char_p, c_ulonglong, |
|||
c_char_p) |
|||
|
|||
libsodium.sodium_init() |
|||
|
|||
buf = create_string_buffer(buf_size) |
|||
loaded = True |
|||
|
|||
|
|||
class Salsa20Crypto(object): |
|||
def __init__(self, cipher_name, key, iv, op): |
|||
if not loaded: |
|||
load_libsodium() |
|||
self.key = key |
|||
self.iv = iv |
|||
self.key_ptr = c_char_p(key) |
|||
self.iv_ptr = c_char_p(iv) |
|||
if cipher_name == b'salsa20': |
|||
self.cipher = libsodium.crypto_stream_salsa20_xor_ic |
|||
elif cipher_name == b'chacha20': |
|||
self.cipher = libsodium.crypto_stream_chacha20_xor_ic |
|||
else: |
|||
raise Exception('Unknown cipher') |
|||
# byte counter, not block counter |
|||
self.counter = 0 |
|||
|
|||
def update(self, data): |
|||
global buf_size, buf |
|||
l = len(data) |
|||
|
|||
# we can only prepend some padding to make the encryption align to |
|||
# blocks |
|||
padding = self.counter % BLOCK_SIZE |
|||
if buf_size < padding + l: |
|||
buf_size = (padding + l) * 2 |
|||
buf = create_string_buffer(buf_size) |
|||
|
|||
if padding: |
|||
data = (b'\0' * padding) + data |
|||
self.cipher(byref(buf), c_char_p(data), padding + l, |
|||
self.iv_ptr, int(self.counter / BLOCK_SIZE), self.key_ptr) |
|||
self.counter += l |
|||
# buf is copied to a str object when we access buf.raw |
|||
# strip off the padding |
|||
return buf.raw[padding:padding + l] |
|||
|
|||
|
|||
ciphers = { |
|||
b'salsa20': (32, 8, Salsa20Crypto), |
|||
b'chacha20': (32, 8, Salsa20Crypto), |
|||
} |
|||
|
|||
|
|||
def test_salsa20(): |
|||
from shadowsocks.crypto import util |
|||
|
|||
cipher = Salsa20Crypto(b'salsa20', b'k' * 32, b'i' * 16, 1) |
|||
decipher = Salsa20Crypto(b'salsa20', b'k' * 32, b'i' * 16, 0) |
|||
|
|||
util.run_cipher(cipher, decipher) |
|||
|
|||
|
|||
def test_chacha20(): |
|||
from shadowsocks.crypto import util |
|||
|
|||
cipher = Salsa20Crypto(b'chacha20', b'k' * 32, b'i' * 16, 1) |
|||
decipher = Salsa20Crypto(b'chacha20', b'k' * 32, b'i' * 16, 0) |
|||
|
|||
util.run_cipher(cipher, decipher) |
|||
|
|||
|
|||
if __name__ == '__main__': |
|||
test_chacha20() |
|||
test_salsa20() |
@ -0,0 +1,188 @@ |
|||
#!/usr/bin/env python |
|||
|
|||
# Copyright (c) 2014 clowwindy |
|||
# |
|||
# Permission is hereby granted, free of charge, to any person obtaining a copy |
|||
# of this software and associated documentation files (the "Software"), to deal |
|||
# in the Software without restriction, including without limitation the rights |
|||
# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
|||
# copies of the Software, and to permit persons to whom the Software is |
|||
# furnished to do so, subject to the following conditions: |
|||
# |
|||
# The above copyright notice and this permission notice shall be included in |
|||
# all copies or substantial portions of the Software. |
|||
# |
|||
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
|||
# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
|||
# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
|||
# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
|||
# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
|||
# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE |
|||
# SOFTWARE. |
|||
|
|||
from __future__ import absolute_import, division, print_function, \ |
|||
with_statement |
|||
|
|||
import logging |
|||
from ctypes import CDLL, c_char_p, c_int, c_long, byref,\ |
|||
create_string_buffer, c_void_p |
|||
|
|||
__all__ = ['ciphers'] |
|||
|
|||
libcrypto = None |
|||
loaded = False |
|||
|
|||
buf_size = 2048 |
|||
|
|||
|
|||
def load_openssl(): |
|||
global loaded, libcrypto, buf |
|||
|
|||
from ctypes.util import find_library |
|||
for p in ('crypto', 'eay32', 'libeay32'): |
|||
libcrypto_path = find_library(p) |
|||
if libcrypto_path: |
|||
break |
|||
else: |
|||
raise Exception('libcrypto(OpenSSL) not found') |
|||
logging.info('loading libcrypto from %s', libcrypto_path) |
|||
libcrypto = CDLL(libcrypto_path) |
|||
libcrypto.EVP_get_cipherbyname.restype = c_void_p |
|||
libcrypto.EVP_CIPHER_CTX_new.restype = c_void_p |
|||
|
|||
libcrypto.EVP_CipherInit_ex.argtypes = (c_void_p, c_void_p, c_char_p, |
|||
c_char_p, c_char_p, c_int) |
|||
|
|||
libcrypto.EVP_CipherUpdate.argtypes = (c_void_p, c_void_p, c_void_p, |
|||
c_char_p, c_int) |
|||
|
|||
libcrypto.EVP_CIPHER_CTX_cleanup.argtypes = (c_void_p,) |
|||
libcrypto.EVP_CIPHER_CTX_free.argtypes = (c_void_p,) |
|||
if hasattr(libcrypto, 'OpenSSL_add_all_ciphers'): |
|||
libcrypto.OpenSSL_add_all_ciphers() |
|||
|
|||
buf = create_string_buffer(buf_size) |
|||
loaded = True |
|||
|
|||
|
|||
def load_cipher(cipher_name): |
|||
func_name = b'EVP_' + cipher_name.replace(b'-', b'_') |
|||
if bytes != str: |
|||
func_name = str(func_name, 'utf-8') |
|||
cipher = getattr(libcrypto, func_name, None) |
|||
if cipher: |
|||
cipher.restype = c_void_p |
|||
return cipher() |
|||
return None |
|||
|
|||
|
|||
class CtypesCrypto(object): |
|||
def __init__(self, cipher_name, key, iv, op): |
|||
if not loaded: |
|||
load_openssl() |
|||
self._ctx = None |
|||
cipher = libcrypto.EVP_get_cipherbyname(cipher_name) |
|||
if not cipher: |
|||
cipher = load_cipher(cipher_name) |
|||
if not cipher: |
|||
raise Exception('cipher %s not found in libcrypto' % cipher_name) |
|||
key_ptr = c_char_p(key) |
|||
iv_ptr = c_char_p(iv) |
|||
self._ctx = libcrypto.EVP_CIPHER_CTX_new() |
|||
if not self._ctx: |
|||
raise Exception('can not create cipher context') |
|||
r = libcrypto.EVP_CipherInit_ex(self._ctx, cipher, None, |
|||
key_ptr, iv_ptr, c_int(op)) |
|||
if not r: |
|||
self.clean() |
|||
raise Exception('can not initialize cipher context') |
|||
|
|||
def update(self, data): |
|||
global buf_size, buf |
|||
cipher_out_len = c_long(0) |
|||
l = len(data) |
|||
if buf_size < l: |
|||
buf_size = l * 2 |
|||
buf = create_string_buffer(buf_size) |
|||
libcrypto.EVP_CipherUpdate(self._ctx, byref(buf), |
|||
byref(cipher_out_len), c_char_p(data), l) |
|||
# buf is copied to a str object when we access buf.raw |
|||
return buf.raw[:cipher_out_len.value] |
|||
|
|||
def __del__(self): |
|||
self.clean() |
|||
|
|||
def clean(self): |
|||
if self._ctx: |
|||
libcrypto.EVP_CIPHER_CTX_cleanup(self._ctx) |
|||
libcrypto.EVP_CIPHER_CTX_free(self._ctx) |
|||
|
|||
|
|||
ciphers = { |
|||
b'aes-128-cfb': (16, 16, CtypesCrypto), |
|||
b'aes-192-cfb': (24, 16, CtypesCrypto), |
|||
b'aes-256-cfb': (32, 16, CtypesCrypto), |
|||
b'aes-128-ofb': (16, 16, CtypesCrypto), |
|||
b'aes-192-ofb': (24, 16, CtypesCrypto), |
|||
b'aes-256-ofb': (32, 16, CtypesCrypto), |
|||
b'aes-128-ctr': (16, 16, CtypesCrypto), |
|||
b'aes-192-ctr': (24, 16, CtypesCrypto), |
|||
b'aes-256-ctr': (32, 16, CtypesCrypto), |
|||
b'aes-128-cfb8': (16, 16, CtypesCrypto), |
|||
b'aes-192-cfb8': (24, 16, CtypesCrypto), |
|||
b'aes-256-cfb8': (32, 16, CtypesCrypto), |
|||
b'aes-128-cfb1': (16, 16, CtypesCrypto), |
|||
b'aes-192-cfb1': (24, 16, CtypesCrypto), |
|||
b'aes-256-cfb1': (32, 16, CtypesCrypto), |
|||
b'bf-cfb': (16, 8, CtypesCrypto), |
|||
b'camellia-128-cfb': (16, 16, CtypesCrypto), |
|||
b'camellia-192-cfb': (24, 16, CtypesCrypto), |
|||
b'camellia-256-cfb': (32, 16, CtypesCrypto), |
|||
b'cast5-cfb': (16, 8, CtypesCrypto), |
|||
b'des-cfb': (8, 8, CtypesCrypto), |
|||
b'idea-cfb': (16, 8, CtypesCrypto), |
|||
b'rc2-cfb': (16, 8, CtypesCrypto), |
|||
b'rc4': (16, 0, CtypesCrypto), |
|||
b'seed-cfb': (16, 16, CtypesCrypto), |
|||
} |
|||
|
|||
|
|||
def run_method(method): |
|||
from shadowsocks.crypto import util |
|||
|
|||
cipher = CtypesCrypto(method, b'k' * 32, b'i' * 16, 1) |
|||
decipher = CtypesCrypto(method, b'k' * 32, b'i' * 16, 0) |
|||
|
|||
util.run_cipher(cipher, decipher) |
|||
|
|||
|
|||
def test_aes_128_cfb(): |
|||
run_method(b'aes-128-cfb') |
|||
|
|||
|
|||
def test_aes_256_cfb(): |
|||
run_method(b'aes-256-cfb') |
|||
|
|||
|
|||
def test_aes_128_cfb8(): |
|||
run_method(b'aes-128-cfb8') |
|||
|
|||
|
|||
def test_aes_256_ofb(): |
|||
run_method(b'aes-256-ofb') |
|||
|
|||
|
|||
def test_aes_256_ctr(): |
|||
run_method(b'aes-256-ctr') |
|||
|
|||
|
|||
def test_bf_cfb(): |
|||
run_method(b'bf-cfb') |
|||
|
|||
|
|||
def test_rc4(): |
|||
run_method(b'rc4') |
|||
|
|||
|
|||
if __name__ == '__main__': |
|||
test_aes_128_cfb() |
@ -0,0 +1,117 @@ |
|||
#!/usr/bin/env python |
|||
|
|||
# Copyright (c) 2014 clowwindy |
|||
# |
|||
# Permission is hereby granted, free of charge, to any person obtaining a copy |
|||
# of this software and associated documentation files (the "Software"), to deal |
|||
# in the Software without restriction, including without limitation the rights |
|||
# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
|||
# copies of the Software, and to permit persons to whom the Software is |
|||
# furnished to do so, subject to the following conditions: |
|||
# |
|||
# The above copyright notice and this permission notice shall be included in |
|||
# all copies or substantial portions of the Software. |
|||
# |
|||
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
|||
# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
|||
# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
|||
# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
|||
# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
|||
# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE |
|||
# SOFTWARE. |
|||
|
|||
from __future__ import absolute_import, division, print_function, \ |
|||
with_statement |
|||
|
|||
import sys |
|||
import logging |
|||
|
|||
__all__ = ['ciphers'] |
|||
|
|||
has_m2 = True |
|||
try: |
|||
__import__('M2Crypto') |
|||
except ImportError: |
|||
has_m2 = False |
|||
|
|||
|
|||
def create_cipher(alg, key, iv, op, key_as_bytes=0, d=None, salt=None, i=1, |
|||
padding=1): |
|||
|
|||
import M2Crypto.EVP |
|||
return M2Crypto.EVP.Cipher(alg.replace('-', '_'), key, iv, op, |
|||
key_as_bytes=0, d='md5', salt=None, i=1, |
|||
padding=1) |
|||
|
|||
|
|||
def err(alg, key, iv, op, key_as_bytes=0, d=None, salt=None, i=1, padding=1): |
|||
logging.error(('M2Crypto is required to use %s, please run' |
|||
' `apt-get install python-m2crypto`') % alg) |
|||
sys.exit(1) |
|||
|
|||
|
|||
if has_m2: |
|||
ciphers = { |
|||
b'aes-128-cfb': (16, 16, create_cipher), |
|||
b'aes-192-cfb': (24, 16, create_cipher), |
|||
b'aes-256-cfb': (32, 16, create_cipher), |
|||
b'bf-cfb': (16, 8, create_cipher), |
|||
b'camellia-128-cfb': (16, 16, create_cipher), |
|||
b'camellia-192-cfb': (24, 16, create_cipher), |
|||
b'camellia-256-cfb': (32, 16, create_cipher), |
|||
b'cast5-cfb': (16, 8, create_cipher), |
|||
b'des-cfb': (8, 8, create_cipher), |
|||
b'idea-cfb': (16, 8, create_cipher), |
|||
b'rc2-cfb': (16, 8, create_cipher), |
|||
b'rc4': (16, 0, create_cipher), |
|||
b'seed-cfb': (16, 16, create_cipher), |
|||
} |
|||
else: |
|||
ciphers = {} |
|||
|
|||
|
|||
def run_method(method): |
|||
from shadowsocks.crypto import util |
|||
|
|||
cipher = create_cipher(method, b'k' * 32, b'i' * 16, 1) |
|||
decipher = create_cipher(method, b'k' * 32, b'i' * 16, 0) |
|||
|
|||
util.run_cipher(cipher, decipher) |
|||
|
|||
|
|||
def check_env(): |
|||
# skip this test on pypy and Python 3 |
|||
try: |
|||
import __pypy__ |
|||
del __pypy__ |
|||
from nose.plugins.skip import SkipTest |
|||
raise SkipTest |
|||
except ImportError: |
|||
pass |
|||
if bytes != str: |
|||
from nose.plugins.skip import SkipTest |
|||
raise SkipTest |
|||
|
|||
|
|||
def test_aes_128_cfb(): |
|||
check_env() |
|||
run_method(b'aes-128-cfb') |
|||
|
|||
|
|||
def test_aes_256_cfb(): |
|||
check_env() |
|||
run_method(b'aes-256-cfb') |
|||
|
|||
|
|||
def test_bf_cfb(): |
|||
check_env() |
|||
run_method(b'bf-cfb') |
|||
|
|||
|
|||
def test_rc4(): |
|||
check_env() |
|||
run_method(b'rc4') |
|||
|
|||
|
|||
if __name__ == '__main__': |
|||
test_aes_128_cfb() |
Loading…
Reference in new issue