Code Red > .NET

Cracking a SheetSet file(.dst) to view and edit values inside/oustide AutoCAD

(1/14) > >>

Jeff H:
First big thanks to Jar http://www.theswamp.org/index.php?topic=46397.0

How would you guys like to do this?

Kerry:

I voted tutorial.
We can't demand code and who has time for a challenge of this sort ?

Must admit I wasn't sure why that post was started.

exmachina:
I voted tutorial.


--- Quote from: Kerry on March 07, 2014, 05:49:27 PM ---Must admit I wasn't sure why that post was started.

--- End quote ---
To give a solution? :lmao:

Jeff H:
I do not want to speak too soon but this is getting better than I thought.

Created a file with .apff extension and added bytes for new custom properties and created text with fields that map to them.
So looks like we can exploit it to make an a way to create custom fields of sort.

This would very usefull

Jeff H:
Will have time to post more information later tonight or tomorrow, but a SheetSet file or .dst is just a XML file with a substitution cipher.


Open a .dst with Notepad++ or something that will display non printable characters.

Or really notepad is fine at first to get started deciphering it, if you open a .dst file in notepad you will see

--- Quote ---ÐÍãà¬ëçâӮߢܮ¬ëâéèçâåÓ®ûøÊ£Ô®ÍÒƒ†ÐÏéùãÈïïîïë¬éàçèÓ®åÞßÚÞÉÚÎÚ£ÜÉËØ£ØÜËÔ£×ßÞΣØÚÊÛ×ÈÊÈÊÔÞÚ®¬ÇÈÓ®åÊÕËØÙÞßÊ£ÛÏÏÔ£ØÜÔÜ£×ÈÕÏ£ÚßÊÎÏÉÏÚÛßÏÚ®ÒÐÏéùãü¬âïãëÓ®ÈîÊçâåëüç⮬ӮԮÒåÉÛÛËÞØßÕ£ÊËÊ×£ØÚÏÞ£ÏÙÔØ£Ê×ÎÜÔÛÈÔØØÚÔÐÝÏéùãüÒÐÏéùãü¬âïãëÓ®Èîúëç⮬Ó®Ô®ÒߢßÐÝÏéùãüÒÐÏéùãü¬âïãëÓ®Êçàëþëçç⮬Ó®Ù®ÒÙÐÝÏéùãüÒÐÏéùãùäëëùë¬éàçèÓ®åÎÞÜÛÙØÊÞ£Ü×ÕÔ£ØßÔÉ£ÔÈßØ£ÞËÚ×ÞÔÏÜÕÕËÈ®¬ÇÈÓ®åÏËÙÈÈÎÊÈ£ÙÚÎÊ£ØÙÜÊ£×ÚÎØ£ÔÜÊ×ÞÚÜØÈÊÏ×®¬âïãëÓ®ùäëëù뮬ӮßÙ®ÒÐÏéùãÉïààÎàéá¬éàçèÓ®åÞÜÙËÏÎØÚ£ØÔÙΣØËÚΣÏßÜΣßÛË×ÏØÎÞßÜÊÊ®¬ÇÈÓ®åËÉÈÈËÛÎߣß×ËÏ£ØËßÛ£ÔÏÔÜ£ÕÛÈØÕÊÛÜØÞÚÚ®¬âïãëÓ®ÉïààÎàéᮬӮßÙ®ÝÒÐÏéùãÉãüëÎïå¬éàçèÓ®åØÈßÜÙ×ÜÔ£ÔÉÔÚ£ØÈ×Û£ÎÎÊØ£ÚÔÎ×ÏÕÎÜÜÕÙß®¬ÇÈÓ®åÙÏ×ÛØÛßÕ£ÚËËÊ£ØßØÈ£ÏÜÕÉ£ÞÙÜÜ×ßÕßßÉÛÙ®¬âïãëÓ®ÉãüëÎï宬Ó®ßÙ®ÒÐÏéùãÉãüëúïàë¬éàçèÓ®åÔÈÞÞÏÞÏØ£ßÕÕÕ£ØÈÕÔ£ÔØÉÉ£Ú×ËÊÕØßÊË×ÛØ®¬ÇÈÓ®åÕËËÎËÎØÕ£ØßËÕ£Ø×É×£×ßÔÚ£ÔÈÞÏÜÛÞÎÏÕÉÛ®¬âïãëÓ®ÃïÊçëà讬Ó®ßÙ®ÒÐÏéùãü¬âïãëÓ®Êàï宬ӮٮÒßÐÝÏéùãüÒÐÏéùãü¬âïãëÓ®úïà뮬Ó®Ô®ÒÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÐÝÏéùãüÒÐÝÏéùãÉãüëúïàëÒÐÝÏéùãÉãüëÎïåÒÐÏéùãÏéÈîÀïþëêëëâéë¬éàçèÓ®å×Ø×ßÜË×Ø£ØÊÉÏ£ØÞÕÉ£ÎÚËÈ£ÞËÉ×ËßÉ×ÜÜÉÕ®¬ÇÈÓ®åÔÔÔÉÛÞÏΣÜÉÜÈ£ØÞÕÚ£×ÏÈÔ£ÉÈÈØ×ÉÔßÜØÉÉ®¬âïãëÓ®ÈëêÈÀﮬӮßÙ®ÝÒÐÏéùãÏéÈîÎàéáþëéèþëêëëâéë¬éàçèÓ®åßßÕÔÞÛÞÙ£ØÕØΣØÉÔÙ£×ÚØÚ£ÛÕÉÜÛÞÔØÕÊÎή¬ÇÈÓ®åÔßØÞÎÔÙÞ£ÚÛÞÏ£ØÞÚÙ£ÎÕÛÊ£×ËÚÛÎÔÞØØ×ÙÜ®¬âïãëÓ®ÈëêÀïîëàÎàᮬÓ®ßÙ®ÝÒÐÏéùãü¬âïãëÓ®Èë鮬Ó®Ô®ÒÎïë¬ùäëë¬ùë¬øëãàïëÐÝÏéùãüÒÐÏéùãü¬âïãëÓ®Âïã뮬Ó®Ô®ÒÉïéáÐÝÏéùãüÒÐÏéùãÊçàëþëêëëâéë¬éàçèÓ®åÚÎÊÔÕÏËÕ£ßÎËÉ£ØÎÈΣ×ÔÎΣÛÎ×ßÊÕÕÕÞÕ×Ù®¬ÇÈÓ®åÜßØÎËÔÛÏ£ÚÉÏÚ£ØÊÚÚ£ÔËÎÏ£ßÜßÛÔÏØÞÈÞÚÞ®¬âïãëÓ®ÂëùäëëÀéïç⮬Ó®ßÙ®ÒÐÏéùãü¬âïãëÓ®ËâçâíÊçàëÂïã뮬Ó®Ô®Ò«ûùËþüþýÊÇÀË«ðÈîðøäÏïÐÝÏéùãüÒÐÏéùãü¬âïãëÓ®ÊçàëÂïã뮬Ó®Ô®ÒÉÖðûëðæäâîðÈîðøäÏïÐÝÏéùãüÒÐÏéùãü¬âïãëÓ®þëàïçëíÊçàëÂïã뮬Ó®Ô®Ò¢ÐÝÏéùãüÒÐÏéùãü¬âïãëÓ®ùëéçïàÊàèëíÊçàëÂïã뮬Ó®Ô®Ò¨¤ÉùÇÈÀíüþýÊÇÀ˧ðÈîðøäÏïÐÝÏéùãüÒÐÏéùãü¬âïãëÓ®ûâéíÊçàëÂïã뮬Ó®Ô®ÒððýõÂËþ£üÉðÉðûëðæäâîðÈîðøäÏïÐÝÏéùãüÒÐÝÏéùãÊçàëþëêëëâéëÒÐÏéùãüæëéüçâÀéïçâ¬éàçèÓ®åËØÜËÏÞØÚ£ÎÏÎØ£Ø×ÜÕ£ÔßÏÛ£ÛßßËÏÙÜÉßÚÊÈ®¬ÇÈÓ®åÎÞ×ßØÔÔÉ£×Þ×Ë£ØÔÈΣÔÜØÜ£ËßËßÙÉÎËÔÛÚÈ®¬âïãëÓ®üæëéüçâÀéïç⮬ӮßÙ®ÝÒÐÏéùãüîàçäýçâ¬éàçèÓ®åÊÛÕÊ×ÚËÕ£ÜÊßÚ£ØÈÉ×£ÔÊÜ×£ÛÞÊÕÎÎÙÔ×ÏÎÚ®¬ÇÈÓ®åÞ×ÉØÎÜÚÜ£ÎÚÎÜ£ØÕÔÚ£ÎÜÉÙ£ÚÜÛËÜÛÈÎÜÚÙÛ®¬âïãëÓ®üîàçäýç⮬ӮßÙ®ÒÐÏéùãùçãàëÊçàëþëêëëéë¬éàçèÓ®åÈßÛÏÜÙÉÞ£ÉÙ×ΣØÞÔÏ£×ÎÎÏ£ÉÜÙßÙØÕÉØ×ÚÊ®¬ÇÈÓ®åÜÎÛÙÞßÕÙ£ØÎ×ߣØÚÛΣ×ßÜÕ£ÊÔÚÚßÊØÙØ×ÛÛ®¬âïãëÓ®Èëêïàýè箬ӮßÙ®ÝÒÐÏéùãü¬âïãëÓ®Èêø뮬Ó®Þ®Ò£ßÐÝÏéùãüÒÐÏéùãü¬âïãëÓ®ËàÊãﮬӮٮÒÞÐÝÏéùãüÒÐÏéùãü¬âïãëÓ®ÀïëÇâꮬӮޮңßÐÝÏéùãüÒÐÏéùãü¬âïãëÓ®üãÊÂïã뮬Ó®Þ®Ò£ßÐÝÏéùãüÒÐÝÏéùãüîàçäýçâÒÐÏéùãþëéë¬éàçèÓ®åÙÊÜÊÏÊßÜ£Ü×ÈË£ØËÎÏ£ÏËÈߣÉØËØÈÚÊËÉÊÛÈ®¬ÇÈÓ®åÉÔÕÞßÈËÔ£ËÎÔÚ£ØÎÞ×£ÎÕÞÜ£ÔÏËÙÉ×ÊßÞ×ÕÉ®¬âïãëÓ®þëé뮬ӮßÙ®ÝÒÐÏéùãùäëëùëàùë¬éàçèÓ®åØØØÕÔÜÎÔ£ÚÛÞÕ£ØÙÏÔ£ÔÈÉØ£ÊÏÎØßÎÕËØÔÎή¬ÇÈÓ®åßßÊÛÙÎÙÕ£ÕÛÛË£ØÛÛÔ£ÔÜÊÕ£×ËÔÜÈØØÊÊÉËÙ®¬âïãëÓ®ùäëëùëàù뮬ӮßÙ®ÝÒÐÏéùãúçëÉïëåçë¬éàçèÓ®åÜÞßÕÙÜÈÊ£ÛÎËÏ£ØÔË×£ÎÉÕÏ£ÙÛÜÔÕÏÚÕØÊÈÜ®¬ÇÈÓ®åÜÞÙÈÚÞÔÙ£×ÈÏÙ£ØØÎÛ£ÎÉØߣÕÛØÊÈÊËßÉÏÕÞ®¬âïãëÓ®úçëÉïëåç뮬ӮßÙ®ÝÒÐÝÏéùãùäëëùëÒÐÝÏéùãÈïïîïëÒƒ†

--- End quote ---


So we could run test with percentage s that letters normally appear, and run test that to try to find letters that normally are next to each, etc......

We have a huge advantage though because we can insert known values into file and analyze what changed, so we could add a custom SheetSet property and sets its value to AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA

Which if you look in above quote there is a part that is

--- Quote ---ùãü¬âïãëÓ®úïà뮬Ó®Ô®ÒÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÏÐÝÏéùãüÒÐÝÏéùãÉ

--- End quote ---

Now if I change property value from AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA to BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB then hopefully only repeating values above will change to another repeating value.

With that confirmed we can set value to ABCDEFGHIJKLMNOPQRSTUVWXYZ.........


Sorry for being short but will get more detailed later today or tomorrow


Navigation

[0] Message Index

[#] Next page

Go to full version