Files
mattermost-patched-enterprise/patch.sh
T

124 lines
3.4 KiB
Bash

#!/bin/bash
set -euo pipefail
BINARY_FILE=$1
PATTERN="48 89 C1 48 8B 84 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 85 C0 74 53"
REPLACEMENT="75"
OFFSET=19
# Setup cleanup for temp files
TEMP_FILE=""
cleanup() {
if [ -n "$TEMP_FILE" ] && [ -f "$TEMP_FILE" ]; then
rm -f "$TEMP_FILE"
fi
}
trap cleanup EXIT
# Check for required dependencies
DEPENDENCIES=(hexdump xxd grep awk dd tr mktemp)
MISSING_DEPS=()
for dep in "${DEPENDENCIES[@]}"; do
if ! command -v "$dep" >/dev/null 2>&1; then
MISSING_DEPS+=("$dep")
fi
done
if [ ${#MISSING_DEPS[@]} -gt 0 ]; then
echo "Error: The following required commands are not installed:"
for dep in "${MISSING_DEPS[@]}"; do
echo " - $dep"
done
echo "Please install them and try again."
exit 2
fi
# Check binary file argument exists and is writable
if [ -z "$BINARY_FILE" ]; then
echo "Error: No binary file specified."
echo "Usage: $0 <binary_file>"
exit 3
fi
if [ ! -f "$BINARY_FILE" ]; then
echo "Error: File '$BINARY_FILE' does not exist."
exit 4
fi
if [ ! -w "$BINARY_FILE" ]; then
echo "Error: No write permission for '$BINARY_FILE'."
exit 5
fi
SEARCH_PATTERN=$(echo "$PATTERN" | tr -d ' ' | tr '?' '.' | tr 'A-Z' 'a-z')
PATCHED_PATTERN=$(echo "$PATTERN" | sed 's/74 53/75 53/' | tr -d ' ' | tr '?' '.' | tr 'A-Z' 'a-z')
# Check binary file argument exists and is writable
if [ -z "$BINARY_FILE" ]; then
echo "Error: No binary file specified."
echo "Usage: $0 <binary_file>"
exit 1
fi
if [ ! -f "$BINARY_FILE" ]; then
echo "Error: File '$BINARY_FILE' does not exist."
exit 1
fi
if [ ! -w "$BINARY_FILE" ]; then
echo "Error: No write permission for '$BINARY_FILE'."
exit 1
fi
echo "Dumping hexcode of original binary"
TEMP_FILE=$(mktemp)
hexdump -ve '1/1 "%.2x"' "$BINARY_FILE" > "$TEMP_FILE"
echo "Searching for rsa.VerifyPKCS1v15 call inside LicenseValidatorImpl.ValidateLicense()"
# Check if already patched
PATCHED_COUNT=$(grep -Eo -b "$PATCHED_PATTERN" "$TEMP_FILE" 2>/dev/null | wc -l)
if [ "$PATCHED_COUNT" -gt 0 ]; then
echo "Binary appears to already be patched (jnz instruction found)."
exit 6
fi
MATCH_COUNT=$(grep -Eo -b "$SEARCH_PATTERN" "$TEMP_FILE" | wc -l)
if [ "$MATCH_COUNT" -gt 1 ]; then
echo "Warning: Found $MATCH_COUNT matches for the pattern. Using the first match."
echo "If patching fails or produces unexpected results, please report this at:"
echo " https://github.com/<your-repo>/issues"
fi
FOUND_OFFSET=$(grep -Eo -b "$SEARCH_PATTERN" "$TEMP_FILE" | awk -F: '{print $1}' | head -n 1)
if [ -z "$FOUND_OFFSET" ]; then
echo "Call not found!"
exit 7
fi
BYTE_OFFSET=$((FOUND_OFFSET / 2 + OFFSET))
BYTE_OFFSET_HEX=$(printf "%x" "$BYTE_OFFSET")
if [ "$BYTE_OFFSET" -lt 0 ]; then
echo "Error: Calculated offset is before the start of the file!"
exit 8
fi
echo "Call found, patching jz at offset 0x$BYTE_OFFSET_HEX with jnz"
if ! printf "$REPLACEMENT" | xxd -r -p | dd of="$BINARY_FILE" bs=1 seek="$BYTE_OFFSET" conv=notrunc > /dev/null 2>&1; then
echo "Error: Failed to write patch to '$BINARY_FILE'."
exit 9
fi
# Verify the patch was applied
WRITTEN_BYTE=$(dd if="$BINARY_FILE" bs=1 skip="$BYTE_OFFSET" count=1 2>/dev/null | xxd -p)
if [ "$WRITTEN_BYTE" != "$REPLACEMENT" ]; then
echo "Error: Patch verification failed! Expected '$REPLACEMENT' but found '$WRITTEN_BYTE' at offset 0x$BYTE_OFFSET_HEX."
exit 10
fi
echo "Licensing code patched!"