diff --git a/docs/HUYA_HDID_ALGORITHM_GEN.md b/docs/HUYA_HDID_ALGORITHM_GEN.md index 9fccec7..aa6e713 100644 --- a/docs/HUYA_HDID_ALGORITHM_GEN.md +++ b/docs/HUYA_HDID_ALGORITHM_GEN.md @@ -875,3 +875,8 @@ hypasswordLogin/MsgLoginReq/LogLoginReq → mid 各异, tail 恒定 8b38f1 → a ## §11.39 R12: s5 零串长度族 (0-40) × S3精选 × in × cnt = 23616 combos / 5s / 零命中 - 累计差分 53K+ combos 零命中; s3/s4 真源 = native BusinessCfg (Java 无类), 需 loadLoginData/配置注入路线 + +## §11.40 R12b: nonce 影响 mid (推翻"豁免"结论) +- direct(nonce=0)=f0012daf / nonce=1=34bd49f5 / nonce=real(0x1a049abb20b0000)=561269ff +- nonce=real 仍 ≠ getOtp 内部 7c0e461e → 剩余差异 = s5 槽 junk 字节 / OTP 内部状态 +- 差分空间扩展: mid = f(in, cnt, s3, s4, s5, nonce) diff --git a/tools/unidbg/hydev/src/hydev/AesProbe.java b/tools/unidbg/hydev/src/hydev/AesProbe.java index d90ccc6..fee1438 100644 --- a/tools/unidbg/hydev/src/hydev/AesProbe.java +++ b/tools/unidbg/hydev/src/hydev/AesProbe.java @@ -209,6 +209,17 @@ public class AesProbe { System.out.println("[burst2] n=" + n + " hits=" + hit + " in " + dt + "ms"); } + String reproOtp(String in, long cnt, String s3, String s4, String s5, long nonce) { + UnidbgPointer pa = writeStdString(in), ps3 = writeStdString(s3), ps4 = writeStdString(s4), ps5 = writeStdString(s5), pout = writeStdString(""); + try { + module.callFunction(emulator, 0x32fa24L, + UnidbgPointer.nativeValue(pa), 2L, cnt, + UnidbgPointer.nativeValue(ps3), UnidbgPointer.nativeValue(ps4), UnidbgPointer.nativeValue(ps5), + 4L, nonce, UnidbgPointer.nativeValue(pout)); + return toHex(readStdString(pout)); + } catch (Throwable tx) { return "err:" + tx; } + } + void burstOtp() { String[] S3 = {"", "hy_300023887", "300023887", "772ed992b0e161276f44ec63671e60155c506294", "1e8bdf7d4f7a01d3", "13.4.22", "1.0.80138", "5008", "xiaomi", "127.0.0.1", "7c5387e0539c023c31c4ff0e807e7256117385ee"}; @@ -701,6 +712,11 @@ public class AesProbe { p.callOtpReal("0", 1L, "hy_300023887", "772ed992b0e161276f44ec63671e60155c506294", "00000000000000000000000000000000", 0L); p.callOtpReal("1724464550000", 0L, "", "", "", 0L); p.burstOtp2(); + // 一致性验证: getOtp 内部 mid=7c0e461e 应可直调复现 + String g = p.reproOtp("0", 1L, "hy_300023887", "hy_300023887", "", 0x1a049abb20b0000L); + System.out.println("[verify] direct(nonce=real) mid=" + (g.length() >= 36 ? g.substring(4, 36) : g) + " expect 7c0e461e8c52e9360e90b5af264af667"); + String g2 = p.reproOtp("0", 1L, "hy_300023887", "hy_300023887", "", 1L); + System.out.println("[verify] direct(nonce=1) mid=" + (g2.length() >= 36 ? g2.substring(4, 36) : g2)); // 基准: 已知 16B 明文 + 24B 钥 // 64B 钥材料测试 (KeyExpansion 以 16B 步长读!!) String k64_zmhav = "ZMHAVPRaxJ3MtXDjduUnXAKQ" + "\0".repeat(0);