mirror of https://github.com/cbeuw/Cloak
I just did a joint and I need to commit before things go wrong
This commit is contained in:
parent
00069b7a69
commit
589900fe52
|
|
@ -187,7 +187,7 @@ start:
|
||||||
case 0x00:
|
case 0x00:
|
||||||
crypto = &mux.Plain{}
|
crypto = &mux.Plain{}
|
||||||
case 0x01:
|
case 0x01:
|
||||||
crypto, err = mux.MakeAESCipher(sta.UID)
|
crypto, err = mux.MakeAESGCMCipher(sta.UID)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Println(err)
|
log.Println(err)
|
||||||
return
|
return
|
||||||
|
|
|
||||||
|
|
@ -154,7 +154,7 @@ func dispatchConnection(conn net.Conn, sta *server.State) {
|
||||||
case 0x00:
|
case 0x00:
|
||||||
crypto = &mux.Plain{}
|
crypto = &mux.Plain{}
|
||||||
case 0x01:
|
case 0x01:
|
||||||
crypto, err = mux.MakeAESCipher(UID)
|
crypto, err = mux.MakeAESGCMCipher(UID)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Println(err)
|
log.Println(err)
|
||||||
goWeb(data)
|
goWeb(data)
|
||||||
|
|
|
||||||
|
|
@ -110,7 +110,7 @@ func (sta *State) ParseConfig(conf string) (err error) {
|
||||||
switch preParse.EncryptionMethod {
|
switch preParse.EncryptionMethod {
|
||||||
case "plain":
|
case "plain":
|
||||||
sta.EncryptionMethod = 0x00
|
sta.EncryptionMethod = 0x00
|
||||||
case "aes":
|
case "aes-gcm":
|
||||||
sta.EncryptionMethod = 0x01
|
sta.EncryptionMethod = 0x01
|
||||||
case "chacha20-poly1305":
|
case "chacha20-poly1305":
|
||||||
sta.EncryptionMethod = 0x02
|
sta.EncryptionMethod = 0x02
|
||||||
|
|
|
||||||
|
|
@ -21,41 +21,37 @@ func (p *Plain) encrypt(plaintext []byte, nonce []byte) ([]byte, error) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func (p *Plain) decrypt(buf []byte, nonce []byte) ([]byte, error) {
|
func (p *Plain) decrypt(buf []byte, nonce []byte) ([]byte, error) {
|
||||||
return buf, nil
|
return buf[:len(buf)-16], nil
|
||||||
}
|
}
|
||||||
|
|
||||||
type AES struct {
|
type AESGCM struct {
|
||||||
cipher cipher.Block
|
cipher cipher.AEAD
|
||||||
}
|
}
|
||||||
|
|
||||||
func MakeAESCipher(key []byte) (*AES, error) {
|
func MakeAESGCMCipher(key []byte) (*AESGCM, error) {
|
||||||
c, err := aes.NewCipher(key)
|
c, err := aes.NewCipher(key)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
ret := AES{
|
g, err := cipher.NewGCM(c)
|
||||||
c,
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
ret := AESGCM{
|
||||||
|
g,
|
||||||
}
|
}
|
||||||
return &ret, nil
|
return &ret, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (a *AES) encrypt(plaintext []byte, nonce []byte) ([]byte, error) {
|
func (a *AESGCM) encrypt(plaintext []byte, nonce []byte) ([]byte, error) {
|
||||||
aesgcm, err := cipher.NewGCM(a.cipher)
|
ciphertext := a.cipher.Seal(nil, nonce, plaintext, nil)
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
ciphertext := aesgcm.Seal(nil, nonce, plaintext, nil)
|
|
||||||
ret := make([]byte, len(plaintext)+16)
|
ret := make([]byte, len(plaintext)+16)
|
||||||
copy(ret, ciphertext)
|
copy(ret, ciphertext)
|
||||||
return ret, nil
|
return ret, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (a *AES) decrypt(ciphertext []byte, nonce []byte) ([]byte, error) {
|
func (a *AESGCM) decrypt(ciphertext []byte, nonce []byte) ([]byte, error) {
|
||||||
aesgcm, err := cipher.NewGCM(a.cipher)
|
plain, err := a.cipher.Open(nil, nonce, ciphertext, nil)
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
plain, err := aesgcm.Open(nil, nonce, ciphertext, nil)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -84,11 +84,14 @@ func MakeDeobfs(key []byte, algo Crypto) Deobfser {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
|
outputPayload := make([]byte, len(decryptedPayload))
|
||||||
|
copy(outputPayload, decryptedPayload)
|
||||||
|
|
||||||
ret := &Frame{
|
ret := &Frame{
|
||||||
StreamID: streamID,
|
StreamID: streamID,
|
||||||
Seq: seq,
|
Seq: seq,
|
||||||
Closing: closing,
|
Closing: closing,
|
||||||
Payload: decryptedPayload,
|
Payload: outputPayload,
|
||||||
}
|
}
|
||||||
return ret, nil
|
return ret, nil
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue