Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix reading eow informations and incorrect crc checks #247

Merged
merged 1 commit into from
Apr 18, 2021

Conversation

jc-lab
Copy link
Contributor

@jc-lab jc-lab commented Apr 12, 2021

  • Incorrect rest_size calculation
  • When calculating CRC, the stored CRC part should be excluded.

@Aorimn
Copy link
Owner

Aorimn commented Apr 16, 2021

Thanks for contributing!
I've no EoW volume at hand, I'll trust you have one and that your fix works for it?

@jc-lab
Copy link
Contributor Author

jc-lab commented Apr 16, 2021

This is the data on my HDD.

46 56 45 2D 45 4F 57 00 38 00 88 00 00 02 00 00 00 02 00 00 00 00 80 00 00 0C 08 00 00 04 04 00 0A 00 00 00 2B 43 BC 27 00 20 EC 03 00 00 00 00 00 C0 93 66 00 00 00 00 00 30 EC 03 00 00 00 00 00 60 1B 17 00 00 00 00 00 50 D0 2A 00 00 00 00 00 40 59 3F 00 00 00 00 00 F0 B4 50 00 00 00 00 00 E0 85 66 00 00 00 00 00 70 00 7A 00 00 00 00 00 30 32 97 00 00 00 00 00 80 D7 AA 00 00 00 00 00 40 74 D0 00 00 00 00
00000000  46 56 45 2d 45 4f 57 00  38 00 88 00 00 02 00 00  |FVE-EOW.8.......|
00000010  00 02 00 00 00 00 80 00  00 0c 08 00 00 04 04 00  |................|
00000020  0a 00 00 00 2b 43 bc 27  00 20 ec 03 00 00 00 00  |....+C.'. ......|
00000030  00 c0 93 66 00 00 00 00  00 30 ec 03 00 00 00 00  |...f.....0......|
00000040  00 60 1b 17 00 00 00 00  00 50 d0 2a 00 00 00 00  |.`.......P.*....|
00000050  00 40 59 3f 00 00 00 00  00 f0 b4 50 00 00 00 00  |.@Y?.......P....|
00000060  00 e0 85 66 00 00 00 00  00 70 00 7a 00 00 00 00  |...f.....p.z....|
00000070  00 30 32 97 00 00 00 00  00 80 d7 aa 00 00 00 00  |.02.............|
00000080  00 40 74 d0 00 00 00 00                           |.@t.....|
00000088

CRC Check:
https://gist.github.com/jc-lab/ab8e6fe555702486b97ca6e2401d0ded

$ dislocker-metadata -v -V /dev/sdb :

Fri Apr 16 23:19:34 2021 [DEBUG] Verbosity level to DEBUG (4) into 'stdout'
Fri Apr 16 23:19:34 2021 [INFO] dislocker by Romain Coltel, v0.7.2 (compiled for Linux/x86_64)
Fri Apr 16 23:19:34 2021 [INFO] Compiled version: :
Fri Apr 16 23:19:34 2021 [DEBUG] Trying to open '/dev/sdb2'...
Fri Apr 16 23:19:34 2021 [DEBUG] Trying to open '/dev/sdb2'...
Fri Apr 16 23:19:34 2021 [DEBUG] Opened (fd #3).
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37e8d0 (0x20 bytes allocated)
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37e900 (0x90 bytes allocated)
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37e9a0 (0x200 bytes allocated)
Fri Apr 16 23:19:34 2021 [DEBUG] Positioning #3 at offset 0 from 0
Fri Apr 16 23:19:34 2021 [DEBUG] Reading volume header...
Fri Apr 16 23:19:34 2021 [DEBUG] Reading 0x200 bytes from #3 into 0x55f0ad37e9a0
Fri Apr 16 23:19:34 2021 [DEBUG] Volume header read
Fri Apr 16 23:19:34 2021 [DEBUG] =====[ Volume header informations ]=====
Fri Apr 16 23:19:34 2021 [DEBUG]   Signature: '-FVE-FS-'
Fri Apr 16 23:19:34 2021 [DEBUG]   Sector size: 0x0200 (512) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Sector per cluster: 0x08 (8) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Reserved clusters: 0x0000 (0) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Fat count: 0x00 (0) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Root entries: 0x0000 (0) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Number of sectors (16 bits): 0x0000 (0) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Media descriptor: 0xf8 (248) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Sectors per fat: 0x0000 (0) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Hidden sectors: 0x00113000 (1126400) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Number of sectors (32 bits): 0x00000000 (0) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Number of sectors (64 bits): 0x0000000000000000 (0) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   MFT start cluster: 0x0000000000060001 (393217) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Metadata Lcn: 0x0000000000000000 (0) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]   Volume GUID: '92A84D3B-DD80-4D0E-9E4E-B1E3284EAED8'
Fri Apr 16 23:19:34 2021 [DEBUG]   First metadata header offset:  0x0000000003ea0000
Fri Apr 16 23:19:34 2021 [DEBUG]   Second metadata header offset: 0x000000004468e000
Fri Apr 16 23:19:34 2021 [DEBUG]   Third metadata header offset:  0x00000000aada7000
Fri Apr 16 23:19:34 2021 [DEBUG]   Boot Partition Identifier: '0xaa55'
Fri Apr 16 23:19:34 2021 [DEBUG] ========================================
Fri Apr 16 23:19:34 2021 [INFO] Volume has EOW_INFORMATION_OFFSET_GUID.
Fri Apr 16 23:19:34 2021 [DEBUG] Positioning #3 at offset 65806336 from 0
Fri Apr 16 23:19:34 2021 [DEBUG] Reading EOW Information header at 0x3ec2000...
Fri Apr 16 23:19:34 2021 [DEBUG] Reading 0x38 bytes from #3 into 0x7ffc7ddbffd0
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37ebb0 (0x88 bytes allocated)
Fri Apr 16 23:19:34 2021 [DEBUG] Reading EOW information's payload...
Fri Apr 16 23:19:34 2021 [DEBUG] Reading 0x50 bytes from #3 into 0x55f0ad37ebe8
Fri Apr 16 23:19:34 2021 [DEBUG] End get_eow_information.
Fri Apr 16 23:19:34 2021 [DEBUG] =======================[ BitLocker EOW informations ]========================
Fri Apr 16 23:19:34 2021 [DEBUG]   Signature: 'FVE-EOW'
Fri Apr 16 23:19:34 2021 [DEBUG]   Structure size: 0x0038 (56)
Fri Apr 16 23:19:34 2021 [DEBUG]   On-disk size: 0x0088 (136)
Fri Apr 16 23:19:34 2021 [DEBUG]   Sector size (1): 0x0200 (512)
Fri Apr 16 23:19:34 2021 [DEBUG]   Sector size (2): 0x0200 (512)
Fri Apr 16 23:19:34 2021 [DEBUG]   Unknown (0x14): 0x00800000 (8388608)
Fri Apr 16 23:19:34 2021 [DEBUG]   Convlog size: 0x00080c00 (527360)
Fri Apr 16 23:19:34 2021 [DEBUG]   Unknown (0x1c): 0x00040400 (263168)
Fri Apr 16 23:19:34 2021 [DEBUG]   Number of regions: 10
Fri Apr 16 23:19:34 2021 [DEBUG]   Crc32: 27bc432b
Fri Apr 16 23:19:34 2021 [DEBUG]   On-disk offsets [0]: 0x3ec2000
Fri Apr 16 23:19:34 2021 [DEBUG]   On-disk offsets [1]: 0x6693c000
Fri Apr 16 23:19:34 2021 [DEBUG] =============================================================================
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37ebb0
Fri Apr 16 23:19:34 2021 [DEBUG] Entering get_eow_check_valid
Fri Apr 16 23:19:34 2021 [DEBUG] Positioning #3 at offset 65806336 from 0
Fri Apr 16 23:19:34 2021 [DEBUG] Reading EOW Information header at 0x3ec2000...
Fri Apr 16 23:19:34 2021 [DEBUG] Reading 0x38 bytes from #3 into 0x7ffc7ddbffd0
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37ebb0 (0x88 bytes allocated)
Fri Apr 16 23:19:34 2021 [DEBUG] Reading EOW information's payload...
Fri Apr 16 23:19:34 2021 [DEBUG] Reading 0x50 bytes from #3 into 0x55f0ad37ebe8
Fri Apr 16 23:19:34 2021 [DEBUG] End get_eow_information.
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37ec40 (0x88 bytes allocated)
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37ec40
Fri Apr 16 23:19:34 2021 [DEBUG] Looking if 0x27bc432b == 0x27bc432b for EOW information validation
Fri Apr 16 23:19:34 2021 [DEBUG] We have a winner (n°1)!
Fri Apr 16 23:19:34 2021 [INFO] EOW information at offset 3ec2000 passed the tests
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37ebb0
Fri Apr 16 23:19:34 2021 [DEBUG] Entering get_metadata_lazy_checked
Fri Apr 16 23:19:34 2021 [DEBUG] Positioning #3 at offset 65667072 from 0
Fri Apr 16 23:19:34 2021 [DEBUG] Reading bitlocker header at 0x3ea0000...
Fri Apr 16 23:19:34 2021 [DEBUG] Reading 0x70 bytes from #3 into 0x7ffc7ddbff90
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37ecd0 (0x260 bytes allocated)
Fri Apr 16 23:19:34 2021 [DEBUG] Reading data...
Fri Apr 16 23:19:34 2021 [DEBUG] Reading 0x1f0 bytes from #3 into 0x55f0ad37ed40
Fri Apr 16 23:19:34 2021 [DEBUG] End get_metadata.
Fri Apr 16 23:19:34 2021 [DEBUG] Reading validations data at offset 0x3ea0260.
Fri Apr 16 23:19:34 2021 [DEBUG] Positioning #3 at offset 65667680 from 0
Fri Apr 16 23:19:34 2021 [DEBUG] Reading 0x8 bytes from #3 into 0x7ffc7ddc0068
Fri Apr 16 23:19:34 2021 [DEBUG] Looking if 0xbfcf9ef4 == 0xbfcf9ef4 for metadata validation
Fri Apr 16 23:19:34 2021 [DEBUG] We have a winner (n°1)!
Fri Apr 16 23:19:34 2021 [INFO] BitLocker metadata found and parsed.
Fri Apr 16 23:19:34 2021 [DEBUG] =====================[ BitLocker information structure ]=====================
Fri Apr 16 23:19:34 2021 [DEBUG]   Signature: '-FVE-FS-'
Fri Apr 16 23:19:34 2021 [DEBUG]   Total Size: 0x0260 (608) bytes (including signature and data)
Fri Apr 16 23:19:34 2021 [DEBUG]   Version: 2
Fri Apr 16 23:19:34 2021 [DEBUG]   Current state: DECRYPTED (1)
Fri Apr 16 23:19:34 2021 [DEBUG]   Next state: DECRYPTED (1)
Fri Apr 16 23:19:34 2021 [DEBUG]   Encrypted volume size: 0 bytes (0), ~0 MB
Fri Apr 16 23:19:34 2021 [DEBUG]   Size of convertion region: 0 (0)
Fri Apr 16 23:19:34 2021 [DEBUG]   Number of boot sectors backuped: 16 sectors (0x10)
Fri Apr 16 23:19:34 2021 [DEBUG]   First metadata header offset:  0x3ea0000
Fri Apr 16 23:19:34 2021 [DEBUG]   Second metadata header offset: 0x4468e000
Fri Apr 16 23:19:34 2021 [DEBUG]   Third metadata header offset:  0xaada7000
Fri Apr 16 23:19:34 2021 [DEBUG]   Boot sectors backup address:   0x3eb0000
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37ef40 (0xc bytes allocated)
Fri Apr 16 23:19:34 2021 [DEBUG]   ----------------------------{ Dataset header }----------------------------
Fri Apr 16 23:19:34 2021 [DEBUG]     Dataset size: 0x00000218 (536) bytes (including data)
Fri Apr 16 23:19:34 2021 [DEBUG]     Unknown data: 0x00000001 (always 0x00000001)
Fri Apr 16 23:19:34 2021 [DEBUG]     Dataset header size: 0x00000030 (always 0x00000030)
Fri Apr 16 23:19:34 2021 [DEBUG]     Dataset copy size: 0x00000218 (536) bytes
Fri Apr 16 23:19:34 2021 [DEBUG]     Dataset GUID: '43C27DFF-BD75-48E5-80B5-B7436B0BA60A'
Fri Apr 16 23:19:34 2021 [DEBUG]     Next counter: 5
Fri Apr 16 23:19:34 2021 [DEBUG]     Encryption Type: AES-XTS-128 (0x8004)
Fri Apr 16 23:19:34 2021 [DEBUG]     Epoch Timestamp: 1617866671 sec, that to say Thu Apr  8 07:24:31 2021
Fri Apr 16 23:19:34 2021 [DEBUG]   --------------------------------------------------------------------------
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37ef40
Fri Apr 16 23:19:34 2021 [DEBUG] =============================================================================
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x50, 0x3, 0x5, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] 
Fri Apr 16 23:19:34 2021 [DEBUG] =======[ Datum n°1 informations ]=======
Fri Apr 16 23:19:34 2021 [DEBUG] Total datum size: 0x0050 (80) bytes
Fri Apr 16 23:19:34 2021 [DEBUG] Datum entry type: 3
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> ENTRY TYPE FVEK (FveDatasetVmkGetFvek)
Fri Apr 16 23:19:34 2021 [DEBUG] Datum value type: 5
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> AES-CCM -- Total size header: 36 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [DEBUG] Status: 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] Nonce: 
Fri Apr 16 23:19:34 2021 [DEBUG] d0 09 f1 37 48 2c d7 01 01 00 00 00 
Fri Apr 16 23:19:34 2021 [DEBUG] MAC: 
Fri Apr 16 23:19:34 2021 [DEBUG] b9 f4 d3 78 2c 0c 13 ed 24 de 4e 60 e3 95 23 79 
Fri Apr 16 23:19:34 2021 [DEBUG] Payload:
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000000 67 8c 47 3a c9 e9 d9 39-8a 2f b3 f2 ad 6d fd b9 
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000010 d3 88 3e a7 54 3f 82 18-54 6c 5c cd 57 ec 03 ec 
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000020 41 62 56 76 07 c0 f6 ba-66 89 96 1c 
Fri Apr 16 23:19:34 2021 [DEBUG] =========================================
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x50, 0xb, 0x5, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] 
Fri Apr 16 23:19:34 2021 [DEBUG] =======[ Datum n°2 informations ]=======
Fri Apr 16 23:19:34 2021 [DEBUG] Total datum size: 0x0050 (80) bytes
Fri Apr 16 23:19:34 2021 [DEBUG] Datum entry type: 11
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> ENTRY TYPE FVEK (TryObtainKey)
Fri Apr 16 23:19:34 2021 [DEBUG] Datum value type: 5
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> AES-CCM -- Total size header: 36 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [DEBUG] Status: 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] Nonce: 
Fri Apr 16 23:19:34 2021 [DEBUG] d0 09 f1 37 48 2c d7 01 02 00 00 00 
Fri Apr 16 23:19:34 2021 [DEBUG] MAC: 
Fri Apr 16 23:19:34 2021 [DEBUG] cf 63 03 6a 2f bf 9b 4a dc 88 56 3e b2 0f 00 4d 
Fri Apr 16 23:19:34 2021 [DEBUG] Payload:
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000000 da 19 e3 50 d0 ef 7e 48-95 cb fe 5d 63 a1 9f b7 
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000010 69 b1 66 c9 f1 37 18 2a-29 31 95 90 fb 7c ac 44 
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000020 46 ed 62 96 09 81 23 54-e8 b5 b9 f6 
Fri Apr 16 23:19:34 2021 [DEBUG] =========================================
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x44, 0x7, 0x2, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] 
Fri Apr 16 23:19:34 2021 [DEBUG] =======[ Datum n°3 informations ]=======
Fri Apr 16 23:19:34 2021 [DEBUG] Total datum size: 0x0044 (68) bytes
Fri Apr 16 23:19:34 2021 [DEBUG] Datum entry type: 7
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> ENTRY TYPE UNKNOWN
Fri Apr 16 23:19:34 2021 [DEBUG] Datum value type: 2
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> UNICODE -- Total size header: 8 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [DEBUG] Status: 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37ef90 (0x78 bytes allocated)
Fri Apr 16 23:19:34 2021 [DEBUG] UTF-16 string: 'DESKTOP-D23A7I4 C: 2021-04-08'
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37ef90
Fri Apr 16 23:19:34 2021 [DEBUG] =========================================
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0xa0, 0x2, 0x8, 0x3
Fri Apr 16 23:19:34 2021 [DEBUG] 
Fri Apr 16 23:19:34 2021 [DEBUG] =======[ Datum n°4 informations ]=======
Fri Apr 16 23:19:34 2021 [DEBUG] Total datum size: 0x00a0 (160) bytes
Fri Apr 16 23:19:34 2021 [DEBUG] Datum entry type: 2
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> ENTRY TYPE VMK
Fri Apr 16 23:19:34 2021 [DEBUG] Datum value type: 8
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> VMK -- Total size header: 36 -- Nested datum: yes
Fri Apr 16 23:19:34 2021 [DEBUG] Status: 0x3
Fri Apr 16 23:19:34 2021 [DEBUG] Recovery Key GUID: '77FEB581-A09A-430D-9E9E-BCC56ECB0578'
Fri Apr 16 23:19:34 2021 [DEBUG] Nonce: 
Fri Apr 16 23:19:34 2021 [DEBUG] 10 a6 f1 37 48 2c d7 01 00 00 00 00 
Fri Apr 16 23:19:34 2021 [DEBUG]    ------ Nested datum(s) ------
Fri Apr 16 23:19:34 2021 [DEBUG] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [DEBUG] Total datum size: 0x002c (44) bytes
Fri Apr 16 23:19:34 2021 [DEBUG] Datum entry type: 0
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> ENTRY TYPE UNKNOWN 1
Fri Apr 16 23:19:34 2021 [DEBUG] Datum value type: 1
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> KEY -- Total size header: 12 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [DEBUG] Status: 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37ef40 (0xc bytes allocated)
Fri Apr 16 23:19:34 2021 [DEBUG] Unkown: 
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000000 00 00 
Fri Apr 16 23:19:34 2021 [DEBUG] Algo: AES-CCM-256 (0x2000)
Fri Apr 16 23:19:34 2021 [DEBUG] Key:
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000000 1e 56 02 b3 11 97 bc ac-ea a5 a3 97 c0 c6 86 95 
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000010 16 95 1c fe b8 e4 15 7c-ba e8 47 73 ce 25 bc cc 
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37ef40
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x2c, 0, 0x1, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [DEBUG] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [DEBUG] Total datum size: 0x0050 (80) bytes
Fri Apr 16 23:19:34 2021 [DEBUG] Datum entry type: 0
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> ENTRY TYPE UNKNOWN 1
Fri Apr 16 23:19:34 2021 [DEBUG] Datum value type: 5
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> AES-CCM -- Total size header: 36 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [DEBUG] Status: 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] Nonce: 
Fri Apr 16 23:19:34 2021 [DEBUG] d0 09 f1 37 48 2c d7 01 03 00 00 00 
Fri Apr 16 23:19:34 2021 [DEBUG] MAC: 
Fri Apr 16 23:19:34 2021 [DEBUG] a4 32 86 7c 21 53 50 52 61 9c 5b 0e 0d 77 b5 da 
Fri Apr 16 23:19:34 2021 [DEBUG] Payload:
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000000 99 e0 c5 ea ba 4d c8 6b-a8 09 c0 1b f4 0d 4d ac 
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000010 1e f4 e3 79 c4 3d 12 05-0c a7 57 81 01 8b 20 ed 
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000020 96 da c5 55 52 62 74 4b-75 5d 02 e6 
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x50, 0, 0x5, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [DEBUG]    ------------------------------
Fri Apr 16 23:19:34 2021 [DEBUG] =========================================
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x64, 0xf, 0xf, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] 
Fri Apr 16 23:19:34 2021 [DEBUG] =======[ Datum n°5 informations ]=======
Fri Apr 16 23:19:34 2021 [DEBUG] Total datum size: 0x0064 (100) bytes
Fri Apr 16 23:19:34 2021 [DEBUG] Datum entry type: 15
Fri Apr 16 23:19:34 2021 [DEBUG] Datum value type: 15
Fri Apr 16 23:19:34 2021 [DEBUG]    `--> VIRTUALIZATION INFO -- Total size header: 24 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [DEBUG] Status: 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] NTFS boot sectors address:  0x3eb0000
Fri Apr 16 23:19:34 2021 [DEBUG] Number of backuped bytes: 0x2000 (8192)
Fri Apr 16 23:19:34 2021 [DEBUG] Unknown:
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000000 05 00 
Fri Apr 16 23:19:34 2021 [DEBUG] Size: 0x004c (76)
Fri Apr 16 23:19:34 2021 [DEBUG] Unknown:
Fri Apr 16 23:19:34 2021 [DEBUG] 0x00000000 00 00 00 00 
Fri Apr 16 23:19:34 2021 [DEBUG] Flags: 0x6 (6)
Fri Apr 16 23:19:34 2021 [DEBUG] Convert Log offset: 0x0000000000000000
Fri Apr 16 23:19:34 2021 [DEBUG] Convert Log size:   0x00000000 (0)
Fri Apr 16 23:19:34 2021 [DEBUG] Sector size (1): 0x200 (512)
Fri Apr 16 23:19:34 2021 [DEBUG] Sector size (2): 0x200 (512)
Fri Apr 16 23:19:34 2021 [DEBUG] =========================================
Fri Apr 16 23:19:34 2021 [DEBUG] Metadata files size: 0x10000
Fri Apr 16 23:19:34 2021 [DEBUG] Entering get_next_datum...
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x50, 0x3, 0x5, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x50, 0xb, 0x5, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x44, 0x7, 0x2, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0xa0, 0x2, 0x8, 0x3
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x64, 0xf, 0xf, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] Going out of get_next_datum
Fri Apr 16 23:19:34 2021 [DEBUG] Virtualized info size: 0x2000
Fri Apr 16 23:19:34 2021 [DEBUG] Got extended info
Fri Apr 16 23:19:34 2021 [INFO] =====[ Volume header informations ]=====
Fri Apr 16 23:19:34 2021 [INFO]   Signature: '-FVE-FS-'
Fri Apr 16 23:19:34 2021 [INFO]   Sector size: 0x0200 (512) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Sector per cluster: 0x08 (8) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Reserved clusters: 0x0000 (0) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Fat count: 0x00 (0) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Root entries: 0x0000 (0) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Number of sectors (16 bits): 0x0000 (0) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Media descriptor: 0xf8 (248) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Sectors per fat: 0x0000 (0) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Hidden sectors: 0x00113000 (1126400) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Number of sectors (32 bits): 0x00000000 (0) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Number of sectors (64 bits): 0x0000000000000000 (0) bytes
Fri Apr 16 23:19:34 2021 [INFO]   MFT start cluster: 0x0000000000060001 (393217) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Metadata Lcn: 0x0000000000000000 (0) bytes
Fri Apr 16 23:19:34 2021 [INFO]   Volume GUID: '92A84D3B-DD80-4D0E-9E4E-B1E3284EAED8'
Fri Apr 16 23:19:34 2021 [INFO]   First metadata header offset:  0x0000000003ea0000
Fri Apr 16 23:19:34 2021 [INFO]   Second metadata header offset: 0x000000004468e000
Fri Apr 16 23:19:34 2021 [INFO]   Third metadata header offset:  0x00000000aada7000
Fri Apr 16 23:19:34 2021 [INFO]   Boot Partition Identifier: '0xaa55'
Fri Apr 16 23:19:34 2021 [INFO] ========================================
Fri Apr 16 23:19:34 2021 [INFO] 
Fri Apr 16 23:19:34 2021 [INFO] =====================[ BitLocker information structure ]=====================
Fri Apr 16 23:19:34 2021 [INFO]   Signature: '-FVE-FS-'
Fri Apr 16 23:19:34 2021 [INFO]   Total Size: 0x0260 (608) bytes (including signature and data)
Fri Apr 16 23:19:34 2021 [INFO]   Version: 2
Fri Apr 16 23:19:34 2021 [INFO]   Current state: DECRYPTED (1)
Fri Apr 16 23:19:34 2021 [INFO]   Next state: DECRYPTED (1)
Fri Apr 16 23:19:34 2021 [INFO]   Encrypted volume size: 0 bytes (0), ~0 MB
Fri Apr 16 23:19:34 2021 [INFO]   Size of convertion region: 0 (0)
Fri Apr 16 23:19:34 2021 [INFO]   Number of boot sectors backuped: 16 sectors (0x10)
Fri Apr 16 23:19:34 2021 [INFO]   First metadata header offset:  0x3ea0000
Fri Apr 16 23:19:34 2021 [INFO]   Second metadata header offset: 0x4468e000
Fri Apr 16 23:19:34 2021 [INFO]   Third metadata header offset:  0xaada7000
Fri Apr 16 23:19:34 2021 [INFO]   Boot sectors backup address:   0x3eb0000
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37ef40 (0xc bytes allocated)
Fri Apr 16 23:19:34 2021 [INFO]   ----------------------------{ Dataset header }----------------------------
Fri Apr 16 23:19:34 2021 [INFO]     Dataset size: 0x00000218 (536) bytes (including data)
Fri Apr 16 23:19:34 2021 [INFO]     Unknown data: 0x00000001 (always 0x00000001)
Fri Apr 16 23:19:34 2021 [INFO]     Dataset header size: 0x00000030 (always 0x00000030)
Fri Apr 16 23:19:34 2021 [INFO]     Dataset copy size: 0x00000218 (536) bytes
Fri Apr 16 23:19:34 2021 [INFO]     Dataset GUID: '43C27DFF-BD75-48E5-80B5-B7436B0BA60A'
Fri Apr 16 23:19:34 2021 [INFO]     Next counter: 5
Fri Apr 16 23:19:34 2021 [INFO]     Encryption Type: AES-XTS-128 (0x8004)
Fri Apr 16 23:19:34 2021 [INFO]     Epoch Timestamp: 1617866671 sec, that to say Thu Apr  8 07:24:31 2021
Fri Apr 16 23:19:34 2021 [INFO]   --------------------------------------------------------------------------
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37ef40
Fri Apr 16 23:19:34 2021 [INFO] =============================================================================
Fri Apr 16 23:19:34 2021 [INFO] 
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x50, 0x3, 0x5, 0x1
Fri Apr 16 23:19:34 2021 [INFO] 
Fri Apr 16 23:19:34 2021 [INFO] =======[ Datum n°1 informations ]=======
Fri Apr 16 23:19:34 2021 [INFO] Total datum size: 0x0050 (80) bytes
Fri Apr 16 23:19:34 2021 [INFO] Datum entry type: 3
Fri Apr 16 23:19:34 2021 [INFO]    `--> ENTRY TYPE FVEK (FveDatasetVmkGetFvek)
Fri Apr 16 23:19:34 2021 [INFO] Datum value type: 5
Fri Apr 16 23:19:34 2021 [INFO]    `--> AES-CCM -- Total size header: 36 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [INFO] Status: 0x1
Fri Apr 16 23:19:34 2021 [INFO] Nonce: 
Fri Apr 16 23:19:34 2021 [INFO] d0 09 f1 37 48 2c d7 01 01 00 00 00 
Fri Apr 16 23:19:34 2021 [INFO] MAC: 
Fri Apr 16 23:19:34 2021 [INFO] b9 f4 d3 78 2c 0c 13 ed 24 de 4e 60 e3 95 23 79 
Fri Apr 16 23:19:34 2021 [INFO] Payload:
Fri Apr 16 23:19:34 2021 [INFO] 0x00000000 67 8c 47 3a c9 e9 d9 39-8a 2f b3 f2 ad 6d fd b9 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000010 d3 88 3e a7 54 3f 82 18-54 6c 5c cd 57 ec 03 ec 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000020 41 62 56 76 07 c0 f6 ba-66 89 96 1c 
Fri Apr 16 23:19:34 2021 [INFO] =========================================
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x50, 0xb, 0x5, 0x1
Fri Apr 16 23:19:34 2021 [INFO] 
Fri Apr 16 23:19:34 2021 [INFO] =======[ Datum n°2 informations ]=======
Fri Apr 16 23:19:34 2021 [INFO] Total datum size: 0x0050 (80) bytes
Fri Apr 16 23:19:34 2021 [INFO] Datum entry type: 11
Fri Apr 16 23:19:34 2021 [INFO]    `--> ENTRY TYPE FVEK (TryObtainKey)
Fri Apr 16 23:19:34 2021 [INFO] Datum value type: 5
Fri Apr 16 23:19:34 2021 [INFO]    `--> AES-CCM -- Total size header: 36 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [INFO] Status: 0x1
Fri Apr 16 23:19:34 2021 [INFO] Nonce: 
Fri Apr 16 23:19:34 2021 [INFO] d0 09 f1 37 48 2c d7 01 02 00 00 00 
Fri Apr 16 23:19:34 2021 [INFO] MAC: 
Fri Apr 16 23:19:34 2021 [INFO] cf 63 03 6a 2f bf 9b 4a dc 88 56 3e b2 0f 00 4d 
Fri Apr 16 23:19:34 2021 [INFO] Payload:
Fri Apr 16 23:19:34 2021 [INFO] 0x00000000 da 19 e3 50 d0 ef 7e 48-95 cb fe 5d 63 a1 9f b7 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000010 69 b1 66 c9 f1 37 18 2a-29 31 95 90 fb 7c ac 44 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000020 46 ed 62 96 09 81 23 54-e8 b5 b9 f6 
Fri Apr 16 23:19:34 2021 [INFO] =========================================
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x44, 0x7, 0x2, 0x1
Fri Apr 16 23:19:34 2021 [INFO] 
Fri Apr 16 23:19:34 2021 [INFO] =======[ Datum n°3 informations ]=======
Fri Apr 16 23:19:34 2021 [INFO] Total datum size: 0x0044 (68) bytes
Fri Apr 16 23:19:34 2021 [INFO] Datum entry type: 7
Fri Apr 16 23:19:34 2021 [INFO]    `--> ENTRY TYPE UNKNOWN
Fri Apr 16 23:19:34 2021 [INFO] Datum value type: 2
Fri Apr 16 23:19:34 2021 [INFO]    `--> UNICODE -- Total size header: 8 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [INFO] Status: 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37ef90 (0x78 bytes allocated)
Fri Apr 16 23:19:34 2021 [INFO] UTF-16 string: 'DESKTOP-D23A7I4 C: 2021-04-08'
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37ef90
Fri Apr 16 23:19:34 2021 [INFO] =========================================
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0xa0, 0x2, 0x8, 0x3
Fri Apr 16 23:19:34 2021 [INFO] 
Fri Apr 16 23:19:34 2021 [INFO] =======[ Datum n°4 informations ]=======
Fri Apr 16 23:19:34 2021 [INFO] Total datum size: 0x00a0 (160) bytes
Fri Apr 16 23:19:34 2021 [INFO] Datum entry type: 2
Fri Apr 16 23:19:34 2021 [INFO]    `--> ENTRY TYPE VMK
Fri Apr 16 23:19:34 2021 [INFO] Datum value type: 8
Fri Apr 16 23:19:34 2021 [INFO]    `--> VMK -- Total size header: 36 -- Nested datum: yes
Fri Apr 16 23:19:34 2021 [INFO] Status: 0x3
Fri Apr 16 23:19:34 2021 [INFO] Recovery Key GUID: '77FEB581-A09A-430D-9E9E-BCC56ECB0578'
Fri Apr 16 23:19:34 2021 [INFO] Nonce: 
Fri Apr 16 23:19:34 2021 [INFO] 10 a6 f1 37 48 2c d7 01 00 00 00 00 
Fri Apr 16 23:19:34 2021 [INFO]    ------ Nested datum(s) ------
Fri Apr 16 23:19:34 2021 [INFO] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [INFO] Total datum size: 0x002c (44) bytes
Fri Apr 16 23:19:34 2021 [INFO] Datum entry type: 0
Fri Apr 16 23:19:34 2021 [INFO]    `--> ENTRY TYPE UNKNOWN 1
Fri Apr 16 23:19:34 2021 [INFO] Datum value type: 1
Fri Apr 16 23:19:34 2021 [INFO]    `--> KEY -- Total size header: 12 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [INFO] Status: 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37ef40 (0xc bytes allocated)
Fri Apr 16 23:19:34 2021 [INFO] Unkown: 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000000 00 00 
Fri Apr 16 23:19:34 2021 [INFO] Algo: AES-CCM-256 (0x2000)
Fri Apr 16 23:19:34 2021 [INFO] Key:
Fri Apr 16 23:19:34 2021 [INFO] 0x00000000 1e 56 02 b3 11 97 bc ac-ea a5 a3 97 c0 c6 86 95 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000010 16 95 1c fe b8 e4 15 7c-ba e8 47 73 ce 25 bc cc 
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37ef40
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x2c, 0, 0x1, 0x1
Fri Apr 16 23:19:34 2021 [INFO] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [INFO] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [INFO] Total datum size: 0x0050 (80) bytes
Fri Apr 16 23:19:34 2021 [INFO] Datum entry type: 0
Fri Apr 16 23:19:34 2021 [INFO]    `--> ENTRY TYPE UNKNOWN 1
Fri Apr 16 23:19:34 2021 [INFO] Datum value type: 5
Fri Apr 16 23:19:34 2021 [INFO]    `--> AES-CCM -- Total size header: 36 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [INFO] Status: 0x1
Fri Apr 16 23:19:34 2021 [INFO] Nonce: 
Fri Apr 16 23:19:34 2021 [INFO] d0 09 f1 37 48 2c d7 01 03 00 00 00 
Fri Apr 16 23:19:34 2021 [INFO] MAC: 
Fri Apr 16 23:19:34 2021 [INFO] a4 32 86 7c 21 53 50 52 61 9c 5b 0e 0d 77 b5 da 
Fri Apr 16 23:19:34 2021 [INFO] Payload:
Fri Apr 16 23:19:34 2021 [INFO] 0x00000000 99 e0 c5 ea ba 4d c8 6b-a8 09 c0 1b f4 0d 4d ac 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000010 1e f4 e3 79 c4 3d 12 05-0c a7 57 81 01 8b 20 ed 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000020 96 da c5 55 52 62 74 4b-75 5d 02 e6 
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x50, 0, 0x5, 0x1
Fri Apr 16 23:19:34 2021 [INFO] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [INFO]    ------------------------------
Fri Apr 16 23:19:34 2021 [INFO] =========================================
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x64, 0xf, 0xf, 0x1
Fri Apr 16 23:19:34 2021 [INFO] 
Fri Apr 16 23:19:34 2021 [INFO] =======[ Datum n°5 informations ]=======
Fri Apr 16 23:19:34 2021 [INFO] Total datum size: 0x0064 (100) bytes
Fri Apr 16 23:19:34 2021 [INFO] Datum entry type: 15
Fri Apr 16 23:19:34 2021 [INFO] Datum value type: 15
Fri Apr 16 23:19:34 2021 [INFO]    `--> VIRTUALIZATION INFO -- Total size header: 24 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [INFO] Status: 0x1
Fri Apr 16 23:19:34 2021 [INFO] NTFS boot sectors address:  0x3eb0000
Fri Apr 16 23:19:34 2021 [INFO] Number of backuped bytes: 0x2000 (8192)
Fri Apr 16 23:19:34 2021 [INFO] Unknown:
Fri Apr 16 23:19:34 2021 [INFO] 0x00000000 05 00 
Fri Apr 16 23:19:34 2021 [INFO] Size: 0x004c (76)
Fri Apr 16 23:19:34 2021 [INFO] Unknown:
Fri Apr 16 23:19:34 2021 [INFO] 0x00000000 00 00 00 00 
Fri Apr 16 23:19:34 2021 [INFO] Flags: 0x6 (6)
Fri Apr 16 23:19:34 2021 [INFO] Convert Log offset: 0x0000000000000000
Fri Apr 16 23:19:34 2021 [INFO] Convert Log size:   0x00000000 (0)
Fri Apr 16 23:19:34 2021 [INFO] Sector size (1): 0x200 (512)
Fri Apr 16 23:19:34 2021 [INFO] Sector size (2): 0x200 (512)
Fri Apr 16 23:19:34 2021 [INFO] =========================================
Fri Apr 16 23:19:34 2021 [DEBUG] Entering has_clear_key. Returning result of get_vmk_datum_from_range with range between 0x00 and 0xff
Fri Apr 16 23:19:34 2021 [DEBUG] Entering get_next_datum...
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x50, 0x3, 0x5, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x50, 0xb, 0x5, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x44, 0x7, 0x2, 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0xa0, 0x2, 0x8, 0x3
Fri Apr 16 23:19:34 2021 [DEBUG] Going out of get_next_datum
Fri Apr 16 23:19:34 2021 [INFO] =======[ There's a clear key here ]========
Fri Apr 16 23:19:34 2021 [INFO] Total datum size: 0x00a0 (160) bytes
Fri Apr 16 23:19:34 2021 [INFO] Datum entry type: 2
Fri Apr 16 23:19:34 2021 [INFO]    `--> ENTRY TYPE VMK
Fri Apr 16 23:19:34 2021 [INFO] Datum value type: 8
Fri Apr 16 23:19:34 2021 [INFO]    `--> VMK -- Total size header: 36 -- Nested datum: yes
Fri Apr 16 23:19:34 2021 [INFO] Status: 0x3
Fri Apr 16 23:19:34 2021 [INFO] Recovery Key GUID: '77FEB581-A09A-430D-9E9E-BCC56ECB0578'
Fri Apr 16 23:19:34 2021 [INFO] Nonce: 
Fri Apr 16 23:19:34 2021 [INFO] 10 a6 f1 37 48 2c d7 01 00 00 00 00 
Fri Apr 16 23:19:34 2021 [INFO]    ------ Nested datum(s) ------
Fri Apr 16 23:19:34 2021 [INFO] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [INFO] Total datum size: 0x002c (44) bytes
Fri Apr 16 23:19:34 2021 [INFO] Datum entry type: 0
Fri Apr 16 23:19:34 2021 [INFO]    `--> ENTRY TYPE UNKNOWN 1
Fri Apr 16 23:19:34 2021 [INFO] Datum value type: 1
Fri Apr 16 23:19:34 2021 [INFO]    `--> KEY -- Total size header: 12 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [INFO] Status: 0x1
Fri Apr 16 23:19:34 2021 [DEBUG] New memory allocation at 0x55f0ad37ef40 (0xc bytes allocated)
Fri Apr 16 23:19:34 2021 [INFO] Unkown: 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000000 00 00 
Fri Apr 16 23:19:34 2021 [INFO] Algo: AES-CCM-256 (0x2000)
Fri Apr 16 23:19:34 2021 [INFO] Key:
Fri Apr 16 23:19:34 2021 [INFO] 0x00000000 1e 56 02 b3 11 97 bc ac-ea a5 a3 97 c0 c6 86 95 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000010 16 95 1c fe b8 e4 15 7c-ba e8 47 73 ce 25 bc cc 
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37ef40
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x2c, 0, 0x1, 0x1
Fri Apr 16 23:19:34 2021 [INFO] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [INFO] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [INFO] Total datum size: 0x0050 (80) bytes
Fri Apr 16 23:19:34 2021 [INFO] Datum entry type: 0
Fri Apr 16 23:19:34 2021 [INFO]    `--> ENTRY TYPE UNKNOWN 1
Fri Apr 16 23:19:34 2021 [INFO] Datum value type: 5
Fri Apr 16 23:19:34 2021 [INFO]    `--> AES-CCM -- Total size header: 36 -- Nested datum: no
Fri Apr 16 23:19:34 2021 [INFO] Status: 0x1
Fri Apr 16 23:19:34 2021 [INFO] Nonce: 
Fri Apr 16 23:19:34 2021 [INFO] d0 09 f1 37 48 2c d7 01 03 00 00 00 
Fri Apr 16 23:19:34 2021 [INFO] MAC: 
Fri Apr 16 23:19:34 2021 [INFO] a4 32 86 7c 21 53 50 52 61 9c 5b 0e 0d 77 b5 da 
Fri Apr 16 23:19:34 2021 [INFO] Payload:
Fri Apr 16 23:19:34 2021 [INFO] 0x00000000 99 e0 c5 ea ba 4d c8 6b-a8 09 c0 1b f4 0d 4d ac 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000010 1e f4 e3 79 c4 3d 12 05-0c a7 57 81 01 8b 20 ed 
Fri Apr 16 23:19:34 2021 [INFO] 0x00000020 96 da c5 55 52 62 74 4b-75 5d 02 e6 
Fri Apr 16 23:19:34 2021 [DEBUG] Header safe: 0x50, 0, 0x5, 0x1
Fri Apr 16 23:19:34 2021 [INFO] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fri Apr 16 23:19:34 2021 [INFO]    ------------------------------
Fri Apr 16 23:19:34 2021 [INFO] =============[ Clear key end ]=============
Fri Apr 16 23:19:34 2021 [DEBUG] Trying to close fd #3...
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37e9a0
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37ecd0
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37e8d0
Fri Apr 16 23:19:34 2021 [DEBUG] Freeing pointer at address 0x55f0ad37e900

@Aorimn
Copy link
Owner

Aorimn commented Apr 18, 2021

Awesome 👍

@Aorimn Aorimn merged commit 017ac72 into Aorimn:master Apr 18, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants