2 * Author......: Jens Steube <jens.steube@gmail.com>
8 #include "include/constants.h"
9 #include "include/kernel_vendor.h"
16 #include "include/kernel_functions.c"
17 #include "OpenCL/types_ocl.c"
18 #include "OpenCL/common.c"
20 #define COMPARE_S "OpenCL/check_single_comp4.c"
21 #define COMPARE_M "OpenCL/check_multi_comp4.c"
31 static void swap (__local RC4_KEY *rc4_key, const u8 i, const u8 j)
36 rc4_key->S[i] = rc4_key->S[j];
40 static void rc4_init_16 (__local RC4_KEY *rc4_key, const u32 data[4])
45 __local u32 *ptr = (__local u32 *) rc4_key->S;
48 for (u32 i = 0; i < 64; i++)
55 for (u32 i = 0; i < 16; i++)
63 j += rc4_key->S[idx] + (v >> 0); swap (rc4_key, idx, j); idx++;
64 j += rc4_key->S[idx] + (v >> 8); swap (rc4_key, idx, j); idx++;
65 j += rc4_key->S[idx] + (v >> 16); swap (rc4_key, idx, j); idx++;
66 j += rc4_key->S[idx] + (v >> 24); swap (rc4_key, idx, j); idx++;
70 j += rc4_key->S[idx] + (v >> 0); swap (rc4_key, idx, j); idx++;
71 j += rc4_key->S[idx] + (v >> 8); swap (rc4_key, idx, j); idx++;
72 j += rc4_key->S[idx] + (v >> 16); swap (rc4_key, idx, j); idx++;
73 j += rc4_key->S[idx] + (v >> 24); swap (rc4_key, idx, j); idx++;
77 j += rc4_key->S[idx] + (v >> 0); swap (rc4_key, idx, j); idx++;
78 j += rc4_key->S[idx] + (v >> 8); swap (rc4_key, idx, j); idx++;
79 j += rc4_key->S[idx] + (v >> 16); swap (rc4_key, idx, j); idx++;
80 j += rc4_key->S[idx] + (v >> 24); swap (rc4_key, idx, j); idx++;
84 j += rc4_key->S[idx] + (v >> 0); swap (rc4_key, idx, j); idx++;
85 j += rc4_key->S[idx] + (v >> 8); swap (rc4_key, idx, j); idx++;
86 j += rc4_key->S[idx] + (v >> 16); swap (rc4_key, idx, j); idx++;
87 j += rc4_key->S[idx] + (v >> 24); swap (rc4_key, idx, j); idx++;
91 static u8 rc4_next_16 (__local RC4_KEY *rc4_key, u8 i, u8 j, const u32 in[4], u32 out[4])
94 for (u32 k = 0; k < 4; k++)
103 swap (rc4_key, i, j);
105 idx = rc4_key->S[i] + rc4_key->S[j];
107 xor4 |= rc4_key->S[idx] << 0;
112 swap (rc4_key, i, j);
114 idx = rc4_key->S[i] + rc4_key->S[j];
116 xor4 |= rc4_key->S[idx] << 8;
121 swap (rc4_key, i, j);
123 idx = rc4_key->S[i] + rc4_key->S[j];
125 xor4 |= rc4_key->S[idx] << 16;
130 swap (rc4_key, i, j);
132 idx = rc4_key->S[i] + rc4_key->S[j];
134 xor4 |= rc4_key->S[idx] << 24;
136 out[k] = in[k] ^ xor4;
142 static void md5_transform (const u32 w0[4], const u32 w1[4], const u32 w2[4], const u32 w3[4], u32 digest[4])
166 MD5_STEP (MD5_Fo, a, b, c, d, w0_t, MD5C00, MD5S00);
167 MD5_STEP (MD5_Fo, d, a, b, c, w1_t, MD5C01, MD5S01);
168 MD5_STEP (MD5_Fo, c, d, a, b, w2_t, MD5C02, MD5S02);
169 MD5_STEP (MD5_Fo, b, c, d, a, w3_t, MD5C03, MD5S03);
170 MD5_STEP (MD5_Fo, a, b, c, d, w4_t, MD5C04, MD5S00);
171 MD5_STEP (MD5_Fo, d, a, b, c, w5_t, MD5C05, MD5S01);
172 MD5_STEP (MD5_Fo, c, d, a, b, w6_t, MD5C06, MD5S02);
173 MD5_STEP (MD5_Fo, b, c, d, a, w7_t, MD5C07, MD5S03);
174 MD5_STEP (MD5_Fo, a, b, c, d, w8_t, MD5C08, MD5S00);
175 MD5_STEP (MD5_Fo, d, a, b, c, w9_t, MD5C09, MD5S01);
176 MD5_STEP (MD5_Fo, c, d, a, b, wa_t, MD5C0a, MD5S02);
177 MD5_STEP (MD5_Fo, b, c, d, a, wb_t, MD5C0b, MD5S03);
178 MD5_STEP (MD5_Fo, a, b, c, d, wc_t, MD5C0c, MD5S00);
179 MD5_STEP (MD5_Fo, d, a, b, c, wd_t, MD5C0d, MD5S01);
180 MD5_STEP (MD5_Fo, c, d, a, b, we_t, MD5C0e, MD5S02);
181 MD5_STEP (MD5_Fo, b, c, d, a, wf_t, MD5C0f, MD5S03);
183 MD5_STEP (MD5_Go, a, b, c, d, w1_t, MD5C10, MD5S10);
184 MD5_STEP (MD5_Go, d, a, b, c, w6_t, MD5C11, MD5S11);
185 MD5_STEP (MD5_Go, c, d, a, b, wb_t, MD5C12, MD5S12);
186 MD5_STEP (MD5_Go, b, c, d, a, w0_t, MD5C13, MD5S13);
187 MD5_STEP (MD5_Go, a, b, c, d, w5_t, MD5C14, MD5S10);
188 MD5_STEP (MD5_Go, d, a, b, c, wa_t, MD5C15, MD5S11);
189 MD5_STEP (MD5_Go, c, d, a, b, wf_t, MD5C16, MD5S12);
190 MD5_STEP (MD5_Go, b, c, d, a, w4_t, MD5C17, MD5S13);
191 MD5_STEP (MD5_Go, a, b, c, d, w9_t, MD5C18, MD5S10);
192 MD5_STEP (MD5_Go, d, a, b, c, we_t, MD5C19, MD5S11);
193 MD5_STEP (MD5_Go, c, d, a, b, w3_t, MD5C1a, MD5S12);
194 MD5_STEP (MD5_Go, b, c, d, a, w8_t, MD5C1b, MD5S13);
195 MD5_STEP (MD5_Go, a, b, c, d, wd_t, MD5C1c, MD5S10);
196 MD5_STEP (MD5_Go, d, a, b, c, w2_t, MD5C1d, MD5S11);
197 MD5_STEP (MD5_Go, c, d, a, b, w7_t, MD5C1e, MD5S12);
198 MD5_STEP (MD5_Go, b, c, d, a, wc_t, MD5C1f, MD5S13);
200 MD5_STEP (MD5_H , a, b, c, d, w5_t, MD5C20, MD5S20);
201 MD5_STEP (MD5_H , d, a, b, c, w8_t, MD5C21, MD5S21);
202 MD5_STEP (MD5_H , c, d, a, b, wb_t, MD5C22, MD5S22);
203 MD5_STEP (MD5_H , b, c, d, a, we_t, MD5C23, MD5S23);
204 MD5_STEP (MD5_H , a, b, c, d, w1_t, MD5C24, MD5S20);
205 MD5_STEP (MD5_H , d, a, b, c, w4_t, MD5C25, MD5S21);
206 MD5_STEP (MD5_H , c, d, a, b, w7_t, MD5C26, MD5S22);
207 MD5_STEP (MD5_H , b, c, d, a, wa_t, MD5C27, MD5S23);
208 MD5_STEP (MD5_H , a, b, c, d, wd_t, MD5C28, MD5S20);
209 MD5_STEP (MD5_H , d, a, b, c, w0_t, MD5C29, MD5S21);
210 MD5_STEP (MD5_H , c, d, a, b, w3_t, MD5C2a, MD5S22);
211 MD5_STEP (MD5_H , b, c, d, a, w6_t, MD5C2b, MD5S23);
212 MD5_STEP (MD5_H , a, b, c, d, w9_t, MD5C2c, MD5S20);
213 MD5_STEP (MD5_H , d, a, b, c, wc_t, MD5C2d, MD5S21);
214 MD5_STEP (MD5_H , c, d, a, b, wf_t, MD5C2e, MD5S22);
215 MD5_STEP (MD5_H , b, c, d, a, w2_t, MD5C2f, MD5S23);
217 MD5_STEP (MD5_I , a, b, c, d, w0_t, MD5C30, MD5S30);
218 MD5_STEP (MD5_I , d, a, b, c, w7_t, MD5C31, MD5S31);
219 MD5_STEP (MD5_I , c, d, a, b, we_t, MD5C32, MD5S32);
220 MD5_STEP (MD5_I , b, c, d, a, w5_t, MD5C33, MD5S33);
221 MD5_STEP (MD5_I , a, b, c, d, wc_t, MD5C34, MD5S30);
222 MD5_STEP (MD5_I , d, a, b, c, w3_t, MD5C35, MD5S31);
223 MD5_STEP (MD5_I , c, d, a, b, wa_t, MD5C36, MD5S32);
224 MD5_STEP (MD5_I , b, c, d, a, w1_t, MD5C37, MD5S33);
225 MD5_STEP (MD5_I , a, b, c, d, w8_t, MD5C38, MD5S30);
226 MD5_STEP (MD5_I , d, a, b, c, wf_t, MD5C39, MD5S31);
227 MD5_STEP (MD5_I , c, d, a, b, w6_t, MD5C3a, MD5S32);
228 MD5_STEP (MD5_I , b, c, d, a, wd_t, MD5C3b, MD5S33);
229 MD5_STEP (MD5_I , a, b, c, d, w4_t, MD5C3c, MD5S30);
230 MD5_STEP (MD5_I , d, a, b, c, wb_t, MD5C3d, MD5S31);
231 MD5_STEP (MD5_I , c, d, a, b, w2_t, MD5C3e, MD5S32);
232 MD5_STEP (MD5_I , b, c, d, a, w9_t, MD5C3f, MD5S33);
240 static void gen336 (u32 digest_pre[4], u32 salt_buf[4], u32 digest[4])
247 digest_t0[0] = digest_pre[0];
248 digest_t0[1] = digest_pre[1] & 0xff;
250 digest_t1[0] = digest_pre[0] << 8;
251 digest_t1[1] = digest_pre[0] >> 24 | digest_pre[1] << 8;
253 digest_t2[0] = digest_pre[0] << 16;
254 digest_t2[1] = digest_pre[0] >> 16 | digest_pre[1] << 16;
256 digest_t3[0] = digest_pre[0] << 24;
257 digest_t3[1] = digest_pre[0] >> 8 | digest_pre[1] << 24;
264 salt_buf_t0[0] = salt_buf[0];
265 salt_buf_t0[1] = salt_buf[1];
266 salt_buf_t0[2] = salt_buf[2];
267 salt_buf_t0[3] = salt_buf[3];
269 salt_buf_t1[0] = salt_buf[0] << 8;
270 salt_buf_t1[1] = salt_buf[0] >> 24 | salt_buf[1] << 8;
271 salt_buf_t1[2] = salt_buf[1] >> 24 | salt_buf[2] << 8;
272 salt_buf_t1[3] = salt_buf[2] >> 24 | salt_buf[3] << 8;
273 salt_buf_t1[4] = salt_buf[3] >> 24;
275 salt_buf_t2[0] = salt_buf[0] << 16;
276 salt_buf_t2[1] = salt_buf[0] >> 16 | salt_buf[1] << 16;
277 salt_buf_t2[2] = salt_buf[1] >> 16 | salt_buf[2] << 16;
278 salt_buf_t2[3] = salt_buf[2] >> 16 | salt_buf[3] << 16;
279 salt_buf_t2[4] = salt_buf[3] >> 16;
281 salt_buf_t3[0] = salt_buf[0] << 24;
282 salt_buf_t3[1] = salt_buf[0] >> 8 | salt_buf[1] << 24;
283 salt_buf_t3[2] = salt_buf[1] >> 8 | salt_buf[2] << 24;
284 salt_buf_t3[3] = salt_buf[2] >> 8 | salt_buf[3] << 24;
285 salt_buf_t3[4] = salt_buf[3] >> 8;
292 // generate the 16 * 21 buffer
312 w0_t[0] = digest_t0[0];
313 w0_t[1] = digest_t0[1];
316 w0_t[1] |= salt_buf_t1[0];
317 w0_t[2] = salt_buf_t1[1];
318 w0_t[3] = salt_buf_t1[2];
319 w1_t[0] = salt_buf_t1[3];
320 w1_t[1] = salt_buf_t1[4];
323 w1_t[1] |= digest_t1[0];
324 w1_t[2] = digest_t1[1];
327 w1_t[2] |= salt_buf_t2[0];
328 w1_t[3] = salt_buf_t2[1];
329 w2_t[0] = salt_buf_t2[2];
330 w2_t[1] = salt_buf_t2[3];
331 w2_t[2] = salt_buf_t2[4];
334 w2_t[2] |= digest_t2[0];
335 w2_t[3] = digest_t2[1];
338 w2_t[3] |= salt_buf_t3[0];
339 w3_t[0] = salt_buf_t3[1];
340 w3_t[1] = salt_buf_t3[2];
341 w3_t[2] = salt_buf_t3[3];
342 w3_t[3] = salt_buf_t3[4];
346 w3_t[3] |= digest_t3[0];
348 md5_transform (w0_t, w1_t, w2_t, w3_t, digest);
368 w0_t[0] = digest_t3[1];
371 w0_t[1] = salt_buf_t0[0];
372 w0_t[2] = salt_buf_t0[1];
373 w0_t[3] = salt_buf_t0[2];
374 w1_t[0] = salt_buf_t0[3];
377 w1_t[1] = digest_t0[0];
378 w1_t[2] = digest_t0[1];
381 w1_t[2] |= salt_buf_t1[0];
382 w1_t[3] = salt_buf_t1[1];
383 w2_t[0] = salt_buf_t1[2];
384 w2_t[1] = salt_buf_t1[3];
385 w2_t[2] = salt_buf_t1[4];
388 w2_t[2] |= digest_t1[0];
389 w2_t[3] = digest_t1[1];
392 w2_t[3] |= salt_buf_t2[0];
393 w3_t[0] = salt_buf_t2[1];
394 w3_t[1] = salt_buf_t2[2];
395 w3_t[2] = salt_buf_t2[3];
396 w3_t[3] = salt_buf_t2[4];
399 w3_t[3] |= digest_t2[0];
401 md5_transform (w0_t, w1_t, w2_t, w3_t, digest);
421 w0_t[0] = digest_t2[1];
424 w0_t[0] |= salt_buf_t3[0];
425 w0_t[1] = salt_buf_t3[1];
426 w0_t[2] = salt_buf_t3[2];
427 w0_t[3] = salt_buf_t3[3];
428 w1_t[0] = salt_buf_t3[4];
431 w1_t[0] |= digest_t3[0];
432 w1_t[1] = digest_t3[1];
435 w1_t[2] = salt_buf_t0[0];
436 w1_t[3] = salt_buf_t0[1];
437 w2_t[0] = salt_buf_t0[2];
438 w2_t[1] = salt_buf_t0[3];
441 w2_t[2] = digest_t0[0];
442 w2_t[3] = digest_t0[1];
445 w2_t[3] |= salt_buf_t1[0];
446 w3_t[0] = salt_buf_t1[1];
447 w3_t[1] = salt_buf_t1[2];
448 w3_t[2] = salt_buf_t1[3];
449 w3_t[3] = salt_buf_t1[4];
452 w3_t[3] |= digest_t1[0];
454 md5_transform (w0_t, w1_t, w2_t, w3_t, digest);
474 w0_t[0] = digest_t1[1];
477 w0_t[0] |= salt_buf_t2[0];
478 w0_t[1] = salt_buf_t2[1];
479 w0_t[2] = salt_buf_t2[2];
480 w0_t[3] = salt_buf_t2[3];
481 w1_t[0] = salt_buf_t2[4];
484 w1_t[0] |= digest_t2[0];
485 w1_t[1] = digest_t2[1];
488 w1_t[1] |= salt_buf_t3[0];
489 w1_t[2] = salt_buf_t3[1];
490 w1_t[3] = salt_buf_t3[2];
491 w2_t[0] = salt_buf_t3[3];
492 w2_t[1] = salt_buf_t3[4];
495 w2_t[1] |= digest_t3[0];
496 w2_t[2] = digest_t3[1];
499 w2_t[3] = salt_buf_t0[0];
500 w3_t[0] = salt_buf_t0[1];
501 w3_t[1] = salt_buf_t0[2];
502 w3_t[2] = salt_buf_t0[3];
505 w3_t[3] = digest_t0[0];
507 md5_transform (w0_t, w1_t, w2_t, w3_t, digest);
527 w0_t[0] = digest_t0[1];
530 w0_t[0] |= salt_buf_t1[0];
531 w0_t[1] = salt_buf_t1[1];
532 w0_t[2] = salt_buf_t1[2];
533 w0_t[3] = salt_buf_t1[3];
534 w1_t[0] = salt_buf_t1[4];
537 w1_t[0] |= digest_t1[0];
538 w1_t[1] = digest_t1[1];
541 w1_t[1] |= salt_buf_t2[0];
542 w1_t[2] = salt_buf_t2[1];
543 w1_t[3] = salt_buf_t2[2];
544 w2_t[0] = salt_buf_t2[3];
545 w2_t[1] = salt_buf_t2[4];
548 w2_t[1] |= digest_t2[0];
549 w2_t[2] = digest_t2[1];
552 w2_t[2] |= salt_buf_t3[0];
553 w2_t[3] = salt_buf_t3[1];
554 w3_t[0] = salt_buf_t3[2];
555 w3_t[1] = salt_buf_t3[3];
556 w3_t[2] = salt_buf_t3[4];
559 w3_t[2] |= digest_t3[0];
560 w3_t[3] = digest_t3[1];
562 md5_transform (w0_t, w1_t, w2_t, w3_t, digest);
564 w0_t[0] = salt_buf_t0[0];
565 w0_t[1] = salt_buf_t0[1];
566 w0_t[2] = salt_buf_t0[2];
567 w0_t[3] = salt_buf_t0[3];
578 w3_t[2] = 21 * 16 * 8;
581 md5_transform (w0_t, w1_t, w2_t, w3_t, digest);
584 __kernel void m09700_m04 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global oldoffice01_t *oldoffice01_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
590 const u32 lid = get_local_id (0);
592 __local RC4_KEY rc4_keys[64];
594 __local RC4_KEY *rc4_key = &rc4_keys[lid];
600 const u32 gid = get_global_id (0);
602 if (gid >= gid_max) return;
606 wordl0[0] = pws[gid].i[ 0];
607 wordl0[1] = pws[gid].i[ 1];
608 wordl0[2] = pws[gid].i[ 2];
609 wordl0[3] = pws[gid].i[ 3];
613 wordl1[0] = pws[gid].i[ 4];
614 wordl1[1] = pws[gid].i[ 5];
615 wordl1[2] = pws[gid].i[ 6];
616 wordl1[3] = pws[gid].i[ 7];
632 const u32 pw_l_len = pws[gid].pw_len;
634 if (combs_mode == COMBINATOR_MODE_BASE_RIGHT)
636 switch_buffer_by_offset_le (wordl0, wordl1, wordl2, wordl3, combs_buf[0].pw_len);
643 const u32 search[4] =
645 digests_buf[digests_offset].digest_buf[DGST_R0],
646 digests_buf[digests_offset].digest_buf[DGST_R1],
647 digests_buf[digests_offset].digest_buf[DGST_R2],
648 digests_buf[digests_offset].digest_buf[DGST_R3]
657 salt_buf[0] = salt_bufs[salt_pos].salt_buf[0];
658 salt_buf[1] = salt_bufs[salt_pos].salt_buf[1];
659 salt_buf[2] = salt_bufs[salt_pos].salt_buf[2];
660 salt_buf[3] = salt_bufs[salt_pos].salt_buf[3];
666 const u32 version = oldoffice01_bufs[salt_pos].version;
668 u32 encryptedVerifier[4];
670 encryptedVerifier[0] = oldoffice01_bufs[salt_pos].encryptedVerifier[0];
671 encryptedVerifier[1] = oldoffice01_bufs[salt_pos].encryptedVerifier[1];
672 encryptedVerifier[2] = oldoffice01_bufs[salt_pos].encryptedVerifier[2];
673 encryptedVerifier[3] = oldoffice01_bufs[salt_pos].encryptedVerifier[3];
679 for (u32 il_pos = 0; il_pos < il_cnt; il_pos++)
681 const u32 pw_r_len = combs_buf[il_pos].pw_len;
683 const u32 pw_len = pw_l_len + pw_r_len;
687 wordr0[0] = combs_buf[il_pos].i[0];
688 wordr0[1] = combs_buf[il_pos].i[1];
689 wordr0[2] = combs_buf[il_pos].i[2];
690 wordr0[3] = combs_buf[il_pos].i[3];
694 wordr1[0] = combs_buf[il_pos].i[4];
695 wordr1[1] = combs_buf[il_pos].i[5];
696 wordr1[2] = combs_buf[il_pos].i[6];
697 wordr1[3] = combs_buf[il_pos].i[7];
713 if (combs_mode == COMBINATOR_MODE_BASE_LEFT)
715 switch_buffer_by_offset_le (wordr0, wordr1, wordr2, wordr3, pw_l_len);
720 w0[0] = wordl0[0] | wordr0[0];
721 w0[1] = wordl0[1] | wordr0[1];
722 w0[2] = wordl0[2] | wordr0[2];
723 w0[3] = wordl0[3] | wordr0[3];
727 w1[0] = wordl1[0] | wordr1[0];
728 w1[1] = wordl1[1] | wordr1[1];
729 w1[2] = wordl1[2] | wordr1[2];
730 w1[3] = wordl1[3] | wordr1[3];
734 w2[0] = wordl2[0] | wordr2[0];
735 w2[1] = wordl2[1] | wordr2[1];
736 w2[2] = wordl2[2] | wordr2[2];
737 w2[3] = wordl2[3] | wordr2[3];
741 w3[0] = wordl3[0] | wordr3[0];
742 w3[1] = wordl3[1] | wordr3[1];
746 append_0x80_2x4 (w0, w1, pw_len);
753 make_unicode (w0, w0_t, w1_t);
754 make_unicode (w1, w2_t, w3_t);
756 w3_t[2] = pw_len * 8 * 2;
760 digest_pre[0] = MD5M_A;
761 digest_pre[1] = MD5M_B;
762 digest_pre[2] = MD5M_C;
763 digest_pre[3] = MD5M_D;
765 md5_transform (w0_t, w1_t, w2_t, w3_t, digest_pre);
767 digest_pre[0] &= 0xffffffff;
768 digest_pre[1] &= 0x000000ff;
769 digest_pre[2] &= 0x00000000;
770 digest_pre[3] &= 0x00000000;
779 gen336 (digest_pre, salt_buf, digest);
781 // now the 40 bit input for the MD5 which then will generate the RC4 key, so it's precomputable!
784 w0_t[1] = digest[1] & 0xff;
805 md5_transform (w0_t, w1_t, w2_t, w3_t, digest);
816 rc4_init_16 (rc4_key, key);
820 u8 j = rc4_next_16 (rc4_key, 0, 0, encryptedVerifier, out);
844 md5_transform (w0_t, w1_t, w2_t, w3_t, digest);
846 rc4_next_16 (rc4_key, 16, j, digest, out);
848 const u32 r0 = out[0];
849 const u32 r1 = out[1];
850 const u32 r2 = out[2];
851 const u32 r3 = out[3];
857 __kernel void m09700_m08 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global oldoffice01_t *oldoffice01_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
861 __kernel void m09700_m16 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global oldoffice01_t *oldoffice01_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
865 __kernel void m09700_s04 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global oldoffice01_t *oldoffice01_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
871 const u32 lid = get_local_id (0);
873 __local RC4_KEY rc4_keys[64];
875 __local RC4_KEY *rc4_key = &rc4_keys[lid];
881 const u32 gid = get_global_id (0);
883 if (gid >= gid_max) return;
887 wordl0[0] = pws[gid].i[ 0];
888 wordl0[1] = pws[gid].i[ 1];
889 wordl0[2] = pws[gid].i[ 2];
890 wordl0[3] = pws[gid].i[ 3];
894 wordl1[0] = pws[gid].i[ 4];
895 wordl1[1] = pws[gid].i[ 5];
896 wordl1[2] = pws[gid].i[ 6];
897 wordl1[3] = pws[gid].i[ 7];
913 const u32 pw_l_len = pws[gid].pw_len;
915 if (combs_mode == COMBINATOR_MODE_BASE_RIGHT)
917 switch_buffer_by_offset_le (wordl0, wordl1, wordl2, wordl3, combs_buf[0].pw_len);
924 const u32 search[4] =
926 digests_buf[digests_offset].digest_buf[DGST_R0],
927 digests_buf[digests_offset].digest_buf[DGST_R1],
928 digests_buf[digests_offset].digest_buf[DGST_R2],
929 digests_buf[digests_offset].digest_buf[DGST_R3]
938 salt_buf[0] = salt_bufs[salt_pos].salt_buf[0];
939 salt_buf[1] = salt_bufs[salt_pos].salt_buf[1];
940 salt_buf[2] = salt_bufs[salt_pos].salt_buf[2];
941 salt_buf[3] = salt_bufs[salt_pos].salt_buf[3];
947 const u32 version = oldoffice01_bufs[salt_pos].version;
949 u32 encryptedVerifier[4];
951 encryptedVerifier[0] = oldoffice01_bufs[salt_pos].encryptedVerifier[0];
952 encryptedVerifier[1] = oldoffice01_bufs[salt_pos].encryptedVerifier[1];
953 encryptedVerifier[2] = oldoffice01_bufs[salt_pos].encryptedVerifier[2];
954 encryptedVerifier[3] = oldoffice01_bufs[salt_pos].encryptedVerifier[3];
960 for (u32 il_pos = 0; il_pos < il_cnt; il_pos++)
962 const u32 pw_r_len = combs_buf[il_pos].pw_len;
964 const u32 pw_len = pw_l_len + pw_r_len;
968 wordr0[0] = combs_buf[il_pos].i[0];
969 wordr0[1] = combs_buf[il_pos].i[1];
970 wordr0[2] = combs_buf[il_pos].i[2];
971 wordr0[3] = combs_buf[il_pos].i[3];
975 wordr1[0] = combs_buf[il_pos].i[4];
976 wordr1[1] = combs_buf[il_pos].i[5];
977 wordr1[2] = combs_buf[il_pos].i[6];
978 wordr1[3] = combs_buf[il_pos].i[7];
994 if (combs_mode == COMBINATOR_MODE_BASE_LEFT)
996 switch_buffer_by_offset_le (wordr0, wordr1, wordr2, wordr3, pw_l_len);
1001 w0[0] = wordl0[0] | wordr0[0];
1002 w0[1] = wordl0[1] | wordr0[1];
1003 w0[2] = wordl0[2] | wordr0[2];
1004 w0[3] = wordl0[3] | wordr0[3];
1008 w1[0] = wordl1[0] | wordr1[0];
1009 w1[1] = wordl1[1] | wordr1[1];
1010 w1[2] = wordl1[2] | wordr1[2];
1011 w1[3] = wordl1[3] | wordr1[3];
1015 w2[0] = wordl2[0] | wordr2[0];
1016 w2[1] = wordl2[1] | wordr2[1];
1017 w2[2] = wordl2[2] | wordr2[2];
1018 w2[3] = wordl2[3] | wordr2[3];
1022 w3[0] = wordl3[0] | wordr3[0];
1023 w3[1] = wordl3[1] | wordr3[1];
1027 append_0x80_2x4 (w0, w1, pw_len);
1034 make_unicode (w0, w0_t, w1_t);
1035 make_unicode (w1, w2_t, w3_t);
1037 w3_t[2] = pw_len * 8 * 2;
1041 digest_pre[0] = MD5M_A;
1042 digest_pre[1] = MD5M_B;
1043 digest_pre[2] = MD5M_C;
1044 digest_pre[3] = MD5M_D;
1046 md5_transform (w0_t, w1_t, w2_t, w3_t, digest_pre);
1048 digest_pre[0] &= 0xffffffff;
1049 digest_pre[1] &= 0x000000ff;
1050 digest_pre[2] &= 0x00000000;
1051 digest_pre[3] &= 0x00000000;
1060 gen336 (digest_pre, salt_buf, digest);
1062 // now the 40 bit input for the MD5 which then will generate the RC4 key, so it's precomputable!
1064 w0_t[0] = digest[0];
1065 w0_t[1] = digest[1] & 0xff;
1086 md5_transform (w0_t, w1_t, w2_t, w3_t, digest);
1097 rc4_init_16 (rc4_key, key);
1101 u8 j = rc4_next_16 (rc4_key, 0, 0, encryptedVerifier, out);
1125 md5_transform (w0_t, w1_t, w2_t, w3_t, digest);
1127 rc4_next_16 (rc4_key, 16, j, digest, out);
1129 const u32 r0 = out[0];
1130 const u32 r1 = out[1];
1131 const u32 r2 = out[2];
1132 const u32 r3 = out[3];
1138 __kernel void m09700_s08 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global oldoffice01_t *oldoffice01_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
1142 __kernel void m09700_s16 (__global pw_t *pws, __global kernel_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global oldoffice01_t *oldoffice01_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 il_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)