Wp2LaTeX could read encrypted documents for wordperfect 4.x and 5.x.
Unfortunatally I have insufficient information about Wordperfect 6.x
Please could you tell me any information about used encryption
method. Do you know some document, link or any other source of
information?
No knowledge of OLE is needed. I could provide to anybody several series
of data unencrypted and encrypted with different passwords. So there is
also no need for knowledge of wordperfect internal objects.
(I am not interested in password cracking only in decrypting).
I know this:
1, The date is somehow stored and influences data.
2, Data are XORead with some serie of data.
3, The seed of serie is stored from 20h to 96h.
4, Most probably the LFSR algorithm is employed but I am unable to
guess polynom order.
5, Some block is placed after data.
Findings from Grok:
Salt 0x1A–0x1F NoTime-based (shared when clock frozen)
Confirmed machine
text2FFB (every 16 bytes of buffer, when outer DI==0):
for di = 0..3:
DX:AX ‹ next_output(control) ; counters++, helpers, table index
lane ‹ Table[f·4 + di] ; Table @ 63F9:2F9F, values ? {0,1,2,3}
State[lane] ‹ DX:AX ; 16 bytes @ SS:1A82
return
Outer (63F9:254A..25B8):
for each 4-byte chunk of buffer:
xor with State words
write back
DI = (DI+1) & 3
if DI==0: call 2FFB
Full next_output structure
text; control @ ES:0010
; ---- counters mod 55 ----
control[+2] = (control[+2] + 1) % 55 ; rA
control[+4] = (control[+4] + 1) % 55 ; rB
; (exact inc/div order matches what you stepped)
; ---- raw dword from 55-entry table ----
; table base at segment offs 0x28 (= control + 0x18)
BX = 0x10 + rB * 4
raw_lo = word ES:[BX + 0x1A] ; e.g. 4C42
raw_hi = word ES:[BX + 0x18] ; e.g. 1976
; ---- mix using rA (code after 2E5A) ----
BX = rA * 4
SI = 0x10 + rA * 4 ; another slot in control
; … mix raw into control / state (xor/add/…) …
; final dword ends up at control ~+0x68, +0x6C, … per lane
; ---- return ----
DX:AX = final dword ; lane0: E9A0:F4DF lane1: 2382:5833
retf 4
Documents:
alleged WP6 cipher.pdf obtained from
Dr Fauzan Mirza