INNER CODE UNIT · C#

GetConfirmPath

ghostvectoracademy/DLLHijackHunter · src/DLLHijackHunter/Canary/CanaryDllBuilder.cs:105

    public static string GetConfirmPath(string deployPath) =>
        Path.Combine(CanaryDir, $"canary_{DeployHash(deployPath)}.confirm");

    /// <summary>
    /// FNV-1a 64-bit over the ASCII deploy path with A-Z folded to a-z, formatted as 16 lowercase
    /// hex digits. Mirrors <c>fnv1a()</c> in Resources/canary_src.c exactly. ASCII paths only.
    /// </summary>
    internal static string DeployHash(string path)
    {
        ulong h = 0xcbf29ce484222325UL;
        foreach (char c in path)
        {
            int b = c & 0xFF;
            if (b >= 'A' && b <= 'Z') b += 0x20;
            h ^= (byte)b;
            h *= 0x100000001b3UL;
        }
        return h.ToString("x16");

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…