老外发布了一篇通用解包器制作工具QuickBMS的图文教程,想学制作解包器的朋友可以仔细看看。 其实不是太难的。
& z$ Z; m3 x2 S, |7 y
& w8 V% F* U* p, j原文 9 ^0 p1 N {, a! O& G' f- l* K# J+ r
http://forum.xentax.com/viewtopi ... 0&sk=t&sd=a
' x4 {' {9 B4 s$ ?, {
* b, [2 q/ h! r# ?4 TI am going to make a tutorial for using quickbms for extracting archives that are no extractors for.
' ?; w; X/ l8 oI am going to start off easy then add more and more difficult archives so you can learn and write your own scripts. - C+ p2 N+ U) e
the tools you need are just 4 things. - z7 o' r) s, K& D
1. A HEX editor I use HxD - Q; H, g+ g- E$ d
2.Quick BMS http://aluigi.org/papers/quickbms.zip
* [: g1 x- C6 O3. a text editor like wordpad
% S5 ^2 |, O4 Y# W0 M; P6 P0 }4. a calculator that supports hex like the one built into windows.
; \* ^5 R+ p" L9 `We will start with a game called FEZ (Fantasy Earth Zero)
2 ^* E$ o* A7 X1 |$ ?. d0 sthis is a great archive format for someone to learn bms scripting from.
, L+ v( ?/ l, R) `0 PI attached a sample.
; G% Y5 g g g. Owebsite http://tw.fez.gamania.com/ c% `. L' d- t1 l# i" ~; v
installer http://tw.dl.gamania.com/fez/FEZ_1103.exe / R/ f8 {% @6 R; t! f5 E
this game uses textures with wrong headers mainly dds and some tga and some kind of .mdl format.
7 J2 x2 x/ o: Q' O. _0 {5 m! N+ b u; T6 w) Z; M' ~* Z7 a
ok so you can download the full installer or this sample pac file here
0 Z) M7 R: G7 ohttp://www.MegaShare.com/1029061 4 h# @3 U. a9 _- O5 b1 y! u5 e( u
ok so open the file up in your hex editor so you see what I have open here
o: Q: P5 y1 R: K7 S8 h% `
- i+ Y, r5 y, j& v+ R0 m# | M, L7 W7 o7 W2 B; n% [! a/ g
9 Z+ F$ a) V# B4 `so if you look to the right you will notice some readable text & r' K# J8 ^' c# M8 Y2 j1 q
Etc\aura.tex , Etc\cursor.tex , Etc\mahoujin.tex , Etc\env2.tex , and Etc\kaze.tex . 2 Y3 ~7 m- n& v4 Q2 y
so just looking with out eyes we now know that there are at least 5 files in this bin file and after we extract them they will be placed in a folder called Etc.
3 R4 M5 e* e% d& Oso lets start looking at the other parts of the header in this file we will start with the first 4 bytes + H" H; \/ A9 j, L! H; e
- Q/ @( U) T, r: U8 twell we have 05 00 00 00 Y5 E' w. q+ v0 R: R3 ^* P
whenever you are working with archives for computer games 99% of the time you read the values in reverse so the above number
9 |# l% f+ v' L6 f* u; @would not be 5,000,000 but instead would be read as 00 00 00 05 or 5
' q4 ]1 U5 R$ g9 P% T3 |' mWell if we remember from earlier we saw 5 file names and our first 4 bytes of our file are equal to 5 so there is a good chance we just discovered where the file count is stored in this archive.
, k+ P, S5 o: ]2 mdata is stored in groups of 4 bytes " a long" 2 bytes " a short" or 1 byte "a byte" so we have our first part of our script
7 m$ N X0 D3 V! q- N' ^get FILES long
) ~, s1 ]' y& ]this tells quickbms to read a long value "aka 4 bytes" and store it as the variable FILES.
# \7 l" [1 } p( Hok the next 4 bytes 74 00 00 00 are not needed in order for quickbms to extract our files but it represents the total size of our header. / Z& y; g' @2 d, p
0 A! W( L+ _* _2 a& ?- T
so I will write the next line of code for quickbms
, v" s9 E* }% V4 ~7 iget HEADERSZ long * [+ Y7 Z* v+ A* M# F# o* g
this stores the header size in the variable HEADERSZ
. m- i, @7 q: f5 v: R+ \ok now we have 2 more bytes before the file name : k& F3 `" Z. }5 o; |3 z5 S
so that is 0C 00 well 2 bytes is know as a short. but what does 00 0C stand for?
; R1 o. m+ A. e% U' U) o4 z; hif we highlight the whole name of the file in out hex editor it shows us a length of C / V' A0 r7 `1 W" C& Q- U
we found the name length so we would write that as 4 o2 E% C* {+ z" L2 Z" {
get NSIZE short
}( q0 X$ K4 t% l4 S) Z. M. ?this stores the 2 bytes in the variable NSIZE representing the length of the name
/ @/ q1 f4 j0 @6 q" r( z ! y2 x% t/ a7 p6 w# p& y r
well next comes the name so to store that as a word in bms language we will write the next line
0 F$ ?- D7 i6 l, jgetdstring NAME NSIZE 1 p2 i/ \( Z) ?, P/ b; }
this is saying store a string "aka a word" in the variable NAME and its length is equal to the variable NSIZE. ( A6 i+ H. ~; ~6 ~$ K' P2 m4 b
ok now we have another 4 bytes after the name 7C 00 00 00 z* ^: V% p. a- u5 \8 K% @1 n0 i
well we already know the name of the file so now to extract the file we need to know its size and location in the archive. ' F0 k! r' r5 c0 [4 B
7C is not a very big number for the size of the file to lets see what happens if we go to offset 7C $ C# k3 O- K$ s: j$ d8 T0 R
in HxD press ctrl +E and type in 7c for the start and end then click ok. ) A# H1 z: w* S4 L8 s% b2 Q
7 T1 R$ }' X. {
you should look like this after clicking ok # c% Q2 C. a( M
* G t, J" p* e. Jhmm this looks good it looks like a file header IMG0 so we will write out line saying that is the start of the file
# Q2 ~0 {$ s- L/ eget OFFSET long
- @7 U% `5 i) p% [4 S8 t2 w; Nthis stores the 4 bytes as the variable OFFSET
- |3 p3 o* j) n0 d: Cok the next 4 bytes are 70 10 00 00 well that looks bigger so lets see if that is the size of out file so it will translate into 00 00 10 70 or 1070 ( p+ |3 [* _9 ]/ T" ]4 Z
so lets go to our offset 7C and then we will add in the length column 1070 # Q# I; i6 v+ n
, g( r( p; t3 P# G8 i0 ]wow look at that I see TRUEVISION-XFILE that is a classic tga ending and we also end just before IMG0 which was the start of our first file $ N$ q* d D M- A! F
; S! Z: V' Y0 N: O: G0 Zso that means we found our size 4 {2 [8 S5 ^7 e( N: A8 s+ t& \( x
we write that as
: d. x/ h5 `5 u% S* Y0 H. dget SIZE long ' J' d; L4 s0 g+ O4 E$ d
this stores the 4 bytes in the variable SIZE
* b( R- `+ m# l5 qok now we have 2 bytes then the next file name hmm that seems familiar ! c5 O4 ]* V' h
lets see 0E 00so that means it translates into 00 0E or E
/ D0 G$ A. z# J1 s: O/ T3 Gwell the last 2 bytes we had before a name was the name size lets see if it still holds true : [, u$ h( h) a
1 h( K8 p! E1 r& ?( v9 h
it does the name length is E / q/ A2 s6 g: Z& t# M
so that means we found where the pattern in the header repeats and we identified all that we need to extract the files so now we can finish our script and our extractor.
! b7 h5 A+ N6 V# y; q% p" e. qwhenever the pattern starts you want to begin a loop so it will keep cycling through it until there are no files left. the easiest way to write that is.
J& t( n$ o" pfor i = 0 < FILES
& ~3 B( A! w4 }- n! E# gthis means run the following commands until i = 0 and set i = FILES
1 Y2 i. d' b8 i/ w* Rso we will put that before our NSIZE variable because that is where the pattern starts.
* T9 k7 ~! m/ H$ Z# o: wnext you want it to write out the file and we do that with the log command in the following format
l1 L7 ]; S2 j6 S6 i" q9 Xlog NAME OFFSET SIZE ! {7 c0 U- T1 J1 q+ N' C* R" C5 W
this says write the file name and fill it with the data starting at the variable OFFSET and a length of SIZE.
$ O- o& z. i; tnow this is great but we want it to keep repeating the loop till there are no more files so we must add ( X( F- d: `9 r3 j- ? S* ]
next i
2 e3 _0 V+ _2 Sat the end so the loop continues. 7 t) k# V1 U% X0 H
ok so now save the file we created as extract.bms - X1 n1 |9 n; r' x( s. I* m3 _
and put Etc.pac extract.bms and quickbms.exe all in the same folder for wthis demo we will say c:\temp
) m* i4 A, G/ [* l0 I7 I9 {% Cso now at the command prompt change to that directory and type ) [# Y5 E' A! J, J: R
quickbms.exe -l extract.bms Etc.pac .
; m' q) ~, r5 ithis will list the the file contents and size or give you an error if your script is not correct.
. _: i) f- U$ x( v; p5 ~( cYay it worked 0 _0 k m. l" P( z- G* y
2 n4 A) p% d. v( mnow lets try extracting them create a folder in c:\temp called extracted
: H4 T7 l8 [. k2 `now type the command / K+ s7 [. L4 W( g5 A3 u
quickbms.exe extract.bms Etc.pac extracted
$ |$ g/ Z7 g, a, w& jyes it worked now they are in the filder and extracted. ; r6 {6 h! n5 Y) p$ {/ I2 M8 `& l, r
. d! n+ ~' ?( N' f
7 v* A" F# z' g) r c
Code:
: S& e* l) ]# R% I3 P- D* uget FILES long 2 u* h* T( l5 W% ]* Z, V0 M- p
get HEADERSZ long 2 O" K& M8 ~6 z, j+ _- I# T3 ~
for i = 0 < FILES
+ }, r B8 s2 ^. p8 b3 q$ jget NSIZE short / V8 J$ n% S+ z6 J9 ^: a
getdstring NAME NSIZE 0 \+ n7 [. s8 Z8 e7 R" T
get OFFSET long
9 |! O3 m& p: c* Y, ?2 m8 i5 bget SIZE long
" a1 O' K. A) o5 z6 S2 [: E7 g6 k: p8 L* k9 u, E$ L
log NAME OFFSET SIZE . M" f( r+ R, G' F& Z. `# o% i n
next i 8 L3 p, c- T7 e2 ~% s1 z
/ e0 B. t( b; P1 [+ m. X* _Let me know what you think of this tutorial and if you want me to continue on with more examples and more compex scripts. |