Skip to content

Instantly share code, notes, and snippets.

@qgustavor
Created September 25, 2018 00:57
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save qgustavor/40b77fa5997d9b1acb5f15d74bbce0b2 to your computer and use it in GitHub Desktop.
Save qgustavor/40b77fa5997d9b1acb5f15d74bbce0b2 to your computer and use it in GitHub Desktop.
MEGA URL checksum: check if some file matches a MEGA file URL like a checksum
<!DOCTYPE html><html lang="en"><meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>MEGA URL checksum</title><style>body{margin:40px auto;max-width:650px;
font:1.1em/1.5 -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Helvetica, Arial, sans-serif;
color:#444;padding:0 10px}h1,h2,h3{line-height:1.2}
label{display:flex;flex-direction:row}input{width:100%;margin-left:1em}
@media print{body{max-width:none}}</style>
<h1>MEGA URL checksum</h1>
<p>Enter a MEGA file URL and a file and this page will check if the file corresponds to the URL.
Dead URLs still work. Folder URLs (those with "!F" in the beginning) don't work because they
don't contain the file checksum.</p>
<form>
<label>URL: <input type="url"></label>
<label>File: <input type="file"></label>
<br>
<button>Check</button> <output></output>
</form>
<script src="https://cdnjs.cloudflare.com/ajax/libs/sjcl/1.0.7/sjcl.min.js" integrity="sha384-X0mQP9Ee57CRKxDlf/55LrrCIwWvXucDZvxkZ/rO5WF2By9Lwva4rEFd2LZLogOs" crossorigin="anonymous"></script>
<script src="https://cdn.rawgit.com/bitwiseshiftleft/sjcl/cc887b518c026407e4ad11ecef37ad9e40d4bd40/core/codecArrayBuffer.js" integrity="sha384-lVE6SeS3AsYL2Aa+6Gebj7kJAELvdqbItqycfASLo8x0cX0loPWIFSBdnMrcJExh" crossorigin="anonymous"></script>
<script>
var outputEl = document.querySelector('output')
document.forms[0].addEventListener('submit', function (e) {
e.preventDefault()
var url = this.elements[0].value
var file = this.elements[1].files[0]
if (!url) {
outputEl.textContent = 'Missing URL'
return
}
if (!file) {
outputEl.textContent = 'Missing file'
return
}
var parsedURL = url.match(/https:\/\/mega\.(?:co\.)?nz\/#![^!]{3,}!([A-Za-z0-9-_]{10,})/)
if (!parsedURL) {
outputEl.textContent = 'Invalid URL'
return
}
var keySum = sjcl.codec.base64url.toBits(parsedURL[1])
for (var i = 0; i < 4; i++) keySum[i] = keySum[i] ^ keySum[i + 4]
var aes = new sjcl.cipher.aes(keySum.slice(0, 4))
var nonce = keySum.slice(4, 6)
var checksum = keySum.slice(6, 8)
nonce = nonce.concat(nonce)
processFile({
aes: aes,
checksum: checksum,
file: file,
finalMac: [0, 0, 0, 0],
increment: 131072,
mac: nonce.slice(),
nonce: nonce,
pos: 0,
posNext: 131072
})
})
var blockSize = 1024 * 1024
function processFile (state) {
outputEl.textContent = 'Processing: ' +
(state.pos * 100 / state.file.size).toFixed(2) +
'% - ' + state.pos + ' / ' + state.file.size
var reader = new FileReader()
var slice = state.file.slice(state.pos, state.pos + blockSize)
reader.addEventListener('load', function () {
handleBlock(sjcl.codec.arrayBuffer.toBits(reader.result), state)
if (state.pos >= state.file.size) {
finishChecksum(state)
} else {
processFile(state)
}
})
reader.readAsArrayBuffer(slice)
}
function handleBlock (result, state) {
for (var pos = 0; pos < result.length; pos += 4) {
for (var i = 0; i < 4; i++) state.mac[i] ^= result[pos + i]
state.mac = state.aes.encrypt(state.mac)
checkBounding(state)
}
}
function checkBounding (state) {
state.pos += 16
if (state.pos >= state.posNext) {
for (var i = 0; i < 4; i++) state.finalMac[i] ^= state.mac[i]
state.finalMac = state.aes.encrypt(state.finalMac)
state.mac = state.nonce.slice()
if (state.increment < 1048576) state.increment += 131072
state.posNext += state.increment
}
}
function finishChecksum (state) {
for (var i = 0; i < 4; i++) state.finalMac[i] ^= state.mac[i]
var mac = state.aes.encrypt(state.finalMac)
var sum = state.checksum
outputEl.textContent = mac[0] ^ mac[1] === sum[0] && mac[2] ^ mac[3] === sum[1]
? 'Checksum matches'
: "Checksum don't matches"
}
</script>
@qgustavor
Copy link
Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment