NAME

nbdkit-xor-filter - obfuscate contents of a plugin with XOR

SYNOPSIS

 nbdkit --filter=xor [PLUGIN ARGS ...] xor=VALUE xorlen=LENBYTES

 nbdkit --filter=xor [PLUGIN ARGS ...] xor=rand[:SEED]

DESCRIPTION

nbdkit-xor-filter is a filter for nbdkit(1) which XORs (exclusive or) a value across all of the data in the underlying plugin. This can be used to obfuscate the contents of a plugin or as a trivial, insecure, but fast type of encryption. For proper encryption, see nbdkit-luks-filter(1).

This filter has two modes. You can XOR with a fixed repeating pattern:

 nbdkit file disk.img --filter=xor xor=0xDEADBEEF xorlen=4

Or you can XOR with the output of a pseudo-random number generator (PRNG) with an optional seed by using xor=rand[:SEED]. The result is more obfuscated. In this mode xorlen is not used:

 nbdkit file disk.img --filter=xor xor=rand:1984

This filter does not currently support sparse plugins. Trim operations will fill the backing plugin with XORed zeroes (which makes it easy to read out the "key", another reason why this is not secure).

PARAMETERS

xor=VALUE

The value to be XORed with the underlying data. This is truncated or extended to xorlen bytes. Usually you want to specify this in hex using the 0x prefix.

The value is big endian. For example xor=0x123456 xorlen=3 will XOR bytes as follows:

 data:     A0 A1 A2 A3 A4 A5 A6
 XOR with: 12 34 56 12 34 56 12
           ────────────────────
 result:   B2 95 F4 B1 90 F3 B4
xor=rand
xor=rand:SEED

XOR the underlying data with the output of a pseudo-random number generator (PRNG). Optionally a seed for the PRNG may be given (otherwise the seed is 0).

The xor parameter is required.

xorlen=LENBYTES

The length of the XOR value, in bytes. Any length from 1 to 8 is supported.

This parameter is required when using xor=VALUE and should not be set for xor=rand.

FILES

$filterdir/nbdkit-xor-filter.so

The filter.

Use nbdkit --dump-config to find the location of $filterdir.

VERSION

nbdkit-xor-filter first appeared in nbdkit 1.48.

SEE ALSO

nbdkit(1), nbdkit-file-plugin(1), nbdkit-luks-filter(1), nbdkit-map-filter(1), nbdkit-pattern-plugin(1), nbdkit-random-plugin(1), nbdkit-swab-filter(1), nbdkit-filter(3), nbdkit_parse_uint64_t(3).

AUTHORS

Richard W.M. Jones

COPYRIGHT

Copyright Red Hat

LICENSE

Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:

THIS SOFTWARE IS PROVIDED BY RED HAT AND CONTRIBUTORS ''AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL RED HAT OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.