rizin/libr/magic/d/default/cafebabe
pancake 1d9955b2d4 Clean unnecessary MAGIC rules and optimize its search
- Cleanup MAGIC database to avoid false positives,
- Optimize magic search loop 6x faster /m
2014-10-22 00:56:11 +02:00

29 lines
1.3 KiB
Text

# $OpenBSD: cafebabe,v 1.3 2009/04/24 18:54:34 chl Exp $
#------------------------------------------------------------------------------
# Cafe Babes unite!
#
# Since Java bytecode and Mach-O fat-files have the same magic number, the test
# must be performed in the same "magic" sequence to get both right. The long
# at offset 4 in a mach-O fat file tells the number of architectures; the short at
# offset 4 in a Java bytecode file is the JVM minor version and the
# short at offset 6 is the JVM major version. Since there are only
# only 18 labeled Mach-O architectures at current, and the first released
# Java class format was version 43.0, we can safely choose any number
# between 18 and 39 to test the number of architectures against
# (and use as a hack). Let's not use 18, because the Mach-O people
# might add another one or two as time goes by...
#
0 beshort 0xcafe
>2 beshort 0xbabe
!:mime application/x-java-applet
#>4 belong >30 compiled Java class data,
>4 belong >30
>>6 beshort <20
>>>6 beshort x compiled Java class data version %d.
>>>4 beshort x \b%d
>>>4 belong 1 Mach-O fat file with 1 architecture
>>>4 belong >1
>>>>4 belong <20 Mach-O fat file with %ld architectures
>2 beshort 0xd00d JAR compressed with pack200
!:mime application/x-java-pack200