# How Wand-Enhancer Bypasses ASAR Integrity Fuses Using version.dll

> Discover how Wand-Enhancer bypasses ASAR integrity fuses with version.dll. Learn how it injects a proxy DLL to patch fuse wires in memory and maintain ASAR integrity.

- Repository: [k1tbyte/Wand-Enhancer](https://github.com/k1tbyte/Wand-Enhancer)
- Tags: internals
- Published: 2026-09-01

---

**Wand-Enhancer disables Electron's ASAR-integrity validation by injecting a proxy version.dll that patches the fuse wire in memory while forwarding legitimate Version API calls to the system library.**

The open-source tool Wand-Enhancer modifies the Wand application by circumventing Electron's cryptographic ASAR protections through native code injection. According to the k1tbyte/Wand-Enhancer repository, the technique leverages Windows DLL search order hijacking to execute privileged memory patches that disable integrity checks at runtime. This allows the enhancer to inject customized web-panel assets without triggering the application's built-in security validations.

## Understanding the ASAR Integrity Fuse

Electron applications embed compile-time configuration flags known as **fuses** directly into the binary image. The ASAR-integrity fuse specifically controls whether the application validates the cryptographic signature of its packaged resources. When enabled, this fuse prevents modifications to the `app.asar` archive by aborting execution if the file's hash does not match the embedded signature.

## The version.dll Proxy Injection Technique

Wand-Enhancer implements a **DLL proxying** strategy that exploits Windows module loading semantics. By naming the payload `version.dll` and placing it adjacent to the target executable, the operating system loads the custom DLL before the genuine system library located in `System32`. This grants the enhancer early execution within the process context while maintaining compatibility by forwarding API calls to the original implementation.

### Loading the Genuine System Library

The proxy implementation in [[`tools/asar-fuses-bypass/library.c`](https://github.com/k1tbyte/Wand-Enhancer/blob/main/tools/asar-fuses-bypass/library.c)](https://github.com/k1tbyte/Wand-Enhancer/blob/master/tools/asar-fuses-bypass/library.c) first establishes transparent forwarding to prevent application crashes. The `SourceInit` function dynamically loads the authentic `version.dll` from the Windows system directory:

```c
WCHAR source[MAX_PATH];
GetSystemDirectoryW(source, MAX_PATH);
wcscat_s(source, MAX_PATH, L"\\version.dll");
g_originalVersionDll = LoadLibraryW(source);

```

After loading the legitimate library, the code resolves all standard Version-Info API functions—such as `GetFileVersionInfoA`, `GetFileVersionInfoSizeW`, and `VerQueryValueW`—and generates forwarders using the `FOR_EACH_VERSION_FORWARDER` macro. This ensures Wand continues receiving accurate version data while the proxy prepares the memory patch.

### Locating the Fuse Wire in Memory

Once loaded, the DLL invokes the bypass routine defined in [[`tools/asar-fuses-bypass/fuses.c`](https://github.com/k1tbyte/Wand-Enhancer/blob/main/tools/asar-fuses-bypass/fuses.c)](https://github.com/k1tbyte/Wand-Enhancer/blob/master/tools/asar-fuses-bypass/fuses.c). The `find_fuse_wire` function scans the process image for a unique 32-byte sentinel pattern that identifies the fuse structure:

```c
FuseWire* find_fuse_wire(int offset) {
    // Scans module memory for the fuse wire sentinel
}

```

This signature-based search distinguishes the fuse configuration from other binary data, returning a pointer to the `FuseWire` structure containing the integrity validation flag.

### Validating and Patching the Fuse

Before modification, the code validates the wire's `version` field against `FUSE_VERSION_SUPPORTED` (currently `1`) and confirms `wire_length` meets `FUSE_MIN_WIRE_LENGTH`. These checks prevent undefined behavior when encountering incompatible Electron binaries.

The patch targets the specific index `FUSE_ASAR_INTEGRITY_VALIDATION` (value `4`) within the fuse array. The implementation changes the state from `FUSE_STATE_ENABLED` (`'1'`) to `FUSE_STATE_REMOVED` (`'r'`) using memory protection manipulation:

```c
unsigned char* target = &wire->fuses[FUSE_ASAR_INTEGRITY_VALIDATION];
VirtualProtect(target, 1, PAGE_EXECUTE_READWRITE, &oldProtect);
patch_fuse(target);  // Sets *target = 'r'
VirtualProtect(target, 1, oldProtect, &oldProtect);

```

This surgical byte modification effectively removes the integrity check, permitting the enhanced web panel to load from a modified `app.asar` without triggering security exceptions.

## Implementation Details from the Source Code

The entry point orchestrating this sequence resides in the proxy's `DllMain`, defined in [`library.c`](https://github.com/k1tbyte/Wand-Enhancer/blob/main/library.c):

```c
BOOL WINAPI DllMain(HMODULE hmod, DWORD fdwReason, LPVOID lpvReserved) {
    if (fdwReason == DLL_PROCESS_ATTACH) {
        DisableThreadLibraryCalls(hmod);
        if (!SourceInit()) return FALSE;
        disable_asar_integrity();
    }
    return TRUE;
}

```

When Windows loads the DLL into the Wand process, `DllMain` executes `disable_asar_integrity()` immediately during process attachment, ensuring the fuse is neutralized before the application attempts to validate its resources.

## Building and Deploying the Bypass

To compile the proxy DLL from the repository source:

```bash
cd tools/asar-fuses-bypass
mkdir build && cd build
cmake .. -DCMAKE_BUILD_TYPE=Release
cmake --build . --target version.dll

```

The resulting `version.dll` must be deployed to the Wand installation directory. The C# orchestration code in [[`WandEnhancer/Core/Enhancer.cs`](https://github.com/k1tbyte/Wand-Enhancer/blob/main/WandEnhancer/Core/Enhancer.cs)](https://github.com/k1tbyte/Wand-Enhancer/blob/master/WandEnhancer/Core/Enhancer.cs) handles this automatically:

```csharp
string weModRoot = _weModConfig.RootDirectory;
string destPath = Path.Combine(weModRoot, "version.dll");
File.Copy(@"path\to\compiled\version.dll", destPath, overwrite: true);

```

Once deployed, launching Wand loads the proxy, which patches memory and forwards Version API calls transparently.

## Summary

- **DLL Search Order Hijacking**: Placing a custom `version.dll` alongside the executable forces Windows to load the proxy before the system library.
- **Transparent API Forwarding**: The proxy loads the genuine `version.dll` from `System32` and forwards all function calls to maintain application stability.
- **Memory Signature Scanning**: The `find_fuse_wire` function locates the Electron fuse structure using a 32-byte unique sentinel pattern.
- **Surgical Byte Patching**: Changing the fuse at index `4` from `'1'` to `'r'` disables ASAR integrity validation without modifying disk files.
- **Runtime Execution**: The `DllMain` entry point triggers the bypass during process initialization, ensuring the patch applies before security checks execute.

## Frequently Asked Questions

### What is Electron's ASAR integrity fuse?

The ASAR integrity fuse is a compile-time configuration embedded in Electron binaries that enables cryptographic verification of the application's `app.asar` package. When enabled, the runtime calculates the archive's hash and compares it against an embedded signature, terminating execution if the files have been modified.

### Why does the proxy use the name version.dll specifically?

Windows executables routinely import functions from `version.dll` to query file version information. Because applications typically load this library early in initialization, naming the proxy `version.dll` ensures the injection occurs before the application performs integrity checks, while the legitimate version information APIs remain available through forwarding.

### Is this bypass technique specific to the Wand application?

While Wand-Enhancer targets the Wand executable specifically, the underlying technique applies broadly to Electron applications that rely on ASAR integrity fuses. The fuse wire structure and indexing constants (such as `FUSE_ASAR_INTEGRITY_VALIDATION` at position `4`) remain consistent across standard Electron builds, making the approach portable to other applications with similar protections.

### Does patching the fuse affect application stability?

The patch modifies only a single byte in memory (changing the fuse state from `'1'` to `'r'`) without altering the executable on disk. Since the proxy forwards all `version.dll` API calls to the genuine system library, the application receives correct version data and behaves normally once the integrity check is disabled. However, incorrect fuse indexing on non-standard Electron builds could cause crashes or failed injections.