How Wand-Enhancer Bypasses ASAR Integrity Fuses Using version.dll

Wand-Enhancer disables Electron's ASAR-integrity validation by injecting a proxy version.dll that patches the fuse wire in memory while forwarding legitimate Version API calls to the system library.

The open-source tool Wand-Enhancer modifies the Wand application by circumventing Electron's cryptographic ASAR protections through native code injection. According to the k1tbyte/Wand-Enhancer repository, the technique leverages Windows DLL search order hijacking to execute privileged memory patches that disable integrity checks at runtime. This allows the enhancer to inject customized web-panel assets without triggering the application's built-in security validations.

Understanding the ASAR Integrity Fuse

Electron applications embed compile-time configuration flags known as fuses directly into the binary image. The ASAR-integrity fuse specifically controls whether the application validates the cryptographic signature of its packaged resources. When enabled, this fuse prevents modifications to the app.asar archive by aborting execution if the file's hash does not match the embedded signature.

The version.dll Proxy Injection Technique

Wand-Enhancer implements a DLL proxying strategy that exploits Windows module loading semantics. By naming the payload version.dll and placing it adjacent to the target executable, the operating system loads the custom DLL before the genuine system library located in System32. This grants the enhancer early execution within the process context while maintaining compatibility by forwarding API calls to the original implementation.

Loading the Genuine System Library

The proxy implementation in [tools/asar-fuses-bypass/library.c](https://github.com/k1tbyte/Wand-Enhancer/blob/master/tools/asar-fuses-bypass/library.c) first establishes transparent forwarding to prevent application crashes. The SourceInit function dynamically loads the authentic version.dll from the Windows system directory:

WCHAR source[MAX_PATH];
GetSystemDirectoryW(source, MAX_PATH);
wcscat_s(source, MAX_PATH, L"\\version.dll");
g_originalVersionDll = LoadLibraryW(source);

After loading the legitimate library, the code resolves all standard Version-Info API functions—such as GetFileVersionInfoA, GetFileVersionInfoSizeW, and VerQueryValueW—and generates forwarders using the FOR_EACH_VERSION_FORWARDER macro. This ensures Wand continues receiving accurate version data while the proxy prepares the memory patch.

Locating the Fuse Wire in Memory

Once loaded, the DLL invokes the bypass routine defined in [tools/asar-fuses-bypass/fuses.c](https://github.com/k1tbyte/Wand-Enhancer/blob/master/tools/asar-fuses-bypass/fuses.c). The find_fuse_wire function scans the process image for a unique 32-byte sentinel pattern that identifies the fuse structure:

FuseWire* find_fuse_wire(int offset) {
    // Scans module memory for the fuse wire sentinel
}

This signature-based search distinguishes the fuse configuration from other binary data, returning a pointer to the FuseWire structure containing the integrity validation flag.

Validating and Patching the Fuse

Before modification, the code validates the wire's version field against FUSE_VERSION_SUPPORTED (currently 1) and confirms wire_length meets FUSE_MIN_WIRE_LENGTH. These checks prevent undefined behavior when encountering incompatible Electron binaries.

The patch targets the specific index FUSE_ASAR_INTEGRITY_VALIDATION (value 4) within the fuse array. The implementation changes the state from FUSE_STATE_ENABLED ('1') to FUSE_STATE_REMOVED ('r') using memory protection manipulation:

unsigned char* target = &wire->fuses[FUSE_ASAR_INTEGRITY_VALIDATION];
VirtualProtect(target, 1, PAGE_EXECUTE_READWRITE, &oldProtect);
patch_fuse(target);  // Sets *target = 'r'
VirtualProtect(target, 1, oldProtect, &oldProtect);

This surgical byte modification effectively removes the integrity check, permitting the enhanced web panel to load from a modified app.asar without triggering security exceptions.

Implementation Details from the Source Code

The entry point orchestrating this sequence resides in the proxy's DllMain, defined in library.c:

BOOL WINAPI DllMain(HMODULE hmod, DWORD fdwReason, LPVOID lpvReserved) {
    if (fdwReason == DLL_PROCESS_ATTACH) {
        DisableThreadLibraryCalls(hmod);
        if (!SourceInit()) return FALSE;
        disable_asar_integrity();
    }
    return TRUE;
}

When Windows loads the DLL into the Wand process, DllMain executes disable_asar_integrity() immediately during process attachment, ensuring the fuse is neutralized before the application attempts to validate its resources.

Building and Deploying the Bypass

To compile the proxy DLL from the repository source:

cd tools/asar-fuses-bypass
mkdir build && cd build
cmake .. -DCMAKE_BUILD_TYPE=Release
cmake --build . --target version.dll

The resulting version.dll must be deployed to the Wand installation directory. The C# orchestration code in [WandEnhancer/Core/Enhancer.cs](https://github.com/k1tbyte/Wand-Enhancer/blob/master/WandEnhancer/Core/Enhancer.cs) handles this automatically:

string weModRoot = _weModConfig.RootDirectory;
string destPath = Path.Combine(weModRoot, "version.dll");
File.Copy(@"path\to\compiled\version.dll", destPath, overwrite: true);

Once deployed, launching Wand loads the proxy, which patches memory and forwards Version API calls transparently.

Summary

  • DLL Search Order Hijacking: Placing a custom version.dll alongside the executable forces Windows to load the proxy before the system library.
  • Transparent API Forwarding: The proxy loads the genuine version.dll from System32 and forwards all function calls to maintain application stability.
  • Memory Signature Scanning: The find_fuse_wire function locates the Electron fuse structure using a 32-byte unique sentinel pattern.
  • Surgical Byte Patching: Changing the fuse at index 4 from '1' to 'r' disables ASAR integrity validation without modifying disk files.
  • Runtime Execution: The DllMain entry point triggers the bypass during process initialization, ensuring the patch applies before security checks execute.

Frequently Asked Questions

What is Electron's ASAR integrity fuse?

The ASAR integrity fuse is a compile-time configuration embedded in Electron binaries that enables cryptographic verification of the application's app.asar package. When enabled, the runtime calculates the archive's hash and compares it against an embedded signature, terminating execution if the files have been modified.

Why does the proxy use the name version.dll specifically?

Windows executables routinely import functions from version.dll to query file version information. Because applications typically load this library early in initialization, naming the proxy version.dll ensures the injection occurs before the application performs integrity checks, while the legitimate version information APIs remain available through forwarding.

Is this bypass technique specific to the Wand application?

While Wand-Enhancer targets the Wand executable specifically, the underlying technique applies broadly to Electron applications that rely on ASAR integrity fuses. The fuse wire structure and indexing constants (such as FUSE_ASAR_INTEGRITY_VALIDATION at position 4) remain consistent across standard Electron builds, making the approach portable to other applications with similar protections.

Does patching the fuse affect application stability?

The patch modifies only a single byte in memory (changing the fuse state from '1' to 'r') without altering the executable on disk. Since the proxy forwards all version.dll API calls to the genuine system library, the application receives correct version data and behaves normally once the integrity check is disabled. However, incorrect fuse indexing on non-standard Electron builds could cause crashes or failed injections.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →