|
Spamkiller v2.76
|
|
|
|
Subject: Cracking |
|
This essay is for knowledge purposes only!! Software developers spend much time in making their programs. They live from the money we give them! Please buy good software!! |
| I. Introduction |
| Hi cracker! Back for more? Good....coz here is another reversing essay! This time I'll show you how to reverse Spamkiller. This time we won't try to patch it, no, we'll fish for a serial. And what serial? A hardcoded one!! That means: the hardcoded serial works with all usernames and companies you fill in!! So no need to make a keygen :-) |
| II. About the protection |
| Has some anti-sice (easy to remove). Further we won't bother about other protections like the trial as we're looking for a serial. |
| III. Cracking it |
|
When I first got my hands on Spamkiller I tried to patch it. However,
I never succeeded in doing it and I became quite frustrated. I didn't
try to find a serial as I thought it would be too hard. But as I had nothing
to loose I gave it a try......god it was dead easy and I even found a
hardcoded serial! :-)
End partial code
End partial code
Start
partial code * Referenced by a CALL at Address:
|:004D10AA
|
:004AC1B0 55 push ebp
:004AC1B1 8BEC mov ebp, esp
:004AC1B3 6A00 push 00000000
:004AC1B5 33C0 xor eax, eax
:004AC1B7 55 push ebp
:004AC1B8 6832C24A00 push 004AC232
:004AC1BD 64FF30 push dword ptr fs:[eax]
:004AC1C0 648920 mov dword ptr fs:[eax], esp
:004AC1C3 A190094E00 mov eax, dword ptr [004E0990]
:004AC1C8 803800 cmp byte ptr [eax], 00
:004AC1CB 740F je 004AC1DC
:004AC1CD 8D45FC lea eax, dword ptr [ebp-04]
* Possible StringData Ref from Code Obj ->"\\.\NTICE"
|
:004AC1D0 BA44C24A00 mov edx, 004AC244
:004AC1D5 E8A27BF5FF call 00403D7C
:004AC1DA EB0D jmp 004AC1E9
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:004AC1CB(C)
|
:004AC1DC 8D45FC lea eax, dword ptr [ebp-04]
* Possible StringData Ref from Code Obj ->"\\.\SICE"
|
:004AC1DF BA58C24A00 mov edx, 004AC258
:004AC1E4 E8937BF5FF call 00403D7C
End partial code To prevent Spamkiller checking for SoftICE, just put a 'ret' instruction in the very beginning of the call. That makes: Before patching: 004AC1B0 55 push ebp After patching: 004AC1B0 C3 ret That's it my dear reader! |
| IV. In the end |
|
Goodbye fellow cracker. Hope you learned something. |
|
Essay written by The Blackbird © 1999-2000 This essay can be freely distributed/ published/ printed etc... as long as no modifications are made. |