|
Winrar 2.70 bèta 2
|
|
|
|
Subject: Cracking |
|
This essay is for knowledge purposes only!! Software developers spend much time in making their programs. They live from the money we give them! Please buy good software!! |
| I. Introduction |
| Enough with difficult targets! Let's get back to the old "registered-flag"-protected programs. Good for 100 % newbies......as this site is intended to ;-) |
| II. About the protection |
| 40-day trial / keyfile |
| III. Cracking it |
| We won't worry about the keyfile and the calculation (coz
it would be a little too complex). Instead we'll make the program believe
it's registered. To do that we have to find a certain 'flag', a place where
a value is stored: 1 if the program is registered, 0 if it's not. For now, run Winrar couple of times, note that there's no option to register the program, however it's not a trial version. Let's disassemble Winrar with our favorite w32dasm! Look at the string references and note "Registered to". Search for that in the dead listing. You see this: Start partial code
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0040B8F5(C)
|
:0040B903 803D946C460000 cmp byte ptr [00466C94], 00 <- Here's the flag compare!
:0040B90A 7472 je 0040B97E <- Jump if not registered
:0040B90C 8DBDF0F9FFFF lea edi, dword ptr [ebp+FFFFF9F0]
:0040B912 BEA8964700 mov esi, 004796A8
:0040B917 B981010000 mov ecx, 00000181
:0040B91C 8D85F0F9FFFF lea eax, dword ptr [ebp+FFFFF9F0]
:0040B922 F3 repz
:0040B923 A5 movsd
:0040B924 50 push eax
:0040B925 8D95F0F9FFFF lea edx, dword ptr [ebp+FFFFF9F0]
:0040B92B 52 push edx
* Reference To: USER32.OemToCharA, Ord:0000h
|
:0040B92C E8A2650500 Call 00461ED3
:0040B931 8D8DF0FAFFFF lea ecx, dword ptr [ebp+FFFFFAF0]
:0040B937 51 push ecx
:0040B938 8D85F0FAFFFF lea eax, dword ptr [ebp+FFFFFAF0]
:0040B93E 50 push eax
* Reference To: USER32.OemToCharA, Ord:0000h
|
:0040B93F E88F650500 Call 00461ED3
* Possible Reference to String Resource ID=00960: "Registered to"
|
:0040B944 68C0030000 push 000003C0
:0040B949 E896C8FFFF call 004081E4
:0040B94E 50 push eax
End partial code Pretty clear I guess: the registered or not flag is located at memory
location 466C94. Search for all '[00466C94]'
in the dead listing and note all offsets of occurences that move a certain
value into the memory location. There should be three of them, like this: :00418147 E8CB9B0400 Call 00461D17 :0041814C 6A01 push 00000001 :0041814E E8C13D0200 call 0043BF14 <- Calculate if valid keyfile etc.... :00418153 A2946C4600 mov byte ptr [00466C94], al <- Move flag into mem End partial code As I said, there should be three occurences at locations: Start partial code * Referenced by a CALL at Addresses: |:0041814E , :0041AD18 , :004263D7 <- See the three locations where it's calculated? :) | :0043BF14 55 push ebp :0043BF15 8BEC mov ebp, esp :0043BF17 81C4BCF3FFFF add esp, FFFFF3BC :0043BF1D 53 push ebx :0043BF1E 56 push esi :0043BF1F 57 push edi :0043BF20 BFA8964700 mov edi, 004796A8 <- We start changing code here. :0043BF25 B8787C4600 mov eax, 00467C78 :0043BF2A E82DE90100 call 0045A85C :0043BF2F 57 push edi :0043BF30 8DBDBCFBFFFF lea edi, dword ptr [ebp+FFFFFBBC] :0043BF36 8BC7 mov eax, edi * Possible StringData Ref from Data Obj ->"rarreg.*" <- That's the keyfile End partial code Run Winrar: it works fine. RAR a file and........oops.....when the trial
is expired you get a message that you should register. There's another
check! Okay, not difficult: set a 'bpm 466c94' in SoftICE (symbol loader,
winrar.exe, then set breakpoint), SoftICE will break everytime that memory
location is accessed. Ignore them. When WinRar is loaded click on add.
The second popup after you clicked "add" you can see this in
SoftICE: |
| IV. In the end. |
|
Hope you enjoyed it, but most important: learned something. See you some
other time (we surely will)! Greets BlackB |
|
Essay written by The Blackbird © 1999-2000 This essay can be freely distributed/ published/ printed etc... as long as no modifications are made. |