Winrar 2.70 bèta 2
[Reversing essay]

Subject: Cracking
Target: Winrar 2.70 bèta 2
Author: BlackB
Date: 2000-03-12
Tools used: W32DASM, Hiew
Difficulty (scale 1-5): 1

Before starting!
This essay is for knowledge purposes only!!
Software developers spend much time in making their programs. They live from the money we give them!
Please buy good software!!
I. Introduction
Enough with difficult targets! Let's get back to the old "registered-flag"-protected programs. Good for 100 % newbies......as this site is intended to ;-)
II. About the protection
40-day trial / keyfile
III. Cracking it
We won't worry about the keyfile and the calculation (coz it would be a little too complex). Instead we'll make the program believe it's registered. To do that we have to find a certain 'flag', a place where a value is stored: 1 if the program is registered, 0 if it's not.
For now, run Winrar couple of times, note that there's no option to register the program, however it's not a trial version. Let's disassemble Winrar with our favorite w32dasm! Look at the string references and note "Registered to". Search for that in the dead listing. You see this:
Start partial code
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0040B8F5(C)
|
:0040B903 803D946C460000          cmp byte ptr [00466C94], 00 <- Here's the flag compare!
:0040B90A 7472                    je 0040B97E <- Jump if not registered
:0040B90C 8DBDF0F9FFFF            lea edi, dword ptr [ebp+FFFFF9F0]
:0040B912 BEA8964700              mov esi, 004796A8
:0040B917 B981010000              mov ecx, 00000181
:0040B91C 8D85F0F9FFFF            lea eax, dword ptr [ebp+FFFFF9F0]
:0040B922 F3                      repz
:0040B923 A5                      movsd
:0040B924 50                      push eax
:0040B925 8D95F0F9FFFF            lea edx, dword ptr [ebp+FFFFF9F0]
:0040B92B 52                      push edx

* Reference To: USER32.OemToCharA, Ord:0000h
                                  |
:0040B92C E8A2650500              Call 00461ED3
:0040B931 8D8DF0FAFFFF            lea ecx, dword ptr [ebp+FFFFFAF0]
:0040B937 51                      push ecx
:0040B938 8D85F0FAFFFF            lea eax, dword ptr [ebp+FFFFFAF0]
:0040B93E 50                      push eax

* Reference To: USER32.OemToCharA, Ord:0000h
                                  |
:0040B93F E88F650500              Call 00461ED3

* Possible Reference to String Resource ID=00960: "Registered to"
                                  |
:0040B944 68C0030000              push 000003C0
:0040B949 E896C8FFFF              call 004081E4
:0040B94E 50                      push eax

End partial code

Pretty clear I guess: the registered or not flag is located at memory location 466C94. Search for all '[00466C94]' in the dead listing and note all offsets of occurences that move a certain value into the memory location. There should be three of them, like this:

Start partial code

:00418147 E8CB9B0400              Call 00461D17
:0041814C 6A01                    push 00000001
:0041814E E8C13D0200              call 0043BF14 <- Calculate if valid keyfile etc....
:00418153 A2946C4600              mov byte ptr [00466C94], al <- Move flag into mem
<- Regged==1 / Unregged==0 :00418158 6A00 push 00000000 :0041815A 8B0DECB84600 mov ecx, dword ptr [0046B8EC] :00418160 51 push ecx

End partial code

As I said, there should be three occurences at locations:
00418153
0041AD1D
004263DC
all containing 'mov byte ptr [00466C94],al' preceeded with the same call.
Now, to crack our program, we have to ensure that the 'AL'-register has '1' as value. As we can't move '1' directly into the memory location and as you would have to do this three times, we'll use the call to move the value '1' into 'AL'.
So let's take a look at 'call 0043BF14':

Start partial code

* Referenced by a CALL at Addresses:
|:0041814E   , :0041AD18   , :004263D7   <- See the three locations where it's calculated? :)
|
:0043BF14 55                      push ebp
:0043BF15 8BEC                    mov ebp, esp
:0043BF17 81C4BCF3FFFF            add esp, FFFFF3BC
:0043BF1D 53                      push ebx
:0043BF1E 56                      push esi
:0043BF1F 57                      push edi
:0043BF20 BFA8964700              mov edi, 004796A8 <- We start changing code here.
:0043BF25 B8787C4600              mov eax, 00467C78
:0043BF2A E82DE90100              call 0045A85C
:0043BF2F 57                      push edi
:0043BF30 8DBDBCFBFFFF            lea edi, dword ptr [ebp+FFFFFBBC]
:0043BF36 8BC7                    mov eax, edi
* Possible StringData Ref from Data Obj ->"rarreg.*" <- That's the keyfile

.......calculation code goes on and on.......until

:0043C2B2 5F pop edi :0043C2B3 5E pop esi :0043C2B4 5B pop ebx :0043C2B5 8BE5 mov esp, ebp :0043C2B7 5D pop ebp :0043C2B8 C20400 ret 0004

End partial code

Indeed, we'll use the code in the call for our purposes: we insert some code that makes AL==1 and then jump to the end and our program is patched!

:0043BF20 xor eax, eax
:0043BF22 mov al, 01
:0043BF24 jmp 43c2b3 (note that in Hiew you have to type the real offset, not 43c2b3!)

Run Winrar: it works fine. RAR a file and........oops.....when the trial is expired you get a message that you should register. There's another check! Okay, not difficult: set a 'bpm 466c94' in SoftICE (symbol loader, winrar.exe, then set breakpoint), SoftICE will break everytime that memory location is accessed. Ignore them. When WinRar is loaded click on add. The second popup after you clicked "add" you can see this in SoftICE:
mov dword ptr [00466C94], 00 at :0040EFD6.
To have a 100 % crack, change that instruction into mov dword ptr [00466C94], 01 and now we're really done!

IV. In the end.

Hope you enjoyed it, but most important: learned something. See you some other time (we surely will)!
Greets goto all you newbies reading this.

Greets

BlackB

Endnote:
Essay written by The Blackbird © 1999-2000
This essay can be freely distributed/ published/ printed etc... as long as no modifications are made.