How to crack Eternal Bliss' vbcrackme10


Howdy gang :)

My thanks goes out to EB for writing all of these fun crackmes.  It was
because of this crackme that I discovered a little bug in ExDec :)

This tutorial will explain how to crack it.  As with my other tutorials,
I'll show code and give you a simple explanation of everything.  My writing
skills aren't the best and my tutorials usually need more explaining, so if
you have any suggestions or comments email me: josephco_@hotmail.com



First of all, we'll run the program.  You'll notice that there are 24 little
boxes you can check or uncheck.  Clicking on some random boxes and hitting
the check button.. nothing happens.  We'll open the program with ExDec and
see what we're able to find.  Digging through some of the code, we come up
with some interesting code:

4043FA: e7 CI4UI1                 
4043FB: f5 LitI4:                  0x1  1  (....)
404400: c7 EqI4                   
404401: 1a FFree1Ad                local_00A8
404404: 1c BranchF:                404410
404407: 28 LitVarI2:               ( local_00A4 ) 0x1  (1)     'important
40440C: Lead1/f6 FStVar           
404410: 04 FLdRfVar                local_00AA
404413: 21 FLdPrThis              
404414: 0f VCallAd                 7b3fc3f0
404417: 19 FStAdFunc               local_00A8
40441A: 08 FLdPr                   local_00A8
40441D: 0d VCallHresult            7b3fbf08
404422: 6b FLdI2                   local_00AA
404425: e7 CI4UI1                 
404426: f5 LitI4:                  0x1  1  (....)
40442B: c7 EqI4                   
40442C: 1a FFree1Ad                local_00A8
40442F: 1c BranchF:                404442
404432: 04 FLdRfVar                local_0094
404435: 28 LitVarI2:               ( local_00A4 ) 0x2  (2)     'important
40443A: Lead0/94 AddVar            local_00BC
40443E: Lead1/f6 FStVar           
404442: 04 FLdRfVar                local_00AA
404445: 21 FLdPrThis              
404446: 0f VCallAd                 7b3fc3e8
404449: 19 FStAdFunc               local_00A8
40444C: 08 FLdPr                   local_00A8
40444F: 0d VCallHresult            7b3fbf08
404454: 6b FLdI2                   local_00AA
404457: e7 CI4UI1                 
404458: f5 LitI4:                  0x1  1  (....)
40445D: c7 EqI4                   
40445E: 1a FFree1Ad                local_00A8
404461: 1c BranchF:                404474
404464: 04 FLdRfVar                local_0094
404467: 28 LitVarI2:               ( local_00A4 ) 0x4  (4)     'important
40446C: Lead0/94 AddVar            local_00BC
404470: Lead1/f6 FStVar           
404474: 04 FLdRfVar                local_00AA
404477: 21 FLdPrThis              
404478: 0f VCallAd                 7b3fc3e0
40447B: 19 FStAdFunc               local_00A8
40447E: 08 FLdPr                   local_00A8
404481: 0d VCallHresult            7b3fbf08
404486: 6b FLdI2                   local_00AA
404489: e7 CI4UI1                 
40448A: f5 LitI4:                  0x1  1  (....)
40448F: c7 EqI4                   
404490: 1a FFree1Ad                local_00A8
404493: 1c BranchF:                4044A6
404496: 04 FLdRfVar                local_0094
404499: 28 LitVarI2:               ( local_00A4 ) 0x8  (8)     'important
40449E: Lead0/94 AddVar            local_00BC
4044A2: Lead1/f6 FStVar           
4044A6: 04 FLdRfVar                local_00AA
...
...
...
40488A: f5 LitI4:                  0x1  1  (....)
40488F: c7 EqI4                   
404890: 1a FFree1Ad                local_00A8
404893: 1c BranchF:                4048A9
404896: 04 FLdRfVar                local_0094
404899: Lead3/c1 LitVarI4:         ( local_param_FF5C ) 0x800000  (8388608)
4048A1: Lead0/94 AddVar            local_00BC
4048A5: Lead1/f6 FStVar           
4048A9: 04 FLdRfVar                local_0094
4048AC: Lead3/c1 LitVarI4:         ( local_param_FF5C ) 0x7715eb  (7804395)
4048B4: 5d HardType               
4048B5: Lead0/33 EqVarBool        
4048B7: 1c BranchF:                4048E3
4048BA: 27 LitVar_Missing         
4048BD: 27 LitVar_Missing         
4048C0: 27 LitVar_Missing         
4048C3: f5 LitI4:                  0x0  0  (....)
4048C8: 3a LitVarStr:              ( local_00A4 ) You have solved it...
4048CD: 4e FStVarCopyObj           local_00BC
4048D0: 04 FLdRfVar                local_00BC
4048D3: 0a ImpAdCallFPR4:          rtcMsgBox

There's too much code to show it all, but the spots marked as "important" are
what we're looking at.  There are (by coincedence or by fate?) 24 of these
spots.  This corresponds to the number of boxes we have :)  Looking at the
numbers on the side, you'll notice that the numbers increase 1,2,4,8,16,32,64
and so on.  As luck would have it, this is exactly how binary works!  At
4048ac we get another hex number, and then there is a compare shortly after.
The key to cracking this is to get a hex to bin converter and find out
what 0x7715eb would be.  After a few keystrokes, you will come up with:
011101110001010111101011.  1 = on | 0 = off OR 1 = CHECKED | 0 = UNCHECKED
Since binary is BACKWARDS we'll need to check the boxes in this order:
110101111010100011101110.  Hit the CHECK button and then a messagebox appears
saying "You have solved it..."

As I've said earlier, my tutorial skills aren't the best so if you have any
questions.. email me :)

joe
