
How to find serial for:
Rusty VB Crackme 1.0
Version 1.0 by Rusty
Written by tnHuAn
|
Introduction |
Ok, now I'm very sad, I meet an accident, and i must go to the hospital. In hospital not have any PC, so I borrow a laptop from my friend. Yeah! this is a very good laptop: PIII 550 , 128 MB RAM with DVD, with this laptop, I can't setup SoftICe and some cracking tool : Hiew , W32dasm, and SmartCheck... Well, and I ask my friend give me a Crack CD, this is my CD, in this CD I write all about Cracking: tools, tutotrials, Crackmes,... Yep... My heath not good, so I can't do cracking in long time, and I have idea, I will choose a VB Crackme, coz a VB Crackme will easier to crack, I will use SmartCheck and it will give me some serial....And I choose a crackme : Rusty VB Crackme 1.0 ( I think : Version 1.0 usually easy ). But I wrong, With this crackme, SmartCheck can't help me anything, and I hate it, I must use SoftICe for this crackme...You know, to crack a VB Crackme, easiest is use SmartCheck, but now I use SoftIce, and It not simple...
|
Tools required |
|
Target's URL |
|
Essay |
Ok, first of all: this crackme is a VB Crackme, so I use smartCheck, but I can't find anything with SmartCheck, so I must use SoftICe....
Run this crackme, enter some fake name and serial . I use :
Press Ctr+D to pop up SoftICe, set a breakpoint at Hmemcpy, and Click : Register it! You will kicked into SoftICe, press F5 , then Press F12 until you in MSVBVM50.Dll code, then trace the code using F10, keep tracing until you are in the program code, you will see: this crackme packed by UPX, but it not important, you don't need unpack it... Now continue tracing until you see this code :
015F:00402634 85C0 TEST EAX,EAX
015F:00402636 0F84B7000000 JZ 004026F3 (NO JUMP)
015F:0040263C 8D85E4FEFFFF LEA EAX,[EBP-011C]
015F:00402642 8D4DDC LEA ECX,[EBP-24]
015F:00402645 50 PUSH EAX
015F:00402646 51 PUSH ECX
015F:00402647 C785ECFEFFFF01000000MOV DWORD PTR [EBP-0114],00000001
015F:00402651 89BDE4FEFFFF MOV [EBP-011C],EDI
015F:00402657 FFD3 CALL EBX
015F:00402659 50 PUSH EAX
015F:0040265A 8D55CC LEA EDX,[EBP-34]
015F:0040265D 8D85D4FEFFFF LEA EAX,[EBP-012C]
015F:00402663 52 PUSH EDX
015F:00402664 50 PUSH EAX
015F:00402665 FF155C414000 CALL [MSVBVM50!rtcMidCharVar]
015F:0040266B 8D8DD4FEFFFF LEA ECX,[EBP-012C]
015F:00402671 8D95F8FEFFFF LEA EDX,[EBP-0108]
015F:00402677 51 PUSH ECX
015F:00402678 52 PUSH EDX
015F:00402679 FF1594414000 CALL [MSVBVM50!__vbaStrVarVal]
015F:0040267F 50 PUSH EAX
015F:00402680 FF1524414000 CALL [MSVBVM50!rtcAnsiValueBstr]
015F:00402686 668985ACFEFFFF MOV [EBP-0154],AX
015F:0040268D 8D459C LEA EAX,[EBP-64]
015F:00402690 8D8DA4FEFFFF LEA ECX,[EBP-015C]
015F:00402696 50 PUSH EAX
015F:00402697 8D95C4FEFFFF LEA EDX,[EBP-013C]
015F:0040269D 51 PUSH ECX
015F:0040269E 52 PUSH EDX
015F:0040269F 89BDA4FEFFFF MOV [EBP-015C],EDI
015F:004026A5 FF15BC414000 CALL [MSVBVM50!__vbaVarAdd]
015F:004026AB 8BD0 MOV EDX,EAX
015F:004026AD 8D4D9C LEA ECX,[EBP-64]
015F:004026B0 FFD6 CALL ESI
015F:004026B2 8D8DF8FEFFFF LEA ECX,[EBP-0108]
015F:004026B8 FF15E0414000 CALL [MSVBVM50!__vbaFreeStr]
015F:004026BE 8D85D4FEFFFF LEA EAX,[EBP-012C]
015F:004026C4 8D8DE4FEFFFF LEA ECX,[EBP-011C]
015F:004026CA 50 PUSH EAX
015F:004026CB 51 PUSH ECX
015F:004026CC 57 PUSH EDI
015F:004026CD FF151C414000 CALL [MSVBVM50!__vbaFreeVarList]
015F:004026D3 83C40C ADD ESP,0C
015F:004026D6 8D956CFEFFFF LEA EDX,[EBP-0194]
015F:004026DC 8D857CFEFFFF LEA EAX,[EBP-0184]
015F:004026E2 8D4DDC LEA ECX,[EBP-24]
015F:004026E5 52 PUSH EDX
015F:004026E6 50 PUSH EAX
015F:004026E7 51 PUSH ECX
015F:004026E8 FF15D4414000 CALL [MSVBVM50!__vbaVarForNext]
015F:004026EE E941FFFFFF JMP 00402634 (JUMP )
Give me your idea about this code, it look like a loop, huh??? yeah, this loop will get each character in your name, and it will calculate, and make a serial .... If you want keygen, this code very important for you... But with my health now , I can only find correct serial, so this code not important with me.... Continue trace, until you see this code :
015F:00402752 8D95E4FEFFFF LEA EDX,[EBP-011C]
015F:00402758 8D8DFCFEFFFF LEA ECX,[EBP-0104]
015F:0040275E FFD6 CALL ESI
015F:00402760 8D8DFCFEFFFF LEA ECX,[EBP-0104]<--- Here : type d ecx
015F:00402766 8D95E4FEFFFF LEA EDX,[EBP-011C]
015F:0040276C 51 PUSH ECX
015F:0040276D 52 PUSH EDX
015F:0040276E C785BCFEFFFF01000000MOV DWORD PTR [EBP-0144],00000001
Yeah!!!, when the highlight at : 00402760 , you type : d ecx, and you will see :
20 00 35 00 32 00 37 00 34 00 37 00 32 00 30 00 .5.2.7.4.7.2.0
Do you remember ? Visual Basic not use normal character, it use WideChar ( w.i.d.e. .c.h.a.r ), so I think my correct serial is : 5274720. Test it please , in this crackme , type:
But when I click button: Register it !, he he he what I get : not a good message , I GET A BAD MESSAGE ....
So I think : I wrong, well I try again, but I can't find anything important.. So I try reverse my serial
5274720 ----> 0274725
And I test is again :
Yeh!!, It Work Good!!!!!, And I get a good message. So to register this crackme: here is correct information:
Ok, Now crackme cracked, and I think it enought for today, now I must sleep, hope I meet some good dream...
BYE...
|
Final Notes |
Ok, if you want to comment me something , please email : tnhuan19@hotmail.com
All member of HAH, and Eddile in Digital Insight
Acid_Cool_178 ( Crack my crackme#6), BiSHoP, a_evil, tKc,....
|
|