
Crackme 2.75 By BuLLeT [TOL '98]
Visual Basic 5
Written by McCodEMaN
Introduction |
Greetings and welcome to the noble art of reverse engineering!
Tools required |
SmartCheck
SoftIce
Target's URL |
http://crackmes.cjb.net
Essay |
First Approach: Using SmartCheck!
Run Smartcheck and configure the settings, like this:
Under Program/settings menu:
*ERROR DETECTION: Check all boxes except 'Report errors immediately'
*ADVANCED SETTINGS: Check the first four boxes. The others should be emty!
*REPORTING: All boxes should be checked
except the one for:
'Report Mouse Move events from ocx controls'
Ok, Smartcheck is ready, are you?
Press F5 to run the program, then type any serial you like. When
you have clicked "Verify"
you recive a: Nope. That's not the one!
Oh yae, i know that, exit the program.
Right then, lets take a look and see what we get from all this, shall we?!
Click on the: Command1_Click and we will see this:
Mid
Mid
Mid
Mid
Mid
Mid
Text1.Text
Command1Caption <--"Verify" (string)
Text1.Text <--"Nope.Thats not the one!" (string)
Place the blue bar at the first Text1.Text and under "View" choose "show all events".
You will now see a bunch of: __vbaVarAdd......
Here they are:
__vbaVarAdd returns DWORD:63F344
= "2rK4"
= "HJ4"
__vbaVarAdd returns DWORD:63F334
= "2rK4HJ4"
= "-"
__vbaVarAdd returns DWORD:63F324
= "2rK4HJ4-"
= "7n8Rg"
__vbaVarAdd returns DWORD:63F314
= "2rK4HJ4-7n8Rg"
= "T09IW"
__vbaVarAdd returns DWORD:63F304
= "2rK4HJ4-7n8RgT09IW"
= "6a7kSl"
__vbaVarAdd returns DWORD:63F2F4
= "2rK4HJ4-7n8RgT09IW6a7kSl"
= "g33"
__vbaVarTstEq returns DWORD:0
= "2rK4HJ4-7n8RgT09IW6a7kSlg33"
Second Approach: Using SoftIce!
Step1 Run the crackme and enter a fakeserial, then place a bp
on __multibytetowidechar
Step2 Press F11
Step3 And we step through the code and find the valid serial at:
:0F0414F3 MOV EBP, EAX <= eax contains our valid serial!
If
you can't see the hole serial, run through the prot-window it's all there.
Step4 And at:
:0F0414FF PUSH EBP => valid serial!
:0F041501 PUSH
ESI => fake serial!
Ok, thats it...but before we quite i'll tell you one more way to crack this program, witch also is described by Prophecy in a txt-file that comes with the crackme zipfile.
Place a bp on __vbaStrComp
Type dd esp to see whats pushed to the stack.
d 00411560 => valid serial!
Final Notes |
I would like to thank:
tKC, for everything!
Razzia, for making me interested in VB in the first place!
Jeff, for making me come back to the VB environment after a long vacation!
Eternal Bliss, for providing us with a great VB source!
| BACK |