Check Box Crackme

Version 5.0 by Gandalf

Written by tnHuAn


Introduction

Hi, Welcome to another my tutorial. This tutorial about Genocide Crew Crackme, I like all Genocide Crew Crackmes, but I don't know why this group not update their website. Hmm, this crackme is one of speacial crackme: it is Check Box Crackme. 
I choose this crackme because I hope newbies can learn something about : How to crack a checkbox crackme. And aim of this crackme with show you: how to break in SoftIce  when you can't find a correct breakpoint. Remember , We always use Hmemcpy as a best breackpoint, but in Win2000 you can't use Hmemcpy. Hmm , you must choose: or find 1 new break point to replace Hmemcpy, or you don't have a best break point as Hmemcpy.

Now, Let 's crack it.Here we go......

Tools required

You can find all tool at : http://crackpltools.prv.pl and at your home.

Target's URL

    http://genocidecrew.cjb.net

Essay

Ok, Fist you must run this crackme
You will see a matrix with 5 row and 5 columns. Hmm, do you see the : INVAIL , is mean :
you uncracked this crackme. To register this crackme, you must check to correct checkbox.
Now, you check random the checkbox, then set a breakpoint : GetdlgitemtextA, 
GetwindowTextA or Hmemcpy, then click Cheack, hmm not breack. Our problem now is: find the 
Correct breakpoint. Ok, not a big problem, If you already read some tKC 's tutorials, you 
will know where you will break. So , I special thank tKC for teach me this method.
OK, load this crackme in DeDe, wait some minute, then choose the Procedures Tab, and look
at in the left window, you will see 2 Unit Name : About and chbk5. Choose Unit : chbk5
Look at the right window, you will see many Event, double click on event : Button3Click.
You will see this code :
0042D3D8   53                     push    ebx
0042D3D9   56                     push    esi
0042D3DA   57                     push    edi
0042D3DB   83C4F8                 add     esp, -$08
0042D3DE   BE7DF74200             mov     esi, $0042F77D
0042D3E3   C6042401               mov     byte ptr [esp], $01
0042D3E7   BF64F74200             mov     edi, $0042F764
0042D3EC   C744240448F74200       mov     dword ptr [esp+$04], $0042F748
Remember this address : 0042D3D8, we will use it.
Now, prees Ctrl+D, to pop up SoftIce, then set a breakpoint at : ShowWindow , so type in
SoftIce: Bpx ShowWindow, press Enter. Well, press F5 to return the crackme, Click the 
"About" button, oh, SoftIce breaked, type in SoftICe : g 0042D3D8, press Enter , you will
return the crackme, click the " Check " button, you will break in SoftIce.
Now we are at the correct breackpoint,in softice, you will this code :
0042D3D8   53                     push    ebx
0042D3D9   56                     push    esi
0042D3DA   57                     push    edi
0042D3DB   83C4F8                 add     esp, -$08
0042D3DE   BE7DF74200             mov     esi, $0042F77D
0042D3E3   C6042401               mov     byte ptr [esp], $01
0042D3E7   BF64F74200             mov     edi, $0042F764
0042D3EC   C744240448F74200       mov     dword ptr [esp+$04], $0042F748
0042D3F4   B101                   mov     cl, $01
0042D3F6   8BC7                   mov     eax, edi
0042D3F8   8B542404               mov     edx, [esp+$04]
0042D3FC   8A18                   mov     bl, byte ptr [eax]
0042D3FE   3A1A                   cmp     bl, byte ptr [edx]
0042D400   7405                   jz      0042D407
0042D402   C60601                 mov     byte ptr [esi], $01
0042D405   EB1C                   jmp     0042D423
0042D407   C60600                 mov     byte ptr [esi], $00
0042D40A   41                     inc     ecx
0042D40B   42                     inc     edx
0042D40C   40                     inc     eax
0042D40D   80F906                 cmp     cl, $06
0042D410   75EA                   jnz     0042D3FC
0042D412   FE0424                 inc     byte ptr [esp]
0042D415   8344240405             add     dword ptr [esp+$04], +$05
0042D41A   83C705                 add     edi, +$05
0042D41D   803C2406               cmp     byte ptr [esp], $06
0042D421   75D1                   jnz     0042D3F4
0042D423   803E01                 cmp     byte ptr [esi], $01
0042D426   7517                   jnz     0042D43F

Do you see this line : 0042D3FE   3A1A                   cmp     bl, byte ptr [edx].

Now at this line : you type : d edx, press Enter, then look at the data window in SoftIce, look the left, you will see:

Hmm, look at above, you can write into a matrix with 5 rows and 5 columns :

Well, this is a matrix we need, you can check the check box same this matrix , huh . And you crackme will be : 



Well, Crackme is cracked simply. huh?

Final Notes

I hope after read this tutorial , you can know something about Cracking skill for 
CheckBox Crackme. Thanks GanDalf for this crackme. It very good.



My Greetz Goes to:


When ever there is a door,
there is an entrance.
And behind an entrance can no secret hide,
when a cracker takes his knowledge for a ride
                                                                               McCodEMaN



ObDuh

The information in this essay is for educational purpose only!
You are only allow to crack, reverse engineer, modify code and debugg programs that you legaly bought and then for personal use only!!
To ignore this warning is a criminell act and can result in lawful actions!

So please note!
I take no responebility for how you use the information in this essay, i take NO responebility for what might happen to you or your computer!
You use this information on your own risk!!

What i mean is: Please buy the software!








Essay written by tnHuAn ŠTRES2000. All Rights Reserved.