
Make a keygen for: Genocide Crew Crackme 9
Version 9.0 by Gandalf
Written by tnHuAn
|
Introduction |
Hey, another tutorial about Genocide Crew Crackme. In this tutorial , I will
show you : HOW MAKE A KEYGEN FOR GENOCIDE CREW CRACKME 9. This is not a
difficult crackme, but it isn't a very easy crackme. I think this crackme is
very good for newbie , who want to learn reversing code. Now , let's crack this
crackme.
|
Tools required |
You can find all tool at : http://crackpltools.prv.pl and at your home.
|
Target's URL |
http://www.genocidecrew.cjb.net
|
Essay |
Hmm, I use SoftIce for WinNT/2K , so I can't use Hmemcpy as a breakpoint. Why? Because in Win2K haven't Hmemcpy in Kernel32.dll. What break point I usually in Win2K ? I usually : GetdlgitemtextA, GetWindowTextA, but this crackme is coded in Delphi, so I can't use GetDlgItemTextA , GetWindowTextA as a breakpoint. Hmm,... I will use a trick which I learn from tKC. I read about trick in tKC 's tutorial, all his tutorials very good for all cracker ( I think ).
Well, If you read tKC 's tutorials, or you read my last tutorial about CheckBox Crackme, you will know this trick. Now, run the crackme, and decomplie this crackme in Dede, disasmble procedure : Button1Click. You will find this address : 00427B48. Ok, load this crackme in SoftIce Symbol loader, in SoftIce, type : G 00427B48, press Enter, you will return the crackme, then enter your fake serial, click Check .Oh, you breaked at good code.... Thanks tKC for this trick....Now you will see this code :
00427B48 55 push ebp
00427B49 8BEC mov ebp, esp
00427B4B 6A00 push $00
00427B4D 53 push ebx
00427B4E 8BD8 mov ebx, eax
00427B50 33C0 xor eax, eax
00427B52 55 push ebp
Using F10 to trace the code, until you see this code:
00427B8F A264974200 mov byte ptr [$429764], al
00427B94 803D6497420005 cmp byte ptr [$429764], $05
00427B9B 752D jnz 00427BCA
00427B9D A160974200 mov eax, dword ptr [$429760]
|
00427BA2 E811FFFFFF call 00427AB8 <--- Press F8 to trace
into this call
00427BA7 803D6597420000 cmp byte ptr [$429765], $00
00427BAE 751A jnz 00427BCA
00427BB0 6A00 push $00
At this line : 00427BA2 , using F8 to trace into the call , in this call using
F10 to trace the code, until you see this code :
00427AC3 E8C0FFFFFF call 00427A88
<---- Make a constant array.....
00427AC8 C6056597420001 mov byte ptr [$429765], $01 <---- first
byte at 429765 = 01
00427ACF C6042401 mov byte ptr [esp], $01<--- first
byte of Esp = 01
00427AD3 83FB03 cmp ebx, +$03 <--- compare Ebx with
03
00427AD6 7C2F jl 00427B07 <--- if < then jump
to 00427B07
00427AD8 8BC3 mov eax, ebx <--- Eax = Ebx = your
fake serial in Hex.
00427ADA BF03000000 mov edi, $00000003 <--- Edi = 03
00427ADF 99 cdq
00427AE0 F7FF idiv edi <--- Eax = Eax / Edi , and
Dl = Eax mod Edi
00427AE2 33C9 xor ecx, ecx <--- Ecx = 0
00427AE4 8A0C24 mov cl, byte ptr [esp] <--- Cl =
first byte of Esp
00427AE7 88540EFF mov [esi+ecx-$01], dl <--- First
byte of [ Esi + Ecx - 01 ] = Dl = Eax mod Edi
00427AEB 8BC3 mov eax, ebx <--- Eax = Ebx
00427AED BB03000000 mov ebx, $00000003 <--- Ebx = 03
00427AF2 99 cdq
00427AF3 F7FB idiv ebx <--- Eax = Eax / Ebx
00427AF5 8BD8 mov ebx, eax <--- Ebx =
Eax
00427AF7 83FB03 cmp ebx, +$03 <--- Compare Ebx with
03
00427AFA 7D03 jnl 00427AFF
00427AFC 881C0E mov [esi+ecx], bl <--- First byte
of [ esi + ecx ] = Bl
00427AFF FE0424 inc byte ptr [esp] <--- First byte
of Esp will add 01
00427B02 83FB03 cmp ebx, +$03 <--- Compare Ebx with
03
00427B05 7DD1 jnl 00427AD8
00427B07 8A0C24 mov cl, byte ptr [esp] <--- Cl =
First byte of Esp
00427B0A 80F901 cmp cl, $01 <--- Compare Cl with 01
00427B0D 7231 jb 00427B40
00427B0F 33C0 xor eax, eax <---- Eax = 0
00427B11 8AC1 mov al, cl <--- Compare Al with Cl
00427B13 8D4406FF lea eax, [esi+eax-$01]
00427B17 33D2 xor edx, edx <---- Edx = 0
00427B19 8AD1 mov dl, cl <---- Dl = Cl
00427B1B 81C247974200 add edx, $00429747
00427B21 8A1A mov bl, byte ptr [edx] <--- Bl
= first byte of Edx
00427B23 3A18 cmp bl, byte ptr [eax] <---- Compare
bl with first byte of Eax
00427B25 7509 jnz 00427B30 <--- if = then jump to
00427B30...
00427B27 C6056597420000 mov byte ptr [$429765], $00
00427B2E EB09 jmp 00427B39 <--- jump to 00427B39
00427B30 C6056597420001 mov byte ptr [$429765], $01
00427B37 EB07 jmp 00427B40
00427B39 49 dec ecx <--- Ecx = Ecx-1
00427B3A 4A dec edx <--- Edx = Edx -1
00427B3B 48 dec eax <--- Eax = Eax -1
00427B3C 84C9 test cl, cl <--- Test Cl
00427B3E 75E1 jnz 00427B21 <--- If Cl <>0
then jump to 00427B21
00427B40 5A pop edx
00427B41 5F pop edi
00427B42 5E pop esi
00427B43 5B pop ebx
00427B44 C3 ret
Look at this part of code , first it make a constant array, you can get this array by : at 00427AC3 , you trace into this call, and you will get constant array like this array :
[ 00, 02, 00, 02, 00, 01, 02, 02, 01, 00, 02,00 ]
Then, it get your serial, and change it to Hex value, and divide it with 3. Ex :
Your serial is:00013, change to Hex = 0D, 0D/3 = 4 , and 07 mod 3 = 01,Dl will = 01, and Cl = the time divide to 3 =1 time, Continue: 4/3=1, 4 mod 3= 01, Dl will = 01, Cl= 02.
And it will make the second array, with all result of your serial mod 3. Ex :
Do you uderstand? I hope you will understand what I say.... Ok, continue, it compare this array with contanst array. I call the name of contanst array is : contanst , and name of second array is : second, and the time your serial divide to 3 is: times.You will register if : For i:=times downto 1 : Constant[times]=Second[times-1]
Well, I will calculate one of correct serial , with the times = 6. Begin :
Contanst = [ 00, 02, 00, 02, 00, 01, 02, 02, 01, 00, 02,00 ]
If you want register , second array must = [ 02, 00, 02, 00, 01, 02 ].
Because the times= 6, so we must begin with the value = 02.Begin the calcultion:
Because: Constant[ times]=Second[times-1], and times=6, so we finish at times-1 = 5.
And the the serial must have the length = 5 , so the correct serial is : 00587.
Ok, you can calculate many correct serial, but I think you can code a keygen, and it will calculate correct serial for you. Huh ? You can see my source code of keygen, I hope it will help some thing for your.
Keygen SourceCode :
Private Sub Command1_Click()
Dim a As Variant
Dim b As Variant
Dim Constant(0 To 11) As Integer
Constant(0) = 0
Constant(1) = 2
Constant(2) = 0
Constant(3) = 2
Constant(4) = 0
Constant(5) = 1
Constant(6) = 2
Constant(7) = 2
Constant(8) = 1
Constant(9) = 0
Constant(10) = 2
Constant(11) = 0
On Error GoTo Loi
Dim i As Integer
a = Text1.Text
b = Constant(a)
i = a - 1
Do
b = b * 3 + Constant(i)
i = i - 1
Loop Until i = 0
Dim s As String
s = b
If Len(s) < 5 Then
Do
s = "0" + s
Loop Until Len(s) = 5
End If
Text2.Text = s
Exit Sub
Loi:
Dim Ms1 As Integer
Ms1 = MsgBox("Please enter X as a interger value: with X >=2 and X <=11 ", vbCritical + vbOKOnly, "Error")
Text1.SetFocus
End Sub
If you don't know how to code a keygen, you can try my keygen. I included it here!
|
Final Notes |
If you need help, need a keygen, or want comment me something about this tutorial, please:
And all I miss.
|
|