
How to make a keygen for hidden password of:
Genocide Crackme 15
Version 15.0 by Gandalf
Written by tnHuAn
|
Introduction |
I hope you still remember : I very like Genocide Crew. In this month, I very
busy , coz in my school, I have a exam. But now, I finished, and I will free
100% in next month, so I will crack crack and crack, he hehe... First my target
in thi "cracking month" is : Genocide Crew Crackme 15. Why ?
Because I like Genocide crackme.Then I choose my second target is all crackme
of "dmc crackme ", dcm crackme have : 11 crackmes with : 8
Crackmes about Name/Serial, 2 crackmes about key file, 1 crackme about
unpacking/patching. I will write all about it in my next tutorials... Now, we
will play with GENOCIDE CRACKME 15.
|
Tools required |
You can find all tool at : http://www,crackpltools.prv.pl and at your home.
|
Target's URL |
|
Essay |
Ok, first of all , run this crackme, and you will see the very cool logo , I like all logo of Genocide :). Well this crackme don't have a textbox for typing password, so I call it is : HIDDEN PASSWORD. To registers this crackme, you must type the correct password.
Now, unpack this crackme, using DEDE, and you will see a procedure : Keypress. Oh yes!it check the key when you press on the keybroad. Now, run Symbol loader, load this crackme using Symbol loader. Note : in DeDe, you will see the address when you disasembler procedure Keypress is : 00429954. In SoftIce , type : " go 00429954 " , press enter, you will return the crackme, now press anykey you want, you will break into SoftIce ( thanks tKC for teaching me this trick). Now you will see a part of code very similar this code :
00429954 55
push ebp
00429955 8BEC
mov ebp, esp
00429957 83C498
add esp, -$68
0042995A 53
push ebx
0042995B 56
push esi
0042995C 33DB
xor ebx, ebx
0042995E 895D98
mov [ebp-$68], ebx
00429961 895DFC mov [ebp-$04], ebx
00429964 8BD9
mov ebx, ecx
00429966 33C0
xor eax, eax
00429968 55
push ebp
Using F10 to trace over , until you will see this
part of code :
0042997F E8509DFDFF call 004036D4
00429984 8B5598 mov edx, [ebp-$68]
00429987 B814B74200 mov eax, $0042B714
|
0042998C E8239EFDFF call 004037B4
00429991 833D10B742000C cmp dword ptr [$42B710], +$0C <---Compare
the length with $0C= 12
00429998 0F8564010000 jnz 00429B02<---if not= will jump to
bad...
Yes, it test the length, if not = 12 , you can't continue, so you must use type the password with 12 character. When you enter enought , continue with F10 , until you see this code:
004299B1 A114B74200 mov eax, dword ptr [$42B714]<---get
the password you type
004299B6 8A00 mov al, byte ptr [eax] <--- move the
hex value of first char into al
004299B8 3447 xor al, $47 <--- Xor it with $47
004299BA 25FF000000 and eax, $000000FF <--- And the
result with $FF
004299BF 8945CC mov [ebp-$34], eax <--- move the
result into [ebp-$34]
--------------------------------------------------------------------------------------------------------
004299C2 A114B74200 mov eax, dword ptr [$42B714]
004299C7 8A4001 mov al, byte ptr [eax+$01]
004299CA 3445 xor al, $45
004299CC 25FF000000 and eax, $000000FF
<---do same above , but with 2nd char
004299D1 8945D0 mov [ebp-$30], eax
---------------------------------------------------------------------------------------
004299D4 A114B74200 mov eax, dword ptr [$42B714]
004299D9 8A4002 mov al, byte ptr [eax+$02]
004299DC 344E xor al, $4E
<---do same above , but with 3rd char
004299DE 25FF000000 and eax, $000000FF
004299E3 8945D4 mov [ebp-$2C], eax
-----------------------------------------------------------------------------------------
004299E6 A114B74200 mov eax, dword ptr [$42B714]
004299EB 8A4003 mov al, byte ptr [eax+$03]
004299EE 344F xor al, $4F
<---do same above , but with 4th char
004299F0 25FF000000 and eax, $000000FF
004299F5 8945D8 mov [ebp-$28], eax
----------------------------------------------------------------------------------------
004299F8 A114B74200 mov eax, dword ptr [$42B714]
004299FD 8A4004 mov al, byte ptr [eax+$04]
00429A00 3443 xor al, $43
<---do same above , but with 5th char
00429A02 25FF000000 and eax, $000000FF
00429A07 8945DC mov [ebp-$24], eax
--------------------------------------------------------------------------------------
00429A0A A114B74200 mov eax, dword ptr [$42B714]
00429A0F 8A4005 mov al, byte ptr [eax+$05]
00429A12 3449 xor al, $49
<---do same above , but with 6th char
00429A14 25FF000000 and eax, $000000FF
00429A19 8945E0 mov [ebp-$20], eax
-------------------------------------------------------------------------------------
00429A1C A114B74200 mov eax, dword ptr [$42B714]
00429A21 8A4006 mov al, byte ptr [eax+$06]
00429A24 3444 xor al, $44
<---do same above , but with 7th char
00429A26 25FF000000 and eax, $000000FF
00429A2B 8945E4 mov [ebp-$1C], eax
-------------------------------------------------------------------------------------
00429A2E A114B74200 mov eax, dword ptr [$42B714]
00429A33 8A4007 mov al, byte ptr [eax+$07]
00429A36 3445 xor al, $45
<---do same above , but with 8th char
00429A38 25FF000000 and eax, $000000FF
00429A3D 8945E8 mov [ebp-$18], eax
-------------------------------------------------------------------------------------
00429A40 A114B74200 mov eax, dword ptr [$42B714]
00429A45 8A4008 mov al, byte ptr [eax+$08]
00429A48 3443 xor al, $43
<---do same above , but with 9th char
00429A4A 25FF000000 and eax, $000000FF
00429A4F 8945EC mov [ebp-$14], eax
--------------------------------------------------------------------------------------
00429A52 A114B74200 mov eax, dword ptr [$42B714]
00429A57 8A4009 mov al, byte ptr [eax+$09]
00429A5A 3452 xor al, $52
<---do same above , but with 10th char
00429A5C 25FF000000 and eax, $000000FF
00429A61 8945F0 mov [ebp-$10], eax
-----------------------------------------------------------------------------------------
00429A64 A114B74200 mov eax, dword ptr [$42B714]
00429A69 8A400A mov al, byte ptr [eax+$0A]
00429A6C 3445 xor al, $45
<---do same above , but with 11th char
00429A6E 25FF000000 and eax, $000000FF
00429A73 8945F4 mov [ebp-$0C], eax
----------------------------------------------------------------------------------------
00429A76 A114B74200 mov eax, dword ptr [$42B714]
00429A7B 8A400B mov al, byte ptr [eax+$0B]
00429A7E 3457 xor al, $57
<---do same above , but with 12th char
00429A80 25FF000000 and eax, $000000FF
00429A85 8945F8 mov [ebp-$08], eax
Well now : after this routine I have 12 number which calculator by my password i
type : 76,77,7D, 7B, 76, 7F, 73, 7D, 7A, 62, 74, 65
Now we continue with this code :
00429A88 8B45CC mov eax, [ebp-$34]
<--- eax = 76 = first result
00429A8B 3345D0 xor eax, [ebp-$30] <--- xor it with
2nd result = 77.
00429A8E 89459C mov [ebp-$64], eax <--- mov result
into [ebp-$64] = 1 = 76 xor 77.
00429A91 BB0A000000 mov ebx, $0000000A <--- mov ebx =
0Ah= 10, ready for a loop
00429A96 8D55D4 lea edx, [ebp-$2C]
00429A99 8D459C lea eax, [ebp-$64]
00429A9C 8B0A mov ecx, [edx] <--- ecx contain the
3rd result
00429A9E 3308 xor ecx, [eax] <--- xor it with 1 (
the result contain in [ebp-$64] )
00429AA0 894804 mov [eax+$04], ecx <---mov the
result into [eax+04]
00429AA3 83C004 add eax, +$04 <--- eax=eax+04
00429AA6 83C204 add edx, +$04<--- edx=edx+04
00429AA9 4B dec ebx <--- ebx= ebx-1
00429AAA 75F0 jnz 00429A9C <--- if ebx != 0 then
jump to 00429A9C
Well , this loop will calculate your password, and change it to another string.It get the first result, then xor with the next number. Ex :
Then it will merge all the result , and make the new password : 11247113141250122241089.
Continue, it will compare this password with a constant password : 2517170143162210624 . Please see this code :
00429ACF 8B45FC mov eax, [ebp-$04]
<---move new password into eax
* Possible String Reference to: '2517170143162210624'
|
00429AD2 BA489B4200 mov edx, $00429B48 <--- move
constant password into edx
|
00429AD7 E8E09DFDFF call 004038BC <----Compare it
00429ADC 7513 jnz 00429AF1 <-----if not , will
jump to bad.
Well, to register this crackme, you must have a new password is : 2517170143162210624 .
Do you remember : we must enter 12 char for a password, so you must cut this string to 11 part.I will cut it to :
25 | 17 | 17 | 0 | 14| 31| 62| 21| 0 | 62 | 4 , change to Hexa : 19 | 11| 11| 0| 1F| 3E|15| 0| 3E| 4
Ok, now you will reverse this routine. Let's go : I choose my first key is : 76
Continue :
Oh yes! the correct password for this crackme is 1*FORGUdhG{m
Now , clear all breakpoint , run this crackme agian, and type : 1*FORGUdhG{m , and you will get the good message.
To make a keygen for this crackme , you must need one key, in above password the key is : 1 . Now I will make the keygen for this crackme. This keygen will allow user type a char , and we will make this char as a key. Here is my source code in VB :
Private Sub Text1_Change()
Text2.Text = ""
If Text1.Text <> "" Then
Dim ch As String
ch = Text1.Text
Dim k As Integer, Char(1 To 12) As Integer
k = Asc(ch)
Dim Cont(1 To 11) As Integer
Cont(1) = 25
Cont(2) = 17
Cont(3) = 17
Cont(4) = 0
Cont(5) = 14
Cont(6) = 31
Cont(7) = 62
Cont(8) = 21
Cont(9) = 0
Cont(10) = 62
Cont(11) = 4
Dim i As Integer
Char(1) = k Xor 71
Char(2) = Cont(1) Xor Char(1)
For i = 2 To 11
Char(i + 1) = Cont(i) Xor Cont(i - 1)
Next i
Char(1) = Char(1) Xor 71
Char(2) = Char(2) Xor 69
Char(3) = Char(3) Xor 78
Char(4) = Char(4) Xor 79
Char(5) = Char(5) Xor 67
Char(6) = Char(6) Xor 73
Char(7) = Char(7) Xor 68
Char(8) = Char(8) Xor 69
Char(9) = Char(9) Xor 67
Char(10) = Char(10) Xor 82
Char(11) = Char(11) Xor 69
Char(12) = Char(12) Xor 87
For i = 1 To 12
Text2.Text = Text2.Text + Chr((Char(i)))
Next i
End If
End Sub
Yon can code a keygen by yourselft, or Click Here to download this keygen.
|
Final Notes |
If you want comment my something about this tutorial, please email to my :
Sphinx ( Are you find? My friend. :)
BiSHoP ( for your great tutorials)
tKC ( for the trick I learn from you)
a_evil ( you are first my cracking teacher)
.... And more more, I can't remember all , sorry.
|
|