How to make a keygen for hidden password of: 

Genocide Crackme 15

Version 15.0 by Gandalf

Written by tnHuAn


Introduction

I hope you still remember : I very like Genocide Crew. In this month, I very busy , coz in my school, I have a exam. But now, I finished, and I will free 100% in next month, so I will crack crack and crack, he hehe... First my target in thi  "cracking month" is : Genocide Crew Crackme 15. Why ? Because I like Genocide crackme.Then I choose my second target is all crackme of  "dmc crackme ", dcm crackme have : 11 crackmes with : 8 Crackmes about Name/Serial, 2 crackmes about key file, 1 crackme about unpacking/patching. I will write all about it in my next tutorials... Now, we will play with GENOCIDE CRACKME 15.

Tools required

You can find all tool at : http://www,crackpltools.prv.pl and at your home.

Target's URL

    http://genocidecrew.cjb.net

Essay

Ok, first of all , run this crackme, and you will see the very cool logo , I like all logo of Genocide :). Well this crackme don't have a textbox for typing password, so I call it is : HIDDEN PASSWORD. To registers this crackme, you must type the correct password.

Now, unpack this crackme, using DEDE, and you will see a procedure : Keypress. Oh yes!it check the key when you press on the keybroad. Now, run Symbol loader, load this crackme using Symbol loader. Note : in DeDe, you will see the address when you disasembler procedure Keypress is : 00429954. In SoftIce , type : " go 00429954 " , press enter, you will return the crackme, now press anykey you want, you will break into SoftIce ( thanks tKC for teaching me this trick). Now you will see a part of code very similar this code :

00429954     55                  push ebp
00429955     8BEC             mov ebp, esp
00429957     83C498         add esp, -$68
0042995A     53                 push ebx
0042995B     56                 push esi
0042995C     33DB           xor ebx, ebx
0042995E     895D98        mov [ebp-$68], ebx
00429961     895DFC       mov [ebp-$04], ebx
00429964     8BD9           mov ebx, ecx
00429966     33C0            xor eax, eax
00429968     55                 push ebp
Using F10 to trace over , until you will see this part of code : 

0042997F E8509DFDFF call 004036D4
00429984 8B5598 mov edx, [ebp-$68]
00429987 B814B74200 mov eax, $0042B714

|
0042998C E8239EFDFF call 004037B4
00429991 833D10B742000C cmp dword ptr [$42B710], +$0C <---Compare the length with $0C= 12
00429998 0F8564010000 jnz 00429B02<---if not= will jump to bad...

Yes, it test the length, if not = 12 , you can't continue, so you must use type the password with 12 character. When you enter enought , continue with F10 , until you see this code: 

004299B1 A114B74200 mov eax, dword ptr [$42B714]<---get the password you type
004299B6 8A00 mov al, byte ptr [eax] <--- move the hex value of first char into al
004299B8 3447 xor al, $47 <--- Xor it with $47
004299BA 25FF000000 and eax, $000000FF <--- And the result  with $FF
004299BF 8945CC mov [ebp-$34], eax <--- move the result into [ebp-$34]

--------------------------------------------------------------------------------------------------------
004299C2 A114B74200 mov eax, dword ptr [$42B714]   
004299C7 8A4001 mov al, byte ptr [eax+$01]                   
004299CA 3445 xor al, $45                                                   
004299CC 25FF000000 and eax, $000000FF                  <---do same above , but with 2nd char  
004299D1 8945D0 mov [ebp-$30], eax

---------------------------------------------------------------------------------------
004299D4 A114B74200 mov eax, dword ptr [$42B714]
004299D9 8A4002 mov al, byte ptr [eax+$02]
004299DC 344E xor al, $4E                        <---do same above , but with 3rd char
004299DE 25FF000000 and eax, $000000FF
004299E3 8945D4 mov [ebp-$2C], eax

-----------------------------------------------------------------------------------------
004299E6 A114B74200 mov eax, dword ptr [$42B714]
004299EB 8A4003 mov al, byte ptr [eax+$03]
004299EE 344F xor al, $4F                                        <---do same above , but with 4th char
004299F0 25FF000000 and eax, $000000FF
004299F5 8945D8 mov [ebp-$28], eax

----------------------------------------------------------------------------------------
004299F8 A114B74200 mov eax, dword ptr [$42B714]
004299FD 8A4004 mov al, byte ptr [eax+$04]
00429A00 3443 xor al, $43                                        <---do same above , but with 5th char
00429A02 25FF000000 and eax, $000000FF
00429A07 8945DC mov [ebp-$24], eax

--------------------------------------------------------------------------------------
00429A0A A114B74200 mov eax, dword ptr [$42B714]
00429A0F 8A4005 mov al, byte ptr [eax+$05]
00429A12 3449 xor al, $49                                            <---do same above , but with 6th char
00429A14 25FF000000 and eax, $000000FF
00429A19 8945E0 mov [ebp-$20], eax

-------------------------------------------------------------------------------------
00429A1C A114B74200 mov eax, dword ptr [$42B714]
00429A21 8A4006 mov al, byte ptr [eax+$06]
00429A24 3444 xor al, $44                                    <---do same above , but with 7th char
00429A26 25FF000000 and eax, $000000FF
00429A2B 8945E4 mov [ebp-$1C], eax

-------------------------------------------------------------------------------------
00429A2E A114B74200 mov eax, dword ptr [$42B714]
00429A33 8A4007 mov al, byte ptr [eax+$07]
00429A36 3445 xor al, $45                                <---do same above , but with 8th char
00429A38 25FF000000 and eax, $000000FF
00429A3D 8945E8 mov [ebp-$18], eax

-------------------------------------------------------------------------------------
00429A40 A114B74200 mov eax, dword ptr [$42B714]
00429A45 8A4008 mov al, byte ptr [eax+$08]
00429A48 3443 xor al, $43                                            <---do same above , but with 9th char
00429A4A 25FF000000 and eax, $000000FF
00429A4F 8945EC mov [ebp-$14], eax

--------------------------------------------------------------------------------------
00429A52 A114B74200 mov eax, dword ptr [$42B714]
00429A57 8A4009 mov al, byte ptr [eax+$09]
00429A5A 3452 xor al, $52                                <---do same above , but with 10th char
00429A5C 25FF000000 and eax, $000000FF
00429A61 8945F0 mov [ebp-$10], eax

-----------------------------------------------------------------------------------------
00429A64 A114B74200 mov eax, dword ptr [$42B714]
00429A69 8A400A mov al, byte ptr [eax+$0A]
00429A6C 3445 xor al, $45                            <---do same above , but with 11th char
00429A6E 25FF000000 and eax, $000000FF
00429A73 8945F4 mov [ebp-$0C], eax

----------------------------------------------------------------------------------------
00429A76 A114B74200 mov eax, dword ptr [$42B714]
00429A7B 8A400B mov al, byte ptr [eax+$0B]
00429A7E 3457 xor al, $57                                <---do same above , but with 12th char
00429A80 25FF000000 and eax, $000000FF
00429A85 8945F8 mov [ebp-$08], eax

Well now : after this routine I have 12 number which calculator by my password i type : 76,77,7D, 7B, 76, 7F, 73, 7D, 7A, 62, 74, 65

Now we continue with this code :

00429A88 8B45CC mov eax, [ebp-$34] <--- eax = 76 = first result
00429A8B 3345D0 xor eax, [ebp-$30] <--- xor it with 2nd result = 77. 
00429A8E 89459C mov [ebp-$64], eax <--- mov result into [ebp-$64] = 1 = 76 xor 77.
00429A91 BB0A000000 mov ebx, $0000000A <--- mov ebx = 0Ah= 10, ready for a loop
00429A96 8D55D4 lea edx, [ebp-$2C] 
00429A99 8D459C lea eax, [ebp-$64]
00429A9C 8B0A mov ecx, [edx] <--- ecx contain the 3rd result
00429A9E 3308 xor ecx, [eax] <--- xor it with 1 ( the result contain in [ebp-$64] )
00429AA0 894804 mov [eax+$04], ecx <---mov the result into [eax+04]
00429AA3 83C004 add eax, +$04 <--- eax=eax+04
00429AA6 83C204 add edx, +$04<--- edx=edx+04
00429AA9 4B dec ebx <--- ebx= ebx-1
00429AAA 75F0 jnz 00429A9C <--- if ebx != 0 then jump to 00429A9C

Well , this loop will calculate your password, and change it to another string.It get the first result, then xor with the next number. Ex :

  1. 76 XOR 77 = 1 --->  DECIMAL : 1
  2. 7D XOR 1 = 7C----> 124
  3. 7B XOR 7C = 7 ----> 7
  4. 76 XOR 7 = 71 ----> 113
  5. 7F XOR 71 = E ---> 14
  6. 73 XOR E = 7D --->125
  7. 7D XOR 7D = 0 ---> 0
  8. 7A XOR 00 = 7A --->122
  9. 62 XOR 7A = 18 --->24
  10. 74 XOR 18 = 6C --->108
  11. 65 XOR 6C = 9 ---->9

Then it will merge all the result , and make the new password : 11247113141250122241089.

Continue, it will compare this password with a constant password : 2517170143162210624 . Please see this code : 

00429ACF 8B45FC mov eax, [ebp-$04] <---move new password into eax

* Possible String Reference to: '2517170143162210624'
|
00429AD2 BA489B4200 mov edx, $00429B48 <--- move constant password into edx

|
00429AD7 E8E09DFDFF call 004038BC <----Compare it
00429ADC 7513 jnz 00429AF1 <-----if not , will jump to bad.

Well, to register this crackme, you must have a new password is : 2517170143162210624 .

Do you remember : we must enter 12 char for a password, so you must cut this string to 11 part.I will cut it to : 

25 | 17 | 17 | 0 | 14| 31| 62| 21| 0 | 62 | 4 , change to Hexa : 19 | 11| 11| 0| 1F| 3E|15| 0| 3E| 4

Ok, now you will reverse this routine. Let's go : I choose my first key is : 76

  1. 76 XOR 6F = 19
  2. 8 XOR 19 = 11
  3. 0 XOR 11= 11
  4. 11 XOR 11 = 0
  5. E XOR 0 = E
  6. 11 XOR E = 1F
  7. 21 XOR 1F = 3E
  8. 2B XOR 3E = 15
  9. 15 XOR 15 = 0
  10. 3E XOR 0 = 3E
  11. 3A XOR 3E = 4

Continue :

  1. 76 XOR 47 = 31 --->  chang to asscii : 1
  2. 6F XOR 45= 2A ---> *
  3. 8 XOR 4E = 46 ---> F
  4. 0 XOR 4F = 4F ---> O
  5. 11 XOR 43= 52 ---> R
  6. E XOR 49= 47 ----> G
  7. 11 XOR 44= 55 ----> U
  8. 21 XOR 45= 64 ----> d
  9. 2B XOR 43= 68 ----> h
  10. 15 XOR 52= 47 ----> G
  11. 3E XOR 45= 7B ----> {
  12. 3A XOR 57 = 6D ---> m

Oh yes! the correct password for this crackme is 1*FORGUdhG{m

Now , clear all breakpoint , run this crackme agian, and type : 1*FORGUdhG{m , and you will get the good message.

To make a keygen for this crackme , you must need one key, in above password the key is : 1 . Now I will make the keygen for this crackme. This keygen will allow user type a char , and we will make this char as a key. Here is my source code in VB : 

Private Sub Text1_Change()
Text2.Text = ""
If Text1.Text <> "" Then
Dim ch As String
ch = Text1.Text
Dim k As Integer, Char(1 To 12) As Integer
k = Asc(ch)
Dim Cont(1 To 11) As Integer
Cont(1) = 25
Cont(2) = 17
Cont(3) = 17
Cont(4) = 0
Cont(5) = 14
Cont(6) = 31
Cont(7) = 62
Cont(8) = 21
Cont(9) = 0
Cont(10) = 62
Cont(11) = 4
Dim i As Integer
Char(1) = k Xor 71
Char(2) = Cont(1) Xor Char(1)
For i = 2 To 11
Char(i + 1) = Cont(i) Xor Cont(i - 1)
Next i
Char(1) = Char(1) Xor 71
Char(2) = Char(2) Xor 69
Char(3) = Char(3) Xor 78
Char(4) = Char(4) Xor 79
Char(5) = Char(5) Xor 67
Char(6) = Char(6) Xor 73
Char(7) = Char(7) Xor 68
Char(8) = Char(8) Xor 69
Char(9) = Char(9) Xor 67
Char(10) = Char(10) Xor 82
Char(11) = Char(11) Xor 69
Char(12) = Char(12) Xor 87
For i = 1 To 12
Text2.Text = Text2.Text + Chr((Char(i)))
Next i
End If
End Sub

Yon can code a keygen by yourselft, or Click Here  to download this keygen.

Final Notes

If you want comment my something about this tutorial, please email to my :
tnhuan19@hotmail.com

My Greetz Goes to:

WiseMan, McCodeMan, and Tres2k   

Sphinx ( Are you find? My friend. :) 

BiSHoP ( for your great tutorials)

tKC ( for the trick I learn from you)

a_evil ( you are first my cracking teacher)

.... And more more, I can't remember all , sorry. 




When ever there is a door,
there is an entrance.
And behind an entrance can no secret hide,
when a cracker takes his knowledge for a ride
                                                                               McCodEMaN



ObDuh

The information in this essay is for educational purpose only!
You are only allow to crack, reverse engineer, modify code and debugg programs that you legaly bought and then for personal use only!!
To ignore this warning is a criminell act and can result in lawful actions!

So please note!
I take no responebility for how you use the information in this essay, i take NO responebility for what might happen to you or your computer!
You use this information on your own risk!!

What i mean is: Please buy the software!








Essay written by tnHuAn ŠTRES2000. All Rights Reserved.