
WinBoost 2001 Standard
Written by anTiHerO
|
Introduction |
Protection: Registration and 10 Day Time Limit
About: WinBoost is a special utility designed to configure and personalize
Windows Me/9X (95/98/98 SE) looks and feels. Using easy to use user interface
you can configure hundreds of Windows Me/9X hidden settings, from Start Menu,
Desktop, Accessories, Windows Explorer, to Internet Explorer. In addition, you
will get hundreds of selected Windows Me/9X Tips & Tricks to boost your
productivity and performance.
WinBoost
2001 Standard Edition is a time limited demo of WinBoost 2001 Gold Edition.
|
Tools required |
Debugger (Softice or TRW2000)
Half a brain
|
Target's URL |
http://www.winboost.com
|
Essay |
OK, shall we begin? Upon starting our target program we are
greeted by a nag screen telling us that we have 10 days to register, click on
the register button, and we will see two dialogue boxes. One for our name, and
one for our serial number. To get an idea of the protection, we need to fill in
the boxes. I used;
Name: anTiHerO
Serial: 1212121212
If we click OK, we don’t get any “ Bad Cracker ” message boxes,
but the dialogue boxes are emptied by the program, telling us that our
attempted registration was wrong. OK, lets get this sucker registered! Re-enter
our registration information, and before clicking on OK, bring up your debugger
and set a breakpoint on the HMEMCPY function by typing the following;
:bpx hmemcpy
This is probably the most used breakpoint, as it causes the
debugger to break whenever something is written to memory, and will almost
always cause the debugger to break in 99.99% of attempts. Right, back to
business. Exit the debugger, and click OK on the registration window. Bang!
Straight back into our debugger! You should be looking at;
KERNEL! HMEMCPY
0167:9EAE PUSH BP
0167:9EAF MOV BP, SP
We don’t want to be here, so keep pressing F12 until we are into
the second instance of our code, and trace through the code using F10 until you
reach this point;
004BED96 CALL 0042E28C
004BED9B MOV EDX, [EBP – 08] < Move
name into EDX
004BED9E MOV EAX, [EBP – 04] <
-------------------------------------------------------------------------- Type D EAX to see name
004BEDA1 CALL 004BEAD0
004BEDA6 LEA EDX, [EBP – 10]
004BEDA9 CALL 00408200
004BEDAE XOR EAX, EAX
004BEDB0 POP EDX
004BEDB1 POP ECX
004BEDB2 POP ECX
004BEDB3 MOV [FS : EAX] EDX
004BEDB6 PUSH DWORD 4BFA94
004BEDBB MOV EAX, [EBP – 0C] < Move “ fake “ serial into EAX
004BEDBE MOV EDX, [EBP – 10] < Hmmmmmmmm ---------------------------------------------- Type D EAX to see our fake serial
004BEDC1 CALL 00403D98 <
---------------------------------------------------------------------- Type D EDX. Whats this? 485473688!
Is this our real serial?
At this point, I cleared all breakpoints and entered the
following into the registration boxes;
Name: anTiHerO
Serial: 485473688
I then clicked OK, NOTHING!!!, well apart from the boxes
blanking themselves, so I knew it was wrong. Dammit! So I shouldn’t have left
my debugger at that point, so after going through everything again, and tracing
past the above code, I eventually ended up at the following section of code;
004BF673 CALL NEAR [ESI + 0C]
004BF676 MOV EDX, [EBP + FFFFFE90] < Move
real serial into EDX
004BF673 MOV EAX, [EBP – 18] <
--------------------------------------------------------------------- Type D EDX to see real serial
Aha!! What do we have here? 9M2R4 – U974H – YE07H – 1Y1P6 !
Surely this must be our real serial. HOLD ON! Don’t be so hasty! If we scroll
down through our data window ( not sure about softice, but with TRW2000 its Alt
and the arrow keys), what do we see? Masses of serial numbers! It looks like
our program has generated every combination of serial numbers to go with our
username. I’m not sure why there isn’t just one serial (I’m not that good
enough yet!).
Time to try this baby out. Clear all breakpoints, and leave the
debugger. I wrote down three of the other serials and tried them (although it
looks like there are hundreds!). I wont give you any of them though, that’s up
to you to find them, and I entered the following into the registration boxes;
Name: anTiHerO
Serial: 9M2R4 –
U974H – YE07H – 1Y1P6
Click OK, REGISTERED!!!!!!! The job is done.
If you want to unregister the program you will have to edit your
Win.ini file located in your windows directory. The WinBoost data will look
like;
[WB]
Owner = anTiHerO
Registered = True
You can have a bit of fun with this! Change the name from
anTiHerO to BigBalls, start up the program….Registered to BigBalls! Hehe. To
unregister the program, change the True statement to read False!
|
Final Notes |
Pat yourself on the back, grab a beer and a cigar, and relax,
safe in the knowledge that you just learnt something usefull!!
[T]urb0z – For introducing me to these infernal
machines
The TRES2000 Crew
My mum
ObDuh
|
The information in this essay is for educational purpose only!
You are only allow to crack, reverse engineer, modify code and debug programs
that you legaly bought and then for personal use only!!
To ignore this warning is a criminal act and can result in lawful actions!
So please note!
I take no responsibility for how you use the information in this essay, i take
NO responsibility for what might happen to you or your computer!
You use this information on your own risk!!
What I mean is: Please buy the software!
Essay written by anTiHerO ©TRES2000. All Rights Reserved.