Winzip 7.0 SR-1
Introduction |
Greetings and welcome to the noble art of reverse engineering!
Tools required |
Numega SoftIce v 3.2x
Target's URL |
http://www.winzip.com
Essay |
Step1 Run winzip and type in:
name: McCodEMaN
reg.nr: 1234567890
Step2 Start softice and place a breakpoint on GetDlgItemTextA
Step3 Return to winzip32.exe and click on [OK] and softice will breakdue to
BPX GetDlgItemTextA.
Step4 Press 'F11'
Step5 Press 'F5' once more to make softice break again.
Step6 Trace down with 'F10' until you see..........
:00408049 803D18D9470000 CMP BYTE PTR......
Type d 0047D918 => Username!
Step7 Now! trace down to..................
:00408053 803D48D9470000 CMP BYTE PTR[0047D948],00
Type: d 0047d948 => Fakecode!
Step8 Ok, we have found two CMP´s, our fakecode and username nowwe should be close
to the realserial!
Trace down to...........
:0040805C E8EAFAFFFF CALL 00407B4B
andstep into the call (F8) this is the first call after the cmp`s of our reginfo.
If you don`t step in to this call and keep on tracing down you will getan error-
message, telling you that you entered wrong serial!
Step9 Go to..............
:00407B58 803D18D9470000 CMP [0047D918],00
Do you remember this CMP? , right our username!
Then we should be on the right place!....let`s go on!
Step10 Keep on tracing until you find....
:00407B90 50 PUSH EAX => saves usename!
Ifyou dump this EAX you will see that it saves our username.
Step11 Ok!, at ........
:00407C29 50 PUSH EAX => Saves 1st valid serial!
andat ........
:00407C53 50 PUSH EAX => Saves 2nd valid serial!
Step13 Type BC * to remove all active breakpoints!
Final Notes |
| BACK |