[Disassembly exercise] 035 of 160 crackme.
The purpose of this series of articles is to try to crack all the 160 crackme step by step from a novice who has no experience (in fact, I am myself, write something similar to a registration machine in any way.
The article is organized according to the following logic (to solve the following problems ):
1. Environment and tools used
2. Program Analysis
3. Train of Thought Analysis and Cracking Process
4. Exploration of registration Machine
----------------------------------
Remind AUDIENCE:If you cannot understand the logic in the article, you must have never done it yourself! The redirection prompt in OD is very powerful. As long as you track it, you can understand it without looking at the code!
----------------------------------
1. Tools and environment:
WINXP SP3 + 52pojie 6 anniversary edition OD + peid + Assembly Gold finger.
Package 160 crackme files.
: Http://pan.baidu.com/s/1xUWOY password: jbnq
Note:
1. The Random Initial address function is enabled for modules and programs in win7 system, which will cause a great burden on analysis. Therefore, we do not recommend using win7 for analysis.
2. The above tools are all the original programs under the 52pojie Forum. NOD32 does not report any viruses, and I personally promise not to conduct any content related to Trojan viruses.
2. program analysis:
To crack a program, you must first understand the program. Therefore, in the process of cracking, the analysis of the initial program is very important. It can help us understand the author's purpose and intention, especially the details of the registration code, this facilitates reverse tracking and derivation.
In the example, open chmand select the 35cupofcoffe.1.exe and save it. Run the program. The program interface is as follows:
A message box is displayed! Why is the text box displayed? I don't know if it was the same. I still don't have its font!
Peid: Microsoft Visual Basic 5.0/6.0
3. Train of Thought Analysis and Cracking Process
1. Open the OD, drag the EXE to the OD window, and wait until the program is paused. Click the run button (F9). ignore this.
2. Enter the pseudo code at will: 123456789. Click the check it button. The message box is displayed. Do not close it. Go back to OD.
... (Oh, that's not the case. I'm used to writing this paragraph !! Token)
OD Open prompt data compression, and then a large number of unidentifiable commands, consider whether to use the P-CODE, the use of VB decompilation tools look:
VB decompiler pro prompts compression, tries to decompress it, and finds a bunch of Chinese garbled characters.
(Here there is an ambush! In fact, the Chinese Garbled text is caused by vb_decompilter_pro_8.2, and later found 9.2 (Forum address:Http://www.52pojie.cn/thread-274209-1-1.html) The version can be used normally !)
Okay, no way. The OD prompts whether to perform Compression Analysis. Select "yes" and run the exe. Right-click "Chinese search engine" and choose "Smart Search.
Right-click incorrect password-> follow. The Code is as follows:
004FEC0E . FF15 D4105000 call dword ptr ds:[<&MSVBVM50.__vbaHresu>; msvbvm50.__vbaHresultCheckObj004FEC14 > 8B4D E8 mov ecx,dword ptr ss:[ebp-0x18]004FEC17 . 51 push ecx004FEC18 . 68 E41B4000 push 00401BE4 ; ..........004FEC1D . FF15 F8105000 call dword ptr ds:[<&MSVBVM50.__vbaStrCm>; msvbvm50.__vbaStrCmp004FEC23 . 8BF0 mov esi,eax004FEC25 . 8D4D E8 lea ecx,dword ptr ss:[ebp-0x18]004FEC28 . F7DE neg esi004FEC2A . 1BF6 sbb esi,esi004FEC2C . F7DE neg esi004FEC2E . F7DE neg esi004FEC30 . FF15 4C115000 call dword ptr ds:[<&MSVBVM50.__vbaFreeS>; msvbvm50.__vbaFreeStr004FEC36 . 8D4D E4 lea ecx,dword ptr ss:[ebp-0x1C]004FEC39 . FF15 50115000 call dword ptr ds:[<&MSVBVM50.__vbaFreeO>; msvbvm50.__vbaFreeObj004FEC3F . 66:3BF7 cmp si,di004FEC42 . 74 6E je short 004FECB2004FEC44 . B9 04000280 mov ecx,0x80020004004FEC49 . B8 0A000000 mov eax,0xA004FEC4E . 894D AC mov dword ptr ss:[ebp-0x54],ecx004FEC51 . 894D BC mov dword ptr ss:[ebp-0x44],ecx004FEC54 . 894D CC mov dword ptr ss:[ebp-0x34],ecx004FEC57 . 8D55 94 lea edx,dword ptr ss:[ebp-0x6C]004FEC5A . 8D4D D4 lea ecx,dword ptr ss:[ebp-0x2C]004FEC5D . 8945 A4 mov dword ptr ss:[ebp-0x5C],eax004FEC60 . 8945 B4 mov dword ptr ss:[ebp-0x4C],eax004FEC63 . 8945 C4 mov dword ptr ss:[ebp-0x3C],eax004FEC66 . C745 9C 001C4>mov dword ptr ss:[ebp-0x64],00401C00 ; Incorrect password004FEC6D . C745 94 08000>mov dword ptr ss:[ebp-0x6C],0x8004FEC74 . FF15 38115000 call dword ptr ds:[<&MSVBVM50.__vbaVarDu>; msvbvm50.__vbaVarDup004FEC7A . 8D55 A4 lea edx,dword ptr ss:[ebp-0x5C]004FEC7D . 8D45 B4 lea eax,dword ptr ss:[ebp-0x4C]004FEC80 . 52 push edx004FEC81 . 8D4D C4 lea ecx,dword ptr ss:[ebp-0x3C]004FEC84 . 50 push eax004FEC85 . 51 push ecx004FEC86 . 8D55 D4 lea edx,dword ptr ss:[ebp-0x2C]004FEC89 . 6A 10 push 0x10004FEC8B . 52 push edx004FEC8C . FF15 E0105000 call dword ptr ds:[<&MSVBVM50.#595>] ; msvbvm50.rtcMsgBox
Among them, there is a key jump: 004fec42. 74 6e je short 004fecb2
I don't know where to go after the jump, because there is no prompt text for that address, but we can try it. Use JMP 004fecb2, haha, it's successful!
4. Exploration of registration Machine
Before this key jump, we found a plaintext text comparison, as shown below:
004FEC17 . 51 push ecx004FEC18 . 68 E41B4000 push 00401BE4 ; ..........004FEC1D . FF15 F8105000 call dword ptr ds:[<&MSVBVM50.__vbaStrCm>; msvbvm50.__vbaStrCmp
Here we will compare ECx with 10 points, and then jump, we will crack the code to restore, enter 10 points, and then find that hahaha, succeeded!
By stupid d Happy