[Language] VC9 [protection] No shell [difficulty] Simple [Tool] ollydbg [Introduction] a powerful file editing tool needless to say, Loading Large size files is faster than UltraEdit. [Body] The registration machine that was originally released with CRD for versions earlier than 12.0.10 is perfect. I don't know why an error occurs when I register the server after version 12.0.10, although the technology is so bad, I can only stick to my head. It seems that no one can crack it, but I want to use it again. In addition, I haven't posted any post after watching the snow for so long, so I just contributed to it, please give me some advice. If you can analyze the algorithm, it will be a little powerless. It will be swallowed up by the jmp of the algorithm function. First, load OD to version 12.0.10 of emeditor, and F9 directly starts the program. Then, the program will pop up a window for registration. Click Enter the activation code to bring up the registration box for the user name and KEY, right-click "OD" and choose "search for"> "name in all modules". Double-click "red" to go to the function entry: Code: 77D23D3A USER32. text Export (DefDlgProcW77D242ED USER32. text Export (SetForegroundWindow77D24305 USER32. text Export (GetDlgItemTextW77D2436E USER32. text Export (GetDlgItem77D245BB USER32. text Export (DrawStateW at this time we do not know where the program is called to this function, it does not matter, we see that emeditor should have The pop-up prompt box says you are not registered. You can choose to enter the activation code. We have filled in the name, enter the activation code whatever you want, and then confirm. od breakpoint response, click the red position and then F4-> F8 code: 77D24305> 8BFF mov edi, edi77D24307 55 push ebp77D24308 8BEC mov ebp, esp77D2430A FF75 0C push dword ptr [ebp + C] 77D2430D FF75 08 push dword ptr [ebp + 8] 77D24310 E8 59000000 call GetDlgItem77D24315 85C0 test eax, eax77D24317 0F84 14590200 je 77D49C3177D2431D FF75 14 push dword ptr [ebp + 14] 77D24320 FF75 10 push dword ptr [ebp + 10] 77 D24323 50 push eax77D24324 E8 A4620000 call GetWindowTextW; Get imput key77D24329 5D pop ebp77D2432A C2 1000 retn 10 so that we can call this function. The logic is simple, after reading the annotations, there are actually many ways to implement crack. My method is to change the red position to mov eax and 1. At this time, no matter what activation code you enter, the code can be successfully passed. Code: 6DBE3886 8B35 9023BF6D mov esi, dword ptr [6DBF2390]; USER32.GetDlgItemTextW6DBE388C 6A 1E push 1E6DBE388E 8D4424 10 lea eax, dword ptr [esp + 10] 6DBE3892 50 push eax6DBE3893 68 43060000 push 6436DBE3898 57 push edi6DBE3899 FFD6 call esi6DBE389B 6A 28 push 286DBE389D 8D4424 4C lea eax, dword ptr [esp + 4C] 6DBE38A1 50 push eax6DBE38A2 68 F3030000 push 3F36DBE38A7 57 push edi6DBE38A8 FFD6 call esi; Call the above GetDlgItemTextW function 6DBE38AA 66: 395C24 0C cmp word ptr [esp + C], bx; Compare first character (the first letter must start with B) 6DBE38AF 0F84 63010000 je %6a 0C push %8d4424 10 lea eax, dword ptr [esp + 10] 6DBE38BB 50 push %e8 3C190000 call 6DBE51FD; verify key is it valid (key verification function, there is a huge maze.) 6DBE38C1 83F8 01 cmp eax, 1; 1 is registered success (1 indicates that the registration is successful. If the registration fails, it will jump to the following page. Different responses have different prompts) 6D BE38C4 75 50 jnz short 6DBE39166DBE38C6 8D9424 98000000 lea edx, dword ptr [esp + 98] 6DBE38CD B9 FC93BF6D mov ecx, 6DBF93FC; UNICODE "eeadmin.exe" 6DBE38D2 E8 BC0EFFFF call 6DBD4793 finally hopes to be able to analyze the algorithm in the 6DBE51FD function if it is idle. I am totally dizzy by jmp ~~~ What we know now is that return is 3. It should be because a small part of the algorithm is modified, which leads to incorrect activation codes calculated by the old number calculator. The function 6DBE51FD is frequently redirected, after two days, we will provide some information that has been followed and hope to have some reference for interested friends. after entering the function, we will initialize a jump table at edi + 4C, next, run the command: Code: jmp dword ptr [edi + eax * 4] to jump to different algorithm logics. The algorithm starts to see that a table is generated at the esp offset of about 0x250, the memory is as follows: Code: 00CCE260 42 00 53 00 34 00 56 00 39 00 4E 00 41 00 43 00 B. s.4.V. 9. n. a. c.00CCE270 44 00 4B 00 57 00 45 00 50 00 58 00 32 00 54 00 D. k. w. e. p. x.2.T. 00CCE280 33 00 59 00 38 00 46 00 51 00 4A 00 4C 00 55 00 3. y.8.F. q. j. l. u.00CCE290 35 00 48 00 5A 00 36 00 52 00 4D 00 37 00 47 00 5. h. z.6.R. m.7.G. 00CCE2A0 53 00 34 00 56 00 39 00 41 00 43 00 4B 00 57 00 S.4.V. 9. a. c. k. 201700cce2b0 45 00 50 00 58 00 32 00 54 00 33 00 59 00 42 00 E. p. x.2.T. 3. y. B .00CCE2C0 38 00 46 00 51 00 4A 00 4C 00 55 00 35 00 48 00 8. f. q. j. l. u.5.H. 00CCE2D0 5A 00 36 00 52 00 4D 00 37 00 4E 00 44 00 47 00 Z.6.R. m.7.N. d. g.0 0CCE2E0 53 00 34 00 56 00 4E 00 42 00 41 00 4B 00 57 00 S.4.V. n. b. a. k. 201700cce2f0 45 00 50 00 32 00 44 00 35 00 54 00 33 00 59 00 E. p.2.D. 5. t.3.Y. 00CCE300 38 00 46 00 51 00 4A 00 4C 00 55 00 43 00 48 00 8. f. q. j. l. u. c. h.00CCE310 5A 00 36 00 52 00 4D 00 37 00 47 00 39 00 58 00 Z.6.R. m.7.G. 9. x.00CCE320 34 00 42 00 57 00 45 00 50 00 53 00 32 00 44 00 4. b. w. e. p.S. 2. d.00CCE330 35 00 54 00 33 00 59 00 38 00 4E 00 46 00 51 00 5. t.3.Y. 8. n. f. q.00CCE340 4A 00 4C 00 55 00 43 00 56 00 48 00 5A 00 36 00 J. l. u. c. v. h. z.6.00CCE350 52 00 4D 00 41 00 4B 00 37 00 47 00 39 00 58 00 R. m. a. k.7.G. 9. x.00CCE360 56 00 4E 00 32 00 54 00 59 00 38 00 46 00 42 00 V. n.2.T. y.8.F. B .00CCE370 53 00 51 00 50 00 58 00 4A 00 43 00 4C 00 41 00 S. q. p. x. j. c. l. a.00CCE380 55 00 35 00 48 00 5A 00 33 00 36 00 44 00 52 00 U.5.H. z.3.6.D. R.00CCE390 4D 00 37 00 34 00 47 00 45 00 39 00 57 00 4B 00 M.7.4.G. e.9.W. k.00CCE3A0 56 00 4E 00 43 00 44 00 57 00 32 00 54 00 33 00 V. n. c. d. listen 2.t. 3.00CCE3B0 59 00 38 00 46 00 42 00 53 00 51 00 45 00 50 00 Y.8.F. b. s. q. e. p.00CCE3C0 58 00 4A 00 4C 00 41 00 55 00 35 00 48 00 5A 00 X. j. l. a. u.5.H. z.00CCE3D0 36 00 52 00 4D 00 37 00 34 00 47 00 39 00 4B 00 6. r. m.7.4.G. 9. k. however, I have never analyzed how to use the key after it is passed in. More people want to move the mouse ~ It may be that I am not familiar with it. If someone wants to give an analysis on the key, thank you first!