Themida and winlicense Shell software shelling tutorial

Source: Internet
Author: User

(a) Themida and without license winlicense Shell software is not said, directly on the script shelling.

(b) Take a look at some of the minor features of different versions of Oep:

Oep features after temida2.1.x.x version (2.0.8.0,2.1.0.10,2.1.3.32, etc.)

Oep features prior to the Temida2.1 version, such as (2.0.3.0,1.8.2.0,1.885, etc.):

Temida Oep Characteristics: (2.0.3.0,)

One, for Winlicense2.1.0.10 and the following version, do not license, you can arbitrarily construct a license direct bypass. Then shelled.

Bypass process

1, first get license name, self-construct a license, then OD run program, pop-up prompt window to get the first address of jmp: firstjmpaddress.

2, the next firstjmpaddress hardware breakpoint, rerun the program, after interruption, enter in the second Jmp,enter, then search for CMP ecx,eax, under Breakpoint, run, interrupt in cmpecxeaxaddress.

3, run a few times, you will get eax,ecx different values, where eax is the correct checkword, the EAX value assigned to ECX can be. There are two different times, so there are two checkword.

4, search Kenrel.dll's first address, this machine is 7c800000, ctrl+b, input: XX 7 C. Then search for the second address of the DLL address, you can get seconddlladdress. After changing the second Checkword, the seconddlladdress changes to the first DLL address, run can be bypass.

Second, after the 2.1.x.x version of the OEP features (2.0.8.0,2.1.0.10,2.1.3.32, etc.):

Bypass process:

1, need a usable license

1th, the 2 steps are the same as above.

In the 3rd step, there is only one checkword, but this checkword value also has two checks, each assigned to ECX can be bypass.

Three, also encountered a bypass, is the need to constantly monitor the value of EAX and seconddlladdress, do not know which version belongs to. You can see the tutorial Winlicense ByPass for seconddlladdress.

The above three versions of the bypass process need to distinguish, mainly see the value of CMP ecx,eax time to identify!

Winlicense shelling Process:

Insert the bypass script into the ZHW hwid themida-winlicense 1.x-2.x Multi PRO Edition 1.2.txt to achieve bypass and shelling.

Search the/*ZHW Bypass * * section to see the inserted script.

Originally from: http://www.jiamikong.com/doc/3724

Themida and winlicense Shell software shelling tutorial

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.