![]() |
|
|
|
#1
|
|||
|
|||
|
Actually i downloaded Orca a couple of days ago and it seemed very similar to the Installshield developer tool.
In anycase this is what I have so far with Orca (based on your instruction) I've attached a jpg with the tables of Control, ControlEvent, ControlCondition and CustomAction. Actually its kinda neat that Orca isolates everything (a little annoying as well as you don't get a visual representation that Installshield gives you ).I've only included the relevant table entries to reduce space so let me know if you feel you need more information. Control - The entry in question is CustomerInformation - this is where you enter the serial number. In fact the variable name "SERIALNUMBER" is right there for everybody to see. ControlCondition - Under CustomerInformation there are 2 entries, SerialNumberEdit and SerialNumberLabel, these don't look very interesting since I think they are just to edit the serial number. The Conditions "LicenseOK="1" looks interesting but I'm not sure where its set ControlEvent - Under CustomerInformation again, the Next has a DoAction which points to a LicenseCheck with condition 1. Changing the condition to "0" gives me the following error "The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2803" CustomAction - Here LicenseCheck is actually called _CheckLicense@4 and appears in TKCommonAct. So this is pretty much where I was when I posted the message initially. Hopefully I've included more details that might be helpful. I think it maybe easier to just post the msi file but I think it might invite the wrath of the admin. Thanks for all of your help. PS: I read the articale in wasm.ru, its pretty good except that the tool they suggest m_extract to extract any function calls in the msi file didn't work for me. |
|
#2
|
|||
|
|||
|
>..."SERIALNUMBER"
>..."LicenseOK="1" >.. .LicenseCheck is actually called _CheckLicense@4 and appears in TKCommonAct. > I can't download any attachments yet, but... Seems there is a custom dll with exported function _CheckLicense. This function has one argument (@4), probably pointer to var "SERIALNUMBER". If function input is valid, it returns 1 (LicenseOK=1) |
|
#3
|
|||
|
|||
|
Activate the "kernel32.GetProcAddress" BP after you inserted the serial and before you press Next.
You'll hopefully catch it retrieving the address of that "CheckLicense" function, amongst others. Then you can BP that function, and see what it does and which module it comes from in the file system. |
|
#4
|
|||
|
|||
|
orca continuing..
I cannot download attachements yet.
Consider uploading your screenshot at some free webspace (eg. /h--p://us.imageshack.com/) or your whole .msi to some similar (eg. /h--p://www.yousendit.com or /h--p://www.ezshare.de) and posting the links so I can get the files. In the meantime: If you look at the "ControlEvent" table you'll see several columns. Does Next have more than one entries? It probably has (one with the license check and another(s) with the next action should license check passed succesfully) The last column "Ordering" specifies which Next Action is executed first (smaller order) Also if the DoAction you're referring to has the form "LicenseCheck=1" (I'm just guessing here as I can't see the screenshot) don't bother to change the "=1" to "=0". Just replace the whole "LicenseCheck=1" with "1" (true) and give it a try. I can probably help more if you post the files somewhere I can get them... Think simple |
|
#5
|
|||
|
|||
|
Here is a link to an image of the orca msi tables
http://img50.exs.cx/img50/7523/orcamsitables9nb.jpg And here is a link to an image of calls I get when I do a bpx kernel32.GetProcAddress in Olly http://img5.exs.cx/img5/1949/intermodularcalls1kw.jpg Thanks for all of your help. Sailor_EDA Last edited by Sailor_EDA; 01-11-2005 at 13:30. |
|
#6
|
|||
|
|||
|
I found this useful h**p://wxw.reteam.org/papers/e42.pdf
|
|
#7
|
|||
|
|||
|
quick fix with orca
The image below shows the minimal changes in msi tables needed to
bypass the serial. You will notice that the custom setup dialog is displayed twice. This can be corrected, but some more table editing is required and I'd rather not devote the time as the main thing is accomplished. A little explaining: This setup was a little more clever in that the Next button had a DoAction of resubmitting itself [CustomerInformation_Next] until a valid serial. But .msi is always the weak link as you can change the action to display another dialog (in this case CustomSetup) further down the installation sequence. Look at the picture with "before"->"after" comparison and you'll understand what I mean. Regards. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|