Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 04-09-2005, 19:46
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
hm... what about Process32First (used by some protectors, but also disallows other pograms to start it), ZwQueryInformationProcess (Used by new VBox HASP SL), and the method used by SDProtector (didn't analyse what it uses)?

all i do is writing tutorials, but not taking part in such contests which helps developing protectors. same as Code-Lock with their "special rulez" you have to explain them more or less how you cracked it (this thread about code-lock was created by you dyn!o )
Reply With Quote
  #2  
Old 04-09-2005, 22:42
dyn!o's Avatar
dyn!o dyn!o is offline
Friend
 
Join Date: Nov 2003
Location: Own mind
Posts: 214
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 8
Thanks Rcvd at 0 Times in 0 Posts
dyn!o Reputation: 1
"and the method used by SDProtector "
As I remember SDProtector used ZwQueryInformationProcess, DebugActiveProcess or RDTSC... Ehh, a little mess in my head... all these protectors are almost the same... I cannot remember which one but I vote for ZwQueryInformationProcess. Any problem? I do not think so (not for you) - just go and write small plugin or macro. If you will encounter RDTSC (but I feel it has been used in other protection) the same here - sounds terrible but it is terribly easy (macro or plugin - just check the actual instruction and skip it/them in case of RDTSC).

"Lock with their "special rulez" you have to explain them more or less how you cracked it (this thread about code-lock was created by you dyn!o )"
I remember that pretty well. I asked them if it is not assymetric cryptography key "trick" and to let me get in. They refused.

Good luck.
Reply With Quote
  #3  
Old 04-09-2005, 23:23
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
it was more than half a year i looked at SDProtector. i didn't look at it again, but going to do so again most things i did through kernel-patching, not in olly itself. i did that because some tools got detected by anti-crack mechanisms and so (through kernel-patch) i fixed it for the whole system. next service pack will kick all the patches

that's the trick about the contests:
you should do what is requested but not like YOU want, you should do how THEY want
Reply With Quote
  #4  
Old 04-09-2005, 23:38
dyn!o's Avatar
dyn!o dyn!o is offline
Friend
 
Join Date: Nov 2003
Location: Own mind
Posts: 214
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 8
Thanks Rcvd at 0 Times in 0 Posts
dyn!o Reputation: 1
"it was more than half a year i looked at SDProtector. i didn't look at it again"
similar here.

"most things i did through kernel-patching"
wow, a hardcore. But the problem comes again with each OS update, as you noticed.

"most things i did through kernel-patching"
sure you can but try to patch RDTSC using this way .

"you should do what is requested but not like YOU want, you should do how THEY want"
damn right.

All in all I suggest you to consider taking the advantage of OllyDbg possibilities (macro/plugin) - it is really powerful.

Good luck and regards.

Last edited by dyn!o; 04-09-2005 at 23:43.
Reply With Quote
  #5  
Old 04-10-2005, 00:20
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
kernel-patches are system wide and so more comfortable because they take effect to every cracking-software too

"sure you can but try to patch RDTSC using this way"
hehe, that must be really hardcore to do that. there was a reference in CBJ how to pass this but without kernel-patching
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ASM coding, do you use a special program, or can you use C for asm-coding instead epikur General Discussion 15 08-18-2004 04:40


All times are GMT +8. The time now is 22:08.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )