Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 06-12-2008, 04:32
LaBBa LaBBa is offline
VIP
 
Join Date: Jul 2003
Posts: 150
Rept. Given: 0
Rept. Rcvd 16 Times in 4 Posts
Thanks Given: 0
Thanks Rcvd at 11 Times in 11 Posts
LaBBa Reputation: 16
I never tried to trace the code with burned cd because it showed me the same error msg about not original CD so i made an image and then start working on the image.. i will check and trace the code with a burned CD and will show my results of debugging.

if i patch the eax value the application crash.
Reply With Quote
  #2  
Old 06-13-2008, 04:34
LaBBa LaBBa is offline
VIP
 
Join Date: Jul 2003
Posts: 150
Rept. Given: 0
Rept. Rcvd 16 Times in 4 Posts
Thanks Given: 0
Thanks Rcvd at 11 Times in 11 Posts
LaBBa Reputation: 16
Hi all

I have just found out that some one in my contry has cracked the CD protection of a newer version of the application i'm trying to crack
i don't know if this new version is like my version that comes with 2 CDs
maybe this version came with 1 DVD.

he added a file that he called : appName.emu
and it's a binary file with this header :

Code:
CD001 GEAR CD/DVD PREMASTERING        GEAR SOFTWARE  2007032013494800200703201349480019830320130322002007032013032200
well i check and there is an application that create a CD copy called GEAR SOFTWARE but i don't see anything spcial about this app.

the Cracker also patch the application so it will read from file .emu data when trying to boot from CD

does any one knows about this kind of CD protection that need to be cracked like so ?

and i don't understand how did he make this dump file and make the application read this when needed... (i don't have the original exe file of this new version so i can't compare it)

i have added the emu file that was added to crack this newer app

regards,
LaBBa.
Attached Files
File Type: zip RespCD15.zip (24.4 KB, 13 views)

Last edited by LaBBa; 06-13-2008 at 05:13.
Reply With Quote
  #3  
Old 06-17-2008, 06:23
LaBBa LaBBa is offline
VIP
 
Join Date: Jul 2003
Posts: 150
Rept. Given: 0
Rept. Rcvd 16 Times in 4 Posts
Thanks Given: 0
Thanks Rcvd at 11 Times in 11 Posts
LaBBa Reputation: 16
Hi ALL
i got it now ...

when i load the original CD after it uses the DeviceIoControl API it read the section of the data it need for password of the DB files.
the section of that data was created with Gear Software and from some reason can't be copy by any of the applications that i used.

so i run the original CD and when i saw that it read the data from the section i have make a dump and saw the section data like the emu file had...

now all i needed to do is make a dump with olly as a binary copy and now i have my own emu file like in the new version that was cracked ...

all i need to do is to make a load to the binary file in run time and thats it.. i belive that the CD will be hacked soon..

tnx for the help..

PS:
the only question left is why any of the software i have used with all kind of profiles coudn't copy the password section that was created with GEAR SOFTWARE ????
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 04:39.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )