Showing posts with label Hints n Tips. Show all posts
Showing posts with label Hints n Tips. Show all posts

A Little Jmp, Mov, Test, Cmp Compendium

 Stupid Plain Patching and help for Newbies

1. Jump patching
When you want that a jump jumps always make this...
xxx(any jump)--->JMP
Another possibility (I think this is better, but you must be carefull!)
JNE--->JN
JNZ--->JE

That are the VERY Basics in Jump oatching! Read More!

Greying Out Menus by sLayer

Search for the menu string in UNICODE (I recommend winhex or hedit)

example-R.E.G.I.S.T.E.R

now just one or two lines above you will spot a .P.(P=50)

change it to either HEX=58 or UNICODE=X and done the menu will be greyed out
For every menu there will be a .P.

PS.Sorry if there is a mistake.I may have forgotten some values Read More!

WinLicense 2.0.6.5 (Patching Registered Dwords)

Download:
http://www.megaupload.com/?d=YQ0H54IE Read More!

Unpacking n Cracking Rar Repair Tool v3.0

Download: 1.59MB
http://www.megaupload.com/?d=6K9O60Y5 Read More!

Some Tricks about VB Programs

Download: 68KB
http://www.megaupload.com/?d=1I6US81T Read More!

A tales of reversing & keygenning two MD5 registration schemas

Download: 1.17MB
http://www.megaupload.com/?d=6LWI6AXE Read More!

REcReatiOn MessageBoxes in Delphi

Download: 1.81MB
http://www.megaupload.com/?d=WK17PBA3 Read More!

P-Code Instructions

Download: 36KB
http://www.megaupload.com/?d=57T8AMAU Read More!

Patching VB Applications Using Olly by Shub-Nigurrath

Download: 629KB
http://www.megaupload.com/?d=Q4Y94R20 Read More!

Patch HWID Execryptor v2.4.1 by Trickyboy

Download: 931KB
http://www.megaupload.com/?d=IJ1ZGEBK Read More!

nBinder Password Finder

Its not the crc of the file its self it is a value that is stored inside the app.....if you set a BP on GetDlgItemTextA you should break after entering the password where as followed by a call which computes the crc32 of the password entered, result will be in EAX and gets compared to the value in ESI the value in ESI is the crc32 of the correct password and that is the value needed for bruteforcing. Read More!

Kill Startup Nags The Easy Way !

Kill Startup Nags The Easy Way !

the startup nag is "Please register....."
i searched for the nag in the hex editor ( i am using hex workshop )and

found it to be at
00054460 !
just before this line (at 00054450 ) i found that a value of "C0" was

present ....... i converted it to "20" and saved the file and voila no

nag screen !

i tried a few appz after thus discovery and found that i was able to

remove the start up nags in most of them !
but remember it dosent work every where !.......other values can be

changed tooo ...... to remove the nag !

TRY THIS ONLY WHEN YOU HAVE LOST ALL HOPE IN REMOVING THE NAGS (because

this is dumb!) ........... and dont forget to make a backup before ! Read More!

Inside Code Virtualizer by scherzo

Download: 2.49MB
http://www.megaupload.com/?d=K6D3FY0Y Read More!

IDA Pro Shortcuts

Download: 67KB
http://www.megaupload.com/?d=LDUV8GV4 Read More!

Anti-Reverse Engineering Guide

Download: 514KB
http://www.megaupload.com/?d=VDUQ5QB9 Read More!

Another hint to enable buttons under VB6

Download: 213KB
http://www.megaupload.com/?d=FTFJJVC3 Read More!

Am i Registered?

I've seen the question alot "When the program starts up it checks Am I Registered? How do I find this?"

Well beginners, I hope this helps some smile.gif

The program will usually check in one of two places:

1) A file. There is no limitation on the location of this file or on its name. It is usually encrypted or unreadable.

2) The registry. The windows registry stores information for applications and the locations and names vary.

So how do you find the sweet spot? Well you could simply F8 through the program in olly but sometimes that takes forever following all the calls. So to simplify things we can search for the APIs (Google now if you dont know what an API is).

RegQueryValue and RegOpenKey are for the registry.

CreateFile, ReadFile, OpenFile, fopen, and fread are for keyfiles.

(These are not all but are most common)

To use this method in reversing, load the target into olly. Then right click on the code window > Search For > All names(labels) in current module. This will bring up the list of APIs used. Click on any of them and start typing the name if you want or you can scroll. Visual basic apps will have vba beside them. Select the one you were looking for and the right click on it > Set breakpoint on every reference. You have just told olly to break every time this API is called. Now run the program and you should land on one of your breakpoints. Go ahead and keep pressing F9 to run the program and make not of how many times you breakpoint. Now reload the application in olly and go through them again. Keep your eyes on the registers and the stack as they hold the params passed to the API being called. You should see something related to registration such as Name or Key or Serial. Sometimes the programs hold a Registered value and other times the name/serial are loaded from the registry and they are checked against the registration function.

Hope thats a point in the right direction.

========

Just a short addition for those having trouble - sometimes if you're stuck determining whether you're looking for a file or registry API then Sysinternals Process Monitor/Filemon/Regmon can help out.

Just gives you an overview of what is being accessed. Read More!