zoukankan      html  css  js  c++  java
  • 010editor爆破与注册机

    对不起了010,下次一定(发出了白嫖的声音)

    在我刚学逆向的时候,010editor30天的试用到期了,我就想着自己破,结果啥都看不懂。。。。。。

    我当时想,等以后一定要把010破了。。。。。。

    不过现在回头看,010真简单啊,一点保护都没有。。。。。。

    >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

    版本:v10.0.1 (64bit)

    工具:x64dbg,ida pro 7.0

    >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

    随便输个用户名和密码

    查找字符串,找到地址

    同时在它上下翻翻,找到

    关键在于控制走到这一条,发现有两处关键的跳转(第一张图中的call就是验证函数)

     

    修改为图中这样

    可以正常使用了

    >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

    其实这样改完每次都会先弹出注册框,还可以再改(咕咕咕)

    不咕了,进入上文说到的关键函数

    把mov eax,113h改为mov eax,0DBh就不会再弹窗了 

    >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

    注册机(咕咕咕)

    再次不咕,进到验证函数

    返回值为2Dh时注册成功

    这里的v41到v48为输入的激活码

    可以看到v44必为0x9c,经过后面encrypt函数会生成激活码的后半部分

    之后就可以写个注册机

    Table = [       0x39cb44b8, 0x23754f67, 0x5f017211, 0x3ebb24da, 0x351707c6, 0x63f9774b, 0x17827288, 0x0fe74821,
                    0x5b5f670f, 0x48315ae8, 0x785b7769, 0x2b7a1547, 0x38d11292, 0x42a11b32, 0x35332244, 0x77437b60,
                    0x1eab3b10, 0x53810000, 0x1d0212ae, 0x6f0377a8, 0x43c03092, 0x2d3c0a8e, 0x62950cbf, 0x30f06ffa,
                    0x34f710e0, 0x28f417fb, 0x350d2f95, 0x5a361d5a, 0x15cc060b, 0x0afd13cc, 0x28603bcf, 0x3371066b,
                    0x30cd14e4, 0x175d3a67, 0x6dd66a13, 0x2d3409f9, 0x581e7b82, 0x76526b99, 0x5c8d5188, 0x2c857971,
                    0x15f51fc0, 0x68cc0d11, 0x49f55e5c, 0x275e4364, 0x2d1e0dbc, 0x4cee7ce3, 0x32555840, 0x112e2e08,
                    0x6978065a, 0x72921406, 0x314578e7, 0x175621b7, 0x40771dbf, 0x3fc238d6, 0x4a31128a, 0x2dad036e,
                    0x41a069d6, 0x25400192, 0x00dd4667, 0x6afc1f4f, 0x571040ce, 0x62fe66df, 0x41db4b3e, 0x3582231f,
                    0x55f6079a, 0x1ca70644, 0x1b1643d2, 0x3f7228c9, 0x5f141070, 0x3e1474ab, 0x444b256e, 0x537050d9,
                    0x0f42094b, 0x2fd820e6, 0x778b2e5e, 0x71176d02, 0x7fea7a69, 0x5bb54628, 0x19ba6c71, 0x39763a99,
                    0x178d54cd, 0x01246e88, 0x3313537e, 0x2b8e2d17, 0x2a3d10be, 0x59d10582, 0x37a163db, 0x30d6489a,
                    0x6a215c46, 0x0e1c7a76, 0x1fc760e7, 0x79b80c65, 0x27f459b4, 0x799a7326, 0x50ba1782, 0x2a116d5c,
                    0x63866e1b, 0x3f920e3c, 0x55023490, 0x55b56089, 0x2c391fd1, 0x2f8035c2, 0x64fd2b7a, 0x4ce8759a,
                    0x518504f0, 0x799501a8, 0x3f5b2cad, 0x38e60160, 0x637641d8, 0x33352a42, 0x51a22c19, 0x085c5851,
                    0x032917ab, 0x2b770ac7, 0x30ac77b3, 0x2bec1907, 0x035202d0, 0x0fa933d3, 0x61255df3, 0x22ad06bf,
                    0x58b86971, 0x5fca0de5, 0x700d6456, 0x56a973db, 0x5ab759fd, 0x330e0be2, 0x5b3c0ddd, 0x495d3c60,
                    0x53bd59a6, 0x4c5e6d91, 0x49d9318d, 0x103d5079, 0x61ce42e3, 0x7ed5121d, 0x14e160ed, 0x212d4ef2,
                    0x270133f0, 0x62435a96, 0x1fa75e8b, 0x6f092fbe, 0x4a000d49, 0x57ae1c70, 0x004e2477, 0x561e7e72,
                    0x468c0033, 0x5dcc2402, 0x78507ac6, 0x58af24c7, 0x0df62d34, 0x358a4708, 0x3cfb1e11, 0x2b71451c,
                    0x77a75295, 0x56890721, 0x0fef75f3, 0x120f24f1, 0x01990ae7, 0x339c4452, 0x27a15b8e, 0x0ba7276d,
                    0x60dc1b7b, 0x4f4b7f82, 0x67db7007, 0x4f4a57d9, 0x621252e8, 0x20532cfc, 0x6a390306, 0x18800423,
                    0x19f3778a, 0x462316f0, 0x56ae0937, 0x43c2675c, 0x65ca45fd, 0x0d604ff2, 0x0bfd22cb, 0x3afe643b,
                    0x3bf67fa6, 0x44623579, 0x184031f8, 0x32174f97, 0x4c6a092a, 0x5fb50261, 0x01650174, 0x33634af1,
                    0x712d18f4, 0x6e997169, 0x5dab7afe, 0x7c2b2ee8, 0x6edb75b4, 0x5f836fb6, 0x3c2a6dd6, 0x292d05c2,
                    0x052244db, 0x149a5f4f, 0x5d486540, 0x331d15ea, 0x4f456920, 0x483a699f, 0x3b450f05, 0x3b207c6c,
                    0x749d70fe, 0x417461f6, 0x62b031f1, 0x2750577b, 0x29131533, 0x588c3808, 0x1aef3456, 0x0f3c00ec,
                    0x7da74742, 0x4b797a6c, 0x5ebb3287, 0x786558b8, 0x00ed4ff2, 0x6269691e, 0x24a2255f, 0x62c11f7e,
                    0x2f8a7dcd, 0x643b17fe, 0x778318b8, 0x253b60fe, 0x34bb63a3, 0x5b03214f, 0x5f1571f4, 0x1a316e9f,
                    0x7acf2704, 0x28896838, 0x18614677, 0x1bf569eb, 0x0ba85ec9, 0x6aca6b46, 0x1e43422a, 0x514d5f0e,
                    0x413e018c, 0x307626e9, 0x01ed1dfa, 0x49f46f5a, 0x461b642b, 0x7d7007f2, 0x13652657, 0x6b160bc5,
                    0x65e04849, 0x1f526e1c, 0x5a0251b6, 0x2bd73f69, 0x2dbf7acd, 0x51e63e80, 0x5cf2670f, 0x21cd0a03,
                    0x5cff0261, 0x33ae061e, 0x3bb6345f, 0x5d814a75, 0x257b5df4, 0x0a5c2c5b, 0x16a45527, 0x16f23945
        ]
    def encrypt(Name):
        Name=Name.upper()
        result=0
        v1=0
        v2=15*0x3E8
        v3=0
        for i in range(len(Name)):
            v4=Name[i]
            v5=Table[v3&0xff]
            v6=(result+Table[v4])&0xffffffff
            v7=Table[v2&0xff]
            v8 = Table[(v4+13)]
            v9 = v4+47
            v10 = v1
            v3+=9
            v2+=13
            v1+=19
            result=(v7+v5+Table[v10]+Table[v9]*(v6^v8))&0xffffffff
        return result
    
    Password=[0,0,0,0,0,0,0,0]
    Name = input("PLZ INPUT USERNAME:")
    Password_Low = encrypt(Name.encode("utf-8"))
    Password[4] = Password_Low&0xff
    Password[5] = (Password_Low>>8)&0xff
    Password[6] = (Password_Low>>16)&0xff
    Password[7] = (Password_Low>>24)&0xff
    Password[3] = 0x9C
    
    for i in range(0xff):
        temp = (((Password[6] ^ i ^ 0x18) + 61) ^ 0xA7)&0xff
        if temp > 0xB:
            Password[0] = i
            break
    for i in range(0xff):
        for j in range(0xff):
            temp = (0xffff&(0x3421^(((0xffff&(((i^Password[7]&0xff)<<8)+(Password[5]^j&0xff)))^0x7892)+0x4d30)))
            if temp/0xb == 0x3E8 and temp%0xb==0:
                Password[1] = i
                Password[2] = j
                break
    
    for i in range(8):
        if i%2==0 and i!=0:
            print("-",end="")
        if Password[i]<=0xa:
            print("0"+str(hex(Password[i]))[2:].upper(),end="")
        else:
            print(str(hex(Password[i]))[2:].upper(),end="")

    不过之后还有网络验证。。。这次是真的咕了

  • 相关阅读:
    centos7 修复引导
    Django 过滤器
    Django 面向对象orm
    Django models字段查询谓词表
    linux常用的监控命令
    常用SQL语句
    python实现FTP服务器
    用python做一个图片验证码
    rsync
    jsonp的理解
  • 原文地址:https://www.cnblogs.com/harmonica11/p/13061824.html
Copyright © 2011-2022 走看看