首页
社区
课程
招聘
infern0正在尝试unpack haspenvelope without dongle!
2004-6-18 17:24 4770

infern0正在尝试unpack haspenvelope without dongle!

2004-6-18 17:24
4770

Infern0, the author of HaspEmulPro2.33 Keygen, is working on unpacking haspenvelope without dongle. c00l.....!!!!
Lots of crack think that is a mission impossible.

TOTEU said in RCE forum:

1. code around HASP entry is now something like this:
cmp eax, 09
push edi
jnz smth

2. iceext 0.53 will manage the sice checks...

3. the flow of (crazy options set, prolly the hardest) envelope is like this:
FN 01/02(1st_seed)/3C(len 0x08)/02/02(2nd_seed)/
/many 3D (len 0x0E) (some of them random -that means no right answer needed)
(some of them are needed and stored in a 2 indexed tables with IN data and OUT data
- space between arrays is 0x800 in my case -this reminds me of the spro envelope
and their random sproqueries indexed as well...) (a cmp eax, edx in a loop
will compare byte by byte the answers stored in the 2nd indexed table)
/then follows 3D with a few blocks needed for restoring the encrypted PE
in my case blocks were with len: 6*0xFFE + 0x4c3 for decrypting/then again 3D with a block
with len 0x5EE/

4. background hasp checks: 01/02/twice fixed 3C blocks


[培训]《安卓高级研修班(网课)》月薪三万计划,掌 握调试、分析还原ollvm、vmp的方法,定制art虚拟机自动化脱壳的方法

收藏
点赞5
打赏
分享
最新回复 (4)
雪    币: 2003
活跃值: (61)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
LOVE 2004-7-1 05:39
2
0
我菜 不懂
雪    币: 12929
活跃值: (3793)
能力值: ( LV7,RANK:100 )
在线值:
发帖
回帖
粉丝
LOCKLOSE 2 2004-7-1 10:39
3
0
牛人当然作牛事啦!:D
雪    币: 250
活跃值: (105)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
baby 2004-7-1 11:22
4
0
牛,一句也没看懂。
有人修改DLL本身一个字节后,然后用某工具带狗载入就可脱壳,剩下的只修复重定位表就可以了。
雪    币: 208
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
mYeXcKsN 2004-7-9 10:22
5
0
带狗的我脱过,没什么问题。没有狗,主要是需要利用pe文件的特点算出密钥。
比如VC编译的 或者bc  delphi等等编译的,文件有特点,可以猜出来某些位置的真实数据,然后算出密钥。
游客
登录 | 注册 方可回帖
返回