- UID
- 26438
注册时间2007-1-1
阅读权限8
最后登录1970-1-1
初入江湖
该用户从未签到
|
发表于 2007-2-12 22:14:37
|
显示全部楼层
脱壳就不用说了ESP定律
用完成断点法
运行程序
填入假码123123123,下万能断点
77D3353D F3:A5 REP MOVS DWORD PTR ES:[EDI],DWORD PTR DS>; 程序断在这里
77D3353F 8BC8 MOV ECX,EAX
取消断点返回
一直F8
004549A6 |. E8 35EDFDFF CALL dump.004336E0
004549AB |. 8B55 F0 MOV EDX,DWORD PTR SS:[EBP-10]
004549AE |. 58 POP EAX
004549AF |. E8 A4F8FAFF CALL dump.00404258 ; 关键call,出现了注册码
004549B4 |. 75 17 JNZ SHORT dump.004549CD ; 爆破点
004549B6 |. 6A 00 PUSH 0
004549B8 |. 66:8B0D 144A4>MOV CX,WORD PTR DS:[454A14]
004549BF |. B2 02 MOV DL,2
004549C1 |. B8 204A4500 MOV EAX,dump.00454A20 ; ASCII "Well done!
Thanks for solving this CrackMe..."
004549C6 |. E8 F128FDFF CALL dump.004272BC
004549CB |. EB 15 JMP SHORT dump.004549E2
004549CD |> 6A 00 PUSH 0
004549CF |. 66:8B0D 144A4>MOV CX,WORD PTR DS:[454A14]
004549D6 |. 33D2 XOR EDX,EDX
004549D8 |. B8 584A4500 MOV EAX,dump.00454A58 ; ASCII "Damn!
The Unlock Code is invalid..."
004549DD |. E8 DA28FDFF CALL dump.004272BC
004549E2 |> 33C0 XOR EAX,EAX |
|