160个练手CrackMe-021
来源:互联网 发布:美工需要学编程吗 编辑:程序博客网 时间:2024/05/17 00:42
1、无壳,Delphi
2、DarkDel定位事件,OD载入
EditKeyPass()
0042CE30 . 33D2 xor edx,edx ; KeyPress0042CE32 . 8A11 mov dl,byte ptr ds:[ecx]0042CE34 . 83C2 F8 add edx,-0x8 ; Switch (cases 8..7A)0042CE37 . 83FA 72 cmp edx,0x720042CE3A . 0F87 80050000 ja Cabeca.0042D3C00042CE40 . 8A92 4DCE4200 mov dl,byte ptr ds:[edx+0x42CE4D]0042CE46 . FF2495 C0CE42>jmp dword ptr ds:[edx*4+0x42CEC0]0042CE4D . 35 db 35 ; 分支 0042CEC0 索引表
键盘按下事件,按下一个键Serial 1和Serial 2 分别加上case中对应的值。
Button1Click()
0042D3C4 /. 55 push ebp ; Try_Click0042D3C5 |. 8BEC mov ebp,esp0042D3C7 |. 33C9 xor ecx,ecx0042D3C9 |. 51 push ecx0042D3CA |. 51 push ecx0042D3CB |. 51 push ecx0042D3CC |. 51 push ecx0042D3CD |. 53 push ebx0042D3CE |. 8BD8 mov ebx,eax0042D3D0 |. 33C0 xor eax,eax0042D3D2 |. 55 push ebp0042D3D3 |. 68 ADD54200 push Cabeca.0042D5AD0042D3D8 |. 64:FF30 push dword ptr fs:[eax]0042D3DB |. 64:8920 mov dword ptr fs:[eax],esp0042D3DE |. 833D 14F74200>cmp dword ptr ds:[0x42F714],0x00042D3E5 |. 74 45 je XCabeca.0042D42C0042D3E7 |. 833D 18F74200>cmp dword ptr ds:[0x42F718],0x00042D3EE |. 74 3C je XCabeca.0042D42C0042D3F0 |. 8D55 FC lea edx,[local.1]0042D3F3 |. 8B83 E0010000 mov eax,dword ptr ds:[ebx+0x1E0]0042D3F9 |. E8 E2C9FEFF call Cabeca.00419DE00042D3FE |. 837D FC 00 cmp [local.1],0x00042D402 |. 74 28 je XCabeca.0042D42C0042D404 |. 8D55 F8 lea edx,[local.2]0042D407 |. 8B83 E4010000 mov eax,dword ptr ds:[ebx+0x1E4]0042D40D |. E8 CEC9FEFF call Cabeca.00419DE00042D412 |. 837D F8 00 cmp [local.2],0x00042D416 |. 74 14 je XCabeca.0042D42C0042D418 |. 8D55 F4 lea edx,[local.3]0042D41B |. 8B83 EC010000 mov eax,dword ptr ds:[ebx+0x1EC]0042D421 |. E8 BAC9FEFF call Cabeca.00419DE00042D426 |. 837D F4 00 cmp [local.3],0x00042D42A |. 75 44 jnz XCabeca.0042D4700042D42C |> B8 C4D54200 mov eax,Cabeca.0042D5C4 ; ASCII "Fill all boxes first dumb!"0042D431 |. E8 56F6FFFF call Cabeca.0042CA8C0042D436 |. 33C0 xor eax,eax0042D438 |. A3 14F74200 mov dword ptr ds:[0x42F714],eax0042D43D |. 33C0 xor eax,eax0042D43F |. A3 18F74200 mov dword ptr ds:[0x42F718],eax0042D444 |. 33D2 xor edx,edx0042D446 |. 8B83 E0010000 mov eax,dword ptr ds:[ebx+0x1E0]0042D44C |. E8 BFC9FEFF call Cabeca.00419E100042D451 |. 33D2 xor edx,edx0042D453 |. 8B83 E4010000 mov eax,dword ptr ds:[ebx+0x1E4]0042D459 |. E8 B2C9FEFF call Cabeca.00419E100042D45E |. 33D2 xor edx,edx0042D460 |. 8B83 EC010000 mov eax,dword ptr ds:[ebx+0x1EC]0042D466 |. E8 A5C9FEFF call Cabeca.00419E100042D46B |. E9 1A010000 jmp Cabeca.0042D58A0042D470 |> 833D 14F74200>cmp dword ptr ds:[0x42F714],0x00042D477 |. 74 6C je XCabeca.0042D4E50042D479 |. 833D 18F74200>cmp dword ptr ds:[0x42F718],0x00042D480 |. 74 63 je XCabeca.0042D4E50042D482 |. 8D55 F0 lea edx,[local.4]0042D485 |. A1 14F74200 mov eax,dword ptr ds:[0x42F714]0042D48A |. E8 C190FDFF call Cabeca.00406550 ; Serial 1 = itoa([0x42F714])0042D48F |. 8B45 F0 mov eax,[local.4]0042D492 |. 50 push eax0042D493 |. 8D55 FC lea edx,[local.1]0042D496 |. 8B83 E4010000 mov eax,dword ptr ds:[ebx+0x1E4]0042D49C |. E8 3FC9FEFF call Cabeca.00419DE00042D4A1 |. 8B55 FC mov edx,[local.1] ; 输入的Serial 10042D4A4 |. 58 pop eax ; 正确的Serial 10042D4A5 |. E8 2664FDFF call Cabeca.004038D0 ; 比较0042D4AA |. 75 39 jnz XCabeca.0042D4E5 ; 爆破点0042D4AC |. 8D55 F0 lea edx,[local.4]0042D4AF |. A1 18F74200 mov eax,dword ptr ds:[0x42F718]0042D4B4 |. E8 9790FDFF call Cabeca.00406550 ; Serial 2 = itoa([0x42F718])0042D4B9 |. 8B45 F0 mov eax,[local.4]0042D4BC |. 50 push eax0042D4BD |. 8D55 FC lea edx,[local.1]0042D4C0 |. 8B83 EC010000 mov eax,dword ptr ds:[ebx+0x1EC]0042D4C6 |. E8 15C9FEFF call Cabeca.00419DE00042D4CB |. 8B55 FC mov edx,[local.1]0042D4CE |. 58 pop eax0042D4CF |. E8 FC63FDFF call Cabeca.004038D00042D4D4 |. 75 0F jnz XCabeca.0042D4E5 ; 爆破点0042D4D6 |. B8 E8D54200 mov eax,Cabeca.0042D5E8 ; ASCII "Hmmm.... Cracked... Congratulations idiot! :-)"0042D4DB |. E8 ACF5FFFF call Cabeca.0042CA8C0042D4E0 |. E9 A5000000 jmp Cabeca.0042D58A
Serial 1 = itoa([0x42F714])
Serial 2 = itoa([0x42F718])
阅读全文
0 0
- 160个练手CrackMe-021
- 160个练手CrackMe-001
- 160个练手CrackMe-002
- 160个练手CrackMe-003
- 160个练手CrackMe-004
- 160个练手CrackMe-005
- 160个练手CrackMe-006
- 160个练手CrackMe-007
- 160个练手CrackMe-008
- 160个练手CrackMe-009
- 160个练手CrackMe-010
- 160个练手CrackMe-011
- 160个练手CrackMe-012
- 160个练手CrackMe-013
- 160个练手CrackMe-014
- 160个练手CrackMe-015
- 160个练手CrackMe-016
- 160个练手CrackMe-017
- 纽约时报:揭秘 Uber 狼性企业文化
- 树莓派3B+ 软件源更改
- MWC 2017 新品终极预告:看完这篇不用看发布会了
- 四年前坚持不买苹果股票的巴菲特,近期却通过苹果股票赚了 16 亿美元
- 特斯拉股价大跌 马斯克身价缩水5亿美金
- 160个练手CrackMe-021
- sql server中T-sql语言使用注意事项
- Oracle 子查询
- 为什么说激光雷达是无人驾驶汽车的“眼睛”?| 本周专栏精选
- 照亮全面屏时代 vivo X20 全面屏手机长城盛大发布
- 数据“土豪”电信云告诉你,如何“玩转”数据生态
- 技术引进再创新,国产X86 CPU和Intel还有多少差距?
- 求1到n ,这n个整数的二进制表示比特1的个数(时间复杂度:O(n))
- 【原创】STL部分常用数据结构用法汇总 -优先队列,set