[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Hacking Challenge

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 6
Thread images: 1

File: lel.png (154KB, 1012x502px) Image search: [Google]
lel.png
154KB, 1012x502px
Any CSfags in here want to help me out?

I came across this program OllyDbg, and by messing around with it for a little, obviously it's purpose is to manipulate applications processes.

I saw that you can use this to "crack" paid applications. Being a WoT fag, I really want to crack this bot and see how good it really is.

I see that the application is written in assembly, so i'm trying to figure out the pathway to the application requesting, and verifying the product key.

Upon running the program, it hits a LEAVE twice, which i'm assuming is just the application loading the main, and the login window along with it's data.

After that, if you push an exception after the 2nd LEAVE it comes to a ADD.ESP.4

Being totally unfamiliar with assembly, i'm not sure what most of this means, i can only see how it works via process. I know that somewhere in between there, i'm trying to find the line that changes a hex value that correlates to a .dll in the system files that allows the application to proceed once given the key. No matter what breakpoints i've tried, nothing has really worked.

This could be very fun, and a great learning experience if anybody would like to join in, and assist a semi-noob coder.
>>
Bump

Really? This board is dead af
>>
>>>/g/
>>
>>8732861

I doubt it was written in assembly... too much work for writing high level logic and network handling. (of course you see assembly now, after the compiler translated it to assembly.) that add esp,4 and leave stuff is about the stack frame of a function call and has nothing to do with the stuff you're interested in. assembly is the most unintuitive form of reading code, so i would recommend you to look for a decompiler to get some more high level language output. good luck, semi coder.
>>
Everything compiles to asm
Read a books on assembly, computer architecture, and reverse engineering
>>
>>8732861
Anon, I have the developer of this Bot on my skype,we're good friends.

Also, this bot was written in C# and obfuscated with SmartAssembly.

Drag the executable inside de4Dot(download this) and then open it with dnSpy (best tool for MSIL)
Thread posts: 6
Thread images: 1


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.