ollydbg 的初级教程 (13千字)
Newbie tutorial by Hoof Arted (Hoof's Workshop)Tutorial - Cracking and KeyGen of DLLShow by Software By Design
Target : DLLShow V4.6 - http://www.gregorybraun.com/
Tools : OllyDBG.exe - http://www.suddendischarge.com
This is my first tutorial and I hope that I will have time to write many
more. I am a newbie at cracking and it has taken me along time to get to
grips with what I am doing. Still have a long way to go. I will be trying to
make this as easy as possible for people to learn from and I do not expect
to be burned by the "PROs" out there for being to simple or doing things the
wrong way. There is no right or wrong way, as long as the target is killed.
I will start by describing the debugging application we will be using in
this tutorial.
I have never been a good SoftIce fan as trying to remember the commands and
setup are just too much for me some days. I have always liked to use W32dasm
but I have also realised that it too has many limitations. After a recent
upgrade to Windows 2000, and the subsiquent refusal of w32dasm to work, I
have set about finding a debugger / disassembler that has the same, if not
more, power than w32dasm. I have found it. Ollydbg, by Oleh Yuschuk, is just
what people like me have been waiting for. For those of you who know how to
use w32dasm, you will realise that there is a whole lot it has that cannot
be found in most other debuggers. A great job has been done here.
To kill the target today, we will be using just the tip of the iceberg of
the tools that are available in this application. Follow me, do what I do
and I will try explain as much as I can.
The reason I have chosen this target, is becuase it does not have a proper
uninstaller. Nothing pisses me off more than software vendors that do not
make their software user friendly.
Lets go.
Download a copy of the traget from the site above. Once you have extracted
it and installed it, run the DLLShow app and click the Register option. You
will see that the app requires a NAME, COMPANY and SERIAL. We all know by
now that the majority of these sort of applications will use the name and
company to generate a serial that we must match. This is the object of
cracking. Find the code, and the process of how it is created.
Ok, now we have this app that requires the serial that we do not (yet) have.
Fire up the Ollydbg and open the app (DLLShow.exe) with it. By defualt, you
will see four sections to the debugger that are used for different things.
The top left section, is used the show the disassembled code. The top right
section, is used to show the contents of the registers at all times. This is
very valuable. Unlike softice, where you have to query an address that is in
the register to see the contents, this debugger shows you the contents. If
it has an ascii word, name, or serial :-), is will show it and you do not
need to request it seperatly.
The bottom left section, shows what is currently loaded, from the app, in
memory. This is good for locating values that are used throughout the
execution. You will see how this is used later. The bottom right section,
shows memory being used by various functions. I am also a newbie and do not
fully understand this window but for now, we do not have to know.
Right, with the application loaded in the debugger, we need to run it.
Select "Debug" and click "Run" or just press F9. The application runs as
normal. Go to the registration screen and enter a NAME, COMPANY, and a
SERIAL. I have entered :
NAME : Hoof Arted
COMPANY : Hoof's Workshop
SERIAL : 77777777
You can use any serial for now, I like to start with all 7's and keep the
length to 8 characters. This makes it easy to spot. (They say that 7 is
lucky. Still waiting)
We know that if we click the OK button, the app will pop with the bad
cracker message. We need to think about where we will want to set a break
point. I like to try the GetDlgItemTextA first as this is a good one to
start with. Setting breakpoints in Ollydbg is quite a bit more difficult
because the search function does not work the way you would expect it to.
Right click on the top left section and select Search for NAME (LABEL). This
will bring up a box with all the imports that the application uses. (An
import is the functions that are called from other dlls that the app uses.)
Scroll down to USER32.GetDlgItemTextA and highlight it. Right click it and
select "Find references to import". Another box will open, showing where in
the app this is referenced. Set a breakpoint of each ref. by pressing F2.
The left hand side will be colored in red. For those of you not able to keep
up at this point, what we have done is tell the debugger to stop when one of
these imports are reached.
Right, now click the OK button on the target. The debugger will stop on
address 4159FB. We do not care about the workings of the GetDlgItem function
so what we want to do is click the address 4159FB and press F2 to clear the
breakpoint. Then, select the next line and press F2 to enable a breakpoint.
Press F9 to run the app through the import. It stops again and this time, we
can see that the ESI register(top right) now has the ASCII value "Hoof
Arted". Great, it has got our name now. If we press F9 again, the app will
stop again at the same breakpoint, but this time, ESI has out COMPANY name
as an ASCII value. Press the F9 key a third time will show ESI with our
SERIAL. OK, now we know that the app has got all out info. What does it do
with it? Lets find out.
Because it has all our info, we need to take it easy as we move through this
app from here. We cannot just go pressing F9. We will shoot right past what
we want to see. So we press F7 to take each step one at a time and we step
through the code untill we get to here :
0040D717 |. 8D4C24 40 LEA ECX,DWORD PTR SS:[ESP+40] <<<<<<<<
0040D71B |. 51 PUSH ECX
0040D71C |. E8 25990000 CALL DLLShow.00417046 <<<<<<< Call (a)
0040D721 |. 56 PUSH ESI
0040D722 |. 8BD8 MOV EBX,EAX
0040D724 |. E8 37820000 CALL DLLShow.00415960 <<<<<<< Call (b)
0040D729 |. 83C4 38 ADD ESP,38
0040D72C |. 3D 92A71901 CMP EAX,119A792
0040D731 |.,75 18 JNZ SHORT DLLShow.0040D74B
Now, if you step through the First call (Call A) you will see that it does
something to our serial number. We are not interested in this at the moment.
Set a breakpoint at 0040D721 and press F9. When we stop at the next line, we
can have a look at the EAX register. My number shows 04A2CB71. What is this
is decimal ? Whip out the calculator, non of this work it out on paper crap
and low and behold, it is our fake serial. All that call A does is convert
our fake serial to HEX. Hmmmm... interesting. Maybe the next call is where
the correct serial number is calculated. Press F7 to enter the call and then
stop. There is something I need to explain to you.
As you can see, the function is shown below :
00415960 /$ 51 PUSH ECX ;
DLLShow.00426006
00415961 |. 53 PUSH EBX
00415962 |. 8B5C24 0C MOV EBX,DWORD PTR SS:[ESP+C]
00415966 |. 56 PUSH ESI
00415967 |. 33F6 XOR ESI,ESI
00415969 |. 53 PUSH EBX ;
/Length Of Name
0041596A |. 897424 0C MOV DWORD PTR SS:[ESP+C],ESI ; |
0041596E |. FF15 B4E04100 CALL DWORD PTR DS:[<&KERNEL32.lstrlen>;
\lstrlenA
00415974 |. 85DB TEST EBX,EBX
00415976 |.,74 4F JE SHORT DLLShow.004159C7
00415978 |. 85C0 TEST EAX,EAX
0041597A |.,74 4B JE SHORT DLLShow.004159C7
0041597C |. 33D2 XOR EDX,EDX
0041597E |. 85C0 TEST EAX,EAX
00415980 |.,7E 45 JLE SHORT DLLShow.004159C7
00415982 |. 55 PUSH EBP
00415983 |. 57 PUSH EDI
00415984 |. BE 183E4200 MOV ESI,DLLShow.00423E18 ;
ASCII "|b!pz*ls;rn|lf$vi^Axpe)rx5aic&9/2m5lsi4@0dmZw94cmqpfhw"
00415989 |. BF 01000000 MOV EDI,1
0041598E |. 2BF3 SUB ESI,EBX
00415990 |. 8BCB MOV ECX,EBX ;
00415992 |. 2BFB SUB EDI,EBX
00415994 |> 0FBE1C0E MOVSX EBX,BYTE PTR DS:[ESI+ECX] ; Move
chrs from ASCII above
00415998 |. 0FBEAC10 E03D4>MOVSX EBP,BYTE PTR DS:[EAX+EDX+423DE0] ;
chr(423DE0 + Len + Pos) to EBP
004159A0 |. 0FAFDD IMUL EBX,EBP ;
Multiply vals
004159A3 |. 8D2C0F LEA EBP,DWORD PTR DS:[EDI+ECX]
004159A6 |. 0FAFDD IMUL EBX,EBP ;
Total multiplied by position starting at 1
004159A9 |. 0FBE29 MOVSX EBP,BYTE PTR DS:[ECX] ; Move
CHR from Name to EBP
004159AC |. 0FAFDD IMUL EBX,EBP ;
Multiply Total by CHR
004159AF |. 8B6C24 10 MOV EBP,DWORD PTR SS:[ESP+10] ;
Bring Total 2 from MEM. Starts as 00000000
004159B3 |. 03EB ADD EBP,EBX ; Add
Total to Total 2
004159B5 |. 42 INC EDX ; Next
CHR
004159B6 |. 41 INC ECX
004159B7 |. 3BD0 CMP EDX,EAX ; End
of Name ?
004159B9 |. 896C24 10 MOV DWORD PTR SS:[ESP+10],EBP ; Move
Total 2 back to MEM
004159BD |.^7C D5 JL SHORT DLLShow.00415994 ; Jump
to begin
004159BF |. 8BC5 MOV EAX,EBP ;
Total 2 = (NAME 1E159AD) (Company 5807304)
004159C1 |. 5F POP EDI
004159C2 |. 5D POP EBP
004159C3 |. 5E POP ESI
004159C4 |. 5B POP EBX
004159C5 |. 59 POP ECX
004159C6 |. C3 RETN
The nice thing about Ollydbg is that you can place comments nexto the ASM
commands, in real time. These comments are perminent but can be changed. I
have yet to see another debugger with this function. It rocks. Right click
the line and select Comment. That easy. No nead to make notes on paper
anymore. All the comments you see nexto the code here, was first typed into
the debugger.
Ok, What we see is that the function checks the length of the NAME
(0041596E).(We must be onto something here). It then moves the ascii
"|b!pz*ls;rn|lf$vi^Axpe)rx5aic&9/2m5lsi4@0dmZw94cmqpfhw" (00415984) into
memory. ???. So, what does this all mean? Well, if we read on, we will see
that it moves the characters from the ASCII mentioned, one by one, into EBX.
It then puts the charatesrs, one by one into EBP from address 423de0 +
(Length of our name) + (Position of character). But, what is at 423de0 ? To
find out, right click the bottom left section and select goto Address. Enter
423de0 and click OK. You will see the following info appear:
00423DE0 23 73 65 72 42 26 6E 7A 7C 6D 66 4D 31 2F 35 28 #serB&nz|mfM1/5(
00423DF0 21 73 64 24 4D 71 2E 7B 73 5D 2B 73 46 6A 74 4B !sd$Mq.{s]+sFjtK
00423E00 70 7A 53 64 74 7A 6F 58 71 6D 62 5E 41 6C 40 64 pzSdtzoXqmb^Al@d
00423E10 76 3A 73 3F 78 2F 00 00 7C 62 21 70 7A 2A 6C 73 v:s?x/..|b!pz*ls
00423E20 3B 72 6E 7C 6C 66 24 76 69 5E 41 78 70 65 29 72 ;rn|lf$vi^Axpe)r
00423E30 78 35 61 69 63 26 39 2F 32 6D 35 6C 73 69 34 40 x5aic&9/2m5lsi4@
00423E40 30 64 6D 5A 77 39 34 63 6D 71 70 66 68 77 0dmZw94cmqpfhw
This is the second part of the code used. The next line multiplies the two
values. In my case, they were 66 and 7C. It then multiplies the total, by
the position of the character in the name that is has counted to. I.e. 1 (H)
2(o).... It then takes the first character from the NAME and multiplies the
total by this. In my case, 48 (H). It then keeps a running total of all the
characters. My total is 1E159AD. Keep pressing F7 untill you reach this
point :
00415400 /$ 8B4424 04 MOV EAX,DWORD PTR SS:[ESP+4]
00415404 |. 56 PUSH ESI
00415405 |. 8B35 84C34200 MOV ESI,DWORD PTR DS:[42C384] ;
DB95DB95 = Hardcoded
0041540B |. 50 PUSH EAX
0041540C |. 81CE 78030000 OR ESI,378 ; Or
with 378 = DB95DBFD
00415412 |. E8 49050000 CALL DLLShow.00415960
00415417 |. 8B4C24 10 MOV ECX,DWORD PTR SS:[ESP+10]
0041541B |. 03F0 ADD ESI,EAX ; Add
Name total and Co total to DB95DBFD
0041541D |. 51 PUSH ECX
0041541E |. E8 3D050000 CALL DLLShow.00415960
00415423 |. 83C4 08 ADD ESP,8
00415426 |. 03C6 ADD EAX,ESI ;
Total = E2F7A8AE
00415428 |. 5E POP ESI
What this does, is it takes you total, and adds it to the hardcoded value
(DB95DB95 OR 378) = DB95DBFD. The whole process of calculating this number
for the NAME is repeated for the company. Both totals are addres to this
figure to give me E2F7A8AE. All that is left to do is convert this to
decimal.
Hoof Arted
Hoof's Workshop
3807881390
Press F9 untill you get the reg error message and enter the new code. Thats
it!!! You have cracked it.
Now we know how the code is created, you can make you own Keygen for this
app. My programming skills suck. It might be worth your while haveing a look
at the website the target comes from. I have cracked many of their apps
because, they are lazy assholes. They all use the same protection scheme.
The only thing that changes is the constant "DB95DB95".
I hope that you have learned something from this and I hope to see many more
tutorials using Ollydbg. This is one kewl debugger.
Hoof Arted (Hoof's Workshop) "Go forth and KICK ass!"
h_arted@hotmail.com
