Fixing Converted Code [Solved]

Posts 1–15 of 19 · Page 1 of 2
Fixing Converted Code [Solved]
i've procceded to do some reverse engineering work to fix some code that i've found.

After decomplieing the .exe ive come up with this sub routine that holds the crypto class to that of the .exe..

Was wondering if anyone had any better ideas to short this down to a smaller function with only using 2 variables...

Code:
//----- (00842A80) --------------------------------------------------------
char __thiscall sub_842A80(void *this, int a2, unsigned int a3)
{
  char result; // 
  unsigned int i; // 
  char v5; // 

  if ( a2 )
  {
    for ( i = 0; i < a3; ++i )
    {
      if ( *(_BYTE *)(i + a2) )
      {
        v5 = *((_BYTE *)this + i % 0xB) ^ *(_BYTE *)(i + a2);
        if ( v5 )
          *(_BYTE *)(i + a2) = v5;
      }
    }
    result = 1;
  }
  else
  {
    result = 0;
  }
  return result;
}
now im trying to shortin it down to something like this but it doesnt seem right..

Code:
void CCrypto::cypto( unsigned char* buffer, unsigned size )
{
		
	for ( unsigned i = 5; i < size; i++)
	{
		
		buffer[i] = (byte)(buffer[i]^0xB );
	}
}
Does this seem right at all????? If u like i can post the ASM to hopefully understand it more...
Err, I found a weird error in your code ._.

Code:
BYTE bVal(int addr) { return *(BYTE*)addr; }

bool Poop(void* this, int offset, uint len)
{
    if (offset > 0)
    {
        for (int i = 0; i < len; i++)
        {
            if (bVal(i + offset) > 0)
            {
                char t = bVal((this + i % Bh) ^ bVal(i + offset));
                if (t > 0)
                    *(_BYTE *)(i + offset) = t; // Err... assignment operation invalid for rvalue ...
            }
        }
    }
    else
        return false;
    return true;
}
it's suppose to be xor with the key being 0xB.

It's suppose to xor the buffer based on the size of the buffer from what it looks like. Was having issues being able to covert it from asm base on what i saw in the debugger.
why would a crypting function return a boolean
Quote Originally Posted by kibbles18 View Post
why would a crypting function return a boolean
To indicate if the crypting succeeded ?
hope this helps more..

Code:
 var_C           = dword ptr -0Ch
 var_8           = dword ptr -8
 var_1           = byte ptr -1
 arg_0           = dword ptr  8
 arg_4           = dword ptr  0Ch

                 push    ebp
                 mov     ebp, esp
                 sub     esp, 0Ch
                 push    esi
                 mov     [ebp+var_C], ecx
                 cmp     [ebp+arg_0], 0
                 jnz     short loc_842A94
                 xor     al, al
                 jmp     short loc_842AF7
 ; ---------------------------------------------------------------------------

 loc_842A94:                             ; CODE XREF: sub_842A80+Ej
                 mov     [ebp+var_1], 0
                 mov     [ebp+var_8], 0
                 jmp     short loc_842AAA
 ; ---------------------------------------------------------------------------

 loc_842AA1:                             ; CODE XREF: sub_842A80:loc_842AF3j
                 mov     eax, [ebp+var_8]
                 add     eax, 1
                 mov     [ebp+var_8], eax

 loc_842AAA:                             ; CODE XREF: sub_842A80+1Fj
                 mov     ecx, [ebp+var_8]
                 cmp     ecx, [ebp+arg_4]
                 jnb     short loc_842AF5
                 mov     edx, [ebp+arg_0]
                 add     edx, [ebp+var_8]
                 movzx   eax, byte ptr [edx]
                 test    eax, eax
                 jz      short loc_842AF3
                 mov     ecx, [ebp+arg_0]
                 add     ecx, [ebp+var_8]
                 movzx   ecx, byte ptr [ecx]
                 mov     eax, [ebp+var_8]
                 xor     edx, edx
                 mov     esi, 0Bh
                 div     esi
                 mov     eax, [ebp+var_C]
                 movsx   edx, byte ptr [eax+edx]
                 xor     ecx, edx
                 mov     [ebp+var_1], cl
                 movzx   eax, [ebp+var_1]
                 test    eax, eax
                 jz      short loc_842AF3
                 mov     ecx, [ebp+arg_0]
                 add     ecx, [ebp+var_8]
                 mov     dl, [ebp+var_1]
                 mov     [ecx], dl

 loc_842AF3:                             ; CODE XREF: sub_842A80+3Dj
                                         ; sub_842A80+66j
                 jmp     short loc_842AA1
 ; ---------------------------------------------------------------------------

 loc_842AF5:                             ; CODE XREF: sub_842A80+30j
                 mov     al, 1

 loc_842AF7:                             ; CODE XREF: sub_842A80+12j
                 pop     esi
                 mov     esp, ebp
                 pop     ebp
                 retn    8
 sub_842A80      endp
its suppose to be a simple xor.. based from a buffer and length of the buffer.
how does this look?

Code:
void CCrypto::cypto( unsigned char* buffer, unsigned size )
{
		
	for ( unsigned i = 5; i < size; i++)
	{
		
		buffer[i] = (byte)(buffer[i] % 0xB )^ (byte)(buffer[i] + 0);
	}
}
Here is an accurate decompilation based on the disassembly you have posted.
Code:
//unsigned char unknown_key[10];

bool CCrypto::Encrypt(unsigned char* buffer, unsigned int size)
{
  if (buffer == null)
    return false;

  for (unsigned int i = 0; i < size; i++)
  {
    if (buffer[i] != 0)
    {
      unsigned char ch = unknown_key[i % 0xB] ^ buffer[i];

      if (ch)
        buffer[i] = ch;
    }
  }
  
  return true;
}
unknown_key is a 10 byte xor key that is a member of the CCrypto class.
Ya that's what I have as my source as well. The only problem is that unknown_key holds something that I have no idea on.

Code:
21 00 01 00 5d 6c 00 00 7a 7c 6f 00 00 00 00 00 5b 51 4f 59 44 5f 5e 52 5d 5d 40 5e 52 00 00 00 00
This hex here should decrypt into my ip address which is doesn't. Here is the C file mabye anyone else can understand more than I can.

Virus Scan on the .rar file

http://www.virustotal.com/file-scan/...16b-1316159312
Client.rarattachment deleted · 6 downloads before removal
@faceofdevil
Set the key to the first 10 chars of your ip and call encrypt on it, then you'll have the original 10 chars
That is assuming it'll end in the same positiom as what contains your ip
@faceofdevil: What the fuck ? What kind of C file is that ????? 901319 lines -.-
Anyways, approved. Anyone who downloads it should run it should check the code before running it lol.
@Hell_Demon: Check the file for lulz plz ? ;P
@Hassan it's a .exe that's been dissembled into .c

If u look at the sub functions and follow it thru it gives you idea in what i was talking about. And you wont be able to run it bec its a decomplied file not a complieable file.

I merly found the sub function that i thought was a routine and dissembled it to work the same way.
Assuming that the key is static, you can do what Hell_Demon suggested because of the properties of xor.

However, if the key is in any way modified during run-time, you must reverse this mechanism. The key could be periodically transformed, or even set by the server. As it is a class member, following this references will help.
Would you have any suggestions or help into hooking that function and printing out what gets sent into that pointer?
Posts 1–15 of 19 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us