Results 1 to 15 of 15
  1. #1
    xPerfection's Avatar
    Join Date
    Sep 2007
    Gender
    male
    Location
    echo $location
    Posts
    38
    Reputation
    10
    Thanks
    0

    [Challenge] Crack Me

    Well its the first 'Crack Me' application I've ever made.
    So don't be mad if its too easy (I don't think it is but however).
    Post a screenshot inside the program when you've done cracking it.

    Virus Scan:
    https://www.virustotal.com/resultado....a1e49df24597b9

    Download (Attached):
    - a security problem was found, please download the new version.
    (its the fixed version)
    Last edited by xPerfection; 09-15-2007 at 12:05 PM.
    xPerfection - Websites and applications programmer.


  2. #2
    radnomguywfq3's Avatar
    Join Date
    Jan 2007
    Gender
    male
    Location
    J:\E\T\A\M\A\Y.exe
    Posts
    8,858
    Reputation
    381
    Thanks
    1,823
    My Mood
    Sad
    One question, did you like translate your password in to some sort of wired string. Because all I can find that could be a password is
    @#n¥65)¦?
    but wait i'm going to try and crack it with ollydbg..

  3. #3
    Jeckels's Avatar
    Join Date
    Apr 2007
    Location
    C:WINDOWS/system32/
    Posts
    1,236
    Reputation
    15
    Thanks
    45

    Cool

    Probably Packed it :/

  4. #4
    radnomguywfq3's Avatar
    Join Date
    Jan 2007
    Gender
    male
    Location
    J:\E\T\A\M\A\Y.exe
    Posts
    8,858
    Reputation
    381
    Thanks
    1,823
    My Mood
    Sad
    Yay, thats what I was thinking, and you can't really decompile VB code so. Is there anyway around this?

  5. #5
    castaway's Avatar
    Join Date
    Mar 2007
    Location
    In a BIG Box.
    Posts
    1,636
    Reputation
    14
    Thanks
    97
    Quote Originally Posted by jetamay View Post
    Yay, thats what I was thinking, and you can't really decompile VB code so. Is there anyway around this?
    yeah
    ollydbg
    but uhmmm
    it looks like a random password...

  6. #6
    w00t?'s Avatar
    Join Date
    Jul 2007
    Gender
    male
    Posts
    257
    Reputation
    10
    Thanks
    29
    Yes i will also try ollydebuger...hehee i discovered whats inside...when u type correct password ask u for name and type crackedby <name>

    but not sure...dont get password yet
    Last edited by w00t?; 09-15-2007 at 09:46 AM.

  7. The Following User Says Thank You to w00t? For This Useful Post:

    joeyjoey (04-04-2008)

  8. #7
    xPerfection's Avatar
    Join Date
    Sep 2007
    Gender
    male
    Location
    echo $location
    Posts
    38
    Reputation
    10
    Thanks
    0
    Its not packed
    And its not a random password, the same password for always

    @woot?
    Yea you right lol

    HINT:
    Its may be a lil hard to crack because on each form its validating if you are really entered the correct password, therefore, just passing the form without entering the correct password (AKA without making the program thinks you did) will result in a error on the next form.
    Last edited by xPerfection; 09-15-2007 at 10:50 AM.
    xPerfection - Websites and applications programmer.


  9. #8
    w00t?'s Avatar
    Join Date
    Jul 2007
    Gender
    male
    Posts
    257
    Reputation
    10
    Thanks
    29
    Yes i tryed bypassing the password form but get error...let me try again...

  10. #9
    xPerfection's Avatar
    Join Date
    Sep 2007
    Gender
    male
    Location
    echo $location
    Posts
    38
    Reputation
    10
    Thanks
    0
    If you passed the password form (done half a way) you shoulda get that message on the next form "Incorrect password was found, you got cought noob."
    Now you gotta bypass the password validation checks. (there's two, one on each form).

    And you done

    Or just get the password..
    Last edited by xPerfection; 09-15-2007 at 03:43 PM.
    xPerfection - Websites and applications programmer.


  11. #10
    ZeaS's Avatar
    Join Date
    Feb 2007
    Posts
    738
    Reputation
    15
    Thanks
    265
    Quote Originally Posted by xPerfection View Post
    If you passed the password form (done half a way) you shoulda get that message on the next form "Incorrect password was found, you got cought noob."
    Now you gotta bypass the password validation checks. (there's two, one one each form).

    And you done

    Or just get the password..
    lol thats nice ^^ can you send me the source data?? ^^

  12. #11
    xPerfection's Avatar
    Join Date
    Sep 2007
    Gender
    male
    Location
    echo $location
    Posts
    38
    Reputation
    10
    Thanks
    0
    Quote Originally Posted by ZeaS View Post
    lol thats nice ^^ can you send me the source data?? ^^
    Do you got MSN?

    PM it to me.
    Last edited by xPerfection; 09-15-2007 at 04:19 PM.
    xPerfection - Websites and applications programmer.


  13. #12
    ZeaS's Avatar
    Join Date
    Feb 2007
    Posts
    738
    Reputation
    15
    Thanks
    265
    i got it cracked ^^


  14. #13
    lucaking1's Avatar
    Join Date
    May 2007
    Posts
    36
    Reputation
    10
    Thanks
    0
    Thats badass Zeas! ( can u teach me ?:P) ima D.X!T Member too you know :P
    Last edited by lucaking1; 09-17-2007 at 01:48 PM.

  15. #14
    xPerfection's Avatar
    Join Date
    Sep 2007
    Gender
    male
    Location
    echo $location
    Posts
    38
    Reputation
    10
    Thanks
    0
    Quote Originally Posted by lucaking1 View Post
    Thats badass Zeas! ( can u teach me ?:P) ima D.X!T Member too you know :P
    Its got crack in this way:
    Quote Originally Posted by zart
    Found the routine getting called by the click event, and looked at this;

    Code:
    004035E8   > 8B45 E8        MOV EAX,DWORD PTR SS:[EBP-18]
    004035EB   . 50             PUSH EAX                                 ;  out password
    004035EC     68 AC284000    PUSH Crack_Me.004028AC                   ;  the password
    004035F1   . FF15 40104000  CALL DWORD PTR DS:[<&MSVBVM60.__vbaStrCm>;  MSVBVM60.__vbaStrCmp
    004035F7   . 8BF0           MOV ESI,EAX                              ;  load result into esi
    004035F9   . 8D4D E8        LEA ECX,DWORD PTR SS:[EBP-18]
    004035FC   . F7DE           NEG ESI                                  ;  negate esi
    004035FE   . 1BF6           SBB ESI,ESI                              ;  sub esi esi
    00403600   . 46             INC ESI                                  ;  increase esi by one
    00403601   . F7DE           NEG ESI                                  ;  negate esi
    00403603   . FF15 98104000  CALL DWORD PTR DS:[<&MSVBVM60.__vbaFreeS>;  MSVBVM60.__vbaFreeStr
    00403609   . 8D4D E4        LEA ECX,DWORD PTR SS:[EBP-1C]
    0040360C   . FF15 9C104000  CALL DWORD PTR DS:[<&MSVBVM60.__vbaFreeO>;  MSVBVM60.__vbaFreeObj
    00403612   . 66:3BF7        CMP SI,DI
    00403615     0F84 D7000000  JE Crack_Me.004036F2
    An invalid serial would return 1 to eax, making the end result when it gets to 00403612 be comping 0 to 0... A valid serial would be something else and zero, taking the jump.

    Changing the JE to JNZ would make it jump on everything but the real password.
    Last edited by xPerfection; 09-17-2007 at 03:39 PM.
    xPerfection - Websites and applications programmer.


  16. #15
    lucaking1's Avatar
    Join Date
    May 2007
    Posts
    36
    Reputation
    10
    Thanks
    0
    With ollyDBG?

Similar Threads

  1. Good Cracks/Serials/Keygens website
    By Elmo in forum Spammers Corner
    Replies: 11
    Last Post: 10-22-2016, 07:05 AM
  2. Cracking challenges have been *** !!! (2)
    By no888 in forum Reverse Engineering
    Replies: 2
    Last Post: 06-07-2011, 02:50 PM
  3. Cracking challenges have been *** !!!
    By no888 in forum Reverse Engineering
    Replies: 0
    Last Post: 03-06-2011, 12:12 PM
  4. Challenge-Cracking WRhax Vip Hack
    By CrazyCracker in forum WarRock - International Hacks
    Replies: 13
    Last Post: 07-31-2007, 01:59 AM
  5. Challenge Thread
    By arunforce in forum General
    Replies: 7
    Last Post: 03-26-2007, 01:22 PM