Jump to content


Photo
- - - - -

[crackme] A very cool crackme with strong anti-debugger


  • This topic is locked This topic is locked
10 replies to this topic

#1 cooooldog

cooooldog

    Member

  • (Full Member)
  • 91 posts

Posted 22 December 2010 - 05:33 AM

Notepad with strong anti-debugger protection.

StongOD does not work. How to debug it?

thanks

Attached File  notepad_se.rar   1.02MB   127 downloads

#2 Teddy Rogers

Teddy Rogers

    Site Administrator

  • (Administrator)
  • 9,948 posts
  • Gender:Male
  • Location:Australia

Posted 22 December 2010 - 07:58 PM

The [crackme] tag has been added to your topic title.

Please remember to follow and adhere to the topic title format - thankyou!

[This is an automated reply]

Posted Image
I would love to change the world, but they won't give me the source code...


#3 ErrorShow

ErrorShow

    Newbie

  • (Junior)
  • 4 posts

Posted 22 December 2010 - 08:44 PM

Notepad with strong anti-debugger protection.

StongOD does not work. How to debug it?

thanks

Attached File  notepad_se.rar   1.02MB   127 downloads


哈哈,这么厉害啊。海风的StrongOD,也抗不住么?
learning,learning...and never stop learning!

#4 EvOlUtIoN

EvOlUtIoN

    Unpacker/Cracker/Coder

  • (Team Member)
  • 448 posts
  • Gender:Male
  • Location:Italy

Posted 24 December 2010 - 09:07 AM

safengine protector?
Nothing is impossible!

#5 denoiser

denoiser

    o.O

  • (Junior+)
  • 25 posts
  • Gender:Male
  • Location:in mess
  • Interests:PACE Interlok

Posted 24 December 2010 - 12:32 PM

this is Shielden v2.0.0

To start debugging break on system entry point and soon will end up on call to GetThickCount which is obviously not jumping (in jump table) where is supposed to. Try to avoid this call and you can start unpacking from there.

Edited by denoiser, 24 December 2010 - 12:36 PM.

Posted Image

#6 LCF-AT

LCF-AT

    I Need A Social Life

  • (Full Member+)
  • 2,226 posts
  • Gender:Not Telling
  • Location:Château-Saint-Martin

Posted 24 December 2010 - 03:14 PM

@ denoiser

So do you mean to bypass the Safeengine message?
Can you post the code part from the place where you talking about?

greetz
Posted Image

#7 LCF-AT

LCF-AT

    I Need A Social Life

  • (Full Member+)
  • 2,226 posts
  • Gender:Not Telling
  • Location:Château-Saint-Martin

Posted 24 December 2010 - 04:07 PM

Ok I see the unpackme has alomst nothing enabled to unpack it! :)
Here my unpacked file without bypassing the Safeengine message!

greetz

Attached Files


Posted Image

#8 cooooldog

cooooldog

    Member

  • (Full Member)
  • 91 posts

Posted 24 December 2010 - 11:51 PM

@LCF-AT

Would you please share us the tips how you can do it?

Since you know, notepad.exe is very popular everywhere :thumbsup:

though I believe absolutely you can get it debugged and unpacked...

just prove it and show it...

and the most importantly, teach us how to do it...

and then Merry christmas and thank you for sharing :yahoo:

Ok I see the unpackme has alomst nothing enabled to unpack it! :)
Here my unpacked file without bypassing the Safeengine message!

greetz



#9 EvOlUtIoN

EvOlUtIoN

    Unpacker/Cracker/Coder

  • (Team Member)
  • 448 posts
  • Gender:Male
  • Location:Italy

Posted 25 December 2010 - 03:54 PM

mayb e it's protected by a trial version of protector?
Nothing is impossible!

#10 Nooby

Nooby

    Member

  • (Full Member)
  • 77 posts

Posted 27 December 2010 - 04:02 AM

it is protected by:
1.Ctrl+G 100739D and write 6A 70
2.dump
3.grab IAT, resource section(see PE header) from a running process
;)

Edited by Nooby, 27 December 2010 - 04:18 AM.


#11 cooooldog

cooooldog

    Member

  • (Full Member)
  • 91 posts

Posted 29 December 2010 - 07:42 AM

@Nooby

谢了, 哥.

@LCF-AT

你啥时候回来? when will you be back ah?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users