Jump to content
Tuts 4 You

[crackme] [.NET] BreakTheMeta (Fix The MetaData)


v0k3

Recommended Posts

Hello reversers,


 


my name is V0K3 and I'm new in this wonderful community!


Today I will post a project done by Lollo90 (and me) for the new entries of the .NET reversing.


This is a pack (probably later there will be more than one) of 10 NET fixmes, the only things you have to do is fixing their MetaData and then change the text of the textbox with both Reflector and SimpleAssemblyExplorer.


 


Is preferred to do it manually so you can write a little tutorial / document on how to fix that specific MetaData.


I know that this won't be hard for you, anyway it can be interesting for the new (.NET) crackers that doesn't know how to deal with MetaData errors.


 


Each Challenge contains 9 simple fixmes and a strong one (not for you :P), we will release a Challenge every week while we have enough 'tricks' :D.


 


I hope you enjoy it :)


 


Cya o/


BreakTheMeta_CHALLENGE1.7z

Edited by v0k3
Link to comment

which one u want break or crack or unpack ? i can try only one which one is most hard /.? and u wanted break it . i see there many file BreakTheMeta_STRONG1.exe one i am trying cracking and unpacking. 


 


ahh lollo60 noob who is put always invalid typdef and token manager and invalid fake method many like 1 milioon by modifiying another obfucator none of his own obfucator ,


Edited by Death
Link to comment

which one u want break or crack or unpack ? i can try only one which one is most hard /.? and u wanted break it . i see there many file BreakTheMeta_STRONG1.exe one i am trying cracking and unpacking. 

 

ahh lollo60 noob who is put always invalid typdef and token manager and invalid fake method many like 1 milioon by modifiying another obfucator none of his own obfucator ,

What's the point of this answer?

This post doesn't make sense, read the topic first please.

Edited by v0k3
Link to comment

@v0k3  BRO in this section rules



CrackMe's / UnPackMe's / KeygenMe's

so u should read first the section rules.


 


only for u this forums dont going to change rules spechially only for u .which is useless in this exe just module give in invalid site and some 2 invalid class nothing else. all fixed


 


 


kinda noob shit i will give source of ur challange  BreakTheMetadata.exe in next post which is useless nothing special . 


Edited by Death
Link to comment

easy shit + wast timer nothing is obfucate . just invalid token and signeture

As it is stating the first post, these are more for people new to .NET reversing that are learning different techniques and such. It is not aimed for people that already know how to crack and patch .NET applications and such.

  • Like 1
Link to comment

@at0ms as i say i understood what u talking about . the exe which is BreakTheMeta_CHALLENGE1.7z readil not so hard that he putted invalid metadata 1 million or 1 thousand and hide module or change module place for sae and reflector anti -> the mention i said who have basic knowledge in .net he can eassily view these by any other explorer . in internet not had only sae and reflector there had more hard explorer which can view il code if file main header is ok . 


example byteme.exe and have some more so there put and see il and read il not so hard and crack not so hard everything there possible . byteme.exe is good explorer and other many related explorer have which not need read file body just file main header is ok then can read these explorer with all can do modify and everything can do cause it reading hex byte il and grabing exe by file header and after modify save it as same cff nothing is change and exe never be crash  .


 


at last i can say u . one way u r right who r fully new b there people for this kind tools hard because they cant read il and who are just normal reverser they can modify it by that explorer eassily [example byteme , and had more]


 


sae and reflector not only one explorer in net there had more hard decompiler . suppose visual studio also can run time read class by debugging an see full can see full src c# so in the result at should give some obfucation these kinda new invalid metadata putting new making deobme or fix metadata [invalid signeture all method and module which for exe is running but sae and reflector can't read but as i say read from first again then understood what i mean. however these new kinda tools which give invalid metadata its not called obfucator its just anti reflector and sae . and this tools fully copied from yck confuser open src which had these that he making deob me they just copied from there the src , yck is pro about it thats for his previous obfucator is doing this . so that lollo or however who making they just copyied yck confuser that src and bit more modding nothing else and nothing new .


 


plss read my post carefully then all understood my english is bad but i hope what i said is proper clear understoodable who know basic english ,


and my signature saying all , so => you totally wrong if u understood what write read carefully u understand .


1. you post r right



 
As it is stating the first post, these are more for people new to .NET reversing that are learning different techniques and such. It is not aimed for people that already know how to crack and patch .NET applications and such. 

for new b mean who r just start reversing today


2.your post fully wrong 


for the user who have understand basic idea about reversing .


 


and remember it invalid metadata putted like this in a exe then it hard to obfucate cecil , dnlib , non of obfucator cant obfucate this kinda file.because obfucator already read first mainfest module and every method token which is invalid that he gave no way to obfucate these kinda file so its properlyyyyyyyyyy useless and that moded obfucator src is copied from yck or ka obfucator old src which gave like that invalid metadata by cecil modifying . and codecracker also made lot tools for fix it , i cant explain more tired by writing these . i wish u bit understood.


but possible obfucate this kinda file which related dngguard hvm obfucator its coded with native so these kinda obfucator only can obfucate these file .


 


and what i said u understood easily if u understand .net language and pro reverser in .net other wise dont read . just forget and should not post more which u not understood and post like blind just for support.


my post understand eassily the guys => yck,oxd4d,codecracker only . other people understand or not i dont know.


 


and have more to say which if i fully explain then need two page so just bit saying for make u understand.


 


good luck


Edited by Death
Link to comment

and this invalid metadata putting and after obfucate . this kind of obfucator i think yck1509 was first guy who made it


http://markmail.org/message/lpl5vp5je3wgyntl


and codecracker also make tools for it universal fixer for fix it .


 


and now that lollo or what ever who doing these i dont know, that was just copied from confuser src they just modding it and put more the result => these file are no way to obfucate which cant read module and method for invalid sigenture which called metadata and chaning module place. its can obfucate if that lollo or whatever who made this if want obfucation then he have to make a new visual studio advance 2099 special edition :-D.


Edited by Death
Link to comment

@at0ms as i say i understood what u talking about . the exe which is BreakTheMeta_CHALLENGE1.7z readil not so hard that he putted invalid metadata 1 million or 1 thousand and hide module or change module place for sae and reflector anti -> the mention i said who have basic knowledge in .net he can eassily view these by any other explorer . in internet not had only sae and reflector there had more hard explorer which can view il code if file main header is ok . 

example byteme.exe and have some more so there put and see il and read il not so hard and crack not so hard everything there possible . byteme.exe is good explorer and other many related explorer have which not need read file body just file main header is ok then can read these explorer with all can do modify and everything can do cause it reading hex byte il and grabing exe by file header and after modify save it as same cff nothing is change and exe never be crash  .

 

at last i can say u . one way u r right who r fully new b there people for this kind tools hard because they cant read il and who are just normal reverser they can modify it by that explorer eassily [example byteme , and had more]

 

sae and reflector not only one explorer in net there had more hard decompiler . suppose visual studio also can run time read class by debugging an see full can see full src c# so in the result at should give some obfucation these kinda new invalid metadata putting new making deobme or fix metadata [invalid signeture all method and module which for exe is running but sae and reflector can't read but as i say read from first again then understood what i mean. however these new kinda tools which give invalid metadata its not called obfucator its just anti reflector and sae . and this tools fully copied from yck confuser open src which had these that he making deob me they just copied from there the src , yck is pro about it thats for his previous obfucator is doing this . so that lollo or however who making they just copyied yck confuser that src and bit more modding nothing else and nothing new .

 

plss read my post carefully then all understood my english is bad but i hope what i said is proper clear understoodable who know basic english ,

and my signature saying all , so => you totally wrong if u understood what write read carefully u understand .

1. you post r right

 

As it is stating the first post, these are more for people new to .NET reversing that are learning different techniques and such. It is not aimed for people that already know how to crack and patch .NET applications and such. 

for new b mean who r just start reversing today

2.your post fully wrong 

for the user who have understand basic idea about reversing .

 

and remember it invalid metadata putted like this in a exe then it hard to obfucate cecil , dnlib , non of obfucator cant obfucate this kinda file.because obfucator already read first mainfest module and every method token which is invalid that he gave no way to obfucate these kinda file so its properlyyyyyyyyyy useless and that moded obfucator src is copied from yck or ka obfucator old src which gave like that invalid metadata by cecil modifying . and codecracker also made lot tools for fix it , i cant explain more tired by writing these . i wish u bit understood.

but possible obfucate this kinda file which related dngguard hvm obfucator its coded with native so these kinda obfucator only can obfucate these file .

 

and what i said u understood easily if u understand .net language and pro reverser in .net other wise dont read . just forget and should not post more which u not understood and post like blind just for support.

my post understand eassily the guys => yck,oxd4d,codecracker only . other people understand or not i dont know.

 

and have more to say which if i fully explain then need two page so just bit saying for make u understand.

 

good luck

I tried to understand your post but i don't understand anything. I suggest you to learn english first... then you will be able to come here again and talk as a normal person.

  • Like 1
Link to comment

@Death


 


I know very very well, that English is not your native language.  But sorry to say brother, I had the same issue. I stopped reading the whole thing after first 2 lines because it was really hard to understand except few points about SAE and reflector.


 


@LoLLo90


 


Dont be rude man, there are plenty of people who cant speak English.  Even English is not my native language too.


Link to comment

@Death

 

I know very very well, that English is not your native language.  But sorry to say brother, I had the same issue. I stopped reading the whole thing after first 2 lines because it was really hard to understand except few points about SAE and reflector.

 

@LoLLo90

 

Dont be rude man, there are plenty of people who cant speak English.  Even English is not my native language too.

I haven't anything against not english people, infact i am italian!But really i can't understand what he wrote.. 

Link to comment

@mr lollo60 


shortcut 


1. as i say 



my post understand eassily the guys => yck,oxd4d,codecracker only . and other people also who understand if he know about invalid token and signeture .
 
2. this invalid metadata u putting invalid signeture and and invalid token => the result u cant obfucate it by vs studio cant read your method body instrucion module e.t.c

3. and this invalid metadata putting and after obfucate . this kind of obfucator i think yck1509 was first guy who made it


http://markmail.org/...pl5vp5je3wgyntl


and codecracker also make tools for it universal fixer for fix it .


you just following that src and put much invalid meta data the result u cant obfucate it for the module place u r changing vs studio cant read it . so this is nothing related anyobfucator and it cant possible to obfucate .


 


so just saying this is totally useless putting much invalid token in every method the result for u cant obfucate it for invalid token every method .


so this is very very very very easy to modify the exe by byte me like this explorer [and have more to say which i cant say again already told] .


 


its eassy to view src by debuging time just vs studio select view class u can see source .


 


shortcut 


1. as i say 



my post understand eassily the guys => yck,oxd4d,codecracker only . and other people also who understand if he know about invalid token and signeture .
 
2. this invalid metadata u putting invalid signeture and and invalid token => the result u cant obfucate it i vs studio cant read your method body instrucion module e.t.c

3. and this invalid metadata putting and after obfucate . this kind of obfucator i think yck1509 was first guy who made it


http://markmail.org/...pl5vp5je3wgyntl


and codecracker also make tools for it universal fixer for fix it .


you just following that src and put much invalid meta data the result u cant obfucate it for the module place u r changing vs studio cant read it . so this is nothing related anyobfucator and it cant possible to obfucate .



so just saying this is totally useless putting much invalid token in every method the result for u cant obfucate it for invalid token every method .
so this is very very very very easy to modify the exe by byte me like this explorer [and have more to say which i cant say again already told] .
 
its eassy to view src by debuging time just vs studio select view class u can see source .

so its a uselesss that u r givining invalid signeture and token and class method and module location change which eassy can see by any byte explorer


 


if u now still now understand then i have to say you go in english school and learn . and say your teacher to learn me short cut english language talking .


 


uselesss this exe that u gave much invalid which was confuser relationship . but now ka not give much invalid metadata for obfucate method more powerfull. have just saying make unpackme which obfucated not invalid metadata shit its useless .


useless why read again 


 


and never going to learn english only for you who dont understand english himself.


 


@Kingstaa


now read again this post . if u luck to understand. 


 


and just if still not understood then dont reply my post.

Edited by Death
Link to comment

@Death


 


First of all, I had no intention of replying to your post, which was hard to read and only special people on your list can understand.  I only replied because I did not find appropriate what lollo60 replied.


 


One more thing, if you want no one should reply to your post, then its good my friend to write in notepad and make yourself feel happy because board is not the right place for you then.


Edited by Kingstaa
Link to comment

i really dont understand why not understand a simple thing if u put much invalid signature and invalid token in every method and hide module in wrong place that exe only u can run but can not obfucate any of method no way that cause vs studio cant obfucate that exe and no way to obfucation thats for he wrote in title "


BreakTheMeta (Fix The MetaData)"  but other some hard decompiler eassily can take the exe full body and can read source or copy cause its not odfuciated.


"


 


now understand? plss let me know?


 


and this invalid metadata put this thing discover first yck 1509 was the first guy http://markmail.org/message/lpl5vp5je3wgyntl so he just follow that confuser src and use a combine obfucator for give some invalid namespace and class and method in exe but exe main code no way to obfucicate. and he modded more the result for he cant give obfucication exe main source cause obsucate time any obfucator or vs studio read module first and method token so there is no way to obfucate it.


 


thats for saying its useless and kidding that he discover a new thing "breakme by sae and reflector" but other any explorer can eassily  take the exe main source and can modify the exe and can do anything whatever u want .


 


thast what i mean,now explain eassily understandable? or still u not understand @


Kingstaa ? plss let me know . if not i will try a other way to make u understand.


 


 


so the result its very very eassy to modify or crack the exe all u can .this is a useless thing and just kidding for new reverser who just started today learn reversing for them its hard only  .


 


its not a obfucator its u can call its a kidding thing .


 


is ok i know he just said u to stop me and not post here cause what i saying if u understand then u also say yes u r right its just kidding for new b.


 


if u want i can write tut now here how to mode this exe how we can see exe source how we can can crack this exe its very very eassy.


 


universal fixer a tools u know so just drop there and fix something which is main thing in the exe then other what to do if u want i can explain now


Edited by Death
Link to comment

thanks i feel good because now u can understand something what i want to say .


my english is bad thats for write very fast and thought that understood able but i see no one understand me what i want to say


Link to comment

@Death: thank you, this is much better. Now I can understand what you are trying to say. It helps to use "." in the end of sentence and BIG letters in the beginning of sentence. :)

@v0k3, @LoLLo90: it's a nice challenge for beginners, thanks!. However, there are few bugs in your challenges. For example, #2 will crash on closing main form:

System.BadImageFormatException: [C:\BreakTheMeta2.exe] The signature is incorrect.   at Fix_The_Data_Is_Your_Meta.Main.Dispose(Boolean disposing)   at System.ComponentModel.Component.Dispose()   at System.Windows.Forms.Form.WmClose(Message& m)   ..
I didn't try to run CodeCracker's tools on your files, but I'm guessing they would take care of most of the invalid metadata.
Link to comment

@Death: thank you, this is much better. Now I can understand what you are trying to say. It helps to use "." in the end of sentence and BIG letters in the beginning of sentence. :)

@v0k3, @LoLLo90: it's a nice challenge for beginners, thanks!. However, there are few bugs in your challenges. For example, #2 will crash on closing main form:

System.BadImageFormatException: [C:\BreakTheMeta2.exe] The signature is incorrect.   at Fix_The_Data_Is_Your_Meta.Main.Dispose(Boolean disposing)   at System.ComponentModel.Component.Dispose()   at System.Windows.Forms.Form.WmClose(Message& m)   ..
I didn't try to run CodeCracker's tools on your files, but I'm guessing they would take care of most of the invalid metadata.

 

Yeah i saw it! sorry!

However i think that codecracker tools can take care of  6 or 7 of them, except the last one, the first and a few other.

 

@Death: i don't understand your hate for me. It's only a beginner challenge, what's the problem? I have never said that it is unbreakable so stop raging.

Edited by LoLLo90
Link to comment

i not hate anyone and something had which i will explain u latter once got time, however it was my last attribute in ur obfucated exe or packed => fix or unpack or however u say . i left ur protection forever and i will never post again in ur new unpack me deobme or whatever u say of ur future protection .


 


good luck  


Edited by Death
  • Like 1
Link to comment
  • 11 months later...
Teddy Rogers

The [crackme] tag has been added to your topic title.

Please remember to follow and adhere to the topic title format - thankyou!

[This is an automated reply]

Link to comment

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...