Jump to content
Tuts 4 You
  • 0
Sign in to follow this  
lucifeey

CrackMe 2 // ConfuserEx 1.0.0-custom

Question

lucifeey

Difficulty :  4/10
Language : .NET
Platform : Windows
OS Version : All
Packer / Protector : ConfuserEx 1.0.0-custom

Description :

Find out the password and give a tutorial how u got that.

Screenshot :

Spoiler

7cd2fc3dd3f2408bbbf053689c24afb8.png

 

CrackMe02.exe

Edited by lucifeey
Forgot OS Version (see edit history)
  • Like 1

Share this post


Link to post

7 answers to this question

Recommended Posts

  • 1
Gyrus

Difficulty: 4/100

Password:

Spoiler

GladUFoundThis!

Run the crackme using dnSpy, do not set initial breakpoint. Break (Ctrl+Break) the execution. Debugger lands on:

mscorlib -> System.IO -> __ConsoleStream -> ReadFileNative()

Step out (Shift+F11). Enter any password. Keep stepping out untill you reach:

CrackMe02 -> ejdGIfwNyDgtHkPvvAolmbGeopHDb -> SJVWQsKldSOfuZPsxaVVTZTVvhnG()

Step out again. Password is in Locals list.

Share this post


Link to post
  • 0
cawk

hmm? what have you changed apart from renaming?

all of codecrackers tool worked fine for this nothing has changed

 

8659b2b143352da7dec08db2b587f103.png
https://gyazo.com/8659b2b143352da7dec08db2b587f103

 

put a bp there on the unpacked file and the pass will be in the locals 

Share this post


Link to post
  • 0
lucifeey
1 hour ago, cawk said:

hmm? what have you changed apart from renaming?

I just changed unclearly the type charset, so it forces to use normal chars. and the wonderful attribute so some deobfuscators wont detect it as confuserex.

Edited by lucifeey
. (see edit history)

Share this post


Link to post
  • 0
XenocodeRCE

Well in short, no real modification, only minor useless addings. I wrote a tutorial on how to custom ConfuserX the right way on rtn-team website

Share this post


Link to post
  • 0
atom0s
On 4/10/2017 at 11:08 PM, XenocodeRCE said:

Well in short, no real modification, only minor useless addings. I wrote a tutorial on how to custom ConfuserX the right way on rtn-team website

Is this post still on rtn's site? I don't see a thread about this there. Would be interested in reading it.

Share this post


Link to post

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  
×
×
  • Create New...