Jump to content
Tuts 4 You

VMProtect x64 v3.6 HWID Lock (All Protection Options)


Recommended Posts

Posted
On 11/29/2023 at 9:15 AM, boot said:

The package for v3.85 has been leaked, unfortunately still lacking passwords.

Is this still doable as you said before with RSA-N pulling from RtlAllocateHeap? Seems like whenever i put breakpoint on CriticalError im instantly getting kicked out.

  • Like 1
  • 2 weeks later...
  • 3 weeks later...
New Year - New Mind
Posted

Hello, everyone.

Try to do this bypass and runme challenge. If you do it successfully, post the screenshot please.

VMProtect MY PC HWID LOCKED

hashgen.vmp.zip

Regards.

sean.

  • Thanks 1
Posted
2 hours ago, New Year - New Mind said:

Hello, everyone.

Try to do this bypass and runme challenge. If you do it successfully, post the screenshot please.

VMProtect MY PC HWID LOCKED

hashgen.vmp.zip 7.21 MB · 0 downloads

Regards.

sean.

Spoiler

2025-02-18_214848.jpg.1fe9d98bc3e084ee3cbe0f80082a2120.jpg

  • Thanks 1
New Year - New Mind
Posted (edited)
2 minutes ago, boot said:
  Hide contents

2025-02-18_214848.jpg.1fe9d98bc3e084ee3cbe0f80082a2120.jpg

@boot Fantastic!!!

How did you do it?

Can you reveal your method?

Regards.

sean.

Edited by New Year - New Mind
Posted
Just now, New Year - New Mind said:

method?

This method has some limitations...

Spoiler

2025-02-18_215519.jpg.5e82f250583af5007aa181ad6070c8db.jpg

  • Thanks 1
New Year - New Mind
Posted
18 minutes ago, boot said:

This method has some limitations...

  Hide contents

2025-02-18_215519.jpg.5e82f250583af5007aa181ad6070c8db.jpg

@boot Does your method work also to this? Your picture above is different from mine even though the RVA is same as yours.

hashgen.vmp.hwid.lock.zip

Regards.

sean.

Posted

There are still many ways to bypass it0e2e1332c2378eb9eeb411490ff962fe.png.e1c8ef32072f1e3eb6a655eb554a82f8.png

  • Like 1
Posted

@New Year - New Mind Could you post the steps to bypass hwid in this case?

I have a target with VMP HWID locked to one of my computer and i wanna try to bypass it.

I can debug it with x64dbg on the hardware that is locked to.

  • Like 1
New Year - New Mind
Posted
On 2/19/2025 at 12:29 AM, StarrySky said:

There are still many ways to bypass it0e2e1332c2378eb9eeb411490ff962fe.png.e1c8ef32072f1e3eb6a655eb554a82f8.png

@StarrySky How to do it?

Regards.

sean.

New Year - New Mind
Posted (edited)
On 2/19/2025 at 12:29 AM, StarrySky said:

There are still many ways to bypass it0e2e1332c2378eb9eeb411490ff962fe.png.e1c8ef32072f1e3eb6a655eb554a82f8.png

@StarrySky Can you make this serial locked one run? I have zipped a wrong serial.txt and protected executable to make a challenge.

hashgen.vmp.serial.locked.zip

If you edit the first character of the serial.txt file, this executable will run. or you have to find the test and conditinal jump instructions which are virtualized after VMProtectSetSerialNumber function. this function returns 2 which means that the serial is invalid, when it returns 0, this executable will run.

And I have a question about how to use a vmprotect feature.

screenshot-57.png

I protected a procedure called "OnBnClicked..." with the options above. and when I clicked the button when it runs, its shows this message and is terminated. how to use this option properly?

screenshot-58.png

 

Regards.

sean.

 

Edited by New Year - New Mind
Posted (edited)
1 hour ago, New Year - New Mind said:

@StarrySky Can you make this serial locked one run? I have zipped a wrong serial.txt and protected executable to make a challenge.

hashgen.vmp.serial.locked.zip 7.63 MB · 0 downloads

If you edit the first character of the serial.txt file, this executable will run. or you have to find the test and conditinal jump instructions which are virtualized after VMProtectSetSerialNumber function. this function returns 2 which means that the serial is invalid, when it returns 0, this executable will run.

And I have a question about how to use a vmprotect feature.

screenshot-57.png

I protected a procedure called "OnBnClicked..." with the options above. and when I clicked the button when it runs, its shows this message and is terminated. how to use this option properly?

screenshot-58.png

 

Regards.

sean.

 

https://forum.tuts4you.com/topic/44928-vmprotect-web-license-manager-v214

 

Edited by HostageOfCode
  • Like 1
Posted
7 hours ago, New Year - New Mind said:

@星空 您能让这个序列锁定一次运行吗?我已经压缩了错误的 serial.txt 和受保护的可执行文件来进行挑战。

hashgen.vmp.serial.locked.zip 7.63 MB · 5 次下载

如果你编辑了serial.txt文件的第一个字符,这个可执行文件就会运行。或者你必须找到在VMProtectSetSerialNumber函数之后虚拟化的测试和条件跳转指令。这个函数返回2,这意味着序列无效,当它返回0时,这个可执行文件就会运行。

我有一个关于如何使用 vmprotect 功能的问题。

屏幕截图-57.png

我使用上述选项保护了一个名为“OnBnClicked...”的过程。当我单击运行时的按钮时,它会显示此消息并终止。如何正确使用此选项?

屏幕截图-58.png

 

问候。

肖恩。

Regarding your question, I have conducted a detailed analysis and recorded it for your reference

Or conduct your own research to bypass it

6ebffbbb-932e-466d-ba98-f4ccabb90cb3.png.8eef546a5fba10053a83a464d8a9e61c.pngd6eba941-0cc1-413f-930b-3ae3a7b8b70e.png.0d5141101f8991950834cd969686e0b1.pngVMProtectSetSerialNumber.png.a9fd0e9533662e5c14f554160b960921.png6ebffbbb-932e-466d-ba98-f4ccabb90cb3.png.8eef546a5fba10053a83a464d8a9e61c.pngd6eba941-0cc1-413f-930b-3ae3a7b8b70e.png.0d5141101f8991950834cd969686e0b1.png

 

  • Thanks 1
New Year - New Mind
Posted

@StarrySky Can you please post a video if you successfully make it run?

Regards.

sean.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...