Breaking copy protection on a 1983 game for Apple 2
ia804502.us.archive.org
ia804502.us.archive.org
I did some 6502 (BBC Micro) games but mostly 68000 (Atari ST). The process was quite similar to the article but I never cracked anything that complicated! Nor did I keep detailed records - I was far to worried about them being evidence to be used against me.
My best crack was working out that I didn't need to figure out how to read the key to decrypt the game from the secret uncopyable protected sector on the disk (I think it had a deliberate CRC error in it so the standard disk firmware wouldn't read it). I disassembled the crypto routine and saw that it just did a simple XOR of the key block over and over again. I then used a frequency analysis on the encrypted game binary to recover the secret key and decrypt the game!
I came to enjoy cracking the copy protection much more than playing the game as it was like having an intellectual battle with the developer. In fact after that playing games lost its appeal and I moved on to creating new things on the computer instead.
I never distributed my cracks though - I was far too frightened of getting caught!
Much of the disk protection was laughable, Ocean games been an example.
They had a routine that would return 1 in the A register so the crack was to load the accumulator with 1, do a nop to fill the gap and continue
I could crack their games in about a minute with a disk sector editor I wrote that would disassemble the game on disk by reading the sectors for the game.
The hardest crack I did was EA’s Skate or Die. It had self modifying code in the copy protection which took quite a while to unwind loops.
I also cracked Ghosts and Goblins, or maybe it was Ghosts and Ghouls, on the Amiga. The chumps who made the disk left the source code to the boot loader on the disk as a deleted file. I undeleted it and “fixed” the boot loader.
Oddly, I worked in copy protection many years later.
One lame scheme I ran into was a basic try to load deliberately bad sector check.
If bad, run game.
If good, fail.
But, they did not check for any specific error! Any error would do to start the game, which was ULTIMA 2.
Because of that, anyone could copy the game disk and cause a disk read error to happen at the right time to play the game.
The easiest thing to do was open the drive door, wait a bit, then close it to see the game load normally.
It was, essentially a:
bool IsGenuineDisk() { return DiskHasSecretStuff(); }
That was my first "crack." I happened to run the game on an Atari computer, which makes sounds during disk I/O. I could hear the sectors, hear the fail, retry, then remaining sectors load.
So, count em up, open the door, listen for fail, close, go!
Didn't even need a single hex value to accomplish.
After that, I got into it on an Apple. Reading this brings back memories. That particular machine is a lot of fun, and it is fun because almost everything is software. Totally open.
These lab notebooks of the cracking process are shared for titles that could not automatically be cracked.
These are the only public records of reverse engineering these titles, though many did this in the 80’s the techniques and findings were never shared beyond the cracks themselves, and 4am is so practiced and proficient I think he definitely wins the title of the best apple ii cracker in history!
4am is ridiculously prolific. The sheer number of bizarre disk-copy protection schemes applied on these old computers has always been fascinating to me. A lot of creativity went into both inventing and reversing these things.
But in later times there was a good community of cracking software for PCs, and those notes continue to live on despite the unfortunate death of the curator/collector, +fravia.
Here's a decent mirror, for example:
https://www.darkridge.com/~jpr5/mirror/fravia.org/academy.ht...
At one point I used wget --mirror to download the whole site, and that was back in the early 90s.
The game Tristan did not remove the comments from its code, so after disassembly, I could see the name of subroutines. One line was something similar to "GOSUB hexaddress" with the comment "doProtec". I naturally assumed this was a subroutine that would run the copy protection code. In those days it was one of those pop up windows that asked a question from a random page in the manual.
A GOSUB and an address was two bytes of code, if I remember correctly. I used the Mac built in Hex editor to edit the binary for Tristan, found the GOSUB line with the correct hex address as its argument and replaced it with two NOOP commands, which were one byte each. I saved the binary file and played the game. And it worked! I could now play Tristan without having to answer the stupid questions from the manual every time.
(*) If you replace the words "need to" with the words "get to," life becomes amazing.
http://mirrors.apple2.org.za/Apple%20II%20Documentation%20Pr...
Demo:
We used it for a couple games when one of us had a bought copy and one of the various copy programs didn’t work (I had a disk full of them being young and not having enough knowledge to crack on my own. )
Worked well for arcade games. Didn’t work well for games that loaded more stuff from disk..
"I'm beginning to suspect that this disk is nothing more than an infinite series of decryption routines with a game bolted on as an afterthought."
https://ia800209.us.archive.org/8/items/BurgerTime4amCrack/B...
Didn't intend to 'crack', just needed copies to play till they degraded while the original stayed in dry sealed storage.
Today I wonder -- who didn't learn assembly back then by reverse engineering games?
And it would be a popular download on the BBS and early internet gateways.
Many had an "80 column card" and later versions included it. However, TV screens of the time could not readably display 80 character wide screens.
Monochrome monitors take composite and can deliver 600 lines or so,