Reverse engineering a software crack
twitter.com
twitter.com
I also do reverse engineering streams on YouTube: https://www.youtube.com/basteg0d69
I believe being successful in reverse engineering, cracking, bypassing security layers (e.g., unlocking cars without keys), and other hacks comes down to understanding the basics of how these systems are designed to work in the first place. Add to this, the possession of the right toolbox to do the job.
Back in 2010, I took on the challenge of cracking paid/licensed POS software. I am, in no way, a cracker or hacker, but once I understood how this app works, I followed a simple logic based on these rules:
a. The app had a trial version with a number of *runs* set, and with each launch of the app, the number will decrease by one. It was set to around 100, I believe.
b. The app runs on a LAN, on multiple computers, with one being the server. To my surprise, there were no IP configurations, and it turned out that it worked on LAN by setting the app directory as a *shared folder* in Windows!!
c. On each app launch, even from other computers (having access to the shared folder), the count will decrease.
So, I started my investigation: 1. Since you have a shared folder, based on (c) above, I assumed the location where the count number is stored *must be inside* this shared folder, not in the Windows registry or other places.
2. I launched the app, wrote down the current count, and closed it.
3. I searched inside this shared folder for *.* (all files), then sorted them by last edited.
4. I picked the first one from the search result as it was the only one with the same time as *now*; it was in a binary format.
5. I opened it using a hex editor, converted (using calc.exe) to HEX the count I wrote down on (2), searched for it, and found it. I identified its position.
6. I closed the hex editor, repeated (2),(3) and (4), and got the same results.
7. Now, I typed 999 in calc.exe and converted it to HEX, and in the open HEX editor, I edited the count at its current position with the new value, saved, and closed the binary file.
8. Restarted the POS app, went to about, and.. booooom , it now thinks that you have 999 days remaining :)
Although I never used this Point of Sale software, it was an exciting achievement for me. I felt like a real hacker.The nice thing is that a signed app will refuse to load a dylib that does not have the same signature. So crackers will be forced to change the whole app signature which can be easily detected in app code.
I have that kind of protection in Lunar (https://lunar.fyi/) and Clop (https://lowtechguys.com/clop) and it seems to be good enough as they have no recent cracks.
It’s impossible to get past inspection on the Apple Store due to that extra script in the app bundle but a downloaded dmg off the web…
Manual code sign checks can only be cracked by patching the binary, which requires a lot more effort than swizzling some methods in a dylib. Or by process injection with Frida, but that requires disabling SIP which most people won’t do just for a cracked app.
1. Mildly harder on a OS level
2. Less popular in countries that produce the most cracks
3. Less popular in general
4. Has an audience that is demonstrably more likely to pay for software
5. Has less strong reverse engineering software. Hopper was awful.
Also, I just wanted to say I love your work. I've learned a lot from your blog, your free trial strategies are interesting, and quite effective: https://shottr.cc/s/1vQa/SCR-20240423-re6.png
The flip side of this is that I've noticed software written solely for macOS/iOS is often more polished than many of the most popular FOSS projects written for Linux.
Obviously I don't have any expectation of software provided for free, but as someone who makes a living developing software I do find it funny how much reticence there is among other developers to pay for high quality software.
I think, as a developer, I value the ability to fix things I don't like. I've done it quite a lot in open source software. Just plant my fix and move on. Steam always felt complete. macOS software often feels closer to completion, though sometimes I do wish I could modify it still. Also, another class is software I trust that I could not do a better job on, like Affinity.
Anyway, I think that's the root of the developer aversion to paying for software.... Well, for me anyway. I wish we had better culture around donating to free software as well.
Though I'm actually not against paying for access to stream media. I am however against telling people what they can do with the media once they stream it (ie saving it to their own drive for future playback).
Paying for access to a media repository makes slightly more sense than paying for access a to software repository also, just given the sheer amount of data that media tends to take up vs how much data software tends to use. GNU software repositories are fairly easily hosted by hobbyists; multi-billion dollar companies often burn money trying to monetize media storage and distribution (particularly video). In that sense, there is some scarcity in media distribution. Software distribution trends to be next to nothing though.
I am also certainly against DRM, as I am any malware :P
challenge accepted
If you're modifying the executable anyway, why not just patch it directly instead of going through these hoops?
The equivalent on Linux would be setting LD_PRELOAD and putting your .so file there. A quick Google search seems to imply that the OSX equivalent is DYLD_INSERT_LIBRARIES but I have no idea how similar they are.
Most relevant I found: https://devblogs.microsoft.com/oldnewthing/20200420-00/?p=10...
Probably in this case the installation of the crack requires admin privileges to modify files in "Program Files" folder. Boom, you've broken the rules ;)
It reminds me of a really smart kid who doesn't want to be seen as a nerd, so writes nonchalantly and injects vulgarities into an otherwise brilliant project. Good Will Hunting vibes.
It's not really offensive, it's just distracting.
For the challenge, and because I disliked software being tied to a specific storage medium.
It was a sport to minimize changes. Like pad out a single assembly instruction with NOPs, change a conditional jump into unconditional one, etc.
P.S. who remembers the legendary Phrozen Crew cracks? They were minimal byte patches that often toggled a conditional jump in an MS-DOS app/game...
in 2024"
That doesn't have anything to do with being old fashioned. It's about how racing works in scene FTPs. When you release something race begins starting from so called affil "sites" (group release to all their affil sites at the same time) from there it propagates to whole scene by couriers. Because of how FTP works you need to split the file into multiple files so it can be uploaded by multiple people from multiple sources making distribution fast. And rar is used for that, there are scene rules for it and it's not using compression option.
> 1.7 The ISO file has to be packed into a RAR archive using the RAR4 or the RAR5 format and the old style volume naming scheme. e.g. grp-gamename.rar, grp-gamename.r00, grp-gamename.r01, ...
Selfish question for a project of my own: is there any way to magically gain early code execution in a process on Windows other than a shim DLL? I'm too lazy to write one to pass through the all exports (reflective shim DLL possible...?)
Thanks for sharing, it was interesting, but wow that's a bad format and bad writing.
I suspect this question is in bad faith but I'll answer anyway: this live tweeted thread is more like someone's thought stream, it is not a technical report.
Many humans are capable of both technical writing, free of cursing, and also of dumping a swear-filled thought stream right into their favourite medium - especially when excitedly reverse engineering, or doing anything they're passionate about.
This has been happening for a long time and is not about "the newer generation". You could've found me writing in a similar way on IRC in the late 90s, also talking about reversing.
FWIW your comment feels valid enough up until your final sentence, you just didn't need to attack "the newer generations".
Why not? He's exactly right, in my experience. It's definitely been my experience that the newer generations (of Americans) are much more likely to casually use swear words, usually the f-word, in regular conversation, even at work. I hear it all the time with my American colleagues. When I was their age, no one talked like that at work, or really in general except maybe in private with their closest friends.
Another big difference is mass media: when I was their age, American TV did not allow swear words. But in the last 10-20 years, it's completely changed, and it's pretty common to hear the f-word on regular TV. So of course the "newer generations" are going to reflect this in their casual speaking.
Courtesy used to be a fallback protocol in society that allowed people of different sensibilities to communicate more efficiently and without personal contexts getting in the way of subject matter. It was also non threatening and the effort put into it was a sign someone was taking the counter part seriously.
Your error has happened to me also but it does eventually work.
I guess it's going to die soon like the other as they run out of guest accounts from scrapping…
Is that the case or is it a bug?
tl;dr it patches the executable by having a shim dll that does the patch when it gets loaded. Pretty common in the game modding community. It finds where it needs to patch by scanning for a byte pattern.
What does the actual patch do? No idea, that's what I was waiting for and I never got it. I was expecting a disassembly comparison of the before and after.
Someone please correct me if I'm wrong.
Without affecting any integrity checks in the target binary.
This is just a bunch of screenshots with ‘lol’ interspersed.
There’s extensions to both which automatically try detect such things from common libraries/known calls/etc which massively cuts down on the timesink.
Infosec twitter moved over to Mastodon a while back, some are also trying out bluesky but Mastodon is where the community has mainly roosted.