I always thought the app was decrypted in memory and then run, and cracked versions were dumped from memory and written to disk. So once loaded, the app binary looks the same to both a cracked app and a legit app. How can you tell the difference?
I always thought the app was decrypted in memory and then run, and cracked versions were dumped from memory and written to disk. So once loaded, the app binary looks the same to both a cracked app and a legit app. How can you tell the difference?
Like OS X apps, iPhone apps are distributed as bundles (directories) containing all the required files (http://en.wikipedia.org/wiki/Application_Bundle).
The info.plist file is a plain xml of key/value pairs of properties that tell the OS how to handle the app, which kind of files can be opened with it etc.
AFAIK, the application that kids use to crack iPhone apps adds a key/value pair to the info.plist which is needed to load the app on a jailbroken device. So, you just need to check for its presence. If the key is there, the app has been cracked.
Pirates have been reverse engineering and cracking Windows Mobile games by hand like this years.
I did some research into mobile app piracy 3 or 4 years ago and found a thriving scene for cracking WinMo, Palm, and J2ME apps and games. And these were not automated cracks, someone sat there with a debugger and reverse engineered the registration keys.