ãšã³ããªãŒ
ããã«ã¡ã¯ãHabralumiãææ°ã®ã¢ã»ã³ãã©ãŒã®ããã°æçš¿ããå€æãããšãkeygenããŒãã¯ããã§éåžžã«äººæ°ãé«ãŸã£ãŠããŸãã ãŸããç§ã¯ç§ã®5ã»ã³ãããããããŸãã
ä»æ¥ã®å®éšããŒãã¯Zuma Deluxeã²ãŒã ã§ããããã¯èªåã§keygenãGoogleã§æ€çŽ¢ããããšã¯ã§ããŸããã§ããïŒç§ã¯ã²ãŒããŒã ãšã¯æããªãã§ãã ããã å 責äºé ïŒæåããæåŸãŸã§ã®ãã®ããã¯ã¯æè²ç®çã§è¡ããããã®ã§ãããäŒç€ŸPopCap Gamesã®æ倱ãæãããšãæå³ãããã®ã§ã¯ãããŸããã
Zumaãã£ã¹ããªãã¥ãŒã·ã§ã³ãã°ãŒã°ã«ã§ããŠã³ããŒãããŠããŠã³ããŒããã OllyDBGãæŠéæºåç¶æ ã«ããŠãåæãéå§ããŸãã
ã¯ããäºåã«äºçŽããŸãããã°ããã®éãç§ã¯Linuxoidã§èªåèªèº«ãé»ãããã®ã§ããã®åã³ã¯ãã¹ãŠWINEã®äžããå§ãŸããŸãã ãã ãããã®ã¿ã¹ã¯ã«ã¯ãéåžžã®ããã¹ããã¡ã€ã«ã«ä¿åãããããããšã³ããªã®ç·šéãWINEã¬ãžã¹ããªã®å€æŽã®è¿œè·¡ãç°¡åã«ãªããªã©ããã®ã¿ã¹ã¯ã«ã¯å©ç¹ãããããšã«æ³šæããŠãã ããã
ããŒã1ïŒé°æ¹¿ãªãã©ãã·ã¥
äžè¬çã«ãã²ãŒã ãéå§ããäºæ³ãããé·ããã¬ã€ããŸãïŒãŸãã¯ããã«HKLM / Software / PopCap / Zumaã¬ãžã¹ããªãã©ã³ãã«ç»ããTimesExecutedããã³TimesPlayedããŒã«ãŒããèšå®ããŸãïŒ-ãããŠåºæ¥äžããïŒOKã[ä»ããè³Œå ¥]ãéžæãããããã¢ãããã©ãŠã¶ãŠã£ã³ããŠãéããŠãæ²æšãª16.99ãŠãŒãã§
ãããã£ãŠãå ¥åãã£ãŒã«ãã ãã§ã«èžãããšãã§ãããã®ããã äºæ³ã©ããããæå¹ãªããŒãå ¥åããŠãã ããããšããã¡ãã»ãŒãžã衚瀺ãããäœãäœã§ããããããããŸãã ææ ®æ·±ãæ€æ»ã§èŠåããæåã®ããšã¯ãã²ãŒã ã®ãããŒã®ãã暪ã«ãããã©ã«ããŒå ã®ååšã§ã.2ã€ã®ãã¡ã€ã«ãããã°ã©ã ã§ã®Flashãã¯ãããžãŒã®äœ¿çšã瀺åããŠããŸãïŒå®éã«ã¯ãFlash.ocxãšdrm.swf ...ã©ãããããã©ãŠã¶ãŒãéããã®ã«æéããããå¯èœæ§ããããŸãã OKããã®drm.swfãéããŸãã
ããŒãç»é²ããããã®é åçãªã·ã§ã«å šäœã¯ãçµå±ã®ãšãããåã.SWFãã¡ã€ã«ã§äœæãããŠããŸãã æ€èšŒã³ãŒãèªäœã¯åãå Žæã«ããã®ã§ããããïŒ èŠãŠã¿ãŸãããã ActionScriptãã³ã³ãã€ã©ïŒããšãã°ã Flareã䜿çšããŸããïŒãååŸããdrm.swfãããœãŒã¹ã³ãŒããååŸããŸãã
ããã«ã³ã³ãã€ã«ãããã®ãèŠãŸãã é ããæ©ããããã®èå³æ·±ãè¡ã«åºããããŸãã
gFrameLabels[4] = 'RegFailed';
ãRegFailedãã§æ€çŽ¢ãããã®ã³ãŒããããã¯ã«æ»ããŸãã
if (_root.RegCodeEdit.text.length >= 23 && _root.validate_regkey(_root.RegCodeEdit.text)) { _root.APError.text = ''; gRegFailedHeader = gHeader_RegFail; gRegFailedMessage = gMessage_RegFail; gRegFailedRetryLocation = 'APScreen'; fscommand('Register', _root.RegCodeEdit.text); }
ããã«ããã æ£ããããŒã¯23æåã®é·ãã§ïŒããã¹ããã£ãŒã«ãèªäœãå ¥åããããšãã§ããªããªããŸãïŒã validate_regkeyïŒïŒã True ãè¿ãããã«åŒ·å¶ã ãŸã ã ã³ãŒãã®åããããã¯ã§gRegFailedMessageãçºçãããããªãæããå€ã®åæåãè¡ããããšããäºå®ã¯ç¡èŠã§ããŸãã ããã§ã¯ããããã«é¢ä¿ãªãããã©ãã·ã¥ãªããžã§ã¯ãããfscommandïŒïŒãä»ããŠããŒã¿ã芪ããã»ã¹ã«è»¢éãããŸãã
ããã§ã validate_regkeyïŒïŒé¢æ°èªäœã䜿çšããŸãã ããã«å šäœããããŸãïŒ
function validate_regkey(string) { if (string.substr(5, 1) == '-' && string.substr(11, 1) == '-' && string.substr(17, 1) == '-') { char = new Array(); k = 0; while (k <= string.length - 1) { char = string.slice(k, k + 1); if (char == '0' || char == '1' || char == '2' || char == '3' || char == '4' || char == '5' || char == '6' || char == '7' || char == '8' || char == '9' || char == 'A' || char == 'B' || char == 'C' || char == 'D' || char == 'E' || char == 'F' || char == 'G' || char == 'H' || char == 'I' || char == 'J' || char == 'K' || char == 'L' || char == 'M' || char == 'N' || char == 'O' || char == 'P' || char == 'Q' || char == 'R' || char == 'S' || char == 'T' || char == 'U' || char == 'V' || char == 'W' || char == 'X' || char == 'Y' || char == 'Z' || char == 'a' || char == 'b' || char == 'c' || char == 'd' || char == 'e' || char == 'f' || char == 'g' || char == 'h' || char == 'i' || char == 'j' || char == 'k' || char == 'l' || char == 'm' || char == 'n' || char == 'o' || char == 'p' || char == 'q' || char == 'r' || char == 's' || char == 't' || char == 'u' || char == 'v' || char == 'w' || char == 'x' || char == 'y' || char == 'z' || char == '-' || char == ' ') { if (k == string.length - 1) { result = 'Thank you for submitting !'; return true; } } else { result = 'Unauthorized character ' + char; return false; } ++k; } } else { result = 'Error in delimiters'; return false; } }
ãŸããäžå€®ç£æ»ã¯æçœãªåäœã§ãã ããããgovnokod.ruã«æçš¿ããå¿ èŠããããŸããããŸããç§ãã¡ã¯ããã§æ¥œããããšãããã€ããã¯ãããŸããã äž»ãªããšã¯ããã®é¢æ°ãã©ã€ã»ã³ã¹ããŒã®æ§é ãæäŸããããšã§ãã
#####-#####-#####-#####
ããã§ãïŒã¯ã¢ã«ãã¡ãããã0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz-
æ£ç¢ºã«23æåã
ããäžåºŠèããŠã¿ããšãããã°ã©ã èªäœã®äžã®æ£ããæåã®ã»ããã¯ãããã«æžããšæããŸãã ããããä»ã®ãšãããããã¯ç§ãã¡ã«éãããããããŸããã OllyDBGãèµ·åããå®éšã«ããŒãããŸãã ãããèµ·åãïŒF9ïŒãã¡ã€ã³ãŠã£ã³ããŠãæç»ããããŸã§åŸ ã¡ãŸãã
ããã«æãå Žæã¯ïŒ
ãRegisterãè¡ã«çããæåã®ãã©ã¡ãŒã¿ãŒã§èŠã€ãã£ãfscommandïŒïŒåŒã³åºããèŠããŠããŸããïŒ
ãããã£ãŠãã¡ã¢ãªãããïŒAlt + MïŒãéãããã®è¡ã®ãšã³ããªãæ¢ããŸãïŒCtrl + BïŒã ãããŠãããã§åœŒå¥³ã¯ã 0x4417D0ã§èªåèªèº«ã«æšªããã£ãŠããŸã ïŒ
ãã®äžã«ãã¬ãŒã¯ãã€ã³ããé 眮ããŸãïŒéžæâShift + F3ïŒã 次ã«ã確èªãŠã£ã³ããŠã§ãããã®ã²ãŒã ãæ¢ã«è³Œå ¥ããŸãããïŒãâãç»é²ããŒãæåã§å ¥åããŸããã®äžã®ãªã³ã¯ãã¯ãªãã¯ããããŒãã£ãŒã«ãã«è±æ°åã®ãŽãããã€ãã³ã§åºåã£ãŠ5æåã®4ãããã¯ã«å ¥åããŸãã ãç»é²ããã¯ãªãã¯ããŸãã
ããŒã2ïŒããæ·±ãããå¿ èŠããã
ããã§ãã€ãã«æ€èšŒã¢ã«ãŽãªãºã ã®å éšã«å ¥ããŸããã ã¡ã¢ãªã®ã³ã³ãããŒã«ãã€ã³ãã®ãªã¹ãã«ç§»åãã 0x4417D0 ïŒAlt + YâDelïŒãåé€ããé¢æ°ã®æåŸãŸã§å®è¡ïŒCtrl + F9ïŒããŸãã ããã«ã¯ç§ãã¡ã«ãšã£ãŠèå³æ·±ããã®ã¯ãªããæ¯èŒãµã€ã¯ã«ã ãããããåŒã³åºãé¢æ°ïŒF8ïŒã«æ»ããè¿ãããçµæã®ãã§ãã¯ã衚瀺ãããŸãã ç¹°ãè¿ããŸãããé¢æ°ã®æåŸãŸã§ãã¹ãŠã¹ãããããŠãåŒã³åºãå ã«æ»ããŸããããïŒ ãããŠä»ãç§ãã¡ã¯ã©ã€ã»ã³ã¹ããŒã¢ãã©ã€ã¶ãŒã®äžå¿ã«ããŸãã ãã®å Žæãå¿ããªãããã«ã 0x04066CAã«ã³ã³ãããŒã«ãã€ã³ãïŒF2ïŒãé 眮ããŠèŠåããŠãã ããã å°ãäžïŒ 0x406757ããã³0x4067A8 ïŒã§ã¯ãéåžžã«èå³æ·±ãæååãã©ã¡ãŒã¿ãŒãRegSucceededãããã³ãRegFailedããæã€é¢æ°åŒã³åºããèŠãããšãã§ããŸãã ãŸããäžäœïŒ 0x406748 ïŒã¯ãå¶åŸ¡ãç®çã®æ©èœã«è»¢éãããã©ã³ãã§ãã ãã®åå²ã¯ãALã¬ãžã¹ã¿ãšBLã¬ãžã¹ã¿ã®æ¯èŒïŒ 0x40672D ïŒã«é¢é£ä»ããããŠããŸãã å ã«ããã«2ã€ã®ã³ãã³ãã«ãã£ãŠåŒã³åºãããé¢æ°0x404260㯠ããŸãã«ç§ãã¡ãæ¢ããŠãããã®ãã€ãŸã æãéèŠãªãã§ãã¯æ©èœã
ãŸããæšæž¬ã確èªããŸããããééã£ããœãŒã¹ããŒã¿ã§æ¯èŒãçã«ãªãããã«æ¯èŒãå€æŽããŸãã éžæç¯å²ã0x406748ã«åããã¹ããŒã¹ããŒãæŒããŸãã ãã¢ã»ã³ãã«ããŠã£ã³ããŠãéããŸãã é·ç§»ãçåŒãJEãäžçåŒãJNEã«ããé·ç§»ã«çœ®ãæããŸãã å®è¡ïŒF9ïŒ...
ã»ããæåã®èŠå¡ããšãããŸãïŒ
ãããä»ãç§ãã¡ã¯åãªãäºè£ã§ã¯ãªããéåžžã«éèŠãªæ å ±ãæžããŠããŸãã ãããŠãããã¯éæããããã®ã§åæ¢ããã«ã¯æ©ãããããšãæå³ããããã°ã©ã ãåèµ·åïŒCtrl + F2ïŒãã 0x404260é¢æ°ã®è žãæãäžããå¿ èŠããããŸãã
ããã§ã®ã¿ã¹ã¯ã¯ãALããã³BLã¬ãžã¹ã¿ããã®é¢æ°å ã§ã©ã®ããã«åäœããããããã³ãããã®ç䟡ãŸãã¯äžç䟡ã®åå ãšãªãã³ãŒããæ£ç¢ºã«ã©ãã«ããããç解ããããšã§ãã
é¢æ°ã®ãããŒã«ãã®åºå£ãã€ã³ãRETNã®è¿ãã«ç§»åããBLã¬ãžã¹ã¿ã®ããã¯ã©ã€ãããªã³ã«ããŸãïŒã³ã³ããã¹ãã¡ãã¥ãŒâã¬ãžã¹ã¿ã匷調衚瀺âEBXïŒã
ã芧ã®ãšãããALã¬ãžã¹ã¿ã®å 容ã¯ãããŒã«ãã®ã»ãŒå šäœã«ããã£ãŠBLã«æ ŒçŽãããåºå£ã®çŽåã«ã³ããŒããã¯ãããã¹ã¿ãã¯ããå ã®EBXå€ãããã«åŸ©å ãããŸãã
ããã«ãALå€èªäœã¯ãéžæã®ããŒã¯ãä»ããäžã®å³ã®é¢æ°ããååŸãããŸãã
ãã®é¢æ°ã®å éšã«å ¥ããŸã-ãããŠäœãèŠããŸããïŒ
ãã®é¢æ°ã«ã¯2ã€ã®åºåå€ïŒ0ãš1ïŒãããããŸãããæåã®é¢æ°ã¯ãé¢æ°ãã©ã¡ãŒã¿ãŒãšããŠæž¡ãããæ§é äœãžã®ãã€ã³ã¿ãŒã§ãããã€ãæååãããã€ã³ã¿ãŒã[ECX + 8]ã«ããæååãšäžèŽããªãå Žåã«çæãããŸãã 2çªç®ïŒå¿ èŠãªãã®ïŒã¯å察ã®ç¶æ³ã§ãã æååãåäžã®å Žåã
ããŒã3ïŒMD5ãRSAãããã³ãã¹ãŠãã¹ãŠ
芪é¢æ°ã«æ»ãã[ECX + 8]ãš[ARG.1 + 8]ã®å€ãã©ãããæ¥ãããèŠãŠã¿ãŸãããããããè¡ãã«ã¯ããããã®è¡ãé 眮ããã¹ã¿ãã¯å ã®2ã€ã®ã¢ãã¬ã¹ã«ãããŒããŠã§ã¢ããã¬ãŒã¯ãã€ã³ããé 眮ïŒéžæâShift + F5ïŒããŸãã ç°ãªããã·ã³æ§æããã³ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã¯ããããã®ã¢ãã¬ã¹ã¯ç°ãªãå¯èœæ§ããããŸãã ãããã£ãŠãç§ã®å Žåããããã¯0x33E624ãš0x33E660ã§ã ïŒäžè¬ã«ãåçã®ããã«ãäžéšã®ESPã®äœçœ®ã«é¢ä¿ãªããã¹ã¿ãã¯ã®ç¶æ ã瀺ãè¿œå ã®ãŠã£ã³ããŠããµã€ãã«è¡šç€ºããããšããå§ãããŸãïŒã
ãããã®ã³ã³ãããŒã«ãã€ã³ãã¯ã次ã®ããã«ããŒããŠã§ã¢ããŒã¹ã§ãªããã°ãªããŸããã ä»ã®ã¿ã€ãã®ã³ã³ãããŒã«ãã€ã³ãã¯ãã¹ã¿ãã¯ã«é 眮ããããšãããã°ã©ã ã®ãã¯ã©ãã·ã¥ãã«ã€ãªããããéå§éã§ä¿åãããŸããã ä»ã®ãšããããããã®ãã€ã³ããéã¢ã¯ãã£ãã«ããå¿ èŠããããŸãïŒã³ã³ããã¹ãã¡ãã¥ãŒâãã¬ãŒã¯ãã€ã³ãâããŒããŠã§ã¢ã®ç¡å¹åïŒã
ããã°ã©ã ãåèµ·åããã¡ã€ã³ã¹ãã£ã³æ©èœïŒ 0x404260 ïŒã®å ¥ãå£ã§åæ¢ããŸãã ãã¬ãŒã¯ãã€ã³ããããã«çœ®ããé¢æ°ã1è¡ãã€ïŒF8ïŒãã¬ãŒã¹ãã2ã€ã®ããŒããŠã§ã¢ãã¬ãŒã¯ãã€ã³ãã®ç¶æ ãç£èŠããŸãã ãã¬ãŒã¹ã¯ãè¡0x404546ãŸã§äž¡æ¹ã®å€ãå€ãããªãããšã瀺ããŠããŸãã ããããããã¯ãã£ãšé¢çœãã§ãã
0x404546ããçŽæ¥åŒã³åºãããé¢æ°ã¯ã 0x41E320é¢æ°ãèµ·åããããã®ãèžã¿å°ãã§ãããããèå³æ·±ãããšã¯äœããããŸããã 0x41E320ã«ãã¬ãŒã¯ãã€ã³ããèšå®ããF9ãæŒããŸãã
çŸæç¹ã§ã¯ãã¹ã¿ãã¯ã«ã¯å¥åŠãªããããããã§ãå°å·ãããæåïŒããšãã°ãA ..... 6..O6NBBO .... E4GXF3O0 ..ïŒãšæ¹è¡æåã§æ§æãããè¡ããããŸããæ¥å°ŸèŸZUMAã ããã«ãã¬ãŒã¹ãã 0x41E37Fã§åŸç¹ããŸã ïŒ
ãŸããŸã ...ã¯ãããããã¯MD5ã¢ã«ãŽãªãºã ã®åæåãã¯ãã«ã§ã ïŒ
MD5ã ããã¯è¯ãã§ãã ããã§ãæ®ãã®é¢æ°ã³ãŒãã®åæã¯ç°¡åã§æ°æ¥œã«ãªããŸããã
- 0x41E320-0x41E397 ïŒçµæã®ããŒã¿åæåãšã¡ã¢ãªå²ãåœãŠ
- 0x41E39B - 0x41E3C3 ïŒäžèšã®è¡ããã®MD5ããã·ã¥ã®èšç®ãšãçµæãžã®ãªã³ã¯ãå«ãæ§é ã®æºåïŒä»¥äžãããã¬ãŒã ããšåŒã³ãŸãïŒ
- 0x41E3C5-0x41E408 ïŒçµæãšããŠåŸæ¹ã«ãã€ããåé 眮ãããµã€ã¯ã«
- 0x41E40A - 0x41E424 ïŒé¢æ°ã®4çªç®ã®ãã©ã¡ãŒã¿ãŒãåºå®ãããŠããïŒ0x5EïŒãããåžžã«trueã«ãªãããšã確èªãããŸãã
- 0x41E426-0x41E474 ïŒåã®ãã§ãã¯ã«ããå®è¡ãããªãã³ãŒã
- 0x41E476-0x41E4B5 ïŒ128ãããMD5ããã·ã¥ã®96ããããžã®ãããªã ãæ©èœã åºå£é¢æ°
次ã«ãæåã®ããŒããŠã§ã¢ãã¬ãŒã¯ãã€ã³ããèŠãŠã¿ãŸãããã
ç§ãèšã£ãããã«ããã®ãããª5ã€ã®æå³ã®æ§é ã¯ãåŸã«ããã¬ãŒã ããšåŒã°ããŸãã
- æåã®DWORDã¯å€æŽããããåžžã«0x44543Cã§ã
- 2çªç®ã®DWORDã®ç®çã¯æ確ã§ã¯ãããŸããïŒã¯ããäžè¬çã«ã¯ãåŸã§éèŠã«ãªããããç¹ã«éèŠã§ã¯ãããŸããïŒ
- 3çªç®ã®DWORDã¯ããã€ãæååãä¿åãããŠããã¡ã¢ãªå ã®ã¢ãã¬ã¹ã§ã
- 4çªç®ã®DWORDã¯ããæå¹ãªãé·ããWORDã§èšå®ããŸãïŒã€ãŸããæååããã®WORDãããã«èšç®ã«äœ¿çšãããæ°ïŒ
- 5çªç®ã®DWORDã¯ããåèšãé·ããWORDã§èšå®ããŸãïŒã€ãŸããè¡ãé 眮ããããã«æåã«å²ãåœãŠãããWORDã®æ°ïŒ
ãããã£ãŠãç§ãã¡ããã£ãä»ãã¬ãŒã¹ããæé ãå®è¡ããåŸãæåã®ãã¬ãŒã ã¯ãã§ã«æºããããŠããŸãã ã€ãŸãããã§ã«è¡ã®1ã€ããããæ¡ä»¶ä»ãã§ãåç §ããšåŒã³ãŸããããããã¯ããŸã èšç®ããŠããªã0x40454F - 0x40458Cã®è¡ãšæ¯èŒãããŸãã
ããã§ãé¢æ°0x41E5A0ãåŒã³åºãããè¡0x404560ã詳ããèŠãŠã¿ãŸãããã
ãã®æ©èœã¯éåžžã«é·ããŠæãããã§ãããããã§ã¯ãé·ããŠæãããããšãç°¡åã§ç解ããããããããã«ããã«ããŸãã ãã®é¢æ°ã¯ãåœç€Ÿãå ¥åããç»é²ããŒã®æååãåŠçãããããæ°ãçŽããŸãã
- 0x41E5A0-0x41E608 ïŒåæåãã¡ã¢ãªã®å²ãåœãŠãäŸå€ãã³ãã©ãŒã®ã€ã³ã¹ããŒã«
- 0x41E60B - 0x41E6EF ïŒæååã®æåã倧æåã«å€æããã1ãããLãã«ããOããšã0ãããQãã«çœ®ãæãããµã€ã¯ã«
- 0x41E6F5-0x41E70A ïŒ2çªç®ã®ãµã€ã¯ã«ã®æºå
- 0x41E710-0x41E7E4 ïŒ28é²æ°ã·ã¹ãã ïŒæåã®æåã¯æäžäœãæåŸã¯æé«ïŒããã®å€æã®ååã«åŸã£ãŠçªå·ãæ§ç¯ãã2çªç®ã®ãµã€ã¯ã«ãæåã»ããã234679ACDEFGHJKLMNPQRTUVWXYZãããã€ãã³ãç¡èŠããçŸåšã®æåããªãå Žåã¯ãšã©ãŒãã¹ããŒããã»ããã§
- 0x41E7EA - 0x41E844 ïŒçµæã®ã³ããŒãäžæãããã¡ãŒã®è§£æŸãçµäº
- 0x41E845-0x41E874 ïŒ2çªç®ã®ãµã€ã¯ã«ã§ãšã©ãŒãã¹ããŒãããå Žåã«å®è¡ããããããŒã«ã
çŽ æŽããããæååã¯æ°å€ã«å€æãããä»ç§ãã¡ã¯ããã䜿ã£ãŠäœããããŠããŸãã
倧åãªç¬éãŸã§ãéã®ããšãè¡ããããšèšãã°ã 0x41E100 ïŒ 0x40458Cããã®åŒã³åºã ïŒã®é¢æ°ã1ã€ããæ®ã£ãŠããŸããã§ããã
ããŠãããã§ã¢ã»ã³ãã©ãŒãªã¹ãã®èªã¿åããšãã³ãŒãã«ã€ããŠæ©ãã€ããã¯ãããŸãããããå人ãããããéã¢ã»ã³ãã«ãå§ããé ã«ã¯ãæå®ãããå®è£ ã§ã¯ãªããŠããéåžžã«æ©ã段éã§ãããã¯ãŒã¯ã«ãªãŒã¯ããŠããPopCapã®ãœãŒã¹ã³ãŒããæããŸããæ©èœããŸãããå°ãªããšããã®ååã äžè¬ã«ã ãã©ã ããŒã«...æ£é¢æ»ââæãéå§ããé¢æ°ã¯aSignature.ModPowïŒeãnïŒãšåŒã°ããŸãã
èå³ã®ãã人ã¯ãè¡00069ããã©ã£ãŠã ããŒã«é¢æ°SexyApp :: ValidateïŒïŒ ïŒSexyApp-äœããã®çç±ã§ãã¿ã³ã¢ã³ãŒãã£ãªã³ãªãã®åªé ãªçŽ³å£«ïŒãšããã§ã«éåžžã«èŠªãã¿ã®ãã0x404260ãšã®é¡èãªé¡äŒŒæ§ãèŠã€ããããšãã§ããŸãã
ãŸãã eãšnèªäœã«ã泚æããããšããå§ãããŸãã
BigInt n("42BF94023BBA6D040C8B81D9"); BigInt e("11");
ãŸãã¯ãã¢ã»ã³ãã©ãŒè¡šçŸã§ã¯ã
ååã瀺ãããã«ã ModPowïŒïŒã¯çŽ¯ä¹æ³ãæå³ããŸãã
è¡00478ã®ã³ã¡ã³ã
// Public RSA stuff BigInt n("D99BC76AB7B2578738E606F7"); BigInt e("11"); BigInt aHash = HashData(aFileData, aFileDataPos, 94); delete aFileData; BigInt aSignature(aSigStr); BigInt aHashTest = aSignature.ModPow(e, n);
æåŸã«ç¶æ³ãæ確ã«ããŸãïŒæ±ã£ãŠããã¢ã«ãŽãªãºã ã¯RSAã§ãã
ããŒã4ïŒéµãžã§ãã¬ãŒã¿ãŒ
ããŠãkeygenã®äœæãéå§ããããã®ã»ãšãã©ãã¹ãŠã®çããŒã¿ããããŸãã ããšã¯ããããªãã¯ã¢ãžã¥ãŒã«0x42BF94023BBA6D040C8B81D9ããã¡ã¯ã¿ãªã³ã°ãããã©ã€ããŒãææ°ãèšç®ããã ãã§ãã ããŠã MSieve + TMG RSA Toolã䜿çšããŠãåºåã§0x03AE5465C52D0C4C0A8FE303DãååŸããŸããæ®ã£ãŠããã®ã¯ãé·ãç®è¡ã®å®è£ ãèšè¿°ããïŒãŸãã¯ãå®æãããã®ãæ¶å»ããïŒããšã§ãã ããŒèªäœãçæããã¢ã«ãŽãªãºã ããããŸãã
- æååUSERNAMEã0AhãZUMAããMD5ãã«ãŠã³ãããŸã
- æåŸã®DWORDãæšãŠãæ®ãã®ãã€ãé ãæžã蟌ã¿ãŸã
- WORD-ovoã§çµæã確èªããã·ãããé©çšããŸãïŒèªã¿åãïŒkeygenã«ã³ããŒã¢ã³ãããŒã¹ãïŒã 0x41D280ãåç §
- åã³éãã€ãé
- åä¿¡é¢æ°ModPowïŒDãNïŒããèšç®ããŸããããã§ãD = 0x3AE5465C52D0C4C0A8FE303DãN = 0x42BF94023BBA6D040C8B81D9ãE = 0x11
- è¡šã234679ACDEFGHJKLMNPQRTUVWXYZãã«åŸã£ãŠæ®å·®ãé æ¬¡ä»£å ¥ããŠ28ã§é€ç®ããèšç®ããããã®ããã©ã€ã»ã³ã¹ããŒãæããã«ãã
ããã§ã¯ã倧åãªè¡ãA ..... 6..O6NBBO .... E4GXF3O0 ..ããäœã§ãããã«ã€ããŠã®æ°æéã®ç 究ãæå³çã«çç¥ããŸããã USERNAMEãšããŠæå®ãããŠããŸãã ç¹ã«ãã³ã³ãã¥ãŒã¿ãŒã®ããŒããŠã§ã¢ã«åºã¥ããŠçæãããã³ã³ãã¥ãŒã¿ãŒã®ãããã¯ãŒã¯ã¢ããã¿ãŒã®æ°ããã®é·ãã«é¢äžããŠããããšãããããŸãã
ç§ã®æèŠã§ã¯ããã®äžä»£ã®ã³ãŒãã¯ãåŠæ³çãªéº»è¬äžæ¯è ã«ãã£ãŠæžãããŸããã ããã§ãããšãã°ãå®éã®ç¶æ³ïŒãã€ã§ããç§ã®ã³ã³ãã¥ãŒã¿ãŒã¯3ã€ãŸãã¯4ã€ã®ãããã¯ãŒã¯ã¢ããã¿ãŒïŒ äœãªã¿ãŒã³ãã€ãŒãµãããã€ã³ã¿ãŒãã§ãŒã¹eth0 ãWiFiã€ã³ã¿ãŒãã§ãŒã¹wlan0ïŒ ãããã³USBããŒãçµç±ã§æ¥ç¶ãããGPRSã¢ãã ã®åœ¹å²ãæããæºåž¯é»è©±ãæã€ããšãã§ããŸãã ppp0 ïŒã æºåž¯é»è©±ãæ¥ç¶ãããšããã«4ã«ãªããŸããåæãããš-3ãããã2ã€ã®ç¶æ ã¯ããžã§ãã¬ãŒã¿ãŒã«ãããšãç°ãªãåç·ã«å¯Ÿå¿ããŠããŸãã ãã®ããããã®ãã¡ã®1ã€ã§ãZumaã16.99ãŠãŒãã§è³Œå ¥ãããããè³Œå ¥ã§ããŸããã
äžè¬ã«ãåè¿°ã®ãã®æ±ãããªãã¯ãçæããã³ãŒãã«åºã¥ããŠã貌ãä»ããkeygenã«ã³ããŒããã ReadProcessMemoryïŒïŒã䜿çšããŠã²ãŒã ã®ã¡ã¢ãªããæ¢ã«å®æããè¡ãç°¡åã«çãããšã«ããŸããã ã¡ãã£ãšããããŒãªã¬ã³ãšããŠãååæååã«èªåã§äœããæžãæ©èœãè¿œå ããŸããïŒãæ³åã®ãšãã ã WriteProcessMemoryïŒïŒã䜿çšïŒã ãã ããæ®å¿µãªããããã®ããªãã¯ã¯WINEã§ã®ã¿æ©èœããŸãïŒã€ãŸããç»é²ã®æå¹æ§ãä¿æããŸãïŒãããå®éã®ãWindowsã§ã¯æ©èœããŸããã
æ®ãã®ããã«-Zuma keygenãæŠå¿µå®èšŒãæããæ¯æããŠãã ããã
èšè¿°èšèªã¯ã¢ã»ã³ãã©ãŒã§ãã MD5ã¢ã«ãŽãªãºã ã¯ãã²ãŒã ãã€ããªããã³ããŒããããã¡ã€ã«ã§ãããã«å€æŽãããŸãã 96ãããæŒç®-æ¬ç©=ïŒ
Keygenã¯ããã®èšäºã§èª¬æãããŠããããŒãžã§ã³ã®Zumaã ãã§ãªããä»ã®ããŒãžã§ã³ïŒä»¥åãŸãã¯ä»¥éïŒã§ããã¹ããããŸããïŒããããŸããã§ããïŒã ãŠãŒã¶ãŒåãæã€ã¢ãã¬ã¹ãç°ãªããšããäºå®ã«ãããããããã©ã€ã»ã³ã¹ããŒèªäœãããããã¹ãŠã«è¿ã¥ãã2003幎以éã®ã¢ã«ãŽãªãºã ã®äžå€æ§ã蚌æããŠããŸãã
ããšãããšåèæç®
ãã®èšäºã¯ããã®ã¹ã¬ããã® æ£ããéãæ¡å ããŠãããWASM.RUãã©ãŒã©ã ã®æ°äººã®æåŠè ã®å©ãããªããã°äžå¯èœã ã£ãã§ãããããŸããTMGããã«ãŒããŒã ã®RSA Toolãšãªã³ã©ã€ã³ã®RSAèšç®æ©http://nmichaels.org/rsa.pyãç§ã倧ãã«å©ããŠãããŸããã
RSAãšMD5ã«é¢ãããŠã£ãããã£ã¢ã®èšäºããã²ãŒã ã®è žã§äœãèµ·ãã£ãŠããã®ããšããæ¬è³ªãç解ããããã«å€ããäžããŠãããŸããã
誰ããèå³ãããå Žåã¯ãããŒããžã®ãã¹ãŠã®ã³ã¡ã³ããšã³ã³ãããŒã«ãã€ã³ããå«ãOllyDBGã®.UDDãã¡ã€ã«ãé åžããŸããã
PS誰ãã30æ¥éã®éã¢ã¯ãã£ãåŸã«ãã¡ã€ã«ãåé€ãããªããããä¿¡é Œæ§ã®é«ããã¡ã€ã«ãã¹ãã£ã³ã°ãµãŒãã¹ãã¢ããã€ã¹ã§ããå Žåãç§ã¯éåžžã«æè¬ããŸãã
PPSãããã³ã°åŸã åé¡ã®ããã±ãŒãžã®Zuma.exeãåãªãã©ãããŒã§ãããZumaã®å®éã®ãã³ãpopcapgame1.exeãšåŒã°ããã¢ãŒã«ã€ããã©ã€ã»ã³ã¹ããŒã䜿çšããŠç¬èªã®ãã©ã«ããŒã«è§£åããã¢ãŒã«ã€ãã§ããããšãçºèŠãããšãã®é©ãã¯...
[æŽæ°ïŒ] Habrastorageã«åçã転éããŸããã