Kako krekovati mIRC 7.32 u 3 faze :)

Forums for the Serbian-speaking Community

Moderators: Gaddafi, munZe

Kako krekovati mIRC 7.32 u 3 faze :)

Postby munZe » June 12th, 2013, 4:17 pm

Sta nam je potrebno od Toolova?

- PEiD (kako bi nasli gde je CRC32)

- HDasm (kako bi nasli odgovarajuce stringove)
Ali posto se kroz verzije provlace ovi stringovi, nece nam biti potrebno :)
0788 - please wait
0773 - valid
0775 - not valid

- DeFixed (asebler u kome cemo odraditi sve)


1. Faza

Potrebno je da pronadjemo CRC, ili ti cyrilic zastitu i da je sklonimo (NOPujemo:))

U verziji 7.32 se nalazi na adresi 46CCEF - Ukoliko je neka druga verzija koristimo PEiD da nam kaze gde je CRC.

Zamenimo JE sa JMP i asemblujemo, snimimo fajl i proverimo da li je to to.


Zatvorimo sve, i probamo da li mIRC radi, ako radi, odlucno smo odradili i prelazimo na drugu fazu.

2. Faza

Otvorimo mIRC sa DeFixed i pokusamo bilo koju registraciju i bacice nas na:


Kada nas baci tamo, stisnemo F2 da napravimo break i ENTER da ispratimo gde nas dalje vodi.

Nadjemo gde nas bacio i

Binary > Fill with NOPs na

JE 004ff2a0

i sledeci JE 004FF2A0 isto



Pa Analise This!

Pa snimimo to sto smo odradili.

Ugasimo sve i proverimo da li smo krekovali kako treba ;)

Posto jesmo idemo na trecu fazu.

3. Faza

U trecoj fazi cemo sjebati validaciju da nas ne smara svaki put kada palimo mirc da kucamo registraciju ponovo.

Otvorimo mirc sa DeFixed

Pa idemo Search for > All referenced text strings

Brejkujemo sve stringove validated (sa F2), pokrenemo i pokusamo registraciju.

Ugasimo sve - pokrenemo ponovo i bacice nas na ovo iz slike.

Zamenimo taj JNZ sa JMP


Snimimo sve promene i mIRC nam je krekovan ;-)

Da bih naucio ovo korisio sam stari tutorijal za krekovanje mirca koji mozete naci ovde:

U pitanju je starija verzija, ali je procedura ista ;-)

Toliko od mene, ukoliko imate problema, slobodno mi se obratite ovde ;-)
Cilj ovog tutorijala je da sprecimo n00bove koji krekuju mIRC, ubace trojanca i stave ga na neki forum za download kako bi nas zarazili.
Ovim cete nauciti kako sami da odradite to i da ne brinete za viruse ;-)

Uzivajte u svojelicno krekovanom mIRCu ;-)
[r00t@err0r #] cat /etc/pwnd
Owner of Majstorov.Info,DBase @ Fewona.Net
TCL,Community,IRC Games (Holdem,Lov,Kviz), Free SHELL Ipv6, Free ZNC Ipv4 & Ipv6 -=> Fewona.Net
Image
Image
User avatar
munZe
Fewona Staff
 
Posts: 149
Joined: December 31st, 2012, 12:20 pm
Location: /bin/false

Re: Kako krekovati mIRC 7.32 u 3 faze :)

Postby t8x » September 14th, 2013, 8:16 am

Very nice :) helped me a lot.

only problem is i don't know why with PEiD i couldnt get the CRC32 check address :( nor your were working :(
I am running on Win7 x64 but i also tried to get the crc check with Vista x86 , no success both cases :( i don't know why is that. In Vistax86 and Win7 x 64 getting the same address for the CRC32 and its not accurate.
t8x
Member
 
Posts: 9
Joined: August 8th, 2013, 3:19 pm

Re: Kako krekovati mIRC 7.32 u 3 faze :)

Postby munZe » September 14th, 2013, 9:24 am

t8x wrote:Very nice :) helped me a lot.

only problem is i don't know why with PEiD i couldnt get the CRC32 check address :( nor your were working :(
I am running on Win7 x64 but i also tried to get the crc check with Vista x86 , no success both cases :( i don't know why is that. In Vistax86 and Win7 x 64 getting the same address for the CRC32 and its not accurate.


CRC in mIRC (in all versions) always starts with:
Image
so when you see this, you will know this is CRC ;) JMP this JE and this is it ;) CRC is death :)
If you have any questions, feel free to ask ;)
[r00t@err0r #] cat /etc/pwnd
Owner of Majstorov.Info,DBase @ Fewona.Net
TCL,Community,IRC Games (Holdem,Lov,Kviz), Free SHELL Ipv6, Free ZNC Ipv4 & Ipv6 -=> Fewona.Net
Image
Image
User avatar
munZe
Fewona Staff
 
Posts: 149
Joined: December 31st, 2012, 12:20 pm
Location: /bin/false

Re: Kako krekovati mIRC 7.32 u 3 faze :)

Postby t8x » September 14th, 2013, 12:46 pm

i found it already thanks to your pictures :D

and i did the job, only wonder why when you use PEid you can get the right numbers but i cant . i get 0046CD58 in win7x64 and vistax32 . but when i found the real one thanks to your post it was something different . let me see what it was - ops found it:

in my case is not the same ;( no idea why ? :

00D9CCEF |. /0F84 AE000000 JE 00D9CDA3

i got 00D9CDA3 instead of JE 0046CDA3


also any idea why PEiD is showing me this instead ?

CRC32 :: 00260E00 :: 00662600
Referenced at 0046CAB3
Referenced at 0046CB62
Referenced at 0046CBB2
Referenced at 0046CD58
t8x
Member
 
Posts: 9
Joined: August 8th, 2013, 3:19 pm


Return to Српски Форум

Who is online

Users browsing this forum: No registered users and 1 guest