CrackMe® Practices for Newbies
CrackMe 2 by CyberBlade [ReFleXZ '99]

Re: Joseph's Thread---Patch it
Monday, 12-Apr-99 23:14:59

    Greeting,

    You want to patch the target so it will look for another program to Zap her it is. Look at the following section of a hex dump of the program an you should be able tp see NUMEGSMARTCHECK shattered among the rest of all other type of bytes. Notice also that character takes 4 bytes of memory. Take the N for instance and it is coded as F54E 0000. Using a hex editor and without bothering about the other three bytes, change each of the characters to create a new name and save this edited file as Crackme2.exe and try running it in SmartCheck. To your surprise and perhaps the disappointment of Cyberblade, you will be able to inspect the program using SmartCheck.


    0000D250 4B65 7941 7363 6969 0000 0000 4032 4000 KeyAscii....@2@.
    0000D260 C833 4000 50F3 4000 F54E 0000 0004 68FF .3@.P.@..N....h.
    0000D270 0A1C 0008 0004 68FF F555 0000 0004 58FF ......h..U....X.
    0000D280 0A1C 0008 0004 58FF FBEF 48FF F54D 0000 ......X...H..M..
    0000D290 0004 38FF 0A1C 0008 0004 38FF FBEF 28FF ..8.......8...(.
    0000D2A0 F545 0000 0004 18FF 0A1C 0008 0004 18FF .E..............
    0000D2B0 FBEF 08FF F547 0000 0004 F8FE 0A1C 0008 .....G..........
    0000D2C0 0004 F8FE FBEF E8FE F541 0000 0004 D8FE .........A......
    0000D2D0 0A1C 0008 0004 D8FE FBEF C8FE 3AB8 FE1D ............:...
    0000D2E0 00FB EFA8 FEF5 5300 0000 0498 FE0A 1C00 ......S.........
    0000D2F0 0800 0498 FEFB EF88 FEF5 4D00 0000 0478 ..........M....x
    0000D300 FE0A 1C00 0800 0478 FEFB EF68 FEF5 4100 .......x...h..A.
    0000D310 0000 0458 FE0A 1C00 0800 0458 FEFB EF48 ...X.......X...H
    0000D320 FEF5 5200 0000 0438 FE0A 1C00 0800 0438 ..R....8.......8
    0000D330 FEFB EF28 FEF5 5400 0000 0418 FE0A 1C00 ...(..T.........
    0000D340 0800 0418 FEFB EF08 FEF5 4300 0000 04F8 ..........C.....
    0000D350 FD0A 1C00 0800 04F8 FDFB EFE8 FDF5 4800 ..............H.
    0000D360 0000 04D8 FD0A 1C00 0800 04D8 FDFB EFC8 ................
    0000D370 FDF5 4500 0000 04B8 FD0A 1C00 0800 04B8 ..E.............
    0000D380 FDFB EFA8 FDF5 4300 0000 0498 FD0A 1C00 ......C.........
    0000D390 0800 0498 FDFB EF88 FDF5 4B00 0000 0478 ..........K....x


    Enjoy,

    Joseph

    Joseph


Message thread:

Joseph's Thread---Zap the Zapper (Joseph) (12-Apr-99 02:42:27)

Back to main board