▄▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄ ▄▄▄ ▄▄▄ ▄▄▄▄▄ ▄▄▄ ▄▄▄▄▄ ▄▄▄▄▄▄▄ ▄▄▄▄▄
█░█ █░█ █░█ █░█ █░█▄█░█ █░█ █░█ █░█ █░█ █░█
█▒█ █▒█ █▒█ █▒█▄ ▀▀█▒█▀▀ █▒█▄ █▒█ █▒█ █▒█ █▒█▄
█▓█ █▓█ █▓█ █▓█▀ ▄▄█▓█▄▄ █▓█▀ █▓█ █▓█ █▓█ █▓█▀
███ ███ ███ ███ ███▀███ ███ ███ ███ ███ ███
▀▀▀ ▀▀▀ ▀▀▀ ▀▀▀▀▀ ▀▀▀ ▀▀▀ ▀▀▀▀▀ ▀▀▀▀▀▀ ▀▀▀▀▀ ▀▀▀ ▀▀▀▀▀
┌────────────────────────────────────────────────────────────────┐
│ mExElit3 Group NFO. │
├────────────────────────────────────────────────────────────────┤
│ wE aR3 a cRacking & Hacking GrouP for nEwbies, whe share │
│ knowledge about cRAcKing & hAckinG since almost none of │
│ the gOOd crack3rs/HacKers out there want to tell or at │
│ least explain something. We will, *ONLY IF YOU KNOW A LITTLE │
│ BIT AT LEAST* The reason you have to know a little bit is │
│ because teaching is REALLY hard to do, so If yOU know a little │
│ asm some cracking and u know unix then drop by EfNeT #mexelite │
│ and if you wanT to jOin Ask for the APP. │
│ │
├────────────────────────────────────────────────────────────────┤
│ PrOgram : FTP Wolf 1.02.000 │
│ uRL : http://www.msw.com.au/fwolf │
│ │
│ cRacked by : drLAN │
├────────────────────────────────────────────────────────────────┤
│ nOteS : The approach to cracking this one is very similar to │
│ the approach to cracking the Warez Wolf 1.05.00 program. By │
│ trying brute force cracing, i found that the prog. was looking │
│ for two keys in its .ini file. The two keys are licensee= and │
│ id=. I guess the bpx getwindowtexta and bpx getdlgitemtexta │
│ approach might work for these programs as well. Perhaps i was │
│ just too tired the first time i tried. Anyway, set your bp's │
│ then give the program some name and reg code. When sICE pops, │
│ F11 to get out of the calling routine. Then search around for │
│ the values you entered. s 0 l ffffffff 'drLAN' found my name │
│ in memory. I set a breakpoint at that memory address (bpm). │
│ Then search for the reg code using s 0 l ffffffff '006969'. │
│ This found my reg code in memory. Set a memory bp there, too. │
│ Now go ahead and Ctrl-D through a few routines until you find │
│ a code segment that looks something like this: │
│ │
│ 0137:00407E19 85C0 TEST EAX,EAX │
│ 0137:00407E1B 0F8403010000 JZ 00407F24 │
│ . │
│ . │
│ . │
│ 0137:00407F24 33C0 XOR EAX,EAX │
│ ... POP EDI │
│ ... POP ESI │
│ ... POP EBX │
│ ... LEAVE │
│ ... RET │
│ │
│ We want to change the conditional jump to an unconditional JMP │
│ and drop into the line below the XOR to bypass it. So change │
│ line 0137:00407E1b to: │
│ │
│ 0137:00407E1B E906010000 JMP 00407F26 │
│ │
│ Using a hex editor, i changed these values in the executable. │
│ Search: 0F840301 │
│ Replace: E9060100 │
│ │
│ Now run it and register it using any name and reg code you │
│ desire. │
│ │
│ My patch will apply the hex code changes mentioned above, if │
│ you don't like playing with hex editors. │
│ │
│ drLAN │
├────────────────────────────────────────────────────────────────┤
│ │
│ rOll eMail HandlE │
├────────────────────────────────────────────────────────────────┤
│ │
│ fOundEr/PreZZ : [email protected] nIabI │
│ │
│ fOundEr/vice : [email protected] x_hack │
│ │
│ cRacKer/senior: [email protected] JosephCo │
│ │
│ cRacKer : [email protected] Sice_boy │
│ │
│ cRacKer : [email protected] |lasher| │
│ │
│ cRacKer : [email protected] drlan │
│ │
│ hacker : [email protected] Muertos │
│ │
│ cRacKer : [email protected] Tgunner │
│ │
│ cRacker : [email protected] IllumiTIE │
│ │
│ cRacKer : [email protected] BurnOut │
│ │
│ BotmAster : [email protected] Robbin │
│ │
├────────────────────────────────────────────────────────────────┤
│ │
│grEEts : │
│ │
│ │
│ VERY special Thanks go to : Razzia ;for the GREAT tuts and help│
│ │
│ PerSonAl : FlotSamj,[PRIMUS],Archimede,[ACP],xphil and the rest│
│ │
│ of you, you know who u are ;) │
│ │
│ │
│ │
│ gRoups : every gropu that ShaRes What ThE scenE has to offer │
│ │
│ again u know who u are │
│ │
│ │
├────────────────────────────────────────────────────────────────┤