破解badcat21---真正的初學者 (5千字)
這個軟體極弱,正好作為破解第一課。
執行badcat21,選註冊,填121212121,按ctrl+n,下bpx hmemcpy,x退出點註冊,pmodule到它領空,按f12,一次就退了,弱吧,嘿嘿
原樣再來一便,到這裡。
按f10往下,
:00482DD5 3BC6
cmp eax, esi
:00482DD7 DBE2
fclex
:00482DD9 7D12
jge 00482DED
:00482DDB 68A0000000 push 000000A0
* Possible StringData Ref from Code Obj ->"N?f??"
|
:00482DE0 681CA04100 push 0041A01C
:00482DE5 53
push ebx
:00482DE6 50
push eax
* Reference To: MSVBVM60.__vbaHresultCheckObj, Ord:0000h
|
:00482DE7 FF1558104000 Call dword ptr
[00401058]
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:00482DD9(C)
|
:00482DED 8B45E0
mov eax, dword ptr [ebp-20]
:00482DF0 8D4DBC
lea ecx, dword ptr [ebp-44]
:00482DF3 8945D4
mov dword ptr [ebp-2C], eax
:00482DF6 8D45CC
lea eax, dword ptr [ebp-34]
:00482DF9 50
push eax
:00482DFA 51
push ecx
:00482DFB 8975E0
mov dword ptr [ebp-20], esi
:00482DFE C745CC08000000 mov [ebp-34], 00000008
* Reference To: MSVBVM60.rtcTrimVar, Ord:0208h
|
:00482E05 FF15C4104000 Call dword ptr
[004010C4]
:00482E0B 8B55E8
mov edx, dword ptr [ebp-18]
來到這裡。這個edx就是算出來的註冊碼
再往下就判斷退出了。
:00482E0E B80B000000 mov eax,
0000000B
:00482E13 89857CFFFFFF mov dword ptr
[ebp+FFFFFF7C], eax
:00482E19 89458C
mov dword ptr [ebp-74], eax
:00482E1C 8D45BC
lea eax, dword ptr [ebp-44]
:00482E1F 899564FFFFFF mov dword ptr
[ebp+FFFFFF64], edx
:00482E25 8D8D5CFFFFFF lea ecx, dword
ptr [ebp+FFFFFF5C]
:00482E2B 50
push eax
:00482E2C 8D55AC
lea edx, dword ptr [ebp-54]
:00482E2F 51
push ecx
:00482E30 52
push edx
:00482E31 C74584FFFFFFFF mov [ebp-7C], FFFFFFFF
:00482E38 897594
mov dword ptr [ebp-6C], esi
:00482E3B C7855CFFFFFF08800000 mov dword ptr [ebp+FFFFFF5C], 00008008
* Reference To: MSVBVM60.__vbaVarCmpNe, Ord:0000h
|
:00482E45 FF154C104000 Call dword ptr
[0040104C]
:00482E4B 8BD0
mov edx, eax
:00482E4D 8D4D9C
lea ecx, dword ptr [ebp-64]
* Reference To: MSVBVM60.__vbaVarMove, Ord:0000h
|
:00482E50 FF1514104000 Call dword ptr
[00401014]
:00482E56 8D857CFFFFFF lea eax, dword
ptr [ebp+FFFFFF7C]
:00482E5C 8D4D8C
lea ecx, dword ptr [ebp-74]
:00482E5F 50
push eax
:00482E60 8D559C
lea edx, dword ptr [ebp-64]
:00482E63 51
push ecx
:00482E64 8D856CFFFFFF lea eax, dword
ptr [ebp+FFFFFF6C]
:00482E6A 52
push edx
:00482E6B 50
push eax
* Reference To: MSVBVM60.rtcImmediateIf, Ord:02A9h
|
:00482E6C FF15E0114000 Call dword ptr
[004011E0]
:00482E72 8D8D6CFFFFFF lea ecx, dword
ptr [ebp+FFFFFF6C]
:00482E78 51
push ecx
* Reference To: MSVBVM60.__vbaBoolVar, Ord:0000h
|
:00482E79 FF15C0104000 Call dword ptr
[004010C0]
:00482E7F 8D4DDC
lea ecx, dword ptr [ebp-24]
:00482E82 8945E4
mov dword ptr [ebp-1C], eax
* Reference To: MSVBVM60.__vbaFreeObj, Ord:0000h
|
:00482E85 FF1578124000 Call dword ptr
[00401278]
:00482E8B 8D956CFFFFFF lea edx, dword
ptr [ebp+FFFFFF6C]
:00482E91 8D857CFFFFFF lea eax, dword
ptr [ebp+FFFFFF7C]
:00482E97 52
push edx
:00482E98 8D4D8C
lea ecx, dword ptr [ebp-74]
:00482E9B 50
push eax
:00482E9C 8D559C
lea edx, dword ptr [ebp-64]
:00482E9F 51
push ecx
:00482EA0 8D45BC
lea eax, dword ptr [ebp-44]
:00482EA3 52
push edx
:00482EA4 8D4DCC
lea ecx, dword ptr [ebp-34]
:00482EA7 50
push eax
:00482EA8 51
push ecx
:00482EA9 6A06
push 00000006
* Reference To: MSVBVM60.__vbaFreeVarList, Ord:0000h
|
:00482EAB FF1534104000 Call dword ptr
[00401034]
:00482EB1 8B17
mov edx, dword ptr [edi]
:00482EB3 83C41C
add esp, 0000001C
:00482EB6 8D45E4
lea eax, dword ptr [ebp-1C]
:00482EB9 50
push eax
:00482EBA 57
push edi
:00482EBB FF9204070000 call dword ptr
[edx+00000704]
很簡單吧?第一次寫破解。
下弦月
相關文章
- 初學者(14) (5千字)2000-06-10
- 5StarZip 2001 破解----初學者破解入門 ---
[BCG]系列 (1千字)2001-04-13
- 一篇破解教程-----面向初學者 (15千字)2001-04-01
- 初學者請進(一篇破解javagirl的心得) (2千字)2000-05-09Java
- 獻給初學者(高手也看看) 破解 Cpukiller 2.0 (1千字)2000-09-17
- 瘋狂單詞破解實錄(初學者請進!) (9千字)2000-08-24
- 初學者(7) (4千字)2000-05-05
- 初學者(8) (4千字)2000-05-07
- 初學者(9) (3千字)2000-05-07
- 初學者(10) (8千字)2000-05-14
- 初學者(11) (2千字)2000-05-18
- 初學者(12) (1千字)2000-06-09
- 初學者(13) (2千字)2000-06-09
- 初學者(15) (3千字)2000-07-04
- 初學者(16) (2千字)2000-07-04
- 初學者(17) (1千字)2000-07-04
- 初學者(18) (2千字)2000-07-05
- 初學者(19) (4千字)2000-07-10
- 初學者(20) (3千字)2000-07-15
- 初學者(20) (1千字)2000-08-08
- 初學者(22) (7千字)2000-08-09
- 初學者(23) (7千字)2000-08-13
- 初學者(26) (9千字)2000-08-17
- 初學者(27) (1千字)2000-08-25
- 初學者的東西:Transoft's Server All 1.02破解
(3千字)2001-01-08Server
- CDSPACE1.95破解手記(專為初學者而作!) (8千字)2000-12-30
- Vopt99 v4.31暴力破解實錄(僅供初學者參考) (5千字)2001-02-19
- 給初學者,因為我就是個初學者(1) (3千字)2000-05-03
- 給初學者,因為我就是個初學者(2) (1千字)2000-05-03
- 給初學者,因為我就是個初學者(4) (1千字)2000-05-03
- 初學者請看! (2千字)2000-12-28
- 初學者作品(6) (1千字)2000-05-04
- 申請加入BCG之第二篇!博奧彩票白金版破解---破解初學者之嘔血篇 (5千字)2001-10-06
- 初學者,不知道有沒有機會進入[CCG]? 附:SNAGIT32 5.10破解。
(5千字)2000-09-28Git
- Internet Maniac ver 1.2b 破解過程(適合初學者)
(7千字)2000-09-13
- 一個簡單的破解,供初學者參考!望高手多加指點! (1千字)2001-03-26
- 初學者來吧!(一篇‘俠客系統修改1。21’的破解) (2千字)2000-05-13
- 初學者作品(5) (788字)2000-05-04