
ãšã³ããªãŒ
ããã«ã¡ã¯ãHabralumiã
ææ°ã®
ã¢ã»ã³ãã©ãŒã®ããã°æçš¿ãã倿ãããšãkeygenããŒãã¯ããã§éåžžã«äººæ°ãé«ãŸã£ãŠããŸãã ãŸããç§ã¯ç§ã®5ã»ã³ãããããããŸãã
仿¥ã®å®éšããŒãã¯Zuma Deluxeã²ãŒã ã§ããããã¯èªåã§keygenãGoogleã§æ€çŽ¢ããããšã¯ã§ããŸããã§ããïŒç§ã¯ã²ãŒããŒã ãšã¯æããªãã§ãã ããã å
責äºé
ïŒæåããæåŸãŸã§ã®ãã®ããã¯ã¯æè²ç®çã§è¡ããããã®ã§ãããäŒç€ŸPopCap Gamesã®æå€±ãæãããšãæå³ãããã®ã§ã¯ãããŸããã
Zumaãã£ã¹ããªãã¥ãŒã·ã§ã³ãã°ãŒã°ã«ã§ããŠã³ããŒãããŠããŠã³ããŒããã
OllyDBGãæŠéæºåç¶æ
ã«ããŠãåæãéå§ããŸãã
ã¯ããäºåã«äºçŽããŸãããã°ããã®éãç§ã¯Linuxoidã§èªåèªèº«ãé»ãããã®ã§ããã®åã³ã¯ãã¹ãŠWINEã®äžããå§ãŸããŸãã ãã ãããã®ã¿ã¹ã¯ã«ã¯ãéåžžã®ããã¹ããã¡ã€ã«ã«ä¿åãããããããšã³ããªã®ç·šéãWINEã¬ãžã¹ããªã®å€æŽã®è¿œè·¡ãç°¡åã«ãªããªã©ããã®ã¿ã¹ã¯ã«ã¯å©ç¹ãããããšã«æ³šæããŠãã ããã
ããŒã1ïŒé°æ¹¿ãªãã©ãã·ã¥
äžè¬çã«ãã²ãŒã ãéå§ããäºæ³ãããé·ããã¬ã€ããŸãïŒãŸãã¯ããã«HKLM / Software / PopCap / Zumaã¬ãžã¹ããªãã©ã³ãã«ç»ããTimesExecutedããã³TimesPlayedããŒã«ãŒããèšå®ããŸãïŒ-ãããŠåºæ¥äžããïŒ

OKã[ä»ãã賌å
¥]ãéžæãããããã¢ãããã©ãŠã¶ãŠã£ã³ããŠãéããŠãæ²æšãª16.99ãŠãŒãã§
ãã®ãããªã²ãŒã ã賌å
¥ãããšãããªãã¡ãŒã衚瀺ãã[ç»é²ããŒãæåã§å
¥å]ãæŒããŸãã

ãããã£ãŠãå
¥åãã£ãŒã«ãã ãã§ã«èžãããšãã§ãããã®ããã äºæ³ã©ããããæå¹ãªããŒãå
¥åããŠãã ããããšããã¡ãã»ãŒãžã衚瀺ãããäœãäœã§ããããããããŸãã ææ
®æ·±ãæ€æ»ã§èŠåããæåã®ããšã¯ãã²ãŒã ã®ãããŒã®ããæšªã«ãããã©ã«ããŒå
ã®ååšã§ã.2ã€ã®ãã¡ã€ã«ãããã°ã©ã ã§ã®Flashãã¯ãããžãŒã®äœ¿çšã瀺åããŠããŸãïŒå®éã«ã¯ãFlash.ocxãšdrm.swf ...ã©ãããããã©ãŠã¶ãŒãéããã®ã«æéããããå¯èœæ§ããããŸãã OKããã®drm.swfãéããŸãã

ããŒãç»é²ããããã®é
åçãªã·ã§ã«å
šäœã¯ãçµå±ã®ãšãããåã.SWFãã¡ã€ã«ã§äœæãããŠããŸãã æ€èšŒã³ãŒãèªäœã¯åãå Žæã«ããã®ã§ããããïŒ èŠãŠã¿ãŸãããã ActionScriptãã³ã³ãã€ã©ïŒããšãã°ã
Flareã䜿çšããŸããïŒãååŸããdrm.swfãããœãŒã¹ã³ãŒããååŸããŸãã
ããã«ã³ã³ãã€ã«ãããã®ãèŠãŸãã é
ããæ©ããããã®è峿·±ãè¡ã«åºããããŸãã
gFrameLabels[4] = 'RegFailed';
ãRegFailedãã§æ€çŽ¢ãããã®ã³ãŒããããã¯ã«æ»ããŸãã
if (_root.RegCodeEdit.text.length >= 23 && _root.validate_regkey(_root.RegCodeEdit.text)) { _root.APError.text = ''; gRegFailedHeader = gHeader_RegFail; gRegFailedMessage = gMessage_RegFail; gRegFailedRetryLocation = 'APScreen'; fscommand('Register', _root.RegCodeEdit.text); }
ããã«ããã æ£ããããŒã¯23æåã®é·ãã§ïŒããã¹ããã£ãŒã«ãèªäœãå
¥åããããšãã§ããªããªããŸãïŒã
validate_regkeyïŒïŒã True ãè¿ãããã«åŒ·å¶
ã ãŸã ã ã³ãŒãã®åããããã¯ã§
gRegFailedMessageãçºçãããããªãæããå€ã®åæåãè¡ããããšããäºå®ã¯ç¡èŠã§ããŸãã ããã§ã¯ããããã«é¢ä¿ãªãããã©ãã·ã¥ãªããžã§ã¯ããã
fscommandïŒïŒãä»ããŠããŒã¿ã芪ããã»ã¹ã«è»¢éãããŸãã
ããã§ã
validate_regkeyïŒïŒé¢æ°èªäœã䜿çšããŸãã ããã«å
šäœããããŸãïŒ
function validate_regkey(string) { if (string.substr(5, 1) == '-' && string.substr(11, 1) == '-' && string.substr(17, 1) == '-') { char = new Array(); k = 0; while (k <= string.length - 1) { char = string.slice(k, k + 1); if (char == '0' || char == '1' || char == '2' || char == '3' || char == '4' || char == '5' || char == '6' || char == '7' || char == '8' || char == '9' || char == 'A' || char == 'B' || char == 'C' || char == 'D' || char == 'E' || char == 'F' || char == 'G' || char == 'H' || char == 'I' || char == 'J' || char == 'K' || char == 'L' || char == 'M' || char == 'N' || char == 'O' || char == 'P' || char == 'Q' || char == 'R' || char == 'S' || char == 'T' || char == 'U' || char == 'V' || char == 'W' || char == 'X' || char == 'Y' || char == 'Z' || char == 'a' || char == 'b' || char == 'c' || char == 'd' || char == 'e' || char == 'f' || char == 'g' || char == 'h' || char == 'i' || char == 'j' || char == 'k' || char == 'l' || char == 'm' || char == 'n' || char == 'o' || char == 'p' || char == 'q' || char == 'r' || char == 's' || char == 't' || char == 'u' || char == 'v' || char == 'w' || char == 'x' || char == 'y' || char == 'z' || char == '-' || char == ' ') { if (k == string.length - 1) { result = 'Thank you for submitting !'; return true; } } else { result = 'Unauthorized character ' + char; return false; } ++k; } } else { result = 'Error in delimiters'; return false; } }
ãŸããäžå€®ç£æ»ã¯æçœãªåäœã§ãã ãããã
govnokod.ruã«æçš¿ããå¿
èŠããããŸããããŸããç§ãã¡ã¯ããã§æ¥œããããšãããã€ããã¯ãããŸããã äž»ãªããšã¯ããã®é¢æ°ãã©ã€ã»ã³ã¹ããŒã®æ§é ãæäŸããããšã§ãã
#####-#####-#####-#####
ããã§ãïŒã¯ã¢ã«ãã¡ãããã0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz-
ãã
æ£ç¢ºã«23æåã
ããäžåºŠèããŠã¿ããšãããã°ã©ã èªäœã®äžã®æ£ããæåã®ã»ããã¯ãããã«æžããšæããŸãã ããããä»ã®ãšãããããã¯ç§ãã¡ã«éãããããããŸããã OllyDBGãèµ·åããå®éšã«ããŒãããŸãã ãããèµ·åãïŒF9ïŒãã¡ã€ã³ãŠã£ã³ããŠãæç»ããããŸã§åŸ
ã¡ãŸãã
ããã«æãå Žæã¯ïŒ
ãRegisterãè¡ã«çããæåã®ãã©ã¡ãŒã¿ãŒã§èŠã€ãã£ã
fscommandïŒïŒåŒã³åºããèŠããŠã
ãŸããïŒ
ãããã£ãŠãã¡ã¢ãªãããïŒAlt + MïŒãéãããã®è¡ã®ãšã³ããªãæ¢ããŸãïŒCtrl + BïŒã ãããŠãããã§åœŒå¥³ã¯ã
0x4417D0ã§èªåèªèº«ã«æšªããã£ãŠã
ãŸã ïŒ

ãã®äžã«ãã¬ãŒã¯ãã€ã³ããé
眮ããŸãïŒéžæâShift + F3ïŒã 次ã«ã確èªãŠã£ã³ããŠã§ãããã®ã²ãŒã ãæ¢ã«è³Œå
¥ããŸãããïŒãâãç»é²ããŒãæåã§å
¥åããŸããã®äžã®ãªã³ã¯ãã¯ãªãã¯ããããŒãã£ãŒã«ãã«è±æ°åã®ãŽãããã€ãã³ã§åºåã£ãŠ5æåã®4ãããã¯ã«å
¥åããŸãã ãç»é²ããã¯ãªãã¯ããŸãã
ããŒã2ïŒããæ·±ãããå¿
èŠããã
ããã§ãã€ãã«æ€èšŒã¢ã«ãŽãªãºã ã®å
éšã«å
¥ããŸããã ã¡ã¢ãªã®ã³ã³ãããŒã«ãã€ã³ãã®ãªã¹ãã«ç§»åãã
0x4417D0 ïŒAlt + YâDelïŒãåé€ãã颿°ã®æåŸãŸã§å®è¡ïŒCtrl + F9ïŒããŸãã ããã«ã¯ç§ãã¡ã«ãšã£ãŠè峿·±ããã®ã¯ãªããæ¯èŒãµã€ã¯ã«ã ãããããåŒã³åºã颿°ïŒF8ïŒã«æ»ããè¿ãããçµæã®ãã§ãã¯ã衚瀺ãããŸãã ç¹°ãè¿ããŸããã颿°ã®æåŸãŸã§ãã¹ãŠã¹ãããããŠãåŒã³åºãå
ã«æ»ããŸãã

ããïŒ ãããŠä»ãç§ãã¡ã¯ã©ã€ã»ã³ã¹ããŒã¢ãã©ã€ã¶ãŒã®äžå¿ã«ããŸãã ãã®å Žæãå¿ããªãããã«ã
0x04066CAã«ã³ã³ãããŒã«ãã€ã³ãïŒF2ïŒã
é
眮ããŠ
èŠåããŠãã ããã å°ãäžïŒ
0x406757ããã³
0x4067A8 ïŒã§ã¯ãéåžžã«è峿·±ãæååãã©ã¡ãŒã¿ãŒãRegSucceededãããã³ãRegFailedããæã€é¢æ°åŒã³åºããèŠãããšãã§ããŸãã ãŸããäžäœïŒ
0x406748 ïŒã¯ãå¶åŸ¡ãç®çã®æ©èœã«è»¢éãããã©ã³ãã§ãã ãã®åå²ã¯ãALã¬ãžã¹ã¿ãšBLã¬ãžã¹ã¿ã®æ¯èŒïŒ
0x40672D ïŒã«é¢é£ä»ããããŠããŸãã å
ã«ããã«2ã€ã®ã³ãã³ãã«ãã£ãŠåŒã³åºããã颿°
0x404260㯠ããŸãã«ç§ãã¡ãæ¢ããŠãããã®ãã€ãŸã æãéèŠãªãã§ãã¯æ©èœã
ãŸããæšæž¬ã確èªããŸããããééã£ããœãŒã¹ããŒã¿ã§æ¯èŒãçã«ãªãããã«æ¯èŒã倿ŽããŸãã éžæç¯å²ã
0x406748ã«åããã¹ããŒã¹ããŒã
æŒããŸãã ãã¢ã»ã³ãã«ããŠã£ã³ããŠãéããŸãã é·ç§»ãçåŒãJEãäžçåŒãJNEã«ããé·ç§»ã«çœ®ãæããŸãã å®è¡ïŒF9ïŒ...

ã»ããæåã®èŠå¡ããšãããŸãïŒ
ãããä»ãç§ãã¡ã¯åãªãäºè£ã§ã¯ãªããéåžžã«éèŠãªæ
å ±ãæžããŠããŸãã ãããŠãããã¯éæããããã®ã§åæ¢ããã«ã¯æ©ãããããšãæå³ããããã°ã©ã ãåèµ·åïŒCtrl + F2ïŒãã
0x404260颿°ã®è
žãæãäžãã
å¿
èŠããããŸãã
ããã§ã®ã¿ã¹ã¯ã¯ãALããã³BLã¬ãžã¹ã¿ããã®é¢æ°å
ã§ã©ã®ããã«åäœããããããã³ãããã®ç䟡ãŸãã¯äžç䟡ã®åå ãšãªãã³ãŒããæ£ç¢ºã«ã©ãã«ããããçè§£ããããšã§ãã
颿°ã®ãããŒã«ãã®åºå£ãã€ã³ãRETNã®è¿ãã«ç§»åããBLã¬ãžã¹ã¿ã®ããã¯ã©ã€ãããªã³ã«ããŸãïŒã³ã³ããã¹ãã¡ãã¥ãŒâã¬ãžã¹ã¿ã匷調衚瀺âEBXïŒã

ã芧ã®ãšãããALã¬ãžã¹ã¿ã®å
容ã¯ãããŒã«ãã®ã»ãŒå
šäœã«ããã£ãŠBLã«æ ŒçŽãããåºå£ã®çŽåã«ã³ããŒããã¯ãããã¹ã¿ãã¯ããå
ã®EBXå€ãããã«åŸ©å
ãããŸãã
ããã«ãALå€èªäœã¯ãéžæã®ããŒã¯ãä»ããäžã®å³ã®é¢æ°ããååŸãããŸãã
ãã®é¢æ°ã®å
éšã«å
¥ããŸã-ãããŠäœãèŠããŸããïŒ

ãã®é¢æ°ã«ã¯2ã€ã®åºåå€ïŒ0ãš1ïŒãããããŸãããæåã®é¢æ°ã¯ã颿°ãã©ã¡ãŒã¿ãŒãšããŠæž¡ãããæ§é äœãžã®ãã€ã³ã¿ãŒã§ãããã€ãæååãããã€ã³ã¿ãŒã[ECX + 8]ã«ããæååãšäžèŽããªãå Žåã«çæãããŸãã 2çªç®ïŒå¿
èŠãªãã®ïŒã¯å察ã®ç¶æ³ã§ãã æååãåäžã®å Žåã
ããŒã3ïŒMD5ãRSAãããã³ãã¹ãŠãã¹ãŠ
èŠªé¢æ°ã«æ»ãã[ECX + 8]ãš[ARG.1 + 8]ã®å€ãã©ãããæ¥ãããèŠãŠã¿ãŸãããã
ãããè¡ãã«ã¯ããããã®è¡ãé
眮ããã¹ã¿ãã¯å
ã®2ã€ã®ã¢ãã¬ã¹ã«ãããŒããŠã§ã¢ããã¬ãŒã¯ãã€ã³ããé
眮ïŒéžæâShift + F5ïŒããŸãã ç°ãªããã·ã³æ§æããã³ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã¯ããããã®ã¢ãã¬ã¹ã¯ç°ãªãå¯èœæ§ããããŸãã ãããã£ãŠãç§ã®å Žåããããã¯
0x33E624ãš
0x33E660ã§ã ïŒäžè¬
ã«ãåçã®ããã«ãäžéšã®ESPã®äœçœ®ã«é¢ä¿ãªããã¹ã¿ãã¯ã®ç¶æ
ã瀺ã远å ã®ãŠã£ã³ããŠããµã€ãã«è¡šç€ºããããšããå§ãããŸãïŒã
ãããã®ã³ã³ãããŒã«ãã€ã³ãã¯ã次ã®ããã«ããŒããŠã§ã¢ããŒã¹ã§ãªããã°ãªããŸããã ä»ã®ã¿ã€ãã®ã³ã³ãããŒã«ãã€ã³ãã¯ãã¹ã¿ãã¯ã«é
眮ããããšãããã°ã©ã ã®ãã¯ã©ãã·ã¥ãã«ã€ãªããããéå§éã§ä¿åãããŸããã ä»ã®ãšããããããã®ãã€ã³ããéã¢ã¯ãã£ãã«ããå¿
èŠããããŸãïŒã³ã³ããã¹ãã¡ãã¥ãŒâãã¬ãŒã¯ãã€ã³ãâããŒããŠã§ã¢ã®ç¡å¹åïŒã
ããã°ã©ã ãåèµ·åããã¡ã€ã³ã¹ãã£ã³æ©èœïŒ
0x404260 ïŒã®å
¥ãå£ã§åæ¢ããŸãã ãã¬ãŒã¯ãã€ã³ããããã«çœ®ãã颿°ã1è¡ãã€ïŒF8ïŒãã¬ãŒã¹ãã2ã€ã®ããŒããŠã§ã¢ãã¬ãŒã¯ãã€ã³ãã®ç¶æ
ãç£èŠããŸãã ãã¬ãŒã¹ã¯ãè¡
0x404546ãŸã§äž¡æ¹ã®å€ãå€ãããªãããšã瀺ããŠããŸãã ããããããã¯ãã£ãšé¢çœãã§ãã
0x404546ããçŽæ¥åŒã³åºããã颿°ã¯ã
0x41E320颿°ãèµ·åããããã®ãèžã¿å°ãã§ãããããè峿·±ãããšã¯äœããããŸããã
0x41E320ã«ãã¬ãŒã¯ãã€ã³ããèšå®ããF9ãæŒããŸãã
çŸæç¹ã§ã¯ãã¹ã¿ãã¯ã«ã¯å¥åŠãªããããããã§ãå°å·ãããæåïŒããšãã°ãA ..... 6..O6NBBO .... E4GXF3O0 ..ïŒãšæ¹è¡æåã§æ§æãããè¡ããããŸããæ¥å°ŸèŸZUMAã ããã«ãã¬ãŒã¹ãã
0x41E37Fã§
åŸç¹ã
ãŸã ïŒ
ãŸããŸã ...ã¯ãããããã¯
MD5ã¢ã«ãŽãªãºã ã®åæåãã¯ãã«
ã§ã ïŒ
MD5ã ããã¯è¯ãã§ãã ããã§ãæ®ãã®é¢æ°ã³ãŒãã®åæã¯ç°¡åã§æ°æ¥œã«ãªããŸããã
- 0x41E320-0x41E397 ïŒçµæã®ããŒã¿åæåãšã¡ã¢ãªå²ãåœãŠ
- 0x41E39B - 0x41E3C3 ïŒäžèšã®è¡ããã®MD5ããã·ã¥ã®èšç®ãšãçµæãžã®ãªã³ã¯ãå«ãæ§é ã®æºåïŒä»¥äžãããã¬ãŒã ããšåŒã³ãŸãïŒ
- 0x41E3C5-0x41E408 ïŒçµæãšããŠåŸæ¹ã«ãã€ããåé
眮ãããµã€ã¯ã«
- 0x41E40A - 0x41E424 ïŒé¢æ°ã®4çªç®ã®ãã©ã¡ãŒã¿ãŒãåºå®ãããŠããïŒ0x5EïŒãããåžžã«trueã«ãªãããšã確èªãããŸãã
- 0x41E426-0x41E474 ïŒåã®ãã§ãã¯ã«ããå®è¡ãããªãã³ãŒã
- 0x41E476-0x41E4B5 ïŒ128ãããMD5ããã·ã¥ã®96ããããžã®ãããªã ãæ©èœã åºå£é¢æ°
次ã«ãæåã®ããŒããŠã§ã¢ãã¬ãŒã¯ãã€ã³ããèŠãŠã¿ãŸãããã

ç§ãèšã£ãããã«ããã®ãããª5ã€ã®æå³ã®æ§é ã¯ãåŸã«ããã¬ãŒã ããšåŒã°ããŸãã
- æåã®DWORDã¯å€æŽããããåžžã«0x44543Cã§ã
- 2çªç®ã®DWORDã®ç®çã¯æç¢ºã§ã¯ãããŸããïŒã¯ããäžè¬çã«ã¯ãåŸã§éèŠã«ãªããããç¹ã«éèŠã§ã¯ãããŸããïŒ
- 3çªç®ã®DWORDã¯ããã€ãæååãä¿åãããŠããã¡ã¢ãªå
ã®ã¢ãã¬ã¹ã§ã
- 4çªç®ã®DWORDã¯ããæå¹ãªãé·ããWORDã§èšå®ããŸãïŒã€ãŸããæååããã®WORDãããã«èšç®ã«äœ¿çšãããæ°ïŒ
- 5çªç®ã®DWORDã¯ããåèšãé·ããWORDã§èšå®ããŸãïŒã€ãŸããè¡ãé
眮ããããã«æåã«å²ãåœãŠãããWORDã®æ°ïŒ
ãããã£ãŠãç§ãã¡ããã£ãä»ãã¬ãŒã¹ããæé ãå®è¡ããåŸãæåã®ãã¬ãŒã ã¯ãã§ã«æºããããŠããŸãã ã€ãŸãããã§ã«è¡ã®1ã€ããããæ¡ä»¶ä»ãã§ãåç
§ããšåŒã³ãŸããããããã¯ããŸã èšç®ããŠããªã
0x40454F -
0x40458Cã®è¡ãšæ¯èŒãããŸãã
ããã§ã颿°
0x41E5A0ã
åŒã³åºãããè¡
0x404560ã詳ããèŠãŠã¿ãŸãããã
ãã®æ©èœã¯éåžžã«é·ããŠæãããã§ãããããã§ã¯ãé·ããŠæãããããšãç°¡åã§çè§£ããããããããã«ããã«ããŸãã ãã®é¢æ°ã¯ãåœç€Ÿãå
¥åããç»é²ããŒã®æååãåŠçãããããæ°ãçŽããŸãã
- 0x41E5A0-0x41E608 ïŒåæåãã¡ã¢ãªã®å²ãåœãŠãäŸå€ãã³ãã©ãŒã®ã€ã³ã¹ããŒã«
- 0x41E60B - 0x41E6EF ïŒæååã®æåã倧æåã«å€æããã1ãããLãã«ããOããšã0ãããQãã«çœ®ãæãããµã€ã¯ã«
- 0x41E6F5-0x41E70A ïŒ2çªç®ã®ãµã€ã¯ã«ã®æºå
- 0x41E710-0x41E7E4 ïŒ28鲿°ã·ã¹ãã ïŒæåã®æåã¯æäžäœãæåŸã¯æé«ïŒããã®å€æã®ååã«åŸã£ãŠçªå·ãæ§ç¯ãã2çªç®ã®ãµã€ã¯ã«ãæåã»ããã234679ACDEFGHJKLMNPQRTUVWXYZãããã€ãã³ãç¡èŠããçŸåšã®æåããªãå Žåã¯ãšã©ãŒãã¹ããŒããã»ããã§
- 0x41E7EA - 0x41E844 ïŒçµæã®ã³ããŒãäžæãããã¡ãŒã®è§£æŸãçµäº
- 0x41E845-0x41E874 ïŒ2çªç®ã®ãµã€ã¯ã«ã§ãšã©ãŒãã¹ããŒãããå Žåã«å®è¡ããããããŒã«ã
çŽ æŽããããæååã¯æ°å€ã«å€æãããä»ç§ãã¡ã¯ããã䜿ã£ãŠäœããããŠããŸãã
倧åãªç¬éãŸã§ãéã®ããšãè¡ããããšèšãã°ã
0x41E100 ïŒ
0x40458Cããã®
åŒã³åºã ïŒã®é¢æ°ã1ã€ããæ®ã£ãŠã
ãŸããã§ããã
ããŠãããã§ã¢ã»ã³ãã©ãŒãªã¹ãã®èªã¿åããšãã³ãŒãã«ã€ããŠæ©ãã€ããã¯ãããŸãããããå人ãããããéã¢ã»ã³ãã«ãå§ããé ã«ã¯ãæå®ãããå®è£
ã§ã¯ãªããŠããéåžžã«æ©ã段éã§ãããã¯ãŒã¯ã«ãªãŒã¯ããŠããPopCapã®ãœãŒã¹ã³ãŒããæããŸããæ©èœããŸãããå°ãªããšããã®ååã äžè¬ã«ã
ãã©ã ããŒã«...æ£é¢æ»ââæãéå§ãã颿°ã¯
aSignature.ModPowïŒeãnïŒãšåŒã°ããŸãã
èå³ã®ãã人ã¯ãè¡00069ããã©ã£ãŠã
ããŒã«é¢æ°
SexyApp :: ValidateïŒïŒ ïŒSexyApp-äœããã®çç±ã§ãã¿ã³ã¢ã³ãŒãã£ãªã³ãªãã®åªé
ãªç޳士ïŒãšããã§ã«éåžžã«
芪ãã¿ã®ãã0x404260ãšã®é¡èãªé¡äŒŒæ§ãèŠã€ããããšãã§ããŸãã
ãŸãã
eãš
nèªäœã«ã泚æããããšããå§ãããŸãã
BigInt n("42BF94023BBA6D040C8B81D9"); BigInt e("11");
ãŸãã¯ãã¢ã»ã³ãã©ãŒè¡šçŸã§ã¯ã

ååã瀺ãããã«ã
ModPowïŒïŒã¯çޝ乿³ãæå³ããŸãã
è¡00478ã®ã³ã¡ã³ã
æåŸã«ç¶æ³ãæç¢ºã«ããŸãïŒæ±ã£ãŠããã¢ã«ãŽãªãºã ã¯
RSAã§ãã
ããŒã4ïŒéµãžã§ãã¬ãŒã¿ãŒ
ããŠãkeygenã®äœæãéå§ããããã®ã»ãšãã©ãã¹ãŠã®çããŒã¿ããããŸãã ããšã¯ããããªãã¯ã¢ãžã¥ãŒã«
0x42BF94023BBA6D040C8B81D9ããã¡ã¯ã¿ãªã³ã°ãããã©ã€ããŒãææ°ãèšç®ããã ãã§ãã ããŠã
MSieve +
TMG RSA Toolã
䜿çšããŠãåºåã§
0x03AE5465C52D0C4C0A8FE303DãååŸããŸãã
æ®ã£ãŠããã®ã¯ãé·ãç®è¡ã®å®è£
ãèšè¿°ããïŒãŸãã¯ã宿ãããã®ãæ¶å»ããïŒããšã§ãã ããŒèªäœãçæããã¢ã«ãŽãªãºã ããããŸãã
- æååUSERNAMEã0AhãZUMAããMD5ãã«ãŠã³ãããŸã
- æåŸã®DWORDãæšãŠãæ®ãã®ãã€ãé ãæžã蟌ã¿ãŸã
- WORD-ovoã§çµæã確èªããã·ãããé©çšããŸãïŒèªã¿åãïŒkeygenã«ã³ããŒã¢ã³ãããŒã¹ãïŒã 0x41D280ãåç
§
- åã³éãã€ãé
- åä¿¡é¢æ°ModPowïŒDãNïŒããèšç®ããŸããããã§ãD = 0x3AE5465C52D0C4C0A8FE303DãN = 0x42BF94023BBA6D040C8B81D9ãE = 0x11
- 衚ã234679ACDEFGHJKLMNPQRTUVWXYZãã«åŸã£ãŠæ®å·®ãé æ¬¡ä»£å
¥ããŠ28ã§é€ç®ããèšç®ããããã®ããã©ã€ã»ã³ã¹ããŒãæããã«ãã
ããã§ã¯ã倧åãªè¡ãA ..... 6..O6NBBO .... E4GXF3O0 ..ããäœã§ãããã«ã€ããŠã®æ°æéã®ç ç©¶ãæå³çã«çç¥ããŸããã USERNAMEãšããŠæå®ãããŠããŸãã ç¹ã«ãã³ã³ãã¥ãŒã¿ãŒã®ããŒããŠã§ã¢ã«åºã¥ããŠçæãããã³ã³ãã¥ãŒã¿ãŒã®ãããã¯ãŒã¯ã¢ããã¿ãŒã®æ°ããã®é·ãã«é¢äžããŠããããšãããããŸãã
ç§ã®æèŠã§ã¯ããã®äžä»£ã®ã³ãŒãã¯ãåŠæ³çãªéº»è¬äžæ¯è
ã«ãã£ãŠæžãããŸããã ããã§ãããšãã°ãå®éã®ç¶æ³ïŒãã€ã§ããç§ã®ã³ã³ãã¥ãŒã¿ãŒã¯3ã€ãŸãã¯4ã€ã®ãããã¯ãŒã¯ã¢ããã¿ãŒïŒ
äœãªã¿ãŒã³ãã€ãŒãµãããã€ã³ã¿ãŒãã§ãŒã¹
eth0 ãWiFiã€ã³ã¿ãŒãã§ãŒã¹
wlan0ïŒ ãããã³USBããŒãçµç±ã§æ¥ç¶ãããGPRSã¢ãã ã®åœ¹å²ãæããæºåž¯é»è©±ãæã€ããšãã§ããŸãã
ppp0 ïŒã æºåž¯é»è©±ãæ¥ç¶ãããšããã«4ã«ãªããŸããåæãããš-3ãããã2ã€ã®ç¶æ
ã¯ããžã§ãã¬ãŒã¿ãŒã«ãããšãç°ãªãåç·ã«å¯Ÿå¿ããŠããŸãã ãã®ããããã®ãã¡ã®1ã€ã§ãZumaã16.99ãŠãŒãã§è³Œå
¥ããããã賌å
¥ã§ããŸããã
äžè¬ã«ãåè¿°ã®ãã®æ±ãããªãã¯ãçæããã³ãŒãã«åºã¥ããŠã貌ãä»ããkeygenã«ã³ããŒããã
ReadProcessMemoryïŒïŒã䜿çšããŠã²ãŒã ã®ã¡ã¢ãªããæ¢ã«å®æããè¡ãç°¡åã«çãããšã«ããŸããã ã¡ãã£ãšããããŒãªã¬ã³ãšããŠãååæååã«
èªåã§äœããæžãæ©èœã远å ããŸããïŒã
æ³åã®ãšãã ã
WriteProcessMemoryïŒïŒã䜿çšïŒã ãã ããæ®å¿µãªããããã®ããªãã¯ã¯WINEã§ã®ã¿æ©èœããŸãïŒã€ãŸããç»é²ã®æå¹æ§ãä¿æããŸãïŒãããå®éã®ãWindowsã§ã¯æ©èœããŸããã
æ®ãã®ããã«
-Zuma keygenãæŠå¿µå®èšŒãæããæ¯æããŠãã ããã
èšè¿°èšèªã¯ã¢ã»ã³ãã©ãŒã§ãã MD5ã¢ã«ãŽãªãºã ã¯ãã²ãŒã ãã€ããªããã³ããŒããããã¡ã€ã«ã§ãããã«å€æŽãããŸãã 96ãããæŒç®-æ¬ç©=ïŒ
Keygenã¯ããã®èšäºã§èª¬æãããŠããããŒãžã§ã³ã®Zumaã ãã§ãªããä»ã®ããŒãžã§ã³ïŒä»¥åãŸãã¯ä»¥éïŒã§ããã¹ããããŸããïŒããããŸããã§ããïŒã ãŠãŒã¶ãŒåãæã€ã¢ãã¬ã¹ãç°ãªããšããäºå®ã«ãããããããã©ã€ã»ã³ã¹ããŒèªäœãããããã¹ãŠã«è¿ã¥ãã2003幎以éã®ã¢ã«ãŽãªãºã ã®äžå€æ§ã蚌æããŠããŸãã
ããšãããšåèæç®
ãã®èšäºã¯
ããã®ã¹ã¬ããã® æ£ããéãæ¡å
ããŠããã
WASM.RUãã©ãŒã©ã ã®æ°äººã®æåŠè
ã®å©ãããªããã°äžå¯èœã ã£ãã§ãããã
ãŸããTMGããã«ãŒããŒã ã®
RSA Toolãšãªã³ã©ã€ã³ã®RSAèšç®æ©
http://nmichaels.org/rsa.pyãç§ã倧ãã«å©ããŠãããŸããã
RSAãš
MD5ã«é¢ãããŠã£ãããã£ã¢ã®èšäºããã²ãŒã ã®è
žã§äœãèµ·ãã£ãŠããã®ããšããæ¬è³ªãçè§£ããããã«å€ããäžããŠãããŸããã
誰ããèå³ãããå Žåã¯ãããŒããžã®ãã¹ãŠã®ã³ã¡ã³ããšã³ã³ãããŒã«ãã€ã³ãã
å«ãOllyDBGã®
.UDDãã¡ã€ã«ãé
åžããŸããã
PS誰ãã30æ¥éã®éã¢ã¯ãã£ãåŸã«ãã¡ã€ã«ãåé€ãããªããããä¿¡é Œæ§ã®é«ããã¡ã€ã«ãã¹ãã£ã³ã°ãµãŒãã¹ãã¢ããã€ã¹ã§ããå Žåãç§ã¯éåžžã«æè¬ããŸãã
PPSãããã³ã°åŸã
åé¡ã®ããã±ãŒãžã®
Zuma.exeãåãªãã©ãããŒã§ãããZumaã®å®éã®ãã³ã
popcapgame1.exeãšåŒã°ãã
ã¢ãŒã«ã€ããã©ã€ã»ã³ã¹ããŒã䜿çšããŠç¬èªã®ãã©ã«ããŒã«è§£åããã¢ãŒã«ã€ãã§ããããšãçºèŠãããšãã®é©ãã¯...
[æŽæ°ïŒ] Habrastorageã«åçã転éããŸããã