5 ms·
Many a crack back in the day was even more simple still, we'd just find and alter the right JE or JNE into a JMP and we're off to the races. As the author fou
by ruleryak 8mo ago
Many a crack back in the day was even more simple still, we'd just find and alter the right JE or JNE into a JMP and we're off to the races. As the author found, the tough part is just finding and interpreting where and how the protection was implemented. If throwing the exe in a hex editor gave you access to String Data References (not always the case, but more common than not) then you'd just fail the check you were trying to skip, find that string, hop over into assembly to see what triggered loading that, and then just alter the logic to jump over it when the time comes.
- antonvs 8mo ago> Many a crack back in the day was even more simple still, we'd just find and alter the right JE or JNE into a JMP and we're off to the races. I did that with dBASE III, which used ProLok "laser protection" from Vault Corporation - a signature burned onto the diskette with a laser. Back then, I found it amazing that Ashton-Tate actually spent money to contract with a copy protection company for something that could be so easily defeated by a teenager reading assembler. They could have easily just written the same kind of code themselves. An example of the power of marketing over substance. I was able to replicate that protection mechanism just by scratching a diskette with a pin. The "laser" was a meaninglessly advanced-sounding solution that added no value compared to any other means of damaging a diskette.
- foresto 8mo ago> I was able to replicate that protection mechanism just by scratching a diskette with a pin. How did you figure out where to scratch it? Was the laser mark visible on the original disk, or did you have to read the code and orient based on the diskette's index hole?
- anyfoo 8mo agoYes, it was apparently very visible: https://martypc.blogspot.com/2024/09/pc-floppy-copy-protection-vault-prolok.html https://martypc.blogspot.com/2024/09/pc-floppy-copy-protecti... But as I mentioned in a sibling comment, I’m not sure it was ever confirmed that it was really a laser that made that mark.
- antonvs 8mo agoI described two different scenarios: defeating the protection, and replicating it, e.g. to protect your own software without paying Vault for their "laser" protection. Defeating the protection didn't involve knowing anything about the laser mark - as the comment I replied to described, it just involved changing a conditional jump to an unconditional one. Replicating the protection involved causing minor damage on the diskette - the details don't really matter, laser, pin scratch, whatever - then formatting the disk, and registering the pattern of bad sectors created by the damage. A normal copy of the disk didn't replicate those bad sectors exactly, which made it possible to detect that the original disk was not present.
- lstodd 8mo agoHa! I remember disk copy programs which read these bad sector patterns and then replicated the error pattern in software (not on physical disk obviously). Similar stuff was later used for CDs IIRC.
- Aaargh20318 8mo agoI remember doing something similar with Lemmings 3D. You could simply NOP over the JMP into the copy-protection subroutine. It was surprisingly easy. Made me feel like such a badass hacker at 15 years old.
- p1mrx 8mo agoWhen I was 10 or so, I "cracked" Slam! Air Hockey for Windows 3.1 by opening the exe in EDIT.COM and replacing some random binary garbage with spaces. After a few attempts, I managed to bypass the shareware dialog but also introduced some weird bugs that I don't recall the details of.
- deleted 8mo ago[deleted]
- 2Gkashmiri 8mo ago"Cheat enginge" This was one of those things you really really wanted but once you toyed with it, it sucked the fun out of games and they felt pointless.
- anyfoo 8mo agoWas ist ever confirmed that it was in fact a laser? I wanted to make a trivia question out of this ProLok protection, because “lasers for copy protection” sounds just weird enough to potentially be a nonsense answer without context, but I couldn’t confirm that the holes were indeed made with lasers, and not with other means.
- antonvs 8mo agoGood question. I don't know the answer, but I'm quite certain that it didn't really matter what mechanism was used to mark a diskette. Any damage would be equally strong as a way to detect copying.
- anyfoo 8mo agoYeah, it matters only in “interestingness” or “coolness”.
- Someone 8mo agoTheir patent (https://patents.google.com/patent/US4785361A/en https://patents.google.com/patent/US4785361A/en) doesn’t mention a laser, but of course that doesn’t imply it wasn’t a laser. I would guess (more or less) identically damaging multiple floppy disks in the same way would be easier with a laser than with something mechanical (e.g. a knife or a drill) (it is fairly easy to control power and duration of a burn), so it might well have been a laser. On the other hand, disk tracks weren’t exactly tiny at that time in history.
- anyfoo 8mo agoIt could be a tiny drop of something corrosive, but with that I’m also still wondering if a laser isn’t simpler, yeah. I have almost no doubt that it could be a laser, it’s just unfortunate (and maybe a little bit suspicious) that I haven’t found it confirmed anyway. Almost like they wanted it to be a laser (hence the folklore around it), but had to use a less cool method to do it. But of course it might as well just have been a laser, and they for some reason declined to market or even just document it that way, for whatever reason.
- hinkley 8mo agoThere's a lot of things going on that lead to this. One, the developers spend more time running this code than we do, and they have to get the program working before we can even use it. So any parts of the program that are hostile to the developers risks killing the entire project. Obfuscating the copy protection can hit a point where it makes bug fixing difficult. Two, lack of training. If you, me, and Steve each have a bag of tricks we all use to crack games, whichever one of us figures it out gets bragging rights but the game remains cracked. Meanwhile Developer Dan has to be aware of all the tricks in all of our bags together if he wants to keep the three of us out. Only there's not three of us, there's 300. Or today, probably more like 30,000. Three, lack of motivation, which is itself several different situations. There's a certain amount of passive aggression you can put into a feature you don't even really want to work on. You can lean into any of the other explanations to defend why your code didn't protect from cracking all that much, but it's a checkbox that's trying to prove a negative, and nobody is going to give you any credit for getting it to work right in the same way they give you credit for fixing that corner glitch that the QA people keep bitching about. Or getting that particle animation to work that makes the AOE spells look badass.
- m463 8mo agoI remember I had some demo software that could be enabled with a code. I was just curious and at the code prompt, I entered the debugger. I dumped the process space and there was a nul-terminated string of letters and numbers. I restarted the process and entered them at the prompt and voila, it was enabled. (I did go on to pay for the software)
- alfiedotwtf 8mo agoCracking is so fun because we have Slides!
- markh1967 8mo agoMany years ago I was a technician supporting a few custom programs on thousands of PCs. The developer of one of these programs had added a date check to his code so the program would refuse to run after a set date and each new release would increase this date by a few months so it would stop working after a few weeks if he ever stopped creating new releases. His contract ended and a few weeks later his software, now relied upon by hundreds of sites, stopped working. The contract for the software development was thoroughly checked and legal action against the developer was started but I asked to see if I could resolve the problem in the meantime. It only took ten minutes with a dissassembler to find the JGT (Jump if greater than) and convert it to a JLT so the software would stop running if the date was before a certain date rather than after. I created a patching tool that simply flipped one bit that was sent out to all the sites and everything was good again. I don't think I'll ever beat the elegance of a single bit flip hack.
- anymouse123456 8mo agoIf you think it's bad now, the early days of the web were absolutely filled with scumbag grifters who made small fortunes hiring contractors and then refusing to pay. Many of them disappeared in the y2k dot com bust, but then seem to have reappeared in SF after 2008. In the late 1990's, my second ever Flash app development client stiffed me on a $10k invoice. He finally figured out 6 months later that he didn't have the source material to make changes and paid the full invoice in order to get it. So I took precautions with the next client. It was a small agency that was serving a much larger business. We were on 30 days net payment terms and I submitted the invoice when the project was done. They didn't pay and within a couple weeks of gentle reminders, they stopped responding. I smiled. Exactly 30 days from the due date, I got a panicked call shrieking about their largest client website being down and did I have anything to do with it?! I asked them what the hell they were talking about, they don't own a website. They never paid for any websites. I happen to own a website and I would be happy to give them access to it if they want to submit a payment. They started to threaten legal nonsense, and how they had a "no time bombs clause in the contract." I laughed because my contract had no such clause. If they signed such a contract with the client, that's not my problem. I told them I wouldn't release the source files until the check cleared my bank, which could be weeks. A cashier's check arrived that morning and their source files were delivered. By the end of it, the folks at the agency thanked me because that client wasn't planning to pay them and they hired me for other work (which, they had to prepay for). Of course I don't know about the OP, but I'd bet the company was trying to stiff that contractor on their last check.
- ale42 8mo agoI remember an icon editor (or something similar) for Windows 3.1, it was a shareware where you could enter a code to remove the nag screen. No crack was necessary, I basically managed to enter valid registration codes by just typing random numbers. In the end I had enough valid numbers that I could figure out the logic, it was something about the sums of digit groups.
- jasomill 8mo agoThis was true for the 10-digit CD keys Microsoft used for many products in the 90s: the first three digits could be almost anything, and the last seven digits had to sum to a multiple of 7, so, e.g., 111-1111111 was a valid product key (for any product that used the scheme).
- bombcar 8mo agoI think it was StarCraft where we’d just try random keys until it would work, usually only three or four needed.
- anilakar 8mo agoA certain automation system vendor uses proper USB license dongles in their PC software but they do not do challenge-response authentication. Instead they send a hardcoded string to the dongle and compare the response against a list that contains various software feature levels. The whole automation system including machinery costs anywhere from 200k to 1M yet Vendor™ tries to milk the customers dry with a 1.5k software license that lets you manage up to 254 physically* connected systems. I'm pretty sure the license dongle is in reality designed to prevent casual tinkering of parameters, which is something only service techs should do. *You can circumvent this with serial-over-Ethernet converters, which has resulted in an Industrial Internet of Shit-level security nightmare as companies happily expose their systems over the internet, thinking that license dongles are a substitute for authentication.
- jeffwass 8mo agoI was wondering this actually, why not just skip past the check entirely instead of going through the effort to pass the check without the dongle?
- harph 8mo agoBecause sometimes skipping is not enough: https://mrwint.github.io/winter/writeup/writeup.html https://mrwint.github.io/winter/writeup/writeup.html
- miki123211 8mo agoAnother method (much more common for software that asks for two pieces of information, like a name and a key) is to take a memdump of the process at the "your key is invalid" dialog, find the invalid key you just typed, and hope that a valid key is somewhere nearby in memory. Unlike the assembly trick, this requires 0 programming expertise beyond the ability to type `strings` on the command line. This works because some programs use a hashing algorithm to calculate the key based on the name, do a strcmp, and pop a messagebox if the keys don't match, without zeroizing the valid key buffer first. If the key buffers are on the stack (or if the two mallocs just happen to use the same region in memory), it is often easy to find a valid key if you know where the invalid one is. I guess software that derives keys this way is far less common than it once was, but I know of somebody who cracked something using this method just a few years ago, so it still pops up from time to time.
- alias_neo 8mo agoWhen I was a child, in the 90s, I did this all of the time. Input a unique string I could watch for, fire up SoftICE, watch for the string, and then step through until the == comparison happened, then either grab the calculated key and input it, or patch the comparison from == to != or just return true, depending on the implementation.
- SV_BubbleTime 8mo agoSoftICE was such a gift and pain in the ass. I did a massive crack that involved a program and it’s inf/dll hardware driver package. Some of the most rewarding work I’ve done and also just so tedious! Having to stop the OS like that and accidentally getting to the kernel but then not wanting to lose my position so having to hit step over and step out until just the right place… whew.
- burnte 8mo agoYep. I used SoftICE to do a few of these dongle-workarounds. Amazing and terrible software. :D