Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   FlexLM Help (https://forum.exetools.com/showthread.php?t=4509)

toro 09-12-2004 03:27

hi szy111

the function at address 424410 is l_getattr, the address of signed32 is 4422cf. it must be call from l_string_key.

toro

szy111 09-12-2004 16:09

hi toro:
thank you again . but in middle of every l_string_key , i can not find 4422cf , why ? only 2 call 424410 !!!

szy111 09-14-2004 17:47

hi toro:
please hlep me !!
i do not know why the address of signed32 is 4422cf ? can you give me detailed information ? thank you .

nikkov 09-14-2004 18:38

Anybody used lmcryptgui from Crackz tutorial page?
I create generator, but it dont't work and terminate with exception :(

toro 09-14-2004 21:47

hi szy111

at least can you see the correct sign that created in end of l_string key for every feature?

toro.

szy111 09-15-2004 13:51

hi toro:
i set breakpoint at 41a1f5 in olly (F2). then F7 ,but it stop at next point !!! how to trace ? please tell me step by step . i begin to use olly .

szy111 09-15-2004 21:43

Quote:

Originally Posted by nikkov
Anybody used lmcryptgui from Crackz tutorial page?
I create generator, but it dont't work and terminate with exception :(

give me the seed and license.dat , l make it for you !!!!

toro 09-15-2004 21:51

Quote:

i set breakpoint at 41a1f5 in olly (F2). then F7 ,but it stop at next point !!! how to trace ? please tell me step by step . i begin to use olly .

there are many tut on internet

toro

nikkov 09-16-2004 11:00

Quote:

Originally Posted by szy111
give me the seed and license.dat , l make it for you !!!!

I haven't seed while, but I search it for autodesk inventor 8
(FlexLm 8.3a).
I haven't SDK for this version, so I want use lmcryptgui, if is it possible.
And another question: can I use SDK not 8.3a version and what changes need made for it.
---------------------------------------------------
AAAAA!!! I am stupid man :(.
I run lmcryptgui without parameter!!!
Now it work, but lmcryptgui can generate license for FlexLm 8.3a ?

Thanks.

szy111 09-16-2004 15:06

run lmcryptgui with seeds and vendor ,then create a exe file ,run exe with license.dat , you will be well .but you must need seeds !!

nikkov 09-16-2004 16:59

Quote:

Originally Posted by szy111
run lmcryptgui with seeds and vendor ,then create a exe file ,run exe with license.dat , you will be well .but you must need seeds !!

O.K. I found seed, vendor and successfully made working license
for autodesk inventor 8. It's easier that crack C-Dilla :)

Thank you for advise.

appleleafs 10-15-2004 05:30

Acutually, the call to signed32 will depend on the behavior of the Flexlm. For example, if the crypt filter is used, the code will skip the call to signed32. They have improved the security in a way, and does not provide compatibility in this special case.
On the other hand, it is a better idea to recover the seed from the job structure, which envolves identify the call to l_sg and record the memory contents. There has been essay's and calc tools to make this very easy. Most important is all the behavior can be defeated in this way. Of course, we are not talking about the ECC.
If you have identified the l_string_key code, you will be able to found the license key information by just looking at the return point of this function. There will be a call to atox, which convert and format the license key in ASCII format, just check the return value in EAX, do a reference to the memory, and dump the key. It is automatically generated for you. There is a easy signature of the atox function, there is a long string 0123456789ABCDEF defined there. Do a search on the code, you will find it easily. Then you can trace back to the point for the key generation. There is no need to recovery seeds, no need to run license generation.

Peter[Pan] 11-01-2004 03:39

Guys thanks for the info, iam back to viewing flexlm apps, i did manage to solve my license problem and thanks :) iam now using the method for l_sg, at all my targets, however i found one target it doenst work for! maybe i maked a mistake, maybe not, anybody can view and see ?

i view the app:
*removed by request*

I got the following information:
Seed1: 38aa43fa
Seed2: 95845bd5
Vendor: Pxxxx

however, putting these into lmcryptgui, and resigning the license file, still results in -8 (Bad Auth)

Any ideas ?

Thanks.

dirkmill 11-01-2004 04:53

@Peter[Pan]:
I just had a quick look at your target and it seems that your seeds are wrong!

I found this:
encseed[0]=6bxxxx58
encseed[1]=9cxxxx2e

You might want to recheck the byte-order of your calcseed-inputs ;)

Dirk

Peter[Pan] 11-01-2004 05:46

gona view straight away! thnx :)

*edit*, yea it guess i was using Jobx04 ++, isnted of Jobx08++

anways i recorded the job, data and vendor name before, and after the call to n36buff

Code:

[BEFORE]
VENDOR: ASCII "Pxxxx"
Name: DATA                              JOB
0x00: 66 00 00 00                      04 00 00 00
0x04: 00 00 00 00                      15 BB F2 4E
0x08: 00 00 00 00                      63 4C 08 B9
0x0C: 00 00 00 00                      C0 D9 02 38
0x10: 00 00 00 00                      E5 B6 0F 2F
0x14: 00 00 00 00                      EA 9B 6F 06
0x18: 00 00 00 00                      B0 7E 2A 4C
0x1C: 00 00 00 00                      09 00 02 00

[AFTER]
VENDOR: ASCII "Pxxxx"
Name: DATA                              JOB
0x00: 66 00 00 00                      04 00 00 00
0x04: 91 00 29 00                      74 35 99 6B
0x08: 3F 99 86 2C                      02 C2 63 9C
0x0C: 5E 3D 1C 00                      C0 D9 02 38
0x10: 00 00 73 00                      E5 B6 0F 2F
0x14: 00 00 00 00                      EA 9B 6F 06
0x18: 00 00 00 00                      B0 7E 2A 4C
0x1C: 00 00 00 00                      09 00 02 00

gives me:
data[0]: 00290091
data[1]: 2C86993F
Vendor: Pxxxx
job+0x08: 0x9C63C202
job+0x0c: 0x3802D9C0
job+0x10: 0x2F0FB6E5
XOR VAL: 0x2fc0d99c
Enc1: 0x2fe9d90d
Enc2: 0x034640a3

still doesnt match yours, maybe iam going wrong somewhere... :/

p.s thanks for the help its really appreciated :)


All times are GMT +8. The time now is 15:36.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX