Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-28-2004, 01:45
Seyedof
 
Posts: n/a
I've tried to crack some SF protected cdrom from a company called Emme productions but i failed I guess many new protection products like SF and CDCOPS3 use the DPM (Data Position Measurement) method which is physically impossible to crack but one may attack the software driver/ lock checking code. Anyone has played with this? I'm also interested in how these DPM kind of locks work (Alcohol 120% can measure and make images of theses protected cdroms).
Reply With Quote
  #2  
Old 08-28-2004, 04:04
dyn!o's Avatar
dyn!o dyn!o is offline
Friend
 
Join Date: Nov 2003
Location: Own mind
Posts: 214
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 8
Thanks Rcvd at 0 Times in 0 Posts
dyn!o Reputation: 1
Doug: Well... I have to negotiate . First of all you are right about SafeDisc, but... this thread discuss StarForce malfunctions. Besides, as far as I know, SafeDisc is the most compatible CD protection on the market.

"All CD copy protections install device drivers now - none of them warn the user about it."

I would rather say: almost all CD protections use device drivers nowadays (for instance: look at hxxp://www.softlock.net - they don't use device drivers, also there are two other which don't use) - none of them warn the user about it - that's right.

Seyedorf: DPM? I am not in any way CD protection specialist but I thought it was emulated already... like twin sectors did. Please attach some more informations if you can.


Regards.
Reply With Quote
  #3  
Old 08-28-2004, 16:08
Seyedof
 
Posts: n/a
Yes, it is emulated , like Alocohol 120% can make images of such cds and mount them on a virtual cdrom and emulate the DPM so the lock checking is fooled as it is the original cd, but this is only an image file, you can not duplicate the locked cd this way. Any attempt to copy these kind of protected cds will cause the physically change in DPM so the copies won't simply pass the lock check. I have not seen also anyone cracked the lock checking routines, this can give us a generic patch for the lock.

still waiting...
Reply With Quote
  #4  
Old 08-28-2004, 16:38
dyn!o's Avatar
dyn!o dyn!o is offline
Friend
 
Join Date: Nov 2003
Location: Own mind
Posts: 214
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 8
Thanks Rcvd at 0 Times in 0 Posts
dyn!o Reputation: 1
Ahh... that's right but who cares about physical CD? It's not about physical copy but rather cracking the protection in general - no matter what way. The game protected by a CD check only always carry the highest risk - much higher than other software protections because it can be attacked from both sides: CD cloning and/or executable cracking.

The last solution, not implemented yet, is to calculate CD access and sectors read speed timings. At the moment it will fool all virtual drives but if someone will implement such a protection then very quickly Aclohol/CloneCD/DaemonTools will contain anti-timing features... and so on... and so on...

The question is if someone will invent a stable CD protection technology which force cracker to break each title manually (like Armadillo and ACProtect do). Then, in some countries, games piracy rate would be lowered - noticeably lowered.

Regards.

Last edited by dyn!o; 08-28-2004 at 16:53.
Reply With Quote
  #5  
Old 08-28-2004, 18:00
taos's Avatar
taos taos is offline
The Art Of Silence
 
Join Date: Aug 2004
Location: In front of my screen
Posts: 580
Rept. Given: 65
Rept. Rcvd 54 Times in 19 Posts
Thanks Given: 69
Thanks Rcvd at 137 Times in 36 Posts
taos Reputation: 54
Perhaps the solution could be that Armadillo uses a CD API protection like Krypton 0.5 but with a strong EXE packed with nanomites...
Reply With Quote
  #6  
Old 09-03-2004, 17:41
peleon peleon is offline
Friend
 
Join Date: Sep 2003
Posts: 174
Rept. Given: 0
Rept. Rcvd 7 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
peleon Reputation: 7
Hi Fellas,

Very good those links dynio Didnt know that starforce was going down but the opposite. I agree that drivers are a bad to make protection...though it's true they are harder to crack. So, it's a bit of compromise.

I tried SF3 long time ago but not success. Does anyone know if there are tutorials or papers explaining about this protection and how to break it? I know that russian guys have tried a lot with SF3 but dont know if they broke it.

Regards.
Reply With Quote
  #7  
Old 09-03-2004, 19:39
taos's Avatar
taos taos is offline
The Art Of Silence
 
Join Date: Aug 2004
Location: In front of my screen
Posts: 580
Rept. Given: 65
Rept. Rcvd 54 Times in 19 Posts
Thanks Given: 69
Thanks Rcvd at 137 Times in 36 Posts
taos Reputation: 54
I don't understand why device drivers are very hard to break...

I think that it's very hard to unpack "some" device drivers.Only that.

For example:

Any device driver (NT) is a SYS file. If you have the SYS file unpacked, then you can reverse (using IDA or other) when you reboot your SO in safe mode.
You can modify all the protection in the sys file (debugger detection, CRC,etc...). When you disable debugger detection, you can use your ring 0 debug. I know it's a hard job but I think it's not very very hard.

Regards
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
SecuROM & StarForce hepL3r General Discussion 11 02-21-2011 00:42
starforce - again... etienne General Discussion 13 02-26-2007 18:16


All times are GMT +8. The time now is 20:42.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )