Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #3  
Old 09-19-2017, 06:54
TempoMat TempoMat is offline
Friend
 
Join Date: Jan 2006
Posts: 89
Rept. Given: 10
Rept. Rcvd 6 Times in 6 Posts
Thanks Given: 4
Thanks Rcvd at 28 Times in 21 Posts
TempoMat Reputation: 6
Quote:
Originally Posted by Kerlingen View Post
It's not RSA, it's ElGamal.
I don't think it is ElGamal.

The Elgamal Encrypt/Decrypt procedures from the FGInt library do not use the 3 padding bits "111" as in the RSA.
Also I have keygened a few applications that use almost the same version of the FGInt library so I could easily identify the decryption routine and confirmed it with a compare.

Furthermore the Elgamal procedures use for conversions "only" the procedure "FGIntToBase256String" whereas the RSA En/Decrypt procedures use "Base2StringToFGInt", FGIntToBase2String, "convertBase256to2"

The program is very old and the original homepage is no more available.
I have therefore attached it here, if you want to try your hands on it.
The main application is compressed with Aspack, so it should not be a problem for a pro like you to unpack it.

By the way it uses BlowFish to save the entered UserName and RegCode in an app_name.fdb file and the RegData are checked on application restart.

My observation is that Kanal plugin in PEID is not able to detect older implementations of the FGIntRSA routines, especially when the RSA values are not in plain ASCII texts.

Using the RE-SIGS v0.18 PUBLIC by dihuxx in IDA to create MAP-file helped to resolve some of the FGIntRSA procedures.

Regards,
TemPoMat
Attached Files
File Type: rar ATMEF.rar (944.5 KB, 14 views)
Reply With Quote
The Following 2 Users Say Thank You to TempoMat For This Useful Post:
tonyweb (09-19-2017), zeuscane (09-19-2017)
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Strange Instruction CTS BE thomasantony General Discussion 2 03-23-2005 04:41


All times are GMT +8. The time now is 10:25.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )