Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 09-16-2022, 17:56
foosaa foosaa is offline
Friend
 
Join Date: Dec 2005
Posts: 112
Rept. Given: 36
Rept. Rcvd 14 Times in 11 Posts
Thanks Given: 179
Thanks Rcvd at 93 Times in 34 Posts
foosaa Reputation: 14
Quote:
Originally Posted by TmC View Post
There is no problem with patching the program. (inlining rather than patching, since it is part of a suite that has also a hardware part and the hardware is checking for program integrity at startup).

Unfortunately, the serial is checked also when requesting updates through the update routine, and even patching the program wont pass the server check.

The serial is passed in cleartext so a patch that simply gives one random hash to check does not work.
Yup. Thought so. Would you mind sharing the program name in a PM? Thanks.
Reply With Quote
  #2  
Old 09-16-2022, 17:23
aijundi aijundi is offline
Friend
 
Join Date: Jul 2019
Posts: 36
Rept. Given: 1
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 2
Thanks Rcvd at 30 Times in 16 Posts
aijundi Reputation: 0
Perhaps you can check this and do something similar
Reply With Quote
  #3  
Old 09-17-2022, 21:38
chants chants is offline
VIP
 
Join Date: Jul 2016
Posts: 826
Rept. Given: 47
Rept. Rcvd 50 Times in 31 Posts
Thanks Given: 737
Thanks Rcvd at 1,140 Times in 529 Posts
chants Reputation: 51
So it looks like you want to do a first pre image attack on MD5.

Wait a second if they are chaining, that opens up a whole new set of opportunities. Why not look into length extension attack and such. You need to explain what is meant by "chaining" in mathematical detail e.g. h(h(bytes[12:16])^bytes[8:12]) where ^ is xor or even concatenation.

The time it takes to handle a group of 4 !!!! Should then based on that list for the final combos be the time per final pair to get the next to last combo etc.

If you want to pass remote validation checks, it may still be impossible as they may further reduced the allowable set or notice unusual activity ertc, no guarantees.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 21:08.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )