![]() |
|
#16
|
|||
|
|||
|
Quote:
Keys1-4 and vendor name are used to derived an original plain key in which stores the keys expired date, supported functions enabled, supported hw-dongles types, and the keys1-4 integrity checksum. crokeys1-2(trlkeys1-2) are only used for enabling TRL options and the integrity checksum of itself. It has nothing to do with the SIGNx generation. |
|
#17
|
|
to get ES1 ES2 VK5 is really easy, you dont need any tools, just locate the l_sg() function where the seeds are uncovered
Code:
00417043 |. 8D8D 80FDFFFF LEA ECX,DWORD PTR SS:[EBP-280] 00417049 |. 51 PUSH ECX ; /Arg3 0041704A |. 8B95 6CFDFFFF MOV EDX,DWORD PTR SS:[EBP-294] ; | 00417050 |. 81C2 0C030000 ADD EDX,30C ; | 00417056 |. 52 PUSH EDX ; |Arg2 00417057 |. 8B85 6CFDFFFF MOV EAX,DWORD PTR SS:[EBP-294] ; | 0041705D |. 50 PUSH EAX ; |Arg1 0041705E |. E8 27040100 CALL thinkflx.0042748A ; <-- Call l_sg() \thinkflx.0042748A 00417063 |. 83C4 0C ADD ESP,0C 00417066 |. 81BD 84FDFFFF >CMP DWORD PTR SS:[EBP-27C],87654321 00417070 |. 74 0C JE SHORT thinkflx.0041707E 00417072 |. 81BD 88FDFFFF >CMP DWORD PTR SS:[EBP-278],12345678 |
|
#18
|
|
|
Quote:
Code:
00417043 |. 8D8D 80FDFFFF LEA ECX,DWORD PTR SS:[EBP-280] 00417049 |. 51 PUSH ECX 0041704A |. 8B95 6CFDFFFF MOV EDX,DWORD PTR SS:[EBP-294] 00417050 |. 81C2 0C030000 ADD EDX,30C 00417056 |. 52 PUSH EDX 00417057 |. 8B85 6CFDFFFF MOV EAX,DWORD PTR SS:[EBP-294] 0041705D |. 50 PUSH EAX 0041705E |. E8 27040100 CALL xxx.0042748A 00417063 |. 83C4 0C ADD ESP,0C 00417066 |. 81BD 84FDFFFF >CMP DWORD PTR SS:[EBP-27C],87654321 00417070 |. 74 0C JE SHORT xxx.0041707E 00417072 |. 81BD 88FDFFFF >CMP DWORD PTR SS:[EBP-278],12345678 inside 0042748A ... 00427563 |. 3355 F4 XOR EDX,DWORD PTR SS:[EBP-C] 00427566 |. 3355 E0 XOR EDX,DWORD PTR SS:[EBP-20] 00427569 |. 3355 E4 XOR EDX,DWORD PTR SS:[EBP-1C] 0042756C |. 8B4D 10 MOV ECX,DWORD PTR SS:[EBP+10] 0042756F |. 8B41 04 MOV EAX,DWORD PTR DS:[ECX+4] 00427572 |. 33C2 XOR EAX,EDX -> ES1 xored by VK5 = real ES1 ... 00427596 |. 334D F4 XOR ECX,DWORD PTR SS:[EBP-C] 00427599 |. 334D E0 XOR ECX,DWORD PTR SS:[EBP-20] 0042759C |. 334D E4 XOR ECX,DWORD PTR SS:[EBP-1C] 0042759F |. 8B45 10 MOV EAX,DWORD PTR SS:[EBP+10] 004275A2 |. 8B50 08 MOV EDX,DWORD PTR DS:[EAX+8] 004275A5 |. 33D1 XOR EDX,ECX -> ES2 xored by VK5 = real ES2 |
![]() |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| SDK 11.x How to find Vendor_Name and Vendor_Key5 in application !! | Gede | General Discussion | 25 | 09-02-2023 17:28 |
| Flexlm 7.2 LIC file use on Flexlm 9.2 display error -73 ? | hanzi | General Discussion | 9 | 07-05-2006 18:51 |