downloadbrowseIamLupo's Crack Me 2

Download Crack_Me_2.zip, 7 kb (password: crackmes.de)
Browse contents of Crack_Me_2.zip

This is a challange that needs to find a password. This can be solved very easy. Good luck! ^_^

Difficulty: 1 - Very easy, for newbies
Platform: Windows
Language: C/C++

Published: 13. Nov, 2014
Downloads: 1487

Rating

No votes yet.
Rate this crackme:

Send a message to IamLupo »

View profile of IamLupo »

Solutions

Solution by acruel, published 23. sep, 2015; download (2 kb), password: crackmes.de or browse.

acruel has not rated this crackme yet.

Submit your solution »

Discussion and comments

basscode
04. Apr 2014
I don't even get the option to input the password.
IamLupo
Author
04. Apr 2014
@basscode: thats right:P you need to understand whats happening :P

Hint: With debugging you can inject your password :D

Good luck!
new_man
09. Apr 2014
hahah i just change the JZ in 21D1 and got the "ya you should ...." but i know it's stupid but i tired so i dont go over all that FILE0 file (i maybe do that later)
new_man
09. Apr 2014
and another thing. i am not so familer with ntfs structure but when i start to look what your code do it's look like he go over every MFT in NTFS. now i try to locate which file he is looking for (i just BP on LODS of the path string and see when it's join to stop. belive or not i found out about files i never know they exsit)
IamLupo
Author
09. Apr 2014
Nice you look at the NTFS code. But don't you think you focus on the wrong part?XD maybe focus on the algorithm to check the password?XD
oozyluce
12. Jun 2014
What is this crack looking for in C:\Windows\System32\config ?

I'm still a noob and i find this crackme extremely challenging. It's been more than a day that i'm trying to solve it but i cant seem to grasp my hands on the utmost important part.

I also notice that you call alot of Microsoft APIS to read files or set file pointers... Should the password be inserted in one of those files in order to "inject" the password in the program?
otto
06. Jul 2014
I'm a beginner and this is not easy at all.
The program seems to read data from the registry but i'm not sure.
Maybe the way to "inject" the password is to modify the registry but again not easy.
IamLupo
Author
19. Jul 2014
There is no need to know where you must input the password ;) you just can inject the password in the memory with a debugger ;)
Just find the assebly code where he checks the password and find the adress. Then you can inject your password ;)
puelo
10. Aug 2014
Crashes for me: Windows 7 x64. No debugger attached.
IamLupo
Author
23. Aug 2014
@puelo: Maybe disable virusscanner?
KingMidas
27. Oct 2014
Hey Lupo,

First off, thanks for the crackme! It's thaught me a lot so far.
I've got the password, and as soon as I find out where that blasted [esi] is coming from i'll have the hFile as well.
Get ready to have that beer with me!

Slt,
Midas
IamLupo
Author
27. Oct 2014
@KingMidas: Nice you had fun ^_^

PS: Beer? Where!:D
KingMidas
27. Oct 2014
Hey Lupo,
Since the GoodBoy's in French, I'm guessing somewhere near the French-Belgian border? ^^
RagingGrim
31. Mar 2015
Edited The First Part Of The Assembly In The Module CrackMe to JMP Crack_Me.00D8223C.

Was fun!
Although I have no idea how to find the password XC
R4v3N-THS
01. Apr 2015
I solved it but that file was a little suspicious. Requires admin privs and it closes out really fast. Just sayin...
horntooter
03. Apr 2015
A couple of things. This has a major virus-y vibe to it. Also, I would suggest definitely supply a way to input the password in the future. If you just inject it, then you might as well set eip=the finish. Done. Also, this is probably higher than a 1 skill-level because of all the virus-y stuff it's doing.
Herz3h
11. May 2015
Im stuck on the part of sam file...cant find ressource on this file :/

You may leave your comment, thoughts and discuss this crackme with other reversers here.
Acting childish will not be tolerated.
HTML and such will be left as-is, so don't try.