downloadbrowselord_Phoenix's CrackMe#4

Download crackme4.zip, 59 kb (password: crackmes.de)
Browse contents of crackme4.zip

Another crackme by myself =)
It's no hard!! And it's stageable, so even newbiez can crack some piece of it.

Pay attention plz ;)

Difficulty: 4 - Needs special knowledge
Platform: Windows
Language: Borland Delphi

Published: 20. Nov, 2005
Downloads: 6871

Rating

Votes: 4
Crackme is quite bad.

Rate this crackme:

Send a message to lord_Phoenix »

View profile of lord_Phoenix »

Solutions

There are no solutions to this crackme yet. Have you solved it? Please write a tutorial and submit it here!

Submit your solution »

Discussion and comments

lord_Phoenix
Author
13. Nov 2005
Try this one plz..
Not so hard as #1, #2, #3 =]
konstAnt
15. Nov 2005
Neither packed with UPX nor with FSG... The crackme should be rejected...
lord_Phoenix
Author
15. Nov 2005
:(
but it's packed with upx
lord_Phoenix
Author
15. Nov 2005
don't trust to analyzers, it's really easy to fool them
trust only ur eyes ;)
Knight
15. Nov 2005
If UPX can't unpack it, that doesn't meens that there aren't upx ;)

Regards,
Knight
TDC[NL]
15. Nov 2005
hehe, that'll need a MUP :)
lord_Phoenix
Author
17. Nov 2005
u can say it's hard?!
-xCr-
17. Nov 2005
I had been unpacked this crackme with Quick Unpack, it can unpack almost all types of packages.
lord_Phoenix
Author
17. Nov 2005
now try to crack it :]
konstAnt
18. Nov 2005
Who says it can be unpacked it isn't being unpacked in mine and PEid says it somewhat other packing when I do hardcore check...
ultrasound
18. Nov 2005
this prog unpacked easily for me using PEiD generic unpacker..
lord_Phoenix
Author
18. Nov 2005
it's not unpackme - it's only crackme =)
-xCr-
18. Nov 2005
I found that it finds Olly by windowname, then runs some procedures, but then as I think tests if there is dbghelp.dll
lord_Phoenix
Author
18. Nov 2005
yeh, there's some antidebug, small stub ;)
MaxM
19. Nov 2005
Well, you can unpack it 'manually' in a second, anyway. Take any tute for UPX, or just scroll at end the stub code with the wheel...
lord_Phoenix
Author
20. Nov 2005
RESUBMITTED FIXED VERSION!
If u really want to crack it - dwonload fixed plz :]
(Tnx to renno)
-xCr-
21. Nov 2005
It's not so hard to overcome protection:
CALL ESI = XOR EAX,EAX
String like %s%s%S = aaaaaa
String OllyDbg.exe = somethk.exe
String IsDebuggerPresent = IsProtectionThere
And that's all. After that the file is simple debugged in IDA.
lord_Phoenix
Author
21. Nov 2005
it's not main protection =)
i can't even call this stuff antidebug ;P
ultrasound
21. Nov 2005
what exactly did you change in this new version? i got as far as finding my 1st serial with the old version, but to get there i had to remove all that debug protection.. I really dont want to have to do that again!

and i dont want to lose all my IDA commenting and renaming!
lord_Phoenix
Author
23. Nov 2005
i fixed some bugs in serial2 and that's all =)
lord_Phoenix
Author
07. Dec 2005
need hints?! ;]
pm or just mail me..
Yosh64
16. Dec 2005
i'm up to "<normal code>"... and your anti-debugger tricks never fooled me :P (have not been bothered to dump/unpack)... my OllyDbg is protected from those nasty debugger strings ;), done that back in the day of trying to unpack armadillo 4.x, hehe :) <- hmm, for now I gotta work out why <normal code> likes to crash, ive got some ideas why :P
Yosh64
16. Dec 2005
lol, I see why... :P
Yosh64
16. Dec 2005
hehe, got "<normal code>" all figured out... it's darn cool :) umm... maybe i should stop posting, this is my third post in a row :\
lord_Phoenix
Author
16. Dec 2005
Yosh64 ::
but it's any antidebug here ;P
did u get a normal code? cool =) now try to get the next one and plz pm me ur serialz..
lord_Phoenix
Author
19. Dec 2005
and no answer as always =(
HMX0101
28. Jan 2006
This crackme is a cool one,
i can sniff the two newbiez code,
a question:

when i put the in the normal code,
the newbie code 2 + '-' + integer part of the newbie code 1, the crackme crashes, why occur this, i'm near of sniff the normal code?
Kerberos
28. Jan 2006
Look on the code after loading normal code ... you need to choose "Normal code" very carefully, or this CrackMe will crash you everytime.
Yosh64
03. Feb 2006
I forgot about this CrackMe, well been awhile since I last looked, but I'm back after receiving an email. But yea I never figured out a good Normal Code :\ BUT I know exactly how it works, still trying to figure how to find where the Normal Code should point you ;)
KLiZMA
03. Feb 2006
1st, 2nd and 3rd stages solved! I'm trying to solve next!
Phanx for the interest crackme!
HMX0101
17. Jun 2006
@lord_phoenix:
please, tell some hints to get a serial in the 3rd stage...
lord_Phoenix
Author
17. Jun 2006
hmm... u must use 3rd stage to get to check of 4th stage ;)

cheerz..

You may leave your comment, thoughts and discuss this crackme with other reversers here.
Acting childish will not be tolerated.
HTML and such will be left as-is, so don't try.