·¢ÐÅÈË: Reinhard.bbs@bbs.sjtu.edu.cn (ÕªÐǵÄÈË), ÐÅÇø: cnhacker
±ê Ìâ: Ñ°ÕÒ×¢²áÂëµÄ·½·¨ -- life ÕûÀí(ת¼Ä)
·¢ÐÅÕ¾: Òûˮ˼Դվ (Fri Apr 25 20:24:42 1997)
תÐÅÕ¾: Lilac!ustcnews!ustcnews!sjtunews!sjtubbs
³ö ´¦: bbs.sjtu.edu.cn
·¢ÐÅÈË: Alex (°¢·É), ÐÅÇø: Hacker
±ê Ìâ: Ñ°ÕÒ×¢²áÂëµÄ·½·¨ [תÌù] weit Öø
ÈÕ ÆÚ: Tue Mar 5 16:44:34 1996
·¢ÐÅÈË: weit@ncicbbs (˶Êó), ÐÅÇø: crack
±ê Ìâ: ¡ò Follow me
·¢ÐÅÕ¾: ¹ú¼ÒÖÇÄÜ»úÖÐÐÄÊï¹âÕ¾ (Mon Mar 4 13:18:58 1996)
תÐÅÕ¾: ncicbbs (local)
Ä¿µÄ£ºÈôó¼ÒÁ˽âÑ°ÕÒ×¢²áÂëµÄ·½·¨
¶ÔÏó£ºWINSMTP V1.07 BETA1.8.S
(Óëtrumpet2.1f¼æÈÝ£¬ÓÉxbÌṩ£¬ÒÑ·ÅÈëÊï¹âÕ¾ftp:/imcoming/winsmtp.exe)
²½Ö裺
1.°²×°winsmtp. (ºÇºÇ£¬µ±È»à¶)
2.½øÈëRegister User¶Ô»°¿ò¡£(·Ï»°)
3.ÔÚRegister KeyÖÐÌîÈë 1234512345 (ÕâÊÇÎÒµÄÏ°¹ß)
4.°´Ctrl-D¼¤»îwinice (ʲôÄãûװSoft-ice for Win? ÄǽâʲôÃÜ? ¿ìÈ¥×°)
5.ÊäÈëhwnd (ʲôÒâ˼£¿¼ûcracking in winÒ»ÎÄ)
winiceÏÔʾ: (µ±È»ÓÐЩСµØ·½¿ÉÄܲ»Ò»Ñù)
-Window-Handle------hQueue------QOwner------ClassName-----Windows-procedure-
110C(0) 1AFF WINSMTP #32769 ....
.
.
.£
2950(1) 1AFF WINSMTP #32770 ....
28C0(2) 1AFF WINSMTP Static ....
29B0(2) 1AFF WINSMTP Edit ....
.
.
.
6.°´EscÖжÏÏÔʾ (Ä㵱ȻҲ¿ÉÒÔ°ÑËûÃÇÈ«²¿¿´Í꣬Èç¹ûÓÐÐËȤµÄ»°)
7.ÊäÈëbmsg 29b0 wm_gettext (¾ÍÊÇÉÏÃæµÄ29B0(2)ÀïµÄ29b0),ÉèÁ¢¶Ïµã0¡£
8.°´F5»Øµ½³ÌÐò¡£(ºÃÏ·ÔÚºóÍ·)
9.µãOk°´Å¥¡£
Õâʱ£¬ÓÉÓڶϵãÆðÁË×÷Óã¬ÖØе½ÁËwinice.µ«ÊÇ´Ëʱ»ðºòδµ½...
10.ÔÙ°´3ÏÂF5¡£(±ð¶à°´»òÉÙ°´)
11.½ÓÏÂÀ´£¬°´F10 (P¹¦ÄÜ) Ö´ÐгÌÐò£¬¿ÉÒÔ¿´¼ûwiniceÆÁÄ»ÉÏ×îÏÂÃæÄÇÌõÂÌÏßÉϵÄ
±êÌâ´ÓCTL3D±äµ½USER£¬Óֱ䵽WINSMTP¡£Ò»»Øµ½WINSMTPÁ¢¼´Í£ÊÖ£¡
12.ÊäÈës ds:0 l ffffffff "1234512345"
»ØÓ¦Èç£
Pattern Found at 1B37:00008320
13.¼üÈëbpm 1b37:8320 ½¨Á¢ÁíÒ»¸ö¶Ïµã¡£
14.ÔÙ°´F5
At last...
µ±³ÌÐòÔٴα»ÖжϺ󣬴úÂë¿òÏÔʾÈ磺
MOV AL,[SI]
XOR AH, AH
MOV DL,ES:[DI]
XOR DH,DH
.
.
.
´Ëʱ£¬ÄãÖ»ÐèÊäÈëdb es:di
ÔÚwiniceÊý¾Ý¿òÀï¾Í»á³öÏÖÄãÃÎÃÂÒÔÇóµÄ×¢²áÂ룡
ÏóÎÒµÄÊÇ: n5o16X3LEIVPxTz9p4s-Ee9p (Õâô³¤£¡»¹·Ö´óСд£¡±ð³´íÁË)
(ÓÉÓÚ×¢²áÂëÓë»úÆ÷IPÓйأ¬ÄãÖ»ÄÜ×Ô¼ºÕÕ¹Ë×Ô¼ºÁË,±ð͵ÀÁÓ´ ^_^ )
15.Éƺó¡£(ÓÃbc 0Óëbc 1Çå¶Ïµã...)
16.×¢²á°É£¡(°¥£¬ÐÂÈËÈ붴·¿£¬Ã½ÈËÌß³öǽ£¬¿É±ðÍüÁËÎÒѽ)
ºó¼Ç£º
ÕâÊÇÒ»¸öµäÐ͵ÄÑ°ÕÒ×¢²áÂëµÄ¹ý³Ì£¬´ÏÃ÷ÈçÄ㣬¶¨ÄܾÙÒ»·´Èý¡£
ҲϣÍû´ó¼ÒÌá³ö¸Ä½øÒâ¼û£¡
--
7m0m©³©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©·
©§ 2m ССף¸£ ££ ¸øÇ×°®µÄÄã 7m °¢·É ( Alex ) ©§
©»©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¿
7;40m0m
·¢ÐÅÈË: Alex (°¢·É), ÐÅÇø: Hacker
±ê Ìâ: Re: Ñ°ÕÒ×¢²áÂëµÄ·½·¨ [תÌù] weit Öø
ÈÕ ÆÚ: Tue Mar 5 16:54:47 1996
==> Alex (°¢·É) Ìáµ½:
> ·¢ÐÅÈË: weit@ncicbbs (˶Êó), ÐÅÇø: crack
> Ä¿µÄ£ºÈôó¼ÒÁ˽âÑ°ÕÒ×¢²áÂëµÄ·½·¨
> .
> .
> 6.°´EscÖжÏÏÔʾ (Ä㵱ȻҲ¿ÉÒÔ°ÑËûÃÇÈ«²¿¿´Í꣬Èç¹ûÓÐÐËȤµÄ»°)
> 7.ÊäÈëbmsg 29b0 wm_gettext (¾ÍÊÇÉÏÃæµÄ29B0(2)ÀïµÄ29b0),ÉèÁ¢¶Ïµã0¡£
> 8.°´F5»Øµ½³ÌÐò¡£(ºÃÏ·ÔÚºóÍ·)
> 9.µãOk°´Å¥¡£
> Õâʱ£¬ÓÉÓڶϵãÆðÁË×÷Óã¬ÖØе½ÁËwinice.µ«ÊÇ´Ëʱ»ðºòδµ½...
ÕâÇ°Ã棬ÎÒÏ°¹ßÊÇÔÚ×¢²áÇ°½øÈëwinice
È»ºóbpx getDlgItemText ¾Í¿ÉÒÔ£¬È»ºó»ØÀ´
¿ªÊ¼×¢²á£¬µ½°´ÏÂ×¢²á¼üµÄʱºò£¬Èí¼þ¾Í»áÈ¥µ÷getdlgitemtext¶ÁÄãµÄ×¢²áÂë
¾Í»á½øÈësoft ice, ÔÀíºÍweit˵µÄ²î²»¶à£¬Ò»¸öÊÇÏûÏ¢Çý¶¯£¬Ò»¸öÊǺ¯Êý
ÏÂÃæ¾ÍÒ»ÑùÁË
> 10.ÔÙ°´3ÏÂF5¡£(±ð¶à°´»òÉÙ°´)
> 11.½ÓÏÂÀ´£¬°´F10 (P¹¦ÄÜ) Ö´ÐгÌÐò£¬¿ÉÒÔ¿´¼ûwiniceÆÁÄ»ÉÏ×îÏÂÃæÄÇÌõÂÌÏßÉϵÄ
> ±êÌâ´ÓCTL3D±äµ½USER£¬Óֱ䵽WINSMTP¡£Ò»»Øµ½WINSMTPÁ¢¼´Í£ÊÖ£¡
> 12.ÊäÈës ds:0 l ffffffff "1234512345"
--
7m0m©³©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©·
©§ 2m ССף¸£ ££ ¸øÇ×°®µÄÄã 7m °¢·É ( Alex ) ©§
©»©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¥©¿
7;40m0m
·¢ÐÅÈË: WeiT (˶Êó), ÐÅÇø: Hacker
±ê Ìâ: Re: Ñ°ÕÒ×¢²áÂëµÄ·½·¨ [תÌù] weit Öø
ÈÕ ÆÚ: Wed Mar 6 11:31:57 1996
==> Alex (°¢·É) Ìáµ½:
> ==> WeiT (˶Êó) Ìáµ½:
> > °¢·ÉÔõô²»Ð´Ò»Ð©ÄØ£¿
> ÎÒ²»ÐÐÀ²£¬¾Í¸ÕÈëÃŵÄˮƽ£¬
> ÎÒ»¹ÏëÇë½ÌÄã½âÃܵÄʱºò¿ÉÒÔÓà Back TraceÂð£¿
> ÎÒ·´¸´¿´help, ¶¼²»ÐУ¬ÓÃshowµÄÀÏÊÇ˵buffer empty, Ī·Ç·ÇÒªÊÇÔ´³ÌÐòdebug?
ºÃÏóÊÇÒªÏÈÉ趨bpr£¬Ö»ÓÐÔÚbpr·¶Î§ÀïµÄÖ¸Áî²Å¿Éback trace. ÒÔ·ÀÔÚ±ÈÈçÏóBIOS
µÄ³ÌÐòÀï ÂÒת¡£
> ÎÒ¾õµÃ±¾°æµÄ120ƪÎÄÕÂдµÄ¼«ºÃ£¡Ð´³öÁ˾«Ë裬weitµÄÎÄÕÂÒ²ÊÇ
^^^^^--²»ºÃÒâ˼£¬Ò»Ö±Ã»×¢Ò⣬ÏÖÔÚ¿´ÁË£¬µÄÈ·ºÜ°ô£¬
°¥£¬Ôç¿´Á˾ÍÉÙ×ßÍä·ÁË
BTW, ÔõôsiceµÄaÀï ²»Ö§³Ö jmp short ?
ÎÒÊÔÁËjmp short ºÍ jmp short ptr ¶¼²»ÐУ¬
Ö»ºÃ×Ô¼ºÐ´»úÆ÷Âë: EB .. ,Ì«Âé·³ÁË:(
--
%@@,
~~~~~~~~~~~~~~~~~~
ÏòÍùÀÖÍÁµÄ˶Êó
·¢ÐÅÈË: WeiT (˶Êó), ÐÅÇø: Hacker
±ê Ìâ: Re: Ñ°ÕÒ×¢²áÂëµÄ·½·¨ [תÌù] weit Öø
ÈÕ ÆÚ: Wed Mar 6 11:31:57 1996
==> Alex (°¢·É) Ìáµ½:
> ==> WeiT (˶Êó) Ìáµ½:
> > °¢·ÉÔõô²»Ð´Ò»Ð©ÄØ£¿
> ÎÒ²»ÐÐÀ²£¬¾Í¸ÕÈëÃŵÄˮƽ£¬
> ÎÒ»¹ÏëÇë½ÌÄã½âÃܵÄʱºò¿ÉÒÔÓà Back TraceÂð£¿
> ÎÒ·´¸´¿´help, ¶¼²»ÐУ¬ÓÃshowµÄÀÏÊÇ˵buffer empty, Ī·Ç·ÇÒªÊÇÔ´³ÌÐòdebug?
ºÃÏóÊÇÒªÏÈÉ趨bpr£¬Ö»ÓÐÔÚbpr·¶Î§ÀïµÄÖ¸Áî²Å¿Éback trace. ÒÔ·ÀÔÚ±ÈÈçÏóBIOS
µÄ³ÌÐòÀï ÂÒת¡£
> ÎÒ¾õµÃ±¾°æµÄ120ƪÎÄÕÂдµÄ¼«ºÃ£¡Ð´³öÁ˾«Ë裬weitµÄÎÄÕÂÒ²ÊÇ
^^^^^--²»ºÃÒâ˼£¬Ò»Ö±Ã»×¢Ò⣬ÏÖÔÚ¿´ÁË£¬µÄÈ·ºÜ°ô£¬
°¥£¬Ôç¿´Á˾ÍÉÙ×ßÍä·ÁË
BTW, ÔõôsiceµÄaÀï ²»Ö§³Ö jmp short ?
ÎÒÊÔÁËjmp short ºÍ jmp short ptr ¶¼²»ÐУ¬
Ö»ºÃ×Ô¼ºÐ´»úÆ÷Âë: EB .. ,Ì«Âé·³ÁË:(
--
%@@,
~~~~~~~~~~~~~~~~~~
ÏòÍùÀÖÍÁµÄ˶Êó
·¢ÐÅÈË: WeiT (˶Êó), ÐÅÇø: Hacker
±ê Ìâ: Re: Ñ°ÕÒ×¢²áÂëµÄ·½·¨ [תÌù] weit Öø
ÈÕ ÆÚ: Thu Mar 7 13:00:15 1996
==> Alex (°¢·É) Ìáµ½:
> ¿ÉÊÇÊÖ²áÀï˵¡° BPR --- ¶Ô¼ÇÒäÌ巶ΧÉèÖÃÖжϵ㡱
> ÄãÓÃbpr À´backtrace³É¹¦¹ýÂð£¿ÒªÊdzɹ¦ÁË£¬ÄÇôÇëÎÊbprµÄµØÖ··¶Î§ÊÇÔõôÉ裿
ÊÇÕâÑùµÄ£ºbpr xxxx:yyyy xxxx:zzzz t
^-Trace Ö®Òâ
È»ºó£¬¿ÉÓÃtrace b¼°show À´¿´Ò»¿´traceµÄhistory.
×îºó£¬ÓÃtrace offÍ˳ötrace b״̬¡£´ó¸Å¾Í½´×ÓÁË¡£
ÎÒÒ²Ö»Óõ½Õâ¶ù£¬ÎÒ²»ÊǺÜϲ»¶siceµÄÕâ¸ö¹¦ÄÜ¡£ÒòΪËü²¢²»ÄÜÕæµÄbacktrace,
Ò²ÐíÊÇÎÒ²»ÇóÉõ½â°É¡£Äã¿ÉÒÔÊÔÊÔ¿´£¬ºÃÓõĻ°¸æËßÎÒ¡£^_^
--
%@@,
~~~~~~~~~~~~~~~~~~
ÏòÍùÀÖÍÁµÄ˶Êó
--
³ÁĬµÄÈË
Reinhard Young
¡ù À´Ô´:¡¤Òûˮ˼Դվ bbs.sjtu.edu.cn¡¤[FROM: 202.96.212.29]
Powered by KBS BBS 2.0 (http://dev.kcn.cn)
Ò³ÃæÖ´ÐÐʱ¼ä£º3.684ºÁÃë