²é¿´: 477  |  »Ø¸´: 1
µ±Ç°Ö÷ÌâÒѾ­´æµµ¡£

sdlj8051

½ð³æ (ÖøÃûдÊÖ)

[½»Á÷] [תÌù]CRC32ÅöײµÄʵÏÖ

?????????????????????

??CRC32??????N??????§¹??,???§¹????0xFFFFFFFF,????N????????????????§¹???

?????????????????????4????????§¹????????????????????????

??:
???????????§¹????ABCD,?????§¹?????????abcd,§¹???????WXYZ,????4???????????mnop
(??????????????????)
???????????ABCD+WXYZ???abcd

????4??????F(x),G(x),H(x),I(x)???????x????????,???????DWORD????¦Ë????¦Ë??4?????

CRC32§¹??abcd???????????:

R0:A,B,C,D
R1:F(m),A^G(m),B^H(m),C^I(m)
R2:F(n),F(m)^G(n),A^G(m)^H(n),B^H(m)^I(n)
R3:F(o),F(n)^G(o),F(m)^G(n)^H(o),A^G(m)^H(n)^I(o)
R4:F(p),F(o)^G(p),F(n)^G(o)^H(p),F(m)^G(n)^H(o)^I(p)

??R4????????4???????§¹???WXYZ,?????????????:

-------------------------
<1>
W=F(p);
X=F(o)^G(p);
Y=F(n)^G(o)^H(p);
Z=F(m)^G(n)^H(o)^I(p);

<2>
m=d^D;
n=c^C^I(m);
o=b^B^H(m)^I(n);
p=a^A^G(m)^H(n)^I(o);
-------------------------

????????????????ABCD,abcd,WXYZ??????,??mnop???§Þ????

????abcd????????,??F(x)???????RF(x),??:
-----------------------
~<1>
p=RF(W);
o=RF(X^G(p));
n=RF(Y^G(o)^H(p));
m=RF(Z^G(n)^H(o)^I(p));

~<2>
d=m^D;
c=n^C^I(m);
b=o^B^H(m)^I(n);
a=p^A^G(m)^H(n)^I(o);
-----------------------

???????????????????????§Ö?????:d,c,b,a  (????????????§³????)

???????????????????,??????????????????RF(x)??????,??????????????????y=F(x)????????:

void TestRF()
{
  BYTE i,j;
  DWORD flag;
  for(i=0;i<=0xFF;i++)
  {
    flag=0;
    for(j=0;j<=0xFF;j++)
    {
      if(HIBYTE(HIWORD(CRC32_tab[j])) == i)
      {
        flag=1;
        printf("%X gets!\r\n",i);
        break;
      }
      if(j==0xFF)break;
    }
    if(!flag)printf("%X can't get RF\r\n",i);
    if(i==0xFF)break;
  }
}

???????????§Ö?0~255????RF(x)???????,?????RF(x)??????????,?????????????!

??????~<1> ~<2>????:

BYTE RF(BYTE x)
{
  BYTE j;
  for(j=0;j<=0xFF;j++)
  {
    if(HIBYTE(HIWORD(CRC32_tab[j])) == x)break;
  }
  return j;
}

BYTE F(BYTE x)
{
  return HIBYTE(HIWORD(CRC32_tab[x]));
}
BYTE G(BYTE x)
{
  return LOBYTE(HIWORD(CRC32_tab[x]));
}
BYTE H(BYTE x)
{
  return HIBYTE(LOWORD(CRC32_tab[x]));
}
BYTE I(BYTE x)
{
  return LOBYTE(LOWORD(CRC32_tab[x]));
}

#define MakeLong(a,b) MAKELONG(b,a)
#define MakeWord(a,b) MAKEWORD(b,a)

DWORD rCRC32(DWORD WXYZ,DWORD ABCD)
{
  BYTE p,o,n,m,a,b,c,d,W,X,Y,Z,A,B,C,D;

  W=HIBYTE(HIWORD(WXYZ));
  X=LOBYTE(HIWORD(WXYZ));
  Y=HIBYTE(LOWORD(WXYZ));
  Z=LOBYTE(LOWORD(WXYZ));

  A=HIBYTE(HIWORD(ABCD));
  B=LOBYTE(HIWORD(ABCD));
  C=HIBYTE(LOWORD(ABCD));
  D=LOBYTE(LOWORD(ABCD));

  p=RF(W);
  o=RF(X^G(p));
  n=RF(Y^G(o)^H(p));
  m=RF(Z^G(n)^H(o)^I(p));

  d=m^D;
  c=n^C^I(m);
  b=o^B^H(m)^I(n);
  a=p^A^G(m)^H(n)^I(o);

  return MakeLong(MakeWord(a,b),MakeWord(c,d));
}

DWORD RCRC32(DWORD WXYZ,DWORD abcd)
{
  BYTE p,o,n,m,a,b,c,d,W,X,Y,Z,A,B,C,D;

  W=HIBYTE(HIWORD(WXYZ));
  X=LOBYTE(HIWORD(WXYZ));
  Y=HIBYTE(LOWORD(WXYZ));
  Z=LOBYTE(LOWORD(WXYZ));

  a=HIBYTE(HIWORD(abcd));
  b=LOBYTE(HIWORD(abcd));
  c=HIBYTE(LOWORD(abcd));
  d=LOBYTE(LOWORD(abcd));

  p=RF(W);
  o=RF(X^G(p));
  n=RF(Y^G(o)^H(p));
  m=RF(Z^G(n)^H(o)^I(p));

  D=m^d;
  C=n^c^I(m);
  B=o^b^H(m)^I(n);
  A=p^a^G(m)^H(n)^I(o);

  return MakeLong(MakeWord(A,B),MakeWord(C,D));
}

DWORD CRC32(DWORD ABCD,DWORD abcd)
{
  BYTE p,o,n,m,a,b,c,d,W,X,Y,Z,A,B,C,D;

  A=HIBYTE(HIWORD(ABCD));
  B=LOBYTE(HIWORD(ABCD));
  C=HIBYTE(LOWORD(ABCD));
  D=LOBYTE(LOWORD(ABCD));

  a=HIBYTE(HIWORD(abcd));
  b=LOBYTE(HIWORD(abcd));
  c=HIBYTE(LOWORD(abcd));
  d=LOBYTE(LOWORD(abcd));

  m=d^D;
  n=c^C^I(m);
  o=b^B^H(m)^I(n);
  p=a^A^G(m)^H(n)^I(o);

  W=F(p);
  X=F(o)^G(p);
  Y=F(n)^G(o)^H(p);
  Z=F(m)^G(n)^H(o)^I(p);

  return MakeLong(MakeWord(W,X),MakeWord(Y,Z));
}

??????????????¡Â????,??????????????????,??CRC32§¹??,???????ABCD
???????????<1><2>????abcd,??abcd?????????????????????????!

????,"DonQuixote[CCG][iPB]"??????????CRC32??0x8A0C90C9,??????¦Ä??????????????????:

int main(int argc, char* argv[])
{

  DWORD x=rCRC32(~0x8A0C90C9,~CRC((BYTE*)"ipb",3));

  char str[5];
  memcpy(str,&x,4);
  str[4]=0;
  printf("x=%X\r\nstring=%s\r\n",x,str);

  return 0;
}

????????§»???:

DonQuixote[CCG][iPB]
123?Dp0
ccg_G??
ipbkw??

?????????????CRC32§¹???=0x8A0C90C9
(????§Ú???????????????,?????http://www.pediy.com/tools/Crypt ... N%20Hash%20Calculat

or%20.zip)

??????????????????????DWORD,????????????????§Þ????¦Ë???DWORD,????????????
??????WXYZ,abcd?????ABCD???????:
-------------------------
(mnop??????~<1>~<2>???)
~<2'>
D=m^d;
C=n^c^I(m);
B=o^b^H(m)^I(n);
A=p^a^G(m)^H(n)^I(o);
-------------------------
????????????????"§¹??"???,?????§Þ????¦Ë????????????

****************************************************************************************8

?????????§»???:

??????????????????????anti-debug??,?????§¹?úY???????????§¹???????
???????~<2'>??~<2>????????§¹?????????,?????????????:CRC(***A***)=A

????windows??????????CRC32§¹???,?????????§Õ??????????????????????§¹?????????????
??????????????RootKit?????????,??????????????????

???TCP/IP??????????CRC32§¹??,??????????§Õ?????????????????????????§¹??????

[ Last edited by sdlj8051 on 2006-10-6 at 12:34 ]
»Ø¸´´ËÂ¥

» ²ÂÄãϲ»¶

ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû

sdlj8051

½ð³æ (ÖøÃûдÊÖ)

ÀûÓ÷´ÏòЧÑéдÁËÒ»¸öanti-debugµÄÀý×Ó£¬È«²¿´úÂëºÍÊý¾ÝÒ»ÆðЧÑ飬ȻºóÀûÓÃЧÑéÖµ½âÃÜ£¬µ±È»Ð§ÑéÖµÊÇÊÂÏÈÏëºÃµÄ£¬Õâ¸öÀý×ÓÀïЧÑéÖµ=0x123456789

¼ÓÃÜǰµÄ´úÂ룺
.code

check_start:

start:
mov esi,check_start
call InitCRC32
mov ecx,check_end-check_start
mov eax,0FFFFFFFFh
call CRC32

mov ecx,(encrypt_end-encrypt_start)
shr ecx,2
mov esi,encrypt_start

decrypt:
push eax
push ecx

mov ecx,4
call CRC32
mov [esi-4],eax

pop ecx
pop eax

inc eax

loop decrypt

encrypt_start:

jmp msgout
msg db "this debugme cracked by none!",0,0,0,0,0,0,0,0,0
tmsg db "test CRC32 by DonQuixote[CCG][iPB]",0
msgout:
invoke MessageBox,NULL,offset msg,offset tmsg,MB_OK
invoke ExitProcess,NULL

encrypt_end:

InitCRC32:

mov ecx, 256

_nexttable:
lea eax, [ecx-1]
push ecx
mov ecx, 8

_nextbit:
shr eax,1
jnc _notcarry
xor eax, 0edb88320h
_notcarry:
dec ecx
jnz _nextbit

pop ecx
mov [dwcrc32table + ecx*4 - 4], eax
dec ecx
jnz _nexttable

ret


CRC32:
;esi=data
;ecx=len of data
;eax=init of checksum

or esi, esi
jz _done
or ecx, ecx
jz _done

_nextbyte:
mov dl, [esi]

xor dl, al
movzx edx, dl
shr eax, 8
xor eax, [dwcrc32table + edx*4]

inc esi
call antibp
loop _nextbyte
_done:
not eax

ret

antibp:
push seh
push fs:[0]
mov fs:[0],esp
db 0CCh
pop fs:[0]
add esp,4
ret

seh:
mov eax,dword ptr ss:[esp+4h]
mov ecx,dword ptr ss:[esp+0Ch]
inc dword ptr ds:[ecx+0B8h]
mov eax,dword ptr ds:[eax]
xor eax,80000003h
jnz start
;xor eax,eax
and dword ptr ds:[ecx+4h],eax
and dword ptr ds:[ecx+8h],eax
and dword ptr ds:[ecx+0Ch],eax
and dword ptr ds:[ecx+10h],eax
and dword ptr ds:[ecx+14h],0FFFF0FF0h
and dword ptr ds:[ecx+18h],0DC00h
ret

check_end:

end start

¶ÔÓ²¼þ¶Ïµã×öÁËÒ»µã´¦Àí£¬¼ÓÃÜËã·¨ÈÔÈ»ÊÇCRC32
ÒòΪÓÃCRC32ЧÑéÒ»¸öDWORDʱ£¬ÖªµÀ ЧÑéÊý¾Ý ЧÑé³õÖµ ЧÑéÖµ 3¸öÖеÄ2¸ö¾Í¿ÉÒÔÇóÁíÍâÒ»¸ö
CRC32:ÊÇCRC32ЧÑ飬eaxÖ¸¶¨Ð§Ñé³õÖµ(eax=0xFFFFFFFF¾ÍÊDZê×¼CRC32)

¼ÓÃÜʱµÄËã·¨£º
#define LEN 0x141
BYTE data[LEN];
DWORD wantedcrc=0x12345678;
DWORD filebase=0x400;
int fixfile()
{
  FILE*fh=fopen("E:\\Crack\\CRC32\\anti.exe","r+";
  fseek(fh,filebase,SEEK_SET);
  fread(data,1,LEN,fh);

  DWORD iendata=0x3A;
  for(int i=0;i<0x1A;i++)
  {
    *(DWORD*)(data+iendata)=rCRC32(~*(DWORD*)(data+iendata),(wantedcrc+i));
    iendata+=4;
  }

  DWORD b=~StdCRC(data,0x5D);
  DWORD a=RevCRC(~wantedcrc,(DWORD*)(data+0x61),(0x141-0x61)/4);
  *(DWORD*)(data+0x5D)=rCRC32(a,b);

  fseek(fh,filebase,SEEK_SET);
  fwrite(data,1,LEN,fh);
  fclose(fh);
  return 0;
}

wantedcrc=0x12345678ÊÇÔ¤ÏÈÉ趨µÄЧÑéÖµ
for(int i=0;i<0x1A;i++)²¿·Ö¼ÓÃÜÊý¾Ý
RevCRC·´ÏòЧÑ飬ȻºóÔÚ*(DWORD*)(data+0x5D)ÕâÀïpatchÐÞ²¹Â룬ʹЧÑéÖµ=wantedcrc

·´ÏòЧÑéµÄ´úÂ룺
//return init reg
DWORD RevCRC(DWORD reg,DWORD*pdata,int n)
{
  for(int i=n-1;i>=0;i--)reg=RCRC32(reg,pdata);
  return reg;
}
//¸ù¾ÝÊý¾ÝºÍЧÑéÖµÇó³öЧÑé³õÖµ


ÀûÓÃCRC32¼ÓÃܵı任Ҳ¿ÉÒÔÓ¦Óõ½ÐòÁкű任À¿ÉÒÔÔö¼ÓÒ»µãдKeyGenµÄÄѶȣº£©
2Â¥2006-08-23 18:15:28
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû
Ïà¹Ø°æ¿éÌø×ª ÎÒÒª¶©ÔÄÂ¥Ö÷ sdlj8051 µÄÖ÷Ìâ¸üÐÂ
×î¾ßÈËÆøÈÈÌûÍÆ¼ö [²é¿´È«²¿] ×÷Õß »Ø/¿´ ×îºó·¢±í
[¿¼ÑÐ] 07»¯Ñ§303Çóµ÷¼Á +5 î£08 2026-03-25 5/250 2026-03-25 22:46 by 418490947
[¿¼ÑÐ] 335·Ö | ²ÄÁÏÓ뻯¹¤×¨Ë¶ | GPA 4.07 | ÓпÆÑо­Àú +6 cccchenso 2026-03-23 6/300 2026-03-25 22:25 by 544594351
[¿¼ÑÐ] 292Çóµ÷¼Á +6 ¶ì¶ì¶ì¶î¶î¶î¶î¶ 2026-03-25 7/350 2026-03-25 22:04 by Î޼ʵIJÝÔ­
[¿¼ÑÐ] ¿¼Ñе÷¼Á +5 ºôºô£¿~+123456 2026-03-24 5/250 2026-03-25 18:15 by xcjcqu
[¿¼ÑÐ] 302Çóµ÷¼Á +4 ½õÒÂÎÀÌÙ½· 2026-03-25 4/200 2026-03-25 16:29 by ¹¦·ò·è¿ñ
[¿¼ÑÐ] 359Çóµ÷¼Á +3 ÍõÁ˸öéª 2026-03-25 3/150 2026-03-25 12:50 by Dyhoer
[¿¼ÑÐ] 293Çóµ÷¼Á +7 ¼ÓÒ»Ò»¾Å 2026-03-24 7/350 2026-03-25 12:02 by userper
[¿¼ÑÐ] 318Çóµ÷¼Á +3 plumÀî×Ó 2026-03-23 3/150 2026-03-25 09:42 by ÎíÉ¢ºóÏàÓölc
[¿¼ÑÐ] ²ÄÁϵ÷¼Á +6 Æ¥¿Ëi 2026-03-23 6/300 2026-03-24 21:09 by greychen00
[¿¼ÑÐ] Çóµ÷¼Á +6 ÑÐÑУ¬½Óµç»° 2026-03-24 7/350 2026-03-24 17:01 by barlinike
[¿¼ÑÐ] 307Çóµ÷¼Á +5 ³¬¼¶ÒÁ°º´óÍõ 2026-03-24 5/250 2026-03-24 15:46 by ÐÇ¿ÕÐÇÔÂ
[¿¼ÑÐ] Ò»Ö¾Ô¸ÎäÀí²ÄÁϹ¤³Ì348Çóµ÷¼Á +6 £þ^£þ©bº¹ 2026-03-19 9/450 2026-03-23 19:53 by pswait
[ÂÛÎÄͶ¸å] ¼±·¢ºËÐÄÆÚ¿¯ÂÛÎÄ +3 ÏÍ´ïÎʽò 2026-03-23 5/250 2026-03-23 17:13 by ÃÃ×Ó²»ºÃÈÇ
[¿¼ÑÐ] 291Çóµ÷¼Á +5 ‹üÈA 2026-03-22 5/250 2026-03-23 09:20 by haoshis
[¿¼ÑÐ] 276Çóµ÷¼Á +3 YNRYG 2026-03-21 4/200 2026-03-23 08:31 by ×íÔÚ·çÀï
[¿¼ÑÐ] 280·ÖÇóµ÷¼Á Ò»Ö¾Ô¸085802 +4 PUMPT 2026-03-22 7/350 2026-03-22 22:13 by ÐÇ¿ÕÐÇÔÂ
[¿¼ÑÐ] Çóµ÷¼ÁÒ»Ö¾Ô¸º£´ó£¬0703»¯Ñ§Ñ§Ë¶304·Ö£¬Óдó´´ÏîÄ¿£¬Ëļ¶Òѹý +6 ÐÒÔËÁ¨Á¨ 2026-03-22 10/500 2026-03-22 20:10 by edmund7
[¿¼ÑÐ] 298Çóµ÷¼ÁÒ»Ö¾Ô¸211 +3 Éϰ¶6666@ 2026-03-20 3/150 2026-03-22 15:50 by ColorlessPI
[¿¼ÑÐ] 085600²ÄÁÏÓ뻯¹¤306 +4 z1z2z3879 2026-03-21 4/200 2026-03-21 23:44 by ms629
[¿¼ÑÐ] 0805²ÄÁÏ320Çóµ÷¼Á +3 ÉÎïÓï 2026-03-20 3/150 2026-03-21 15:46 by Î޼ʵIJÝÔ­
ÐÅÏ¢Ìáʾ
ÇëÌî´¦ÀíÒâ¼û