|
ARTeam Tutorial Visit:
http://cracking.accessroot.com
|
http://forum.accessroot.com CAM350 Release
8.0 Version 8.5 |
| Information | Simple cracking tutorial |
| Target | CAM350 Release 8.0 Version 8.5 |
| Available | http://www.downstreamtech.com/CAM350/CAM350_eval_form.asp |
| Tools | OllyDbg 1.10 |
| Protection | Licensing file |
| Level | Beginner |
| Category | Cracking |
| Author(s) | ThunderPwr September 2004 |
| Requirements | Windows XP, IE 5.5 and above for best viewing |
|
1. Introduction
|
|
During
all the page of this simple tutorial, step by step explanation is
making in order to show how overcome nag message and layer limitation. |
| 2. What
we can do |
|
Our purpose is force the full layer visualization for any gerber file. |
|
STEP 1 – Executable file analysis
after installationt
|
|
This file isn’t packed and came
without any integrity check then next step is about debugging and
patching. |
|
STEP 2 – Debugging and patching
stage
|
|
Now you can run the application (press
F9), after few seconds you are into the main window, look for the
nag there is a shareware text:
press the enter key and you give another
message which remember about the shareware mode.Now write your name
and fake registration number (write a simple registration code, it
will be useful when you made the debugging step and must recognize
when and where serial is readed and stored), for example: Now go to the OllyDbg code window and press F12 to stop the execution, press ALT+K to show the call stack :
it's time to make some backtracing
into the code, press CTR+G and write 0040B2F0, you can look this section
of code: This code is called from 00401CF9
(look into the panel window at the bottom of the code section), press
again CTRL+G (or right click and select Go To -> Expression) then
write 00401CF9 and press Enter:
Place a breakpoint on 00401CF9 and
restart OllyDbg, press F9 to run the program, execution will be stop
on our breakpoint, step with F9 until you reach the 00401D14 location
(in this place the nag screen of fig. 5 isn't showed), there is a
jump into the CamDLL module, press F7 to jump into this dll.
now press F9, the nag is showed, stop
execution with F12 and scroll down into the stack, look for the first
occourrence of nag text "You have invoked CAM350 in demo mode
...":
press CTRL+G and write 10061E7A:
trace down into the code until you
reach the 10061D26 location, there is a JNZ CamDLL.10061E80 this is
a conditional jump, try to change this into a simple unconditionl
JMP to the same location and we have defeated the nag message (save
this patch with right click and then select Copy to executable ->
Selection -> Save, look for figure 21 and following in order to
have some detail how to patch with OllyDbg).
Now is time for the initial nag of
the figure 4, about this place a breakpoint on address 0040B2F0 into
the main executable module camnt95 (this can be viewed from figure
8) try to change the MOV ...,1 into
Now is time to patch the demo limitation about the layer visualization, to do this you must load a complex gerber in order to give the limitation message. To load the gerber use the autoimport function, this can be reach from the File menu and then select Import:
A new window arise, then select your
directory where reside the gerber file to show:
Press the Finish button to start the
process, after some file loading a new message box arise:
Go to the code window, press F12 to
stop the program, and then press ALT+K, nothing interesting, scroll
down into the stack window until you reach the first occourrence of
the message box text:
the first return after the nag message
is into the CamDLL module on address 10084946, go to this module (press
Enter on the highlighted stack row showed into fig. 19) and scroll
up into the code: you can look on 10084918 a JNZ SHORT
CamDLL.10084960 conditional jump try to change this in a JMP instruction
to avoid the limitation message and to keep all layer loaded and showed,
save this change into the CamDLL module in order to fix the patch
(press Enter and write the patch then press Assemble.
After this close this box and select
the row which is patched, right click on the code window, then select
Copy to Executable -> Selection:
a new window arise, right click and
then choose Save to fix this into the CamDLL module:
Now is time to check if our patch
work, close OllyDbg and restart the program, load again the gerber
with the autoimport function now you can look all the layer loaded
and showed into the main screen, nothing nag message appear, work
done! |
|
3. Conclusion
|
|
|
|
8. Greetingz
|
|
[MAIN TEAM]
|