ARTeam Tutorial

Visit: http://cracking.accessroot.com | http://forum.accessroot.com

CAM350 Release 8.0 Version 8.5
Cracking


Information Simple cracking tutorial
Target CAM350 Release 8.0 Version 8.5
Available http://www.downstreamtech.com/CAM350/CAM350_eval_form.asp
Tools OllyDbg 1.10
Protection Licensing file
Level Beginner
Category Cracking
Author(s) ThunderPwr  September 2004
Requirements Windows XP, IE 5.5 and above for best viewing


1. Introduction


This program is a nice PCB (Printed Circuit Board) IDE (Integrated Develompent Environment) to show gerber data and make PCB layout and tooling file. Program came from the author unpacked and without any type of CRC check or other crypted signature, to unlock the program you need a right license.dat file. Mainly use about this program is about gerber viewer feature, this is useful to check our gerber output when you have finished layout working and have done all the file necessary to build your PCB (then before send the file to our favourite manufacturer). This program start, when unregistered, in demo mode, one limitation is about maximum layer which can be see, our task is force the visualization of all layer into our PCB without registering the product.

During all the page of this simple tutorial, step by step explanation is making in order to show how overcome nag message and layer limitation.
In order to to download the program you must register from DownStream, this is a free registration to walk on the download page (program size is about 18 Mb).



2. What we can do


Our purpose is force the full layer visualization for any gerber file.


STEP 1 – Executable file analysis after installationt


When the installation process is ended you must check if the target program is encrypted/packed or in a plain form. In order to make this we can use the PeiD file scanner, see figure 1 for detail:


Fig. 1 PEiD file scanner detail.


Fig. 2 Crypto signature analysis.

This file isn’t packed and came without any integrity check then next step is about debugging and patching.



STEP 2 – Debugging and patching stage


Load the executable into OllyDbg, be sure if your debugging options is equal to the setting reported into
figure 1:


Fig. 3 Debugging options window.

Now you can run the application (press F9), after few seconds you are into the main window, look for the nag there is a shareware text:


Fig. 4 Nag screen.

press the enter key and you give another message which remember about the shareware mode.Now write your name and fake registration number (write a simple registration code, it will be useful when you made the debugging step and must recognize when and where serial is readed and stored), for example:


Fig. 5 Another nag message about the demo mode.

Now go to the OllyDbg code window and press F12 to stop the execution, press ALT+K to show the call stack :


Fig. 6 Call stack.

it's time to make some backtracing into the code, press CTR+G and write 0040B2F0, you can look this section of code:


Fig. 7 Snipped of the code at 0040B2F0.

This code is called from 00401CF9 (look into the panel window at the bottom of the code section), press again CTRL+G (or right click and select Go To -> Expression) then write 00401CF9 and press Enter:


Fig. 8 Snipped of the code at 00401CF9.

Place a breakpoint on 00401CF9 and restart OllyDbg, press F9 to run the program, execution will be stop on our breakpoint, step with F9 until you reach the 00401D14 location (in this place the nag screen of fig. 5 isn't showed), there is a jump into the CamDLL module, press F7 to jump into this dll.


Fig. 9 Jump into the CamDLL module.

now press F9, the nag is showed, stop execution with F12 and scroll down into the stack, look for the first occourrence of nag text "You have invoked CAM350 in demo mode ...":


Fig. 10 Stack snipped.

press CTRL+G and write 10061E7A:


Fig. 11 Go to the to the conditional jump.

trace down into the code until you reach the 10061D26 location, there is a JNZ CamDLL.10061E80 this is a conditional jump, try to change this into a simple unconditionl JMP to the same location and we have defeated the nag message (save this patch with right click and then select Copy to executable -> Selection -> Save, look for figure 21 and following in order to have some detail how to patch with OllyDbg).


Fig. 12 Defeat the nag message.

Now is time for the initial nag of the figure 4, about this place a breakpoint on address 0040B2F0 into the main executable module camnt95 (this can be viewed from figure 8) try to change the MOV ...,1 into
MOV ...,0 and restart OllyDbg, you can see into the new window that the Shareware text and OK button are not present, then you can patch again the executable:


Fig. 13 Patching the main nag window into the camnt95 main module.


Fig. 14 New nag message without the Shareware text.

Now is time to patch the demo limitation about the layer visualization, to do this you must load a complex gerber in order to give the limitation message. To load the gerber use the autoimport function, this can be reach from the File menu and then select Import:


Fig. 15 AutoImport function.

A new window arise, then select your directory where reside the gerber file to show:


Fig. 16 AutoImport window.

Press the Finish button to start the process, after some file loading a new message box arise:


Fig. 17 Message about demo limitation in gerber loading.

Go to the code window, press F12 to stop the program, and then press ALT+K, nothing interesting, scroll down into the stack window until you reach the first occourrence of the message box text:


Fig. 18 Text for the message box about demo version.

the first return after the nag message is into the CamDLL module on address 10084946, go to this module (press Enter on the highlighted stack row showed into fig. 19) and scroll up into the code:


Fig. 19 Code snipped around the demo message.

you can look on 10084918 a JNZ SHORT CamDLL.10084960 conditional jump try to change this in a JMP instruction to avoid the limitation message and to keep all layer loaded and showed, save this change into the CamDLL module in order to fix the patch (press Enter and write the patch then press Assemble.


Fig. 20 Patch for the layer limitation.

After this close this box and select the row which is patched, right click on the code window, then select Copy to Executable -> Selection:


Fig. 21 Patching the layer limitation.

a new window arise, right click and then choose Save to fix this into the CamDLL module:


Fig. 22 Saving the patch to the file.

Now is time to check if our patch work, close OllyDbg and restart the program, load again the gerber with the autoimport function now you can look all the layer loaded and showed into the main screen, nothing nag message appear, work done!



3. Conclusion


This is a very simple tut, i've made it quickly because for my need i've to check some gerber file before to send it in manufacturing, i've not checked all the option for this program, but i thinks this can be full working. I hope this tutorial can be useful to better understand simple code analysis and patching with OllyDbg.

Remember, if you plan to use this software you must purchase the product in order to support the author to develop other good software.

Any suggest, correction or criticism is welcome, if you need help about this tutorial or other stuff you can reach me on ARTeam forum.



8. Greetingz

[MAIN TEAM]
| Nilrem | Ferrari | MaDMAn_H3rCuL3s | EJ12N | Kruger | Shub-Nigurrath | Jdog45 | Teerayoot | R@Dier |

[TRIAL MEMBERS]
| ThunderPwr | Eggi |

 

ThunderPwr