Posted: Fri Jun 06, 2008 4:02 pm Post subject: Getting registry info and configuration files
I've got two questions related to the same program. The sneaky authors of the program have planted an expiration notice in my computer---I assume in the registry. I've tried breaking on RegQueryInfoKeyA, RegQueryValueExA and RegQueryValueExW. These are the only Registry Query calls I can find. Are there any other intermodular calls that could be used to fetch an expiration value in the registry?
This program runs with a configuration file. You get a demo configuration file to evaluate the program and if you buy it, you get another configuration file that never expires. If you open the configuration file in NOTEPAD, some of it is encrypted. I'll paste below:
My NAME InstitutionMy institution SerialNum6772
ep_standAloneNetUsers ProgConfigMode cfgm_demo LastBuild 3.00.0315NeedCountercodeAfter û˜@CountercodeModecm_standard
doSecurityAllowAlerts ValidationModevm_countercodeHasTemporaryConfigModeMaxSecurityUsers TempConfigModecfgm_pro
I've changed my name and institution, but as you can see there are some squares and funny characters that presumably are making the program expire.
Does anybody know anything about the use of encrypted configuration files and how to decrypyt them and alter them to our evil advantage?
I'm afraid there is no encrypted data in your file. The squares and other strange symbols could be only numerical quantities, not having a direct correspondence in ASCII code.
Try to open in an hex editor to find which quantities do have the strange symbols. Have in mind that they could be hexa values, so translating them to decimal maybe will provide you some sense to them...
You only need to trace in your target from CreateFileA function, when this file is open, and see what happens with these strange values.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You cannot download files in this forum