好友
阅读权限10
听众
最后登录1970-1-1
|
本帖最后由 jcyhlh 于 2010-7-21 11:13 编辑
004A1381 |. 8B86 F8020000 mov eax,dword ptr ds:[esi+0x2F8]
004A1387 |. E8 D813F9FF call Esearch.00432764 ; 获取假码
004A138C |. 8B45 F0 mov eax,[local.4]
004A138F |. 8D55 FC lea edx,[local.1]
004A1392 |. E8 B172F6FF call Esearch.00408648
004A1397 |. 8D45 EC lea eax,[local.5]
004A139A |. E8 B9F1FFFF call Esearch.004A0558 ; 机器码
004A139F |. 8B55 EC mov edx,[local.5]
004A13A2 |. 8B45 F4 mov eax,[local.3]
004A13A5 |. E8 66F4FFFF call Esearch.004A0810 ; 用户名和机器码相连计算
004A13AA |. 8BD0 mov edx,eax
004A13AC |. B9 97000000 mov ecx,0x97
004A13B1 |. 8B45 FC mov eax,[local.1]
004A13B4 |. E8 F7F5FFFF call Esearch.004A09B0 ; 假码进行浮点计算,与获取的时间进行运算
004A13B9 |. 8BD8 mov ebx,eax ;此处将EAX改为ECX,因为这时ECX为1,可以爆破,但重启有验证。
004A13BB |. A1 B85D4A00 mov eax,dword ptr ds:[0x4A5DB8]
004A13C0 8898 80000000 mov byte ptr ds:[eax+0x80],bl
004A13C6 A1 B85D4A00 mov eax,dword ptr ds:[0x4A5DB8]
004A13CB 84DB test bl,bl ; 标志位比较
004A13CD 75 2C jnz short Esearch.004A13FB ; 关键跳
004A13CF 8D45 F8 lea eax,dword ptr ss:[ebp-0x8]
004A13D2 BA A4144A00 mov edx,Esearch.004A14A4 ; 无效的注册密码!
004A13D7 |. E8 9C28F6FF call Esearch.00403C78
004A13DC |. 6A 30 push 0x30
004A13DE |. 8B45 F8 mov eax,[local.2]
004A13E1 |. E8 3E2CF6FF call Esearch.00404024
004A13E6 |. 8BD0 mov edx,eax
004A13E8 |. B9 B8144A00 mov ecx,Esearch.004A14B8 ; 提示
004A13ED |. A1 C45C4A00 mov eax,dword ptr ds:[0x4A5CC4]
004A13F2 |. 8B00 mov eax,dword ptr ds:[eax]
004A13F4 |. E8 AFF9FAFF call Esearch.00450DA8
004A13F9 |. EB 66 jmp short Esearch.004A1461
004A13FB |> A1 B85D4A00 mov eax,dword ptr ds:[0x4A5DB8]
004A1400 |. 05 8C000000 add eax,0x8C
004A1405 |. 8B55 FC mov edx,[local.1]
004A1408 |. E8 2728F6FF call Esearch.00403C34
004A140D |. A1 B85D4A00 mov eax,dword ptr ds:[0x4A5DB8]
004A1412 |. 05 88000000 add eax,0x88
004A1417 |. 8B55 F4 mov edx,[local.3]
004A141A |. E8 1528F6FF call Esearch.00403C34
004A141F |. A1 B4594A00 mov eax,dword ptr ds:[0x4A59B4]
004A1424 |. 8B00 mov eax,dword ptr ds:[eax]
004A1426 |. E8 4180FFFF call Esearch.0049946C
004A142B |. E8 0C0C0000 call Esearch.004A203C
004A1430 |. 8D45 F8 lea eax,[local.2]
004A1433 |. BA C8144A00 mov edx,Esearch.004A14C8 ; 注册成功!
004A1438 |. E8 3B28F6FF call Esearch.00403C78
自己再跟一下。算法我跟了一下,没有跟出来,太乱。期待高手。 |
|