dihux keygenme1 solution by ToMKoL [c4U]

Tools nedded:	SoftICE or other debugger
		Some compiler (i prefer vc++ 6)
		RSATool 2

First run keygenme and see what we need to do. In about we see that
we need to write a keygen and that rsa200 is used. So let's enter
some name and serial:
ToMKoL
11223344556677889900998877665544332211
In softice just break on getdlgitemtexta and you'll land here:
00401065                 push    19h
00401067                 push    offset unk_404330
0040106C                 push    2711h
00401071                 push    [ebp+hWnd]
00401074                 call    GetDlgItemTextA
Get entered name
00401079                 cmp     eax, 5
0040107C                 jb      loc_401214
00401082                 cmp     eax, 14h
00401085                 ja      loc_401214
0040108B                 mov     dword_404429, eax
Name must be 5<=name<=20
00401090                 push    96h
00401095                 push    offset unk_404349
0040109A                 push    2712h
0040109F                 push    [ebp+hWnd]
004010A2                 call    GetDlgItemTextA
004010A7                 test    al, al
004010A9                 jz      loc_401214
Get entered serial, check if we have entered something
004010AF                 lea     esi, ds:404349h
loc_4010B5:
004010B5                 lodsb
004010B6                 test    al, al
004010B8                 jz      short loc_4010D8
004010BA                 cmp     al, 30h
004010BC                 jb      loc_401214
004010C2                 cmp     al, 39h
004010C4                 jbe     short loc_4010B5
004010C6                 cmp     al, 41h
004010C8                 jb      loc_401214
004010CE                 cmp     al, 46h
004010D0                 ja      loc_401214
004010D6                 jmp     short loc_4010B5
Is serial in hex, if not wrong serial
loc_4010D8:
004010D8                 xor     ecx, ecx
loc_4010DA:
004010DA                 push    0
004010DC                 call    sub_401250 - bigcreate
004010E1                 mov     lpAddress[ecx*4], eax
004010E8                 inc     ecx
004010E9                 cmp     ecx, 6
004010EC                 jnz     short loc_4010DA
This loop creates 6 big numbers.
004010EE                 push    lpAddress
004010F4                 push    10h
004010F6                 push    offset n
004010FB                 call    sub_4013F3 - strtobig
00401100                 push    dword_404415
00401106                 push    10h
00401108                 push    offset e
0040110D                 call    sub_4013F3 - strtobig
00401112                 push    dword_404425
00401118                 push    10h
0040111A                 push    offset serial - strtobig
0040111F                 call    sub_4013F3
strtobig is something like cinstr from miracl, it converts string to big format
00401124                 push    offset name
00401129                 call    lstrlenA
0040112E                 push    dword_404419
00401134                 push    eax - name lenght
00401135                 push    offset name
0040113A                 call    sub_40134C - bytestobig
get's name len and converts it to big format, something like bytes_to_big from miracl
0040113F                 push    dword_404421 - c
00401145                 push    lpAddress - n
0040114B                 push    dword_404415 - e
00401151                 push    dword_404425 - serial
00401157                 call    sub_402204 - powmod
something like powmod from miracl, computes c=serial^e mod n
0040115C                 mov     eax, 1337h
00401161                 push    0
00401163                 push    dword_40441D - x
00401169                 push    eax
0040116A                 push    dword_404421 - c
00401170                 call    sub_401D27 - divide
something like divide from miracl, computes x=c/1337h
00401175                 push    dword_40441D - x
0040117B                 push    dword_404419 - name
00401181                 call    sub_4012C7 - compare
00401186                 jnz     short loc_40119C
if x==name then we're registered
00401188                 push    0               ; uType
0040118A                 push    offset aInfo    ; lpCaption
0040118F                 push    offset aSerialIsValid ; lpText
00401194                 push    [ebp+hWnd]      ; hWnd
00401197                 call    MessageBoxA
So the whole registration scheme looks like this:
n,e,serial,name - to big
c=serial^e mod n
x=c/1337h
if x==name registered else bad boy
so if we want to find correct serial for our name we must do this:
name,n,d - to big
c=name*1337h
m=c^d mod n
and m is our serial, d is private key
To factor n we use rsatool and after factoring just click calc d and we have private key.
e=10001
p=970E1A438A10E069571BDCCBB
q=EB3FFE9F5C761995147C7A28B
n=8ACFB4D27CBC8C2024A30C9417BBCA41AF3FC3BD9BDFF97F89
d=32593252229255151794D86C1A09C7AFCC2CCE42D440F55A2D
Keygen source included. This keygenme is great to learn basics in rsa.

tom_c4u@o2.pl - comments, questions and everything else
www.crackmes.prv.pl - polish crackmes site