MeaCulpa
November 26th, 2002, 11:54
Hi All,
I'm working on Softwrap v.3.5 - 3.6.1 protected targets, and need some pointers please..... (BlackBird; Eisenbeiss
Target: anything protected with a new softwrap.
Problem: the newer softwrap has a funtion to not allow any trial period for evaluation....you have to buy online etc. before the app unlocks...
Research: There's 2 essays out (both version 1.x related) from Blackbird and Eisenbeiss. In older versions you could deadlist to get string refs and start from there. Alternatively bpx'ing on WritePocessMemory (etc.) APIs would provide a starting point for dumping.....
NchantA also wrote an essay, does anyone have this one please?
[The file format stayed largely the same, with license file .sw; loader exe file of +- 360kb (same for all apps) and the .locked file with RSA512, destroyed import table etc..)
What if the app does not allow evaluation, there is no string/data references, nothing. It does not start the program so we cant get a starting point for unpacking/dumping....
( I am thinking along the line of altering the loader exe so that it changes the options with wich the app was packed, so that it changes from no eval/trial to allowing a trial.....just an idea
Can this still be unpacked manually.
Any help/suggestions would be welcome please.
thanks
MeaCulpa
I'm working on Softwrap v.3.5 - 3.6.1 protected targets, and need some pointers please..... (BlackBird; Eisenbeiss

Target: anything protected with a new softwrap.
Problem: the newer softwrap has a funtion to not allow any trial period for evaluation....you have to buy online etc. before the app unlocks...
Research: There's 2 essays out (both version 1.x related) from Blackbird and Eisenbeiss. In older versions you could deadlist to get string refs and start from there. Alternatively bpx'ing on WritePocessMemory (etc.) APIs would provide a starting point for dumping.....
NchantA also wrote an essay, does anyone have this one please?
[The file format stayed largely the same, with license file .sw; loader exe file of +- 360kb (same for all apps) and the .locked file with RSA512, destroyed import table etc..)
What if the app does not allow evaluation, there is no string/data references, nothing. It does not start the program so we cant get a starting point for unpacking/dumping....
( I am thinking along the line of altering the loader exe so that it changes the options with wich the app was packed, so that it changes from no eval/trial to allowing a trial.....just an idea
Can this still be unpacked manually.
Any help/suggestions would be welcome please.
thanks
MeaCulpa