SERIAL NUMBER IS FISHY - DECLINE YOUR PATCH'ITCH'ING AxMan v3.12R A Cracking Tutorial by ASTAGA [D4C/C4A] DISCLAIMER This reading material is not intended to violate Copyrights and/or it is law, but educational purposes only. I hold no responsibility ( by all means and in any shape whatsoever ) of the mis-used of this material. Read END NOTES section at the end of this file. ABOUT THE PROGRAM AxMan is a 32-bit windows application that will split any file into pieces. These pieces can then be later restored to recover the original file. AxMan offers many features and customizations so that it can suit each user's individual needs. Have you ever downloaded a program that you wanted to make a backup copy of only to realize that it was too large to fit onto a single floppy disk? Have you ever tried to email someone a large program only to have it not get there because of restrica tions that certain email servers make on the size of emails? Have you ever wanted to distibute files from your internet site but they are so large that people get frustrated trying to down load them, having their connections lost and being forced to start over? If you answered yes to any of the questions above, then AxMan is the program for you! WHERE TO DOWNLOAD Author : Mosaic Software Solutions Copyright : Mosaic Software Solutions Homepage : http://www.mosaicware.com URL : http://www.mosaicware.com/axman312r.exe patience on their slow site Size : 2.4 MB as of December 24,2000 Rel Date : September 17,2000 HOW TO GET VALID SERIAL NUMBER by using SoftIce 1. Run WINNC.EXE, in the registration dialog box type these below informations : Name : Pirates Order Company : Red Rackham Code : 73881050 Do not click OK button yet 2. Load SoftIce by pressing [ CTRL + D ], set a breakpoint as follow : BPX hmemcpy [enter] and F5 to return to the main program 3. Now, click OK button... you'll return back into SoftIce! In within SoftIce press F5 2 times, then F12 several times until you see and break at : ( keep on pressing F12 when you drop dead at MFC42, KERNELL,etc ) ______________________________________________________________ 015F:00406906 E897B00000 CALL 004119A2 <== break here 015F:0040690B 8D4DE4 LEA ECX,[EBP-1C] ==> D ECX 015F:0040690E E825FBFFFF CALL 00406438 015F:00406913 FF75EC PUSH DWORD PTR [EBP-14] 015F:00406916 8D4DE4 LEA ECX,[EBP-1C] 015F:00406919 C645FC03 MOV BYTE PTR [EBP-04],03 015F:0040691D FF75E8 PUSH DWORD PTR [EBP-18] *** 015F:00406920 FF75F0 PUSH DWORD PTR [EBP-10] 015F:00406923 E83CFBFFFF CALL 00406464 015F:00406928 84C0 TEST AL,AL ==> D ECX; D EDX 015F:0040692A 7518 JNZ 00406944 015F:0040692C 6A30 PUSH 30 015F:0040692E 6810AC4100 PUSH 0041AC10 015F:00406933 68ECAB4100 PUSH 0041ABEC 015F:00406938 8BCE MOV ECX,ESI 015F:0040693A E821B00000 CALL 00411960 ==> beggar-off message 015F:0040693F E98E000000 JMP 004069D2 ... ... _________________________ AXMAN!.text+5906 _______________ FOR THOSE WHO CAN'T REACH 015F:00406906 do a search string WHERE EVER YOU ARE AS LONG AS YOU ARE IN THE MAIN PROGRAM'S CODE : s 0 l ffffffffff E8 97 B0 00 00 8D 4D [enter] SoftIce will response : Pattern found at 0167:00406906 <== bpx this location Virtual memory and memory address may differ in your PC - BUT NOT FOR THE HEX CODE. : bc 00 [enter] ==> no longer needed : bpx 015F:00406906 [enter] Press F10 once - stop at 015F:0040690B - display ECX register : d ecx [enter] see that fake code at virtual address 0167:00674980 ??? Press F10 5 times - stop at 015F:0040691D - look at SS register : d 006748E0 see that "Red Rackham" your company name ?? SEveral lines below you can also see your name. Press F10 3 times - stop at 015F:00406928 - display ECX and EDX registers : : d edx [enter] a 914-337-330 appear at virtual address 0167:0065ED4C . : d ecx [enter] your fake 73881050 appear at virtual address 0167:00674980 Press F10 6 times, step passed CALL instruction at 015F: 0040693A ==> you'll got beggar-off message. Here you quiet sure that 914-337-330 is your reg code. And lamer(z) who do you wanna keygen trace CALL function at 015F:00406923. 5. Disable all breakpoints by typing BD * [enter] Press F5 or X to return to the main program 6. Repeat registration procedure and keyed-in 914-337-330 as your S/N. Click OK button ..... there you're registered. 7. Where the hell is my registration code is stored ?? The correct registration code is stored in the registry as follows : REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Mosaic Software Solutions\AxMan\ 3.00\License] "InstallDate"="2451903" "Name"="Pirates Order" "Company"="Red Rackham" "Key"="914-337-330" 8. How can I practise with my own user name ? - I strongly recommended you not to do this ! E N D N O T E S Distributing your serial number is illegal and is no different than distributing illegal copies of the registered software. Violation of this rule may result in temporary or permanent revocation of this license and cancellation of the serial number; the original licensee will also be held responsible for damages, physical and estimated. Do not distribute your crack release based on this tutorial, because you become a LAMER(s)!!!!!!!! ( tHATDUDE (PC97) defined LAMER(s) is the guy who sits in front of personal computer, using Hex Editor, ripping off other group(s) crack release, repacking (distro) them under his name. Adopted from newsgroup alt.cracks, alt.crackers - February 1997 ) More about LAMER(s): lamer /n./ [prob. originated in skateboarder slang] Synonym for luser, not used much by hackers but common among warez d00dz, crackers, and phreakers. Oppose elite. Has the same connota tions of self-conscious elitism that use of luser does among hackers. < SOURCE: http://sagan.earthspace.net/jargon/jargon_27.html > Never attribute to malice that which is adequately explained by stupidity ASTAGA [D4C/C4A] tute-axman312r.zip [EOF] 12/24/00 11:21:11 PM