Welcome to Cracking Tutorial #22! Ah, what a *good* birthday I had yesterday! :) Not too sick to work on this 2 versions! (#22 and #23) Like I said earlier, nothing is gonna stop me now! :) Thanks goto dAvId/nIgHtMaRe for tutors in this version.. Ok, let's rave! You'll need the following tools: (I use these tools, I assume you'll use 'em, but it doesn't mean that you'll need to use all those tools, so be sure to get them handy for the examples in this tutorial!) SoftIce 3.25 W32Dasm 8.93 Hacker's View 6.04 SmartCheck 6.03 TASM 5.00 Windows Commander 3.53 (I use it coz of easier to multitask) Don't ask me where to download all these tools since you had a chance to get them when you used my older tutorials. Here are a few good cracking sites where you can grab tools from: http://surf.to/HarvestR or http://harvestr.cjb.net http://catalyst.intur.net/~Iczelion/tools.html http://www.suddendischarge.com or ask any crackers to get you these tools! Are you ready?! OK! ;) PART 1: ~~~~~~ HOW TO CRACK Pretty Html 3.5 bY dAvId/nIgHtMaRe'1 April 1999 Welcome to my 3rd Cracking Tutorial ah its been a while since my second cracking tutorial but i have been busy well lets crack This time i'll teach you how to crack Pretty Html 3.5 Sorry for my bad grammatic, but i hope u will under stand it anyway... Tools Used: W32Dasm 89.3 Hiew 6.04 Far 1.52 or any other Norton Commander like clone 1 or more cups of coffee (A Pot will usualy do) you can also drink tea 1 or more ciggys (A Pack will usualy do) (Smoke em baby Smoke em) he he Where http://mpp.at Protection Type serial Crack Type *PATCH* Ok run the proggy your get a nag telling you this is an unregistreted version of this app and you got 30 number of days of your trial period hmm i dont think thats is enough of time app goto <-Enter Registration Key-> Enter name dAvId/nIgHtMaRe'1 / and serial 123454 you'll get the message sux remember it or Write it down on a pice of paper you know that there happends 3 things when you get old 1 you dont remember very well any more 2 you dont see very well any more and 3 you dont remember very well any more he he NOT THAT i'm old hmm can any body guess my age now goto far copy prettyhtml.exe to prettyhtml.w32 for use whit w32dasm and copy prettyhtml.exe to prettyhtml.exx 4 backup in case you fuck up run w32dasm and dissambly prettyhtml.w32 when done goto Strn Ref button Click it go down until you see the message incorrect name or serial... double click on it then close down the Strn Ref Windows you should see this * Possible StringData Ref from Code Obj ->"Incorrect name or serial..." :0048B89B E8B4B6F7FF Call 00406F54 | * Reference To: user32.MessageBeep, Ord:0000h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:0048B7AC(C) <- What is this ? you know right ? | :0048B88F A12C544900 mov eax, dword ptr [0049542C] :0048B894 E81783F7FF call 00403BB0 :0048B899 6A00 push 00000000 Follow (U)nconditional or (C)onditional press the up arrow until you see this * Possible StringData Ref from Code Obj ->" Thank you, ..." :0048B7A3 E8380A0000 call 0048C1E0 :0048B7A8 837DF800 cmp dword ptr [ebp-08], 00000000 :0048B7AC 0F84DD000000 je 0048B88F <- its this one :0048B7B2 8D45F8 lea eax, dword ptr [ebp-08] hmm whats this a flag test i wonder what happends if you change the je to jne you guessed it it will register so fire up hiew prettyhtml.exe press f4 select decode mode and press f5 enter 8ABAC press f3 change je 84 to jne 85 press f9 to update the file run Pretty Html 3.5 goto enter <-Enter Registration Key-> enter any name any key *boom* **regged** cool you crack Pretty Html 3.5 try to practice whit doing this by your self to unregister this proggy goto installed directory and delete pretty.reg and restore the old prettyhtml.exx whit your new prettyhtml.exe if you got any comments or questions send em to me if i got enough time i'll send you an e-mail back you might find me on irc/EFNET in the channel #c.i.a under the nick dAvId_nM1 if i got time i'll chat anyway i'hope you sea you in tutor #4 Cracking Tutorial #3 Written by dAvid/nIgHtMaRe'1 On April 1999 wanna contact me yeah its possibal e-mail me at dAvIdnM1@usa.net PART 2: ~~~~~~ HOW TO CRACK Access Denied 1.11 bY dAvId/nIgHtMaRe'1 April 1999 Welcome to my 4th Cracking Tutorial This time i'll teach your how to crack Access Denied 1.11 Sorry for my bad grammatic, but i hope u will under stand it anyway... Tools Used: W32Dasm 89.3 Hiew 6.04 Far 1.52 or any other Norton Commander like clone 1 or more cups of coffee (A Pot will usualy do) you can also drink tea 1 or more ciggys (A Pack will usualy do) (Smoke em baby Smoke em) he he Where www.winfiles.com Protection Type serial Crack Type *PATCH* Ok run the Access Denied 1.11 there is no nags but unregged shareware still sux so lets crack in the help menu your'll see a Enter registration Code now enter the menu and enter Name dAvId/nIgHtMaRe'1 or any name you like as code enter 123454 or any code you like you'll get the message Wrong Code try again / yes we will later goto far copy access.exe to access.exx for backup in case you fuck up he he and copy access.exe to access.w32 for use whit w32dasm goto W32Dasm and dissambly access.w32 when dissambled goto Strn Ref button click it Close Strn Ref Windows then press down until you see * Possible StringData Ref from Data Obj ->"Wrong code, try again" :00403C4B 6836BB4000 push 0040BB36 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:00403BF4(C), :00403C00(C), :00403C08(C) :00403C49 6A00 push 00000000 * Possible StringData Ref from Data Obj ->"Registration Error" | fuck look at all those jumps i guess it check more than once oh well press up until you see * Possible StringData Ref from Data Obj ->"Thank you for support" :00403C13 680EBB4000 push 0040BB0E * Possible StringData Ref from Data Obj ->"Good day for you!" :00403C0C E841640000 Call 0040A052 :00403C11 6A40 push 00000040 * Reference To: USER32.MessageBeep, Ord:0000h :00403BF4 7553 jne 00403C49 <- check point 1 :00403BF6 E81B120000 call 00404E16 :00403BFB 3D1D663600 cmp eax, 0036661D :00403C00 7547 jne 00403C49 <- check point 2 :00403C02 81FEC58E73D7 cmp esi, D7738EC5 :00403C08 753F jne 00403C49 <- check point 3 :00403C0A 6A40 push 00000040 so you'll will have to change all 3 jumps ok run hiew access.exe press f4 and select decode mode press f5 enter 31F4 change jne 74 to je press f9 to update file press f5 enter 3200 change jne 74 to je press f9 to update file press f5 enter 3208 change jne 74 to je press f9 to update file you''l get the message thank you for registrering goto help:about UNREGISTRETED still hmm sux what now goto Strn Ref button click it go down until you see * Possible StringData Ref from Data Obj ->"Licensed to "%s"" :00403D8D 3D45740000 cmp eax, 00007445 :00403D92 7527 jne 00403DBB <- looks familer :00403D94 E87D100000 call 00404E16 :00403D99 3D1D663600 cmp eax, 0036661D :00403D9E 751B jne 00403DBB <- one more :00403DA0 6898134100 push 00411398 ok now run hiew access.exe goto press f4 and select decode mode press F5 enter 3392 change jne 74 to je press f9 to update file press f5 enter 339E change jne 74 to je press f9 to update file Run Access Denied 1.11 goto register enter any name any key look in the about its your name *boom* **regged** cool your cracked Access Denied 1.11 if you got any comments or questions send em to me if i got enough time i'll send you an e-mail back you might find me on irc/EFNET in the channel #c.i.a under the nick dAvId_nM1 if i got time i'll chat anyway i'hope you sea you in tutor #5 Cracking Tutorial #4 Written bY dAvId/nIgHtMaRe'1 On April 1999 wanna contact me yeah its possibal e-mail me at dAvIdnM1@usa.net PART 3: ~~~~~~ HOW TO CRACK Instyler SmartSetup 2.0 bY dAvId/nIgHtMaRe'1 April 1999 Welcome to my 5th Cracking Tutorial This time i'll teach you how to crack Instyler SmartSetup 2.0 Sorry for my bad grammatic, but i hope u will under stand it anyway... Tools Used: W32Dasm 89.3 Hiew 6.04 Far 1.52 or any other Norton Commander like clone 1 or more cups of coffee (A Pot will usualy do) you can also drink tea 1 or more ciggys (A Pack will usualy do) (Smoke em baby Smoke em) he he Where www.instyler.com Protection Type serial Crack Type *PATCH* run proggy when it start goto register press it as name enter dAvId/nIgHtMaRe'1 or any name you like and as key enter 123454 or any key you like you'll not get an error message or nothing goto far copy creator.exe to creator.exx for backup in case you fuck up and copy creator.exe to creator.w32 for use whit w32dasm run w32dasm and dissamble when done dissambling goto the Strn Ref button Click it press down until you see Thank You for your support. Your double click on it good now continue close Strn Ref Window and you'll see this * Possible StringData Ref from Code Obj ->"Thank You for your support. Your " ->"copy of instyler SmartSetup is " ->"now registered." :004657C6 B9E0584600 mov ecx, 004658E0 * Possible StringData Ref from Code Obj ->"Thank You" :004657B5 E8922B0000 call 0046834C <- the call :004657BA 837DF800 cmp dword ptr [ebp-08], 00000000 :004657BE 0F8482000000 je 00465846 <- Flag Check is it regged :004657C4 6A41 push 00000041 so if you change the je to jne you get the message Thank You for your support. Your copy of instyler SmartSetup is now registered try it run hiew creator.exe press F4 select decode mode press F5 enter 64BBE press F3 change the je 84 to jne 85 run the program does it work ? well no fuck why not well this proggy like a loot of other also check is its regged at startup remeber that cuse you'll need it a loot so what now remember the call is marked it as <- the call i bet your do goto search enter 0046834C search down you'll once thats not it Search again next time you find it you'll see this :0046AD57 E8F0D5FFFF call 0046834C <- the call :0046AD5C 837DF400 cmp dword ptr [ebp-0C], 00000000 :0046AD60 7512 jne 0046AD74 <- Flag Check is it regged :0046AD62 8D8330060000 lea eax, dword ptr [ebx+00000630] * Possible StringData Ref from Code Obj ->"Unregistered Evaluation Copy" so if you change the je to jne you'll have a fully regged copy of Instyler SmartSetup 2.0 cool right ? try it run hiew creator.exe press F4 select decode mode press F5 enter 6A160 press F3 change the je 84 to jne 85 run the program enter any name any key does it work ? Yeah it Works Cool you Cracked Instyler SmartSetup 2.0 if you got any comments or questions send em to me if i got enough time i'll send you an e-mail back you might find me on irc/EFNET in the channel #c.i.a under the nick dAvId_nM1 if i got time i'll chat anyway i'hope you sea you in tutor #6 Cracking Tutorial #5 Written bY dAvId/nIgHtMaRe'1 On April 1999 wanna contact me yeah its possibal e-mail me at dAvIdnM1@usa.net PART 4: ~~~~~~ HOW TO CRACK PTS-AudioCD MP3-Studio 1.1b bY dAvId/nIgHtMaRe'1 April 1999 Welcome to my 6th Cracking Tutorial This time i'll teach you how to crack PTS-AudioCD MP3-Studio 1.1b Sorry for my bad grammatic, but i hope u will under stand it anyway... Tools Used: W32Dasm 89.3 Hiew 6.04 Far 1.52 or any other Norton Commander like clone 1 or more cups of coffee (A Pot will usualy do) you can also drink tea 1 or more ciggys (A Pack will usualy do) (Smoke em baby Smoke em) he he Where http://www.hilchner.de Protection Type serial Crack Type *PATCH* run PTS-AudioCD MP3-Studio 1.1b the window at startup will be there not mater what if you register it or not it will still be there if you want to you can remove it knock your self out goto help:register enter 123454 or any code you like press ok you'll get the error message Invalid registration code double click on you Close Strn Ref Windows you'll now see this * Possible Reference to String Resource ID=61261: "Invalid registration code." :00405435 6AFF push FFFFFFFF :00405437 6A00 push 00000000 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:00405404(C) follow the call press shift + f12 and enter 00405404 You'll end up here :004053FD E83EFBFFFF call 00404F40 <- the call :00405402 84C0 test al, al <- test if its correct :00405404 742F je 00405435 <- flag test is it regged is? ok now run hiew audio.exe press F4 select decode mode press F5 enter 4804 press F3 change the je 74 to jne 75 press F9 to update file run PTS-AudioCD MP3-Studio 1.1b does it work NO! its still unregged fuck what now well remember <-the call i marked i bet you do goto search enter 0040F440 press the search down you'll end up here :00405AA8 E893F4FFFF call 00404F40 <- the call :00405AAD 84C0 test al, al <- test if its correct :00405AAF 7511 jne 00405AC2 <- flag test is it regged is? run hiew audio.exe ok now run hiew audio.exe press F4 select decode mode press F5 ente 4EAF press F3 change the jne 75 to jn 74 press F9 to update file well better be sure that not another check well lets check goto search enter 0040F440 press the search up you'll end up here you find it once skip it search again you'll allready changed that byte search again you find the real call skip that we dont waner change that this this you'll end up here :004041C6 E8750D0000 call 00404F40 <- the call :004041CB 84C0 test al, al <- test if its correct * Possible Reference to Menu: MenuID_006C | :004041CD 6A6C push 0000006C :004041CF 7435 je 00404206 <- flag test is it regged is? ok now run hiew audio.exe press F4 select decode mode press F5 ente 35CF press F3 change the je 74 to jne 75 press F9 to update file run PTS-AudioCD MP3-Studio 1.1b does it work yeah cool you cracked PTS-AudioCD MP3-Studio 1.1b now go make some cds if you got any comments or questions send em to me if i got enough time i'll send you an e-mail back you might find me on irc/EFNET in the channel #c.i.a under the nick dAvId_nM1 if i got time i'll chat anyway i'hope you sea you in tutor #7 Cracking Tutorial #6 Written bY dAvid/nIgHtMaRe'1 On April 1999 wanna contact me yeah its possibal e-mail me at dAvIdnM1@usa.net PART 5: ~~~~~~ HOW TO CRACK Super Sensitive Disk-Scanner 98 v2.00.4.99 English Version bY dAvid/nIgHtMaRe'1 on April 1999 Welcome to my 7th Cracking Tutorial This time i'll teach you to how crack Super Sensitive Disk-Scanner 98 v2.00.4.99 English Version Sorry for my bad grammatic, but i hope u will under stand it anyway... Tools Used: W32Dasm 89.3 Soft-Ice 3.24 Far 1.52 or any other Norton Commander like clone 1 or more cups of coffee (A Pot will usualy do) you can also drink tea 1 or more ciggys (A Pack will usualy do) (Smoke em baby Smoke em) he he Where http://software.webset.de/cadkas/ Protection Type serial Crack Type Correct Serial Ok Start Super Sensitive Disk-Scanner 98 v2.00.4.99 English Version you notice a nag that says you have 30 days left until it will expire unless you register sux goto register enter name dAvId/nIgHtMaRe'1 or Any Name you like and as code 123454 or any code you like you'll get an error message telling you <-Number is incorrect-> remember it goto far copy ssds_eng.exe to ssds_eng.w32 for use whit w32dasm start w32dasm and dissamble ssds_eng.w32 when dissambled goto the Strn Ref button click it goto down until you see Number is incorrect double click on it and close down the Strn Ref Window you'll see this * Possible StringData Ref from Code Obj ->"Number is incorrect" * Possible StringData Ref from Code Obj ->"The number is incorrect. The registered " ->"copy did not become activated." * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:0045F3EB(C) ok follow the (U)nconditional or (C)onditional Jump press shift + F12 enter 0045F3EB and you'll be here :0045F3E4 E897FEFFFF call 0045F280 <- Trace this call :0045F3E9 84C0 test al, al :0045F3EB 0F84F1000000 je 0045F4E2 trace the call press right arrow and you'll end up here now just keep looking true the code until you see a cmp and that just might the the one your looking for you'll say i'right later i know you will :0045F280 55 push ebp :0045F281 8BEC mov ebp, esp :0045F283 81C4F0FDFFFF add esp, FFFFFDF0 :0045F289 53 push ebx :0045F28A 56 push esi :0045F28B 57 push edi :0045F28C 8955F8 mov dword ptr [ebp-08], edx :0045F28F 8945FC mov dword ptr [ebp-04], eax :0045F292 8B45FC mov eax, dword ptr [ebp-04] :0045F295 E82E4BFAFF call 00403DC8 :0045F29A 8B45F8 mov eax, dword ptr [ebp-08] :0045F29D E8264BFAFF call 00403DC8 :0045F2A2 33C0 xor eax, eax :0045F2A4 55 push ebp :0045F2A5 6879F34500 push 0045F379 :0045F2AA 64FF30 push dword ptr fs:[eax] :0045F2AD 648920 mov dword ptr fs:[eax], esp :0045F2B0 C685F4FDFFFF00 mov byte ptr [ebp+FFFFFDF4], 00 :0045F2B7 BFC2080000 mov edi, 000008C2 :0045F2BC 8D85F4FEFFFF lea eax, dword ptr [ebp+FFFFFEF4] :0045F2C2 8B55FC mov edx, dword ptr [ebp-04] :0045F2C5 B9FF000000 mov ecx, 000000FF :0045F2CA E82149FAFF call 00403BF0 :0045F2CF 0FB6B5F4FEFFFF movzx esi, byte ptr [ebp+FFFFFEF4] :0045F2D6 85F6 test esi, esi :0045F2D8 7E3F jle 0045F319 :0045F2DA C745F401000000 mov [ebp-0C], 00000001 :0045F2E1 8D9DF5FEFFFF lea ebx, dword ptr [ebp+FFFFFEF5] you stop here now you remember i say you should look for a cmp well look down under what do you see ? yes it a cmp edi,eax good that the one :0045F342 8D55F4 lea edx, dword ptr [ebp-0C] :0045F345 8B45F8 mov eax, dword ptr [ebp-08] :0045F348 E8EB37FAFF call 00402B38 :0045F34D 3BF8 cmp edi, eax <-breakpoint on this one ok start Super Sensitive Disk-Scanner 98 v2.00.4.99 English Version goto register enter name dAvId/nIgHtMaRe'1 or any like and as code 123454 or any on you like now don't press ok yet go into soft-ice press ctrl+d or what every you hot key is place a breakpoint on hmemcpy bpx hmemcpy press ctrl+d press OK press F11 to leave kernl now keep pressing F12 until you in the code of of ssds_eng type bd * cuse you wont that break point bpx 0045F34D press x to leave soft-ice and it will break into this code :0045F348 E8EB37FAFF call 00402B38 :0045F34D 3BF8 cmp edi, eax do a ? eax you see your dummy code 123454 do a ? edi and you'll see your real code in my case 12434 do a bc * to clean the breakpoint on the cmp press F5 you'll get the error goto register enter name dAvId/nIgHtMaRe'1 and as code 12434 *boom* **regged** cool you cracked Super Sensitive Disk-Scanner 98 v2.00.4.99 English Version if you got any comments or questions send em to me if i got enough time i'll send you an e-mail back you might find me on irc/EFNET in the channel #c.i.a under the nick dAvId_nM1 if i got time i'll chat anyway i'hope you sea you in tutor #8 Cracking Tutorial #7 Written bY dAvid/nIgHtMaRe'1 On April 1999 wanna contact me yeah its possibal e-mail me at dAvIdnM1@usa.net PART 6: ~~~~~~ HOW TO CRACK Coolrun 2.0 bY dAvid/nIgHtMaRe'1 on April 1999 Welcome to my 8th Cracking Tutorial This time i'll teach you to how crack Coolrun 2.0 Sorry for my bad grammatic, but i hope u will under stand it anyway... Tools Used: W32Dasm 89.3 Soft-Ice 3.24 Far 1.52 or any other Norton Commander like clone 1 or more cups of coffee (A Pot will usualy do) you can also drink tea 1 or more ciggys (A Pack will usualy do) (Smoke em baby Smoke em) he he Where http://software.webset.de/cadkas/ Protection Type serial Crack Type Correct serial Ok Start Coolrun 2.0 you notice a nag that says you have 30 days left until it will expire unless you register sux goto register enter name dAvId/nIgHtMaRe'1 or Any Name you like and as code 123454 or any code you like you'll get an error message telling you <-Number is incorrect-> remember it goto far copy coolstart.exe to coolstart.w32 for use whit w32dasm start w32dasm and dissamble coolstart.w32 when dissambled goto the Strn Ref button click it goto down until you see Number is incorrect double click on it and close down the Strn Ref Window you'll see this * Possible StringData Ref from Code Obj ->"Number is incorrect" * Possible StringData Ref from Code Obj ->"The number is incorrect.The registered" ->"copy did not become activated." * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:0044F49B(C) ok follow the (U)nconditional or (C)onditional Jump press shift + F12 enter 0044F49B and you'll be here :0044F494 E897FEFFFF call 0044F330 <-trace this call :0044F499 84C0 test al, al :0044F49B 0F84F1000000 je 0044F592 trace the call press right arrow and you'll end up here now just keep looking true the code until you see a cmp and that just might the the one your looking for you'll say i'right later i know you will :0044F330 55 push ebp :0044F331 8BEC mov ebp, esp :0044F333 81C4F0FDFFFF add esp, FFFFFDF0 :0044F339 53 push ebx :0044F33A 56 push esi :0044F33B 57 push edi :0044F33C 8955F8 mov dword ptr [ebp-08], edx :0044F33F 8945FC mov dword ptr [ebp-04], eax :0044F342 8B45FC mov eax, dword ptr [ebp-04] :0044F345 E8BE49FBFF call 00403D08 :0044F34A 8B45F8 mov eax, dword ptr [ebp-08] :0044F34D E8B649FBFF call 00403D08 :0044F352 33C0 xor eax, eax :0044F354 55 push ebp :0044F355 6829F44400 push 0044F429 :0044F35A 64FF30 push dword ptr fs:[eax] :0044F35D 648920 mov dword ptr fs:[eax], esp :0044F360 C685F4FDFFFF00 mov byte ptr [ebp+FFFFFDF4], 00 :0044F367 BF43120000 mov edi, 00001243 :0044F36C 8D85F4FEFFFF lea eax, dword ptr [ebp+FFFFFEF4] :0044F372 8B55FC mov edx, dword ptr [ebp-04] :0044F375 B9FF000000 mov ecx, 000000FF :0044F37A E8B147FBFF call 00403B30 :0044F37F 0FB6B5F4FEFFFF movzx esi, byte ptr [ebp+FFFFFEF4] :0044F386 85F6 test esi, esi :0044F388 7E3F jle 0044F3C9 :0044F38A C745F401000000 mov [ebp-0C], 00000001 :0044F391 8D9DF5FEFFFF lea ebx, dword ptr [ebp+FFFFFEF5] you stop here now you remember i say you should look for a cmp well look down under what do you see ? yes it a cmp edi,eax good that the one :0044F3F2 8D55F4 lea edx, dword ptr [ebp-0C] :0044F3F5 8B45F8 mov eax, dword ptr [ebp-08] :0044F3F8 E89336FBFF call 00402A90 :0044F3FD 3BF8 cmp edi, eax <-breakpoint on this one ok start Coolrun 2.0 goto register enter name dAvId/nIgHtMaRe'1 or any like and as code 123454 or any on you like now don't press ok yet go into soft-ice press ctrl+d or what every you hot key is place a breakpoint on hmemcpy bpx hmemcpy press ctrl+d press OK press F11 to leave kernl now keep pressing F12 until you in the code of of coolstart type bd * cuse you wont need that break point bpx 0045F34D press x to leave soft-ice and it will break into this code :0044F3F8 E89336FBFF call 00402A90 :0044F3FD 3BF8 cmp edi, eax do a ? eax you see your dummy code 123454 do a ? edi and you'll see your real code in my case 14867 do a bc * to clean the breakpoint on the cmp press F5 you'll get the error goto register enter name dAvId/nIgHtMaRe'1 and as code 14867 *boom* **regged** cool you cracked Coolrun 2.0 if you got any comments or questions send em to me if i got enough time i'll send you an e-mail back you might find me on irc/EFNET in the channel #c.i.a under the nick dAvId_nM1 if i got time i'll chat anyway i'hope you sea you in tutor #9 Cracking Tutorial #8 Written bY dAvid/nIgHtMaRe'1 On April 1999 wanna contact me yeah its possibal e-mail me at dAvIdnM1@usa.net We really hope you've enjoyed this tutorial too much as we did! Don't miss Tutor #23 soon! ;) And as I said last time: Without knowledge, there's no power! ;) Credits go to: WhizKid for Splash Logo. dAvId/nIgHtMaRe for providing all the tuts in this version. tKC/CiA (hey it's me!) for coding this version :) All the crackers (non-members of CiA) are welcome to send tutors for the next tutorials .. see below for my email address! Greetz goto all my friends! You can find me on IRC or email me at tkc@reaper.org Oh btw, please don't expect me to reply your mails, since I get 50+/- mails everyday.. be sure that I really appreciate your mails! :) Coded by The Keyboard Caper - tKC The Founder of PhRoZeN CReW/Crackers in Action '99 Compiled on 1 May 1999 Cracking Tutorial #22 is dedicated to... umm.. *I wish I would know to whom I should dedicate* ...umm..ok.. to all the crackers *g*