<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gudasoft &#187; cracking</title>
	<atom:link href="http://www.gudasoft.com/tag/cracking/feed" rel="self" type="application/rss+xml" />
	<link>http://www.gudasoft.com</link>
	<description>Impossible is nothing</description>
	<lastBuildDate>Thu, 06 Oct 2011 07:17:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>How to help your self if the windows expires</title>
		<link>http://www.gudasoft.com/uncategorized/04/20/485/windows-activation/2009</link>
		<comments>http://www.gudasoft.com/uncategorized/04/20/485/windows-activation/2009#comments</comments>
		<pubDate>Mon, 20 Apr 2009 19:19:19 +0000</pubDate>
		<dc:creator>guda</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cracking/hacking]]></category>
		<category><![CDATA[cracking]]></category>

		<guid isPermaLink="false">http://www.gudasoft.com/?p=485</guid>
		<description><![CDATA[What is your key that you are using: http://magicaljellybean.com/keyfinder/ Activation console: oobe/msoobe /a Manual method http://www.computing.net/answers/windows-xp/windows-activation-expired/159468.html I have searched in Internet for some activation removal tools like RESET 5 but I cant find any active online. How to login in expired windows: click login try pressing WIN-U keys to bring out the Narrator dialog box. Then [...]]]></description>
			<content:encoded><![CDATA[<p>What is your key that you are using:</p>
<ul>
<li>http://magicaljellybean.com/keyfinder/</li>
</ul>
<p>Activation console:</p>
<ul>
<li>oobe/msoobe /a</li>
<li><a href="http://www.chervenbriag.com/index.php?topic=109.0">Manual method</a></li>
<li><a href="http://www.computing.net/answers/windows-xp/windows-activation-expired/159468.html">http://www.computing.net/answers/windows-xp/windows-activation-expired/159468.html</a></li>
</ul>
<p>I have searched in Internet for some activation removal tools like RESET 5 but I cant find any active online.</p>
<p>How to login in expired windows:</p>
<ul>
<li>click login try pressing WIN-U keys to bring out the Narrator dialog box. Then on the menu in the left, click <em>About</em> then click on the link for Microsoft website. IE will launch (not tested)</li>
<li>Or you could just go into safe mode with a DOS prompt; type explorer.exe and have a full safe mode machine running allowing you to bypass the activation with a hack</li>
</ul>
<p>The conclusion is:</p>
<p>Use the aways the latest windows version. Turn off the windows updates to be not surprised bad.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gudasoft.com/uncategorized/04/20/485/windows-activation/2009/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Some Bad Ideas</title>
		<link>http://www.gudasoft.com/uncategorized/01/13/463/some-bad-ideas/2009</link>
		<comments>http://www.gudasoft.com/uncategorized/01/13/463/some-bad-ideas/2009#comments</comments>
		<pubDate>Tue, 13 Jan 2009 21:26:27 +0000</pubDate>
		<dc:creator>guda</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cracking]]></category>

		<guid isPermaLink="false">http://www.gudasoft.com/?p=463</guid>
		<description><![CDATA[Today we think with my colegue Vergil what will happend if we make/prepare an ISO file for the latest Windows Vista, install a keylogger, trojans and antivirus software (patched/setupped to ignore the installed keylogger). Then put some good programs, make some fancy changes and upload it as free downloading version world wide. Brrrr. That sounds [...]]]></description>
			<content:encoded><![CDATA[<p>Today we think with my colegue Vergil what will happend if we make/prepare an ISO file for the latest Windows Vista, install a keylogger, trojans and antivirus software (patched/setupped to ignore the installed keylogger). Then put some good programs, make some fancy changes and upload it as free downloading version world wide.</p>
<p>Brrrr. That sounds awfull. I am using such boosted/patched windowses. Maybe my life belongs to someone</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gudasoft.com/uncategorized/01/13/463/some-bad-ideas/2009/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My first trojan</title>
		<link>http://www.gudasoft.com/english/development/01/03/385/my-first-trojan/2009</link>
		<comments>http://www.gudasoft.com/english/development/01/03/385/my-first-trojan/2009#comments</comments>
		<pubDate>Sat, 03 Jan 2009 16:30:48 +0000</pubDate>
		<dc:creator>guda</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[cracking/hacking]]></category>
		<category><![CDATA[cracking]]></category>

		<guid isPermaLink="false">http://www.gudasoft.com/?p=385</guid>
		<description><![CDATA[Recently I have found my first trojan on my hard disk. it is called 300lv because one bastered have taken from me 300lv to buy me cheap fdd-diskets and forgets to return me the money and the disketts. So I have written this small self-installing app in return. here it is for free download &#8230; [...]]]></description>
			<content:encoded><![CDATA[<p>Recently I have found my first trojan on my hard disk.</p>
<p>it is called 300lv because one bastered have taken from me 300lv to buy me cheap fdd-diskets and forgets to return me the money and the disketts.</p>
<p>So I have written this small self-installing app in return.</p>
<p>here it is for free download &#8230;</p>
<p><a href="http://www.gudasoft.com/wp-content/uploads/2009/01/300lv.arj">300lv</a></p>
<p>Awards: It is honered by the Bulgarian Academy Antivirus software.</p>
<p>The story continues. This code has no self-replication code in it. But in Bulgaria it seems that people like to do tricks to themselfs so after 2 years I have infected with my own trojan :)</p>
<p> </p>
<p>And another of my friends has gone with his infected computer in the police asking them to arrest me /he doesnt know that I am the author of the trojan/ I was lucky that it was before 1994 and the police is sleeping.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gudasoft.com/english/development/01/03/385/my-first-trojan/2009/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Debuggers</title>
		<link>http://www.gudasoft.com/uncategorized/01/03/33/debuggers/2009</link>
		<comments>http://www.gudasoft.com/uncategorized/01/03/33/debuggers/2009#comments</comments>
		<pubDate>Sat, 03 Jan 2009 13:39:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cracking]]></category>

		<guid isPermaLink="false">http://blog.gudasoft.com/?p=33</guid>
		<description><![CDATA[In my example I will try to find the best tools for debugging windows programs. General plan for cracking a program install the program search for already made cracks for this version astalavista.box.sk check what type of protection it has search for universal patch/cracks/dongle emulators Try Define the right terms Debuggers http://en.wikipedia.org/wiki/Debugger#External_links KERNEL &#8211; http://rr0d.droids-corp.org/ [...]]]></description>
			<content:encoded><![CDATA[<p>In my example I will try to find the best tools for debugging windows programs.</p>
<p>General plan for cracking a program</p>
<ul>
<li> install the program</li>
<li>search for already made cracks for this version
<ul>
<li>astalavista.box.sk</li>
</ul>
</li>
<li> check what type of protection it has</li>
<li> search for universal patch/cracks/dongle emulators</li>
<li>Try</li>
</ul>
<p>Define the right terms</p>
<ul>
<li>Debuggers
<ul>
<li>http://en.wikipedia.org/wiki/Debugger#External_links</li>
<li>KERNEL &#8211; http://rr0d.droids-corp.org/</li>
<li>Oly &#8211; http://www.ollydbg.de/download.htm</li>
</ul>
</li>
<li>Portals
<ul>
<li>http://www.openrce.org/downloads/</li>
<li><a href="http://game-hacks.xzone-bg.com/profile.php?lookup=5890">bg: http://game-hacks.xzone-bg.com/profile.php?lookup=5890</a></li>
</ul>
</li>
</ul>
<p>Symbols win32 http://www.microsoft.com/whdc/devtools/debugging/symbolpkg.mspx#d</p>
<ul></ul>
]]></content:encoded>
			<wfw:commentRss>http://www.gudasoft.com/uncategorized/01/03/33/debuggers/2009/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking Tools</title>
		<link>http://www.gudasoft.com/english/software/crackinghacking/09/05/119/hacking-tools/2008</link>
		<comments>http://www.gudasoft.com/english/software/crackinghacking/09/05/119/hacking-tools/2008#comments</comments>
		<pubDate>Fri, 05 Sep 2008 21:24:54 +0000</pubDate>
		<dc:creator>guda</dc:creator>
				<category><![CDATA[cracking/hacking]]></category>
		<category><![CDATA[cracking]]></category>

		<guid isPermaLink="false">http://www.gudasoft.com/?p=119</guid>
		<description><![CDATA[Hack distributions BackTrack is the most Top rated linux live distribution focused on penetration testing. NST Steganos Hacker Tools here -&#62; (E-mail: www@serials.ws Name: www.serials.ws Serial: 50GWR0N-F71A39F) &#60;- hidden text here Metasploit &#8211; in ruby (huh?!) videos TOP100 tools exploit search list &#8211; > http://milw0rm.com/links/]]></description>
			<content:encoded><![CDATA[<p>Hack distributions</p>
<ul>
<li><a href="http://www.remote-exploit.org/backtrack.html">BackTrack </a>is the most Top rated linux live distribution focused on penetration testing.</li>
<li><a href="http://www.networksecuritytoolkit.org/nst/index.html">NST</a></li>
<li>Steganos Hacker Tools here  -&gt;
<div style="display:none">(E-mail: www@serials.ws Name: www.serials.ws Serial: 50GWR0N-F71A39F)</div>
<p>&lt;- hidden text here</li>
</ul>
<p><a href="http://www.metasploit.com/">Metasploit</a> &#8211; in ruby (huh?!) <a href="http://www.metasploit.org/framework/gallery/">videos</a></p>
<p><a href="http://sectools.org/">TOP100 tools</a></p>
<p>exploit search list &#8211; > http://milw0rm.com/links/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gudasoft.com/english/software/crackinghacking/09/05/119/hacking-tools/2008/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Back to the crack scene</title>
		<link>http://www.gudasoft.com/uncategorized/07/13/85/back-to-the-crack-scene/2008</link>
		<comments>http://www.gudasoft.com/uncategorized/07/13/85/back-to-the-crack-scene/2008#comments</comments>
		<pubDate>Sun, 13 Jul 2008 11:41:57 +0000</pubDate>
		<dc:creator>guda</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cracking]]></category>

		<guid isPermaLink="false">http://www.gudasoft.com/?p=85</guid>
		<description><![CDATA[I have cracked one bulgarian software for window I have used ollydbg. The steps were: I want to attach on &#8220;Start&#8221; button, but it was in cyrillic so I have to start some resource editor to change the text to latin characters. I have put a breakpoint on the start handle and button messages I [...]]]></description>
			<content:encoded><![CDATA[<p>I have cracked one bulgarian <a href="http://dogrami.hit.bg/">software for window</a></p>
<p><span id="more-85"></span></p>
<p>I have used ollydbg.</p>
<p>The steps were:</p>
<ol>
<li>I want to attach on &#8220;Start&#8221; button, but it was in cyrillic so I have to start some resource editor to change the text to latin characters.</li>
<li>I have put a breakpoint on the start handle and button messages</li>
<li>I got the message &#8220;Good bye&#8221; from the program.<br />
NEVER put such a messages in your program if you want to survive longer. It is better to quit silently instead of point to the cracker &#8220;Here, here, crack me, please&#8221;.</li>
<li>I have run Boarland Decompiler, check the address where &#8220;Good bye&#8221; is used, and I have put a breakpointer there.</li>
<li>Then bypass the &#8220;protection&#8221; by making the jnz to jmp</li>
<li>save the executable to have in this stable state</li>
</ol>
<p>Then it was simple. The code was in memory. But how I could be able to show it to the poor users? I have decided to use memory viewer and put some instructions there&#8230;.not good. not nice. Then I have a plan. There was a button &#8220;Instructions for registrations&#8221; I thoutgh that this is the perfect place to give the real instructions for registrations and show the code there :)</p>
<ol>
<li>Some googling on how to display MessageBoxA and I have found this example <a href="http://www.reversing.be/article.php?story=20060112212536583">here </a>. \</li>
<li>Then I have replaced the end of the &#8220;Instructions for registrations&#8221; function with the following code</li>
</ol>
<pre><code>
0047F903     A1 6C694800    MOV EAX,DWORD PTR DS:[48696C]
0047F908     6A 00          PUSH 0
0047F90A     50             PUSH EAX
0047F90B     50             PUSH EAX
0047F90C     6A 00          PUSH 0
0047F90E     E8 EF0DFD7D    CALL user32.MessageBoxA
0047F913     A1 70694800    MOV EAX,DWORD PTR DS:[486970]
0047F918     6A 00          PUSH 0
0047F91A     50             PUSH EAX
0047F91B     50             PUSH EAX
0047F91C     6A 00          PUSH 0
0047F91E     E8 DF0DFD7D    CALL user32.MessageBoxA
0047F923     A1 74694800    MOV EAX,DWORD PTR DS:[486974]
0047F928     6A 00          PUSH 0
0047F92A     50             PUSH EAX
0047F92B     50             PUSH EAX
0047F92C     6A 00          PUSH 0
0047F92E     E8 CF0DFD7D    CALL user32.MessageBoxA
0047F933     A1 78694800    MOV EAX,DWORD PTR DS:[486978]
0047F938     6A 00          PUSH 0
0047F93A     50             PUSH EAX
0047F93B     50             PUSH EAX
0047F93C     6A 00          PUSH 0
0047F93E     E8 BF0DFD7D    CALL user32.MessageBoxA
0047F943     90             NOP
0047F944     90             NOP                                      ; |

nop-ping till the end of the function here...

0047FA39     90             NOP
0047FA3A     90             NOP
0047FA3B     90             NOP
0047FA3C   . 5E             POP ESI
0047FA3D   &gt; 5B             POP EBX
0047FA3E   . C3             RETN

</code></pre>
<p>Then save the patched file from ollydebug.</p>
<p>Final notes.</p>
<p>I am not happy on what I have done. I am writing also software and I know what means someone to crack your software. So I will publish the crack here but you should find it yourself. It is simple protection for the users which don&#8217;t want to pay :)</p>
<div style="display: none"><a href="http://www.gudasoft.com/wp-content/uploads/2008/07/dogrami-crack.zip">dogrami-crack</a><br />
&#8211;&gt;</div>
]]></content:encoded>
			<wfw:commentRss>http://www.gudasoft.com/uncategorized/07/13/85/back-to-the-crack-scene/2008/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

