U E D R , A S I H C RSS

이영호/n Protect Reverse Engineering

( ZeroWiki http://www.dasomnetwork.com/~leedw/ . .)
. ZeroWiki ? . . . .
. , , , . . . ? -- Leonardong
Cracking 하 nProtect 해하 .

: (Mabinogi)
Protector : guardcat nProtect 행하

# 1
nexon Protector .
nProtect guardcat 행하 .
( nProtect hooking, 포함 ,
nProtect 포함 Exception Handling .)

guardcat EnumServicesStatusA Process OpenProcess debug .
, OpenProcess Process Hooking하 gc_proch.dll .
=> guardcat.exe -> gc_proch.dll
행하 , 트 파 , 파 .
트 파 host patch eady.sarang.net/~dark/12/Mabi/ 3
. 행히 guardcat Packing, Enchypher 한 encoding .

# 2
=> gcupdater -> guardcat.exe -> gc_proch.dll
guardcat.exe 행하 gc_proch.dll hooking .
!!! gc_proch.dll .
gc_proch.dll 파 행하 gaurdcat.exe debugger .
update . gc_proch.dll mabinogi.exe .

=> mabinogi.exe -> client.exe -> gcupdater -> guardcat.exe -> gc_proch.dll
.
2 ...
1. mabinogi.exe( . createprocess client.exe 행하 .)
2. client.exe(client , gameguard . . 1. -확 , . 2. Debugger Process Check.- . 3. gcupdater.exe . 4. createprocess gcupdater 행한. 5. 행하 gcupdater IPC 할 thread .)
3. gcupdater( 3 . guardcat.exe, INST.dat, gc_proch.dll wsprintf .- API . createprocess guardcat.exe .)
4. guardcat.exe( EnumServicesStatusA Process List gc_proch.dll 파 IPC . Process 크하 gc_proch.dll . 한 IPC 통해 client.exe Exception .)
5. gc_proch.dll( debugger . .) -> dll injection .

# 3
key client.exe .
client.exe , , updater 통한 protector mabinogi .
client.exe gcupdater.exe . , .

zeropage ( google .)

-------------------------------------
mabinogi.exe -> client.exe

CreateProcess()
|ModuleFileName = NULL
|CommandLine = ""C:\Program Files\Mabinogi\client.exe" code:1622 ver:237 logip:211.218.233.200 logport:11000 chatip:211.218.233.192 chatport:8000 setting:"file://data/features.xml=Regular, Korea""
|pProcessSecurity = NULL
|pThreadSecurity = NULL
|InheritHandles = FALSE
|CreationFlags = 0
|pEnvironment = NULL
|CurrentDir = "C:\Program Files\Mabinogi"
|pStartupInfo = 0012E4F0
|pProcessInfo = 0012E4E0

client.exe code:1622 ver:237 logip:211.218.233.200 logport:11000 chatip:211.218.233.192 chatport:8000 setting:"file://data/features.xml=Regular, Korea" .
-------------------------------------

reverse engineering .
Protector cracking . -_-^
Valid XHTML 1.0! Valid CSS! powered by MoniWiki
last modified 2021-02-07 05:30:32
Processing time 0.0556 sec