0x03 Afkayas_2
单步走找到对应name:name
的serial:1066990
接下来写注册机,先看算法:
第一步跟上一题一样:
004081F2 | 50 | push eax | eax:L"355662"
004081F3 | 8B1A | mov ebx,dword ptr ds:[edx] | edx:L"355662"
004081F5 | FF15 F8B04000 | call dword ptr ds:[<&__vbaLenBstr>] | 获取name字段长度
004081FB | 8BF8 | mov edi,eax | edi:L"-1-0", eax:L"355662"
004081FD | 8B4D E8 | mov ecx,dword ptr ss:[ebp-18] | [ebp-18]:L"name"
00408200 | 69FF 385B0100 | imul edi,edi,15B38 | strlen(name)*0x15b38=0x56ce0
00408206 | 51