Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!

cracked.io | Best Forum Around | Free Premium Accounts




 49002

ChessBotX 1.6.1s Latest Version (Uncracked)

by phantompainn - 03 May, 2022 - 05:39 AM
This post is by a banned member (phantompainn) - Unhide
6
Posts
1
Threads
3 Years of service
#1
(This post was last modified: 03 May, 2022 - 05:40 AM by phantompainn.)
From Cracklab user "vladtheimpaler"

There are both DEMO and full version of the product.
Full version requires registration key without it quits when you try to play.
Only demo version can be downloaded for free.

I did not bother with the demo version since I found a full version on the internet!

Bot is written in Delphi7-compiled in Boreland Delphi

Packer: Unknown, DiE shows VMP (perhaps false), other detectors do not show any.
The program has segment with the .upx0 tag but I was unable to unpack it using upx -d
After I unpacked it with QuickUnpack I did not look any further into the protection and

instead I went to look for the licensing method.

1st Phase - Activation:

After many hours I found out that the licensing method goes something like this:
-the license registration key is stored within /System/sysdump64.sys file,
-it is 25key string like this "123456789qwertyuiopasdfgh"(example)
-then only few parts of the key are being sent:
dbf=12345qwert&dlc=yu&(22 key)
as GET request to the address "http: //chess-cheat(dot)com/test.php"
-after that the site returns a response of 45key string (different one each time):
"2e739ef0b22befa8f69339da8fb3bc1c76891134474A0" (example)
at Address 00670B07

which is made of two parts the first one being a md5 encryption
2e739ef0b22befa8f69339da8fb3bc1c = of what it seems like a random 6figure number 117890(in
this example) and the second one looking like DES decryption 76891134474A0 (not sure)

-> Then the first part(32 md5 hash) is being compared with the md5 hash of this part of
our registration key "12345qwert" = (B1EF741BEE14A29ACBE5686F59B62569).
Overwriting the strings in memory to make them equal made the program registered (it did
not quit anymore and the color indicator changed from yellow to green)
comparison is made at Address: 004053C7

2nd Phase - Make it play:

Unfortunately patching the registration key in memory did not made it possible to play
because what happens when we press the play button is that there is another string comparsion.

-This time we send 45string "dbf=12345qwert&dlc=yu&website=lichess%2Eorg&T" as POST
request to a different address "http: //chess-cheat(dot)com/set.php"
which returns us a 55string (different each time) like this:

"a43211144d28e83bb92a01329e75142d24215875894534878A0O622"
which also has 32md5 hash as a starting point.
the issue here is that I couldn't find the right place of the comparison.
overwriting the starting md5 of this 55key with the md5 hash of the 10string of our key
did not patch it giving us a messagebox with "Chessboard not found"

Download: https://easyupload.io/440j58


Any help or pointers are helpful and welcome!

Questions:

1. Is the automatic unpacking of QuickUnpack enough or should I look more into the packer and try to do it manually?

2. Can we find a way to redirect the registration website with one of ours that will give us the wanted response?

3. Even if we manage to patch it in memory will there be a way to make a loader of it? Is that possible even if the memory addresses of the stored strings are different eachtime.
This post is by a banned member (Ulubatli_Hasan) - Unhide
45
Posts
0
Threads
1 Year of service
#2
I don't know anything about these issues, I just want this bot to be cracked
This post is by a banned member (phantompainn) - Unhide
6
Posts
1
Threads
3 Years of service
#3
(03 May, 2022 - 09:30 AM)Ulubatli_Hasan Wrote: Show More
I don't know anything about these issues, I just want this bot to be cracked

That's what we're trying to do
This post is by a banned member (phantompainn) - Unhide
6
Posts
1
Threads
3 Years of service
Bumped #4
This is a bump
This post is by a banned member (Ulubatli_Hasan) - Unhide
45
Posts
0
Threads
1 Year of service
#5
(04 May, 2022 - 01:05 PM)phantompainn Wrote: Show More
This is a bump
i found this, the register part is passed but it doesn't read the board https://anonfiles.com/L8T4X7c5y4/ChessBotX_1.5.8f_rar
This post is by a banned member (auralol) - Unhide
auralol  
Registered
78
Posts
0
Threads
3 Years of service
#6
(04 May, 2022 - 01:58 PM)Ulubatli_Hasan Wrote: Show More
(04 May, 2022 - 01:05 PM)phantompainn Wrote: Show More
This is a bump
i found this, the register part is passed but it doesn't read the board https://anonfiles.com/L8T4X7c5y4/ChessBotX_1.5.8f_rar

have you  gotten it to read thee board to this day or is it still not working?
This post is by a banned member (Ulubatli_Hasan) - Unhide
45
Posts
0
Threads
1 Year of service
#7
(13 May, 2022 - 06:02 PM)auralol Wrote: Show More
(04 May, 2022 - 01:58 PM)Ulubatli_Hasan Wrote: Show More
(04 May, 2022 - 01:05 PM)phantompainn Wrote: Show More
This is a bump
i found this, the register part is passed but it doesn't read the board https://anonfiles.com/L8T4X7c5y4/ChessBotX_1.5.8f_rar

have you  gotten it to read thee board to this day or is it still not working?
no unfortunately it still doesn't work
This post is by a banned member (sluxe30) - Unhide
sluxe30  
Registered
38
Posts
0
Threads
1 Year of service
#8
nothing yet? I really wanted this bot

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 2 Guest(s)