当前位置:网站首页>Crack the simple login system with NOP method

Crack the simple login system with NOP method

2022-06-21 06:54:00 There is no sound in the wind

Catalog

One . Crack the object

Two . Preliminary analysis

3、 ... and . use OD debug


One . Crack the object

A simple login system ( Please test in a legal environment ).

Two . Preliminary analysis

After trying , We found that the login window has only three login opportunities .

Unsuccessful login each time , There will be “ user Wrong password also n Second chance ” Tips .

3、 ... and . use OD debug

OD: One 32 Bit assembly analysis debugger

OD website :OllyDbg Chinese station

First drag the login system into OD( Or use OD open ).

Enter the string search interface ( Right click — Chinese search engine — Intelligent search ).

By preliminary analysis , We get “ user Wrong password also n Second chance ” keyword , Try searching this string , So as to determine the relevant process .

ps: It is not recommended to search a string in a whole sentence , It is recommended to search for some keywords , Because the string display may be split into multiple lines .

Successfully found the relevant string , Double click this line to return to the debugging page .

 

Then start looking for key points .

Found a jump to the line before the key string , And the conditions hold , perform .

ps: The jump arrow shows Red Then the condition holds , Indicates execution ; The jump arrow is grayed out , Don't execute .

 

Look down again .

Found the second jump , Skip key strings directly , And the conditions hold , perform .

Compare the two jumps , We found that the first jump is the key jump , Because it skips " Landing successful " link .

We came to the first jump , Lower breakpoint ( Switch ).

 

 

Back to the system , No response after entering the password , The system is suspended .

In this case, you can directly execute the empty instruction , Invalidate a jump , Do the following .

( Right healthy - Binary system - use NDP fill )

Back to the system , You can log in directly .


原网站

版权声明
本文为[There is no sound in the wind]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/172/202206210616294286.html