Reverse Engineering RET Homepage RET Members Reverse Engineering Projects Reverse Engineering Papers Reversing Challenges Reverser Tools RET Re-Search Engine Reverse Engineering Forum Reverse Engineering Links

Go Back   Reverse Engineering Team Board > Reverse Engineering Board > Reverse Code Engineering
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
  #1  
Old 02-20-2010, 09:07 PM
Kama7 Kama7 is offline
Member
 
Join Date: Feb 2010
Posts: 9
Default Multikey 18.2.3 & reg file

I did my search and reading . I did it again and search again...

Can some body explain these term from a reg file :

"Option"=hex:01,01,02,4A,1F,00,00,00,00,00,00, 00
what does it mean ???? please explain in details if you can .

"NetMemory"=hex:05,00,80,00,02,FF,00,00,FF,FF,FD,F F

what does it mean ???? please explain in details if you can .

"SecTable"=hex:9A,21,2C,25,DE,65,6C,65
what does it mean ???? please explain in details if you can .

I really appreciate anyone who can spend time to help

[Don't reply to your own posts, use the Edit button if you have something to add]

Thank You
Peace

Last edited by Git : 02-21-2010 at 07:09 AM.
Reply With Quote
  #2  
Old 02-21-2010, 07:10 AM
elite.r elite.r is offline
Member
 
Join Date: Mar 2008
Posts: 17
Default

Read the manual for multikey.
Reply With Quote
  #3  
Old 02-21-2010, 09:46 AM
SonofabiT SonofabiT is offline
Senior Member
 
Join Date: Dec 2008
Posts: 351
Default

@Kama7 - See a typical Hasp dump here.

Reference : http://hungosh.fatal.ru

Last edited by SonofabiT : 11-04-2010 at 08:50 AM.
Reply With Quote
  #4  
Old 02-21-2010, 05:13 PM
Kama7 Kama7 is offline
Member
 
Join Date: Feb 2010
Posts: 9
Default

elite.r : You go read the manual and maybe you will understand what I am asking for .

Sonofabit : Thank You for the image . It is very helpful , it is infac exactly what i am looking for .
I would like to study the dump file for HASPHL2010,HASPHL2009and make a small program to convert it to dng for everybody to use.
Any sugestion or contribution is welcome

Thank you again Sonofabit - People like you make this forum rock
Reply With Quote
  #5  
Old 02-21-2010, 05:49 PM
gnerogeem gnerogeem is offline
Senior Member
 
Join Date: Aug 2009
Location: Kalimdor
Posts: 553
Default

@Kama7
Do you know who is elite.r?
He is the creator of the Multikey that you been using for free right now.
So before flaming him, please RTFM!
Seriously, you sir are unmannered.
__________________
Pink is the new black.
Reply With Quote
  #6  
Old 02-21-2010, 06:08 PM
Kama7 Kama7 is offline
Member
 
Join Date: Feb 2010
Posts: 9
Default

gnerogeem: I dont' think so - proof it !

- I don't use Multikey and even if he is the creator of multikey he need to learn how to talk nicely to people before he learn programming
Reply With Quote
  #7  
Old 02-21-2010, 06:15 PM
Git Git is offline
Super Moderator
 
Join Date: Oct 2007
Location: Torino
Posts: 1,797
Default

Yes, he is the author, and yes, his request is bang on the mark. All the info you need is in the manual - why don't you just read it instead of expecting other people to do so for you?

Git
Reply With Quote
  #8  
Old 02-21-2010, 06:23 PM
Kama7 Kama7 is offline
Member
 
Join Date: Feb 2010
Posts: 9
Default

OK GIT

I search for the manual and I read this :

1A - HASP4 Time
EA - HASP HL
DA - HASP HL Time

"Memory" = dword: 00000001 - the size of memory

"SecTable" = hex: 00,00,00,00,00,00,00,00 - Reserved table

"NetMemory" = hex: 03,00,0 F, D0, 02,00,00,00, FF, FF, FE, FF - cell "network" memory

"Option" = hex: 00,00,00,00,00,00,00,00,00,00,00,00,00,00 - additional options:

[0] = 0x69 - work without time delay tables crypto-key dekriptov HaspHL.

"Data" = hex: - a memory

"ColumnMask" = dword: 000000FF

"CryptInitVect" = dword: 0000003F

Tabular emulated functions hasp_decrypt + hasp_encrypt, in the absence of values in tables
values are processed by the Inland AES agoritmu. If necessary, change defoltnogo
key AES algorithm to make a reg file its value:

"AesKey" = hex: 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

Tables are arranged in podvetkah core dump location:
Decrypt: [HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ MultiKey \ Dumps \ 12345604 \ DTable];


All I am looking for is some more clarification any additional informations which someone out there may know .

Thank You Git ... not everybody here is lazy and want a free ride for solution . Sometimes we have to believe that there still
people out there with a good heart .

Peace
Reply With Quote
  #9  
Old 02-22-2010, 05:59 AM
elite.r elite.r is offline
Member
 
Join Date: Mar 2008
Posts: 17
Default

@Kama7
Simply ask questions more particularly ))

"Option" is in general individually for each type of emulators

Typical contents NetMemory USB of a HASP-key:
Offset: 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F
Data : 12 1A 12 0F 03 00 70 00 02 FF 00 00 FF FF FF FF
Decoding:
12 1A 12 0F - Serial number a key
03 00 - the Coded type of a key?
70 00 - a key Memory size in bytes
02 FF-?
00 00 - Quantity of users for a network key (00 00 - local)
FF FF-?
FF - key Type (FF - local, FE - Net, FD - Time)
FF-?

"SecTable" - solver makes this data from keydump
(Or still to show source codes as it becomes?)
Reply With Quote
  #10  
Old 02-22-2010, 04:24 PM
Kama7 Kama7 is offline
Member
 
Join Date: Feb 2010
Posts: 9
Default

Elite.r :

I detected a slightly imperfect in the command of the English language . ( I am myself is using English as my third language ).

but Thank You Elite.r for your reply and your patient .

I am always grateful with peoples who devoted their times and efford to share knowleges .

It is their unselfishness and kindness which make our world today a better place to live .

With respect

Kama7
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump





Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2020, Jelsoft Enterprises Ltd.