[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: help with deprotecting Catalyst 3.0



Bryan Parkoff <nospam@nospam.com> wrote:
>     There is a possibility that Open-Apple-Control-Reset can wipe memory 
> with all zeroes to boot slave disk from ProDOS.  It is because RESET vector 
> is located in $3F0 to $3FF (I can't remember which one).  If you are lucky 
> to have Apple II with monitor ROM which it does not have AutoStart ROM, it 
> would be much easier to deprotect all copy protected disks.  Monitor ROM 
> does not wipe memory with all zeroes.  You can only hit RESET key, it 
> prompts "*" as assembly prompt.  It does nothing without going through any 
> routines like BASIC to overwrite memory.
>     Some hackers can be able to crack using Apple II with monitor ROM, but 
> it can be very difficult on Apple //e.  I hope that it helps.

Actually, it can be very easy on an Apple //e.  There's a trick where you
map the memory on the extended 80-column card into main memory, and boot
a disk.  When you hit reset, the Apple //e switches back to the "real"
main memory before chasing the reset vector at $3f2.  You're left sitting
at a DOS prompt with the entire program in aux mem.

I believe the Computist article on the subject was about cracking Apple's
version of Adventure.

-- 
Send mail to fadden@fadden.com (Andy McFadden) - http://www.fadden.com/
CD-Recordable FAQ - http://www.cdrfaq.org/
CiderPress Apple II archive utility for Windows - http://www.faddensoft.com/
Fight Internet Spam - http://spam.abuse.net/spam/ & http://spamcop.net/