[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Gertrude's secrets (TLC) now available



For convenience, here's Antoine's full method from howtocrack.rtf:

********************

1. Check the format
- Launch Copy II+, bit-copy mode and edit all tracks
=> Epilog markers are all changed and give the following information:
- Header markers: D5AA96 Fx Fx EB (instead of D5AA96 DEAAEB)
- Data markers: D5AAAD Fx Fx EB (instead of D5AAAD DEAAEB)
=> The diskette is not entirely formatted
- Only tracks $00 to $12 are formatted, the rest is garbage


2. Make a copy
As epilog markers were changed, we can either enter the usual B942:18
thing or bypass the check of the epilog markers (it speeds up the
copy)
- Launch Advanced Demuffin 1.4
- Go to the monitor
- B930: 18 60
- B98B: 18 60
- Press CTRL-Y
- Copy 16-sec tracks $00 to $12


3. Test the copy
Boot the copy, beep, it reboots, there's a check…


4. Please boot trace (on a IIgs)
- Go to the monitor (CALL -151)
- 9600<C600.C6FFM
- 96FB: A9 59 8D 84B A9 FF 8D 84C 4C 801
- 9600G
(beep)

Now, let's analyze the code at the usual RWTS place (from
$B700..$BFFF): at $B700, there is a call to $BB00.

At $BB00, a routine moves the $BB00..$BBFF area to $0200 and returns
from the subroutine. Weird…

Let's analyze the code at $BB0C (real address $020C)… It is a
desynchro protection, similar to the Epyx ones (funny, another shared
protection)

The principle is easy: the code reads some valid nibbles, adds some
cycles to desync the Logic State Sequencer and then reads other non-
valid nibbles (here E7 E7 EE). Then it reads eight nibbles and compare
them to the ones in its table (E7 FC EE E7 FC EE EE FC)

It the values are found, we have an original diskette. If not, it is a
copy, it clears the RAM area and reboots.

If it is an original disk, it patches values in RAM and puts #$80 at
$9E4E and #$A1 at $9E4F and jumps to $9E4D (note 1 for later)


5. How to remove the check
We know the first boot steps: $0801 (boot1) then $B700 then $BB00
(install the check) then the usual DOS 3.3 steps.

We need to find where the $020C routine is called. We have three major
ways: a JSR, a JMP or an indirect call.

To ease our life, we will search for the following pattern 0C 02
(instead of 4C 0C 02 or 20 0C 02)
- Launch Disk Fixer
- Press F (Find)
- Press H (Hexa)
- Enter 0C02
=> We have three results:
- Track 0 / Sector B / Offset 4E
- Track 10/F/31
- Track 12/D/3C
=> The last two findings are parts of a track/sector list of a DOS 3.3
file. We will focus on the first entry.

- Press R (Read) to read T0 / SB with Disk Fixer
- Move to offset 38 and press L to disassemble
=> At $4D, we have a 4C 0C 02 (JMP $020C)

We have found it!  We replace 4C 0C 02 with 4C 80 A1 (see note 1
above)

6. Make a clean crack
We may also want to save cycles by bypassing the installation of the
protection check!
- Launch Disk Fixer
- Read T0/S1
- At offset $0, replace 20 00 BB (JSR $BB00) with 2C 00 BB (BIT $BB00)
- Save the sector back to disk


7. Are there other ways to crack it?
Yes, rewrite the $BB00 (real address $0200) routine. Or install a real
DOS 3.3 (not tested)


Reboot and enjoy!

Antoine "LoGo" Vignau
Brutal Deluxe Software