Reverse Engineering RET Homepage RET Members Reverse Engineering Projects Reverse Engineering Papers Reversing Challenges Reverser Tools RET Re-Search Engine Reverse Engineering Forum Reverse Engineering Links

Go Back   Reverse Engineering Team Board > Reverse Engineering Board > Reverse Code Engineering
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
  #11  
Old 06-06-2009, 08:23 AM
iksi iksi is offline
Member
 
Join Date: Apr 2008
Posts: 36
Default

Ok. here is reg file:

REGEDIT4



[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Dongle s\Services\MyLittleKeys\Dump\31BC6B07]

"Name"=""

"Copyright"=""

"SN"=dword:0018B008

"DongleType"=dword:00000002

"Type"=dword:000000EA

"Memory"=dword:00000000

"NetMemory"=hex:8C,F4,12,00,00,00,00,00,00,00,00,0 0

"SecTable"=hex:3C,C1,5F,C3,74,C1,57,C3

"ColumnMask"=dword:0000009B

"CryptInitVect"=dword:00000010

"Data"=hex:\

00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00


Now where must import encription and decription table if necesary?
Reply With Quote
  #12  
Old 06-06-2009, 08:32 AM
Git Git is offline
Super Moderator
 
Join Date: Oct 2007
Location: Torino
Posts: 1,797
Default

>> "Memory"=dword:00000000 <<

Git
Reply With Quote
  #13  
Old 06-06-2009, 08:46 AM
iksi iksi is offline
Member
 
Join Date: Apr 2008
Posts: 36
Default

Quote:
Originally Posted by SonofabiT View Post
@iksi
Did you get a hasp.dmp with file size 719 bytes from nodongle.biz's h5dmp.exe v 1.41 ?
Yes dump size is 719 bites.
Reply With Quote
  #14  
Old 06-06-2009, 08:53 AM
iksi iksi is offline
Member
 
Join Date: Apr 2008
Posts: 36
Default

Quote:
Originally Posted by Git View Post
>> "Memory"=dword:00000000 <<

Git
After this line i need write. e table= question next line d table = anwer.
here is text file get from toro monitor
HaspHL In:> Hasphl_decrypt, Length=16
Data:
E38B424943D8D1A7BE60E8532C049890
HaspHL In:> Hasphl_decrypt, Length=16
Data:
E42E084631EFF988DF373D252D510800
HaspHL In:> Hasphl_decrypt, Length=16
Data:
581475C5043670DD3A1D41B579DB9CB5
HaspHL In:> Hasphl_decrypt, Length=16
Data:
EA84CD95B66E108A11FA029FE1E2A053
HaspHL In:> Hasphl_decrypt, Length=16
Data:
96C8EBD7BCCF066DDDAC0AD6AE77921D
HaspHL In:> Hasphl_decrypt, Length=16
Data:
AD627CB14C33524E7A25DFB8C5913777
HaspHL In:> Hasphl_decrypt, Length=16
Data:
46839752FE9DA102B9C11D2CC156DF9A
HaspHL In:> Hasphl_decrypt, Length=16
Data:
A2E5E91032BF6492692CDEC24267A066
HaspHL In:> Hasphl_decrypt, Length=16
Data:
9320E664C259F27B1BF8FC9C18CF2CA1
HaspHL In:> Hasphl_decrypt, Length=16
Data:
F03AD356B08B7A283B17E2304BBA2C9F
HaspHL In:> Hasphl_decrypt, Length=16
Data:
7695F0AE908EB2F342D29BC5ED2ACDB3
HaspHL In:> Hasphl_decrypt, Length=16
Data:
918AC5C405834BDEFFF9EE7DAF078D4D
HaspHL In:> Hasphl_decrypt, Length=16
Data:
A3D02CFC5023C9423D1270A2680F72CB
HaspHL In:> Hasphl_decrypt, Length=16
Data:
DD37F540738DD9953EC8E7E95E5291CB
HaspHL In:> Hasphl_decrypt, Length=16
Data:
FE0F695A76FC2BCA6283D571094AE4E4
HaspHL In:> Hasphl_decrypt, Length=16
Data:
CFC4D9E8395907CAD95DC201C937A0F6
HaspHL In:> Hasphl_decrypt, Length=16
Data:
F46CD256BB68710B084DB009153A9628
HaspHL In:> Hasphl_decrypt, Length=16
Data:
8C50CFFE134E696376D689EE5C5369B9
HaspHL In:> Hasphl_decrypt, Length=16
Data:
1F9357E9ED8A96A39F4087533FD92624
HaspHL In:> Hasphl_decrypt, Length=16
Data:
5834243D82BC30A2DB9E8529B7708052
HaspHL In:> Hasphl_decrypt, Length=16
Data:
76F2ECCFD51A4928CCFD84CDC4216661
HaspHL In:> Hasphl_decrypt, Length=16
Data:
2389BFE43F4623EE4D2C0A2A1D3CCF03
HaspHL In:> Hasphl_decrypt, Length=16
Data:
1238FCA4B5D077675BA012CAA9871B12
HaspHL In:> Hasphl_decrypt, Length=16
Data:
AB5A1F1598CB2F7EF23C630FE710B0AD
HaspHL In:> Hasphl_decrypt, Length=16
Data:
56D4E65FFCED09FE6BFD6D840F39BB40
HaspHL In:> Hasphl_decrypt, Length=16
Data:
2631024BB9DA1A7E198B1EBFD1529C26
HaspHL In:> Hasphl_decrypt, Length=16
Data:
96A98FA5C87EDC6FA039F0B840DC9481
HaspHL In:> Hasphl_decrypt, Length=16
Data:
2E855B3145421C3CDAD2BEC966BC72E2
HaspHL In:> Hasphl_decrypt, Length=16
Data:
F9B7AE9A5CDB70F60B5C1475E3DA1738
HaspHL In:> Hasphl_decrypt, Length=16
Data:
46839752FE9DA102B9C11D2CC156DF9A
HaspHL In:> Hasphl_decrypt, Length=16
Data:
1202C8AD883DC58E41807BEEAB5052D2
HaspHL In:> Hasphl_decrypt, Length=16
Data:
13878E13D71E12F568D04452FE045D1A
HaspHL In:> Hasphl_decrypt, Length=16
Data:
41997123049283CAE08957C020D05F2C
HaspHL In:> Hasphl_decrypt, Length=16
Data:
55B97A60F784190EAAA5B37F104459B2
HaspHL In:> Hasphl_decrypt, Length=16
Data:
77F23DEEBC841262BA76606B4131DFDB
HaspHL In:> Hasphl_decrypt, Length=16
Data:
C9ABE0025DB091336CC425A1A4DEB4A6
HaspHL In:> Hasphl_decrypt, Length=16
Data:
D0B688207145AECB3D029771E408C22E

it's ok?
Reply With Quote
  #15  
Old 06-06-2009, 11:14 AM
Git Git is offline
Super Moderator
 
Join Date: Oct 2007
Location: Torino
Posts: 1,797
Default

You are only showing half the data. It is a Decrypt operation, so it should be given a string of bytes (16, 32 or 48) and get the same number of bytes back from the function, but decrypted.

When you have all the pairs of data, follow the instructions in the MultiKey emulator manual, or search here - there has been loads of threads on the subject. You will benefit much more by learning how to do it than somebody just handing you a solution.

Git
Reply With Quote
  #16  
Old 06-06-2009, 02:46 PM
excelance excelance is offline
Senior Member
 
Join Date: Oct 2007
Location: BULGARİA
Posts: 96
Default

Quote:
Originally Posted by iksi View Post
Hi all.
I have program protected with hasp ch. I try make a dump with h5api but i get a message that only created file hasp.dmp, and for created hl key for multi key i'm need hhlmem.dmp, and this file don't created. Any solutions? Thanks again.

dear ...

Your dongle hasp hl basic , this dongle no have memory.

h5dmp ????:???? saved same .dmp file, no saving other hh_mem.dmp.View toro monitor 3.2 or hasploger your dongle Q A
pairs.İnsert this viewing pairs for your reg file Q A table.


Regards.
Reply With Quote
  #17  
Old 07-08-2009, 03:32 PM
Thangdc Thangdc is offline
Senior Member
 
Join Date: Oct 2007
Posts: 63
Default how to make QTable for muntikey

I heve Hasp HL memory dump is 0 and log file from hloger, but when i create emulator soft is not run please help me
Reply With Quote
  #18  
Old 08-27-2009, 08:28 AM
SonofabiT SonofabiT is offline
Senior Member
 
Join Date: Dec 2008
Posts: 351
Default

Could anyone please share an example of hhl_mem.dmp (112 bytes) generated by nodongle-team's h5dmp.exe from an actual haspHL dongle (not emul) ?

The hhl_mem.dmp which i mean is a file which has size = 112 bytes.
Reply With Quote
  #19  
Old 08-27-2009, 08:52 AM
Git Git is offline
Super Moderator
 
Join Date: Oct 2007
Location: Torino
Posts: 1,797
Default

Here you are.

Git
Attached Files
File Type: zip hhl_mem.zip (183 Bytes, 157 views)
Reply With Quote
  #20  
Old 09-01-2009, 12:39 AM
skr706 skr706 is offline
Senior Member
 
Join Date: Oct 2007
Posts: 80
Default

Dear Friends,
I emulated hasp dongle using HaspHL2007/Edgetool. The software works fine for few minutes and then restarts. sometimes it gives an error message ang shuts down the software. (the software doesnt run more than 3-4 minutes) whereas the same software (old version) works fine with the same emulator.
Could someone please sugest me the solution for the same to my PM skr706@gmail.com

Best Regards

Sunil
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump





Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2020, Jelsoft Enterprises Ltd.