11 ms·
How to crack my software and add a back door
- readme 13y agoThis is satire, right? "A plaintext file requires a special tool, called a text editor, to change its content." "I recommend notepad.exe or pico. Linux hackers may use WINE to run notepad.exe." [rofl] EDIT: I think it's just the author's sense of humor, not actually satire.
- NamTaf 13y agoCorrect. Tongue was planted firmly in cheek of the authour when he wrote this. It's great.
- laurent123456 13y agolol, not just wrote it but did it. The screenshot at the end is Notepad in Linux.
- deleted 13y ago[deleted]
- jessaustin 13y agoI think this would be considered satire: Jar files are complex. So complex, a major conference carried a talk on how to reverse engineer them in early 2012.
- phyalow 13y agoThat triggered my bullshit detector. This also made me laugh " unzip tool uses a sophisticated algorithm based on LZ77 and Huffman coding."
- dmayle 13y agoThat's an interesting anti-pirating technique... Demonstrate how to crack your own licensing, while at the same time adding a backdoor to make users conflate the two. Obviously, all cracked versions of his software have backdoors in them... Except his attack is valid against all unsigned binaries... even his own. He could be distributing a backdoor and not even be aware of it...
- raffi 13y agoMy startup creates software for use in penetration tests and red team assessments. I distribute backdoors and I'm quite aware of it. :) I wrote this post to show how to use my software to backdoor a pirated copy of my software.
- ssafejava 13y agoThis is really funny - but the content shows the author's dedication to teaching (and learning) penetration techniques, even when it involves his own software. I would imagine that losing potential customers isn't a concern because the kind of people buying this software (generally) wouldn't run pirated versions. So instead, it makes a cool demo. Very cool, raffi.
- D9u 13y agoGood means of exercising damage control... "The cracked versions are backdoored! Use official release to be safe."
- kristofferR 13y agoOr "The cracked versions are backdoored! Use the official trial and crack it using the method I supplied to be safe", if you can't afford the hefty $2500 price tag due to not being a professional hacker/pentester.
- shadowOfShadow 13y agoThat entitled attitude of the complainer is so familiar. Hate that shit.
- Shank 13y agoHe writes software to demonstrate security flaws to a fairly niche market. I'd say his actions are justified - he's just showing that it isn't safe at all to download a cracked version of a pentesting software package.
- jethro_tell 13y agoshadowOfShadow's wording is a little unclear, but I suspect he was talking about the email exchange with a non customer complaining about lack of support.
- raffi 13y agoI read shadowOfShadow's comment the same way you do. (for others reading this): in the comments section, I reproduce an exchange (anonymized, of course) I had with someone complaining about my support--when they were trying to install a cracked version of my software. This exchange is what led to the blog post linked here.
- valleyer 13y agoThat user appears to claim he has a valid license to your software (third e-mail). Is that wrong?
- annnnd 13y agoHe only has the license for a trial version.
- raffi 13y ago@valleyer: He "signed up" for a trial and emailed me for help. But, when he asked for help, he provided the tar command he typed and the output of the tar command. He changed the tar command he typed to make it look like he was trying to install my trial. The output of tar told a different story though. The cracked trial was distributed as a .tgz with a space in it. Because this guy didn't know to put quotes around the filename, tar gave him an error he didn't know how to interpret. He left the output untouched, and I was able to determine the name of the file he was trying to extract, google it, and strongly conclude he was asking for support for a cracked version of my software.
- mcherm 13y agoThat's brilliant. Make it as easy as possible for "cracked" versions of your product to contain malicious back doors, thus encouraging people to avoid the cracked copies and pay for a properly licensed one.
- reginaldjcooper 13y agoBut now we can all crack it safely from the trial version.
- Deestan 13y agoBy "we", you mean technically savvy people. The number of us who need this software but don't make enough money to pay for it, or for some reason don't want to pay for it, is likely small enough to be ignored completely.
- dylangs1030 13y agoOr, download the trial, and crack it from there? No malicious backdoors there.
- mnutt 13y agoThe downside for him may be that users don't really care whether they got a cracked version or a legitimate version when their computer gets infested with malware; they're going to write angry posts about it online and say his software is broken or broke their computer. So it may be in his brand's best interest to keep users from using malware versions, even if those users may deserve what they get.
- x0054 13y agoThat's why I am of a firm belief that if you are going to pirate software, at least have the common decency to crack it your self and NOT REDISTRIBUTE. On a side note I am amazed that more developers do not sign their own code with checksums and alteration verification routines. Sign your software, then do a runtime check if the code has been altered. If so, after few hours of use, present the user with a nice message: "Congratulations, you have a cracked copy of our software. We find it sad that you did not want to buy it from us. It's possible that we may starve as a result. In any case, we would like you to stop using this copy. To encourage you to do so we are going to begin now uploading the contents of your hard drive to our servers. You may stop this process at any time by closing the program and removing it from your computer. Thank you."
- jacquesm 13y agoPlease do not follow this advice.
- fauigerzigerk 13y agoThat's completely pointless. If a cracker is able to remove the license check he will also be able to remove your checksum verification. Putting yourself in a difficult legal position on top of it helps no one.
- eps 13y agoWell-implemented integrity checks are much harder to remove compared to nop'ing single conditional jump.
- deleted 13y ago[deleted]
- rangibaby 13y agoThis DRM just turns things into an arms race, and eventually makes your software seem more and more like malware. A non-game example off the top of my head is Milkshape 3d, a basic modelling software that was popular in the early 00s because it had importers and exporters for the games that were wildly popular then such as Counter-Strike. The teenagers using it had no money to pay for the full version, so cracking of it was rife. Eventually the "anti-piracy" mechanisms built into it by the author got crazy enough that the program was essentially broken. I can't really remember specifics, except that it crashed your computer (!) if you tried to use a certain app-sniffing software.
- enscr 13y agoWhat if the software requires an internet connection to dial back home & verify the software authenticity .. say once every 30 days? Is that too annoying for users?
- Shank 13y agoI think it's quite obvious that the author is very well aware of how to implement DRM in such a way that it can't be circumvented, but it easily enters the territory of whether or not he would actually gain users from it. Cobalt Strike isn't exactly a $100 copy of Office - potential users who are going to use it to its full extent are going to be willing to pay the steep cost of entry as it is. In other words, while it would be possible to guard against piracy, the end result wouldn't be more sales of Cobalt Strike.
- sgift 13y agoI can only speak for my observations in the gaming community and there are more or less two camps, which can be summarized as: No back-dialing, ever. Basically they do not want the company to have a remote-switch to disable the software after they've buyed it, do not want the risk to not be able to play a game anymore just because a company decided to put down the servers and want to be able to play everywhere without an internet connection (e.g. I sit at my laptop and cannot play your singleplayer game because you decided to need dial-back? No chance.) The other camp doesn't care about it, more or less. Sure, they would like it if there was no dial-back for the games, but it doesn't hinder them from still buying and playing at platforms/games that require this as long as their playing experience isn't dimished by it. Steam is more or less the platform of choice for the second camp and seems to be growing all the time, so most users probably would acccept an dial-back connection once, every 30 days or even at every start. Quick note: Always-On is still something which is considered off-limits. Ubisoft tried it various times with their games and fell flat on the face. They've backpaddled to activate once by now.
- antocv 13y agoWhy is he root on his own machine when he uses unzip? I hope this is satire. "The unzip tool uses a sophisticated algorithm based on LZ77 and Huffman coding". Oh wow. Who would have thought. " These files do not represent the socio-economic status of the code." Oh. Lame humor.
- ssafejava 13y agoObviously he's just joking, and most of the people in this thread got it. He's not incompetent, he wrote both Armitage and Cobalt Strike, and the latter has some really incredible features that are hard to find elsewhere. I'd say he knows his way around a computer. Snarking about why he's root when he runs unzip does not advance the discussion and despite your efforts, it does not make you look smarter than him.
- antocv 13y agoIt is just too lame humor, I wasnt criticizing or questioning the smarts of the author. If anything, Im critizing his writing style, the blog article is not fun to read as it comes from a presumptions and arrogant/entitled position. Or maybe its just me I dont see anything funny in that article, I just dont find the poking at virtual Linux users and people interested in cracking from a position of authority funny. Effectively the entire article is making fun of hackers, people who are curious how to break software and make it do unspecified things, people who dare poke and dare crack. But its his software, so it is ok for him to make fun of others right? The cracking culture is many peoples first step into hacking and programming, we wouldnt be here if all of us really payed for the stuff we used as kids.
- ohashi 13y agoHe's walking through how to crack his own software and you are complaining that he is anti cracking culture? If this is your attempt at humor, it's really failing.
- raffi 13y agoI'll answer to unzip. In the post, I'm using a Linux distribution called Kali Linux. Kali is the successor to BackTrack Linux. Most people who use my software, use it with Kali Linux. Kali is a distribution with a focus on offensive security. Most tools require root to run. It's very rare to find a Kali user who uses sudo and works from a non-root account. root for all actions is normal. Some people may use Kali day to day, but it's built to do a job. http://www.kali.org/ http://www.kali.org/ I didn't call out Kali specifically, but all of my screenshots show Kali's default window manager theme. I don't know if my audience earns the "hacker" badge by your standards... but I suspect most of them recognize Kali from a distance.
- nathell 13y agoshell.sl? Is this a dialect of Smalltalk?
- VMG 13y agoIt the authors own programming language, Sleep: http://sleep.dashnine.org/manual/ http://sleep.dashnine.org/manual/
- rheide 13y agoThis would seem like the perfect tactic if the software also has a quiet phone-home system built in that contacts the author if the file checksums don't match. I bet you could get interesting statistics on how many people would try this method after publishing such an article.
- crazygringo 13y agoI've actually wondered if the cracked versions of Photoshop tend to have backdoors... and with the recent articles on the NSA, if the NSA itself is trying to put out the most popular cracked versions. I mean, if there's a single piece of software that is more pirated, I don't know what it is. They probably have more sophisticated ways, but you never know.
- sixothree 13y agoWhy bother with applications when you can have the OS?