Quote:
Originally Posted by JustMeWhy?
Great job, you are half way there!
Now, simply use ollydbg to make Conquer.exe load the modified Server.dat, and open directly (Instead of having to use blacknull).
Use this guide, the second guide is on the 2nd page,
|
Thanks alot, i've managed to do the 2nd page guide of the server.dat as for the bypassying play.exe i m not being able. once i open the conquer witht he olly dbg and find the 273F this is what appears
004B9C08 . 68 3F270000 PUSH 273F
004B9C0D . 8BCE MOV ECX,ESI
004B9C0F . FF50 3C CALL DWORD PTR DS:[EAX+3C]
004B9C12 . 50 PUSH EAX ; |Text
004B9C13 . 6A 00 PUSH 0 ; |hOwner = NULL
004B9C15 . FF15 20D86000 CALL DWORD PTR DS:[<&USER32.MessageBoxA>>; \MessageBoxA
004B9C1B . 33C0 XOR EAX,EAX
004B9C1D > E9 BD000000 JMP Conquerc.004B9CDF
004B9C22 > 8BCE MOV ECX,ESI
004B9C24 . E8 BF380E00 CALL <JMP.&MFC42.#2621>
004B9C29 . 68 40CD0A00 PUSH 0ACD40
004B9C2E . E8 F1350E00 CALL <JMP.&MFC42.#823>
004B9C33 . 59 POP ECX
004B9C34 . 8945 F0 MOV DWORD PTR SS:[EBP-10],EAX
004B9C37 . 8365 FC 00 AND DWORD PTR SS:[EBP-4],0
004B9C3B . 85C0 TEST EAX,EAX
004B9C3D . 74 09 JE SHORT Conquerc.004B9C48
004B9C3F . 8BC8 MOV ECX,EAX
004B9C41 . E8 BA73F4FF CALL Conquerc.00401000
004B9C46 . EB 02 JMP SHORT Conquerc.004B9C4A
004B9C48 > 33C0 XOR EAX,EAX
004B9C4A > 834D FC FF OR DWORD PTR SS:[EBP-4],FFFFFFFF
004B9C4E . A3 6CFB6800 MOV DWORD PTR DS:[68FB6C],EAX
004B9C53 . 8946 20 MOV DWORD PTR DS:[ESI+20],EAX
004B9C56 . 8B0D 6CFB6800 MOV ECX,DWORD PTR DS:[68FB6C]
004B9C5C . E8 7174F4FF CALL Conquerc.004010D2
004B9C61 . 8B0D 6CFB6800 MOV ECX,DWORD PTR DS:[68FB6C]
004B9C67 . 6A 05 PUSH 5
004B9C69 . E8 9E350E00 CALL <JMP.&MFC42.#6215>
004B9C6E . 8D85 E8FEFFFF LEA EAX,DWORD PTR SS:[EBP-118]
004B9C74 . 50 PUSH EAX ; /s
004B9C75 . E8 3C390E00 CALL <JMP.&MSVCRT.strlen> ; \strlen
004B9C7A . 85C0 TEST EAX,EAX
004B9C7C . 59 POP ECX
004B9C7D . 74 46 JE SHORT Conquerc.004B9CC5
004B9C7F . 8D85 6CFFFFFF LEA EAX,DWORD PTR SS:[EBP-94]
004B9C85 . 50 PUSH EAX ; /s
004B9C86 . E8 2B390E00 CALL <JMP.&MSVCRT.strlen> ; \strlen
following the instructions guide, i should have to change the
004B9C1D > E9 BD000000 JMP Conquerc.004B9CDF
to 004B9C1D > E9 BD000000 JMP SHORT 0046883C
but it doesnt let me..it says i should use long form..
and i cant remove the conquerc. just the text after...
any idea what im doing wrong?