armadilloarmadillo是一套强大的软件保护系统,可以为您的程序添加装甲般的外壳。通过艺术性的加密、数据压缩和其它安全特性保护您的程序不被盗版和破解。armadillo可以让您在5分钟内为您的程序设计并添加一套完全的软件保护和注册系统,并且不需要您修改任何程序代码!armadillo支持所有语言编写的32位windowsexe文件。
armadilloisapowerfulsoftwareprotectionsystem.itwrapsaroundyourprogramlikeanarmoredshell,defendingyourworkfrompiratesandprogramcrackerswithstate-of-the-artencryption,datacompression,andothersecurityfeatures.itallowsyoutodesignandaddacompletesoftwareprotectionandregistration-keysystemtoyourexistingprogramsinfiveminutesorless,withnochangestoyourprogram'scode!anditworkswithanylanguagethatproducesa32-bitwindowsexefile.
debug-blocker阻止调试器
copymem-ii双进程
1、nanomitesprocessing
nanomites是armadillo嵌入子进程的int3中断,虽然在getrightfinal版本里没有使用nanomites保护,但是却在crusader写的教程里的beta版本里用了。可能有50,100甚至200个int3,它们被放入了子进程的第一个section,以阻止子进程脱离父进程运行。int3中断替代了原始文件的条件跳转。所以每当父进程接收到int3中断,它就到存放跳转类型的report中去,看一下标志以决定是否跳转,然后测算出新的eip,改变到子进程中去然后继续运行直到下一个int3。
问题是我们不知道每个跳转和int3的对应关系,所以我们将要在本篇教程中学习如何patch它。首先我们要学如何手动patch它,然后(在第二篇教程中)我们将要学习如何让计算机自动逐行patch它。
2、importtableelimination输入表乱序
importtableeliminationisanotheranti-dumpingdefense.itremovestheimporttableoftheprogram,makingitmuchmoredifficulttoreconstructtheunprotectedprogramfile.unlikecopymem-iiandthenanomites,thisdefensedoesnotrequirethedebugger-blocker,butitisonlyavailableincustombuilds.
importtableelimination一般是把输入表放在壳申请的内存处并且乱序处理。
对于输入表乱序,以前有两种解法:①、写代码重新排序;②、直接用importrec“创建新的iat”功能来构造新的输入表。
3、codesplicing远程地址
strategiccodesplicingisanotheranti-dumpingdefense.itremovesportionsofyourcodeandplacesthemrandomlyinmemory,changingthemsothattheystilloperatethesamebutarecodeddifferently.unlikecopymem-iiandthenanomites,thisdefensedoesnotrequirethedebugger-blocker,butitisonlyavailableincustombuilds.
codesplicing通常称为远程地址,armadillo会把程序中的部分代码挪移到壳申请的内存段运行,普通dump会导致此部分代码丢失
4、memory-patchingprotections内存校验
hememory-patchingprotectionspreventanattackerfromusingaloadertochangeyourprogram'scodeinmemory,onceit'sloaded.ifyouhandleanypartoftheexpirationlogicinyourprogram'scode,oruseenvironmentvariablestocontrolfeaturesthatareonlyallowedinthepaid-forversion,thenyourprogrammightbevulnerabletoamemory-patchingattack.
ifyouusethisoption,youmustuseeithercopymem-iiorthemonitoringthread(orboth),oritwon'tbeabletodoanything.
theonlytimethisoptioncancauseaproblemisifyourprogramusesself-modifyingcode--thisoptionwouldconsiderthatanattack,andwoulddeliberatelycrashyourprogramtostopit.