rapid1337.com

Robocop

2004-07-28 · [ security ] · by staff

Robocop – Ocean Software (1987)

<-- SleepWalker (1993) AGA | [ Security ]

[ read in diskmag ]


Robocop – Ocean Software (1987)

————————————————–

This time we need:

  1. Robocop disk or CAPS

image

  1. Amiga or WinUAE emu

  2. Action Replay cartridge or ROM

  3. Some cans of Red Bull and good music

In this tutorial we’re going to reverse the game Robocop.

First of all, we have to figure out about what kind of protection we’re dealing with.

For this purpose, fire up X-Copy or any other copier, and make a copy of it.

Soon you’ll notice that the first track seems to be protected somehow.

Moving along, insert your created copy and reset the Amiga.

Hmm what the..

01-Guru.jpg

I’m not in mood for any meditation stuff right now so let’s get rid off it.

Hit AR, since our game screws up quite early and the trackcounter was on track when it crashed, we don’t have to dig very deep into the game.

Now locate where the bootblock get’s loaded in.

FS “DOS” Here’s what we get

02-Bootblock.jpg

It found one occurence 5C40. Scroll down a bit until you reach 5C9C “JMP (A3)” . Note this address.

Ok now that we know these addresses, we have to figure out where the code which causes the Amiga to crash is loaded. Its quite obvious that we’re dealing here with the Rob Northen Copylock protection.

So let’s search for its signature.

F 48 7A

It gives us 2 results A498 and A4A8

03-RNC.jpg

We have to find the exact address where this jump at 5C9C jumps to.

This means we have to find out what value is written to the register A3 To do so, i locked up execution at 5C9C by creating an infinite loop jumping to 5C9C.

Unfortunately the instruction “JMP 5C9C” uses more bytes than “JMP (A3)”, so it overwrites the instruction at 5C9E.

But we’re lucky, because there’s some free space after the instruction “RTS” at 5CA0, which means we can shift those 2 instruction a bit.

But be aware there is a reference to those 2 instructions at 5C68 “BEQ 5C9E”, make sure you fix this to “BEQ 5CA2”.

Always keep in mind, that when you’re modifying the bootblock, you have to issue the “BOOTCHK” command. This ensures that the checksum of the bootblock is re-calculated.

You dont have to follow this part step by step, i just included it to illustrate how i figured out the value in A3. Additionally if i would show every step involved in modifying this piece of code and putting it back on disk, it would take more time than writing the whole tutorial =) Just compare the 2 following pictures and you should understand whats going on.

Before

04-Loop-Bef.jpg

After

05-Loop-Aft.jpg

Alright after loading the the prepared disk, we’re stuck at 5C9C in our infinite loop. Now the right moment has come to check register A3.

R

06-Register.jpg

Nice at register A3, we see the value A498. Remember earlier in this tutorial we figured out that the Copylock routine start exactly there.

Since our copied disk crashes at instruction “A4A2 ILLEGAL” we have to find out how the program behaves when it passes this instruction when all the protection is intact.

For this reason put the original Robocop disk into the disk drive and reset the Amiga.

Hit AR when the trackcounter is at track 0, dissassemble instruction A498.

Hmm nothing special, still the problematic routine in there. Exit AR.

Wait until the trackcounter moves away from track 0 and hit AR again. Dissassembe once again A498 Hey whats that? The code changed!

07-Loader-1.jpg

07-Loader-2.jpg

Looks for me like a loader. Notice the “JMP 60000” at A502.

Do you think the same what i think? I assume the routine we had in there before, was intended to decrypt the game loader and after all this done it passes execution to the game loader.

We need this loader! In order to do so, we gonna rip the loader and place it on a blank disk.

The starting and the ending point in memory is what we need to successfully dump the loader.

NQ A498

08-Loaderdump.jpg

The end seems to be around ACEF, check the precise end

M ACEF

The last byte is at AD12.

Its size is 87A bytes. Dump it on a blank disk.

SM LOADER, A498 AD12 What we now going to try is, to locate the Copylock routine on disk and replace it with our decrypted loader.

Insert our copy and restart the Amiga. Hit AR before any loading occurs.

Read in the first tracks to memory

RT 0 2 50000

Now read in our dumped loader from disk at 60000 LM LOADER, 60000 Alright now we got the crappy one and the good one in memory.

Issue this command TRANS 60000 6087A 50400 This command transfers our loader which is in memory at 60000 – 6087A to location 50400 (Start of the Copylock routine). 50000 – 50399 are reserved for the bootblock so leave it untouched.

Write it back to disk

WT 0 2 50000

09-LoaderTransfer.jpg

Reset the Amiga. Wait a few seconds..

Ahh here comes the ocean logo. I love this company.

10-Logo.jpg

Dont let your steel butt getting kicked. Go and clean up the city from these nuke addicted jerks =)

11-Title.jpg

scenex – july 2004

#amiga #cracking #track-protection


<-- SleepWalker (1993) AGA | [ Security ] | WIZ ?N? LIZ -->