Log inRegister an accountBrowse CSDbHelp & documentationFacts & StatisticsThe forumsAvailable RSS-feeds on CSDbSupport CSDb Commodore 64 Scene Database
 Welcome to our latest new user Harvey ! (Registered 2024-11-25) You are not logged in - nap
CSDb User Forums


Forums > C64 Coding > Malicious Packer?
2023-08-17 01:35
ws

Registered: Apr 2012
Posts: 251
Malicious Packer?

I was interested in this entry Galaxy Cargo + Poker because i wanted to see if the badness of the raster routine had anything to do with PAL/NTSC timing. It turned out, that it is just very badly coded.

What puzzled me was, that the depacker was partially obfuscated by an EOR routine. I reverted that and started the program again, but for fun i also altered the chars in the SYS line to WS/G*P. Prog started and all of a sudden, my attached disk was empty, named "PREPARE TO DIE!". (I probably could have used Ians Unp64 V2.36, which gives a depacked largefile, but what i wanted was to have just an de-ofuscated original binary.) My mistake was to not examine the code any further.

This packer actually has a routine checking if the sysline was altered, and if so, the routine will format your currently inserted Disk or VOLUME to "PREPARE TO DIE!". Imagine if one had mounted a flashdrive or even an entire harddisk. Quite dangerous.

Does anybody know something about this >PWR< Packer(?) thing?

Are there any other examples of malicious C64 code like this, like screwing up your disk if things have been altered?
 
... 22 posts hidden. Click here to view all posts....
 
2023-08-19 19:17
Rastah Bar
Account closed

Registered: Oct 2012
Posts: 336
I remember are crack where, on pressing the reset button (IIRC), a big grim reaper sprite would appear and the disk would be formatted.
2023-08-19 21:38
ws

Registered: Apr 2012
Posts: 251
@Bansai: That is actually a pretty sweet/nasty idea for a tool "Very Fast Floppy Compressor"...
"A new and groundbreaking method of reorganizing and compressing suboptimally filled blocks!!!! 25% more free disk space guaranteed - in almost no time!"
Just display some stats, scrolling lists of data, some percentage counter, move the floppy-head around and alter the bam to 25-30% more blocks free. And since afterwards one could successfully store a new file, everything would look legit. Until the rude awakening upon trying to load one of the damaged files. :-D Evil!
2023-08-25 20:16
Count Zero

Registered: Jan 2003
Posts: 1926
https://csdb.dk/release/?id=52462&show=notes#notes

Not sure if the soft format is applied by some protection program or manually.
2023-08-25 20:30
ws

Registered: Apr 2012
Posts: 251
@Count Zero:
Thanks! That one was also "protected" with PWR Coder V1.89 , it seems!
2023-08-25 20:35
iAN CooG

Registered: May 2002
Posts: 3187
It's a crypting layer in every prg by CIA Design and also, with different sysline, in Men at Work cracks like Star Slayer and Rolling Thunder
I've called it CIA Crypt v2.x not having any other clues ;)
2023-08-25 21:50
Richard

Registered: Dec 2001
Posts: 621
There was another nasty compression tool (according to codebase), which was the FROGS version of "Fast Cruel V4.0+". It injects some kind of FROG infection into Fast Cruelled programs.
2023-08-25 22:12
iAN CooG

Registered: May 2002
Posts: 3187
Well, those are just Trojan horses, not anti-hacking protections. "Coders" are about protections of programs from tampering.
2023-09-03 14:09
iAN CooG

Registered: May 2002
Posts: 3187
Another coder/protector that formats in case of tampering just got uploaded
Checksum Protector V1.0 aka FCG Coder.
I found several uses of this one but never found the actual coder so far.
2023-09-03 20:00
ws

Registered: Apr 2012
Posts: 251
Thanks! Seems to follow the same principle as PWR Coder, from the looks of it.
2024-01-19 12:12
iAN CooG

Registered: May 2002
Posts: 3187
found another nasty one
Protector V1.3
tampering with the protected prg will resutl in drive set to write mode, trashing everything.
Found used in Typhoon
Previous - 1 | 2 | 3 | 4 - Next
RefreshSubscribe to this thread:

You need to be logged in to post in the forum.

Search the forum:
Search   for   in  
All times are CET.
Search CSDb
Advanced
Users Online
psych
rexbeng
t0m3000/hf^boom!^ibx
Andy/AEG
chriz74
Electric/Extend
TCE/Hokuto Force
Bieno/Commodore Plus
Marq/Fit^Lieves!Tuor..
Martin Piper
Barfly/Extend
Guests online: 101
Top Demos
1 Next Level  (9.7)
2 13:37  (9.7)
3 Coma Light 13  (9.7)
4 Edge of Disgrace  (9.6)
5 Mojo  (9.6)
6 The Demo Coder  (9.6)
7 Uncensored  (9.6)
8 Wonderland XIV  (9.6)
9 Comaland 100%  (9.6)
10 What Is The Matrix 2  (9.6)
Top onefile Demos
1 Layers  (9.6)
2 Party Elk 2  (9.6)
3 Cubic Dream  (9.6)
4 Copper Booze  (9.6)
5 Libertongo  (9.5)
6 Rainbow Connection  (9.5)
7 Onscreen 5k  (9.5)
8 Morph  (9.5)
9 Dawnfall V1.1  (9.5)
10 It's More Fun to Com..  (9.5)
Top Groups
1 Performers  (9.3)
2 Booze Design  (9.3)
3 Oxyron  (9.3)
4 Nostalgia  (9.3)
5 Censor Design  (9.3)
Top Graphicians
1 Mirage  (9.7)
2 Archmage  (9.7)
3 Mikael  (9.6)
4 Carrion  (9.6)
5 Sulevi  (9.6)

Home - Disclaimer
Copyright © No Name 2001-2024
Page generated in: 0.053 sec.