Log inRegister an accountBrowse CSDbHelp & documentationFacts & StatisticsThe forumsAvailable RSS-feeds on CSDbSupport CSDb Commodore 64 Scene Database
 Welcome to our latest new user Northwind ! (Registered 2024-11-20) You are not logged in - nap
CSDb User Forums


Forums > C64 Coding > Malicious Packer?
2023-08-17 01:35
ws

Registered: Apr 2012
Posts: 251
Malicious Packer?

I was interested in this entry Galaxy Cargo + Poker because i wanted to see if the badness of the raster routine had anything to do with PAL/NTSC timing. It turned out, that it is just very badly coded.

What puzzled me was, that the depacker was partially obfuscated by an EOR routine. I reverted that and started the program again, but for fun i also altered the chars in the SYS line to WS/G*P. Prog started and all of a sudden, my attached disk was empty, named "PREPARE TO DIE!". (I probably could have used Ians Unp64 V2.36, which gives a depacked largefile, but what i wanted was to have just an de-ofuscated original binary.) My mistake was to not examine the code any further.

This packer actually has a routine checking if the sysline was altered, and if so, the routine will format your currently inserted Disk or VOLUME to "PREPARE TO DIE!". Imagine if one had mounted a flashdrive or even an entire harddisk. Quite dangerous.

Does anybody know something about this >PWR< Packer(?) thing?

Are there any other examples of malicious C64 code like this, like screwing up your disk if things have been altered?
2023-08-17 02:55
ws

Registered: Apr 2012
Posts: 251
The culprit in this case is PWR Coder V1.89. (And also this one PWR Coder V1.89, All Fucked Up Import)

I recommended these production notes:
Upon execution you have to enter a source and target filename, aswell as a start sys adress, or alternatively zero for basic RUN. The source program will load and you will be provided with an inverted "!" in the upper left of the screen. Now press <SPACE> for your fucked up target to be saved. After the saving is done, a reset occurs.

This is a malicious tool and usage can result in loss of your data. 

From the Scrolltext of the XADES Intro (sic!):
HEY YOU  YES YOU HERE IS PWR BACK AFTER ONE WEEK WITH A NEW CODER  YOU CANNOT CHANGE TEXTS IN THE CODED PRG  IF YOU DO IT THE DISC WILL BE FORMATED  THIS CODER WAS WRITTEN BY GKC [TILT] OF PWR  GREETS TO ALL OUR CINTACTS

TL:DR; if you alter the text of the SYS line to anything but >PWR< , this program will format your disk upon execution. 
2023-08-17 10:06
Krill

Registered: Apr 2002
Posts: 2968
Quoting ws
the routine will format your currently inserted Disk or VOLUME to "PREPARE TO DIE!". Imagine if one had mounted a flashdrive or even an entire harddisk.
Do any of the virtual filesystem implementations actually implement formatting a volume on a command from C-64?

That would be quite a bad idea already. =)
2023-08-17 10:25
iAN CooG

Registered: May 2002
Posts: 3186
I have found different program protectors/coders that have malicious payload, formatting drive 8 in case of tampering.
FCG Protector
H.Leise Protector (pratically the same as above with small differences, both by Flash/FCG)
FSW Protector (Florasoft)
STL protector (Starline)

There is also "ICS Drive 8 Coder" that simply will crash if not loaded from drive 8, only found in ICS cracks.

I haven't found so far this PWR coder used in the wild, else I would have added its identification at least, but since it can be removed as a generic routine, seems not even needed. I can add it just for completeness.

Edit: done

Scanners added:
- PWR Coder, formats disk if sysline is tampered with. Added hack to allow any
sysline by forcing the check with itself so it's always "good".
2023-08-17 17:55
chatGPZ

Registered: Dec 2001
Posts: 11348
Quote:
Do any of the virtual filesystem implementations actually implement formatting a volume on a command from C-64?

That would be quite a bad idea already. =)

<offtopic>not format - but there is currently no concept of "chroot", so you can traverse the entire host filesystem and read/delete whatever you see</offtopic>
2023-08-17 21:46
ws

Registered: Apr 2012
Posts: 251
Correction:
I must admit that the extension of my warning to "Volume", "Flash Drive" and "Harddisk" was done without sufficient knowledge of the actual access that C64 emulators are given to the host file system. My alertedness was solely based on the experience that, e.g. with Vice in deactivated true-drive emulation mode, one can list all files present on the host system in the directory from which Vice was launched, via dir listing ($).
Furthermore, my personal experience with the Amiga emulator WinUAE led me to the hasty and possibly false conclusion that almost every file available on the host system can be arbitrarily changed or deleted, if appropriately accessible by the emulator's file system. Also i have no experience working with CF-Card readers in a C64 context.

However, if a C64 program is designed to delete the contents of the currently mounted floppy without any prior warning (i am not sure if the terse announcement in the XADES intro scroller can be regarded as a sufficient warning), i still consider that worth reporting :-)

@ian: thank you for including the PWR Coder in Unp64!
2023-08-18 04:45
ChristopherJam

Registered: Aug 2004
Posts: 1408
Perhaps only tangentially related, but I'm reminded of the time an annoying classmate of Silicon had been hassling him for a pirate copy of some game or other. My brother eventually relented, but only by giving the guy a copy that would trash the disk the first time you played it (something about seeking around with write enabled IIRC :D).

"What do you mean it stopped working? The game loaded when you got home didn't it? Must've been a shitty blank disk you gave me, and no I'm not giving you another copy."
2023-08-18 12:09
tlr

Registered: Sep 2003
Posts: 1787
Quoting ws
What puzzled me was, that the depacker was partially obfuscated by an EOR routine. I reverted that and started the program again, but for fun i also altered the chars in the SYS line to WS/G*P. Prog started and all of a sudden, my attached disk was empty, named "PREPARE TO DIE!".

These were presumably done to stop just that. A lot of text changed cracks were starting to float around, and crackers didn't want that so tools like these got coded. The ones by Flash are the ones I saw first, were there any earlier?
2023-08-18 20:11
Burglar

Registered: Dec 2004
Posts: 1085
I actually did the same thing on an intro I coded for some group, added a screenram checker so they couldn't change creds, and if change detected quick-format the disk.

what I didn't know was that the format was also triggered by merely freezing the intro with action replay and restarting it ;)

"do you have a new copy? it autodestructed on restart?!"
2023-08-19 00:59
Bansai

Registered: Feb 2023
Posts: 48
Quoting ChristopherJam
"What do you mean it stopped working? The game loaded when you got home didn't it? Must've been a shitty blank disk you gave me, and no I'm not giving you another copy."
I'm guessing if someone wanted to be truly rotten about this, alter the BAM, then at some point when the person says, "Hey, I have 300 blocks free so I'll copy more stuff onto this disk," the disk dies at their hand (apparently) outside of execution of your boobytrapped program/disk. Like you said, it's the blank disk's fault.
2023-08-19 17:52
ChristopherJam

Registered: Aug 2004
Posts: 1408
Bansai: haha, evil.
Burglar: Oh nooo. Still, can't have people stealing intro graphix ;)
 
... 22 posts hidden. Click here to view all posts....
 
Previous - 1 | 2 | 3 | 4 - Next
RefreshSubscribe to this thread:

You need to be logged in to post in the forum.

Search the forum:
Search   for   in  
All times are CET.
Search CSDb
Advanced
Users Online
EALL/HT
hedning/G★P
Copyfault/TOM/tsn
REBEL 1/HF
t0m3000/hf^boom!^ibx
Andy/AEG
mutetus/Ald ^ Ons
zbych
juN3bula/N3U
Dwangi/Fairlight
FABS/HF
Mason/Unicess
Guests online: 273
Top Demos
1 Next Level  (9.7)
2 13:37  (9.7)
3 Coma Light 13  (9.7)
4 Edge of Disgrace  (9.6)
5 Mojo  (9.6)
6 Uncensored  (9.6)
7 Wonderland XIV  (9.6)
8 Comaland 100%  (9.6)
9 No Bounds  (9.6)
10 Christmas Megademo  (9.5)
Top onefile Demos
1 Layers  (9.6)
2 Party Elk 2  (9.6)
3 Cubic Dream  (9.6)
4 Copper Booze  (9.6)
5 Libertongo  (9.5)
6 Rainbow Connection  (9.5)
7 Onscreen 5k  (9.5)
8 Morph  (9.5)
9 Dawnfall V1.1  (9.5)
10 It's More Fun to Com..  (9.5)
Top Groups
1 Performers  (9.3)
2 Booze Design  (9.3)
3 Oxyron  (9.3)
4 Nostalgia  (9.3)
5 Censor Design  (9.3)
Top Diskmag Editors
1 Magic  (9.8)
2 hedning  (9.6)
3 Jazzcat  (9.5)
4 Elwix  (9.1)
5 Remix  (9.1)

Home - Disclaimer
Copyright © No Name 2001-2024
Page generated in: 0.047 sec.