Log inRegister an accountBrowse CSDbHelp & documentationFacts & StatisticsThe forumsAvailable RSS-feeds on CSDbSupport CSDb Commodore 64 Scene Database
 Welcome to our latest new user jmi ! (Registered 2024-09-15) You are not logged in - nap
CSDb User Forums


Forums > C64 Coding > Malicious Packer?
2023-08-17 01:35
ws

Registered: Apr 2012
Posts: 248
Malicious Packer?

I was interested in this entry Galaxy Cargo + Poker because i wanted to see if the badness of the raster routine had anything to do with PAL/NTSC timing. It turned out, that it is just very badly coded.

What puzzled me was, that the depacker was partially obfuscated by an EOR routine. I reverted that and started the program again, but for fun i also altered the chars in the SYS line to WS/G*P. Prog started and all of a sudden, my attached disk was empty, named "PREPARE TO DIE!". (I probably could have used Ians Unp64 V2.36, which gives a depacked largefile, but what i wanted was to have just an de-ofuscated original binary.) My mistake was to not examine the code any further.

This packer actually has a routine checking if the sysline was altered, and if so, the routine will format your currently inserted Disk or VOLUME to "PREPARE TO DIE!". Imagine if one had mounted a flashdrive or even an entire harddisk. Quite dangerous.

Does anybody know something about this >PWR< Packer(?) thing?

Are there any other examples of malicious C64 code like this, like screwing up your disk if things have been altered?
 
... 22 posts hidden. Click here to view all posts....
 
2023-08-25 20:16
Count Zero

Registered: Jan 2003
Posts: 1878
https://csdb.dk/release/?id=52462&show=notes#notes

Not sure if the soft format is applied by some protection program or manually.
2023-08-25 20:30
ws

Registered: Apr 2012
Posts: 248
@Count Zero:
Thanks! That one was also "protected" with PWR Coder V1.89 , it seems!
2023-08-25 20:35
iAN CooG

Registered: May 2002
Posts: 3170
It's a crypting layer in every prg by CIA Design and also, with different sysline, in Men at Work cracks like Star Slayer and Rolling Thunder
I've called it CIA Crypt v2.x not having any other clues ;)
2023-08-25 21:50
Richard

Registered: Dec 2001
Posts: 620
There was another nasty compression tool (according to codebase), which was the FROGS version of "Fast Cruel V4.0+". It injects some kind of FROG infection into Fast Cruelled programs.
2023-08-25 22:12
iAN CooG

Registered: May 2002
Posts: 3170
Well, those are just Trojan horses, not anti-hacking protections. "Coders" are about protections of programs from tampering.
2023-09-03 14:09
iAN CooG

Registered: May 2002
Posts: 3170
Another coder/protector that formats in case of tampering just got uploaded
Checksum Protector V1.0 aka FCG Coder.
I found several uses of this one but never found the actual coder so far.
2023-09-03 20:00
ws

Registered: Apr 2012
Posts: 248
Thanks! Seems to follow the same principle as PWR Coder, from the looks of it.
2024-01-19 12:12
iAN CooG

Registered: May 2002
Posts: 3170
found another nasty one
Protector V1.3
tampering with the protected prg will resutl in drive set to write mode, trashing everything.
Found used in Typhoon
2024-01-19 13:05
hedning

Registered: Mar 2009
Posts: 4694
I don't know if this one was discussed before. The Bonanza Crew spread a lot of disks with some kind of protection against tampering with the disks. I had to reach out to Mason to add cleaned up versions of their releases four years ago, like Super Real Darwin + [seuck].

If you tamper with the disk in any way the disk will get erased. Here's the Darwin spread disk in it's evil original form: https://www.dropbox.com/scl/fi/swwzr8yaln7pxbn44ajiy/Bonanza.zi..
2024-01-19 15:31
chatGPZ

Registered: Dec 2001
Posts: 11290
A bunch of those people who sold cracks also put timebombs into their stuff...like you can run it 100 times, then it deletes itself
Previous - 1 | 2 | 3 | 4 - Next
RefreshSubscribe to this thread:

You need to be logged in to post in the forum.

Search the forum:
Search   for   in  
All times are CET.
Search CSDb
Advanced
Users Online
TheRyk/MYD!
The Syndrom/TIA/Pret..
kbs/Pht/Lxt
Freeze/Blazon
Scooby/G★P/Light
rexbeng
pby/HF/Acrise
bugjam
Thierry
dstar/Fairlight
Brush/Elysium
lucommodore
Matt
megasoftargentina
Higgie/Kraze/Slackers
-trb-
icon/The Silents, Sp..
Pajda/Faith Design
Guests online: 135
Top Demos
1 Next Level  (9.7)
2 13:37  (9.7)
3 Coma Light 13  (9.7)
4 Edge of Disgrace  (9.6)
5 Mojo  (9.6)
6 Uncensored  (9.6)
7 Wonderland XIV  (9.6)
8 Comaland 100%  (9.6)
9 No Bounds  (9.6)
10 Unboxed  (9.6)
Top onefile Demos
1 Layers  (9.6)
2 Party Elk 2  (9.6)
3 Cubic Dream  (9.6)
4 Copper Booze  (9.6)
5 Rainbow Connection  (9.5)
6 It's More Fun to Com..  (9.5)
7 Dawnfall V1.1  (9.5)
8 Onscreen 5k  (9.5)
9 Daah, Those Acid Pil..  (9.5)
10 Morph  (9.5)
Top Groups
1 Booze Design  (9.3)
2 Oxyron  (9.3)
3 Nostalgia  (9.3)
4 Censor Design  (9.3)
5 Triad  (9.2)
Top Diskmag Editors
1 Magic  (9.8)
2 Jazzcat  (9.5)
3 hedning  (9.4)
4 Elwix  (9.1)
5 Remix  (9.1)

Home - Disclaimer
Copyright © No Name 2001-2024
Page generated in: 0.052 sec.