Reverse Engineering Team
Unregistered, You must accept the Forum Rules below to be able to use some forum functions.

Read forum rules below...

1. All posts must be written in English.
2. Don't spam/abuse any other member via E-mail or Private Messages.
3. Have phun!

For breaking above rules you may be warned/banned appropriately!

Join the forum, it's quick and easy

Reverse Engineering Team
Unregistered, You must accept the Forum Rules below to be able to use some forum functions.

Read forum rules below...

1. All posts must be written in English.
2. Don't spam/abuse any other member via E-mail or Private Messages.
3. Have phun!

For breaking above rules you may be warned/banned appropriately!
Reverse Engineering Team
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Basic SRM backup tutorial

Go down

Basic SRM backup tutorial Empty Basic SRM backup tutorial

Post by ovis25 Fri Mar 30, 2018 2:49 am

This basic backup tutorial is only for BACKUP NOT emulation.
http://www21.zippyshare.com/v/A4eh0mbj/file.html

1.First in many cases you don't know what dongle you have, so we need to identify it.
See Tutorials - 1.identify dongles.
2.Because SRM can use envelope to protect exe, dll etc. and encryption keys are unknown we need to make usbtrace log. It is best to make with HOT PLUGIN. See "usbtrace log with hot plugin - remove fist dongle"
That means you start usbtrace before you have inserted dongle in usb and start target applications.
From my experience I can tell that you need to log as long it is possible to get all Q-A pairs if possible, that needs to be done correctly because application will crash if Q-A pairs are missing from emulator.
Push all menu, work in application for at least 1-2h. I know it sounds weird but are soft that have pairs that we get after some time. Stop Usbtrace and export log in TXT.
See tutorial "make hot plugin usb trace log".
3.Now we need to get HL pass and make dump for HL part and SRM part so we use Rengteam VidTool to do it. For this we need Petools to dump applications exe, dll, etc. while working with original dongle. Also we get session AES key and Vendor Code, it is recommended that you dump key after usbtrace logging is stopped.

See "backup procedure basic".
4. Now dump HL part with pass from Vidtool and next dump SRM part also.
See "backup procedure basic".
5. If files application are enveloped with SRM envelope u need to extract from dumped exe, dll, etc Q-A table with requested feature CBFF - default for example. This will be used in emulation exactly like in Aladdin HL tutorial but SRM.

http://www21.zippyshare.com/v/A4eh0mbj/file.html

Because I mentioned tools I give credits to developers:
Rengteam
http://rengteam.blogspot.com/
Nodongle
http://nodongle.biz/

and all others that help backup and emulate it!

ovis25

Posts : 648
Points : 1234
Reputation : 332
Join date : 2014-06-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum