.NET Reverse Enginering - Part 2

In Part 1 we cleaned our protected assembly and now it is decompilable and runnable.

In this part, we will try to remove activation checking.

Ok, Let’s do it.

Let’s run the application and visually observe when activation occurs. I will not show a screenshot of this, but activation message box shows right after the form is loaded/rendered. After clicking ok program exits.

Of course, it will be done in OnLoad event. Go Search it: DnSpy > Edit > Search Assemblies > OnLoad.

onload event

Here it is. Now lets find usage of VerifyTypeAttributes function. (Funny name yes?) Right click on the function name and click analyze.

onload function analyse

Here we see that it is used in the class constructor, navigate to that constructor by double clicking on it.

onload event

Right-click on it and choose Edit IL Instructions.

editing IL

Modify selected instructions and place nop instead.

Run the application again and boonzaaay, now you can reopen your incognito mode browser tab again.

Written on March 20, 2017