Master the fundamental concepts of reverse engineering through this focused micro-challenge.
You have read the whole brief, and the concepts above stay free on every task. Writing and running the code needs a plan.
Three hints are available for this task, revealed one at a time inside the code workspace so you can struggle productively before seeing them.
Every task includes starter code, theory, and hidden tests so you can implement and verify locally in the browser.
How it worksBinary patching modifies compiled machine code to alter program behavior. In an educational context, it demonstrates how fragile client-side validation is and why software protection must not rely solely on local checks.
Locate the license check in disassembly by searching for strings like "license", "serial", or "trial", then finding the strcmp or memcmp that compares user input.
A typical check in assembly:
cLoading…
Patching strategies:
JNE (0x75) to JE (0x74)0x90 bytes so execution falls throughcheck_license to always return 1You will document how to find a validation function and apply a patch to bypass it. This teaches why code signing and Secure Boot exist: without them, anyone can silently alter a shipped binary's behavior in minutes.
Patching license checks on software you do not own violates license agreements and potentially law. This exercise uses educational crackmes where patching is the intended learning goal. In professional malware analysis, similar techniques reveal how protectors work so defenders can build better detection. Document every byte you change and keep the original binary intact for comparison and reporting.
Reimplement a crackme's license check, then show what each classic binary patch does to it.
check_license(key) returns 1 only when all three tests pass:
0x2aThe caller is call check_license; test eax, eax; jne valid (jne is opcode 75). The patches:
| Patch | Effect | Verdict |
|---|---|---|
none | unchanged | the check's result |
invert | 75 becomes 74 (je) | valid exactly when the check failed |
nop | the jump becomes 90 90 | always invalid: execution falls through to the failure path |
force | check_license returns via mov eax, 1 | always valid |
Any other word prints patch: unknown and keeps the check's result.
The patch word on line 1, the key (one token, 1-63 characters) on line 2.
cLoading…
Each test line ends in ok or fail, and the XOR is 2 lowercase hex digits. The patch line is patch: none, patch: invert (75 -> 74), patch: nop (75 -> 90 90), patch: force (mov eax, 1) or patch: unknown. The verdict is License valid. Full version. or License invalid. Trial mode.