Does anyone know how to debug this kind of software made with Qt? Can anyone give me a hint? Or is anyone able to crack this new version of EaseUS?
Download

**License Key Format EXAMPLE**
G4Q7N-PL6J2-V9FZM-1W6SR-KD2YO
When you enter the correct activation serial, it connects to the server
Firebase is used for product information that is irrelevant to activation (firebasefetch.exe)
POST
**REAL ACTIVATION URL**
Host: activation.easeus.com
Connection: Keep-Alive
Cache-Control: no-cache
Process: "C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe"
**Requests When Validating Serial**
GET
Response
JKLm5PsKLXcTsJ47Ft-GH-2Q91Tkl-RE-WUfd7K1TsL0wXa34q
GET
Response
367UUQ5LPZX37Ft-GH-2Q91Tkl-RE-W
**Request to Open the Program Already Activated**
GET
Response
396QPzWjYk13Q4g-KN-2V84Zn-RT-J
**When you activate the program, this file is generated. It contains the serial, which is also saved in the registry**
"C:\Users\USER\AppData\Roaming\EaseUS\DRW\Configure.dat"
[register]
sn=G4Q7N-PL6J2-V9FZM-1W6SR-KD2YO
key=AbCdEfGhIjKlMnOpQrStUvWxYz1234567890+/
tech_expired=0
[HKEY_LOCAL_MACHINE\Software\EASEUS\DRW]
"SNExpired"=hex(3):30,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"SN"=hex(3):47,34,51,37,4E,2D,50,4C,36,4A,32,2D,56,39,46,5A,4D,2D,31,57,36,\
53,52,2D,4B,44,32,59,4F,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00
"SNKey"=hex(3):41,62,43,64,45,66,47,68,49,6A,4B,6C,4D,6E,4F,70,51,72,53,74,\
55,76,57,78,59,7A,31,32,33,34,35,36,37,38,39,30,2B,2F,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\Software\EASEUS\EaseUS Data Recovery Wizard]
"ExpiredDate"="2099-01-30"
"ExpiredDays"=hex(3):FF,FF,FF,FF,FF,FF,FF,FF
**Another file created during activation**
"C:\Program Files (x86)\EaseUS\ENS\.wpn.js"
{
"options": {
"verbosity": 3
},
"credentials": {
"appId": "xYzPQL83BBB",
"androidId": 9876543210123456789,
"securityToken": 1928374655647382910,
"GCMToken": "xyrHAbcTgKl:APA91bMfNqYt74D58qFTsWPbZY-XyuvwwL_XQRVGtK8XYzWmku5LxsdY7pUvBfqWE4zPLo0JDQsHYaOPz6bnr5mQXdRTYXzl04KJTEBAs7kfiUv7L3dbJxKg-QP4Kv9gixeGfaRzB7rQ2"
},
"keys": {
"id": 83472918374659102,
"secret": 984321657423,
"privateKey": "8LpQvZT6PnYXBOZPxN4yp_RD72R6Sr9zjhNuxCVQsa1",
"publicKey": "BAabWxkgGhdfTFhLrQcvdYQu4VY63MR8HZR2gIspdqNNyTD6ptX9kq3sVvQMNBt3yBW8KPYb4wGGur8GF7h6qKP",
"authSecret": "WwqzFNhPCduUVbWsaGFtjP"
},
"subscriptions": []
}
**IMPORTANT**
Apparently, a token is generated using local system and hardware information, and sent as a parameter to the only activation URL that actually matters:
This request is what determines whether the program is activated. All other connections can be blocked without affecting activation.
I can modify the server response and it doesn't affect the activation process as long as a response is returned. However, if I remove the response entirely and leave it empty, the program deactivates. This suggests that the real validation is handled within the executable itself; the server call is simply a connectivity check, as usual.
"C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRW.exe"
is the process that launches the application (DRWUI.exe)
However, this one is the process that actually contains the entire user interface and all the activation information:
"C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe"
So, I’m not sure how to trace them properly. Any tips or suggestions?
Download

**License Key Format EXAMPLE**
G4Q7N-PL6J2-V9FZM-1W6SR-KD2YO
When you enter the correct activation serial, it connects to the server
Firebase is used for product information that is irrelevant to activation (firebasefetch.exe)
POST
**REAL ACTIVATION URL**
Host: activation.easeus.com
Connection: Keep-Alive
Cache-Control: no-cache
Process: "C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe"
**Requests When Validating Serial**
GET
Response
JKLm5PsKLXcTsJ47Ft-GH-2Q91Tkl-RE-WUfd7K1TsL0wXa34q
GET
Response
367UUQ5LPZX37Ft-GH-2Q91Tkl-RE-W
**Request to Open the Program Already Activated**
GET
Response
396QPzWjYk13Q4g-KN-2V84Zn-RT-J
**When you activate the program, this file is generated. It contains the serial, which is also saved in the registry**
"C:\Users\USER\AppData\Roaming\EaseUS\DRW\Configure.dat"
[register]
sn=G4Q7N-PL6J2-V9FZM-1W6SR-KD2YO
key=AbCdEfGhIjKlMnOpQrStUvWxYz1234567890+/
tech_expired=0
[HKEY_LOCAL_MACHINE\Software\EASEUS\DRW]
"SNExpired"=hex(3):30,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"SN"=hex(3):47,34,51,37,4E,2D,50,4C,36,4A,32,2D,56,39,46,5A,4D,2D,31,57,36,\
53,52,2D,4B,44,32,59,4F,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00
"SNKey"=hex(3):41,62,43,64,45,66,47,68,49,6A,4B,6C,4D,6E,4F,70,51,72,53,74,\
55,76,57,78,59,7A,31,32,33,34,35,36,37,38,39,30,2B,2F,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\Software\EASEUS\EaseUS Data Recovery Wizard]
"ExpiredDate"="2099-01-30"
"ExpiredDays"=hex(3):FF,FF,FF,FF,FF,FF,FF,FF
**Another file created during activation**
"C:\Program Files (x86)\EaseUS\ENS\.wpn.js"
{
"options": {
"verbosity": 3
},
"credentials": {
"appId": "xYzPQL83BBB",
"androidId": 9876543210123456789,
"securityToken": 1928374655647382910,
"GCMToken": "xyrHAbcTgKl:APA91bMfNqYt74D58qFTsWPbZY-XyuvwwL_XQRVGtK8XYzWmku5LxsdY7pUvBfqWE4zPLo0JDQsHYaOPz6bnr5mQXdRTYXzl04KJTEBAs7kfiUv7L3dbJxKg-QP4Kv9gixeGfaRzB7rQ2"
},
"keys": {
"id": 83472918374659102,
"secret": 984321657423,
"privateKey": "8LpQvZT6PnYXBOZPxN4yp_RD72R6Sr9zjhNuxCVQsa1",
"publicKey": "BAabWxkgGhdfTFhLrQcvdYQu4VY63MR8HZR2gIspdqNNyTD6ptX9kq3sVvQMNBt3yBW8KPYb4wGGur8GF7h6qKP",
"authSecret": "WwqzFNhPCduUVbWsaGFtjP"
},
"subscriptions": []
}
**IMPORTANT**
Apparently, a token is generated using local system and hardware information, and sent as a parameter to the only activation URL that actually matters:
This request is what determines whether the program is activated. All other connections can be blocked without affecting activation.
I can modify the server response and it doesn't affect the activation process as long as a response is returned. However, if I remove the response entirely and leave it empty, the program deactivates. This suggests that the real validation is handled within the executable itself; the server call is simply a connectivity check, as usual.
"C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRW.exe"
is the process that launches the application (DRWUI.exe)
However, this one is the process that actually contains the entire user interface and all the activation information:
"C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe"
So, I’m not sure how to trace them properly. Any tips or suggestions?
Last edited: