Friday, January 27, 2012

U.S. carriers have started blocking an app that allows Android smartphone users free wireless tethering for other web-ready devices.
The application, “Wireless Tether for Root Users,” is still available on the Android Market. But if you have a phone that’s on the Verizon, AT&T or T-Mobile networks, you won’t be able to download or install it.
Try and access the app from the Android Market, and when prompted to choose a device on which to install it, you’ll only be able to select Sprint-carried devices or Wi-Fi–only products.
Wired.com attempted to install the application on a number of devices, and was able to do so only on a Sprint-carried Evo 4G and Galaxy Tab, as well as Wi-Fi–only products. Our Verizon, T-Mobile and AT&T devices were unable to receive the app for installation.
A spokesperson from Verizon confirmed the application is not available to Verizon Wireless customers. AT&T, Sprint, T-Mobile and Google did not immediately respond to requests for comment.
Screenshot: What we saw when trying to download the Wireless Tether app from Android Market.
If you’ve rooted your Android phone, using it as an internet hotspot for your other devices is one of its biggest perks. When nary an internet-enabled cafe is nearby, apps like Wireless Tether allow you to use your phone’s 4G, 3G or 2G data connection to access the web from another connected (or “tethered”) device, like your laptop or Wi-Fi–only tablet.
The best part: You bypass the monthly fee that most carriers charge for wireless tethering on devices (standard monthly charge for wireless tethering on the big four U.S. carriers is $30).
That’s why blocking the application makes sense in terms of a carrier’s bottom line. Missing out on that extra cash while its customers consume its precious bandwidth for free isn’t attractive to carriers.
This sort of interference isn’t anything new. After being fed up with jailbreaking iPhone owners who used similar apps to tether for free, AT&T decided to call their bluff. In March, the company started sending warning messages and then automatically billing customers who were suspected of using unofficial tethering apps. AT&T said it would charge for the service unless a customer immediately stopped using his or her unofficial tethering app.
To the resourceful Android phone owner, these carrier actions won’t be a huge problem. Although the app won’t be available through the official Android Market, you can go directly to the developers’ site andsideload the program onto your device. And if you’ve rooted your device and have a mod like Cyanogen 7.0 installed, there’s already a wireless-tethering option built into the program interface, eliminating the need to download another app.
Applanet is simply the installous app for ur Android. Many users use iPhone but the Android FUN is not behind Google is upgrading its software's and making android great day by day so to make it great u need to access some of the coolest apps available in the market but all PAID so that’s why we have Applanet app for android which will give u access to paid apps for free check its features here .:

Access Paid Apps for FREE.

Applanet's massive database contains more than 9,000 Android applications. You have access the to latest version of both free and paid applications found in the Android Market and even some you can't and won't have to pay anything! Applanet is your one-stop alternative app market.

Familiar Interface

Whether you are a power user or new to Android, Applanet has a familiar interface like the one found in the Android Market. You can view Apps, Games and which of your existing applications of updates available.

Share Your Experience Each user has the ability to rate and leave a comment about apps that they have download and installed from Applanet. This could include reasons why you use/enjoy an app, flaws with an app or notify us if the application appears to be out-of-date.
How to use Applanet on Android .:
Using Applanet application on Android is really simple, first download the above Applanet Application now after downloading the above application simply transfer this application to your Android Device and click on it to install it.
Now after you have installed the application in your phone simply fire it up and search the paid application you wanna download that’s it click on install and enjoy the application.
You can download as many Games, Apps, Utilities and much more so have fun and make sure to like and share this post with your friends.
  

Setting up the Ground :
Well, it seems people are getting crazy about Android platform(everyone is trying to buy an Android phone!). lets see if I can get my hands dirty with this Linux+java clean room engineered platform.

To begin our journey we need Android SDK, a target to test with and the necessary tools.

You can download the necessary file from these locations:

Android SDK: http://developer.Android.com/sdk/index.html
Deurus Android crackme 03: http://crackmes.de/users/deurus/android_crackme03/
Smali and baksmali: http://code.google.com/p/smali/
Dex2jar: http://code.google.com/p/dex2jar/
Java decompiler: http://java.decompiler.free.fr/

Download and install Android SDK, SDK platform(latest is 2.2 at the time of writing), necessary Java packages and rest of the tools. Create a virtual device from SDK menu and start emulation. Within few minutes you can see the emulator booting up and showing the phone screen. Well, thats it! we have our emulator up and running.

Getting Started with the Game :
Now we need to install the software(crackme, its legal!) to the emulator. For that you may have to get acquainted with Android debug bridge(adb). Installing a apk file is pretty simple, all you have to do is to run two commands from Android SDK directory/tools.



After the installation you can see the crackme icon from application menu.



Now run the crackme by clicking on it. If everything went as expected you will see the crackme application on the screen.



Now we will play with it, pressing check button with no inputs pops a message 'Min 4 chars', and with a proper name it pops up 'Bad boy'. We have to remember these strings because we will be using them as our search keys when we disassemble the apk(actually dex) files. Also note that we have two hardware ids and we need to find out what those exactly means. 

Real Android Reversing :
As our crackme is up and running in emulator, we now move onto reversing it. If you have read apk file format, you can visualize it as a extended JAR file which essentially is a zip file. Now you can change the crackme file name from Crackme03.apk to Crackme03.zip and decompress it to any folder.



Now the interesting file for us is classes.dex, which contains the compiled vm codes. We are going to disassemble the dex file with baksmali. Commands are pretty simple as you can see from screen shots.



If everything worked fine, we will have a folder structure similar to Java packages. Interesting .smali files are located at '\com\example\helloandroid'. Open all the .smali files into your favorite text editor(I use Notepad++). If you have never done anything related to reverse engineering/esoteric programming/assembly(IL) programming, you will probably think: WTF!. Relax. We have just opened a disassembled dex file. Now, if you are thinking how on earth someone can find the correct location of checking function, I hope you remember those pop up strings I told earlier. Yeah, 'Min 4 chars' and 'Bad boy'. Now we will use those strings as our search keys. Searching Min 4 chars in all the opened .smali files, we will find a hit in HelloAndroid$2.smali line 130.



Our aim is to understand the serial checking function and write a keygen for it. For that we have to know all the dalvik opcodes that are used here. You can visit this page to understand the opcodes and after that you can convert disassembled code to much higher language constructs. I will provide a brief code snippet which actually implements the algorithm. Two hardware ids used are IMEI and sim serial number.



As you can see, the algorithm is pretty straight forward. It is using name and two hardware ids as input and doing some operations on them to make a serial. We can easily recode it in any programming language we prefer to make it as a keygen. Anyway, I am not posting any keygen sources as it will spoil the whole phun!

Decoding the Algorithm :
A demonstrative serial calculation routine is given below:

Code:
Name: aaaaa
HW ID1: 0000000000000000
HW ID2: 89014103211118510720
Here are stepwise instructions on generating final serial number
At first 'aaaaa' will be converted to '9797979797', from which we will take first 5 letters and convert it into integer 97979
This will be xored with 0x6B016 resulting 511661 and this will be first part of serial. 
For second part, we will take first 6 letters from HW ID1 and HW ID2, convert them to integer and xor, resulting 000000^890141 = 890141.
For third part we will use first 6 characters from HW ID1.
Formatting with the specified delimiter the serial will become '511661-890141-000000'.


Final Verification of Reversing :
Now we will put the same magic number into our Crackme application. 



Bingo! everything worked as expected. Now, for all those who thinks it is pretty hard to read all those disassembled instructions and manually converting them to higher language constructs, there are other options. As dalvik is based on design of Java, it is also susceptible to decompilation. There is no decompiler available at this moment, but there is hope. 

For now we can use another utility which converts dex files to jar files so that we can use Java decompilers to see much more abstracted code. From starting of this blog post you may have noticed the tool dex2jar. Use dex2jar to convert classes.dex to classes.dex.dex2jar.jar. Open it in a Java decompiler and you can see much better output than dalvik disassembly. Please note that dex2jar is still in development phase and the output is meaningless at many places. This should be used only to get a quick understanding of all the functions.

Conclusion :
In this introductory article, Dhanesh explains reversing Andriod using the emulator and all available tools in sequence with pictorial elaborative steps. It is mainly based to set up your ground for further reversing work on Andriod Platform. 

Well, thats it! We have analyzed an Android program and defeated its protection. Cheerio!

Special How To Crack Gameloft Android HD Games Credit Goes to Djeman for Inventing This Method:
unpack an android package (apk) with a zip extractor, disassemble dex file in smali source files with dex2jar .
delete this {blue} line in the LicenseManagement.smali in the Billing folder.
Code:
if-nez v0, :cond_1

.line 224
const-string v0, "ANDROID BILLING"

const-string v0, "THIS IS A FULL VERSION PREVIOUSLY BILLED"

invoke-static {v2, v3, v0}, Lcom/gameloft/android/GAND/GloftRFHP/Billing/GLDebug;->debugMessage(ILjava/lang/String;Ljava/lang/String;)V

.line 225
invoke-static {}, Lcom/gameloft/android/GAND/GloftRFHP/Billing/LicenseManagement;->saveUnlockGame()V

move v0, v2

.line 230
:goto_1
return v0

.line 229
:cond_1
const-string v0, "ANDROID BILLING"

const-string v0, "THIS IS NOT A FULL VERSION!!!!"
So you have to delete the blue line, to avoid the game to jump to the read line (by deleting this line game will never show THIS IS NOT A FULL VERSION).
rebuild apk After that you need to sign it to run on your mobile.
http://developer.android.com/guide/p...p-signing.html
http://forum.mobiles24.com/showthrea...810#post365810

To understand Dalvik's commands more, you'll need that website
http://pallergabor.uw.hu/androidblog...k_opcodes.html

And if you want to go further, for the .so file, the ELF Dynamic library, you have to use IDA Pro to analyze it, and with ARM doc (Find it here) you'll be allowed to modify the file with a hexadecimal editor by calculating the ARM opcodes.
Get Blackberry Apps Serials and Activation Codes: The Ultimate Guide kracking Blackberry Softwares Moded By Nabilove

Please read before:

I received a lot of PM from many members asking me to repost this thread that was delated, to help other ppl who still dont know the kracking secret of the Blackberry Apps.

The idea is same kracking any computer software using a debugger so nothing new but the way changed, some forums (like "PDAxxx" and others) claims that its their idea, its wrong, the idea was posted first time on an american forum "krackbexxy" and was delated cause its agains their policy, and then was treated on "Srintgxxxs" forum, now this forum is dead, and then the secret was keept on a few forums for months, there is some members who know that and they keep it secret to get more credits, reputations and popularity.

I come today to offer this guide to all my ipmart friends, and broke this secret, and this post will be up to date than any other forum.

someone will tell me:

- why dont keep it secret, the developers will made new changes and the kracking process will be harder?
i will tell them that there is always a solution for any problem, for ex. Nokia, nokia is the biggest company and RIM is nothing beside Nokia, you can go and have a look in the moding section for nokia on this forum, we always find a solution to krack nokia apps and nokia phone security.
and it will be so boring to get all serials for all software.

NB: kracking is against law, and this guide is for information only, i dont take any responsibility on any software you kracked, and/or installed on your device. you can always read and check developer license agreement.



Here is the detailed guide using ollydbg as debugger, you can also use winhex, it gives the same result, i made some changes on the guide to fit the new apps.

Tools :

1- Blackberry jde Download Here (http://na.blackberry.com/eng/develop...javadevenv.jsp) chose the version same your device version, if you dont know, hold "alt+shift" and press "H"
2- Olly debugger Download Here: Version 1.10 (www.ollydbg.de/odbg110.zip) (Stable) or Version 2.00 Beta (www.ollydbg.de/odbg200j.zip)
3- MDS Services Simulator (optional, required for some email software) can be downloaded here (https://www.blackberry.com/Downloads...A3F9117CA45157)
4- Dmpclean.bat (attached)
5- Our target app - Ascendo Datavault (download @ http://www.ascendo-inc.com/DataVault.html)


How To? :

1-Download and install blackberry jde version of choice, chose the version same your blackberry version, to check your device version hold "alt+shift" and press "H"

2-when the installation is complete.
click start > programs > research in motion > blackberry jde 4.x.x locate device simulator icon > right click and go to properties then click on find target. create a shortcut of defaultsimulator.bat on your desktop or the quick launch menu, whichever you prefer.
copy dmpclean.bat into your simulator’s folder, by default it should be c:\program files\research in motion\blackberry jde 4.x.x\simulator basically the same folder where the defaultsimulator.bat file is located. once copied, create a shortcut of dmpclean.bat as well next to your defaultsimulator.bat shortcut on the desktop or quick launch.

3-Right click on shortcut to defaultsimulator.bat and choose edit, at the end of the text you will see /pin=0x2100000A change this value to your blackberry's pin, and behind add your IMEI without any quotes (necessary for some IMEI verified applications) , and save it.
For example, if my pin number is 24d25d8a and my IMEI is 357880.00.879598.5
then the parameter would look like this /pin=0x24d25d8a /IMEI=357880008795985

4-Launch the device emulator by double clicking on the shortcut to defaultsimulator.bat icon. be patient, it takes some time to load the
simulator as it has the same feel as your blackberry. (note, jde 4.5.0 or maybe even lower versions start up much faster).
To be sure your pin is being read correctly, navigate to options > scroll down to status and check for your pin.

5-To install an application into the simulator click on file > load java program> point to the DataVault.cod “our target app” then navigate to downloads and run the program. go to register, it shows our pin “good” and it’s asking
for the registration code else it will expire. leave it (dont close it)

6-let's launch the debugger now. double click on ollydbg.exe, once loaded click on file then choose attach. the attach window opens up very small, simply stretch by pulling it from the right buttom corner so you can see the
running programs on your computer. we are looking for a process name titled fledge with a path to the executable which should look like the following -c:\program files\research in motion\blackberry jde 4.x.x\simulator\fledge.exe - select this process and click attach. as it
finishes loading all necessary files the debugger will pause, simply press F9 once or twice to continue or sometimes SHIFT + F9, depending on olly’s mood. leave it (dont close it)

7-Now go back to the simulator and enter any facke code, untill you see the message "field full" (we will enter the following as your code 97531) then press arrow down ↓ and click on register. note: do not enter 1234567... as your bogus serial ever because most likely you will end up nowhere. after pressing enter or clicking to register a window comes up saying “Wrong Key!”. we knew that. leave it (dont close it)

8-Now go back to the debugger window (OllyDbg), then click on do an ALT + M to open the memory map, and select the first line in the memory map window. then do CTRL + B to search for the number we entered in the ASCII field and enter 97531 as your search string and click oK.

it begins to search in the memory for our bogus serial, a window titled dump pops up shortly showing the 97531 number we entered in the application > right below it shows our pin number > further down our serial is being constructed > finally we see the serial 42350 which happens to be the correct serial for my bogus pin number 24d25d8a.

9-To test our discovered registration code let’s switch to the simulator window and enter it to see what happens, well just as we hoped it would be “you have successfully register..."


Remember:

1-Almost of registration codes for blackberry apps are generally 5 characters long in numeric format, unless the developer decided to get super creative, they made it longer and become alphanumerical, and others get two serials, one Key and one Activation Code

2-Most Blackberry apps are pin specific, which means that when you discover one working key for one pin it doesn’t always mean it will work on all other berries.

3-When searching the memory map in olly, your search string could sometimes be in UNICODE, however i only noticed some Blackberry app thus far.

4-When searching for serial in the dump sometimes the first search result isn’t the only instance. while in the dump do CTRL+L to see if your bogus serial shows up more than once. with some apps the reg code shows up right away and with others you have to look for it. i also noticed that some times the reg code appears around your pin number, you might get lucky with some apps if you search for your pin number in ASCII while in the dump window by doing CTRL+B. generally, once your first search result pops up in the dump window you may need to scroll up or sometimes down several pages until you find your valid reg code. anyway, once you find a key or two and feel comfortable enough you will try other features of the debugger…

5-Remember, you may not be successful with every app when it comes to finding a valid reg code. while in the dump window you will see 5 digit number 45654, this is a port number and not a serial. you will also see PURG followed by some numbers, this is not a serial either. when you download trial apps make sure the app has the option to register by inputting a serial which would make the app fully registered, otherwise some apps are just demo apps with expiration or limited functionality, these are not trial. we are not kracking the apps with this method but just finding the right codes for our pin.

6-You will be unable to krack some new apps version, try to krack the old one, install it on your blackberry and update to the new one, the apps will stay registerd in almost of time excepl for some (berrybuzz.v2,...etc)

7-Use Dmpclean.bat everytime before starting to clean the simulator’s memory to default.

Blackberry LCD reverse engineering

was looking to source some LCD screens for an upcoming project, and was considering buying them from SparkFun. While the Nokia panels they sell are not expensive, they aren’t necessarily the cheapest option either – especially when building in volume.
He searched around for something he could use instead, and settled on Blackberry screens. Old Blackberry models were even more durable than the current offerings, plus companies are trying to get rid of old handsets by the truckload. The only problem was that he could not find any information online that would show him how to write to the screens.
It took a bit of digging, but he eventually determined which ICs were used to drive the LCD screen. He had no luck finding screen pinout information online, so after spending a few hours testing things with his multimeter, he came up with a full listing on his own.
He wired up a connector so that he could use the screen on a breadboard, then got busy writing code to display some text on the screen. Everything came together nicely as you can see in the video below, and he has released his code in case anyone else is looking to repurpose some old Blackberry screens.
All we want to know is what sort of project all these screens are going to be used in.

You can replace this text by going to "Layout" and then "Page Elements" section. Edit " About "