Author: Duan Gang
Publisher:
Publish Date: 2003-06-01
Features: Software protection is the main means of safeguarding the interests of software developers and a crucial aspect of the software development process. To keep pace with technological advancements, this book updates outdated content from the previous edition and incorporates numerous new technologies. It comprehensively covers new software encryption and decryption techniques and related solutions on the Windows platform, adopting a step-by-step approach from basic debugging to deep disassembly, from superficial registration code analysis to commercial software protection, encompassing almost all aspects of Windows-based software protection. The book is divided into three parts. The first part introduces the fundamental knowledge related to encryption and decryption techniques. The second part thoroughly discusses various new software encryption and decryption techniques and methods, such as static analysis techniques, dynamic analysis techniques, serial numbers, warning windows, time restrictions, and encryption algorithms like MD5, SHA, RSA, and ElGamal. The third part primarily focuses on PE file knowledge, including enhancing file functionality, packing and unpacking, and patching techniques. This book is the result of meticulous effort by top experts in the field of cryptography, showcasing the depths of software encryption and decryption through the analysis of numerous examples. It serves as an indispensable professional reference for software developers. Since the inception of computers, their technological advancements have been relentless, with new technologies and ideas constantly emerging. Personal computer operating systems have evolved through DOS, Windows 3.x, Windows 9x, Windows 2000, and Windows XP. Application software has grown from just a few or dozens of bytes in the early days to now occupying several CDs, with thousands of shareware and commercial software becoming increasingly and complex in terms of technical content. The technical secrets of an excellent software often become the target of theft. As software developers, to protect the software painstakingly developed from being easily "borrowed" by others, it is necessary to study software protection (encryption) and cracking (decryption) techniques. However, resources on software protection and cracking are currently scarce, forcing many software developers to explore on their own, leading to wasted effort and time. With the popularity of software distribution through shared networks, the urgency of software protection and data encryption techniques has become increasingly evident. The history of software encryption and decryption development is typically divided according to the evolution of operating systems, so the history of software encryption and decryption development is essentially the history of operating system development.
1. DOS Era
During this era, software was primarily full versions and incomplete Demo versions, along with some disk copy protection. Shareware was rarely seen. Therefore, decryption in the DOS era usually involved removing certain restrictions or bypassing original disk checks, with the results often shared on amateur BBS platforms. However, it is worth noting that software from this era, due to the ease of accessing system-level operations in 16-bit operating systems, featured exceptionally strong protection methods. Additionally, the difficulty of tracking and cracking was inherent in the 16-bit platform, where it was hard to distinguish between system space and program space, leading to a significant divide in software protection mechanisms.
2. Early Windows 95
When Windows 95 emerged, many were not accustomed to the platform, and resources on encryption and decryption were scarce, creating a nightmare for many. During this period, shareware gradually became popular, with an increasing number of shareware programs using serial number protection. However, many programmers were unfamiliar with the newly introduced Windows 95, leaving them feeling overwhelmed and resulting in weak encryption in their software, making serial number encryption schemes particularly vulnerable at the time.
3. Late Windows 95
This period should be considered the coexistence of Windows 95 and Windows 98. By this time, programmers had become well-versed in the Windows 9x system, and software requiring advanced programming skills and close ties to system core operations began to emerge. During this era, most shareware still relied on serial number encryption, but these serial numbers were typically the result of complex calculations, making them much harder to crack than early software.
4. Windows 2000/XP Era
This period marked the coexistence of Windows 9x and Windows 2000/XP. During this time, encryption shells for various software proliferated, especially with the advent of specialized packing software, significantly enhancing software protection quality. Simultaneously, decryption techniques improved, with new decryption tools emerging. Serial number encryption during this period increasingly adopted irreversible encryption algorithms in cryptography, making the decryption process increasingly resemble higher mathematics. Software crackers needed a deep understanding of various mature encryption algorithms or the ability to exploit vulnerabilities in software encryption algorithms (e.g., the Keygens for WinRAR and CloneCD utilized encryption vulnerabilities in ECC elliptic algorithms).
About This Book
In early 2000, the author wanted to find friends to discuss encryption and decryption, but unfortunately, there was a lack of systematic technical resources in China at the time, limiting exchanges. Therefore, a homepage called "KanXue College" was created to explore encryption and decryption knowledge together with others. This was the only technical site in China dedicated to encryption and decryption at the time and grew healthily with the support of netizens. Later, the software debugging forum provided on the homepage became a well-known encryption and decryption technology forum in China, attracting many top experts in the field. With a spirit of knowledge sharing, theyly contributed their expertise, creating over 2,500 original articles to date, significantly advancing the development of encryption and decryption technology in China.
This was a challenging book to write, as it was a completely new field at the time. In the six years since Windows 95 was released, no books on this topic were published, and online resources were scarce. To fill the gap in Chinese literature on encryption and decryption on the Windows platform, the author collaborated with top experts from the software debugging forum, overcoming numerous challenges, and launched the first edition of this book in September 2001, titled "Encryption and Decryption—Software Protection Technology and Comprehensive Solutions." In the first edition, an analysis of popular software protection techniques from both encryption and decryption perspectives was attempted. The hope was that after reading this book, readers would gain an understanding of various popular software protection and cracking techniques. The first edition was well-received by readers and won the 2002 National Bestselling Book Award (Technology Category)! It achieved top sales rankings in many computer bookstores across the country and ranked among the top few in the sales charts of the renowned Huazhi Network for over a year. The following year, a traditional Chinese edition was published in Taiwan and was warmly welcomed by readers.
To keep pace with technological advancements, the author spent six months preparing and six months writing, gathering insights from top experts in cryptography from the software debugging forum (KanXue Forum) and updating most of the content from the first edition to complete the second edition, "Encryption and Decryption." This 500-page book nearly covers all aspects of Windows-based software protection, from basic debugging to deep disassembly, from superficial registration code analysis to commercial software protection, with a breadth and depth unmatched by any similar publication in China to date.
Table of Contents
The second edition is based on the first but removes outdated content and incorporates many new technologies. Half of the book is different from the first edition, with a more rational structure. It supplements and strengthens content on Windows and Unicode, code reverse engineering, detailed IDA operations, SoftICE symbolic debugging, OllyDbg operations, cryptographic algorithm applications, VB's Pcode tracking, enhancing PE file functionality, SEH technology, and unpacking techniques.
What is API? What is Unicode? What is reverse engineering? What are the differences between encryption and decryption on Windows 9x and Windows 2000/XP? Understanding these basic concepts is essential for addressing various issues during the encryption and decryption process. The book's foundational chapters (Chapter 1: "Fundamentals" and Chapter 2: "Code Analysis Techniques") systematically address these questions.
During software decryption, a primary task is analyzing the software being decrypted. This is covered in Static and Dynamic Analysis Techniques. The book dedicates significant space to these techniques, including detailed operations of reverse engineering tools like IDA, and the latest operations of SoftICE and OllyDbg. These topics are found in Chapters 3: "Static Analysis Techniques" and Chapter 4: "Dynamic Analysis Techniques." Some software authors may underestimate the planning and implementation of software protection solutions, often believing their protections are easily bypassed by crackers. This section aims to help these authors understand some software attack methods to better protect their work.
In this era, studying encryption and decryption without some knowledge of cryptography is unthinkable. The second edition provides detailed explanations of how algorithms like MD5, SHA, CRC, RSA, and ElGamal are applied in software protection, with source code examples provided on the accompanying CD! These topics are covered in Chapters 5: "Software Protection and Weaknesses" and Chapter 6: "Encryption Algorithms."
Currently, the two primary languages are interpreted languages and compiled languages. One of the major weaknesses of interpreted languages is that they can be reverse-engineered, so the focus of their protection should be on preventing reverse engineering. This topic is discussed in Chapter 7: "Reverse-Engineered Languages."
PE is the executable file format for Windows, and understanding PE files will deepen your understanding of the operating system. If you know the secrets of EXE and DLL files, you will become a more knowledgeable programmer. The book extensively explains the PE format with detailed illustrations in Chapter 8: "PE File Format." Once you master the PE format, you can freely perform "surgeries" on PE files for secondary development, such as adding menus, buttons, and other functionalities. This part will take you into another realm of computing (Chapter 9: "Enhancing PE File Functionality").
SEH has been around for a long time, but there is limited documentation on it. SEH not only simplifies program error handling, making programs more robust, but is also widely used in anti-debugging and encryption. The book explains the mechanism of SEH from a decryption perspective and covers other anti-debugging techniques, such as Anti-Debug and jump instructions. Software authors can apply these techniques to enhance the anti-debugging capabilities of their software (Chapter 10: "Anti-Tracking Techniques").
Nowadays, more and more software uses packing protection. During software analysis and localization, unpacking is an essential step. Chapter 11: "Packing and Unpacking" provides detailed techniques for unpacking various types of shells, allowing readers to apply advanced anti-tracking techniques from these shells in their own software. Chapter 12: "Patching Techniques" introduces file patching and memory patching techniques, with a focus on the application of SMC technology in patching. Learning about patching can be both interesting and valuable.
Commercial software protection techniques are essentially encryption techniques for commercial software. Truly valuable commercial software often employs these techniques for protection. Chapter 13: "Commercial Software Protection Techniques" explains common commercial protection methods, such as software dogs, Vbox, SalesAgent, and Flexlm, and analyzes their advantages and disadvantages.
Target Audience
This book is suitable for the following readers:
- Those interested in software encryption and decryption
- Software developers interested in software protection
- Readers interested in reverse engineering
- Readers interested in debugging techniques
Prerequisites
To use this book, you should have the following knowledge:
- Assembly language basics
- C language knowledge
- Win32 programming
- Windows API programming
- Understanding of Windows API can help, but it is not mandatory
- This book does not assume any prior experience in encryption or decryption
Acknowledgments
I would like to thank my alma mater, Tongji University, whose spirit of "unity and perseverance" has always guided my work and studies!
I am grateful to the Computer Division of Electronic Industry Press for their strong support of this book!
I also want to thank the numerous top cryptography experts from the software debugging forum who participated in the first edition, as their involvement made this book possible.
The second edition has undergone significant changes, referencing the contributions of the following friends in the first edition:
1. Blowfish (http://www.shieldsoftware.com/) for contributions to "Software Protection Techniques," "Anti-Debug," and "JAVA Program Reverse Engineering"
2. DREAMtHEATE for "Windows Message Mechanism"
3. DDXia[CCG] for "Remote Debugging Techniques" and "Patching Techniques"
4. Passion for "FileMon Usage" and "TimeLOCK Protection"
5. Ljtt for "Jump Instructions"
6. Arbiter for "FrogsICE Usage Introduction" and "CRC Principle"
7. Ajj (http://ajj.126.com/) for "IceDump and NticeDump Usage"
8. Fisheep (fisheep@sohu.com) for "VBOX4.3," "SalesAgent Protection Technology," "FlexGen Tool Usage," "Decrypting Using FlexLmSDK," and "Floating Point Instruction Summary"
9. Wu Chaixiang (http://www.souxin.com/) for "Common Breakpoint Setting Techniques" and "Understanding Shells"
10. mr.wei for "DeDe Usage"
11. Zou Dan (http://www.zoudan.com) for the paper "Research on Encryption of Executable Files Under Windows 95"
12. TiANWEi (http://winice.yeah.net) for "SoftICE Command Manual"
Special Thanks for the Second Edition
1. Hume (http://humeasm.yeah.net/) for providing "Instruction Optimization"
2. Lao Luo's Colorful World (http://www.luocong.com/) for "CRC32 Practice" and "Wonderful Base64 Encoding"
3. Ye Yue for "Blowfish Algorithm Decryption"
4. WaWa (Wang Lingdi) for "MD5 Algorithm"
5. Blowfish for "REVirgin Usage Guide" and "Bypassing Protection Hidden in SEH Handlers"
I would also like to thank SunBird, Hying, Spring, pll621, Ajj, Xiao Lou, Ljtt, Arbiter, Aming, Cooljiang, Yang Cai, WinDos2K, and Xiao Moutong, among others, from the software debugging forum for their support and assistance! The words and actions of forum users have been integrated into the text of this book and cannot be listed one by one.
Special Thanks to the CCG Group for their technical support!
About the Companion CD
All examples and source code are provided on the companion CD, with most examples developed and tested using Microsoft Visual C++ 6.0. Due to copyright issues, the companion CD only includes free or shareware mentioned in the book. If you need to use copyrighted software for learning purposes, it is recommended to search using search engines (e.g., www.google.com). The software provided on the CD has been thoroughly tested and is free of viruses. However, some encryption and decryption tools may use certain virus techniques, causing some code to resemble virus characteristic codes and trigger false positives from antivirus software. Please do not make the files on the CD into virtual drives and debug them, as this may lead to unexplained errors. It is recommended to copy the files to your hard drive and remove the read-only attribute before debugging.
Feedback
We would greatly appreciate it if you could share your thoughts on this book. If you have any questions or your own debugging stories, feel free to post them on the forum of the author's homepage. I am happy to answer any reasonable questions raised by friends, as answering these questions will also benefit me greatly.
Encryption and decryption
📌 Related Posts
Literature
New Concept Authorware 6.0 Tutorial
2026-09-14
Literature
The Power of Positive Thinking (A book that completely transforms professional mindset and corporate destiny! Translated into 42 languages and best-selling worldwide)
2026-09-15
Literature
World Youth Literature Classics Collection -- The Adventures of Marco Polo and the Swan
2026-09-13
Literature
Narrate the city
2026-09-14
Literature
Latest exhibition hall booth design.2
2026-09-19
Literature
Nomads
2026-09-19
Literature
Sui and Tang Heroes 5-8
2026-09-19
Literature
Being bullied and being humiliated
2026-09-19