{"__v":0,"_id":"5638d42668b11f0d0048c8d5","category":{"__v":11,"_id":"551558324c7c1e39003735a0","pages":["55155913fd26132300e74e32","55155b2907e9252f00348881","55156a8307e9252f00348899","553a6a6a2af5f20d000fc2d2","555ca4ee15a89b0d00c1aee9","558154478625220d00429c78","55a5052a750a9a23005332be","55a62e85249a40190051d98d","55e41f711020fe0d00388a00","5609036331beb60d001b6585","5638d42668b11f0d0048c8d5"],"project":"547cd7662eaee50800ed1089","version":"547cd7662eaee50800ed108c","sync":{"url":"","isSync":false},"reference":false,"createdAt":"2015-03-27T13:16:34.125Z","from_sync":false,"order":7,"slug":"tips-and-tricks","title":"Tips and Tricks"},"parentDoc":null,"project":"547cd7662eaee50800ed1089","user":"547cd6ac78fd57080023ca99","version":{"__v":9,"_id":"547cd7662eaee50800ed108c","project":"547cd7662eaee50800ed1089","createdAt":"2014-12-01T21:02:30.851Z","releaseDate":"2014-12-01T21:02:30.851Z","categories":["547cd7672eaee50800ed108d","54c8f8ae0174630d00efa874","54c8f8bd7a11f60d0022a832","54c8f8c60174630d00efa876","54c8f8f10174630d00efa877","55155826bc466623002afe83","551558324c7c1e39003735a0","56052058e266000d008971c7","57909a453b845d0e006a37d5"],"is_deprecated":false,"is_hidden":false,"is_beta":false,"is_stable":true,"codename":"","version_clean":"1.0.0","version":"1.0"},"updates":[],"next":{"pages":[],"description":""},"createdAt":"2015-11-03T15:35:02.241Z","link_external":false,"link_url":"","githubsync":"","sync_unique":"","hidden":false,"api":{"results":{"codes":[]},"settings":"","auth":"required","params":[],"url":""},"isReference":false,"order":7,"body":"We are doing our bests to protect our frameworks, however, we are developers and we perfectly understand, that there is no uncrackable software, but there are lots of ways to make attackers’ efforts significantly more time-consuming. So here are some our best-practice tips to do this:\n1. Inlining the code where activation status and trial state are checked.\n2. Adding checking code to some core places where main functionality should be performed.\n3. Using C/C++ functions with check code instead of Objective-C classes and methods, use C structures instead of Objective-C ivars and properties.\n4. Using name obfuscation for functions/variables that are connected to activation/trial check.\n5. Combining original system/Kevlar functions usage with previously saved (e.g. at startup) pointers to them in your check code:\n\t\n[block:code]\n{\n  \"codes\": [\n    {\n      \"code\": \"// somewhere at start (e.g. in -applicationWillFinishLaunching:)\\n\\tBOOL (*isActivated_func_p)(NSInteger *) = &DMKIsApplicationActivated;\\n\\t...\\n\\t// some check code (e.g. in -applicationDidFinishLaunching:)\\n\\tNSInteger kevlarError = NSIntegerMax;\\n\\tif (!(isActivated_func_p(&kevlarError) && kevlarError == DMKevlarNoError))\\n\\t{\\n\\t\\t// if DMKIsApplicationActivated returns YES then kevlarError must be DMKevlarNoError\\n\\t\\t// not activated here\\n\\t\\t…\\n\\t}\",\n      \"language\": \"objectivec\"\n    }\n  ]\n}\n[/block]","excerpt":"","slug":"anticrack-protection-tips","type":"basic","title":"Anticrack Protection Tips"}

Anticrack Protection Tips


We are doing our bests to protect our frameworks, however, we are developers and we perfectly understand, that there is no uncrackable software, but there are lots of ways to make attackers’ efforts significantly more time-consuming. So here are some our best-practice tips to do this: 1. Inlining the code where activation status and trial state are checked. 2. Adding checking code to some core places where main functionality should be performed. 3. Using C/C++ functions with check code instead of Objective-C classes and methods, use C structures instead of Objective-C ivars and properties. 4. Using name obfuscation for functions/variables that are connected to activation/trial check. 5. Combining original system/Kevlar functions usage with previously saved (e.g. at startup) pointers to them in your check code: [block:code] { "codes": [ { "code": "// somewhere at start (e.g. in -applicationWillFinishLaunching:)\n\tBOOL (*isActivated_func_p)(NSInteger *) = &DMKIsApplicationActivated;\n\t...\n\t// some check code (e.g. in -applicationDidFinishLaunching:)\n\tNSInteger kevlarError = NSIntegerMax;\n\tif (!(isActivated_func_p(&kevlarError) && kevlarError == DMKevlarNoError))\n\t{\n\t\t// if DMKIsApplicationActivated returns YES then kevlarError must be DMKevlarNoError\n\t\t// not activated here\n\t\t…\n\t}", "language": "objectivec" } ] } [/block]