Showing posts with label iphone ipa crack app store strategies. Show all posts
Showing posts with label iphone ipa crack app store strategies. Show all posts

Monday, November 3, 2008

Being Even More Subversive

In my previous installment I mentioned being subversive in the behaviour you take toward the kids that pirate your software. This goes double for your code too.

How so?

Well, it would be sufficient for an automated cracking script to search for strings in your application bundle that matched 'SignerIdentity' and alert the cracker. An apt cracker would use this to find any code references to this string and investigate its purpose. It would not be a challenge for him to alter your code so that it didn't function correctly but allowed your application to continue without pause.

What now?

Instead of using 'SignerIdentity' in its entirety, you have a few options:
  1. Iterate over all keys in infoDictionary and check them against the length of SignerIdentity
  2. You know the number of keys in Info.plist so act on that
  3. Iterate over all values in infoDictionary and check the values
Ad nauseam.

You can combine this with other strategies like performing your IPA crack check every 3 executions, only once, or at random. It's up to you and the scheme for detection is limited only by your imagination.

There are over 5000 paid applications ripe for the cracking on the App Store. Between homework and masturbating, there is no way for every single pirated application to be checked for IPA crack checks.

Now that we have the basic strategy in place, we've laid the foundation for some very impressive and interesting applications. This will make for some fun times on the App Store.

Please, if you're interested in what I write, please post a comment and tell your friends about me. I crave the attention.

Sunday, November 2, 2008

Strategies - An Introduction

In this posting we'll discuss some of the various strategies you, my intrepid and enterprising App Store developers, can utilize to protect your application.

So your application got cracked. Now what?

If you've been following along then you'll know there are several ways to detect a compromised application bundle. There are a few more ways that you can use but those are the aces in my sleeve and will be revealed at a later date.

Some of you might think, "okay so a 15 year old pizza face offspring of some yuppies just cracked my application... I'll just push out a new update and quit the application if Info.plist is modified!" Well, yeah, you could do that. But what's the first thing the cracker is going to do after he cracks your application? He's going to run it to test his handy work.

If your application bombs out on execution then it's a simple task for a kid with a hex editor to modify your decrypted application so that it doesn't crash.

Your knee jerk reaction has been thwarted and you've only slowed down ONE cracker and ZERO copiers.

Really, so NOW what?

If you remember the previous article (Prelude) then KNOWING is half the battle. The process for cracking an application is literally automated.

TAKE ADVANTAGE OF THAT FACT.

If copies of your pirated software are using resources on an external server, say, for tracking high scores, downloading new resources for your application (hello Tap Tap Revenge NIN edition!), a help or feedback screen, then use this to your advantage.

Be Subversive

If you're making an AJAX, SOAP, or HTTP request then just pass along a little more information in the query string to indicate the user doesn't own your software. On your server, alter your behaviour for these users.

You could forget the high score or triage the scores into a list of high scores for pirated users.

Instead of downloading new NIN songs, you could serve out RIAA/MPAA propaganda songs that tell users not to pirate.

Instead of providing a help screen with a list of troubleshooting advice, alter the list with a first step that says, "BUY MY SOFTWARE AND THEN I WILL HELP YOU".

But sir, this is just more work!

True, it is, in the short term.

There's the old software adage, "You can't fight piracy.. those zit faced virgins wouldn't have bought your software anyway."

Now consider a convenient store keeper. He doesn't say, "Those kids wouldn't have bought candy anyway.. let them just steal it!"

Stealing from a faceless corporation is one thing, but the App Store isn't a corporation. It's made up of software from people like you and me. Apple takes a sizable cut for being the proxy between sellers and buyers so this doesn't leave much of a margin for sellers.

In other words: Every penny counts.

If you can catch someone who has pirated your software, and willfully convert them into a buyer, then you've made some cash. If you ignore piracy then you've made nothing.

Homework

Re-read this article, re-read my previous articles. You now have the tools to catch a pirate and hopefully take his money.

Be sure to leave a comment here if these methods have worked for you.

I'll be presenting something really interesting within the coming week, so stay tuned!