Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


WinAPIHook
Goto page Previous  1, 2, 3, 4
 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming
View previous topic :: View next topic  
Author Message
Zand
Master Cheater
Reputation: 0

Joined: 21 Jul 2006
Posts: 424

PostPosted: Sat Nov 24, 2007 11:42 pm    Post subject: Reply with quote

Jewbacca does another method which removes the requirement of emulating packet auth algos. What I saw in Matsy's method, however, is just the mov eax,262 to mov eax,755 and the push 00 (CreateProcessA). This disables gameguard from functioning (handles), therefore removing its ability to verify with the server that it is still running, hence you get dced(in gunz). The server - gameguard client callback used to be once every 3-5 minutes, then proceeded to be once every 10-30 seconds (and right after a successful login procedure), now it is somewhere in the 2 minute range (last I checked).
Back to top
View user's profile Send private message
Zand
Master Cheater
Reputation: 0

Joined: 21 Jul 2006
Posts: 424

PostPosted: Sun Nov 25, 2007 5:33 am    Post subject: Reply with quote

Jewbacca basically used Matsy's method along with a 3rd address, which would somehow "bypass" the server checks. This is because GunZ, like MapleStory, would DC if the server realised gameguard wasn't running. As far as I can recall, using Matsy's method in MapleStory woudn't let you login. When Jewbacca first posted this method in the GunZ section, you would be able to login and play until the check (about 3 minutes after you login).
Matsy's method woudn't be that hard to port, considering that if you do a CTRL+F find for "mov eax, 262" it will be the only one, and searching for "CreateProcessA" woudn't be that hard either. What you posted might be the code, I can't be sure, because the added section would delete itself. What legion did beyond Matsy's method was to enable us to stay connected to the server by emulating the gameguard callback from the server, making the server think gameguard was running. Depending on which gunz.exe you have (there were two), check inside the added section (-L-o-D-).
Back to top
View user's profile Send private message
Legion
How do I cheat?
Reputation: 0

Joined: 19 Jul 2007
Posts: 3

PostPosted: Thu Nov 29, 2007 4:20 am    Post subject: Reply with quote

Thou shall be enlightened.
Wall of text version.

Lets begin with xtrap.
A long time ago i used to run a gameclient emulator on international gunz online.
I used it to help powerlevel people who had been deleted.
Eventually xtrap was added to the game.
It did not take long until the authsystem in xtrap was put into use.
Inorder to complete the loginstage you need to supply the server with a valid hashkey.
It could look like this:
Seed: 276626477456472F
Hashkey: 49293-27419-E11CB-5B345-DB962

So inorder to generate these hashkeys properly from the seed i had to reverseengineer xtrap.
And so i did...
If i look at xtrap today, the algorithm to generate these keys is diffrent.
It has been greatly simplified, probably would take half the time to reverseengineer it,
compared to the old variant.
One of my modified gameclients got leaked and that might have been the cause for the rewrite...
All in all, this should answer the question:
"Does xtrap have server auth capabilities?"
"Yes! It's up to the gamedeveloper wether they implement it or not..."
MAIET never coded their own security system so it's a spawn of wiselogic..
In gunz online it's used when you login and then periodicly (like every 5 minutes, to poll that xtrap is running).
Since my keygen now should be outdated i have included it as a download.
Sourcecode ofcourse...
Check it out if you are interested in the old workings of xtrap Smile
The code wasn't exactly cleaned so it's a bit ugly, though it was fully functional.

Now on to Gameguard.
The server auth has been used since gameguard first appeared on ijji gunz.
Every now and then you get a request from the server, like:
MC_REQUEST_GAMEGUARD_AUTH(index, value1, value2, value3)
The gameclient will respond with something like:
MC_RESPONSE_GAMEGUARD_AUTH(index, value1, value2, value3)

I ofcourse wanted to run my clientemulator on ijji gunz.
So i had to reverseengineer the gameguard keygenerator algorithm.
This i did and it ran happily with my clientemulator.
As i sidenote, i also ran it on my windowsmobile smartphone.

Due to alot of reasons gameguard isn't really well suited for gunz,
it will steal way to much CPU time and cause fps drops.
Because of this reason i created my "annihilator" exe's.
1. They were simple modifications of the gunz gameclient where i made sure gameguard wasn't loaded.
2. For this to work i simply hooked myself into the command processing (MC_REQUEST_GAMEGUARD_AUTH) and diverted
these calls(2 of them) to my keygenerator.
So no, this is not a bypass, it's a emulation of the server auth scheme.
Gameguard wasn't loaded, keygen calls diverted.
I should note that gamemon was packed with themida at this time.

Gunz was emergency patched and i didn't release any more modified clients.
It did not take long for INCA to act.
They modified the auth algorithm.
Somewhere along here they also changed settings/upgraded themida/used code virtualizer as parts of the keygenerator now is virtualized.
Im not really a oreans product expert, so i can't say exactly what they did.
The most important corepart of the algorithm looks intact, apart from this the codeflow is diffrent.

I saw someone comment on the post where i mentioned execryptor.
The story about this was that i did some reversing on a japanese game released in 2005.
This game had parts obfuscated with a now obsolete version of execryptor.(not virtualmachine based)
Since i was a bit bored i wrote a deobfuscator.
In the same process i also implemented my own obfuscator based on these results, however i slightly improved it.
To follow the good spirit of crackme's i used this obfuscator on the keygenerators in my modified gameclients. Wink

Now i would like to give some advice for thoose that jump to conclusions way to fast:
Always properly analyze a program before you claim to know what it does,
else it will make you look like a fool.

/Legion



The Extension 'rar' was deactivated by an board admin, therefore this Attachment is not displayed.

Back to top
View user's profile Send private message
dadypop
Master Cheater
Reputation: 0

Joined: 23 Dec 2005
Posts: 362
Location: [email protected]

PostPosted: Tue Dec 11, 2007 7:21 pm    Post subject: Reply with quote

ZOMFG!!?!?! IT'S LEGION?!?!? FTW?!? LEGION POSTING ON CEF? ZOMFGD WTF WTG BBQSAUCE!

Nice to hear from you again Legion.

That should shut up x0r's mouth.

x0r, I know you're a genius and all...I know your life story...finishing high school at age 9 and stuff...and then learning stuff w/ computers for a few years b4 you go to university..but seriously dude...chill out.

Eventually there will be some things beyond your comprehension. Just because it seems to be past your level, doesn't give you the right to criticize it.

Everything OWS and Legion have said is true. Just because you have a bit of proof to prove them wrong, DOESNT MAKE YOU 100% RIGHT!

Maybe they have OTHER proof to COUNTER your proof which would make your proof invalid.

And as my dad always told me, "NEVER ASSUME ANYTHING. When you assume something, you make an "ass" out of "u" and "me"."

Kthx.

_________________
prohacker53 wrote:
hello i see this 2x exp card so i byed two of the same and when it was time i only get 2x exp and not 4x????? must i activate something because i only get 2 exp for for example a snail when i should get 4????


LAWLZ PWNED.
Back to top
View user's profile Send private message AIM Address Yahoo Messenger
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming All times are GMT - 6 Hours
Goto page Previous  1, 2, 3, 4
Page 4 of 4

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites