 |
Cheat Engine The Official Site of Cheat Engine
|
| View previous topic :: View next topic |
| Author |
Message |
Zand Master Cheater
Reputation: 0
Joined: 21 Jul 2006 Posts: 424
|
Posted: Sat Nov 24, 2007 11:42 pm Post subject: |
|
|
| Jewbacca does another method which removes the requirement of emulating packet auth algos. What I saw in Matsy's method, however, is just the mov eax,262 to mov eax,755 and the push 00 (CreateProcessA). This disables gameguard from functioning (handles), therefore removing its ability to verify with the server that it is still running, hence you get dced(in gunz). The server - gameguard client callback used to be once every 3-5 minutes, then proceeded to be once every 10-30 seconds (and right after a successful login procedure), now it is somewhere in the 2 minute range (last I checked).
|
|
| Back to top |
|
 |
Zand Master Cheater
Reputation: 0
Joined: 21 Jul 2006 Posts: 424
|
Posted: Sun Nov 25, 2007 5:33 am Post subject: |
|
|
Jewbacca basically used Matsy's method along with a 3rd address, which would somehow "bypass" the server checks. This is because GunZ, like MapleStory, would DC if the server realised gameguard wasn't running. As far as I can recall, using Matsy's method in MapleStory woudn't let you login. When Jewbacca first posted this method in the GunZ section, you would be able to login and play until the check (about 3 minutes after you login).
Matsy's method woudn't be that hard to port, considering that if you do a CTRL+F find for "mov eax, 262" it will be the only one, and searching for "CreateProcessA" woudn't be that hard either. What you posted might be the code, I can't be sure, because the added section would delete itself. What legion did beyond Matsy's method was to enable us to stay connected to the server by emulating the gameguard callback from the server, making the server think gameguard was running. Depending on which gunz.exe you have (there were two), check inside the added section (-L-o-D-).
|
|
| Back to top |
|
 |
Legion How do I cheat?
Reputation: 0
Joined: 19 Jul 2007 Posts: 3
|
Posted: Thu Nov 29, 2007 4:20 am Post subject: |
|
|
Thou shall be enlightened.
Wall of text version.
Lets begin with xtrap.
A long time ago i used to run a gameclient emulator on international gunz online.
I used it to help powerlevel people who had been deleted.
Eventually xtrap was added to the game.
It did not take long until the authsystem in xtrap was put into use.
Inorder to complete the loginstage you need to supply the server with a valid hashkey.
It could look like this:
Seed: 276626477456472F
Hashkey: 49293-27419-E11CB-5B345-DB962
So inorder to generate these hashkeys properly from the seed i had to reverseengineer xtrap.
And so i did...
If i look at xtrap today, the algorithm to generate these keys is diffrent.
It has been greatly simplified, probably would take half the time to reverseengineer it,
compared to the old variant.
One of my modified gameclients got leaked and that might have been the cause for the rewrite...
All in all, this should answer the question:
"Does xtrap have server auth capabilities?"
"Yes! It's up to the gamedeveloper wether they implement it or not..."
MAIET never coded their own security system so it's a spawn of wiselogic..
In gunz online it's used when you login and then periodicly (like every 5 minutes, to poll that xtrap is running).
Since my keygen now should be outdated i have included it as a download.
Sourcecode ofcourse...
Check it out if you are interested in the old workings of xtrap
The code wasn't exactly cleaned so it's a bit ugly, though it was fully functional.
Now on to Gameguard.
The server auth has been used since gameguard first appeared on ijji gunz.
Every now and then you get a request from the server, like:
MC_REQUEST_GAMEGUARD_AUTH(index, value1, value2, value3)
The gameclient will respond with something like:
MC_RESPONSE_GAMEGUARD_AUTH(index, value1, value2, value3)
I ofcourse wanted to run my clientemulator on ijji gunz.
So i had to reverseengineer the gameguard keygenerator algorithm.
This i did and it ran happily with my clientemulator.
As i sidenote, i also ran it on my windowsmobile smartphone.
Due to alot of reasons gameguard isn't really well suited for gunz,
it will steal way to much CPU time and cause fps drops.
Because of this reason i created my "annihilator" exe's.
1. They were simple modifications of the gunz gameclient where i made sure gameguard wasn't loaded.
2. For this to work i simply hooked myself into the command processing (MC_REQUEST_GAMEGUARD_AUTH) and diverted
these calls(2 of them) to my keygenerator.
So no, this is not a bypass, it's a emulation of the server auth scheme.
Gameguard wasn't loaded, keygen calls diverted.
I should note that gamemon was packed with themida at this time.
Gunz was emergency patched and i didn't release any more modified clients.
It did not take long for INCA to act.
They modified the auth algorithm.
Somewhere along here they also changed settings/upgraded themida/used code virtualizer as parts of the keygenerator now is virtualized.
Im not really a oreans product expert, so i can't say exactly what they did.
The most important corepart of the algorithm looks intact, apart from this the codeflow is diffrent.
I saw someone comment on the post where i mentioned execryptor.
The story about this was that i did some reversing on a japanese game released in 2005.
This game had parts obfuscated with a now obsolete version of execryptor.(not virtualmachine based)
Since i was a bit bored i wrote a deobfuscator.
In the same process i also implemented my own obfuscator based on these results, however i slightly improved it.
To follow the good spirit of crackme's i used this obfuscator on the keygenerators in my modified gameclients.
Now i would like to give some advice for thoose that jump to conclusions way to fast:
Always properly analyze a program before you claim to know what it does,
else it will make you look like a fool.
/Legion
|
|
| Back to top |
|
 |
dadypop Master Cheater
Reputation: 0
Joined: 23 Dec 2005 Posts: 362 Location: [email protected]
|
Posted: Tue Dec 11, 2007 7:21 pm Post subject: |
|
|
ZOMFG!!?!?! IT'S LEGION?!?!? FTW?!? LEGION POSTING ON CEF? ZOMFGD WTF WTG BBQSAUCE!
Nice to hear from you again Legion.
That should shut up x0r's mouth.
x0r, I know you're a genius and all...I know your life story...finishing high school at age 9 and stuff...and then learning stuff w/ computers for a few years b4 you go to university..but seriously dude...chill out.
Eventually there will be some things beyond your comprehension. Just because it seems to be past your level, doesn't give you the right to criticize it.
Everything OWS and Legion have said is true. Just because you have a bit of proof to prove them wrong, DOESNT MAKE YOU 100% RIGHT!
Maybe they have OTHER proof to COUNTER your proof which would make your proof invalid.
And as my dad always told me, "NEVER ASSUME ANYTHING. When you assume something, you make an "ass" out of "u" and "me"."
Kthx.
_________________
| prohacker53 wrote: | | hello i see this 2x exp card so i byed two of the same and when it was time i only get 2x exp and not 4x????? must i activate something because i only get 2 exp for for example a snail when i should get 4???? |
LAWLZ PWNED. |
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
|