 |
Cheat Engine The Official Site of Cheat Engine
|
| View previous topic :: View next topic |
| Author |
Message |
Macka Cheater
Reputation: 0
Joined: 08 Oct 2006 Posts: 26
|
Posted: Thu May 08, 2008 6:13 am Post subject: Finding a mathematical connection for server emulation |
|
|
Hi guys,
I'm trying to emulate a server, I have 2 packet captures of the "same" communication, and there is only a slight difference between the 2 sets of captures.
Packet Capture 1
Client sends the following
| Code: | 00000000 68 e1 31 33 43 20 26 20 53 20 4d 61 63 6b 65 6e h.13C & S Macken
00000010 7a 69 65 00 00 00 00 00 00 73 65 72 76 65 72 00 zie..... .server.
00000020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
00000030 00 00 00 00 00 00 00 00 00 00 53 57 5f 44 00 00 ........ ..SW_D..
00000040 00 00 00 00 00 73 65 72 76 65 72 00 00 00 00 00 .....ser ver.....
00000050 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
00000060 00 00 00 00 00 00 54 00 00 00 00 00 00 00 00 00 ......T. ........
00000070 00 00 00 32 39 39 32 00 00 00 00 00 00 00 69 38 ...2992. ......i8
00000080 36 5f 6e 33 00 00 00 00 00 00 00 0a 08 37 38 00 6_n3.... .....78.
00000090 31 34 00 14. |
Server Responds with
| Code: | 00000000 2f c3 1b 89 00 25 01 0e 00 00 07 b5 00 00 00 00 /....%.. ........
00000010 00 00 00 00 0a 08 01 04 00 73 65 72 76 65 72 00 ........ .server.
00000020 53 57 5f 44 00 SW_D. |
Packet Capture 2
Client Sends
| Code: | 00000000 68 de 31 33 43 20 26 20 53 20 4d 61 63 6b 65 6e h.13C & S Macken
00000010 7a 69 65 00 00 00 00 00 00 73 65 72 76 65 72 00 zie..... .server.
00000020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
00000030 00 00 00 00 00 00 00 00 00 00 53 57 5f 44 00 00 ........ ..SW_D..
00000040 00 00 00 00 00 73 65 72 76 65 72 00 00 00 00 00 .....ser ver.....
00000050 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
00000060 00 00 00 00 00 00 54 00 00 00 00 00 00 00 00 00 ......T. ........
00000070 00 00 00 33 37 33 36 00 00 00 00 00 00 00 69 38 ...3736. ......i8
00000080 36 5f 6e 33 00 00 00 00 00 00 00 0a 08 37 38 00 6_n3.... .....78.
00000090 31 34 00 14. |
Server responds with
| Code: | 00000000 2f 6b 1e 63 00 25 01 0e 00 00 17 70 00 00 00 00 /k.c.%.. ...p....
00000010 00 00 00 00 0a 08 01 04 00 73 65 72 76 65 72 00 ........ .server.
00000020 53 57 5f 44 00 SW_D. |
Looking at line 8 of the clients messages I have
00000070 00 00 00 32 39 39 32 00 00 00 00 00 00 00 69 38 ...2992. ......i8
00000070 00 00 00 33 37 33 36 00 00 00 00 00 00 00 69 38 ...3736. ......i8
The only difference is the (hex) 32 39 39 32 from the first packet capture and the (hex) 33 37 33 36 from the second packet capture.
Looking at the server responces the differences are again minimal.
00000000 2f c3 1b 89 00 25 01 0e 00 00 07 b5 00 00 00 00 /....%.. ........
00000000 2f 6b 1e 63 00 25 01 0e 00 00 17 70 00 00 00 00 /k.c.%.. ...p....
For the first paket capture the server reponds with (hex) c3 1b 89 and for the second it responds with (hex) 6b 1e 63
I believe there is some connection between (hex) 32 39 39 32 and (hex) c3 1b 89
and that this connection is the same for (hex) 33 37 33 36 and (hex) 6b 1e 63
I just cant figure out what it is. does anyone have any ideas or suggstions on how i can find the connection. i dont think the rest of the packet matters, because they are exactly the same apart from the differences i pointed out
_________________
"I Believe it is an eye-dee-ten-tee error, it takes too long to explain. Have a nice day sir" - Tech Support |
|
| Back to top |
|
 |
Estx Expert Cheater
Reputation: 0
Joined: 04 Mar 2008 Posts: 172
|
Posted: Thu May 08, 2008 8:04 am Post subject: |
|
|
| Code: | 00000000 2f 6b 1e 63 00 25 01 0e 00 00 17 70 00 00 00 00 /k.c.%.. ...p....
00000010 00 00 00 00 0a 08 01 04 00 73 65 72 76 65 72 00 ........ .server.
00000020 53 57 5f 44 00 SW_D. |
I'll break it up for you from my initial analysis of the packet (most likely inaccurate).
2F - First byte, obviously the packet switch for whatever the command is.
The next 4 bytes may be the client-server tick/userid/client-server version..?
The 6th byte may be the packet length.
11th and 12th may be the port.
33rd to 36th may be the IP.
.. What game server are you trying to emulate?
And as for understanding packets, pay attention to the environment at the time - what the time is, what user is connected, how many are connected, what IP's/Port's are being negotiated etcetera.
What happens if you just return to the client the same value that was sent?
|
|
| Back to top |
|
 |
Macka Cheater
Reputation: 0
Joined: 08 Oct 2006 Posts: 26
|
Posted: Thu May 08, 2008 11:07 pm Post subject: |
|
|
The Uni I go to offers SolidWorks (a 3D CAD program) for free to the students, the catches are:
The students must provide their own DVD to burn the installation files off the Uni's network
The students need to connect to the Uni's VPN via the internet to borrow a license for up to 30 days at a time. This requires the students to have the interenet, a fair few people don't have the internet (living in student accomodation, cant afford it etc), The other option is to bring your computer in and connect to the Uni's network, also not an option for many.
I want to be able to emulate the server so those people can get a license key, however the emulated server will be hard coded so they can only borrow the license for the duration of the course.
I would have to agree, 2f is almost definately the packet switch, it appears to occur only when the initial connection to the server is made.
There is some sort of handshake going on here, and if an incorrect responce is supplied the server will not complete the handshake (it will stop sending data but keep the connection active.
The initial packet structure appears to be:
68 e1 31 33 [Hex for Computer users account name, in this case C & S Mackenzie] 00 00 00 00 00 00 [Hex for Computers name, in this case my PC is called "Server"] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 53 57 5f 44 00 00 00 00 00 00 00 [hex for computer name again] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 54 00 00 00 00 00 00 00 00 00 00 00 00 [some sort of checksum or something] 00 00 00 00 00 00 00 69 38 36 5f 6e 33 00 00 00 00 00 00 00 0a 08 37 38 00 31 34 00
The responce packet structure, as ESTX pointed out:
2f [3Bytes Responce Checksum] 00 25 01 0e 00 00 [2Bytes, also part of the responce check sum, or i assume so] 00 00 00 00 00 00 00 00 0a 08 01 04 00 [Computers name again] 00 53 57 5f 44 00
_________________
"I Believe it is an eye-dee-ten-tee error, it takes too long to explain. Have a nice day sir" - Tech Support |
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
|