[Discussion] Removing DC Flag

08/21/2009 03:17 NovaCygni#16
Quote:
Originally Posted by dlnqt View Post
So far:

For removing the dc flag, all I have to learn is removing dc flag by attaching ollydbg to process, get disconnected by wearing bracelets then tracing back to the dc flag, once i find the 1 byte and the value it should be changed to, on to the next step.
Well actually what your technically doing is not bypassing the DC itself but the check that happens BEFORE the d/c.
Quote:
Originally Posted by dlnqt View Post
So if I want to do a lot more than this, I should learn packet parsing and decryption (client can do this for me to my understanding :D)??
Nope you should learn Ollydbg, Reversing and ASM... will take you, what, 2 months of learning, and you could be happilly stackin Alz instead of damage :)

*Edit a good practice project for learning is to "De-Parenthise" cabal.exe ;) Google is allways a beginners best friend...
08/21/2009 03:35 cabalbuyer#17
got 2 pro on ollydbg
08/21/2009 03:55 dlnqt#18
I was ablt to stack alz on official server from 1 to 30k. Stackeld Alz for hours and maybe I did something, I have screen to prove. :D Maybe yours has no limit XD

EDIT: what packer does cabalmain.exe use anyway? I don't think its yoda 1.x, I think its yoda 1.0.3.2.. What do you mean by de-parenthisizing? I search for it in google, the only thread it pointed to was your discussion in cabal eu forums :p
08/21/2009 04:11 cabalbuyer#19
pro n rich for u both. sell me ur guide if can. i willing to pay for it. hehe
08/21/2009 04:16 dlnqt#20
LOL. I'm am but far from getting that to work. and even if I get it to work, I'll won't sell it to anyone.. This is for educational purposes as it will widen my knowledge on asm :D and it will also help me on other games and not just cabal.

If you also want to this kind of hack, just follow our discussion and try to do it yourself. It's really helpful.
08/21/2009 04:20 cabalbuyer#21
i never study this kind of program but i have study C++ vitial basic all basic knowledge only. that y i read all that u 2 discuss i just know a bit but still blur to me.
08/21/2009 04:41 168Atomica#22
i WONT even sell it for 10kphp or even higher
i love cabal and I was really pissed off when power was bestowed to kidz who doesn't even have the second thought of using it on large scale...

fortunately the game is patched and i thanked nova for the wisdom he shared. I was working with the tool a since I joined elite... but I stopped.

Let the price be to those who are deserving to have them..

Goodluck to those GM who said that this thing is impossible.... hahahhahha. They have seen the consequences of their mockery.

-AMEN


@dlnq - we're on the right path buddy. Hope we make it to the higher circles of reversers ^^ goodluck
08/21/2009 04:54 dlnqt#23
.... reserved. posted something terrible..
08/21/2009 06:19 ibonehj15#24
haha
bumpy n_nV
ill be reading this guide over and over again
i maybe TOO NOOB on everything but
ill be trying this as well
the thing i need to know is unpackingT_T
hehe well thanx nova and dlnqt
credits for you
and cheers
08/21/2009 06:29 ibonehj15#25
sorry double post
where on earth can we get yoda 1.0.3.2
wud that be yoda widget??
sorry as i st8ed with my 1st post here
that im all noob at this
but im willing to study this ^^
cheers again
08/21/2009 07:52 totoybakal#26
Quote:
Originally Posted by dlnqt View Post
I already know how to unpack cabalmain.exe, but my question is where will I change the 1 byte for DC flag? Will I use CE (code caving/or just freezing values) or do I have to make changes to cabalmain.exe itself?

Also, I don't have a clue if there's such a thing as a "live" debugger. Wherein if I attach a debugger to the process, and if I do something in-game like equip a bracelet, will I see the debugger change? (if it will point if I jumped into something etc)

Thanks
Hi, I am trying to create an application that will allow damage/2-slot hack to work again
in Cabal PH. Can you kindly give me some pointers on how to unpack cabalmain.exe?

I had downloaded one tool that identifies that the packer used in cabalmain.exe is
yoda's cryptor 1.x / modified. Is this accurate? I also read somewhere in other forums that packer used was asprotect. I don't know yet which one is correct.

I've been trying to unpack the file using yoda and/or asprotect unpacking tools that
I had found in the Internet. But none of them had succeeded so far.

Do I have to manually unpack cabalmain.exe or are there already available tools out there
that can be readily used to unpack it?

Thanks in advance.
08/21/2009 14:00 168Atomica#27
no we will not spoonfeed things anymore.
just give hint and clues and references.

you should all earn only what you can do..
things you cannot do means-- you should try harder

regarding your question, a simple tutorial is available... As seen on many posts, google is your best friend

[Only registered and activated users can see links. Click Here To Register...]
08/21/2009 15:07 spankwirenation#28
any success with this guys?
08/21/2009 19:19 NovaCygni#29
Quote:
Originally Posted by 168Atomica View Post
no we will not spoonfeed things anymore.
just give hint and clues and references.

you should all earn only what you can do..
things you cannot do means-- you should try harder

regarding your question, a simple tutorial is available... As seen on many posts, google is your best friend

[Only registered and activated users can see links. Click Here To Register...]
Well done!!! ;) Like the way I hinted to get the olly plugins ;) Id list all I had but then people would just download them without knowing why they needed them, and Googling things just makes things easiar for people to understand... oh my other favorite resource after Google, is Wiki... if ever a term or method is used you dont understand try Wiki first if you can and THEN google so u better understand what your searching for...


Deparenthised exe : A exe file that does not require a "Loader"... for example using the Husky command to bypass autopatch and the loader is "Technically" doing what I Deparenthised exe does...
08/21/2009 20:36 bboyecko#30
damn gotten quite inactive regarding this, glad to see people making advancements on themself instead of asking others how to do it step-by-step.

time for me to also try this