COPAC - Conquer Online Packet Logger / Editor

07/02/2005 18:43 adrianna#16
found the packet that gives ping lol

14 00 F1 03 16 24 12 00 00 00 00 00 1B 00 00 00 ; .....$..........
74 72 13 00 ; tr..
07/02/2005 18:48 chocoman4k#17
XtremeX-CO:
You don't have to edit in order to check if you can cheat this way. There are 2 possible vulnerabilities:
1. You can pick up more gold than you dropped.
2. You can drop more gold than you have.

As we know that we cannot see the exact details of items before we didn't pick them up for example +1 +2 + 3 etc, 1 or 2 sockets, the gems in it, exact amount of gold, we know that number 1 *probably* won't work. You just pick up the Sycee/Silver/Gold and the server gives you the exact amount of silver you just picked up. So we must work with number 2. OK, log a packet where you dropped 100 silvers. Now take those silvers up again and give them to a friend or get rid of them in another way, just don't put them at exactly the same location where you picked them up. When you got 99 or less silvers in your inventory, try to send the packet again. Now if you see that you dropped 100 silvers although you didn't have so much, we know that it's working. I personally don't think it will work, but I'd be glad to hear the opposite :P

About your packets that pick the gold up, as you can see no specific pattern it might be that you only tell the server that you picked the gold up, not -how much- gold you pick up. And the changing values are probably the coordinates. This would proove that 1 will not work, number 2 is left to try. Have fun :D

Sired22:
I could add that feauture, when enough people request it or I find some nice way to do it :)
Of course I could add such a small script, but it maybe wouldn't be worth the time.
I think that better fits into an item dropper tool than in a packet logger/editor don't you think :P

adrianna:
Haha nice :P
07/02/2005 19:38 pappawolfie#18
tested cant drop more than you have in your inventory, did get it tho to where i can drop at a fixxed location could be fun messin with noobs in market 100 gold appear outta no where :)
07/02/2005 19:45 sniper__freak#19
hmmm, we can try this with sockets ;)
07/02/2005 20:00 BadBoY_AC#20
hmmm well... u can drop gold and pick it up.. but u use ur gold.. and get not new gold... :(

edit: i found the packet for withdraw gold from warehouse..... but still not remaining in warehouse..

but works everywhere lol
07/02/2005 20:36 XtremeX-CO#21
Heres the gw jump packet, go to gw, stand outside the wall and just press this until it says invalid jump and u dc, relog and ure inside.

1C 00 F2 03 97 15 90 00 68 FF 11 00 E2 00 C6 00 ; ........h.......
00 00 00 00 D3 00 C5 00 8E 00 00 00 ; ............

doesnt seem to work anymore o well ill make another 1 later
07/02/2005 20:49 sniper__freak#22
guys, i was thinking maybe were taking the wrong approach, i have a method that might guarantee us getting mets/dbs/drops tell me if this is true,

another person drops a DB/met/item on teh ground
you record and get the packet of them dropping it,
then u re-emulate that, to make the server think that theres mets/db/items there

we should also try this for xp skills and HP/MP
07/02/2005 20:53 XtremeX-CO#23
ok has anyone found anything better ? all I have is 2 sm, maybe u can make it work

1C 00 FE 03 8F 19 D2 A7 4E 0B 12 00 77 25 23 CF ; ........N...w%#.
07 34 86 B6 15 00 00 00 FB E7 21 B8 ; .4........!.

1C 00 FE 03 60 1F D9 A7 4E 0B 12 00 77 25 23 CF ; ....`...N...w%#.
07 B4 86 CE 15 00 00 00 FB E7 21 57 ; ..........!W

and sme jump packets which work. If you edited the walking packets, or not even edit just resend, u could walk,but ure client doesnt see it. u can only see when u hit an invalid coordinate
07/02/2005 21:04 sniper__freak#24
xtreme, nice work i think the 2nd line is telling the co-ords
07/02/2005 22:41 chocoman4k#25
BadBoY_AC:
share :)
Maybe you can post withdraw and deposit packets?
And aswell try to take items from warehouse?

sniper__freak:
This would not work, as you are not authorized to do actions for other people.
And if they got no DB/met/item they cannot drop it.
Everything else would be client side.
07/02/2005 22:47 ~Unknown~#26
I tested the wh deposit and withdraw and i got this...

Withdraw
14 00 F1 03 08 00 00 00 10 27 00 00 0B 00 00 00 ; .........'......
6B 5C FA 03 ; k\..

With deposit I seemed to get two real quick so check these out

14 00 F1 03 08 00 00 00 00 00 00 00 09 00 00 00 ; ................
D6 9E FC 03 ; ....


14 00 F1 03 08 00 00 00 10 27 00 00 0A 00 00 00 ; .........'......
D6 9E FC 03 ; ....



*Edit* Btw if it matters 10000 silver was deposited and withdrawn.
07/02/2005 22:51 chocoman4k#27
Would be useful to know how much money you have withdrawn/deposited or which item you've stored/taken.
07/02/2005 22:52 ~Unknown~#28
Check my edit :D
07/02/2005 22:58 chocoman4k#29
Alright, 10000 decimal equals 2710 in hexadecimal. Convert 2710 to low endian and the result is 1027.

14 00 F1 03 08 00 00 00 10 27 00 00 0B 00 00 00 ; .........'......
6B 5C FA 03 ; k\..

there is our 10 27 :)
No clue what the 0B means though.
Did someone try withdrawing outside of the city and on maps with no warehouses?
07/02/2005 23:01 ~Unknown~#30
I withdrew it on the tc map with a warehouse, but just now I attempted on a map with no warehouse and my Co logger and conquer just closed...>.<