BY-PASS hackshield RF novus rising summary

11/16/2009 12:53 Crisliboon#31
Quote:
Originally Posted by jhejay01 View Post
turning off the kernel is way to sophisticated. as well us building up a HS that wont inject the DLL of RF.

bypassing new RFPH is very easy just do some experiment inside the
hackshield folder and thats it! nasa en-ph ^^


1st, method sa BIN. edit nyo. hanapin nyo yung "Declaration na" "Game Hack Ditected"
2nd, wag nlng kayu mag tanong kung pano. C++ gamitin nyo.
"UPX" ang pag pack nila sa RF exe. nandun lahat kailangan nyo. enjoy.


as you notice inside the hackshield folder may mga
nadagdag na files just do something to this new 3 folder...
and xmpre sa files na psapi.dll and EHsvc.dll.. i know u knew it...

what i did is to make a dummy files or to fool the game that it really uses the real hackshield.

Let's start with the files that come along with hackshield, these are:

- EhSvc.dll
the main Hackshield file, contains the HackShield class used by Engine.dll,
does the basic functions like loading/unloading its kernel mode driver, file integrity scanning,
memory integrity scanning. the checksum generated by the
integrity scans are used to authenticate with the game-server

- v3warpns.v3d and v3warpds.v3d
contain each a kernel mode driver (.sys file) in encrypted from, one v3d contains a
win9x driver the other a winNT driver.
once the driver has been loaded it will protect the ro process from being accessed
(read/write) by every non-kernel mode programm
(example: taskmanager)

- v3pro32s.dll
i didn't look at it yet, but i suspect it to be the loader for the .sys driver files (.v3d files)
maybe not written by Hackshield creators

- EGRNAP.dll and EGRNAPX2.dll
ahhnlab "anti-virus" scanning libs, probably used to scann for programms like packet sniffers,
memory editors etc

- Hshield.log
produced by EhSvc.dll, its encrypted with an evolving XOR key, i've reversed that algo,
its included in my hackshield emu source & there's a ready to use decryption tool in SagaTools,
however it doesn't contain much useful info
(basically logs detections/checksum errors for gravity/hackshield to investigate)

- psapi.dll
a proccess helper library by Microsoft, nothing special




clue :
1. bypass HS.
2.edit rf bin. (EHSvc.dll related)
3.edit rf.exe using XVI32 [launcher] (edit it so the patcher wont patch your edited HS folder)


Check nio ha sa en-ph folder ng rf eh may mga hidden files which is a process status helper.
Hindi katulad dati na 3 lang ang DLL, ngaun more than 10 na. CCR put it there for a reason.
Hindi lang psapi.dll ang tumatakbo ngaun madami pa.
Ung iba naddc kahit ma bypass pa nila kasi ngaun may server side checks na ginagawa ang server ng LU
per client na nakakonek sa kanila so if 1 of the DLL's doesn't respond, disconnected kayo.

ALL THOSE THINGS WAS IDEAS COMBINED IM THIS FORUM....
PAG USAPAN NATIN PARA MAGAWA NA
:):):):):):):):):):):)
is this bypass also can done to RF equilibrium or any Private servers?

if yes can u PM me here or just reply here :D

wishing your attetion.
11/19/2009 03:52 jpogzs#32
Try your best guys. It took me one month to figure out the bypass. Btw I don't edit any of the RF files. I just use some programs. Just try harder.
11/21/2009 05:20 BeelZeelBub23#33
^^ Uu nga tama sya, baka masira nyu lang RF sa PC nyu. Hanap na lang kayu ng iba dyan...
11/21/2009 07:04 soulhart#34
Quote:
Originally Posted by jhejay01 View Post
turning off the kernel is way to sophisticated. as well us building up a HS that wont inject the DLL of RF.

bypassing new RFPH is very easy just do some experiment inside the
hackshield folder and thats it! nasa en-ph ^^


1st, method sa BIN. edit nyo. hanapin nyo yung "Declaration na" "Game Hack Ditected"
2nd, wag nlng kayu mag tanong kung pano. C++ gamitin nyo.
"UPX" ang pag pack nila sa RF exe. nandun lahat kailangan nyo. enjoy.


as you notice inside the hackshield folder may mga
nadagdag na files just do something to this new 3 folder...
and xmpre sa files na psapi.dll and EHsvc.dll.. i know u knew it...

what i did is to make a dummy files or to fool the game that it really uses the real hackshield.

Let's start with the files that come along with hackshield, these are:

- EhSvc.dll
the main Hackshield file, contains the HackShield class used by Engine.dll,
does the basic functions like loading/unloading its kernel mode driver, file integrity scanning,
memory integrity scanning. the checksum generated by the
integrity scans are used to authenticate with the game-server

- v3warpns.v3d and v3warpds.v3d
contain each a kernel mode driver (.sys file) in encrypted from, one v3d contains a
win9x driver the other a winNT driver.
once the driver has been loaded it will protect the ro process from being accessed
(read/write) by every non-kernel mode programm
(example: taskmanager)

- v3pro32s.dll
i didn't look at it yet, but i suspect it to be the loader for the .sys driver files (.v3d files)
maybe not written by Hackshield creators

- EGRNAP.dll and EGRNAPX2.dll
ahhnlab "anti-virus" scanning libs, probably used to scann for programms like packet sniffers,
memory editors etc

- Hshield.log
produced by EhSvc.dll, its encrypted with an evolving XOR key, i've reversed that algo,
its included in my hackshield emu source & there's a ready to use decryption tool in SagaTools,
however it doesn't contain much useful info
(basically logs detections/checksum errors for gravity/hackshield to investigate)

- psapi.dll
a proccess helper library by Microsoft, nothing special




clue :
1. bypass HS.
2.edit rf bin. (EHSvc.dll related)
3.edit rf.exe using XVI32 [launcher] (edit it so the patcher wont patch your edited HS folder)


Check nio ha sa en-ph folder ng rf eh may mga hidden files which is a process status helper.
Hindi katulad dati na 3 lang ang DLL, ngaun more than 10 na. CCR put it there for a reason.
Hindi lang psapi.dll ang tumatakbo ngaun madami pa.
Ung iba naddc kahit ma bypass pa nila kasi ngaun may server side checks na ginagawa ang server ng LU
per client na nakakonek sa kanila so if 1 of the DLL's doesn't respond, disconnected kayo.

ALL THOSE THINGS WAS IDEAS COMBINED IM THIS FORUM....
PAG USAPAN NATIN PARA MAGAWA NA
:):):):):):):):):):):)




ARAL ulit ako ng Computer Classes para mas MADALI ko tong intindihin...
11/21/2009 12:48 bagofjoy#35
mga tol pakipost nman yung name ng computer shop and exact location kung saan may RF Equilibrium..totally wipe out kc yung computer shop dito (Pasig) sa amin eh. Thanks
11/21/2009 12:48 bagofjoy#36
gamitin nyo search engine...the Net is very usefull...
11/22/2009 09:58 ujeen#37
all i can say is nawawalang gana na ako sa mga online games... puro nlng bug hacks cheat nakikita ko.... no matter what the developer will do to their game to make it safe, it is still a programming language that can be edit and bypass... ika nga eh walang padlock na ginawa na walang kasamang susi.... hays sana sing taba ng utak nyo ang utak ko... ang masasabi ko lang ay magaling ang pinoy napu2nta nga lang sa kalokohan... ^_^
11/23/2009 13:39 bagofjoy#38
Quote:
Originally Posted by ujeen View Post
all i can say is nawawalang gana na ako sa mga online games... puro nlng bug hacks cheat nakikita ko.... no matter what the developer will do to their game to make it safe, it is still a programming language that can be edit and bypass... ika nga eh walang padlock na ginawa na walang kasamang susi.... hays sana sing taba ng utak nyo ang utak ko... ang masasabi ko lang ay magaling ang pinoy napu2nta nga lang sa kalokohan... ^_^
Yabang mo rin pare noh...alam mo ba kung saan ka... pmunta ka lang dito pra mang-insulto... ayos ka rin noh... akala mo kung malinis tong taeng to... HOY!!! Pinoy ka rin at tao ka rin.. this is part ng buhay ng tao...TAE.. Mataba raw baka yabang mo mataba rin...o baka puro hangin lng yan..sus.. Pinoy ka nga...TAE!!!
11/23/2009 14:36 novusdeathole#39
Quote:
Originally Posted by soulhart View Post
ARAL ulit ako ng Computer Classes para mas MADALI ko tong intindihin...




nde tinuturo sa skul yan sariling sikap yan...
11/24/2009 06:40 soulhart#40
Quote:
Originally Posted by novusdeathole View Post
nde tinuturo sa skul yan sariling sikap yan...
Un basics ba...
11/24/2009 13:26 bagofjoy#41
Wag kau masyado...sugapa.. parang gusto nyo lahatin ang hack,,, paano kau mgeenjoy nyan sa laro... ginagamit ko fly hack lang and autoloot (coin thing - during yosi break) nde na kailangan yang mga iba parang walang kachallenge challenge na laruin yung games pag ganun.. minsan damage hack pero ginagamit ko sa mobs lang during lvl 50's and up.. mahirap nman ibully ung mga nglalaro ng patas...

sya nga pala yung gamit nila dyan is C++... tapos na problema nyo kau na bahala mgtweaking... iresearch nyo na lang sa internet yan... kung gusto nyo ng libre na kahit ano check this out... [Only registered and activated users can see links. Click Here To Register...]... libre to download nyo lang yung bittorrent...tapos

enjoy...
11/27/2009 11:45 novusdeathole#42
grrrrrrrrrrrr wla pa rin update.........
01/27/2010 08:02 jasperondgo#43
DONT WASTE UR TIME PEOPLE, MAKUNTENTO NALANG KAYO SA MGA HINTS NILA SINCE ELITEPVPERS HAVE A MOTTO "GREED IS GOOD" EDI GANUN NALANG DIN GAWIN NIYO PAG NATUTO KAYO EDI WAG NIYO NARING I SHARE, ITS UP NALANG PO SA INYO KUNG MAGBIBIGAY KA NG HINTS OR NOT..... WELL AFTER ALL THE HEADACHES THAT IVE BEEN THROUGH AND A LITTLE DETAIL FROM OTHER PEOPLE WHO POSTED SOME HINTS WORTH NAMAN KC IKA NGA NILA "THE STRONG MAY LIVE, BUT THE WEAK WILL TRIUMPH" :handsdown::handsdown::handsdown:
01/27/2010 09:47 kingxking#44
palagay ko visual studio yan kc 40k php ung package nun tapos visual c++ ung program ^^
01/27/2010 11:00 myljon#45
hayz... mag aral na lang keo ng c++...

amf!!! d kami nag aaral ng c++

direct JAVA na kami kahit 1st year college pa lng T_T