[Discussion] Removing DC Flag

08/30/2009 19:02 logan432#106
Quote:
Originally Posted by gopotato View Post
@spideys

first of all, im pretty sure you are running cabalmain.exe which is still packed.
secondly, cabal doesnt hang as you attach to its process, it is PAUSED.
lastly, using plugins are useless if you dont know WHAT THEY DO.

protip1: each different plugin performs different tasked that they are programmed to do. meaning, using a plugin WITH NO RELATION to what you are trying to do is simply USELESS.

@hackers who made this hack work: heres something new for us guys:

I made the old "god mode" work. meaning, stacking bracelets/earrings with no negative stacks. (defense hack / 30k alz drop (max for Cabalph) et. al.)

heres how:
1. Simply do the old process of stacking, it will DC.
2. Perform the cracking of the exe.
3. Voila, stacking god mode works.

Why does this happen:
I found out that there isnt only one trigger for DC. certain actions have certain DC flags, THEY ARE NOT ON THE SAME TRIGGER. which gives me the idea that it "MAY" be possible to the accessory hack that was posted on the other page. I will reply here after I verify that.

EDIT: what is god mode? god mode is the previous version of the damage/2 slot item hack, in which has no negative effect (like getting 1 alz or reducing defense value to negative when using Earring of guard, thus getting one shotted even by garlies)
thanks
08/30/2009 22:32 zero-maed#107
This just keeps getting better and better.
And now to put it 0n action....think I'll go crazy once i get this done.

Thanks for the new info.
08/31/2009 01:04 168Atomica#108
Quote:
Originally Posted by NoobWant2Learn View Post
by the way.. is opening the file cabal .exe and finding the oep=unpack??? whats the difference between a pack and a unpack pls shed some light
uhmmm yes but not exactly
unpacking would include other procedures such as header erasing, IAT redirection, CRC checks, protection bypass and finding the OEP, among others...

but SINCE- we have a bypass (CR in this case) to do some stuff for us, what you need to do is find the OEP. :rtfm:

@dlqt thank you for your post in this thread - I already figured out that I do not need to study bypassing. It's the file adapter.dll you mentioned earlier which allowed me to figure out that all I need is a bypass.

I hope with this hint, you could eliminate some sweat for studying anything that won't help you to reach dmg/2slot hack. (Well if you are on a hurry)
08/31/2009 01:33 ayer0924#109
can anyone tell what is olly? and how can it help us? I dont understand what it is all about..

Sorry for being so innocent about that thing.... I hope someone can explain it to me...
08/31/2009 02:56 168Atomica#110
google it...
08/31/2009 03:49 sparrowaie#111
does this mean dc flag = trigger address?? but the root problem for us noobs would be the unpacking part. to start with, what exactly is the protection/packer of cabalmain.exe? i see in PEiD its yoda 1.x / modified. and i know that its not accurate. any accurate ideas? this will really help us learn.
08/31/2009 04:12 HumanaOne#112
Quote:
Originally Posted by 168Atomica View Post
uhmmm yes but not exactly
unpacking would include other procedures such as header erasing, IAT redirection, CRC checks, protection bypass and finding the OEP, among others...

but SINCE- we have a bypass (CR in this case) to do some stuff for us, what you need to do is find the OEP. :rtfm:

I hope with this hint, you could eliminate some sweat for studying anything that won't help you to reach dmg/2slot hack. (Well if you are on a hurry)
but how do we find the OEP, whenever i try to Find OEP by Section Hop (Trace Into), i always end up inside the ntdll module and then it terminates at address: 77175E74

... please give us some light in unpacking the cabalmain.exe file in the correct manner
08/31/2009 04:37 NoobWant2Learn#113
thats my problem also.. i read the MUP OLLYDbG+OLYDMP. all i understand is finding the oep by using the plugin ollydump... after w/c it leaves me no idea... pls help guyz
08/31/2009 05:57 junnifer#114
i'm really confuse on which people are really telling the truth. gopotato said using CabalRider is enough to bypass GG. but he also said an Unpacked cabalmain.exe is needed. The way I understand it, CabalRider is design to call cabalmain to execute.
I already did unpack cabalmain and when I'm trying to run it using ollydbg, it was detected by GG. So I tried using Rider to bypass GG and like what I said I think it is design to call cabalmain.exe. I'm not sure if gopotato really know what he is talking about.

I also tried running 1st cabalmain using Rider for bypass, then attach it to ollydbg and like others problem it pauses.

Running cabalmain again using Rider for bypass, attached my unpacked cabalmain and unfortunately nothing happens.

What I really think at this stage is a plugin which can hide my ollydbg. Already tried all the plugin that is recommended here but nothing works for me.
08/31/2009 05:59 bboyecko#115
Quote:
Originally Posted by gopotato View Post
well okay, seriously I dont want to be rude to others who are giving TIPS, but oh well. here goes: Im shedding some light to you:

first of all, WHY THE FCK WOULD YOU NEED HIDEOLLY/PHANTOM?

-no, seriously you dont need that.

You will need that so that GameGuard wont detect that you are attaching ollydbg to Cabal.

But how the fck will you STACK WITHOUT BYPASSING GG? so thats why YOU DONT NEED IT. what you need is a working bypass to enable both OLLYDBG and Cheat Engine. (preferrably CabalRider)

A working bypass is ENOUGH to let olly and CE attach themselves to cabal.

If you guys dont get what I mean, then you seriously need to stop working on this.

I dont know if the guys who posted that are trying to let you FIND OUT that you dont actually need this, to see your observation skills, or hes just fckng around with you. but hey, you should be thankful to them anyway. Because although the information is a bit misleading, it still gives me the idea on how to make this work.
hideolly to hide it from GG and mhs (which ofcourse is made undetected) to hook unto cabal.exe
08/31/2009 06:16 NoobWant2Learn#116
as for hideolly plugin i already did consult my friend mr.google about it, but i think hes directing me to hidedbg, is this the same with hideolly?? i cant really find hideolly plugin.. to my understanding, unpacking the cabal itself and attaching it to olly wont work. i need a person whose telling the exact path for us.. sorry for bad english... i know lots of people are trying to help here, but this leads me to nowhere.... sigh.. im really determined to make this work....*yawn, pls pretty pls with sprinkle on tops guide us to the right path..
08/31/2009 07:53 gopotato#117
@junnifer

you got it partly wrong. ofcourse you need both a bypass and an unpacked cabalmain.exe. but here is where you get it wrong. you are not using the bypass on the UNPACKED cabalmain. i'll be too kind to tell you how to retarget your CR

using CR, change the target of CR from the original cabalmain.exe to your MODIFIED cabalmain.exe. how? its SIMPLE.

a.Get a new cabalrider installer.
b.Install cabalrider to your desired directory.
c.Run your newly installed cabalrider.
d.Click on start game, you will notice that an error message will appear asking for the location of your cabalmain.exe
e.select your UNPACKED cabalmain.exe as the target.
f.bham now you're running your unpacked cabal hooked with CR to bypass GG.

actually im pissed at you, you being stupid doesnt mean I dont know what Im saying okay? Any more insult I get from any of you will result me to NOT GIVING OUT ANY MORE HELP. got it?

why are fckng people keep on asking things and if they cant do it right, blame it on the person trying to help? its so pathetic
08/31/2009 08:11 spankwirenation#118
can i insult you? hehe
08/31/2009 08:15 gopotato#119
I dare you to do so

EDIT:

LOL. selfish mofo, you already have a working exe. If you Insult me, it wont affect you

haha. bad bad kid
08/31/2009 08:23 bboyecko#120
Quote:
Originally Posted by gopotato View Post
@junnifer

you got it partly wrong. ofcourse you need both a bypass and an unpacked cabalmain.exe. but here is where you get it wrong. you are not using the bypass on the UNPACKED cabalmain. i'll be too kind to tell you how to retarget your CR

using CR, change the target of CR from the original cabalmain.exe to your MODIFIED cabalmain.exe. how? its SIMPLE.

a.Get a new cabalrider installer.
b.Install cabalrider to your desired directory.
c.Run your newly installed cabalrider.
d.Click on start game, you will notice that an error message will appear asking for the location of your cabalmain.exe
e.select your UNPACKED cabalmain.exe as the target.
f.bham now you're running your unpacked cabal hooked with CR to bypass GG.

actually im pissed at you, you being stupid doesnt mean I dont know what Im saying okay? Any more insult I get from any of you will result me to NOT GIVING OUT ANY MORE HELP. got it?

why are fckng people keep on asking things and if they cant do it right, blame it on the person trying to help? its so pathetic
wow all that uninstalling/installing, error message etc made me get a headache :rolleyes:
just rename it :cool: