Cracked CabalRider (CabalRider_SG1.0.14 - No Payment)

06/02/2008 02:49 rags2bitches#1
Taken from GZP


What This Package Contains

- The latest CabalRider bot for SG (CabalRider_SG1.0.14 as of 1st June 2008)

The actual bypass..

- Unpacked + modified CabalRider.exe, Adapter.dll, Impetus.dll to point to 127.0.0.1 for Server 1
- CabalRiderRider_server.exe - A fake authentication server originally coded in Perl & ported to VB6

Additional files..


- MSWINSCK.OCX - for the Winsock component used in my VB6 auth server

Why am I releasing this?

This was originally intended to be a private bypass for my friends who could not afford / did not wish to pay the RM30 fee for CabalRider.. however it turns out I cannot trust most of my 'friends' as they would choose to sell and distribute my creations for their own profit.

This is against my principles as I do what I do because I can. Furthermore, if it's going to be leaked out against my will - the authors of the bot might as well know about it and patch the flaw in their authentication system.

How does it work?

CabalRider (after a little probing with Wireshark, Olly & WPE Pro) turns out to be vulnerable to a simple authentication replay attack. The server does just that, replays a successful authentication sequence twice. One for the initial loader and the second request made by the .dll files once they have been loaded into Cabal.

This is only for CabalSEA and will be my last attempt at cracking CabalRider.

---

Mirrors Provided by Heip

[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]

Credits to the CabalRider Team for the bot, exile (me) for the bypass. Enjoy

UPDATE : Received mix feedback from the people here at GZP. It may or may not work for you (this is, afterall a simple bypass and the actual login routine may exchange hashes that are unique to each machine). However, it does work on all my 3 PCs, my friends PCs and a vast majority of other systems out there.

I came up with this roughly less than 2 days after CabalRider went pay to use so yeah, consider this more of a PoC (Proof of Concept) rather than a fully and extensively tested release.
06/02/2008 03:06 max5473#2
but this were the last work of the maker.

after xtrap patched/cabal rider new version outs.
this not work anymore.although some1 learn how to do this from the maker XD
06/02/2008 04:48 salemchai#3
the carck cannnot use properly when i try to login it hang on loading
06/02/2008 04:55 requiescence#4
Good thing it doesn't work. Pity it's allowed to post these things on this forum.
06/02/2008 05:23 start3214#5
i can login but login to game bot no out for me use....
06/02/2008 05:39 spiritkobra#6
work like charm
ths alot
06/02/2008 05:40 lollipopolol#7
now cabalrider is version 1.5 and need pay also sad
06/02/2008 05:47 revilion#8
thanks dude.
really..
06/02/2008 05:58 fama#9
same here. i can login but couldn't call out the bot menu in-game.
hopefully someone here can dissemble the files or teach us how to dissemble the files to bypass the authentication server.
lol
:P
06/02/2008 06:24 kevin90#10
Clean enought???

Antivirus Version Last Update Result
AhnLab-V3 2008.5.30.1 2008.05.30 -
AntiVir 7.8.0.26 2008.06.01 -
Authentium 5.1.0.4 2008.06.01 -
Avast 4.8.1195.0 2008.06.01 -
AVG 7.5.0.516 2008.06.01 -
BitDefender 7.2 2008.06.02 -
CAT-QuickHeal 9.50 2008.05.31 -
ClamAV 0.92.1 2008.06.02 -
DrWeb 4.44.0.09170 2008.06.01 -
eSafe 7.0.15.0 2008.06.01 suspicious Trojan/Worm
eTrust-Vet 31.4.5837 2008.05.30 -
Ewido 4.0 2008.06.01 -
F-Prot 4.4.4.56 2008.06.01 -
F-Secure 6.70.13260.0 2008.06.02 -
Fortinet 3.14.0.0 2008.06.02 -
GData 2.0.7306.1023 2008.06.02 -
Ikarus T3.1.1.26.0 2008.06.02 -
Kaspersky 7.0.0.125 2008.06.02 -
McAfee 5307 2008.05.30 -
Microsoft 1.3520 2008.06.02 -
NOD32v2 3150 2008.06.01 -
Norman 5.80.02 2008.05.30 -
Panda 9.0.0.4 2008.06.01 Suspicious file
Prevx1 V2 2008.06.02 -
Rising 20.46.62.00 2008.06.01 -
Sophos 4.29.0 2008.06.02 Sus/ComPack-C
Sunbelt 3.0.1139.1 2008.05.29 -
Symantec 10 2008.06.02 -
TheHacker 6.2.92.331 2008.06.02 -
VBA32 3.12.6.6 2008.06.01 -
VirusBuster 4.3.26:9 2008.06.01 -
Webwasher-Gateway 6.6.2 2008.06.01 Win32.Malware.gen!80 (suspicious)
06/02/2008 06:30 leelc99#11
if you think it isn't safe, don't use it. i don't care anymore, i just wana rider. woohoo!
06/02/2008 06:33 kevin90#12
but does not work tho
06/02/2008 06:38 francescliu#13
same here. i can login but couldn't call out the bot menu in-game.
hopefully someone help us to solve it...
06/02/2008 06:44 iloveit123#14
cant work!!can open the starter!! but cant load the game!! grrr
06/02/2008 06:47 sk8leton89#15
it works LOL..just read the readme guys..and thanks to rags2bitches ;)