Packet Type 15000?

10/02/2011 01:24 Cyanogen#1
Hi,

Anyone know what this packet is for? It looks like it's full of a random mess.
10/02/2011 01:49 Korvacs#2
Im pretty certain thats not a valid packet type, unless you wanna post a dump of it so that we can take a look at it.
10/02/2011 01:55 Cyanogen#3
Code:
Server -> Client - Type:0x3a98 Size:38
 >1E00983A B900F433 43771E1D EE812EE4< ...:...3Cw...... 00000000
 >901AE7E8 FC152355 ACCE0000 00005451< ......#U......TQ 00000010
 >53657276 6572<                       Server           00000020
Client doesn't ever seem to respond to it, but there are a lot of them, even just standing still doing nothing. I thought it might be related to the 1022 (switch 56) packets, if you know what I mean. Data in it is different every time, most likely some kind of cypher?

Looking through my packet log i noticed the first 2 bytes after the type always has the high order byte as 0 (assuming the value is 16 bit) but the low order byte can be anything from 00-ff. Last 4 bytes are always 0's.
10/02/2011 02:08 Korvacs#4
Is this on the latest client?
10/02/2011 02:13 Cyanogen#5
Yes, i just grabbed that packet literally 10 minutes ago.

Doesn't seem to effect the bot-check as far as I can see (i have blocked it and not been bot-jailed), but I'm getting worried it's a "delayed" detector. Similar to what WoW does, lets them compile a list of botters then ban-wave them all.

I'd crack open OlyDbg and try to see what the client was doing with it if I had better debugging skillz, but my experience in that area is very limited.
10/12/2011 03:57 Cyanogen#6
I think it's an anti-private server packet. Kind of the reverse of a client check, a server verifier. Could be wrong though but I can't see what else it could possibly do.
10/12/2011 07:08 BaussHacker#7
Have you checked if there is any response back to the server with the packet type?

If not, then you're probably right about it's a server identifier.
01/30/2012 22:33 phize#8
Quote:
Originally Posted by Heroka View Post
did u try to rebuild it . and reinstall netframework again maybe that help .
Holy fuck, you retard. Stop posting.
01/30/2012 23:00 { Angelius }#9
Never bothered to figure out whats the use of that packet but its never new and has nothing to do with the current patch thing its been there for over then 3 months now,

10/26/2011 was the very fist time i saw that packet. and it looks like this
PHP Code:
Length 30Type15000
1E 00 98 3A 24 00 14 F2 AA 08 87 4E F1 A1 13 69                 
; ?:$ ???N??i
B6 2F 16 26 E1 25 DB 2A DC F7 00 00 00 00                         
;/&?%U*U÷