another HackShield bypass method

11/22/2011 18:05 Yiting#1
OUT OF DATE.
11/22/2011 20:53 keepDan#2
I bet you don't know what the kernel driver is.

Quote:
Originally Posted by Yiting View Post
I wrote a small program could launch HackShield as a service, then all clients just shared this instance without any protection (they are in different processes). YES! you can run multiple game client directly.:awesome:


How to Use
- Download and Extract CrackShield.zip
- Place HSLaunch.exe, dinput8.dll into your Mabinogi folder
- Run HSLaunch.exe, and waiting tray balloon tip shown (about 3~30 seconds).
- Run Mabinogi

Features
- Graceful shutdown all scanning thread, only main thread just run a message loop without any scanning method.
- Automatically remove kernel driver entry of HackShield, while program exit.
- Blocked network logging to HackShield site.

Comments
- You can run any debugging tool (OllyDbg, Cheat Engine... etc) freely, but don't try to attach HSLaunch's process, it still protected by kernel driver.
- Source of dinput8.dll has included, if someone need to integrate into other mods.
11/22/2011 22:55 Checkbox#3
Hi. Can I know the environment you developed this for? What OS, what version of HackShield, and what version of Mabinogi you developed this for?

Your method of bypassing is pretty interesting since I didn't think of it and didn't expect it would work so I would like to look into getting it to work and personally confirm that your idea works. Given the quality of the program, I assume you did confirm that your idea works so I figure that it's something on my end rather than you jumping the gun and releasing something that doesn't work. You did check that you can log into the game before releasing this, right?

I tested this on Windows XP 32-bit on the current version of NA Mabinogi with HackShield updated to the current version. While I was able to confirm the multiclienting part and that it does get around the EagleNT restrictions, it gives an auth error when I try to log in. I looked at your code and you just make it skip everything but the auth function so I assume you deal with the checks that would normally make the auth function choke when calling it without running the init functions in your HSLaunch program.

Also, I'm interested if you came from another modding community since it's not often I see capable people pop out from nowhere.
11/23/2011 00:03 Yiting#4
I'm using Win7 64bit, version of EhSvc.dll is 5.5.10.147, game version is ver99.
I didn't fully tested on WinXP since my virtual pc cannot run mabinogi.:(

Quote:
Originally Posted by Checkbox View Post
Hi. Can I know the environment you developed this for? What OS, what version of HackShield, and what version of Mabinogi you developed this for?
11/23/2011 01:21 kcy1019#5
This is interesting..
I never expected that method like this will work, too.
and multiclienting is GREAT!

Thank you for releasing this :D

(Anyway, since I'm using 32bit WinXP, I can see only the auth error and can't login..)
11/23/2011 01:38 Checkbox#6
This is with a clean client, right? This isn't used with anything else?
You also did make sure you were able to log in? I'm talking with people who tested with a similar environment to what you specified and they also got an auth error.
11/23/2011 02:11 xlogic#7
I'll try on Vista. ;o
11/23/2011 07:02 Yiting#8
I made a small test suite for friends, and known this version only works on 64bit Windows with EagleX64.sys....

Now, I'm trying to deal with EagleXNt.sys, may not be so fast....
11/24/2011 10:22 Yiting#9
A new version for both 32bit and 64bit Windows, tested on XP and 7 (new method should be working on Vista, too).

Please keep Client.exe and HShield folder clear, those file used for identify which game HackShield running in.
11/24/2011 15:50 Epvp_God#10
Quote:
Originally Posted by Yiting View Post
A new version for both 32bit and 64bit Windows, tested on XP and 7 (new method should be working on Vista, too).

Please keep Client.exe and HShield folder clear, those file used for identify which game HackShield running in.
???!!!
11/25/2011 00:46 tylian1#11
Works perfectly. :)

Still not convinced it's safe but, it works. No doubt about that. :D
11/25/2011 01:45 Checkbox#12
I looked at the file and I couldn't find anything suspicious. It's actually well designed software. If it did anything malicious, the author hid it very very well.
11/25/2011 01:48 lilaznboy2#13
Quote:
Originally Posted by Checkbox View Post
I looked at the file and I couldn't find anything suspicious. It's actually well designed software. If it did anything malicious, the author hid it very very well.
But it works! Who caaaaares. :D
11/25/2011 01:49 tylian1#14
Quote:
Originally Posted by lilaznboy2 View Post
But it works! Who caaaaares. :D
Me! :l
11/25/2011 01:52 Checkbox#15
These comments are made because people are naturally suspicious of contributions here due to others constantly [Only registered and activated users can see links. Click Here To Register...]. I'm basically saying that this software is safe which I think is something that should be said so that people will be more comfortable with trying it out. It's a waste if software such as this isn't appreciated.