Elsword's security system by Adrian

01/01/2014 13:06 Adrian420#1
Good evening,
As some people may have heard by now on this game a secret logging system represents the most powerful weapon against hackers.
The main issue I hope to cover here is how logs look like and what's being logged.


What's being logged:
  • The level of your character as well as the dungeon you're playing in. For example: you can’t access x-2 secret dungeon at lv 6 unless you are a hacker.
  • Drops of all kind: ED and items acquired.
  • All dungeon results: for example how much ED/ Exp you have acquired, clear time, etc.
  • How many mobs you have killed during the respective run.
  • What stages you clear during the run.
  • How much damage you deal. By knowing this we can assume that they also know how much dmg you receive or if you receive anything at all.
  • Based on the value and particularities of the damage you have dealt or received they might be able to guess about how much: phy/mag attack/defence, add.dmg, crit, red.dmg and evasion, you have. What I can say for sure is that when you kill a mob they know exactly how much damage you have dealt and if it was a critical hit or not.
  • Since they know if mobs receive damage or not they also know by what means dies a mob.
  • They know how many accounts you have by tracking your IP. Every account you have ever accesed with your IP(even once) is counted as " one of your accounts". This is how many innocents get banned when a hacker gets banned on IP.
  • They log trades of all kind: mail, direct, board. They know what item you trade.
  • They know from which account to which account goes the item you have send. They recognize accounts not only by IP but also by name. As simple as: account "x" is trading with account "y".
  • They know the exact date of all logs. Year,month,week,day,hour,minute. Logs have a length in time of 5 or more months which makes me believe that logs never get deleted.
  • Logs are stored in your account's history. In other words your account is "the main villain" not your characters - deleting or renaming a character is pointles since logs remain on your account's history.
  • Mods are detectable and bannable.
  • They have a list of all items you have on your account and their effects/particularities. They know which items[gear, costumes, accessories] you have used during a run and their characteristics[enhancement, effects & sockets].

Secret KOMCheck algorithm:
Exactly as the name suggests the client runs a secret, hidden KOMCheck method/algorithm that checks KOM files.
This KOMCheck method/algorithm:
-Is incorporated in the game's client,
-Does not need files from the internet (non-bypassable),
-Only reports when the normal KOMCheck and this second method give different results (i.e. when the normal KOMCheck has been bypassed),
-Does not close the client but each time it detects a modified KOM file an entry in the login packet is sent to the server.

This is how admins can find out if you have a modded client and since the alteration of the client is strictly forbidden by T&C you can legitly get banned even if you don't have any abnormal logs.
Example: bans took for voice mods follow this system.

Solution:
Basically, you don't have to edit KOM files.
Programs like [Only registered and activated users can see links. Click Here To Register...] , ELX or Cheatengine can alterate the in-game experience without making modifications in the structure of the KOM.

Special thanks to Joni-St who analised the client binary and made this descovery.



Safe way to hack based on IP change:


I'm a hacker and I'm in big trouble, what should I do?

What I want to add:
These are only my ideas on how to evade security. Based on the presented info about logs you may come up with better solutions. Do whatever you decide to do and keep in mind that variety will save your ass.

Prints:
I had more but I've lost them when my old hard-disk broke. Some info here can be confirmed not only by me but also by any hacker who made a ticket after getting banned.

That's all, I hope this topic helps people understand how things work. Also feel free to update my list with anything useful that's not already been told.
01/01/2014 13:23 Parampaa#2
I can't understand that ticket :facepalm: , could you translate it?
01/01/2014 13:35 Adrian420#3
Quote:
Originally Posted by Parampaa View Post
I can't understand that ticket :facepalm: , could you translate it?
Here
Use google translate, I don't know german.
01/01/2014 20:14 Otes#4
#Approuved

I also had an ip ban
4 accound, 3 with cheat and 1 without cheat.
01/03/2014 00:42 JackSkywalker#5
does anyone have a good ip changer?
01/03/2014 01:10 Adrian420#6
Quote:
Note that we do not provide details about the investigation.
Absolutely hilarious.
Unfortunately now is too late for them to do that. I made a swear that if they ever send me to grave again I'm taking their security down with me.
They saw me guilty for hacking, I see them guilty for treating children and their feelings as a piece of wood, for throwing away people's work and friends, for abusing power.
Thank you for support Otes, I really appreciate your efforts.


Quote:
does anyone have a good ip changer?
Your internet provider is the best IP changer.
01/03/2014 05:24 Parampaa#7
Hmm, it's still impossible for GM to spend all his time to check all player logs then inspect one by one, right?

And, they have bunch support ticket, managing game, and etc, right?
01/03/2014 07:07 Adrian420#8
There isn't only one person checking logs. They have a team for this.
And checking one by one? No, as you may see, they IP ban everything they find.

Though ...
There is something that makes me think they need fresh data to find you, mainly because normal logs are constantly replacing abnormal logs(like in a long long list). So if you stop now you might have a slight chance.
Keep in mind that this is only an assumption with a low chance of probability, I don't have enough information to confirm something like this.
Also what if they automatically "underline" abnormal logs? so they can easily find them afterwards. Everything is possible.
And you know ... many people have a hack account and safe account: the discovery of the hack account and a IP ban will most likely lead to the same result.
In other words: you have this high probability that stop hacking now won't make any difference.
01/03/2014 12:08 Parampaa#9
I think better not talking/asking about our ID (for cheating) or keep it secret so the GM won't see our logs. But, bug trap function still bothering me, it send screen shoot when the game crashes then automatically delete that file. The file name is ErrorLog.txt and Crash_ScreenShot.jpg in \data folder, do you have any idea how to deny it being sent except disconnecting internet?
01/03/2014 23:50 Adrian420#10
Quote:
I think better not talking/asking about our ID (for cheating) or keep it secret so the GM won't see our logs. But, bug trap function still bothering me, it send screen shoot when the game crashes then automatically delete that file. The file name is ErrorLog.txt and Crash_ScreenShot.jpg in \data folder, do you have any idea how to deny it being sent except disconnecting internet?
What you're trying to do seems to be the job of a sniffer.
Quote:
Who have delete my reply ?
Maybe a forum moderator, because it was double post. But don't worry, you can now check my post for the 3rd img.
01/15/2014 17:33 Otes#11
Ok... :/ !

So for henir farmeur I suggest you to use a vpn and never connect your main account as your ip cheating account !
If you have 2 PC it would be nice too and don't forget to use vpn, A Good vpn.
01/17/2014 21:41 Adrian420#12
Update.
I've been trying to make the list more intelligible for you guys, therefore, some points that were pretty messed up got a fresh and hopefully a more "friendly" aspect.
My english still needs a lot of practice:facepalm:

2nd Update
Further aspect improvements and some new hacking strategies.

3rd Update
The introduction was modified:
-Shorter.
-The term "records" was changed into "logs", highlighting that logs exist in text format not in video format.
Mild hacks updated:
-Elemental resistance


4th Update:
-New information added to the list.
-4th screenshot
01/31/2014 11:52 BabyBeelz#13
Bumping coz poster asked me to
02/07/2014 17:56 Adrian420#14
Update.
02/08/2014 23:41 oinah#15
you posting these will make them think on how to deal with ELX files soon