Any Ideas? (Debugging Cabalmain.exe)

09/11/2009 22:02 howcow95#1
Well I managed to get a TwinR to be able to Live Debug Cabalmain.exe I even managed to get the proper asm codes in olly so I load up TwinR to attempt to use it as a bypass to be able to Live Debug but it ends up that TwinR detects my olly and it shuts down! I've already tried to run it sandboxed but it doesn't work.... any other ideas?
09/12/2009 10:53 oren_studio#2
y dont u run twinr first to bypass, close twinr (make sure the process has been terminated in the task manager), then attach olly to cabalmain?
09/12/2009 22:59 howcow95#3
will try... and lol it's hard to explain but I don't really have TwinR someone who wants the hack aswell is offering to let me use their's but they don't wana give it to me until they can do the hack themselves so I wusn;t able to fool around and see my options much but ty! I will try this!


edit: dusnt work ... cabal simply closes wen u run olly
09/20/2009 19:23 ktamer#4
I'm having this same issue. I need a bypass but there isn't one around for NA. So what I tried was running Cabalmain.exe and at the update screen opening Ollydbg. Then I try to attach to cabalmain.exe and select Start Game at the Update Window. I was hoping that the instant Shut down might show in Olly but after analyzing anything Olly freezes and shuts down. I get nowhere I get nothing. Without a proper X-Trap bypass, removing the Flag, or even finding the possible address/value is next to impossible. I've tried using Hideolly and Phantom. Both of which X-Trap can still find instantly...:mad:
09/20/2009 21:17 howcow95#5
well heres something I can share with you and maybe you can help me back O.O ... if you use StrongOD instead of phantOm (don't use phantOm at all it has to be uninstalled) then you can bypass TwinR's security but the thing is you can't unpack and livedebug cabalmain.exe without using the phantOm .dll sooooooo you must open up cabalmain.exe(using phantOm) dump it, fix it then close olly and take out the phantOm and install StrongOD than you might be able to open the unpacked cabalmain.exe without using phantOm but the thing is I'm having various issues with getting the cabalmain.exe fixed I get it dumped and it's 11701 kb but after that I'm unable to fix it properly using imprec, what happens is that the unpacked and dumped and supposedly fixed cabalmain.exe doesn't run like norm cabalmain... infact it doesnt run at all >.>
09/21/2009 07:31 zen83#6
This is a file that you uploaded on forum few weeks ago. I've tried to unpack it, i'm not so sure this will work or not since i don't have Cabal NA install on my PC.
[Only registered and activated users can see links. Click Here To Register...]
09/21/2009 09:27 NovaCygni#7
Quote:
Originally Posted by ktamer View Post
Both of which X-Trap can still find instantly...:mad:
Im gathering you havnt set the correct settings in the Plugins menu for them!
[Only registered and activated users can see links. Click Here To Register...] [Only registered and activated users can see links. Click Here To Register...]

And a olly folder with plugins and scripts that work with Xtrap :
[Only registered and activated users can see links. Click Here To Register...]
09/21/2009 13:05 howcow95#8
what phantOm are you using .... mine has slightly more options but even with those options ticked it still doesn't work >.> maybe it could be the phantOm i'm using?
09/21/2009 16:26 Teandormus#9
Im just wondering , what u can get if u unpack cabalmain rufl ? ._. sry for offtop but im interested.
09/21/2009 18:50 .Law.#10
Use dmg hack,all methods,and alz drop rate hacks.
Use a bug/exploit to never spend CC on Cash Shop items( you need the CC but it wont go down)
Name hack to "[GM]XXXXXX" server sided.
Class hack /with beeing able to buy skills.
More smaller things.
09/21/2009 20:54 ktamer#11
Everything Nova provided was more than amazing. Unfortunately enough for me I'm still at block one. I try to run Cabal through Cabal Rider. Should I make an attempt to use TwinR. Because the attempts I've made fail because it either wont load or it says there's a corrupt cabal.enc file. I configured PhantOm like Nova suggested. And then also tried what cow suggested. I think I'm stuck with a POS cabalmain.exe. So, might I be lacking in resources? I have relative knowledge, just this X-Trap is a true Hell.
09/21/2009 22:00 Teandormus#12
O____________O Punk u should try to debug q,q <gimme>
09/21/2009 22:16 .Law.#13
Pft,If I was able to run the unpacked exe. till' now i would've given you et alrdy nubie >:,still stuck,but there are some new imortant tips , will try again later since im overloaded with school /etc.
09/21/2009 22:55 howcow95#14
dam punk >.> I know I'm doing something wrong while I'm either unpacking or dumping and I'm pretty sure it has to do with the OEP that I think I found lol... because once it's dumped and supposedly fixed my unpacked.exe doesn't run lawl it tells me that somethings wrong and hacking has been detected or something like that >.>

as for debugging punk... can you debug w/o getting detected?
09/21/2009 23:01 .Law.#15
Err,cabal EU sux,so I have no problem doing it ;d,and same goes for me,can't run the unpacked file yet.
[Only registered and activated users can see links. Click Here To Register...]
You can find another flash-type tut on unpacking an exe,this time that exe is packed with UPX.