Updated GWA2

02/05/2020 19:51 Boostachu#1
Hello community,

This is an updated version of GWA2. It does not support all functions yet. Different people worked on it, I did NOT check it so please use it at own risk, it is open source so you can check it yourself.
02/06/2020 10:54 Boostachu#2
Quote:
Originally Posted by Der Moench View Post
WARNING
Don't use it ... malware inside!
Since it is open source, can you tell me which lines include malware? Otherwise I will report your post as spam
02/06/2020 11:59 Boostachu#3
Quote:
Originally Posted by Der Moench View Post
lines 4400 and 4401
I have compared both the old GWA2 and the updated one, and those lines are almost identical. I also used Virustotal on the file, zero detections. Please stop trolling.



[Only registered and activated users can see links. Click Here To Register...]


Quote:
Originally Posted by CoderAndy View Post
i didn't checked everything but the lines you saying dosen't have anything malicious, probably you trying to scare ppl, are you that guy Prince something ???

it seems like a copy cat account of DerMoench14 and copy paste the warning posts.
Probably teq mad because he can't sell his GWA2 scam.
02/06/2020 12:02 random/#4
teq is a french terrorist
02/06/2020 12:05 Der Moench#5
Quote:
Originally Posted by CoderAndy View Post
i didn't checked everything but the lines you saying dosen't have anything malicious, probably you trying to scare ppl, are you that guy Prince something ???

it seems like a copy cat account of DerMoench14 and copy paste the warning posts.
You can check all the injection code using the debugger and make sure which addresses are stored in memory and track the data overshoot. If you check this carefully, you will find that the beginning of the movement begins with these lines. After that, you will enter the login and password information, all this will be sent by the code further.

Quote:
Originally Posted by Boostachu View Post
I have compared both the old GWA2 and the updated one, and those lines are almost identical. I also used Virustotal on the file, zero detections. Please stop trolling.



[Only registered and activated users can see links. Click Here To Register...]




Probably teq mad because he can't sell his GWA2 scam.
I looked at the code movement, You can see for yourself that the ASM code is not secure. Did you specifically write this file to trick people and steal their accounts?
02/06/2020 12:29 Der Moench#6
Most likely the author of the topic is in a conspiracy with scammers, because people will trust him with his reputation.
02/06/2020 12:46 Der Moench#7
Quote:
Originally Posted by CoderAndy View Post
i didn't say that it's safe for ppl to download, i said about the lines and the injection code you saying it's false, post a pic with olly or ida pointing at that specific addresses then.

you copied the name of another person that has reputation so who tries to scam ?
I sent you the beginning of the code where the user data theft begins. I will not prescribe detailed instructions on how to do this, because attackers will see this method and start using it, you must understand this.
02/06/2020 13:10 Boostachu#8
Quote:
Originally Posted by Der Moench View Post
I sent you the beginning of the code where the user data theft begins. I will not prescribe detailed instructions on how to do this, because attackers will see this method and start using it, you must understand this.
That is like saying "just trust me, I won't show evidence because then people might copy it" to the judge.

If you really want to convince people, then show valid proof. Also you should write on your main account instead of posting on a freshly made account faking another user.

And to clarify, like CoderAndy, I did not check the whole code. Pointing to those 2 lines just isn't enough.
02/06/2020 13:33 Der Moench#9
Quote:
Originally Posted by Boostachu View Post
That is like saying "just trust me, I won't show evidence because then people might copy it" to the judge.

If you really want to convince people, then show valid proof. Also you should write on your main account instead of posting on a freshly made account faking another user.

And to clarify, like CoderAndy, I did not check the whole code. Pointing to those 2 lines just isn't enough.
Are you so stupid that you can't see the virus code like that?

Quote:
Originally Posted by CoderAndy View Post
@[Only registered and activated users can see links. Click Here To Register...]
but why you copied DerMoench14 acc name to post this and your account is just few hours fresh ?

look if you are teq and you care so much for your shop sales etc i can understand it's money loss, any pro coder selling that kind of stuff and expecting not to get leaked what can i say must be dumb af, at some point it will happen,
imo you need the plebs to use scripts so you can hide yourself.

(probably you enjoy all that back and forth with posting having the troll face and all)
I'm sorry but I no know DerMoench14.
02/06/2020 15:58 oneshout#10
So, people are listening a guy (for me, a troll with a fresh account) that the only post that have been done is :
- it's a scam
- warning
- Teqatle is a terrorist

Sometimes, i don't understand... but we have 2 choices :
- it's a troll that deserve to be ban
- it's Teqatle himself trying to hate GWA2 release cuz it's public now :cool:
02/06/2020 20:56 yuramisu#11
Hello,

It is difficult to keep gwa2 outated in public and it is better ;)

With helped a uptated gwa2, i'm working about gwapi, it is not really Perfect :feelsbadman:
02/07/2020 03:09 list comprehension#12
Quote:
Originally Posted by Der Moench View Post
I sent you the beginning of the code where the user data theft begins. I will not prescribe detailed instructions on how to do this, because attackers will see this method and start using it, you must understand this.
Let us just say it does grab a character name, email address, and password. Fine that can be hidden fairly well in asm, hooks,etc. However these information is worthless unless the attacker can get ahold of it. The ways to get the information out of the client would be through in game chat, REST API, winsock socket. Just glancing through it i don't see any reference to those and can easily run it with wireshark to check for outgoing traffic and if paranoid can disable the chat hooks.

I would like to see actual evidence not a function hook that is nearly identical with no calls to windows api needed or autoit apis for outside communication.
02/07/2020 13:52 GW Devil#13
fyi if you copy n paste your emails & passwords they can't log keystrokes. I've been doing this for years.
02/07/2020 15:10 oneshout#14
Quote:
Originally Posted by CoderAndy View Post
or you can create a .txt file and write:

@[Only registered and activated users can see links. Click Here To Register...] off
cd C:\Games\Guild Wars
start Gw.exe -email -password -character "My Character Name"
exit

and save it as a .bat file, instant login nothing to write really useful when you experiment with new scripts and gw crashes, ofc you can add all the info to a gw shortcut but i use the .bat to start other stuff too.
but don't forget :
Quote:
Putting your password in a shortcut or a batch file makes it easily accessible to everybody with access to your computer. Never use this option if you are sharing your computer with other people whom you do not trust.
Usage note: if your password contains spaces, put " at the start and end of your password. Example: -password "1234 5" . These quotation symbols are not required if there are no spaces in your password. Example: -password 12345 .
[Only registered and activated users can see links. Click Here To Register...]
02/07/2020 18:38 havochavoc2#15
If you use the command line arguments to login, the login information will be stored in the process memory in plain text.