Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Cabal Online
You last visited: Today at 03:21

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[Discussion] Removing DC Flag

Discussion on [Discussion] Removing DC Flag within the Cabal Online forum part of the MMORPGs category.

Closed Thread
 
Old 09/16/2009, 15:11   #301
 
elite*gold: 0
Join Date: Feb 2008
Posts: 15
Received Thanks: 1
to logan432 have you try UIF to find RVA address and Size ?
zen83 is offline  
Old 09/17/2009, 04:49   #302
 
elite*gold: 0
Join Date: Aug 2009
Posts: 54
Received Thanks: 1
Quote:
Originally Posted by zen83 View Post
to logan432 have you try UIF to find RVA address and Size ?
nope.. i will try thanks
logan432 is offline  
Old 09/17/2009, 22:18   #303
 
pssye's Avatar
 
elite*gold: 0
Join Date: Nov 2008
Posts: 209
Received Thanks: 6
Unhappy

Can anyone help me out if im at the right path =) got this error msg using Ollysocket trace

0042D886 send return value = invalid socket
0042D66E shutdown = invalid socket

i tried to put a Jmp in that address but still the same problem. Is the Jmp the solution or just changing the flags to it?? anyway i tried both.and still got the same problem. Im really noob at Olly. thanks a lot for the good Soul to reply.. anyway can pm or send the msg at .. thanks


btw. i think my cabal is still upacked.

Frm Dlnqt post :

[RELEASE+DISCUSSION] Unpacked CABALMAIN.EXE
Update: September 7, 2009 1:03PM (+8 GMT) - VERY IMPORTANT PLEASE READ: You don't need an unpacked cabalmain.exe in removing the DC flag, live debugging will already suffice. The benefit for an unpacked cabalmain.exe is that you will be able to apply the removal of the dc flag PERMANENTLY. Meaning you don't need to open up ollydbg anymore.


Quote:
Originally Posted by NoobWant2Learn View Post
@168Atomica

Can we find the code w/c dc us using live dbg, without unpacking it???


Yes.. having an unpacked cabalmain.exe only means that the fix is permanent.. unless cabalmain.exe updated, you have to do it again.

well if you don't want to unpack cabalmain.exe, live debug is enough.. but you need to do it everytime you run cabalmain.exe.
------------------------------------------------------------------------------

So the code is same on upacked and original / unmodified cabalmain.exe
Attached Images
File Type: jpg invalid socket.JPG (178.2 KB, 107 views)
pssye is offline  
Old 09/18/2009, 05:19   #304
 
elite*gold: 0
Join Date: Oct 2007
Posts: 364
Received Thanks: 74
Sorry can't help you with this.. I haven't completed all my tests yet
dlnqt is offline  
Thanks
1 User
Old 09/18/2009, 05:32   #305
 
pssye's Avatar
 
elite*gold: 0
Join Date: Nov 2008
Posts: 209
Received Thanks: 6
ok thanks.. hope someone can help me out ..
pssye is offline  
Old 09/18/2009, 06:09   #306
 
NoobWant2Learn's Avatar
 
elite*gold: 0
Join Date: Aug 2009
Posts: 137
Received Thanks: 26
@pssye

did try all those u have tried.... guess what?? FAILED..
tried NOPing it Tried JMPing it, tried RETNing it, Tried using both socket trace, and call trace.. still finds no luck, in socket trace ul find a comment "overlapped flags" w/asm POP ESI, but still no idea on it... tried call trace but still dont know what to change at where to change..

Edit: BTW, Even if the flag is just under my nose, i still wouldnt recognize it... im studying which caller calls which, (WHAT,WHERE, to change)<---- very impt.
NoobWant2Learn is offline  
Thanks
1 User
Old 09/18/2009, 08:47   #307
 
pssye's Avatar
 
elite*gold: 0
Join Date: Nov 2008
Posts: 209
Received Thanks: 6
Unhappy

Quote:
Originally Posted by NoobWant2Learn View Post
@pssye

did try all those u have tried.... guess what?? FAILED..
tried NOPing it Tried JMPing it, tried RETNing it, Tried using both socket trace, and call trace.. still finds no luck, in socket trace ul find a comment "overlapped flags" w/asm POP ESI, but still no idea on it... tried call trace but still dont know what to change at where to change..

Edit: BTW, Even if the flag is just under my nose, i still wouldnt recognize it... im studying which caller calls which, (WHAT,WHERE, to change)<---- very impt.

awwwtss... I thought you already know the answer to this .. =( i thought that you are you it now .. =( thanks a lot Bro..
pssye is offline  
Old 09/18/2009, 08:51   #308
 
NoobWant2Learn's Avatar
 
elite*gold: 0
Join Date: Aug 2009
Posts: 137
Received Thanks: 26
i thought also... but im not there yet.. im kinda losing hope on this.. but for sure i did saw someone using 2 slot hack, i did saw an alz drop of 1 alz... pretty sure its coming from a 2 slot hack...can we talk on ym? have some questions also il pm u my mail
NoobWant2Learn is offline  
Old 09/18/2009, 09:46   #309
 
pssye's Avatar
 
elite*gold: 0
Join Date: Nov 2008
Posts: 209
Received Thanks: 6
yes DH still exist , maybe using this method ... but really few people knows it..

someone out there ??? =) anyone =) Jai Ho .... =)
pssye is offline  
Old 09/18/2009, 15:11   #310
 
elite*gold: 0
Join Date: Jul 2009
Posts: 85
Received Thanks: 0
HELLO D*W*N hehehehehe noob from what server are you?
spankwirenation is offline  
Old 09/18/2009, 15:30   #311
 
NoobWant2Learn's Avatar
 
elite*gold: 0
Join Date: Aug 2009
Posts: 137
Received Thanks: 26
playing on saturn... what about it, dont worry im not a threat, im out of idea...so hopeless...
even if i want to buy, still i cant... residing in cebu Y_Y
NoobWant2Learn is offline  
Old 09/18/2009, 15:33   #312
 
pssye's Avatar
 
elite*gold: 0
Join Date: Nov 2008
Posts: 209
Received Thanks: 6
Im from Neptune .. How about you spank??
pssye is offline  
Old 09/18/2009, 15:34   #313
 
NoobWant2Learn's Avatar
 
elite*gold: 0
Join Date: Aug 2009
Posts: 137
Received Thanks: 26
ooopps.. sorry i thought your asking me.. oh well..
NoobWant2Learn is offline  
Old 09/18/2009, 15:58   #314
 
168Atomica's Avatar
 
elite*gold: 0
Join Date: Jul 2008
Posts: 72
Received Thanks: 85
Quote:
Originally Posted by dlnqt View Post
Question, how did you manage to patch/pack the client back to its original state along with the removal of the dc flag? And how did you manage to keep the IAT intact along with original PE header, RVA, Size etc?
huh? i thought you managed to do it?
patch the pe headers, as you know, redirection and erasing occurs in cabalmain so that dumping would be impossible.. thats the use of protectors...
ok enough with the lectures

1. i patched the pe header so that it no longer erases and redirect imports
-read "i copied the pe header of an unpacked cabalmain"
(*hint: i used private server cabalmain to extract headers of an unpacked file) - again you should not rely solely on your cabal client. You must be resourceful

2. now we solved the api redirection and erasing, patch the crc check so that it always passes the check (remember that this is the main cause why unpacked client go to ExitThread)

3. you will also encounter the code that detects olly. But by configuring olly plugins (Phantom / Hideolly) properly, you can ignore this step -- but if you want, patch the code manually ^^ (there are hundred of ways to kill it, NOP it, set the condition to zero so that it will always pass, etc. etc.)

4. I do not know why you need to repack the file. My cabalmain file is not packed. I was able to generate one 2mb and one 8mb file and they are both working.

5. Fix import tables using the tools provided. Delete unnecessary thunks. Have you tried to delete some unresolved pointers? Maybe not. Try to experiment. explore it. Some will work some will fail you. BUt make sure you have found the correct OEP before fixing the IAT. (I myself have tried typing addresses from 40000 onwards in increments of 1 during my trial and error period)

And for the question on how I managed to unpack/pack back to original state-- a patched client is not its original state. One question: did you find the OEP? If you mean using cabalmain in smaller size, use LordPE rebuild PE so that it will reduce to approx ~20% of the unpacked size. But you dont have to do that unless you are in scarce for hard disk space (OMG)

I am not saying that my process is the only way. There are hundreds of ways to find the OEP. Some tools provides 1 pack unpacking. Some apps, some scripts.

omg this is a long post.. im sorry...
168Atomica is offline  
Thanks
1 User
Old 09/18/2009, 17:39   #315
 
elite*gold: 0
Join Date: Sep 2009
Posts: 20
Received Thanks: 3
its not that simple as you think. one step at a time. dont rush.dont lose hope.
when you made it ul say this "yeah, why i ddnt think of it" for sure u miss i critical detail..
well, ill be leaving the rest to you guyz.. read the whole thread again. from pages 1-8.
ul understand what i mean
DH4PH is offline  
Closed Thread


Similar Threads Similar Threads
[Discussion]Removing Weapon hit(s) limitations.
12/15/2009 - Mabinogi - 20 Replies
Was wondering, your thoughts/ideas about removing these restrictions. Like a short sword "Normal 3 hit weapon" I'd like to work on this, however. I'm clueless as to where to start or what to try. DLL edits? Maybe a PE saying "I've only hit once, let me keep slashing this bears throat s'more" that sort of thing. cause N + (figure 8 here) sounds pretty sweet.
Removing Dc Flag guides.
09/26/2009 - Cabal Online - 5 Replies
Hey all. I need a bit help with this ... i was reading all removing dc flag threads but i dont understand much, can someone give me bit of guides that will help me with this ? ok i have bypass , but i need really good guides bcoz im noob :(
cabal discussion. and program discussion xtrap killer
08/02/2009 - Cabal Online - 1 Replies
now alot of people had the chance of trying how to hack and such, google only gave me small hints on bypassing and factors. on my search of learning how to bypass xtrap i came across an interesting pogram... " Xtrap Killer 2279" a person named of Irius or some sort made the program. Cheat Engine :: View topic - X-trap Killer 2275 it was at the cheatengine site so i thought maybe the community can take a look at it! since this is trusting enough. i managed to understand how to...
Binary Discussion Discussion
04/08/2009 - CO2 Private Server - 10 Replies
I dont think thats going to work, youve just made yourself a hell of alot of work :rolleyes: Would be better to ban advertising servers in this section since 90% of people moved over to binarys anyway, theres barely any source code released because everyone either uses LOFT or the binarys, neither of which really need code (LOFT needs a complete rewrite but nothing really specific) I would release a few things but all i can only really give out is some classes, all of my systems are...



All times are GMT +1. The time now is 03:25.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.