|
You last visited: Today at 17:20
Advertisement
[Proof of Concept]Why not to trust a public multi-client (bananasplit in asm)
Discussion on [Proof of Concept]Why not to trust a public multi-client (bananasplit in asm) within the CO2 Programming forum part of the Conquer Online 2 category.
09/23/2008, 05:54
|
#1
|
elite*gold: 0
Join Date: Apr 2007
Posts: 950
Received Thanks: 2,410
|
[Proof of Concept]Why not to trust a public multi-client (bananasplit in asm)
Patch 5063
Now this is only designed for you to input the command but could just as easily be modified to do the same if someone says it to you. This guide only explains the un-equipping phase.
First I start here:
This is a subfunction of the Sendtext function, during this function EAX stores the current text about to be sent from the chat box to a packet, at 00457E85 EAX changes so I will make my hook just before here, 00457E7D has a large enough command to be changed to a JMP so this will do just fine.
This could be caved anywhere but for now ill put it at the end of the exe - so LEA EDI,DWORD PTR DS:[ESI+FA8] becomes JMP 00524BAE
And now for the code:
In english, this checks to see if the text you just sent matches a set codeword and if so, un equips all your gear, like I said this could easily be made so that if someone says the codeword to you, everything will unequip, I wont tell you how to do it, but the information is right there with a little modding its easily possible.
|
|
|
09/23/2008, 06:45
|
#2
|
elite*gold: 0
Join Date: Sep 2008
Posts: 490
Received Thanks: 595
|
Now thats why i dont trust multi's by others haha,
Also glad theres the lock function!
So i tried this,
tho without success, well the only success is that my hat got unequiped,
I tripple checked everything how does this look like do you see if I made a mistake or was it meant to only unequip hat? 
If so why the other calls?
Code:
0045DF4A . /E9 B1230D00 JMP Conquer.00530300
0045DF4F |90 NOP
0045DF50 > |8BCF MOV ECX,EDI ; ntdll.7C910208
Code:
00530300 > 8DBE A80F0000 LEA EDI,DWORD PTR DS:[ESI+FA8]
00530306 . 8BD0 MOV EDX,EAX
00530308 . BB 41035300 MOV EBX,Conquer.00530341 ; ASCII "bananasplit"
0053030D . 52 PUSH EDX ; /s2 = "ÍxA4$"
0053030E . 53 PUSH EBX ; |s1 = ""
0053030F . E8 68A5FCFF CALL <JMP.&MSVCRT.strcmp> ; strcmp
00530314 . 58 POP EAX ; kernel32.7C817067
00530315 . 75 23 JNZ SHORT Conquer.0053033A
00530317 . E8 822BF2FF CALL Conquer.00452E9E
0053031C . E8 A22BF2FF CALL Conquer.00452EC3
00530321 . E8 C22BF2FF CALL Conquer.00452EE8
00530326 . E8 E22BF2FF CALL Conquer.00452F0D
0053032B . E8 022CF2FF CALL Conquer.00452F32
00530330 . E8 222CF2FF CALL Conquer.00452F57
00530335 . E8 422CF2FF CALL Conquer.00452F7C
0053033A >^ E9 11DCF2FF JMP Conquer.0045DF50
0053033F 00 DB 00
00530340 00 DB 00
00530341 . 62 61 6E 61 6E 61>ASCII "bananasplit",0
|
|
|
09/24/2008, 06:54
|
#3
|
elite*gold: 0
Join Date: Apr 2007
Posts: 950
Received Thanks: 2,410
|
Go into the calls to unequip slots and you'll see theres a JNZ or something, nop those jumps and it should work, that happened to me as well when I first did it but it seems to work without it for me now.
|
|
|
09/24/2008, 10:56
|
#4
|
elite*gold: 0
Join Date: Apr 2006
Posts: 71
Received Thanks: 5
|
Correct me if im noob saying this lol
But would not be enough to check orignal conquer.exe file and downloaded one size?
I always do it if I download multi and i suposse your asm lines added would increase size
|
|
|
09/24/2008, 11:23
|
#5
|
elite*gold: 0
Join Date: Apr 2007
Posts: 950
Received Thanks: 2,410
|
Quote:
Originally Posted by soymadmax
Correct me if im noob saying this lol
But would not be enough to check orignal conquer.exe file and downloaded one size?
I always do it if I download multi and i suposse your asm lines added would increase size
|
Nope, this code is done inside the exe so there is no change in size.
|
|
|
09/24/2008, 13:59
|
#6
|
elite*gold: 0
Join Date: Sep 2008
Posts: 490
Received Thanks: 595
|
Got it, i have to admit, very nice haha.
Now, the spot where you set your jmp aint a good spot,
When u try to whisper you will crash haha.
If I can find the jmp to a emote now THAT would be nice,
perhaps you can help me find the jmp to the kneel emote
|
|
|
09/24/2008, 16:53
|
#7
|
elite*gold: 0
Join Date: May 2007
Posts: 175
Received Thanks: 254
|
so lets say unequip is possible, ummm itemlock?
|
|
|
09/24/2008, 17:29
|
#8
|
elite*gold: 0
Join Date: Sep 2008
Posts: 490
Received Thanks: 595
|
Quote:
Originally Posted by emmanication
so lets say unequip is possible, ummm itemlock?
|
Thats not the point tho (besides that everyone has a seller), I think *M* meant this to proof that it can be done.
|
|
|
09/24/2008, 20:14
|
#9
|
elite*gold: 20
Join Date: Jun 2005
Posts: 1,013
Received Thanks: 381
|
Quote:
Originally Posted by emmanication
so lets say unequip is possible, ummm itemlock?
|
It doesn't matter what the hack does, the point *M* has made with this post, is anyone can modify the client to do anything. It doesn't even need to be an in game thing, but you could modify the client to run/control other applications on your machine, and it would go past any antivirus or firewall you have installed. If you download any binary from anyone, you're running the risk of losing control of your machine, so why bother, when you could just follow a simple guide and make the multi-client yourself?
|
|
|
09/25/2008, 00:40
|
#10
|
elite*gold: 0
Join Date: Sep 2008
Posts: 490
Received Thanks: 595
|
Ive patched the pathfinding button with this, I like it better, that button useless anyway.
|
|
|
09/25/2008, 07:50
|
#11
|
elite*gold: 0
Join Date: Nov 2006
Posts: 805
Received Thanks: 464
|
Someone could release a loader that modifies the client to do this as well ;o
|
|
|
09/25/2008, 07:51
|
#12
|
elite*gold: 0
Join Date: Apr 2007
Posts: 950
Received Thanks: 2,410
|
Quote:
Originally Posted by unknownone
It doesn't matter what the hack does, the point *M* has made with this post, is anyone can modify the client to do anything. It doesn't even need to be an in game thing, but you could modify the client to run/control other applications on your machine, and it would go past any antivirus or firewall you have installed. If you download any binary from anyone, you're running the risk of losing control of your machine, so why bother, when you could just follow a simple guide and make the multi-client yourself?
|
Yeah what he said.
Imagine hooking CO's anti-virus to delete all the files its supposed to scan, easily possible and would probably break Windows.
Quote:
Originally Posted by _fobos_
Got it, i have to admit, very nice haha.
Now, the spot where you set your jmp aint a good spot,
When u try to whisper you will crash haha.
If I can find the jmp to a emote now THAT would be nice,
perhaps you can help me find the jmp to the kneel emote 
|
Ya I know it crashes whisper, that just seemed like a good place for the jump considering the mod isnt made for gameplay, however this can be used for functionality also, you can build in commands to help you, unequiping all items at once has its uses, you could also build in things like speedhack etc via command. I will try later to find the kneel function, I have some ideas of where to start(GraphicD.GameDataSetQuery comes to mind).
|
|
|
09/25/2008, 15:59
|
#13
|
elite*gold: 0
Join Date: Sep 2008
Posts: 490
Received Thanks: 595
|
Quote:
Originally Posted by *M*
Yeah what he said.
Imagine hooking CO's anti-virus to delete all the files its supposed to scan, easily possible and would probably break Windows.
Ya I know it crashes whisper, that just seemed like a good place for the jump considering the mod isnt made for gameplay, however this can be used for functionality also, you can build in commands to help you, unequiping all items at once has its uses, you could also build in things like speedhack etc via command. I will try later to find the kneel function, I have some ideas of where to start(GraphicD.GameDataSetQuery comes to mind).
|
I will look for it aswell and yes, certainly it will have uses I tried to find the emotes i set breakpoints on all the BtnClick.wav and i hit a bp when i opened it, it just didnt get me far so i gave up, then i searched the same way for pathfinding only instead i put a bpon all NDSound.DXPlaySound and that got me further and got me to patch the pathfinding button to unequip all.
|
|
|
09/25/2008, 20:15
|
#14
|
elite*gold: 0
Join Date: Aug 2006
Posts: 147
Received Thanks: 360
|
hi i'm having troubles in this edit. i'm noob in asm I try to found LEA EDI,DWORD PTR DS:[ESI+FA8] to edit and put de JMP but i can't find LEA EDI,DWORD PTR DS:[ESI+FA8] the addres isn't the same and i try with Control+F but it say unckown identifier.
can anybody help me?
|
|
|
09/25/2008, 20:35
|
#15
|
elite*gold: 0
Join Date: Sep 2008
Posts: 490
Received Thanks: 595
|
Quote:
Originally Posted by darkirax
hi i'm having troubles in this edit. i'm noob in asm I try to found LEA EDI,DWORD PTR DS:[ESI+FA8] to edit and put de JMP but i can't find LEA EDI,DWORD PTR DS:[ESI+FA8] the addres isn't the same and i try with Control+F but it say unckown identifier.
can anybody help me?
|
Id say get a copy of the older exe (by downloading the older patch and install it in a new folder then rename the exe to Conquer1.exe or somethin and copy it to ur co folder), look for it look for something familiar and the info is out there really, lil searching in both exe's will get u there.
Like i said all info needed is there, only need to update.
|
|
|
 |
|
Similar Threads
|
Cnttuchmes public hack+ proof
04/07/2011 - WarRock Hacks, Bots, Cheats & Exploits - 4 Replies
his is my hack plus proof for a coder
when you inject my gamertag will come up
This hack includes "ITS A NO MENU"
FAST_HEALTH= active automatic
FAST_AMMO= active automatic
FAST_FLAG= active automatic
FAST_REPAIR= active automatic
noSPAWNwait=active automatic
Spread= active automatic
|
SELLING PSF WALLHACK W/PROOF TRUST ME
03/27/2011 - Soldier Front - 5 Replies
I AM AIREX22 SO IM NOT SCAMMER MY E-MAIL IS [email protected] WE CAN 1 ON 1 AS PROOF THAT BYPASS NOT WALHACK YOU CAN USE 3 HACK WITH IT.......
|
WarCraft III 1.24+ CRC SHA1 Cracked!!! Proof Of Concept/DEMO
11/24/2010 - General Gaming Discussion - 1 Replies
VIDEO: YouTube - WarCraft III 1.24+ CRC SHA1 Cracked!!! Proof Of Concept/DEMO
This is a demo that WarCraft III - The Frozen Throne v1.24+ map protection of CRC, SHA1 can still be cracked and it's still possible for "collided maps" (FYI collided maps are maps that aren't exactly identical to each other therefore making the possibility of running a cheated map with an original one). I've been trying to manipulate the skill's hashtable(gamecache replaced since 1.23+) of DotA Allstars but too...
|
All times are GMT +1. The time now is 17:21.
|
|