|
You last visited: Today at 17:12
Advertisement
Elsword's security system by Adrian
Discussion on Elsword's security system by Adrian within the Elsword forum part of the MMORPGs category.
01/01/2014, 13:06
|
#1
|
elite*gold: 0
Join Date: Sep 2013
Posts: 94
Received Thanks: 55
|
Elsword's security system by Adrian
Good evening,
As some people may have heard by now on this game a secret logging system represents the most powerful weapon against hackers.
The main issue I hope to cover here is how logs look like and what's being logged.
What's being logged:
- The level of your character as well as the dungeon you're playing in. For example: you can’t access x-2 secret dungeon at lv 6 unless you are a hacker.
- Drops of all kind: ED and items acquired.
- All dungeon results: for example how much ED/ Exp you have acquired, clear time, etc.
- How many mobs you have killed during the respective run.
- What stages you clear during the run.
- How much damage you deal. By knowing this we can assume that they also know how much dmg you receive or if you receive anything at all.
- Based on the value and particularities of the damage you have dealt or received they might be able to guess about how much: phy/mag attack/defence, add.dmg, crit, red.dmg and evasion, you have. What I can say for sure is that when you kill a mob they know exactly how much damage you have dealt and if it was a critical hit or not.
- Since they know if mobs receive damage or not they also know by what means dies a mob.
- They know how many accounts you have by tracking your IP. Every account you have ever accesed with your IP(even once) is counted as " one of your accounts". This is how many innocents get banned when a hacker gets banned on IP.
- They log trades of all kind: mail, direct, board. They know what item you trade.
- They know from which account to which account goes the item you have send. They recognize accounts not only by IP but also by name. As simple as: account "x" is trading with account "y".
- They know the exact date of all logs. Year,month,week,day,hour,minute. Logs have a length in time of 5 or more months which makes me believe that logs never get deleted.
- Logs are stored in your account's history. In other words your account is "the main villain" not your characters - deleting or renaming a character is pointles since logs remain on your account's history.
- Mods are detectable and bannable.
- They have a list of all items you have on your account and their effects/particularities. They know which items[gear, costumes, accessories] you have used during a run and their characteristics[enhancement, effects & sockets].
Secret KOMCheck algorithm:
Exactly as the name suggests the client runs a secret, hidden KOMCheck method/algorithm that checks KOM files.
This KOMCheck method/algorithm:
-Is incorporated in the game's client,
-Does not need files from the internet (non-bypassable),
-Only reports when the normal KOMCheck and this second method give different results (i.e. when the normal KOMCheck has been bypassed),
-Does not close the client but each time it detects a modified KOM file an entry in the login packet is sent to the server.
This is how admins can find out if you have a modded client and since the alteration of the client is strictly forbidden by T&C you can legitly get banned even if you don't have any abnormal logs.
Example: bans took for voice mods follow this system.
Solution:
Basically, you don't have to edit KOM files.
Programs like , ELX or Cheatengine can alterate the in-game experience without making modifications in the structure of the KOM.
Special thanks to Joni-St who analised the client binary and made this descovery.
Safe way to hack based on IP change:
The most easyest way of them all:
You need 2 PC's and two different IP's on each PC. What you want to do is to grind "one big load" on your hacking account(s). Like 4 absolute sets for example.
What you must do when you transfer these is to make everything look like a every day trade.
Go in the market and put the item(s) you want to trade at a ridiculously low price(1000 ED or so). With your safe account rapidly buy, using the board, 2/3 of the amount. The rest you let there to be taken by other players or by friends of yours. Repeat the process until everything you wanted is on your safe account.
Remember that you can only do this whole trick once or twice because even if they don't recognize you by IP they will surely recognize you if you're constantly buying items with only one account.
I'm a hacker and I'm in big trouble, what should I do?
You should make a new account, because you risk a ban, but NOT BEFORE asking your internet provider for a new IP. Why? Because if you get IP banned without changing the IP your new account will also get banned even though you did not used any hacks on it.
The safest way to do this while keeping your items:
Ask a friend who isn't a hacker to make you a new account. You trade your items to him via direct trade. After the transfer is complete you can change your IP and play on your new account.
This is a bit risky, but in the same time you "should" be safe because it only looks like you're giving things away.
If you have a dynamic IP things are a lot more easier since you can do the whole process by yourself via mail trade. Don't forget to change IP when you relog.
What I want to add:
These are only my ideas on how to evade security. Based on the presented info about logs you may come up with better solutions. Do whatever you decide to do and keep in mind that variety will save your ass.
Prints:
I had more but I've lost them when my old hard-disk broke. Some info here can be confirmed not only by me but also by any hacker who made a ticket after getting banned.
---------------------------------------------
---------------------------------------------
---------------------------------------------
---------------------------------------------
That's all, I hope this topic helps people understand how things work. Also feel free to update my list with anything useful that's not already been told.
|
|
|
01/01/2014, 13:23
|
#2
|
elite*gold: 0
Join Date: Jun 2013
Posts: 224
Received Thanks: 60
|
I can't understand that ticket  , could you translate it?
|
|
|
01/01/2014, 13:35
|
#3
|
elite*gold: 0
Join Date: Sep 2013
Posts: 94
Received Thanks: 55
|
Quote:
Originally Posted by Parampaa
I can't understand that ticket  , could you translate it?
|
Here
Hallo *****,
du hast mit dem Charakter ***** am 11.06.2013 um 09:27 Uhr den Dungeon "Untwerwelt (Hölle)" alleine betreten. Zu diesem Zeitpunkt war der Charakter Level 60. Du hast die erste Stage nicht abgeschlossen, sondern bist aus dem Dungeon raus gegangen, nachdem du 5.094.442 ED erfarmt hast und dies nur von 6 Monster. Genauso hast du am 09.06.2013 um 14:58 Uhr mit dem selben Char im gleichen Dungeon ebenfalls keine Stage abgeschlossen und erhieltes von einem Monster einen ED Betrag von 3.021.567. Ein drittes vergehen wäre noch mit dem Charakter *****, am 06.06.2013 um 20:35Uhr. Dort hast du im Dungeon "Altarraum (Experte)"ebenfalls wurde hier die erste Stage nicht gecleart und der Dungeon wurde nach einem erfarmten Betrag von 1.136.570 ED. Diese sind Werte, der, mit legalen Mitteln in einem Dungeon run, nicht zu erreichen ist.
Bitte antworte auf dein Ticket unter: Ticketsystem
Gehe dort auf "Ticketverlauf" und gib den Schlüssel und die Prüfsumme aus der Email ein.
Klicke dort dann auf "Antwort schreiben"
Mit freundlichen Grüßen,
*****
***** - Elsword.de
Use google translate, I don't know german.
|
|
|
01/01/2014, 20:14
|
#4
|
elite*gold: 0
Join Date: Jul 2013
Posts: 422
Received Thanks: 119
|
#Approuved
I also had an ip ban
4 accound, 3 with cheat and 1 without cheat.
|
|
|
01/03/2014, 00:42
|
#5
|
elite*gold: 0
Join Date: Oct 2009
Posts: 181
Received Thanks: 24
|
does anyone have a good ip changer?
|
|
|
01/03/2014, 01:10
|
#6
|
elite*gold: 0
Join Date: Sep 2013
Posts: 94
Received Thanks: 55
|
Quote:
|
Note that we do not provide details about the investigation.
|
Absolutely hilarious.
Unfortunately now is too late for them to do that. I made a swear that if they ever send me to grave again I'm taking their security down with me.
They saw me guilty for hacking, I see them guilty for treating children and their feelings as a piece of wood, for throwing away people's work and friends, for abusing power.
Thank you for support Otes, I really appreciate your efforts.
Quote:
|
does anyone have a good ip changer?
|
Your internet provider is the best IP changer.
|
|
|
01/03/2014, 05:24
|
#7
|
elite*gold: 0
Join Date: Jun 2013
Posts: 224
Received Thanks: 60
|
Hmm, it's still impossible for GM to spend all his time to check all player logs then inspect one by one, right?
And, they have bunch support ticket, managing game, and etc, right?
|
|
|
01/03/2014, 07:07
|
#8
|
elite*gold: 0
Join Date: Sep 2013
Posts: 94
Received Thanks: 55
|
There isn't only one person checking logs. They have a team for this.
And checking one by one? No, as you may see, they IP ban everything they find.
Though ...
There is something that makes me think they need fresh data to find you, mainly because normal logs are constantly replacing abnormal logs(like in a long long list). So if you stop now you might have a slight chance.
Keep in mind that this is only an assumption with a low chance of probability, I don't have enough information to confirm something like this.
Also what if they automatically "underline" abnormal logs? so they can easily find them afterwards. Everything is possible.
And you know ... many people have a hack account and safe account: the discovery of the hack account and a IP ban will most likely lead to the same result.
In other words: you have this high probability that stop hacking now won't make any difference.
|
|
|
01/03/2014, 12:08
|
#9
|
elite*gold: 0
Join Date: Jun 2013
Posts: 224
Received Thanks: 60
|
I think better not talking/asking about our ID (for cheating) or keep it secret so the GM won't see our logs. But, bug trap function still bothering me, it send screen shoot when the game crashes then automatically delete that file. The file name is ErrorLog.txt and Crash_ScreenShot.jpg in \data folder, do you have any idea how to deny it being sent except disconnecting internet?
|
|
|
01/03/2014, 23:50
|
#10
|
elite*gold: 0
Join Date: Sep 2013
Posts: 94
Received Thanks: 55
|
Quote:
|
I think better not talking/asking about our ID (for cheating) or keep it secret so the GM won't see our logs. But, bug trap function still bothering me, it send screen shoot when the game crashes then automatically delete that file. The file name is ErrorLog.txt and Crash_ScreenShot.jpg in \data folder, do you have any idea how to deny it being sent except disconnecting internet?
|
What you're trying to do seems to be the job of a sniffer.
Quote:
|
Who have delete my reply ?
|
Maybe a forum moderator, because it was double post. But don't worry, you can now check my post for the 3rd img.
|
|
|
01/15/2014, 17:33
|
#11
|
elite*gold: 0
Join Date: Jul 2013
Posts: 422
Received Thanks: 119
|
Ok... :/ !
So for henir farmeur I suggest you to use a vpn and never connect your main account as your ip cheating account !
If you have 2 PC it would be nice too and don't forget to use vpn, A Good vpn.
|
|
|
01/17/2014, 21:41
|
#12
|
elite*gold: 0
Join Date: Sep 2013
Posts: 94
Received Thanks: 55
|
Update.
I've been trying to make the list more intelligible for you guys, therefore, some points that were pretty messed up got a fresh and hopefully a more "friendly" aspect.
My english still needs a lot of practice
2nd Update
Further aspect improvements and some new hacking strategies.
3rd Update
The introduction was modified:
-Shorter.
-The term "records" was changed into "logs", highlighting that logs exist in text format not in video format.
Mild hacks updated:
-Elemental resistance
4th Update:
-New information added to the list.
-4th screenshot
|
|
|
01/31/2014, 11:52
|
#13
|
elite*gold: 0
Join Date: Jul 2010
Posts: 25
Received Thanks: 7
|
Bumping coz poster asked me to
|
|
|
02/07/2014, 17:56
|
#14
|
elite*gold: 0
Join Date: Sep 2013
Posts: 94
Received Thanks: 55
|
Update.
|
|
|
02/08/2014, 23:41
|
#15
|
elite*gold: 3
Join Date: Feb 2010
Posts: 29
Received Thanks: 1
|
you posting these will make them think on how to deal with ELX files soon
|
|
|
 |
|
Similar Threads
|
Help trying to bot in L2 Interlude with System NProtect security
03/04/2012 - Lin2 Exploits, Hacks, Bots, Tools & Macros - 0 Replies
Hello... Well i'm playing in a Interlude server with NProtect system... when i log without the oficial system or with ig/oog bot it disconnect me after some seconds... anyone knows a way to evade this?
some servers with this protection:
BRL2 Server Interlude 500x
L2 Black - Inauguracao em 03.03.2012
L2WarPlace Servidor Brasileiro Interlude
Thanks...
|
Did Yahoo change the security system?
05/12/2011 - Silkroad Online - 3 Replies
hello guys
i wanted to buy acc but it's verified to yahoo and when i told the seller it's not safe he told me that i can't acsses with s/a while the verifed mail to yahoo is active
i tried with my email when i was in the verifed email screen of my yahoo i choosed i can't acsses this bla bla bla ......
and my yahoo got block for 12 hours so is that right?
|
need a DB security system
06/28/2008 - EO PServer Hosting - 0 Replies
i need a db security system and a lille help to host my server 24/7 not my original server a new one ill make this friday or tuesday and tell ya guy OK?
|
All times are GMT +1. The time now is 17:12.
|
|