Register for your free account! | Forgot your password?

Go Back   elitepvpers > Other Online Games > Browsergames > Facebook
You last visited: Today at 12:17

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



recover the RELEASE: Marvel's Avengers Alliance (Public Ultimate Force Drop)

Discussion on recover the RELEASE: Marvel's Avengers Alliance (Public Ultimate Force Drop) within the Facebook forum part of the Browsergames category.

Closed Thread
 
Old   #1
 
elite*gold: 0
Join Date: Feb 2014
Posts: 15
Received Thanks: 5
Question recover the RELEASE: Marvel's Avengers Alliance (Public Ultimate Force Drop)

Greetings I would like to know who knows how to create hacks


this was patched but I think you can recover

to use the Xml files with charles hack not working

but if they notice any changes in the original XML files of the game

and in my opinion someone who knows what hacks can recover
jerseyman is offline  
Old 02/10/2014, 02:35   #2
 
elite*gold: 0
Join Date: Jun 2013
Posts: 74
Received Thanks: 23
You need to adjust the XML files however you like, and also adjust ce.swf so that CVE's get ignored.

Use notepad++ to edit the XMLs, and use Sothink to edit the SWF. Use Charles to map your edited files locally.

Now you know how to create amazing Marvel hacks. Read everything, learn everything, experiment, and share.

Hacking games is a lifestyle, not a series of steps. Keep learning.
nukyalur is offline  
Thanks
9 Users
Old 02/10/2014, 03:13   #3
 
elite*gold: 0
Join Date: Mar 2013
Posts: 46
Received Thanks: 4
You can download the new game files, by using a program called "HTT track". Google it, i already got the server files, but i haven't found nothing to fix the force drop hack, so good luck
Master532 is offline  
Old 02/10/2014, 03:22   #4
 
elite*gold: 0
Join Date: Jan 2014
Posts: 86
Received Thanks: 7
I downloaded the current xmls and swf but not sure what should i change to avoid CVE and make it work like the guy did. Ok, i have to replace every itemid (xmls) with the item i wanna drop (more than 2000 lines, very very long time!), but i dont really have any idea what next. Anyone?
kyflash is offline  
Old 02/10/2014, 05:32   #5
 
elite*gold: 0
Join Date: Nov 2013
Posts: 31
Received Thanks: 23
It was patched at the server.
golpebaixo is offline  
Old 02/10/2014, 08:42   #6
 
iubjaved's Avatar
 
elite*gold: 0
Join Date: Nov 2013
Posts: 53
Received Thanks: 32
You can download updated files from charles by saving those request/response in .xml format.

Now that you have those updated files, you might be wondering what to do next? well if you intend to make it work you gotta try right? Then here it comes :

1. You need to change the client.xml files, not that every line of codes need to be replaced but only some lines ( probably couple hundred) to drop those items. Now you might be thinking why not all the lines just cause there are so many reward ids? Not true! That file contains all the data of a client side ( including move proc details with the proc rate, task ids , etc) altohether 250k line of codes! So yes it will definitely take time to modify them.

2. Now that you're done with the most irritating part, you can get done with rest ab.xml and 101.xml.

3. Now to do the .swf file, using a decompiler. I suggest use sothink swf decompiler. Now that you opened sothink, select the swf file from the left panel and you will see those folders appeared on the right panel. expand those folders , you will find its contents. Select actionscript and you can view the source code, p-code and raw data. You can search for a desired string you are looking for by searching by a keyword in action script window of the current script or all the scripts. The result will appear at the bottom window.


Hope this info helps. Good Luck
iubjaved is offline  
Thanks
10 Users
Old 02/10/2014, 09:33   #7
 
elite*gold: 0
Join Date: Jul 2008
Posts: 64
Received Thanks: 7
Quote:
Originally Posted by kyflash View Post
I downloaded the current xmls and swf but not sure what should i change to avoid CVE and make it work like the guy did. Ok, i have to replace every itemid (xmls) with the item i wanna drop (more than 2000 lines, very very long time!), but i dont really have any idea what next. Anyone?
guys someone could share lastest xmls...
rappelzbot is offline  
Old 02/10/2014, 09:36   #8
 
elite*gold: 0
Join Date: Jan 2014
Posts: 119
Received Thanks: 1
if one itself with it knows a lot then this is no problem
unfortunately, I do not know a lot about it
Promo81 is offline  
Old 02/10/2014, 10:13   #9
 
elite*gold: 0
Join Date: Jun 2013
Posts: 29
Received Thanks: 2
Work item drop hack?
kamilhacker is offline  
Old 02/10/2014, 10:18   #10
 
elite*gold: 0
Join Date: Feb 2014
Posts: 59
Received Thanks: 12
Quote:
Originally Posted by iubjaved View Post
You can download updated files from charles by saving those request/response in .xml format.

Now that you have those updated files, you might be wondering what to do next? well if you intend to make it work you gotta try right? Then here it comes :

1. You need to change the client.xml files, not that every line of codes need to be replaced but only some lines ( probably couple hundred) to drop those items. Now you might be thinking why not all the lines just cause there are so many reward ids? Not true! That file contains all the data of a client side ( including move proc details with the proc rate, task ids , etc) altohether 250k line of codes! So yes it will definitely take time to modify them.

2. Now that you're done with the most irritating part, you can get done with rest ab.xml and 101.xml.

3. Now to do the .swf file, using a decompiler. I suggest use sothink swf decompiler. Now that you opened sothink, select the swf file from the left panel and you will see those folders appeared on the right panel. expand those folders , you will find its contents. Select actionscript and you can view the source code, p-code and raw data. You can search for a desired string you are looking for by searching by a keyword in action script window of the current script or all the scripts. The result will appear at the bottom window.


Hope this info helps. Good Luck
Pretty detailed information, I would work on that if I had some spare time (work to do :/ )
Thankfully I got pretty much everything I'll ever need from inaudax release, so rigt now only thingI need is U-ISO
Quick question, do you know if there's some kind of method to bypass the requests/responses from the servers when you accept a gift? And then repeat that request/response to get a huge amount of that accepted gift?
Is it necessary to edit any xml file or the swf? I saw a vid in which only by retouching something in the request/reponse url this was doable, but I wanna be sure that nothing else is needed, otherwise I would be wasting my time (I think this hack is also made by inaudax, but it's private I think)

EDIT: I've been playing around with Charles and the requests/resposes, but it seems thay added a huge hash code to each of them so nobody can "play" with them. Is here some moethod to do what I mentioned above? (I'm not asking for the method, just want to know if there's something possible to do). Tanks!
wolvie1984 is offline  
Old 02/10/2014, 10:35   #11
 
elite*gold: 0
Join Date: Oct 2013
Posts: 349
Received Thanks: 67
Quote:
Originally Posted by iubjaved View Post
You can download updated files from charles by saving those request/response in .xml format.

Now that you have those updated files, you might be wondering what to do next? well if you intend to make it work you gotta try right? Then here it comes :

1. You need to change the client.xml files, not that every line of codes need to be replaced but only some lines ( probably couple hundred) to drop those items. Now you might be thinking why not all the lines just cause there are so many reward ids? Not true! That file contains all the data of a client side ( including move proc details with the proc rate, task ids , etc) altohether 250k line of codes! So yes it will definitely take time to modify them.

2. Now that you're done with the most irritating part, you can get done with rest ab.xml and 101.xml.

3. Now to do the .swf file, using a decompiler. I suggest use sothink swf decompiler. Now that you opened sothink, select the swf file from the left panel and you will see those folders appeared on the right panel. expand those folders , you will find its contents. Select actionscript and you can view the source code, p-code and raw data. You can search for a desired string you are looking for by searching by a keyword in action script window of the current script or all the scripts. The result will appear at the bottom window.


Hope this info helps. Good Luck
Thanks bro.

And how do i fix that i can open my Marvel profile? I just can't open it -.- stucks at loading.
aimjunkies is offline  
Old 02/10/2014, 13:04   #12
 
iubjaved's Avatar
 
elite*gold: 0
Join Date: Nov 2013
Posts: 53
Received Thanks: 32
Quote:
Originally Posted by wolvie1984 View Post
Pretty detailed information, I would work on that if I had some spare time (work to do :/ )
Thankfully I got pretty much everything I'll ever need from inaudax release, so rigt now only thingI need is U-ISO
Quick question, do you know if there's some kind of method to bypass the requests/responses from the servers when you accept a gift? And then repeat that request/response to get a huge amount of that accepted gift?
Is it necessary to edit any xml file or the swf? I saw a vid in which only by retouching something in the request/reponse url this was doable, but I wanna be sure that nothing else is needed, otherwise I would be wasting my time (I think this hack is also made by inaudax, but it's private I think)

EDIT: I've been playing around with Charles and the requests/resposes, but it seems thay added a huge hash code to each of them so nobody can "play" with them. Is here some moethod to do what I mentioned above? (I'm not asking for the method, just want to know if there's something possible to do). Tanks!



First of all , let me clear you how it works. When you accept a gift, you send two request to playdom server , one consisting of the gift data and another to accept the message. As soon as these infos are sent, server responses with jQuery callback functions. This function is used after the current effect is 100% done.


If you recall inaudax to discover an exploit earlier, by which you can get as many energy by simply changing the gift parameters and adding codes as provided. But unfortunately it got patched.

Answer to your first question :- Yes, by manipulation variables. Marvel avengers game uses SSL which provides lot of security but its not enough to prevent such variable manipulation attacks. But since after their upgrade, i think thet are using Java Applet. The way it works is pretty simple. It signs the message sent from the client and validate the certificate instead of letting browser do that, in order for ''charles'' to not get in between the client and the server with a fake certificate. This applet is designed to reject such fake certificate. To overcome it, you need to replace embedded certificate provided by the applet and replace it with a fake one.

You keep playing with it, and learn more about it but you cannot wish to succeed at your first try without having any idea of it at all. Good Luck.

Quote:
Originally Posted by aimjunkies View Post
Thanks bro.

And how do i fix that i can open my Marvel profile? I just can't open it -.- stucks at loading.
Clear cache. If you have charles opened at same time, make sure the ''map local'' is disabled. If the problem still persists, use another browser ( Newly Installed) and try it there.

Hope it resolves the issue you are facing.
iubjaved is offline  
Thanks
4 Users
Old 02/10/2014, 13:09   #13
 
elite*gold: 0
Join Date: Feb 2014
Posts: 59
Received Thanks: 12
Quote:
Originally Posted by iubjaved View Post
First of all , let me clear you how it works. When you accept a gift, you send two request to playdom server , one consisting of the gift data and another to accept the message. As soon as these infos are sent, server responses with jQuery callback functions. This function is used after the current effect is 100% done.


If you recall inaudax to discover an exploit earlier, by which you can get as many energy by simply changing the gift parameters and adding codes as provided. But unfortunately it got patched.

Answer to your first question :- Yes, by manipulation variables. Marvel avengers game uses SSL which provides lot of security but its not enough to prevent such variable manipulation attacks. But since after their upgrade, i think thet are using Java Applet. The way it works is pretty simple. It signs the message sent from the client and validate the certificate instead of letting browser do that, in order for ''charles'' to not get in between the client and the server with a fake certificate. This applet is designed to reject such fake certificate. To overcome it, you need to replace embedded certificate provided by the applet and replace it with a fake one.

You keep playing with it, and learn more about it but you cannot wish to succeed at your first try without having any idea of it at all. Good Luck.



Clear cache. If you have charles opened at same time, make sure the ''map local'' is disabled. If the problem still persists, use another browser ( Newly Installed) and try it there.

Hope it resolves the issue you are facing.
Wow, thanks man. That actually makes a lot of sens (the requests/responses now look indeed quite different from what they looked before last week's patch)
And I did noticed two different requests, now I know why there are two. Although I admit I have no clue on how to replace the certificate, you have given me alot of info
Hope I can figure out the bypass. Thanks for taking the time to explain!
wolvie1984 is offline  
Old 02/10/2014, 15:31   #14
 
elite*gold: 0
Join Date: Feb 2009
Posts: 19
Received Thanks: 4
Quote:
Originally Posted by iubjaved View Post
You can download updated files from charles by saving those request/response in .xml format.

Now that you have those updated files, you might be wondering what to do next? well if you intend to make it work you gotta try right? Then here it comes :

1. You need to change the client.xml files, not that every line of codes need to be replaced but only some lines ( probably couple hundred) to drop those items. Now you might be thinking why not all the lines just cause there are so many reward ids? Not true! That file contains all the data of a client side ( including move proc details with the proc rate, task ids , etc) altohether 250k line of codes! So yes it will definitely take time to modify them.

2. Now that you're done with the most irritating part, you can get done with rest ab.xml and 101.xml.

3. Now to do the .swf file, using a decompiler. I suggest use sothink swf decompiler. Now that you opened sothink, select the swf file from the left panel and you will see those folders appeared on the right panel. expand those folders , you will find its contents. Select actionscript and you can view the source code, p-code and raw data. You can search for a desired string you are looking for by searching by a keyword in action script window of the current script or all the scripts. The result will appear at the bottom window.


Hope this info helps. Good Luck
Hello man!

Since the hacker has released inaudax it that was corrected I started trying to do something, I was in doubt whether to do something in the swf. and edit it as you helped me with that, I now get some things done, how to make items fall or add store items, change prices, but I still have a problem in validating when I purchase an item he asks for I update the game, now with the drop when I caught something and leave the game the item is no longer there. (Do this only with the xml I have not done anything in the swf)

I can open the swf file. encoding it and totally different from the xml can not understand anything, I will study it to see if I can get something! you have any tips?

Thanks for the help, sorry my bad english!
wagner2009 is offline  
Thanks
1 User
Old 02/10/2014, 15:37   #15
 
elite*gold: 0
Join Date: Jan 2014
Posts: 119
Received Thanks: 1
it would be great if somebody would get out,
you would help one very much

can you speak german wagner2009???
Promo81 is offline  
Closed Thread


Similar Threads Similar Threads
Marvel Avengers Alliance Item Drop Hack
05/26/2014 - Browsergames Trading - 17 Replies
Hi, Can you do the hack tool for item drop in MAA? Please....:handsdown:
Marvel's Avengers Alliance Ultimate Bot
02/08/2014 - Facebook - 130 Replies
Marvel's Avengers Alliance Ultimate Bot - YouTube Marvel's Avengers Alliance Ultimate Bot Features: Selective Drop - Choose drop what you want. (CP, SP, ISO and more!) Ultimate Force Drop - Unlimited drops 100% drop rate upon attacking. CVE / Serv Exploit - No more 'Combat Verification Error' and MAA will validate our illegal battles regardless. Will last for a very long time since I have 2 different working exploits (private). Battle Bot - The bot will attack and collect drops for...
RELEASE: Marvel's Avengers Alliance (Public Ultimate Force Drop)
02/05/2014 - Facebook - 1212 Replies
Hello, I've decided to release my 'Public Ultimate Force Drop' to the public today for Facebook and possbily Playdom version -- (please read About.txt for more info) -- but remember this is not the same as my Ultimate bot as the bot is based on a separate exploit. RELEASE: Marvel's Avengers Alliance (Public Ultimate Force Drop) - No longer working! This public hack was released on 30/01/2014 and it has been working for 6 days. Eventually, Playdom patched it on 5/02/2014. Thankyou...



All times are GMT +1. The time now is 12:19.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.