Hi all!
I'm Working on standalone kal sniffer - it will not be based on client directly.
I only want to sniff packets and decode it correctly (without modification).
So... What i need?
Need few packet dumps first raw - from sniffer like wireshark and the same packets decoded by... You I know that no one give me working international server packet sniffer based on client hook but I think my request is rational.
Need only few packets started from server choose until char will be loaded.
Now i have some problems, first of all i think they changed old swordcrypt packet encoding/decoding key from 0 to 23 after that i get correct signature $2A (welcome packet) and connection packet but something is wrong... so I want compare it.
Ya I know next packets are encrypted by AES and i think i know how to bite it.
i don't think that you will be able to work out how it's crypted just by analysing the packets sniffed by wireshark and without doing some reverse engineering / debugging the engine.exe
but well...if you want to i can give you some packets
Code:
//Connect-Packet (0x08) - crypted with xor-crypt:
connectPacket->fillBuffer("bdddddbb",0x08,appTime,clientinfo->getConnectionParam(0),clientinfo->getConnectionParam(1),clientinfo->getConnectionParam(2),clientinfo->getConnectionParam(3),1,2); //connection params are recieved by the updater (everything uncrypted)
--> recv welcome packet (0x2a) (also crypted with xor crypt)
Code:
//Version-Check (0x09) - crypted with xor+aes:
versionCheck->fillBuffer("bdbd",0x09,clientinfo->getSync(),1,version); //you need to calculate sync and version with the information you get in 0x2a packet
Code:
//Login (0x02) - crypted with xor+aes:
loginPacket->fillBuffer("bdss",0x02,clientinfo->getSync(),clientinfo->getUserName(),clientinfo->getPassword());
--> recv loginAnswer (0x2b) - crypted with xor+aes
Code:
//2nd Password(0x75) - crypted with xor+aes:
secondPasswordPacket->fillBuffer("bdbs",0x75,clientinfo->getSync(),0,clientinfo->get2ndPassword());
--> recv available chars (0x11) - crypted with xor+aes
--> recv restore charinfo (0x19) - crypted with xor+aes
xor-key and (packed) aes key are also recieved by 0x2a packet
xor-send key gets increased by every packet which is sent
xor-recv key is always the same
so... I missed XOR that's why i get bad data - I don't have any packet data before and after encryption. If I get them then it's easy to calculate XOR key from it.
Thanks for above information it helped me a lot. Now I'm sure that packet ID's are correct and also get fresh info about bytes - very useful.
I don't have working hook on recv/send function, years ago I wrote it in Delphi but probably now it didn't work correctly and will be detected by HS. (C++ is not my lovely language) Also I don't need to calculate any data like getSync because I will read it (don't care about modification). Thanks again if someone could also send me those dumps I will be appreciated - if not I just spend more time to calculate it but who care the most important info I have now.
This is rally only XOR or something more? Tested single XOR with all 256 possible key's, XOR + swordcrypt, swordcrytp + XOR in all 64 possible key's and nothing -,-.
Swordcrypt Table was changed? My encrypt/decrypt table steel work on config.pk files.
My $08 packet to compare is based on getConnectionParam values from named shared memory and i know that it's good.
@pleaX thanks for that info I found new tables for SwordCrypt (or dunno how call it but historical first encryption in KalOnline, also standard in priv svr)
@Mahatma I entered a bit of confusion after your post. Probably by naming this encryption - when I changed xor crypt algoritm to SwordCrypt with new tables your informations were found to be clear and correct, thx.
For full 128bit block of data is used AES - if not full there is used simple XOR encryption with 16 byte key (like @meak1 talk about) I known that long time ago but never tested, till now:P
@meak1 Thanks also go to you, maybe I use those sync and AcceptAddy, to make rally stand alone application... dunno what with HS, CRC calculation, but this is topic for another story.
so... at last...
...Probably the first working Proxy written in Delphi for international servers :P
I found info that HS ask for chosen random memory region from KalOnline, so I think it's almost impossible to make HS client emulator without running process or process dump.
My RE skill is quite low... so probably i will send only "ping" packets (to keep connection) and HS/CRC request to KalOnline client, rest will be handled by my program.
[Release] +5500 Packets structure , client/packets constants 10/07/2012 - CO2 PServer Guides & Releases - 10 Replies edit : if u know nothing about packets go to this post first
explaining what is packets , and explaining a packet with details and everything
http://www.elitepvpers.com/forum/co2-pserver-disc ussions-questions/2162344-packets-packets-packets. html#post19074533
i start making my very own packet structure to use them on my new proxy but i thought of ripping them from the source
so yeah the following packets is ripped of trinity base source
right now im just providing the packets structure...
[PROBLEM]Cannot dump. No dump device defined. 07/30/2011 - Metin2 Private Server - 5 Replies Moin,
bin ja eigentlich nicht der, der bei Problemen direkt ins Forum rennt,
aber seit kurzem macht FreeBSD sehr eigenartige dinge, z.s. im folgenden Bild:
http://img337.imageshack.us/img337/9282/faild.png
Wenn ich 3-4 mal Reboote Startet er, aber vorher auch nicht...
Und jetzt kommts, das Passiert mit ALLEN SF's die ich besitze, d.h.
neu machen kann ich vergessen... Kann da jemand Abhilfe schaffen?
[Packets] Wie änder ich flyff packets? 07/16/2011 - Flyff Private Server - 19 Replies HeyHo,
Ich würde sehr gerne wissen wie man die Flyff Packets ändert...
ich denke mal Zahlen ändern werden nicht ausreichen oder?