Register for your free account! | Forgot your password?

Go Back   elitepvpers > Search Forums
You last visited: Today at 20:01

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Showing results 1 to 25 of 35
Search took 0.02 seconds.
Search: Posts Made By: iszoPL
Forum: Kal Online 02/26/2013, 21:51
Replies: 40
Views: 3,918
Posted By iszoPL
heh have a nice evening ;) i'll try to code this...

heh have a nice evening ;) i'll try to code this now. I hope it'll work xD

Edit.

Ok thank you very much for help. I did all u told me to and it works like a charm xDD

captured chat send...
Forum: Kal Online 02/26/2013, 21:38
Replies: 40
Views: 3,918
Posted By iszoPL
Ok then what's this for in ur code? Because i'm...

Ok then what's this for in ur code? Because i'm now a little confused xD

if(buf[2] == 0x2A){
SendKey=*(BYTE*)&buf[7];

is this pointer the same data?
Forum: Kal Online 02/26/2013, 21:19
Replies: 40
Views: 3,918
Posted By iszoPL
You mean that there are 2 seperate pointers for...

You mean that there are 2 seperate pointers for aes key and table key?

The one u gave is to table with aes data and

BYTE *TKey = (BYTE*)*((DWORD*)(PacketSendMain+0xCA));

this is for table...
Forum: Kal Online 02/26/2013, 18:58
Replies: 40
Views: 3,918
Posted By iszoPL
Well i want to have a look at encrypted send...

Well i want to have a look at encrypted send packets so i can learn more about them.

So AES key is this 540 bytes long unknown table in baka code?

Basically i have to dump this table, swap it...
Forum: Kal Online 02/26/2013, 18:02
Replies: 40
Views: 3,918
Posted By iszoPL
I have to get straight some info because it's...

I have to get straight some info because it's chaos in my head right now xDD

This is captured packet 0x2a

57 0 2A 73 2B DD 9 3E 32 6D 25 51 36 8A 25 51 61 F6 F7 27 0 4 0 0 0
22 0 0 2 12 2 18...
Forum: Kal Online 02/26/2013, 14:37
Replies: 40
Views: 3,918
Posted By iszoPL
I'm trying to reverse this shit and it's so...

I'm trying to reverse this shit and it's so annoying ;p I can't find anywhere in near calls any trace of AES key. I thought that recv packet are not crypted and as it turns out they are ;p

There...
Forum: Kal Online 02/25/2013, 23:50
Replies: 40
Views: 3,918
Posted By iszoPL
heh most of his stuff is generated by IDA as i...

heh most of his stuff is generated by IDA as i see ;) Now i'm tracing call of decrypt func so i can find this stupid eas key xD I already have decrypttable. xor key also changed? Oh, and HS is too...
Forum: Kal Online 02/25/2013, 23:36
Replies: 40
Views: 3,918
Posted By iszoPL
There is alot to reverse ;p I guess it's not a...

There is alot to reverse ;p I guess it's not a job for today. It seems like alot of work for me since I am new at reversing ^^ and baka source's are complicated for me. Specially that I've never had...
Forum: Kal Online 02/25/2013, 21:52
Replies: 40
Views: 3,918
Posted By iszoPL
I'm guessing that 00484E80 is Decrypt func...

I'm guessing that

00484E80 is Decrypt func and at 007412E0 is DecryptTable right? ;) Now i have to guess what parameters they are taking ^^
Forum: Kal Online 02/25/2013, 21:08
Replies: 40
Views: 3,918
Posted By iszoPL
But this function u gave is encrypt. I didn't yet...

But this function u gave is encrypt. I didn't yet tried to reverse it. I guess it takes buffer and some other stuff to do it. I guess it would be easier to find their decrypt function and just use...
Forum: Kal Online 02/25/2013, 20:51
Replies: 40
Views: 3,918
Posted By iszoPL
hmm so i have to find decrypt table in order to...

hmm so i have to find decrypt table in order to decrypt packets right and decrypt function. Or just use encrypt function in reversed order?
Forum: Kal Online 02/25/2013, 20:39
Replies: 40
Views: 3,918
Posted By iszoPL
Thanks. I love you xDD I'd try to check it myself...

Thanks. I love you xDD I'd try to check it myself after decrypting send packets but it's huge help for me ;) I guess encrypt table can be also used to decrypt packets. I know it's a stupid question...
Forum: Kal Online 02/25/2013, 20:17
Replies: 40
Views: 3,918
Posted By iszoPL
Thanks blood ;) I changed my send to ...

Thanks blood ;)

I changed my send to

void KalTools::SendEngine(DWORD Header,LPCSTR szFormat,...)
{
va_list args;
va_start(args, szFormat);
...
Forum: Kal Online 02/25/2013, 17:10
Replies: 40
Views: 3,918
Posted By iszoPL
Ye so pretty much my engineSend did the same...

Ye so pretty much my engineSend did the same thing but it was calling directly their function and passing parameters. Anyway is this sit packet ok? I want to check if it works

send(0x1F,"b",1);
Forum: Kal Online 02/25/2013, 16:59
Replies: 40
Views: 3,918
Posted By iszoPL
oh... i get it know. This kind of programming is...

oh... i get it know. This kind of programming is new for me so don't be angry if i don't undestand how sometimes some things works.
Forum: Kal Online 02/25/2013, 16:37
Replies: 40
Views: 3,918
Posted By iszoPL
Yes i know this example. But in order for this to...

Yes i know this example. But in order for this to work you need to place JMP over first 5 bytes of this func to ur function right? And if I try that hs detects memory corruption.

Edit.

@blood
...
Forum: Kal Online 02/25/2013, 16:27
Replies: 40
Views: 3,918
Posted By iszoPL
I can hook IAT send. How can i answer to that if...

I can hook IAT send. How can i answer to that if it needs socket,buf,len,flags.
It's easier to use engineSend than ws2 send. I'd have to crypt packet first in order to use IAT hooked send.

I...
Forum: Kal Online 02/25/2013, 16:21
Replies: 40
Views: 3,918
Posted By iszoPL
I changed calling convention to cdecl already....

I changed calling convention to cdecl already. I've noticed it after posting ;p.

@meak
I am using their send function. I just got address and sendEngine is executing it as u can see. I can't hook...
Forum: Kal Online 02/25/2013, 15:42
Replies: 40
Views: 3,918
Posted By iszoPL
[Question] Sending data

I have 2 questions.

I know that packets are encrypted. I found address of send in engine, not ws2 send but engineSend func that takes data before it's encrypted.

I am able to use it but i...
Forum: Kal Online 02/20/2013, 23:41
Replies: 15
Views: 4,557
Posted By iszoPL
hmm... so if first doesn't work then any idea why...

hmm... so if first doesn't work then any idea why my thread is not working properly when injected before hs?

Edit.

Ok so I found a way to inject without beeing detected and without any driver...
Forum: Kal Online 02/20/2013, 21:47
Replies: 15
Views: 4,557
Posted By iszoPL
Second sounds pretty easy and I already tried...

Second sounds pretty easy and I already tried that. Unfortunately even that it injects before hs there is a problem with my thread. It seems like they are blocking each other with main thread. If i...
Forum: Kal Online 02/20/2013, 21:16
Replies: 15
Views: 4,557
Posted By iszoPL
oO so I had this the whole time and I didn't know...

oO so I had this the whole time and I didn't know that was it. I'm guessing then that this is part of that obfuscated IAT. I was checking earlier dumped engine. Highlited address is add of recv in...
Forum: Kal Online 02/20/2013, 20:12
Replies: 15
Views: 4,557
Posted By iszoPL
Ok so I'm trying to do mid-function hook as you...

Ok so I'm trying to do mid-function hook as you said.

DWORD dwJMPback = (DWORD)GetProcAddress(GetModuleHandle(L"ws2_32.dll"),"recv") + 0xA; //The Jump Back address

__declspec(naked) void...
Forum: Kal Online 02/20/2013, 14:06
Replies: 15
Views: 4,557
Posted By iszoPL
I'll try that but this raises the question. Why...

I'll try that but this raises the question. Why isn't it showing up at IAT of engine.exe? Is it hidden some way? Lucky that i found a kernel driver that is letting me attach dbg to engine after hs...
Forum: Kal Online 02/19/2013, 02:35
Replies: 15
Views: 4,557
Posted By iszoPL
My hook partially works. GetProcAddress returns...

My hook partially works. GetProcAddress returns fRecv function adress instead of original recv from ws2_32. This was just to check and yes it works fine(just check).

Well after injecting I checked...
Showing results 1 to 25 of 35

 
Forum Jump

All times are GMT +1. The time now is 20:03.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.