Welcome to the RaGEZONE - MMORPG development forums.

C1 AntyBot-HowTo 1&2: Network.dll reoptimisation and encryption kay change

This is a discussion on C1 AntyBot-HowTo 1&2: Network.dll reoptimisation and encryption kay change within the L2Off Archives forums, part of the Lineage 2 - Official category; Nice post ~ Thank you ^^ Tested and working in under 2 minutes :)...

Page 2 of 3 FirstFirst 123 LastLast
Results 16 to 30 of 36
  1. #16
    Ultimate Member
    Rank
    Member
    Join Date
    Apr 2005
    Location
    Other
    Posts
    171
    Liked
    0
    Click
    Nice post ~ Thank you ^^

    Tested and working in under 2 minutes :)

  2. #17
    Member
    Rank
    Member
    Join Date
    May 2004
    Location
    Russia
    Posts
    65
    Liked
    0

  3. #18
    Registered
    Rank
    Member
    Join Date
    Jan 2005
    Location
    AL
    Posts
    9
    Liked
    0
    только учти что ключи уже ищут в памяти, а не в dll, а в памяти он всегда распакован

  4. #19
    Member
    Rank
    Member
    Join Date
    May 2004
    Location
    Russia
    Posts
    65
    Liked
    0
    Next idea: when gamer in game, some time ahead him appear random numeric string.
    If player enter it to the general game chat between 5 or 10 minutes, so they are not a bot )

    This idea have very simple automatic solution:

    1) Add numeric string ahead player nickname
    2) Wait 5-10 min while player enter it
    3) Replace string to old and kick player if not 2)

    any corrections?

  5. #20
    Member
    Rank
    Member
    Join Date
    Apr 2005
    Location
    Russia
    Posts
    46
    Liked
    0
    about external bots and 2 servers with same id - try to add first server 0.0.0.0 instead 127.0.0.1 and external bots cannot in :) but user need to select server 2 with in testing mode.

    note: with 127.0.0.1 ip in db any user may forward 7777 local port to 7777 port on remote ip with no problems, in that case i dunno about how to do that :)

    2KEMBL: i think there is need a bot that after 5-10min login user type in private smth like: "hello! 5+7-1=? reply to me, if not your account will be banned for 24hours" :)

  6. #21
    Newbie
    Rank
    Member
    Join Date
    Jul 2005
    Posts
    2
    Liked
    0
    Quote Originally Posted by juster
    в общем того раза уже хватило чтобы отсечь внешних ботов. теперь все юзают ингейм ботов. вот бы теперь обсудить отлов ингейм валкеров, и проч.
    Невозможно в принципе. Или патчить Network.dll на отлов определенных процессов в памяти.

  7. #22
    Opus Dei
    Rank
    Member +
    Join Date
    May 2004
    Posts
    303
    Liked
    1
    This is very usefull, stickied, i also try to merge with Your other thread.

  8. #23
    Hardcore Member
    Rank
    Member
    Join Date
    Aug 2005
    Location
    Greece
    Posts
    147
    Liked
    0
    1rst You can dump the dll from memory, even the most compressed and protected one and get the hash key. Just wait until L2.exe go to login screen (the dll is fully decrypted there, we dont need its IAT table etc etc), then dump the dll with yoda's LordPE. Search for the hash bla bla. Tested with PeCompact, Armadillo, Aspack/ASPr, UPX and some other packers.
    2nd You can patch l2walker (outgame) in memory and change its default hash key (2 times in memory image) and play as normal as before. I know that this way works as i did it before.
    3rd You forget the sounds in some bots like l2walker, so sending messages is not the way.
    4rth You can code a proxy that enters into the second testing server where the bot cant and emulate the packets needed for the bot to operate (something hybrid like muhax - all you need is l2j code).

    Sorry but these sollutions are for kids. What you need is a program that:
    a) protects l2 files from editing by hex or memory editors
    b) checks for debuggers,dumpers
    c) checks for varius cheats
    d) changes in memory the hash key
    e) encrypts the packets in client (using hooks in winsock dll function to preserve the ip of the user) and decrypts them in server
    f) reports back to server if found anything suspicious

    and keep in mind of users' privacy!!!

  9. #24
    Registered
    Rank
    Member
    Join Date
    Nov 2004
    Posts
    7
    Liked
    0
    thats why gameguard was bundled to l2 right?

  10. #25
    Hardcore Member
    Rank
    Member
    Join Date
    Aug 2005
    Location
    Greece
    Posts
    147
    Liked
    0
    for some parts yes. but gameguard can be disabled very easy.

  11. #26
    █║▌║▌║TheMerc iful║▌║▌║█
    Rank
    Subscriber
    Join Date
    Jan 2005
    Location
    DXB
    Posts
    957
    Liked
    93
    But Then Yet... The Fix That Has Been Released Has The Capability To Stop The Bot...

    Tanx Again Guys For The Release... It Is Well Appreciated...
    L.P.: "God save us everyone, When we burn inside the fires of a thousand suns, For the sins of our hand, the sins of our tongue,.. The sins of our father, the sins of our young."
    SARCASM: Because Beating The SHIT! Out People Is Illegal...

  12. #27
    Newbie
    Rank
    Member
    Join Date
    Oct 2005
    Location
    Europe, UK, London, Manchester
    Posts
    4
    Liked
    0
    Tanx For The Boost...
    May The Force Be With You!!! :starwars:

  13. #28
    arkanoid
    Guest
    thanks for the help

  14. #29
    Newbie
    Rank
    Member
    Join Date
    May 2006
    Posts
    1
    Liked
    0
    and c3 stopping botting ?

  15. #30
    Newbie
    Rank
    Member
    Join Date
    Oct 2005
    Location
    Argentina
    Posts
    2
    Liked
    0
    Que placer verte por aqu

 

 
Page 2 of 3 FirstFirst 123 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •