Welcome!

Join our community of MMO enthusiasts and game developers! By registering, you'll gain access to discussions on the latest developments in MMO server files and collaborate with like-minded individuals. Join us today and unlock the potential of MMO server development!

Join Today!

[Icarus Online] Decrypting packets and getting 8-bit XOR key ?

Divine Celestial
Joined
Feb 25, 2013
Messages
808
Reaction score
343
Title.

If anyone knows, please speak here.
I don't mind if the examples are from different games.

Cheat sheet:
Launcher.exe loads GameGuard => GameGuard loads CryGame.dll => Game is locked and cannot make a dump.

Packets with hashing:
Header: /i:myhash /r:0000001 /u:0000002
76 00 0B 03 02
Data:
63 CB A6 42 88 17 BF B5 5A C7 A8 A3 07 3E E7 1B BA F3 EA 7D 4C A6 5B 29 E8 0D 25 F4 A1 EE E1 A2 BB D4 B8 60 F1 66 61 00 2A 79 CE D6 1D E0 2F 6E 56 76 E9 C9 83 26 49 1D 8C F2 2F 9A 7B F8 56 07 9A
55 2E DE 20 C9 B2 D9 39 AE 4B 8C 5E 64 1B 9A 72 E2 BF D8 5F 17 84 39 D6 D7 BC 24 DC 4A D5 AB A9
Ending:
43 F5 2C E5 7F 6F 59 B7 C9 DF 96 54 56 60 22 64
=========================================================================
Header: /i:myhash /r:0000001 /u:0000002
76 00 0B 03 02
Data:
67 A9 72 44 70 25 E0 C8 34 B2 84 FE E0 4C DD ED EB B2 58 E1 22 D1 CE 16 7E 8C 8B 47 18 22 15 85 76 EF 0F 10 A8 3C AD D9 9F 32 68 BC 6B DB 04 F8 BD 2A 6B 78 E1 AD FD 37 40 40 11 2D 36 1C C5 80 D6
55 2E DE 20 C9 B2 D9 39 AE 4B 8C 5E 64 1B 9A 72 E2 BF D8 5F 17 84 39 D6 D7 BC 24 DC 4A D5 AB A9
Ending:
43 F5 2C E5 7F 6F 59 B7 C9 DF 96 54 56 60 22 64
=========================================================================
Header: /i:myhash /r:0000002 /u:0000002
76 00 0B 03 02
Data:
62 A9 72 44 70 25 E0 C8 34 B2 84 FE E0 4C DD ED EB EE D2 D2 38 96 DF 85 17 B8 DD 76 F6 AC 05 C7 CA 3C 63 9A 10 4D 76 5B 16 DF 55 C2 D7 DF A3 68 4C 0E 0C 2C B8 EF A3 AD 4B AF CB 84 88 A0 F6 BB 6D
3D CB 06 95 B0 ED 36 64 09 A8 15 E3 D8 A3 27 09 C6 0A B2 E9 10 A4 61 DC 00 20 49 12 CF A4 97 1A
Ending:
0C 21 17 9A A6 CD 0F 7A 2C 83 AB 96 6D 05 49 E3
=========================================================================
Header: /i:myhash /r:0000002 /u:0000002
76 00 0B 03 02
Data
61 C3 67 E1 4C E9 A8 2A 02 14 CD 24 2D 5C 40 4D 89 72 3B 1A 5A FC 51 70 E7 5C CC 00 02 5D 98 A6 A3 AA AF 9A 18 6C A7 12 6A 0E D9 92 4B 67 96 CC 2E 6D E3 C6 04 15 F0 15 06 A5 BE F6 0A 0F 37 AA 88
CF E7 6E 92 F8 8F 27 C2 B8 92 DC 33 F8 23 32 70 39 E3 0C 21 85 67 EE 18 F6 B9 6A 00 D9 8D A4 F2
Ending:
0C 21 17 9A A6 CD 0F 7A 2C 83 AB 96 6D 05 49 E3
=========================================================================
Header: /i:201508251013chaozzisbest /r:0000002 /u:0000002
76 00 0B 03 02
Data:
6A 70 4B 31 14 28 7A F3 09 8B D0 95 B8 B0 37 82 9A 08 3E 0D 40 0B 17 B8 F3 D2 59 BA 27 71 4D 27 3E 9A 76 DF 05 E6 13 DA 72 BD D2 A3 D1 52 AB 95 F2 08 C4 72 B6 65 23 F5 44 2B 7F D0 CA FB AD 5D AF
A0 3F 82 3C B3 94 4D 0C 24 8A 0B 9B A6 40 A4 93 35 36 35 0D 3B 03 33 7F 8F 25 56 05 37 E5 70 84
Ending:
0C 21 17 9A A6 CD 0F 7A 2C 83 AB 96 6D 05 49 E3
=========================================================================
Header: /i:201508251013chaozzisbest /r:0000002 /u:0000002
76 00 0B 03 02
Data:
5C 70 4B 31 14 28 7A F3 09 8B D0 95 B8 B0 37 82 9A 08 3E 0D 40 0B 17 B8 F3 D2 59 BA 27 71 4D 27 3E 47 9A 47 A9 07 B2 03 4E 99 A4 92 55 AF 5F C1 31 E1 EA 99 C7 50 A2 C6 61 67 2B DA FD 4A DF F0 05
5F 93 2F FD 0B 21 DB 60 DB 87 FE 7E 73 F0 08 21 61 04 20 69 3D 73 7B A6 D8 66 FD AB 53 CA 19 CF
Ending:
0C 21 17 9A A6 CD 0F 7A 2C 83 AB 96 6D 05 49 E3

Hooked send() function goes to 3A5124B7 Address, but IDA doesn't show anything.
DNC ?
 
Last edited:
Back
Top