GMO eX700 (Finally)

Page 5 of 8 FirstFirst 12345678 LastLast
Results 61 to 75 of 109
  1. #61
    Apprentice k2diablo is offline
    MemberRank
    May 2012 Join Date
    7Posts

    Re: GMO eX700 (Finally)

    Can someone post the ASM New XOR Function?

  2. #62
    Don't be a hater 1Word is offline
    MemberRank
    Jan 2006 Join Date
    At homeLocation
    1,779Posts

    Re: GMO eX700 (Finally)

    Please don't turn this into an advertisment thread :)

  3. #63
    NN - Nord & Noob mauka is offline
    MemberRank
    Jul 2004 Join Date
    1,728Posts

    Re: GMO eX700 (Finally)

    Quote Originally Posted by k2diablo View Post
    Can someone post the ASM New XOR Function?
    well, i dint try debug it, but u can find protocol core and start BP on it and check what changes there is.

    Search for string: "Send Request Server List"
    and check from where this function is called -> function is called from protocol core

    OK, this main.exe is badly wrong unpacked or shit is virtualized :/
    @0115F05F offset u need set BP and on C3 r C4 packet u need check what it does do before decrypt it and push it into protocol core, but all opcodes are fucked up.. so its must be virtualized :/

    Code:
      MOV EAX,DWORD PTR SS:[EBP+8h]
      JMP 9C345A2h
      JMP 06637CBh
      MOV DWORD PTR SS:[EBP-102Ch],EAX
      JMP 066391Ch
      SUB ESP,8h
      JMP 9CA59BEh
      MOV DWORD PTR SS:[EBP-102Ch],EAX
      JMP 066391Ch
      MOV ECX,DWORD PTR SS:[EBP+8h]
      MOV EDX,DWORD PTR DS:[ECX+4h]
      MOV DWORD PTR SS:[EBP-75Ch],EDX
      JMP 09FA507h
      MOV EAX,DWORD PTR SS:[EBP+8h]
      ADD EAX,4h
      MOV DWORD PTR SS:[EBP-75Ch],EAX
      JMP 09FA507h
      MOV EAX,DWORD PTR SS:[EBP-10h]
      MOVZX EAX,BYTE PTR DS:[EAX+2h]
      CMP EAX,0C2h
      JE 0439644h
      JMP 115F2CBh
      XOR EAX,EAX
      MOV WORD PTR SS:[EBP-4h],AX
      JMP 9CA704Ch
      PUSH 0FF6828h
      PUSH 119B180h
      JMP 0663B55h
      MOV EAX,DWORD PTR SS:[EBP-204h]
      MOVZX EAX,BYTE PTR DS:[EAX+669F66h]
      JMP DWORD PTR DS:[EAX*4h+4h669CEEh]
      MOV ECX,DWORD PTR SS:[EBP+8h]
      JMP 06637CEh
      MOV DWORD PTR SS:[EBP-1020h],1020h1h
      CMP DWORD PTR SS:[EBP-102Ch],102Ch0h
      JGE 06639A1h
      JMP 115F285h
      OR EAX,0FFFFFFFFh
      MOV EBX,DWORD PTR SS:[ESP]
      JMP 9CA59DDh
      NOP 
      ADC BYTE PTR SS:[ECX+8DFC2474h],CL
      AND AL,0FCh
    unreadable
    Last edited by mauka; 24-05-12 at 02:27 PM. Reason: wrong offset xD

  4. #64
    Account Upgraded | Title Enabled! inkredibil is offline
    MemberRank
    Nov 2005 Join Date
    217Posts

    Re: GMO eX700 (Finally)

    Quote Originally Posted by GlobalMu View Post
    Hello Everyone, I bring you an announcement about the Ex700 of Mu Online!



    Check it out on: Official MU Online
    Mu Developers should learn more from developers of private servers ,

    Why peoples prefer private and not official? Why are private server overcrowded ? Think a bit at that ?

  5. #65
    Hybrid Gembrid is offline
    MemberRank
    Mar 2006 Join Date
    1,121Posts

    Re: GMO eX700 (Finally)

    Quote Originally Posted by mauka View Post

    but all opcodes are fucked up.. so its must be virtualized :/


    unreadable

    it's obfuscated

  6. #66
    NN - Nord & Noob mauka is offline
    MemberRank
    Jul 2004 Join Date
    1,728Posts

    Re: GMO eX700 (Finally)

    Ima not good in unpacking and never like it.. anoining. t4You says: needs use "CodeDoctor" to deobfuscate code

    Code:
    Functions:
    
    1) Deobfuscate
    
    Select instructions in disasm window and execute this command. It will try 
    to clear the code from junk instructions.
    
    Example:
    
    Original:
    00874372    57                      PUSH EDI                                     
    00874373    BF 352AAF6A             MOV EDI,6AAF2A35
    00874378    81E7 0D152A41           AND EDI,412A150D
    0087437E    81F7 01002A40           XOR EDI,402A0001
    00874384    01FB                    ADD EBX,EDI                                 
    00874386    5F                      POP EDI                                     
    
    Deobfuscated:
    00874372    83C3 04                 ADD EBX,4
    garbage

    Added: its works xD
    Last edited by mauka; 25-05-12 at 11:58 AM.

  7. #67
    Hybrid Gembrid is offline
    MemberRank
    Mar 2006 Join Date
    1,121Posts

    Re: GMO eX700 (Finally)

    Quote Originally Posted by mauka View Post
    Ima not good in unpacking and never like it.. anoining. t4You says: needs use "CodeDoctor" to deobfuscate code
    well, it's not unpacking, it's deobfuscating, if you unpack main, you can leave the code obfuscated if you don't need to know how it works, otherwise need to deobfuscate, and CodeDoctor won't help you a lot =)


    and i think, if you want to discuss main.exe, it's a bad thread :D and better create new one
    Last edited by Gembrid; 25-05-12 at 12:08 PM.

  8. #68
    NN - Nord & Noob mauka is offline
    MemberRank
    Jul 2004 Join Date
    1,728Posts

    Re: GMO eX700 (Finally)

    If codedoctor not help, ima gonna cry fenix for do this shit for me xD
    * whats the point of friends if u dont USE them (TROLOLOLOL)

    Quote Originally Posted by Gembrid View Post
    if you want to discuss main.exe, it's a bad thread :D and better create new one
    nah, its related to x700

    Added: deobfocusated not so hard i see.. u can easy folow calls untill u land where u need ;)
    or manualy resolve all JMPs xD
    Last edited by mauka; 25-05-12 at 12:34 PM.

  9. #69
    Apprentice k2diablo is offline
    MemberRank
    May 2012 Join Date
    7Posts

    Re: GMO eX700 (Finally)

    mauka and did u found anything new about packets enc/dec?

  10. #70
    NN - Nord & Noob mauka is offline
    MemberRank
    Jul 2004 Join Date
    1,728Posts

    Re: GMO eX700 (Finally)

    Nope, the code is totlay fucked up and i need it deobfuscated to reverse func :/ not NOP it

  11. #71
    Don't be a hater 1Word is offline
    MemberRank
    Jan 2006 Join Date
    At homeLocation
    1,779Posts

    Re: GMO eX700 (Finally)

    Quote Originally Posted by inkredibil View Post
    Mu Developers should learn more from developers of private servers ,

    Why peoples prefer private and not official? Why are private server overcrowded ? Think a bit at that ?
    How are private servers overcrowded ? 70% of servers have 0-30 on, 15% 30 - 100, 10% 100-200 and 5% 200+
    While GMO easily has 2000+ online

  12. #72
    Alpha Member 2009x2014 is offline
    MemberRank
    Dec 2009 Join Date
    2,765Posts

    Re: GMO eX700 (Finally)

    Quote Originally Posted by 1Word View Post
    How are private servers overcrowded ? 70% of servers have 0-30 on, 15% 30 - 100, 10% 100-200 and 5% 200+
    While GMO easily has 2000+ online
    now count all private servers in one ^_^

  13. #73
    Don't be a hater 1Word is offline
    MemberRank
    Jan 2006 Join Date
    At homeLocation
    1,779Posts

    Re: GMO eX700 (Finally)

    Quote Originally Posted by 4FUNer View Post
    now count all private servers in one ^_^
    That is not a fair statement... it's like comparing the most powerfull country population to the population of the rest of the world

    Anyway, sorry for offtopic guys, you can come back to ex700 now -.-

  14. #74
    NN - Nord & Noob mauka is offline
    MemberRank
    Jul 2004 Join Date
    1,728Posts

    Re: GMO eX700 (Finally)

    Quote Originally Posted by 1Word View Post
    How are private servers overcrowded ? 70% of servers have 0-30 on, 15% 30 - 100, 10% 100-200 and 5% 200+
    While GMO easily has 2000+ online
    in mean time zhyper got more players then gmo ;) shore its be cause of k2 gays ^__^

  15. #75
    Apprentice DarkFlame is offline
    MemberRank
    Nov 2009 Join Date
    19Posts

    Re: GMO eX700 (Finally)

    What is this update? o_o



Page 5 of 8 FirstFirst 12345678 LastLast

Advertisement