Hi Ragezone i have a big problem with this packet ( Outbound 1394 Length opcode 006|001) "charselection -> ingame login"
that looks like so as hex17 32 44 65 63 72 79 70 74 30 30 36 5F 30 30 31 00 00 32 32 37 66 36 35 31 37 66 36 31 30 35 30 65 34 64 38 61 33 33 36 64 34 37 31 38 66 33 32 32 38 33 30 62 35 35 30 33 35 65 35 35 31 32 38 35 66 30 61 31 39 36 31 34 34 61 31 30 35 33 63 65 34 36 38 64 36 33 63 31 64 63 32 65 32 33 66 31 62 35 34 38 62 63 36 61 63 66 34 33 61 32 33 37 64 38 39 66 64 35 61 32 63 31 64 36 33 66 64 39 66 35 36 65 64 35 61 37 35 63 61 38 62 37 64 34 38 30 34 66 34 66 66 30 37 64 30 62 39 61 33 63 35 37 31 64 64 64 35 61 31 66 30 38 62 63 38 33 34 30 31 31 32 36 39 33 38 66 64 33 39 30 35 66 65 66 32 33 32 35 30 39 66 31 38 37 33 38 66 35 34 66 37 30 30 39 37 63 34 36 31 63 38 63 36 36 64 66 33 38 38 31 33 66 65 65 62 36 37 32 66 66 63 32 32 37 32 63 31 39 30 66 32 31 39 61 36 35 32 30 36 36 31 66 64 37 37 65 32 66 65 36 32 64 39 39 35 30 32 65 61 38 30 34 36 39 38 64 30 61 38 31 31 61 65 65 36 64 64 37 31 33 66 34 39 37 38 30 38 62 62 62 33 64 64 66 61 62 64 34 66 36 66 61 61 62 33 31 62 32 33 61 36 37 37 34 66 31 61 62 35 66 35 66 33 37 34 62 31 63 39 39 30 33 64 62 66 63 62 38 33 32 66 63 33 32 33 37 39 30 37 66 38 61 39 32 33 39 30 30 63 32 39 66 34 32 65 31 34 64 66 33 30 63 36 33 30 38 63 63 34 30 34 65 62 66 34 32 62 33 30 32 32 65 62 35 38 65 65 37 65 39 64 36 30 36 37 39 35 38 66 31 32 63 30 33 35 65 30 64 63 65 38 31 37 38 33 61 34 35 36 61 33 61 30 62 35 31 36 34 37 65 39 66 30 66 37 63 65 34 64 62 34 38 35 34 66 64 36 38 30 61 65 33 38 32 30 36 63 37 34 63 38 35 30 35 30 61 37 63 63 66 30 64 61 62 33 36 38 64 33 61 61 33 38 66 66 61 39 61 30 38 39 66 34 36 65 34 35 39 63 30 64 38 39 66 34 33 31 31 31 63 63 64 37 63 33 61 33 65 38 65 32 34 62 66 33 65 33 32 37 38 31 30 30 38 34 37 34 65 39 31 38 39 63 35 61 33 34 34 61 66 66 38 34 62 38 65 31 64 30 62 38 38 31 36 37 61 64 31 63 62 32 34 36 36 35 62 61 38 33 62 66 31 30 35 32 38 34 30 38 63 66 33 65 37 30 31 38 63 31 61 62 66 63 30 32 34 37 36 66 66 63 66 32 32 32 31 31 30 36 32 38 37 39 39 61 35 61 34 66 35 61 38 63 35 64 35 32 63 30 36 65 63 31 37 32 63 62 62 38 31 65 61 30 64 37 66 66 63 38 35 65 62 33 31 63 32 66 61 39 36 66 34 64 34 36 62 37 37 39 63 64 34 32 39 36 35 66 36 37 37 36 64 33 36 37 62 65 61 38 62 61 64 62 64 38 62 35 36 63 38 31 34 62 33 35 30 39 35 34 30 62 37 34 38 39 37 35 31 63 64 65 36 33 31 64 38 38 38 65 35 32 32 34 64 39 66 65 62 63 64 38 63 39 38 32 32 65 35 34 63 64 35 65 31 36 30 62 65 37 33 33 31 66 32 38 62 37 34 35 34 32 63 37 31 33 64 65 66 65 66 64 64 66 37 62 30 61 36 33 30 31 38 61 36 33 37 37 61 63 36 38 38 63 63 61 62 65 30 33 64 63 61 32 35 66 62 63 65 65 65 36 37 37 61 30 33 66 35 30 61 38 36 36 31 32 38 65 34 64 38 62 66 34 65 35 62 63 30 32 37 61 66 33 63 33 65 34 64 34 31 30 37 61 39 65 64 31 39 31 37 61 37 35 64 63 66 63 39 35 61 65 65 36 36 39 34 30 65 30 64 38 65 64 33 30 62 62 32 64 65 38 61 36 64 30 31 39 37 31 63 66 39 34 64 35 65 32 37 63 66 30 38 36 33 64 39 33 63 33 35 39 61 30 63 33 31 37 30 37 38 30 38 66 61 66 38 31 64 33 61 63 62 66 35 64 30 63 39 37 35 33 33 32 64 62 63 62 36 66 62 34 65 64 33 63 31 65 31 38 35 34 37 33 35 30 39 64 36 30 35 65 38 37 33 34 33 61 34 30 33 31 38 66 34 38 35 61 61 32 64 33 36 66 61 35 32 36 65 34 35 34 61 63 35 36 33 38 61 62 30 63 30 33 66 33 61 37 34 31 66 30 34 61 39 31 65 37 61 30 66 35 35 64 62 34 33 66 38 36 36 32 35 62 33 34 33 63 30 34 65 33 32 38 36 36 35 65 66 37 30 65 38 38 64 64 62 32 63 38 61 63 64 32 39 62 38 31 63 63 39 62 31 35 30 36 63 37 61 37 34 39 32 31 36 35 39 33 37 39 31 39 38 36 31 38 66 35 32 32 30 62 63 38 62 38 30 31 66 35 65 32 31 31 35 65 62 32 35 34 64 64 30 30 32 66 64 31 63 63 61 33 66 33 66 36 66 66 66 30 64 38 38 39 31 63 37 36 31 37 37 38 37 63 38 66 34 64 62 31 61 62 36 31 32 35 63 62 61 36 39 36 35 64 32 30 30 30 62 61 61 32 37 65 62 34 34 65 33 31 34 39 64 38 38 35 34 32 36 39 66 63 63 32 33 36 33 65 65 34 38 33 35 39 65 62 33 61 35 38 36 38 62 38 35 36 62 35 64 64 63 37 30 37 31 36 32 31 38 34 38 64 62 39 33 62 35 37 35 66 65 66 61 64 33 32 35 34 30 35 37 64 38 66 37 61 39 65 39 36 38 62 62 36 34 63 38 66 65 39 62 64 64 31 39 30 37 37 38 64 37 31 39 32 62 65 35 34 35 63 64 34 63 30 33 63 61 37 36 62 64 36 36 65 62 37 64 37 63 34 65 30 32 39
Attachment 115038Attachment 115037
once what we know is :
It seems to be from the SHN files
[06.09.2012 22:20:26] Diamondo25: b0ee829043fd2f6e7c10fade5500b855abstate.shn
[06.09.2012 22:22:14] Diamondo25: there we go
[06.09.2012 22:23:04] Diamondo25: I found the crypto function
[06.09.2012 22:24:00] Diamondo25: yep
[06.09.2012 22:26:38] Diamondo25: It won't be easy, I guess
[06.09.2012 22:30:57] Diamondo25: It's an easy crypto, but I don't get how they make the hashes
[06.09.2012 22:31:03] Diamondo25: I'm sure they are static
[06.09.2012 22:31:12] Diamondo25: and you can easily find the hashes from the client
[06.09.2012 22:31:22] Diamondo25: as they are on a static address
on this packed are cliend id , charname and 40-50 hashes maybe from shn's
so what we need is a good asm coder :) there can maybe help us :)
thats for a Clientless Bot



Reply With Quote


