Idle Heroes 1.34.4 tools. Source Mobile 

RaGEZONE VIP
RaGEZONE VIP
Joined
Dec 24, 2023
Messages
22
Reaction score
347
Releasing some decrypted and decompiled LUAC/LUA game scripts for Idle Heroes 1.34.4 latest patch (on current date) and tools for reverse-engineering.


Complete reverse engineering toolkit for Idle Heroes
  • Decrypt encrypted Lua files (DHGAMES→XOR→XXTEA→ZLIB)
  • Decompile Lua 5.1 bytecode to readable source code
  • Extract game data (heroes, items, skills) to JSON
  • Analyze game mechanics and formulas
  • Reconstruct Protobuf schemas
  • Generate SQL for database import

Decrypted Lua bytecode files
  • Original encrypted files → decrypted using reverse-engineered algorithm
  • Lua 5.1 bytecode format (Cocos2d-x)
  • Contains: game configs, hero/item data, battle logic, UI, network protocol

​

Decompiled Lua source code
  • Human-readable Lua source recovered from bytecode
  • Includes variable names, function structures, game logic

Link:
To view the content, you need to sign In or register.
 
Last edited:
Great, Thank You, sitxovni !
But I cannot decompile properly, getting only consts in comments. So I decided to decomplile it by hand, small file "activitylogin.lua". And the problem is the 1st opcode it contains is 0x14, which just skipped by LuaDecompiler. Then another three 0x14 and then several 0x0e, which skipped too.
Maybe it's not the last version of decompiler on github?

And there is 1 issue little I have to fix: paths in decrypt_ULTIMATE.py are hardcoded and not relative like in "decompile_...py". Decryptor seems working, I got same files as in github decrypting my own. Can you check decompiler?
Releasing some decrypted and decompiled LUAC/LUA game scripts for Idle Heroes 1.34.4 latest patch (on current date) and tools for reverse-engineering.
 
Great, Thank You, sitxovni !
But I cannot decompile properly, getting only consts in comments. So I decided to decomplile it by hand, small file "activitylogin.lua". And the problem is the 1st opcode it contains is 0x14, which just skipped by LuaDecompiler. Then another three 0x14 and then several 0x0e, which skipped too.
Maybe it's not the last version of decompiler on github?

And there is 1 issue little I have to fix: paths in decrypt_ULTIMATE.py are hardcoded and not relative like in "decompile_...py". Decryptor seems working, I got same files as in github decrypting my own. Can you check decompiler?
Nice to see someone is truly using it, I’ll try my best update it according to your findings. It would be great if you post it in “issues” in GitHub repo
 
Nice to see someone is truly using it, I’ll try my best update it according to your findings. It would be great if you post it in “issues” in GitHub repo

Trying to use) Finally I found the problem: `decompile_all_advanced.py` uses `advanced_decompiler.py`, which have no idea about bytecode reordering. But there is an `improved_lua_decompiler.py`, which knows everything. So I just patched `decompile_all_advanced.py` to use proper decompiler.

Another minor issues: `generate_import_sql.py` doesn't create destination dir (other tools do). Also it searching `data` in the current dir, while other script puts it into `private-server/data`.

Btw, how to get newest apk or update data? I only can get some 1.34 version, which is older then yours. An current/future events are event newer.

Sorry, I cannot post on GitHub at the moment
 
Trying to use) Finally I found the problem: `decompile_all_advanced.py` uses `advanced_decompiler.py`, which have no idea about bytecode reordering. But there is an `improved_lua_decompiler.py`, which knows everything. So I just patched `decompile_all_advanced.py` to use proper decompiler.

Another minor issues: `generate_import_sql.py` doesn't create destination dir (other tools do). Also it searching `data` in the current dir, while other script puts it into `private-server/data`.

Btw, how to get newest apk or update data? I only can get some 1.34 version, which is older then yours. An current/future events are event newer.

Sorry, I cannot post on GitHub at the moment
Thanks for your research. Yeah, it seems to be truth, cuz i was trying different methods and solutions. This project is not just “decompiler” or smth..it is everything I’ve made and everything I was working with, so yeah - it indeed needs some time to figure out what is what and how it works. About apk - idk, latest apk you can find somewhere in web like I did.. updated resources can be easily transferred from your phone
 
Thanks for your research. Yeah, it seems to be truth, cuz i was trying different methods and solutions. This project is not just “decompiler” or smth..it is everything I’ve made and everything I was working with, so yeah - it indeed needs some time to figure out what is what and how it works. About apk - idk, latest apk you can find somewhere in web like I did.. updated resources can be easily transferred from your phone
ok, thanks!
digging deeper, I'm sure there is a bug in opcode mapper. the 0x14 opcode transforms to CONCAT, but registers contain objects. Lua cannot concat objects afaik. Looks like it should be NEWTABLE instead.
Also it's very strange to have "_ALT" versions and miss many opcodes, especially GETGLOBAL. maybe it's not the final version on github? or can you share decompiled "libcocos2dlua.so.c" or it's part so I can try to help to find, what's the problem?
 
Releasing some decrypted and decompiled LUAC/LUA game scripts for Idle Heroes 1.34.4 latest patch (on current date) and tools for reverse-engineering.


Complete reverse engineering toolkit for Idle Heroes
  • Decrypt encrypted Lua files (DHGAMES→XOR→XXTEA→ZLIB)
  • Decompile Lua 5.1 bytecode to readable source code
  • Extract game data (heroes, items, skills) to JSON
  • Analyze game mechanics and formulas
  • Reconstruct Protobuf schemas
  • Generate SQL for database import

Decrypted Lua bytecode files
  • Original encrypted files → decrypted using reverse-engineered algorithm
  • Lua 5.1 bytecode format (Cocos2d-x)
  • Contains: game configs, hero/item data, battle logic, UI, network protocol

​

Decompiled Lua source code
  • Human-readable Lua source recovered from bytecode
  • Includes variable names, function structures, game logic

Link: [Hidden content]
thank
 
current live version of game if anyone is intested

# The final XOR key pattern
REALKEY = bytearray([
0x3C, 0xB5, 0x3C, 0x7F, 0x83, 0x94, 0xBA, 0x3B,
0x2B, 0xB2, 0x73, 0x5B, 0xEF, 0xEE, 0xE2, 0xA3,
0x3B, 0x2B, 0xCC, 0x66, 0x3D, 0xE5, 0x2C, 0xD7,
0x4D, 0x2E, 0x17, 0xE6, 0xF3
])


- `Magic_String`: A hardcoded string built into the client. For this version, it is: `rwmkxhgi6;578i650`
def get_password_hash(salt, password):
"""
Implements the legacy password hashing:
MD5(salt + "rwmkxhgi6;578i650" + MD5(password))
"""
if isinstance(salt, bytes):
salt = salt.decode('utf-8', errors='ignore')

md5_pass = hashlib.md5(password.encode('utf-8')).hexdigest()
final_str = f"{salt}rwmkxhgi6;578i650{md5_pass}"
return hashlib.md5(final_str.encode('utf-8')).hexdigest()

i also have all the game tables dumped via frida - source of truth for everything client side and the combat sequence 'streaming' working this includes animation keys for heroes etc.


 

Attachments

Last edited:
i also have all the game tables dumped via frida - source of truth for everything client side and the combat sequence 'streaming' working this includes animation keys for heroes etc.
you can restore that tables from lua. I convert everything from `src/app/config` to jsons — there are tables.
btw, have you depack spinejson? it doesn't seem like original binary spine format. maybe XORed. just interesting
 
sadly this is AI-generated code full of hallucinations (e.g. "exracted" protobuf is just crazy). But decryption part works.
Fun fact: this project contains wrong opcode_mapping.txt with duplicates and missing opcodes, and now this hallucination already poisoned at least one another project (some lua decompiler), which is also documents that IH has such a strange opcode mapping :)
 
Back