Localhostr.dll and Localhosting think tank

Re: Localhostr.dll

I don't quite know your problem, if x0r said it was hack shield, then what part? Oh and my code doesn't bypass Hackshield it just stops localhosting if it is Hackshield. You could hook IsWow64Process and stop the driver from loading, but that only stops the driver.
 
Last edited:
Re: Localhostr.dll

I have no idea how HackShield finds out that the connection was redirected, x0r just suggested me to turn off HS completely by preventing the injection (but I failed, it just wouldn't load that HS dll in my LoadLibraryA hook).

My problem is that my connect hook isn't called with a return address in some HackShield dll.

Also when I use your precompiled DLL, the same thing happens; MapleStory shuts down exactly 1 minute after it connected to my server.

So there has to be some other check?
 
Re: Localhostr.dll

KFC said that when he hooked timing APIs they where called, I'll look into that.

Edit:

The login information uses RSA in MSEA maybe, GMS will use it too.

"During that period of time, my knowledge on Java was still limited also, odin's structure. I didn't managed to get through the login server due to RSA encryption of password, until then v.74 patch of MSEA's Episode 2 when z0mgn01 gave me some hints on preventing the Visual C++ exception to be thrown. That was probably when the project really started. I always like playing with new codes, API to achieve the best performance I can get with the odin source."
 
Last edited:
Re: Localhostr.dll

I don't think GMS uses RSA. The client sends a cookie generated by their webservers (asp?) and passes it right away.
Are you sending the Nexon IP in the SERVER_IP packet or your local one?
Maybe you want to send Nexon's because you hook the connect method anyways...
You guys are getting close, GL.
 
Re: Localhostr.dll

KFC said that when he hooked timing APIs they where called, I'll look into that.

Edit:

The login information uses RSA in MSEA maybe, GMS will use it too.

"During that period of time, my knowledge on Java was still limited also, odin's structure. I didn't managed to get through the login server due to RSA encryption of password, until then v.74 patch of MSEA's Episode 2 when z0mgn01 gave me some hints on preventing the Visual C++ exception to be thrown. That was probably when the project really started. I always like playing with new codes, API to achieve the best performance I can get with the odin source."


You make a mistake here.
What GMS does is read up a cookie from the Nexon website, and use that + the username in the login packet. Not only that is sent, but a check to a different server (for if the cookie did exist) is sent too, before (!) a login packet is sent to the loginserver!
MSEA and EMS uses the RSA encryption for the password, but they don't have the 'web login' system, so the normal login packet (with username and password) is sent instead of a username and cookie (sending your password will result in a 'Activate your account in 30 days' warning, which is fake).
This other server does not have any type of 'handshake' packet (thus no IV is set) and it seems to be connected to a different type of server (like HTTP or something). If you connect to the IP with a browser, you'll see a page with a string. That's all.

You could emulate that server, but I never found the encryption nor the IP in the client... It isn't the Maple Encryption, so it must be some other encryption code.
 
Re: Localhostr.dll

KFC said that when he hooked timing APIs they where called, I'll look into that.

Edit:

The login information uses RSA in MSEA maybe, GMS will use it too.

"During that period of time, my knowledge on Java was still limited also, odin's structure. I didn't managed to get through the login server due to RSA encryption of password, until then v.74 patch of MSEA's Episode 2 when z0mgn01 gave me some hints on preventing the Visual C++ exception to be thrown. That was probably when the project really started. I always like playing with new codes, API to achieve the best performance I can get with the odin source."

Yes, that's probably where you can start. I'm sure HS wasn't the cause of this because I've removed it successfully by hooking LoadLibrary on MSEA AND I could get in-game successfully with IP check terminating the client after 20 seconds.

or

163 89 0000418A getaddrinfo
51 8A 00015A3F gethostbyaddr
52 8B 000162D4 gethostbyname
57 8C 000075EB gethostname
164 8D 00007175 getnameinfo
5 8E 0001A863 getpeername
53 8F 00015719 getprotobyname
54 90 0001565C getprotobynumber
55 91 00015CD3 getservbyname
56 92 00015B71 getservbyport
6 93 00006661 getsockname
7 94 00009C32 getsockopt


Some other API you might want to try hooking.. I'm testing them right now

I've yet to fix this check =\
 
Last edited:
Re: Localhostr.dll

If we emulate the 'cookie' server and return a static cookie and then send an 'this cookie is ok' response we would get the login packet, no? It's that or removing the entire check. I did a little search for what calls MapleStory's send function and what they called, or where called by.



Isn't much, I noticed a shift left by 03, it's used in Maple Crypto but the stuff I dumped looks useless. I can't attach the god damn debugger in Windows 7.

Edit:

Has any one hooked gethostbyname? If so, what names does MapleStory lookup?
 
Last edited:
If we emulate the 'cookie' server and return a static cookie and then send an 'this cookie is ok' response we would get the login packet, no? It's that or removing the entire check. I did a little search for what calls MapleStory's send function and what they called, or where called by.



Isn't much, I noticed a shift left by 03, it's used in Maple Crypto but the stuff I dumped looks useless. I can't attach the god damn debugger in Windows 7.

Edit:

Has any one hooked gethostbyname? If so, what names does MapleStory lookup?
I will try on that once I get home, getaddrinfo doesnt seems to be the one used by Ip check.
 
Last edited:
Try inet_addr, I have my DLL setup to hook inet_addr and gethostbyname but Maple is down until tomorrow.

Hooking inet_addr is useless isn't it? You are just reassigning Nexon's IP to the client.
I've just tried hooking on inet_addr to Nexon's IP and ws2_32.connect to 127.0.0.1, it didn't disconnect me though however I'm connecting to the Nexon's server :D

Edit : nvm, my bad. I didn't notice that the .DLL is using inet_addr API too. Despite fixing this, IP check are still detecting it.
 
Last edited:
Hooking inet_addr is useless isn't it? You are just reassigning Nexon's IP to the client.
I've just tried hooking on inet_addr to Nexon's IP and ws2_32.connect to 127.0.0.1, it didn't disconnect me though however I'm connecting to the Nexon's server :D
Code:
unsigned long WINAPI inet_addrHook (const char *cp) 
{
	printf ("inet_addr called with IP: %s", cp);
	return inet_addrOrg(cp);
}
I did an inet_addr hook for Divine Souls, figured it was worth a shot here seeing as it's called a couple times on .83, not sure about .87, above is what I'm goina try to see what its connecting to and whatever, GMS is down how are you testing?!

BTW: Come on IRC i'll be on for 15 more minutes we can talk.
 
Last edited:
I'm having issues injecting in to .88. I'm injecting once I click Start Game on GameLauncher.exe, injecting to MapleStory.exe. It looks like the DLL is doing absolutely nothing though, command window won't open at all.
Code:
#include <windows.h>
#include <detours.h>
#include <stdio.h>

#pragma comment(lib, "detours.lib")
#pragma comment (lib, "ws2_32")


typedef int (WINAPI *connectTypedef) (SOCKET, sockaddr_in *, int);
connectTypedef connectOrg;

typedef struct hostent* (WINAPI *gethostbynameTypedef) (const char *);
gethostbynameTypedef gethostbynameOrg;

typedef unsigned long (WINAPI *inet_addrTypedef) (const char *);
inet_addrTypedef inet_addrOrg;


struct hostent* WINAPI gethostbynameHook(const char *name) 
{
	printf ("gethostbyname called with name as %s\n", name);
	return gethostbynameOrg(name);
}

int WINAPI connectHook (SOCKET s, sockaddr_in *addr, int len)
{
	printf ("Connecting to: %s:%u\n", inet_ntoa(addr->sin_addr), htons(addr->sin_port));
	int ret = connectOrg (s, addr, len);

	printf ("Return %i\n", ret);
	if (ret == SOCKET_ERROR)
	{
		printf ("Socket Erorr: %u\n\n", WSAGetLastError());
	}

	return ret;
}

const char *LOCALHOST = "127.0.0.1";
unsigned long WINAPI inet_addrHook (const char *cp) 
{
	printf ("inet_addr called with IP: %s\n", cp);
	return inet_addrOrg(cp);
}

BOOL WINAPI DllMain (HMODULE module, DWORD reason, LPVOID)
{
	if (reason == DLL_PROCESS_ATTACH)
	{
		DisableThreadLibraryCalls (module);
		AllocConsole();
		freopen("CONOUT$", "w", stdout);
		freopen("CONIN$",  "r", stdin);
		connectOrg = (connectTypedef)DetourFunction ((PBYTE)GetProcAddress(GetModuleHandleA("ws2_32"), "connect"), (PBYTE)connectHook);
		gethostbynameOrg = (gethostbynameTypedef)DetourFunction ((PBYTE)GetProcAddress(GetModuleHandleA("ws2_32"), "gethostbyname"), (PBYTE)gethostbynameHook);
		inet_addrOrg = (inet_addrTypedef)DetourFunction ((PBYTE)GetProcAddress(GetModuleHandleA("ws2_32"), "inet_addr"), (PBYTE)inet_addrHook);
	}
	
	return TRUE;
}

Ideas? Pretty sure something changed.
 
I don't use GameLauncher, I'm running MapleStory.exe with GameLaunching as parameter.


Look at this, the marked entry:
MangEmu - Localhostr.dll and Localhosting think tank - RaGEZONE Forums


It's probably a bug in the client where it wants to load the dll from its execution path (but why no other dll, only that one?!). What if the client really uses a COPY of ws2_32 to check if it's connected to the right place? Maybe also one of those DLLs with that strange names in system32 and HShield\\ are copies of other libraries?
 
I don't use GameLauncher, I'm running MapleStory.exe with GameLaunching as parameter.


Look at this, the marked entry:
MangEmu - Localhostr.dll and Localhosting think tank - RaGEZONE Forums


It's probably a bug in the client where it wants to load the dll from its execution path (but why no other dll, only that one?!). What if the client really uses a COPY of ws2_32 to check if it's connected to the right place? Maybe also one of those DLLs with that strange names in system32 and HShield\\ are copies of other libraries?

What're the parameters for it?
 
I would check if the dlls are packed or encrypted, if not then compare them. I'm sorry I haven't been active, I'm dealing with my emulator.

Edit: I hooked CreateFile a version or two back, I never saw anything being passed except for Themida stuff and Pipes. It might have changed, but most likely MapleStory uses a call to CopyFile.
 
Last edited:
Back