Ohka BOTS!! Reverse Engineering

Newbie Spellweaver
Joined
Sep 3, 2013
Messages
29
Reaction score
15
BOTS!! (Acclaim) — "Bout Evolution" Server, Overhauled for the Ohka Client

TL;DR
Took the old 2009 "Bout Evolution" Java/MySQL emulator and rebuilt large parts of it from scratch so it works with the Ohka client (the unprotected 2008-era client rip the private-server scene already circulates — the original Acclaim retail client is a dead end thanks to GameGuard + ASProtect stacked together). Full attached zip: source code, compiled jars, DB install script, and a 300-line technical log of every bug found and fixed.

Login → lobby → character creation → room creation → matches with real combat → boss mechanics → victory/defeat → XP/leveling → item drops → full shop (buy/sell/equip, gigas AND coin currency) all work end to end right now.

Why this took as long as it did
The 2009 source assumes the original 2007 client. The Ohka client speaks a meaningfully different dialect of the same protocol, and there is no documentation for any of it — no packet list, no field layout, nothing. Every fix in this release came from the same loop, repeated dozens of times over one very long session:

  1. Run a transparent TCP/UDP proxy between the real Ohka client and the actual live BOTS server, log every byte in both directions.
  2. Reproduce the same action against our emulator, diff the two captures byte-by-byte.
  3. Find the field that's wrong, missing, or extra. Patch it. Repeat.

That method is the only reason any of this works, because guessing consistently failed — three separate times a "looks right" fix caused a WORSE bug (a client crash where there'd only been a soft freeze, or silent data corruption) until the next real capture proved the actual mechanism. A few of the uglier problems that ate hours each:

  • The session model is IP-based with no token. The channel server picks whichever account row has a matching `current_ip`. Two accounts logging in from the same IP (i.e. any local test setup with 2 characters) silently hijacks the first account's session. Fixed by clearing `current_ip` on disconnect + `ORDER BY lastlogin DESC` as a tiebreaker.
  • All item prices in the shipped item DB are exactly 10x too high. 100% of the `coins` column and ~94% of `buy`/`sell` were multiples of 10 — a dead giveaway of an import gone wrong somewhere upstream. Client shows 220, server was charging 2200.
  • The end-of-stage packet (`0x1F2F`) carries a field that's tied to which dungeon you're in (`offset+118 = dungeonIndex + 8`). Get it wrong and the client silently REJECTS the result packet and shows DEFEAT — even with the map 100% cleared. This one took several rounds of "why does a perfect capture-matched packet still lose the match."
  • Victory/defeat has nothing to do with any flag in the result packet. The client tracks its own live monster count. If anything is still alive when the result arrives, it's a loss, full stop — no exceptions, no "kill the boss and it's an auto-win." Real captures proved boss kills DO chain-kill certain structure-type monsters (confirming what a very patient tester kept insisting was true), but only after a specific "gatekeeper" monster dies and triggers a burst packet.
  • Maps come in pairs that share the same underlying dungeon/monster-roster (`dungeonIndex = ((mapId-3)/2)*2`), each with its own monster count and its own gatekeeper type. There is no monster-count table anywhere in the client's files that's readable — tried the dungeon catalog binary, the monster-AI binary, positional matching by coordinates, byte-signature scanning across 2,300+ client files. Nothing decodes cleanly; it's a raw memory-dump format with pointers, not a serialization format.

Since that last one couldn't be reverse-engineered from static files, the server now learns dungeons automatically at runtime — first clear of any new map pair triggers an idle-timeout fallback (server sends the unlock burst after ~15s of no kills, then locks in the exact monster count once you finish), and writes it to a plain-text `dungeons.txt` that persists across restarts. Every dungeon after the first clear resolves instantly, same as the ones already mapped by hand from real captures.

What's confirmed working
  • Login, lobby (rooms, chat, character list) — fully interactive
  • Character creation & selection
  • Room creation, joining, map selection
  • Live combat: monster kills, boss/gatekeeper mechanics, chain-kill on structure monsters
  • Match completion with the real result screen (proper timing: ~5.2s after last kill, 6.0s hold, then return to lobby) — both VICTORY and the correct visual
  • XP + leveling curve, calibrated so lvl 5 ≈ 2 stages, lvl 10 ≈ 9, lvl 20 ≈ 67
  • Item drops as a physical box on the ground (not just a backend inventory add — proper pickup packet + visual)
  • Full shop: buy with gigas, buy with coins, sell, equip/unequip across every gear category (head/body/arm, minibot/gun/efield/wing/shield/gear, skills/pack, coin slots)
  • Server-learned dungeon table — currently covers 4 dungeon pairs (8 maps) out of a possible ~30+, growing every time someone plays a new one

Known gaps / good places to contribute
  • ~60 of the ~88 map slots have no learned monster-count yet — auto-learns on first real clear, no code changes needed, just play them
  • No level-up visual effect (which packet/field triggers it is still unidentified)
  • No consumable-item stacking (needs new qty/flag columns in the inventory table — schema change, not wired up)
  • ~67% of item names in the DB dump are garbled (wrong text encoding on import, cosmetic only)
  • 385 items have no defined price and are intentionally left unpurchasable
  • The room-creation packet (`0xEE2E`) is still a hardcoded replay from a captured real session (works, but ships another server's room ID and a couple of stray chat strings baked in — cosmetic, not a bug)

Requirements
  • JDK 8 (the source compiles as Java 1.6 target — `javac -source 1.6 -target 1.6`)
  • MySQL or MariaDB (tested on MariaDB 10.11)
  • The Ohka client (the unprotected 2008-engine client already floating around this scene). Point its `patch.ini` at `127.0.0.1`.

Setup guide
  1. Database: create a MySQL/MariaDB instance, then run `install.sql` — it creates the `bout_evolution` DB, all tables, unique indexes (username/charname), and a `test/test` account to log in with immediately.
  2. DB credentials: edit `dev-login/configs/mysql.conf` and `dev-channel/configs/mysql.conf` (both need to point at the same DB — they share tables like `rooms` and `bout_users`).
  3. Firewall: run `0-AbrirFirewall.bat` as Administrator once — opens TCP 11000/11102 and UDP 11010/11011.
  4. Start the servers: run `1-LoginServer.bat` then `2-ChannelGameServer.bat` (both need to stay open — they log everything to `logs/protocol.log` in each folder if you need to debug).
  5. Point the client: the Ohka client's `patch.ini` needs `ip=127.0.0.1` under both `[login]` and `[channel]` — a ready-made copy is included as `patch.ini.localhost`.
  6. Play: launch `ohka_game.exe` (or use `3-Cliente.bat` if your client is at `D:\Ohka BOTS`, adjust the path otherwise), log in with `test`/`test`, and go.
If anything breaks, `4-Rebuild.bat` recompiles both servers from source (needs JDK 8 on PATH or edit the script's JDK path) — always start from source if the prebuilt jars behave oddly, they may be stale relative to `src/`.

In the zip
  • Full Java source for both servers (`dev-login/src`, `dev-channel/src`)
  • Precompiled `.jar`s, ready to run
  • `install.sql` — full item database (2650 items) + schema
  • `PROTOCOLO-OHKA.md` — packet-by-packet protocol reference (~85 client commands mapped)
  • `dev-notes/REVERSE-ENGINEERING-NOTES.md` — the full raw dev log this whole project came out of: every bug, every dead end, every byte offset, in the order it was actually discovered. If you're going to extend this, read that file first — it'll save you from re-discovering the same three refuted theories about how monster kills work that I had to burn real time ruling out.

Everything here builds on the original leaked "Bout Evolution" (2009, credited to TokXilChaosZ + Auron3) server source that's already circulated on this forum — this is that codebase upgraded to speak the modern Ohka client's protocol, with the shop/combat/progression systems that were previously non-functional now working end to end.

Have at it — would genuinely love to see someone pick up the remaining ~60 unmapped stages, or dig into the level-up visual / item-stacking gaps. Questions welcome, I'll check back on this thread.
 

Attachments

Last edited:
Salve mano from uruguay! I don't know why, but I searched for this old game I remember playing back in my childhood and I can't believe I found you! I used to play this a lot but stopped completely when acclaim servers went offline, and I was never interested in private servers. Reading through the notes as someone who doesn't know about bots history is fascinating, you are basically doing what TokXilChaosZ & Auron3 did to acclaim servers, but with Claude, and to a private server right?. I will test this soon, amazing work and I hope you keep us updating on the progress!
 
It does worth the work, no one want to play this game anymore. unfortunately.
did you shut the project down then? and the large private servers are dead because the people that run them 9./10 times are not all there in the head, they are balistic
 
Yeah I'm not working in the revervse eng anymore haha
I believe a Browser version could make more succsess!
But I couldn't make it good, however I didn't try Opus 5.5, It should do the job if you're willing to spend money on it.
 
Back