Patching Grand Fantasia (XLegend) IP Validation
Quick guide to bypass the IP whitelist check in WorldServer (server_006.074.64.64.tar).
Finding the Target
The Code
The Patch
At offset 0x0824FCF2, change 1 byte:
The jz only jumps to the success block if the last IP matched. Swapping it for an unconditional jmp means the flow always reaches "Service OK", skipping the retn that would otherwise reject your connection.
This should work on any XLegend binary that has the IP lock — the same logic applies to both ZoneServer and WorldServer, which are the only ones that actually need this patch.
Any questions, I'm here to help.
Quick guide to bypass the IP whitelist check in WorldServer (server_006.074.64.64.tar).
Finding the Target
- Open the binary in IDA Pro
- Open the strings window with Shift+F12
- Find Service OK and double-click it — IDA takes you to where it's defined in the data section
- Press X on the string to list all xrefs
- The xref points straight into the success block — scroll up a bit and you're inside the IP validation function
The Code
Code:
.text:0824FC9B mov dword ptr [esp], offset a113231510 ; "113.23.151.0"
.text:0824FCA2 cmp esi, eax
.text:0824FCA4 cmovz ebx, edi
.text:0824FCA7 call sub_839D460
.text:0824FCAC mov dword ptr [esp], offset a113231370 ; "113.23.137.0"
.text:0824FCB3 cmp esi, eax
.text:0824FCB5 cmovz ebx, edi
; ... (more XLegend IPs)
.text:0824FCDF mov dword ptr [esp], offset a219841680 ; "219.84.168.0"
.text:0824FCE6 cmp esi, eax
.text:0824FCE8 cmovz ebx, edi
.text:0824FCEB call sub_839D460
.text:0824FCF0 cmp esi, eax
.text:0824FCF2 jz short loc_824FD18 ; <--- PATCH HERE
.text:0824FCF4 test bl, bl
.text:0824FCF6 jnz short loc_824FD18
.text:0824FCF8 add esp, 1Ch
; ... stack cleanup ...
.text:0824FD00 retn ; <--- rejects the connection
.text:0824FD18 loc_824FD18:
.text:0824FD34 mov dword ptr [esp+4], offset aServiceOk ; "Service OK\n"
.text:0824FD3F call dword ptr [edx+10h]
.text:0824FD45 ; ... stack cleanup ...
.text:0824FD49 retn ; <--- success
The Patch
At offset 0x0824FCF2, change 1 byte:
| Bytes | |
| Original (jz) | 74 24 |
| Patched (jmp) | EB 24 |
The jz only jumps to the success block if the last IP matched. Swapping it for an unconditional jmp means the flow always reaches "Service OK", skipping the retn that would otherwise reject your connection.
This should work on any XLegend binary that has the IP lock — the same logic applies to both ZoneServer and WorldServer, which are the only ones that actually need this patch.
Any questions, I'm here to help.

