Jump to content

Recommended Posts

Posted

Well you cannot modify l2.bin without unpacking but its not needed to unpack it. You are writing a bot, not some crack so packer means literally ntohing because u focus on runtime.

 

By the way, what do you want to achieve in the end?

 

Im interested  because I want to learn RE, RPM/WPM, and maybe later packet analysis.. I tried with Lena's tutorials but they seem so outdated and i lost my motivation after awhile. I know a bit C#, I already managed to create a console application which reads bytes that i need from memory, but this is so easy/basic compared to RE and Hooking :P

 

So basically,

you inject your dll in l2.bin -> 

using faction GetModuleHandle to retrive gameguard.des ->

Then im loosing it a bit because IDA - DeAssembly uses a fuction qmemcpy which I have no idea what it is..

 

Its something like that in my mind inject -> getmodulehandle -> getprocaddress -> virtualprotect

 

Sorry if I said something stupid (probably I did) but everything is so messy in my head.. :P

Posted (edited)

well lenas tutorials are great for beginners. You have to get used to clean compiled code and go with small steps... i remember how o started i had to go through every tut like 5 times because i did not understand anything. If you are gettin headache from clean compiled code then tell me what do you see here

 

 

 

EHP8yRT.png

 

 

 

 

Do you see whats goin on here? XD

 

And to answer

 


Its something like that in my mind inject -> getmodulehandle -> getprocaddress -> virtualprotect

 

 

There are tons of ways to prevent dll injection. Do you know what exactly happens when you are loading the dll? Dont use getprocaddress. lameguard = insta ban, smartguard = insta ban.  And virtualprotect on sg = ban also.

 

How do i know that?

Edited by Szakalaka
Posted (edited)

It looks like virtualized to me lol. Anyway, thanks alot for your time. I thought anti-cheats wouldn't be so complex but im totally wrong. I'll start again with Lena's Tutorials :)

 

Do you think C# is viable for patching ? 

Edited by fxb0t
Posted (edited)

a lot of knowledge but im on mechanical engineer...

 

Szaka, with cliext 1.0.0.9 there is any solution? for 1.0.0.6 i just use injector with tower dll, but now i cant inject without kick in few minutes.(or in char select)

with the old suspent methots i cant do it.  (now i have anti cheat .exe)

 

with adr 1.71 the client just shut down or get disconnect on char select.

 

http://i.imgur.com/Hvusvoa.png

 

 

 

 

 
Edited by mariuda
Posted

@Szakalaka

Maybe You have something to "scam" lameguard and run more clients? For example 9 at l2tales?

 

I know there is sandboxie, virtual machines, but need 2 adrenaline keys for that:/

Posted

@Szakalaka

Maybe You have something to "scam" lameguard and run more clients? For example 9 at l2tales?

 

I know there is sandboxie, virtual machines, but need 2 adrenaline keys for that:/

at mxc is shared mac id changer for tales 

Posted

AchYlek You mean Stergios hwid changer? It need 2 Cards or Card + WiFi. And it change PC name, so my windows 10 is getting lost, and asking me for active everytime i change it this way.

I can pay for something like .dll that will do it when i run L2, or any other tool that wont affect Windows activation etc.

Posted

does this bypass work on L2 averia 10x?

suspend game at char select, kick dsetups and inject tower, but sometimes u will get error when your window is unactive, for that pm szakalaka 

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.




  • Posts

    • What webhosting are you using? You'll need to talk with administrators of the webhosting to open outgoing connections to port 1433, maybe they won't open it for you, instead, you should get a webhosting for mu online since they always have 1433 port open for outgoing connections. Also, make sure you have your 1433 TCP port open for incoming connections, for security, I suggest you exclusively add the cPanel IP Address to connect to your port 1433 in your firewall, so no one else can try to connect to your database. Let me know if you have any questions, happy to help.
    • He just doesn't answer, I've tried everything, Telegram, his own forum, everything, I don't know what's his deal, but I've tried for months
    • Send direct message to @Maxtor
    • Hello guys , does anyone know what files needed to use those cloaks for H5 client? I’m not using an interface and I don’t want to use one so there are any way to use them without interface? 
    • Closed beta testing starts in early October!        We’re looking for the most active and attentive players to help fine-tune the project before launch. This is your chance to be among the first to try out our new features and directly influence how the server develops.   What beta testers will do: — Check the client and core mechanics — Find bugs, errors, and inconsistencies — Evaluate the convenience and practicality of current solutions — Share detailed, constructive suggestions for improvement      Your feedback will be key to making the project balanced and comfortable for everyone.   Requirements: — Willingness to complete specific tasks — Experience playing on Interlude (PTS, clean client) — Experience with the HF client is a plus   Ready to help? The server launch is planned for early December, so now is the perfect time to join the test and make your contribution. To participate, you must send a direct message (DM) to one of the following: - Send a DM to our Telegram channel - Send a DM to our forum moderators: PrintF or EchØ - Send a DM to our Discord server admin @EchØ
  • Topics

×
×
  • Create New...

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock