Jump to content

New Private Server AntiBot System


l33ts

Recommended Posts

Hi, on this weekend a lot of private servers changed its old antibot system (la2.gr, Roxy, L2Dex ...)

 

There are some new dll & files in this patch windrv.dll, unbot.dll, hguard.dll & more.

 

I've been seeing packets with a own made sniffer, and aparently they seem to be normal l2 encripted packets, two bytes with packet length and the rest of bytes encripted with blowfish. But whit the token obtained from the client (Token in memory of l2.exe process) they cant be decoded, and also the packet chechsum fails.

 

I think they have changed the client/server encription method, or the token offset in memory. Also they now prevent the exe to be inyected/loaded.

 

I dont have enought reverse reverse engineer/cracking exp to debug the process and see how the client is coding now the packets, but i would be able to make a l2walker pasarell for the new crypt method.

 

Thx.

 

 

Link to comment
Share on other sites

well, if the blowfish/packets haven't changed then rebuilding the system folder with the token should work... I have no idea how to do that but if ever you go on a server building forum and search arround you could maybe find some information.

Link to comment
Share on other sites

i think that

loader scans if you run any bot and blocks login

if you dont run anything it unblocks login

by default l2.exe is locked and when you run loader without bot it lets you log in

simple isnt it?

Link to comment
Share on other sites

Its not in that way exactly, the loader looks for a l2walker.exe process in memory if found it connect to an antibot server and logs you.

 

The loader also seem to override some lineage crypt functions or crypt/hide the token, whit a captured login (a valid packet) packet and the debuger running, as you can see in the image the token is _;5.]94-31==-%xT!^[$, but isnt it.

 

dbg543hz0.th.jpg

 

So... we need a cracker :P

 

 

Link to comment
Share on other sites

well i checked into this because i was a little curious myself... but this antibot system is simple... its adding extra encryption to sent packets, it hooks winsock, hooks ws2_32.connect for god knows what purpose... need to look into it, and hooks ws2_32.send to encrypt the packets before they are sent to the server, this looks like its only on authd packets... hlapex wont work because it happens to hook ws2_32.connect also -.-

 

untitled4ny1.jpg

^ ws2_32.connect/send

Link to comment
Share on other sites

i doubt it, if it was made by the maker of hlapex it wouldnt be on GREEK servers + their friends... my guess is that Dex were the ones that either made it or bought it, and then demon (la2.gr) bought it from them

Link to comment
Share on other sites

  • 2 weeks later...

k ... I managed to connect with ig bot ... its able to read information like map ...

bot not verified ... so im just able to use the information functions and scripts.

 

btw anyone knows how to craft with a script using the recipe book ?

Link to comment
Share on other sites

there is another problem ... you get disconnected every once in a while. So there seem to be more than just the auth package that differ. You just cant move or write or open inventory ... but u can see others move and write. weired situation.

Link to comment
Share on other sites

xift i had the problem u talk about with l2 client from c2 to c4. I believe it's a bug from nvidia onboard networkcard. If u have nforce that may be the reason not walker. I've upgraded drivers and dont get it anymore. (still think demonas is admin on la2.gr here to spy for antibot upgrades :D)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



  • Posts

    • Hi, my client version is Classic Kamael.   I build up the story line gradually with the option to turn different parts of the story on and off.   I mean you start a server and you only have The Kamael classic. As an admin, you will be able to gradually enable additional zones, RBs, items, instances, etc. through configs, up to Hi5 (I only have hi5 for now). Sometime in the future I want to add the GoD stuff as well because the new RB is strong and the regular S grade stuff is weak. Of course, there are some limitations of the game client, which I will not remove yet.   For example, I couldn't put Rafforty NPC on hi5 position because you can't get it here and there in the Classic client, so I put it on others.   It's a change that I like.   I'm most looking forward to coming up with zones, quests and instances for Gracia.
    • Hello. If you are looking for a reliable writing company that can provide a high level of service and high quality writing, then I recommend you to visit Essay Pro review https://nocramming.com/essaypro-review, where you can make sure for yourself that this company can be the best assistant in your difficult studies. The company's review is objective and easy to understand, which will help any user to quickly understand the information.
    • Why not making hi5 files to support login/play at the client and only make some client parts for the rest? Isnt it more easy?
    • Powerful Spells Caster & Spiritual Healer Web: lovespellsafrika.com Phone: +27780802727 WhatsApp +27789121499 Email: bbaantu@gmail.com Real Magic Spells | How To Get Back Ex-Boyfriend or Ex-Girlfriend. Real Magic Spells for all purpose; Now you can benefit through the use of spells like Love Spells, Money Spells, Talismans, Charms, Prayers, Curses and Chants. Magic Spells can be spell cast for many purposes. Talismans and Charms work as powerful Ingredients. If you need any spiritual knowledge on the power of Spells and Magic you can always Powerful Magic Rings Love Spells                     Casting of Simple and Effective Love Spells Easy Love Spells Spells for Attraction between two Lovers Binding Love Spells Get back Lost Lover Spells Spells to Strengthen Love Relation Lost Love Spells Soul Mate Spells Marriage Spell for a happy Married Life. Retrieve a Lost Love Spells Bring Back Your Love Spells Gay Love Spells, Lesbian Love Spells Anti-Love Spells, Divorce Spells, Break up Spells How to Get Back Ex-Boyfriend, or Ex-Girlfriend Casting Spells to Get Rid of Your Husband, Wife or Partner without Fights or them hating you Magic Rings, Powerful Love Rings Spells to stop a divorce Voodoo Spells for Love Love Return Spells Money & Prosperity Spells Phone: +27780802727 WhatsApp +27789121499 How to Cast Magic Money Spells Lottery Spells or Lotto Spells Voodoo Spells for Money Black Magic Spell for Money Protection & Banishing Spells Black Magic Spells and Curses to Destroy Enemy or Evil People Protection from Black Magic Spells and Curses Dark Magic Spells Voodoo Spells for Revenge Spells to win court cases &legal matters Healing spells for all purpose Stroke Diabetics Lottery Spells Phone: +27780802727 WhatsApp: +27789121499 Web: lovespellsafrika.com
  • Topics

×
×
  • Create New...