Jump to content

Recommended Posts

Posted

Hi, on this weekend a lot of private servers changed its old antibot system (la2.gr, Roxy, L2Dex ...)

 

There are some new dll & files in this patch windrv.dll, unbot.dll, hguard.dll & more.

 

I've been seeing packets with a own made sniffer, and aparently they seem to be normal l2 encripted packets, two bytes with packet length and the rest of bytes encripted with blowfish. But whit the token obtained from the client (Token in memory of l2.exe process) they cant be decoded, and also the packet chechsum fails.

 

I think they have changed the client/server encription method, or the token offset in memory. Also they now prevent the exe to be inyected/loaded.

 

I dont have enought reverse reverse engineer/cracking exp to debug the process and see how the client is coding now the packets, but i would be able to make a l2walker pasarell for the new crypt method.

 

Thx.

 

 

Posted

well, if the blowfish/packets haven't changed then rebuilding the system folder with the token should work... I have no idea how to do that but if ever you go on a server building forum and search arround you could maybe find some information.

Posted

i think that

loader scans if you run any bot and blocks login

if you dont run anything it unblocks login

by default l2.exe is locked and when you run loader without bot it lets you log in

simple isnt it?

Posted

Its not in that way exactly, the loader looks for a l2walker.exe process in memory if found it connect to an antibot server and logs you.

 

The loader also seem to override some lineage crypt functions or crypt/hide the token, whit a captured login (a valid packet) packet and the debuger running, as you can see in the image the token is _;5.]94-31==-%xT!^[$, but isnt it.

 

dbg543hz0.th.jpg

 

So... we need a cracker :P

 

 

Posted

well i checked into this because i was a little curious myself... but this antibot system is simple... its adding extra encryption to sent packets, it hooks winsock, hooks ws2_32.connect for god knows what purpose... need to look into it, and hooks ws2_32.send to encrypt the packets before they are sent to the server, this looks like its only on authd packets... hlapex wont work because it happens to hook ws2_32.connect also -.-

 

untitled4ny1.jpg

^ ws2_32.connect/send

Posted

i doubt it, if it was made by the maker of hlapex it wouldnt be on GREEK servers + their friends... my guess is that Dex were the ones that either made it or bought it, and then demon (la2.gr) bought it from them

  • 2 weeks later...
Posted

k ... I managed to connect with ig bot ... its able to read information like map ...

bot not verified ... so im just able to use the information functions and scripts.

 

btw anyone knows how to craft with a script using the recipe book ?

Posted

there is another problem ... you get disconnected every once in a while. So there seem to be more than just the auth package that differ. You just cant move or write or open inventory ... but u can see others move and write. weired situation.

Posted

xift i had the problem u talk about with l2 client from c2 to c4. I believe it's a bug from nvidia onboard networkcard. If u have nforce that may be the reason not walker. I've upgraded drivers and dont get it anymore. (still think demonas is admin on la2.gr here to spy for antibot upgrades :D)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • ## [1.4.0] - 2026-01-28   ### ✨ New Features - **Vote System**: Lineage 2 servers can now use our vote–reward system. Players vote on the website and claim rewards in-game (1 vote = 1 claim) - **Vote Page**: On each server’s page (`/servers/<server>`), a **“Vote for Server”** button opens a dedicated vote page with cooldown info and optional Turnstile verification - **By Votes View**: The **“By Votes”** tab on the main page shows **actual vote counts** per server - **API Documentation**: New **API Docs** page at `/docs` (and footer link) with HMAC auth, endpoints, and examples for game server integration - **Vote API (My Servers)**: Server owners can open **“Vote API”** in My Servers to manage credentials, cooldown, allowed IPs, and open the docs   ### 🔄 Improvements - **Server Pages**: Single-server data is cached and loads faster; server pages can be opened by ID or by name (e.g. `/servers/my-server-name`) - **API Root**: Visiting the API root redirects to the docs URL configured in admin (default: site docs page) - **Admin Panel**: New **“Vote System”** tab for global settings (Turnstile, API security, default cooldown, docs URL)   ### 🔐 Security & Reliability - Turnstile (CAPTCHA) support for vote submissions to reduce abuse - HMAC-protected game server API for secure vote check/claim and stats
    • "I recently purchased the account panel from this developer and wanted to leave a positive review.   The transaction was smooth, and the developer demonstrated exceptional professionalism throughout the process.   What truly sets them apart is their outstanding post-sale support. They are responsive, patient, and genuinely helpful when addressing questions or issues. It's clear they care about their customers' experience beyond just the initial sale.   I am thoroughly satisfied and grateful for the service. This is a trustworthy seller who provides real value through both a quality product and reliable support. 100% recommended."
    • Server owners, Top.MaxCheaters.com is now live and accepting Lineage 2 server listings. There is no voting, no rankings manipulation, and no paid advantages. Visibility is clean and equal, and early listings naturally appear at the top while the platform grows. If your server is active, it should already be listed. Submit here https://Top.MaxCheaters.com This platform is part of the MaxCheaters.com network and is being built as a long-term reference point for the Lineage 2 community. — MaxCheaters.com Team
    • ⚙️ General Changed “No Carrier” title to “Disconnected” to avoid confusion after abnormal DC. On-screen Clan War kill notifications will no longer appear during Sieges, Epics, or Events. Bladedancer or SwordSinger classes can now log in even when Max Clients (2) is reached, you cannot have both at the same time. The max is 3 clients. Duels will now be aborted if a monster aggros players during a duel (retail-like behavior). Players can no longer send party requests to blocked players (retail-like). Fixed Researcher Euclie NPC dialogue HTML error. Changed Clan leave/kick penalty from 12 hours to 3 hours. 🧙 Skills Adjusted Decrease Atk. Spd. & Decrease Speed land rates in Varka & FoG. Fixed augmented weapons not getting cooldown when entering Olympiad. 🎉 Events New Team vs Team map added. New Save the King map added (old TvT map). Mounts disabled during Events. Letter Collector Event enabled Monsters drop letters until Feb. 13th Louie the Cat in Giran until Feb. 16th Inventory slots +10 during event period 📜 Quests Fixed “Possessor of a Precious Soul Part 1” rare stuck issue when exceeding max quest items. Fixed Seven Signs applying Strife buff/debuff every Monday until restart. 🏆 Milestones New milestone: “Defeat 700 Monsters in Varka” 🎁 Rewards: 200 Varka’s Mane + Daily Coin 🌍 NEW EXP Bonus Zones Hot Springs added Varka Silenos added (hidden spots excluded) As always, thank you for your support! L2Elixir keeps evolving, improving, and growing every day 💙   Website: https://l2elixir.org/ Discord: https://discord.gg/5ydPHvhbxs
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..