Jump to content

[Aion ] Anti-Debugger


D4rkAngeL666

Recommended Posts

Dunno if this was already posted, of still work since I got few minutes to stay in nfront of pc I dont got time to test again.

 

well here we go.

 

Even though Gameguard has been removed from Aion's launch, some parts of its protection remain. For instance, when you try to run OllyDbg, Aion immediately exits. This guide will demonstrate one simple way to prevent that from happening. Ultimately, I aim to also remove Aion's anti-breakpoint code and all other anti-debugging code.

 

This guide assumes that you have the following software:

 

    * OllyDbg

    * AionPauser (written by myself in C# download binary+source)

 

 

Without further ado...

 

Step 1 -

Run Aion and (preferably) wait until you get to the login screen.

 

Step 2 -

Run AionPauser.exe and press space or otherwise suspend all of Aion's threads. This works because Aion's anti-cheat code runs entirely within its own process. Suspending all threads ensures that Aion can do _not shit_ against us. Leave AionPauser running - you will need it later to resume.

 

Step 3 -

Run OllyDbg, attach to Aion's process (default is AION.bin.) You will get messages informing you that AION.bin, CrySyste.dll, and Game.dll are packed. Just hit OK for all of them. Now, feel mildly satisfied that Aion hasn't shut down while OllyDbg is running and attached. Of course, Aion is still paused and we can't learn much from debugging a paused process! If we were to unpause now, Aion would almost immediately notice OllyDbg and shut down as before.

 

Interjection -

Now, thinking time. How was Aion detecting OllyDbg? It turns out that it uses several really, really commonplace and well-documented methods. One of which is the dumb-shit Win32 API, IsDebuggerPresent. So let's set a breakpoint on that API.

 

Step 4 -

Pressing CTRL+G in OllyDbg will open up the "Enter expression to follow" window. Type "IsDebuggerPresent" and hit enter. Press F2 to set a breakpoint on the function address that you jump to.

 

Step 5 -

Resume all threads by hitting space in AionPauser. Press F9 in OllyDbg to allow Aion to run. Smile as OllyDbg catches the IsDebuggerPresent breakpoint shortly after resuming.

 

Step 6 -

In the title bar of OllyDbg's CPU/debugging window (i.e. NOT OllyDbg's main window), you will see what thread IsDebuggerPresent was called on. Select View>Threads and _KILL_ the thread that was calling IsDebuggerPresent. By doing so, we've terminated the thread that was running anti-debugger code.

 

Conclusion -

Now Aion is running while OllyDbg is attached! Sadly, if you set a breakpoint, and the breakpoint is caught, Aion will crash.

 

ALL:

 

    * Reverse the anti-breakpoint code

    * Automate everything

 

 

this info was posted by Guturrul

Link to comment
Share on other sites

  • 8 months later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Posts

    • https://maxcheaters.com/topic/223806-driver-service-for-all-servers-reborndionclub-and-more/
    • L2RAPTOR continues to grow!! We have players and clans from Europe, South America, Russia, and Ukraine. Come join us! Server will stay open minimum 1 year!
    • Greetings, dear friends Today, I’d like to tell you a little story. It’s a story of how we constantly innovate, while other admins are just copying what we do without any inspiration. It’s a desperate cry from others to stay relevant when we put our on the table (you read that, I didn’t say it). You will see this happening again with our new server. You will start seeing lots of servers start working on implementing their own version AI players when our server starts getting attention. It’s not that we are ahead of our times, it’s that other servers don’t give a shit, they just want your wallet. Why are you still playing on scam servers? I’ve said it 10k times already. We do the work we believe is best instead of scrambling up random average features to bait people into joining a boring but profitable server. We want an extremely transparent, fair, and fun server because it’s also going to be extremely profitable and satisfying. Reject scam servers, join legit servers. Here’s a list of legit servers: L2Aqua If you want your server added to the list, let me know. If you want me to create a new voting site where we only accept legit servers, let me know. Here’s a list of everything servers have copied from us over the years Our old friend nuked our database and made his own server, web, and client from our own effort. We’ve reworked our client, web, and server since - while it seems that this other project is stuck in the past. Servers are using our old clients with all our skins, armors, animations, etc. They won’t fix the very obvious client bugs we’ve long fixed Servers ripped up Hubris interface which he made from 0 and copied and shared components even when he has released a public code for the interface Some servers even had the audacity to ask us for help on how to adapt it for their own server Lots of Skins stuff, like Twitch Cloak (I made it myself back when there were only a few L2 streamers around), Pandemonium armor, Paragon armor, Phase armor, Vesper Noble Weapons, Lava Weapons, Devil Weapons , basically everything… Can you imagine how lame you have to be to be using Devil weapons on a server that’s not L2Devil and not even renaming them? Basically our whole work which we did from 0 over all these years is shared around the internet. Have fun if you find it, go on and use it! Just… don’t ask us for support? If you gave credit I’d actually respect you more. Now, these are kind of easy to see. You make a cool weapon, I copypaste the weapon into my own client, and I now have the weapon too, yay! Thank you for your hard work! What’s not so easy to see is how we set the standards in the scene and later people adapt to us. We created the standard: Buffs amount, Buffs in the NPC Buffer, Item prices, Items in the GM Shop, Steal not overbuffing, Cancel returning buffs, automatic potions, you think about it, there’s a chance we did it first and people adapted. Get ready because it’s coming. Once the server starts skyrocketing in population, scam admins are going to scramble for their own barely functional version of AI Players! I’m calling it now because it’s fun to brag about later Even the description isn’t safe One of the things that I never understood is why are other servers copying our server description? Like, is it our server too? It first started happening with L2Aeron a long time ago, when I standardized how server descriptions should be formatted, and people copied the format. But this is on another level.           Can you be less imaginative and creative than that? We’ve already even changed our web, your web is outdated! Let’s see how much time before they adapt to our web’s changes. I don’t mind, do whatever, I just think it’s sad that you have no original thoughts to offer to your community. How many days before admins start posting daily with cool images? We’re flattered by the imitation, but remember that copying us can never replicate the heart and soul of our server. Our community is unique, and it’s built on the trust we share. Good luck creating trust copying others. So, when you see imitations, take pride in the fact that they’re inspired by the best. We’ll keep innovating and leading the way, setting standards for others to follow. Soon there will be more legit servers than scam servers. Watch us closely transform the Lineage 2 Scene with our success. We want everyone to copy our values. We want a better Lineage 2 Private Servers scene. Thank you for being a part of our extraordinary community.
    • Greetings, dear friends   Just passing by to show you this gem.   I've written these words on my webpage. Scam servers are using it as their server description.   It's not just ONE server! It's more and more servers copying.   Can we please stop supporting scam servers? Thank you!  
    • i dont understand the part with skill 7030 as the skill in config is 2046 why we put the parameter isagathion in 7030 skill id?  
  • Topics

×
×
  • Create New...

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock