Jump to content

[GUIDE] ***Kasha Antibot ByPass***


TILEMACHOS

Recommended Posts

This is a Tutorial on how to bypass Kasha Antibot and attach L2 Walker or any other program on protected Server

 

First of all i want the Forum operators hide this post for Vip Members and donators only!!

 

This is my way and it working perfect for every server...

 

Let's Start!!  ;D

 

First of all you must have some Tools :

 

1) Hide Toolz

 

2) Proxifier

 

3) L2fork

 

Ok Now..

We need to make a second copy of Lineage client...it should look like this

 

copies.jpg

 

Next we need a clean System Folder and set the server Address inside the l2.ini file at 127.0.0.1

 

We take that Clean System and we place it at the secondary lineage client

 

systempaste.jpg

 

Then we should paste the Protected System folder that Server Provides us to the other Lineage client

 

serversystempaste.jpg

 

Your Next move now is Run and Set Proxifier!Set it like that

 

proxifiersetup.jpg

 

proxifiersetup1.jpg

 

ruleset1.jpg

 

rule2.jpg

 

You Must Put 2106,7777 on Port range for a strange check that some servers doing to block you if you are connectin via Proxy Server

 

Now Lets have some Fun

Run Hide Tools and then L2fork and press Start

Next Go again in Hide tools Window find L2Fork and left click on it and Hide it

Go to Proxifier and Disable the Rule for L2 by unchecking the rule

Next Run L2.exe from the clean Client with l2walker or what hack you want

Hide L2.exe with Hide Tools

Put your login information...Press ok and Select Bartz

Now the screen is freeze

We are going again to proxifier...Open now the rule by checking it

Now we are running L2.exe from the server we need to bot and put again your login information..press Ok until you reach the server selection menu..Now select your server and press ok.

Swicht to the first freezed client and as you can your character is appeard on this client...when you are in Lineage world close the second client...

 

Hide Tools is a clever program that make proccesses to run in stealth mode

Kasha Security module cannot find it if we run it before the l2 client...

And this will never be fixed because Fyyre has done great work on it

Kasha knows that but he can do nothing and this is good for us!!  :D :D :D

 

I have tried in the past to unpack the l2.exe that kasha made....I used ollyDgb ICE wich is undetectable but i haven't enough skills to do that...

If someone is good in unpacking he can crack in and block this stupid security module!!

Have a nice Bot Day  :D :D :D

Link to comment
Share on other sites

Mpj i Know that you are good enough ...are you the L2fork developer??  :D  ::)

 

Well i have to show you something...

 

First of all we know that Kasha malaga had a few help by Fyyre on this...here is a screenshot from an msn talk that Fyyre and Kasha had on how to make his antibot :P

 

quote-fyyre.jpg

 

Well when i first mess up with this protection it was when i was started playing on l2Dex Arion Server

L2fork helped me a lot to bot with l2net and L2walker too..but after a strong update i had the idea to use programs in stealth mode so the Security module cannot fnd them...

The Best of all is HideToolz by Fyyre...But why i choose them...???

 

Because while i was searching on how the security works i found some posts on forums that kasha was posting..

 

He talked about an exploit..it was all about hidetoolz

He admitted that if HideToolz are running before his security it is undetectable...but if you run hidetoolz after running L2 the great antibot will block them...

He tryed to solve it..and of course he asked Fyyre on how to fix it

Fyyre Answered that he just can't do nothing!!! Actually nobody can  :o

Then i tried this way..and it was working HideToolz managed to hide everything from KashaSecurity if i run them before i do anything else!!! Make sure that HideToolz are hiding itself before you start!!

It worked for me over 8 months :D :D

 

But Mpj...Do you know any good cracker that can unpack l2.exe after kasha edit?? It will be more helpfull and less boring from running all this apps

Also i know that the packers he is using is The Enigma Protector and VmProtect

 

Fyyre on this msn talk i posted admitted that he can't open the l2.exe on debugger..I managed to do it with OllyICE v1.10

Our next move is unpack and bypass  ;)

 

Link to comment
Share on other sites

I think Yes it can bypass all the protections that servers are running until today and it will be cause of the structure that l2 connects...

Let's say you wanna run with l2walker...

You must run proxifier,l2fork and l2.exe from the clean system with l2walker...then open the l2.exe with server pacht...

Did you checked with l2File edit in l2.ini of clear system the line: ServerAddr=127.0.0.1

 

Link to comment
Share on other sites

Yes of course...instead of L2fork you can use Ipjack if you have problems

You can find it on L2net forum to download it  :D :D

And of course on the clean system you can add treasure box,colored messaged or any other tweak that you like..and still stay undetectable  :o

Link to comment
Share on other sites

im not the l2fork dev, but Oddi is an editor and stlbjr is the creator... and I cannot unpack l2.exe... :/ I can hexing and small program edits is as far as I go.

Link to comment
Share on other sites

Good Morning Mpj123

Yeah Sorry Stlbjr is the creator :P

To hex edit you need to unpack it first...all kasha protected systems are heavilly packed  >:(

I ll manage to do it

Link to comment
Share on other sites

pretty good bypass thanks a lot.hoping is working for l2certus.

 

 

Question: I start the normal client with l2walker,should i hide the walker too?  /sloved

 

 

Link to comment
Share on other sites

Can you give me another help ?

When i Install lineage2.exe there is no l2.ini so i put the l2.ini from my server and change the Servadress...

when i log with the clean system i get password/login error

and sometimes i click 2x times on l2.exe and nothing happens

 

WallyLobo...to fully understand how to do it...

Plz follow bypass bakeice guide to fully understand the basics

Link to comment
Share on other sites

Glad its contribution, plus I had also posted a method to break the Kasha Malaga.

 

Below is a link to the Guide:

 

http://www.maxcheaters.com/forum/index.php?topic=162556.0

 

PS: The method is practically the same for most servers, however there are some servers that already use a more recent version of Kasha, and the method for breaking it is different.

 

Edit: I decided to take the tests here, and even opening the hidetoolz before running L2.exe protected, it is detected.

 

Kasha constantly updates the security module. The last update made by him, was my fault. As described in my guide on how to evade the Kasha, he was no option to block the connection using Process Explorer.

 

After the last update he did, I tried again, and saw it was useless to update what he did. I changed the connection method, and still remain using L2Walker and L2NET.

 

Here in Brazil I have a Forum L2Walker, and the security module also blocks my L2Walker Forum. If you're playing, and open the site on my forum, Kasha closes L2.exe

 

Soon I will post a full Guide to break this new version of Kasha.

 

 

 

Link to comment
Share on other sites

The Best we can do to avoid This protection is an opensource L2Walker or anything like...

Compile it with different name from the original...Kasha module searching for internal apllication names...

So i think this is the best way to do it..

i already try that..with l2fork...and it really worked :D

But i don't think that there's l2walker sourcecode is leaked :/

 

Ps: Try reset your computer before run hidetoolz so memory is clear and no pachted by Kasha ;)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.




×
×
  • Create New...