QuestionHelpCreating own Login-Token (new as of patch 1.3.3.0)

Posts 1–5 of 5 · Page 1 of 1
Creating own Login-Token (new as of patch 1.3.3.0)
Deca did change the way the game is started with the Patch 1.3.3.0, it used to be like this:
Code:
"C:\Users\Maik8\Documents\RealmOfTheMadGod\Production\RotMG Exalt.exe" "data:{
platform:Deca,
password:passwordAsBase64Here,
guid:emailAsBase64Here,
env:4
}"


platform is just a static parameter
password is just the base64 encoded password of the account
guid is the same for the email
env:4 is aswell static
And from what I can see, it is now like this:
Code:
"C:\Users\Maik8\Documents\RealmOfTheMadGod\Production\RotMG Exalt.exe" data:{
platform:Deca,
guid:emailAsBase64Here,
token:WndtQk1pQ0NGNytweGxSTnM2d1hsQ3JITnRNYkpaeVliTasZGh0dk5LYzNtcVNQWU1FS0FRMDNzVFdCS1ZmR0F4WTd3awncjJ5MFFOVzNJekFyeHk0Yytus1E1c1FNZmdBU3BzcnREPLACED_STUFF_HEREYzNFcxakRjbzViWnpjY0dpZGF1TXlmdXBQakRkaFhMSktTcDlrWmZnelo5bGZXUXdicUdXeVdCUkdSeTEzbnNsYkQyM3ppMXc3a28zQ21TeGRFVlpkQWNncnE5SlNVSlF6L2RobTcvcWQ0QUpXSlpdasdddnZxMzFwTkRwZVhVR3dEbVlWNEtIWU9BPT1=,
tokenTimestamp:MTYxNDcxNzg4Mw==,
tokenExpiration:MTMwMDAwMA==,
env:4}


platform is static again
guid is the same as in the old version, just base64 encoded
token seems to be the new password parameter
tokenTimestamp is the timestamp of the token creation as unix in base64 
tokenExpiration does not make much sense here as it's value is 1300000 (Jan 16 1970)
My guess: adding both together (timestamp and expiration) gives me a date in 15 days, wich seems okay.
env:4 is aswell static
I now need to find a way to create this tokens myself.
I have no idea what this token could be, probably some sort of hash?
It's not MD5, SHA1 or Bcrypt as far as I can tell.

I tried to decompile the launcher, but it is written in C++ - wich won't be of much help because of that.

Any help will be appreciated!

PS: If you want to help and find a way to get your token, just start an exalt instance via the original launcher and use a tool called "Processexplorer" (by Microsoft), find your Instance and go to properties, there you will find it ("Image" -> Command line ).
Hey chief, that token is received by the client through account/verify, the web request for logging in along with the other data. The timestamp is in unix time and seconds, as well as the expiration being how many seconds till it expires (its like 15 days). Just make sure to base64 the token, the timestamp and expiration when passing it through to exalt. Also now they send on account/verify + some other web request a new field called "clientToken" which is your devices unique identifier, a HWID basically so make sure to rebuild that or make both your tool and exalt have the same one. If you wanna see how Deca puts together all the launch params on the launcher, here is the reversed version https://pastebin.com/nFBdE29Q
/account/verify request returns token

edit: DIA4A posted answer literally 5 seconds before me. hes got better explanation, sorry
this Powershell snippet might help you on your journey:

$guid = YOUREMAIL
$password = YOURPASSWORD
$clientToken = D22fb7333aaf110b2e87f031c5b28d20112ee6c3
$ExaltExePath = "C:\Users\WHATEVER\Documents\RealmOfTheMadGod\Produ ction\RotMG Exalt.exe"
$encodedguid = [Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes($guid))


$bodyverify = @{
guid = $guid
password = $password
clientToken = $clientToken
game_net = 'Unity'
play_platform = 'Unity'
game_net_user_id = ''
}

$headerverify = @{
"Accept" = '*/*'
"Accept-Encoding" = 'identity'
"Content-Type" = 'application/x-www-form-urlencoded'
"User-Agent" = 'UnityPlayer/2019.3.14f1 (UnityWebRequest/1.0, libcurl/7.52.0-DEV)'
}


[xml]$accountinfo = Invoke-RestMethod -Uri "https://www.realmofthemadgod.com/account/verify" -Method 'Post' -Body $bodyverify -Headers $headerverify
$accounttoken = $accountinfo.Account.AccessToken
$tokenExpiration = $accountinfo.Account.tokenExpiration
$tokenTimestamp = $accountinfo.Account.tokenTimestamp
$tokenExpirationencrypted = [Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes($tokenExpiration))
$tokenTimestampencrypted = [Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes($tokenTimestamp))


$bodylogin = @{
do_login = 'true'
accessToken = $accounttoken
game_net = 'Unity'
play_platform = 'Unity'
game_net_user_id = ''
}

$LoginResult = Invoke-RestMethod -Uri "https://www.realmofthemadgod.com/char/list" -Method 'Post' -Body $bodylogin -Headers $headerverify
$LoginResultCharName = $LoginResult.Chars.Account.Name



$ArgumentList = $("data:{platformeca,guid:" + $encodedguid + ",token:" + $accounttoken + ",tokenTimestamp:" + $tokenExpirationencrypted + ",tokenExpiration:" + $tokenTimestampencrypted + ",env:4}"

Start-Process -NoNewWindow -FilePath $ExaltExePath -ArgumentList $ArgumentList

}
This script would launch a client and pass the right parameters to the exalt exe. Kind of a launcher.
(didn't test it - i modified my original one (which serves another purpose) for you.

Red: stuff you need / should edit
Blue: info you want to find.


Beware: you need to find out which "clientToken" (Unique Token OF for your PC) you have!
So fire-up fiddler, and then launch the exalt launcher and log in.
Then inspect the request which goes to https://www.realmofthemadgod.com/account/verify and see which "clientToken" was generated.
Replace the ClientToken from my snippet and put the one in that you saw in Fiddler.

PS: when copying, make sure you don't copy the smileys in the code snippet
Quote Originally Posted by theross View Post
this Powershell snippet might help you on your journey:



This script would launch a client and pass the right parameters to the exalt exe. Kind of a launcher.
(didn't test it - i modified my original one (which serves another purpose) for you.

Red: stuff you need / should edit
Blue: info you want to find.


Beware: you need to find out which "clientToken" (Unique Token OF for your PC) you have!
So fire-up fiddler, and then launch the exalt launcher and log in.
Then inspect the request which goes to https://www.realmofthemadgod.com/account/verify and see which "clientToken" was generated.
Replace the ClientToken from my snippet and put the one in that you saw in Fiddler.

PS: when copying, make sure you don't copy the smileys in the code snippet
I am already done, see the ExaltAccountManager 1.4 here in the forum, it is the tool I needed that for.
But thank you for the effort anyways!
Posts 1–5 of 5 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us