Reversing Encryption Conversation

Posts 1–11 of 11 · Page 1 of 1
Reversing Encryption Conversation
Hey. I'm just throwing around ideas here, but get this.

I was thinking I wanted to decrypt the encrypted text files that CA loads up at the beginning of each game.

I thought I could do this by counting coincidences at first, but Im having a hard time finding any real code or lessons on it. Most of the code I see is for real encryptions like DES or triple DES, but to the point. (finally)

I supposed the easiest way would be just to monitor when and how CA accesses the files and when it decrypts them I just steal the algorithm of hook its functions and somehow get it to print out a copy. Now I change a few things and run the algorithm again and it should be reencrypted and ready to load up right?

So I guess what Im asking is do you think this will work. The only problem I can for see is that perhaps the algorithms won't be symmetrical.

This isn't really a code discussion. Im just talking about possible approaches to the situation right now.
How would you go about monitoring how Combat Arms accesses these files? I don't understand how you're going to find the algorithm, assuming this theory works.
Quote Originally Posted by Void View Post
How would you go about monitoring how Combat Arms accesses these files? I don't understand how you're going to find the algorithm, assuming this theory works.
I would monitor the I/O system. there are several tools to do it, I read about it in my book on reversing, not sure about the specifics though. Anyway when I come across the functions in which I see these I/O functions have been called in ca I would use a debugger or something to see if they are converted or anything. It depends how difficult it will be to track the process. I suppose the more I learn abt asm the better I'll understand that.
It's not a very simple theory but I'm going to say it anyways..

If it were that simple, don't you think it would have been done by now? Actually I don't even know if it has been done.

Also, I don't know too much about 'packing' or actually know what 'packing' is for that matter. But, if the decryptor is packed, how are you going to 'reverse' it?
Lol. It prbly will be packed (good point). In which case I suppose I would just have to find another way. I might try doing some research and looking at older lithtech games and see if there encryptions are not packed, but that's all assuming though. =/
I'm not saying your theory won't work, I find it to be a very well thought out theory. I don't know if you already have done this but, make your own decryptor and try out your theory on your own program, this way you have full access to the source code and know exactly what you're looking for.
correct me if i'm wrong....

you are saying.

1. CA sends decrypted data to your pc.

2. your pc decrypts it

3. your pc executes it.

4. your pc encrypts the result.

5. your pc sends back the encrypted data.


it sounds logical but if I worked at nexon I would combine step 2 and 3 by directly executing the encrypted file, because it is more difficult for hackers to find out what the encrypted file is that way.
If I understood your idea correctly, isn't this a bit like the same work one do when serialfishing? Altough it's probably a lot easier to do than this. Well it's worth a shot anyway, if there are any way to do this it's probably best done with OllyDbg, decent knowledge and a lot of patient. Good luck if you try this one, it's been too long since I used Olly and I forgot a lot I don't have time to learn so I wouldn't try it
Wasn't ba able to decrypt all those files? ;o
Quote Originally Posted by Hell_Demon View Post
Wasn't ba able to decrypt all those files? ;o
Well he was able to open them up. And even though he showed me the plugin code I have no idea how to do it myself. I think I just need a lot more experience in other things before I come back and try to tackle this problem. Sometimes its best to find a way around a wall rather then jump over it. I have zero experience in cryptology, but I do know at least something about memory hacking, and I read in this book once and this hacker went inside a program using a Hex editor and changed something around so that he could do an SQL injection attack. I imagine that is sorta what I want to do here, instead of trying to brute force a password (in my case crack a file) so I guess that's sort of what I want to do here. Anyway I digress. This is all speculation, but thanks for entertaining my ideas. I don't like talking about stuff with out any proof to show for it.

I will find out more the less time I spend talking about it. You've given me good things to look out for, but I've got a lot to learn until I can judge how right or wrong your theories will be.
uhm since they are text files try looking for file parsing functions when debugging CA(low level debugging)
coz normally progs like this will have to get file input and then it will go thru the decryption pipeline to be understood by the program so the next function called after text input should be the decrption algorithms
Posts 1–11 of 11 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Talk with us