Another idea to unpatch mods.

Posts 1–14 of 14 · Page 1 of 1
Another idea to unpatch mods.
Hey, I came across a old tut from 2009, and it says:

 
The tutorial
- Unpacking/Cracking Combat Arms -
- Tutorial -

This tutorial will teach you how to unpack and disable the hacking message for Combat Arms. This is a very simple process, and if you like it you can learn more at a few sites I personally like, listed at the bottom in the credits. So, if you are interested, keep reading.

- Tools You Will Need -

OllyDbg - Our debugger
PE Explorer - Our unpacker
PEiD - Our identifier
CRC32 PEiD Plugin - Used to fix the CRC32 with PEiD

1. Install PE Explorer to your computer.
2. Create a folder on your Desktop called "Cracking Tools".
3. Extract PEiD-0.94-20060510.zip into your folder.
4. Extract odbg110.zip into your folder.
5. Extract crc32-gelios.zip to your Desktop.
6. Open up the crc32-gelios folder, and copy crc32.dll to the "plugins" folder in your PEiD folder.

- Unpacking -

BEFORE UNPACKING BACKUP THE ENGINE.EXE LOCATED AT "C:\NEXON\COMBAT ARMS" TO YOUR DESKTOP! WE WILL NEED IT FOR LATER!

Alright, the unpacking stage. To unpack the client, open up PE Explorer. Then hit File, Open File. Go to your Combat Arms directory (usually C:\Nexon\Combat Arms), and open up Engine.exe. Now it will unpack it. Click File, Save File As, and save it as Engine.exe, overwriting the old one. It is now unpacked Told you it was easy...

- Cracking -

Ah, the fun part of this tutorial. Open up OllyDbg, and hit F3. Now browse to your Combat Arms directory, and open Engine.exe. Now, we know that when we try to open a hack, or a cheat engine, or something that modifies memory, HackShield (Combat Arm's anti-cheat protection) detects it. The message it reports to us is "A hacking tool has been discovered...", or something like that. So, we want to remove that message

Right click anywhere in the "CPU - main thread, module Engine" window of OllyDbg. Click Search For, All Referenced Text Strings. It will open a new window. Right click in this new window, and choose Search For Text. Enter in "a hacking tool" without the quotes. Untick case sensitive, and tick Entire Scope, and search. It will find the line, now double click that line. It will bring you back to the main window, but this time you are at the address of the ASCII line you found.



This is the line if you can't see it in the picture:

Code:
00505D55 |. 68 D0BD6600 PUSH Engine.0066BDD0 ; ASCII "A hacking tool has been discovered in the following location so the program has been shut down.
(%s)"

So, move your mouse up 9 and right click. Choose Binary, Edit. Next click on the 4, and change it to 5.



What we just did was change the computer from saying "Jump if equal" to "Jump if not zero". Basic ASM can get you really far

All done cracking it Now we just need to fool the game into thinking it is unmodified, by chanigng the CRC32 to the unmodified value.

Open PEiD, and press the "..." button. Find the unmodified Engine.exe on your Desktop, and open it. Now hit the "->" button, plugins, and CRC32. A new window should popup, copy the value you see. To save you time, it is "0954F8BC".



Now, close PEiD. Re-open PEiD, but this time open your modified Engine.exe. Load up the plugin again, and paste in the original value that you got above. Then match my settings in the picture below, click "Fix it!", then "Done".

NOTE TO ALL BYTES: xGhostshoTx is another screen name I go by


- Credits -

People:

deadnesser - A lot of this tutorial was because of him, he is awesome
Jibz - He and the other creators of PEiD below, because without it the final step would not work
Qwerton
snaker
xineohP
Gelios


So, I'm thinking maybe there's a similar way for mods, but the problem, the reason why I didn't do it myself, is because PE Explorer gives an error when saving the unpacked engine
You would have to spoof the MD5 hash, as nexon now checks the MD5 of the game files.
I would rather spoof one file then spoofing all mods we make, wouldn't you?
Quote Originally Posted by Rainscape View Post
I would rather spoof one file then spoofing all mods we make, wouldn't you?
When you inject/folder the file, the MD5 of the entire rez file is changed.

>.>
You misunderstood what I said, basically using the method in the first post, you would be able to bypass the message that comes up between the running man and the login screen, therefore not needing to MD5 spoof all the rez files, except for the engine file, maybe.
lol this is exactly what i suggested in many other threads but many people ignored it cause im a newbie XD
No , you said "OMG I NEED A PATCH NAOW I CANT GET MY MODS TO WORK , DO SOMETHIGN SOME1"

He has a viable idea.

Spoofing the MD5 is possible , we could even use rezinject again and then just build a simple user interface that would ask you what file you modified and then it would replace the MD5 with the spoofed , unmodified version of the original code.

Easy in theroy.

Hard in practice.

#ideas
Quote Originally Posted by -P-a-i-d- View Post
"OMG I NEED A PATCH NAOW I CANT GET MY MODS TO WORK , DO SOMETHIGN SOME1"
I love arguing with someone with 94 posts... No, I tried doing this myself, I don't asking someone to do something unless I try it myself.
Does a post count matter? Bro I've been here as long as you... I was here when MPGH still had there public hack out for Combat Arms ( v.1.26 ? ) , and that sure as hell as a long time ago.

Post count means nothing.

Plus , that wasn't directed to you. That was directed to @FailureMastr
Quote Originally Posted by -P-a-i-d- View Post
Does a post count matter? Bro I've been here as long as you... I was here when MPGH still had there public hack out for Combat Arms ( v.1.26 ? ) , and that sure as hell as a long time ago.

Post count means nothing.

Plus , that wasn't directed to you. That was directed to @FailureMastr
lol now thats fail XD
I already figured out how to bypass everything and i'm playing with all of the mods that were in my TEXTURESCRIPTS. That includes my modded guns, weapon skins, etc. They aren't detected, and I plan on keeping it that way for a long time, and no, i'm not giving away my secret. If anyone wants proof, i'm uploading a youtube video of some gameplay with my mods right now, but it won't be finished until tomorrow because the total size of the video is 500+ MB, and my modem is shit when it comes to downloading/uploading data.
Quote Originally Posted by adoramereku View Post
I already figured out how to bypass everything and i'm playing with all of the mods that were in my TEXTURESCRIPTS. That includes my modded guns, weapon skins, etc. They aren't detected, and I plan on keeping it that way for a long time, and no, i'm not giving away my secret. If anyone wants proof, i'm uploading a youtube video of some gameplay with my mods right now, but it won't be finished until tomorrow because the total size of the video is 500+ MB, and my modem is shit when it comes to downloading/uploading data.

Will be looking forward to it.
Quote Originally Posted by FailureMastr View Post


thoughs are only texture edits. any crossmods?
They aren't... Take another look. The ROF on the M14 shoots much faster than normal along with the M16A3 and the MP5A4, and the reload speed is much faster. I have crossmods, but they are on guns that were not shown in the video.
Posts 1–14 of 14 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Talk with us