|
||
|
|
#101 (permalink) |
|
Forum Expert
|
Client.cfg values for 5.0.2a
Code:
44627FD0: "5.0.2a 2D" 41A90D 5 7 434520 7 6
__________________
Angels are falling the very last time, down they're burning in hate and decline, unfaithful and violent we're breaking the spell, we're god, we're scissor, in heaven and hell! |
|
|
|
|
|
#102 (permalink) |
|
Forum Expert
|
Client.cfg values for 5.0.2b
Code:
446B9D85: "5.0.2b 2D" 41A6FD 5 7 4342F0 7 6
__________________
Angels are falling the very last time, down they're burning in hate and decline, unfaithful and violent we're breaking the spell, we're god, we're scissor, in heaven and hell! |
|
|
|
|
|
#104 (permalink) |
|
Forum Expert
|
Client.cfg values for 5.0.2c
Code:
4491BE15: "5.0.2c 2D" 41A6FD 5 7 4342C0 7 6
__________________
Angels are falling the very last time, down they're burning in hate and decline, unfaithful and violent we're breaking the spell, we're god, we're scissor, in heaven and hell! |
|
|
|
|
|
#105 (permalink) |
|
Forum Newbie
|
Uhmm... I used the tutorial with client 5.0.2b.
I tried to follow tre tutorial (both the difficult and the easy part), but I found these problems: 1. With "hard" part I can follow him until he says encrypted data size should be 0x3E... my size is 4... moreover I don't know where I should read the TOS value... (my bad!) 2. With the easy part, I found that the address containing the "], 33h" is at 0041A826, and is into the subroutine at address 0041A810... 0041A6FD is the address in the above routine for "push ebp", so why is it?. About the SendBuffer, the tutorial says we need to find the "mov bp, ax"... I found it 0041A6FD, and the corresponding routine is 0041A6D0... so... can anyone explain me what's wrong? Last edited by BladeWise; 06-22-2006 at 06:16 AM. |
|
|
|
|
|
#106 (permalink) |
|
Forum Expert
|
yeah, the tutorial seems to be outdated a bit... TOS stands for Top of the stack.
"push ebp" at 0041A6D pushes the address of the buffer onto the stack.
__________________
Angels are falling the very last time, down they're burning in hate and decline, unfaithful and violent we're breaking the spell, we're god, we're scissor, in heaven and hell! |
|
|
|
|
|
#108 (permalink) |
|
Forum Newbie
|
You can get OllyDbg here. This screenshot shows OllyDbg in action, the window with the stack view is the lower right one. The top of the stack is the first entry in that list.
|
|
|
|
|
|
#111 (permalink) |
|
Forum Expert
|
Client.cfg values for 5.0.2f
Code:
44B30695: "5.0.2f 2D" 41A6FD 5 7 4342C0 7 6
__________________
Angels are falling the very last time, down they're burning in hate and decline, unfaithful and violent we're breaking the spell, we're god, we're scissor, in heaven and hell! |
|
|
|
|
|
#112 (permalink) |
|
Forum Newbie
Join Date: Feb 2004
Posts: 35
|
Thanks Arul.
Based on your new values... I compared the 5.0.2f dasm against 5.0.2g... and here are the values for client 5.0.2g 2D (one again... unchanged offsets, wierd! however, these are tested and working) Code:
44B30695: "5.0.2g 2D" 41A6FD 5 7 4342C0 7 6 |
|
|
|
![]() |
| Bookmarks |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|