NEED HELP TO MAKE MY LCAL SERVER!!!!!

Discussion about Helbreath Server Files.
Post Reply
TyLLy_4
Member
Posts: 107
Joined: Tue Jan 27, 2004 1:17 am

Post by TyLLy_4 »

<span style='color:red'><span style='font-family:Optima'>HEY HI YALL ... IM MAKIUNG A LOCAL SERVER AS IT SAYS IN THE FORUM .... AND IM ALMOS DONDE .. BUT I HAVE A PROBLEM ... WHANIM GOING TO CHANGE THE IP ADREES IN THE CLIENT ... I CANT!!! SO .. PLEASE CAN SOME TELL ME HOW TO DO IT ... IM TRYING HARD ... BUT SHIT .. I DONT FIND A THIG .... IM LOOKING ON IT IN ODBG ...
SHOULD I BEEN USING OTHER PROGRAM .. ANSWER AS SOON AS POSIBLE ... THANKS
P.D. THATS THE BEST HACKING WEBSITE EVER!!! :ph34r: :ph34r: :ph34r: :ph34r: :ph34r: :ph34r: :ph34r: </span></span>
<a href='http://tylly4.3a2.com' target='_blank'>)-=[TyLLy_4]=-(</a>
Knowledge
noob
Posts: 10
Joined: Mon Jan 26, 2004 4:08 pm

Post by Knowledge »

OMFG :blink:
jorge51
Member
Posts: 118
Joined: Wed Oct 29, 2003 6:33 pm
Location: Some Place In The World
Contact:

Post by jorge51 »

lol u dont know how to change the ip of ur client?..... o well in ur .hex program find the words "checksum error" above it there will be some numbers..ok when u find it just change it to ur ip.. lol.... atleast thats what i did :)
GrAnNy
Member
Posts: 193
Joined: Sat Nov 08, 2003 3:49 pm

Post by GrAnNy »

Knowledge wrote: OMFG  :blink:
same words....but i'll add this: go learn some english :blink:

PS: Theres a button called Caps Lock usually on the left side of keyboard, press it and check on the right top side of keyboard that the Light next to the Caps Lock wouldn't be green, then you can write normally. :lol:
WHO EVER ADDS ME TO MSN ASK FIRST BY PM HERE OR OTHERWISE I WILL BLOCK YOU BRUTALLY!!!
TyLLy_4
Member
Posts: 107
Joined: Tue Jan 27, 2004 1:17 am

Post by TyLLy_4 »

ok people ... i gopt the caps thingy .. it was hard and i had to practise .. but i already got it! now ... (and iknow im so dub) i cant find the goddamm ip adress..... thats what i see a few lines up of my checksum error .. can u guyz please tell me where the freaking ip adress is??? thanks a lot ( and sorry about the english .. im cuban rafter) hehe thanks yal



00402019 . 51 PUSH ECX
0040201A . 8D8D 20D90400 LEA ECX,DWORD PTR SS:[EBP+4D920]
00402020 . 8985 1CE90400 MOV DWORD PTR SS:[EBP+4E91C],EAX
00402026 . C74424 70 0100>MOV DWORD PTR SS:[ESP+70],1
0040202E . E8 EDDB0800 CALL HBG.0048FC20
00402033 . 8B85 1CE90400 MOV EAX,DWORD PTR SS:[EBP+4E91C]
00402039 . 8B95 B8D80400 MOV EDX,DWORD PTR SS:[EBP+4D8B8]
0040203F . 33DB XOR EBX,EBX
00402041 . 50 PUSH EAX ; /Arg1
00402042 . 8D8D F0550000 LEA ECX,DWORD PTR SS:[EBP+55F0] ; |
00402048 . 899D 1CC20400 MOV DWORD PTR SS:[EBP+4C21C],EBX ; |
0040204E . 8995 C4D80400 MOV DWORD PTR SS:[EBP+4D8C4],EDX ; |
00402054 . E8 07DA0800 CALL HBG.0048FA60 ; \HBG.0048FA60
00402059 . 25 FF000000 AND EAX,0FF
0040205E . B9 05000000 MOV ECX,5
00402063 . BE 64354A00 MOV ESI,HBG.004A3564 ; ASCII "roqhsdr[[sqddr0-o`j"
00402068 . 8D7C24 28 LEA EDI,DWORD PTR SS:[ESP+28]
0040206C . 8985 2CD90400 MOV DWORD PTR SS:[EBP+4D92C],EAX
00402072 . 8985 34D90400 MOV DWORD PTR SS:[EBP+4D934],EAX
00402078 . 8985 30D90400 MOV DWORD PTR SS:[EBP+4D930],EAX
0040207E . 8985 38D90400 MOV DWORD PTR SS:[EBP+4D938],EAX
00402084 . 899D 10DF0400 MOV DWORD PTR SS:[EBP+4DF10],EBX
0040208A . 889D 58E40400 MOV BYTE PTR SS:[EBP+4E458],BL
00402090 . 889D 57E40400 MOV BYTE PTR SS:[EBP+4E457],BL
00402096 . 889D 56E40400 MOV BYTE PTR SS:[EBP+4E456],BL
0040209C . F3:A5 REP MOVS DWORD PTR ES:[EDI],DWORD PTR DS>
0040209E . B9 05000000 MOV ECX,5
004020A3 . BE 4C354A00 MOV ESI,HBG.004A354C ; ASCII "bnmsdmsr[[a`cvnqc-sws"
004020A8 . 8D7C24 3C LEA EDI,DWORD PTR SS:[ESP+3C]
004020AC . 8B15 44354A00 MOV EDX,DWORD PTR DS:[4A3544]
004020B2 . F3:A5 REP MOVS DWORD PTR ES:[EDI],DWORD PTR DS>
004020B4 . 8B0D 40354A00 MOV ECX,DWORD PTR DS:[4A3540]
004020BA . 66:A1 48354A00 MOV AX,WORD PTR DS:[4A3548]
004020C0 . 53 PUSH EBX ; /hTemplateFile
004020C1 . 53 PUSH EBX ; |Attributes
004020C2 . 6A 03 PUSH 3 ; |Mode = OPEN_EXISTING
004020C4 . 53 PUSH EBX ; |pSecurity
004020C5 . 894C24 2C MOV DWORD PTR SS:[ESP+2C],ECX ; |
004020C9 . 8A0D 4A354A00 MOV CL,BYTE PTR DS:[4A354A] ; |
004020CF . 53 PUSH EBX ; |ShareMode
004020D0 . 8B1D CCF04900 MOV EBX,DWORD PTR DS:[<&KERNEL32.CreateF>; |kernel32.CreateFileA
004020D6 . 68 00000080 PUSH 80000000 ; |Access = GENERIC_READ
004020DB . 68 28354A00 PUSH HBG.004A3528 ; |FileName = "CONTENTS\badword.txt"
004020E0 . 66:A5 MOVS WORD PTR ES:[EDI],WORD PTR DS:[ESI] ; |
004020E2 . 895424 3C MOV DWORD PTR SS:[ESP+3C],EDX ; |
004020E6 . 66:894424 40 MOV WORD PTR SS:[ESP+40],AX ; |
004020EB . 884C24 42 MOV BYTE PTR SS:[ESP+42],CL ; |
004020EF . FFD3 CALL EBX ; \CreateFileA
004020F1 . 83F8 FF CMP EAX,-1
004020F4 . 90 NOP
004020F5 . 90 NOP
004020F6 . 8B3D D0F04900 MOV EDI,DWORD PTR DS:[<&KERNEL32.CloseHa>; kernel32.CloseHandle
004020FC . 50 PUSH EAX ; /hObject
004020FD . FFD7 CALL EDI ; \CloseHandle
004020FF . 6A 00 PUSH 0 ; /hTemplateFile = NULL
00402101 . 6A 00 PUSH 0 ; |Attributes = 0
00402103 . 6A 03 PUSH 3 ; |Mode = OPEN_EXISTING
00402105 . 6A 00 PUSH 0 ; |pSecurity = NULL
00402107 . 6A 00 PUSH 0 ; |ShareMode = 0
00402109 . 68 00000080 PUSH 80000000 ; |Access = GENERIC_READ
0040210E . 68 14354A00 PUSH HBG.004A3514 ; |FileName = "SPRITES\TREES1.PAK"
00402113 . FFD3 CALL EBX ; \CreateFileA
00402115 . 8BF0 MOV ESI,EAX
00402117 . 83FE FF CMP ESI,-1
0040211A . 90 NOP
0040211B . 90 NOP
0040211C . 6A 00 PUSH 0 ; /pFileSizeHigh = NULL
0040211E . 56 PUSH ESI ; |hFile
0040211F . FF15 D4F04900 CALL DWORD PTR DS:[<&KERNEL32.GetFileSiz>; \GetFileSize
00402125 . 3D 862C1C00 CMP EAX,1C2C86
0040212A . 56 PUSH ESI
0040212B . EB 22 JMP SHORT HBG.0040214F
0040212D . FFD7 CALL EDI ; \CloseHandle
0040212F . 8B95 1CE90400 MOV EDX,DWORD PTR SS:[EBP+4E91C]
00402135 . 6A 30 PUSH 30 ; /Style = MB_OK|MB_ICONEXCLAMATION|MB_APPLMODAL
00402137 . 68 0C354A00 PUSH HBG.004A350C ; |Title = "ERROR"
0040213C . 68 DC344A00 PUSH HBG.004A34DC

a bit long huh?
:ph34r: :ph34r: :ph34r: :ph34r: :ph34r: :ph34r: :ph34r: :ph34r:
<a href='http://tylly4.3a2.com' target='_blank'>)-=[TyLLy_4]=-(</a>
ed1tor
Regular
Posts: 58
Joined: Wed Nov 12, 2003 4:20 pm

Post by ed1tor »

strip off the client. so the coded within the exe was encrypted and use a hex editor to open the stripped exe and look for this string "checksum"
charlie
Outpost4lyfe
Posts: 3324
Joined: Sun Apr 06, 2003 12:24 am
Location: Mt GOD
Contact:

Post by charlie »

haha use a hex editor not a debugger :P
Girlfriends are dedicated hookers.
hayato1
Regular
Posts: 38
Joined: Wed Oct 15, 2003 5:51 pm

Post by hayato1 »

wow finally u not with cap lock......the world is peace!!!!!
GrAnNy
Member
Posts: 193
Joined: Sat Nov 08, 2003 3:49 pm

Post by GrAnNy »

hayato1 wrote: wow finally u not with cap lock......the world is peace!!!!!
thanks to me..... :)
WHO EVER ADDS ME TO MSN ASK FIRST BY PM HERE OR OTHERWISE I WILL BLOCK YOU BRUTALLY!!!
TyLLy_4
Member
Posts: 107
Joined: Tue Jan 27, 2004 1:17 am

Post by TyLLy_4 »

OOOO
THAT EXPLAINS EVERYTHING!! THANKS A LOT .. BUT NOW .. CAN U TELL ME A GOD HEX EDITOR (IM NEW AT THE BUSINES) HEHE THANKS U ALL (and sory for the caps again .. its just superior to me man!)

but anyway ill write it down again without caps (i dont feel like ereasing

-that explains everything, thanks a lot! but now ... can u tell me a god hex editor (im new at the busines) hehe thanks u all
p.d. (i use odgb .. is there anyway to make it hex editor .. i mean there is a window taht sais hex code .. bit i dun understand nothing ..... )

thanks u all again :ph34r: :ph34r: :ph34r: :ph34r: :ph34r: :ph34r:
<a href='http://tylly4.3a2.com' target='_blank'>)-=[TyLLy_4]=-(</a>
magsec4
Member
Posts: 120
Joined: Tue Nov 18, 2003 3:31 am

Post by magsec4 »

just go to download.com and search for a hex editor. what i recommend is EasyHex. its easy to use, plain, simple, just like notepad or a .txt editor, except it edits hex :P .
Post Reply