Blizzhackers

Return of the Jedi

* Login   * Register    * FAQ    * Search

Join us on IRC: #bh@irc.synirc.net (or Mibbit Web IRC)


MuleFactory


It is currently Thu May 23, 2013 5:19 pm


All times are UTC [ DST ]





Post new topic Reply to topic  [ 102 posts ]  Go to page Previous  1, 2, 3, 4, 5, 6, 7  Next
Author Message
 Post subject:
PostPosted: Sun Jun 18, 2006 1:06 pm 
 
User
User

Joined: Sat Mar 25, 2006 5:47 am
Image

and then it closes.. hmm, any ideas? looking foward to getting it working

Top
 Profile  
 Post subject:
PostPosted: Sat Jul 01, 2006 5:01 am 
 
User
User
User avatar

Joined: Sun Mar 19, 2006 6:17 pm
of course it works (I mean the concept, haven't tested that "software")

I assumed it was an well-known fact...apparently, I was wrong.

here's how to do it without any "special" tools, if you have some *nix machine lying around:

-bash-3.00# tcpdump -A -s 1500 -i fxp0 host x.x.x.x and port 3724 | grep charname
tcpdump: listening on fxp0
E..Y..@.........P..3........n.}.P.........^b;.........charname.proving it works.
^C-bash-3.00#


(where fxp0 would be the interface and X.X.X.X the ip of the server used there, like 80.239.x.x)

it's good to use while trying to understand a certain char, I just use 1>>1 and 2>>2 , then tail -f 1.

probably gonna be useless to most of you though, tcpdump is just a tool, not a real frontend.

for those that wanna use this on windows machines...just use ethereal and set the port to 3724, packet size 1500. you can always use filters as well, to remove "trash".

and yeah, if you're not a regular *nix user, you probably didn't understand a damn thing I said :) sorry.

gl.

Top
 Profile  
 Post subject:
PostPosted: Wed Jul 05, 2006 6:00 pm 
 
User
User

Joined: Wed Jul 05, 2006 5:44 pm
Hey first of all, a great little program. I use it for fun and to finally see what my imp is really saying when he speaks demonic. However lately I have gotten this message:

Image

KLHTM Threat 0. I just wondered what it is. It's being spammed every second or so, sometimes with a value much higher than 0. Is it anything to be worried about?

Top
 Profile  
 Post subject:
PostPosted: Mon Jul 10, 2006 11:57 am 
 
User
User

Joined: Mon May 15, 2006 8:36 am
kanly wrote:
of course it works (I mean the concept, haven't tested that "software")

I assumed it was an well-known fact...apparently, I was wrong.

here's how to do it without any "special" tools, if you have some *nix machine lying around:

-bash-3.00# tcpdump -A -s 1500 -i fxp0 host x.x.x.x and port 3724 | grep charname
tcpdump: listening on fxp0
E..Y..@.........P..3........n.}.P.........^b;.........charname.proving it works.
^C-bash-3.00#


(where fxp0 would be the interface and X.X.X.X the ip of the server used there, like 80.239.x.x)

it's good to use while trying to understand a certain char, I just use 1>>1 and 2>>2 , then tail -f 1.

probably gonna be useless to most of you though, tcpdump is just a tool, not a real frontend.

for those that wanna use this on windows machines...just use ethereal and set the port to 3724, packet size 1500. you can always use filters as well, to remove "trash".

and yeah, if you're not a regular *nix user, you probably didn't understand a damn thing I said :) sorry.

gl.


So what you are basicly saying is that the text people speak goes plaintext over the line? I understood that it wasnt encrypted but I at least expected some compressionmethod.

And if I saw the screenies from wowsniffer correctly it didnt show the usernames. Or they were edited out?

I installed the windows port of TCPdump on my XP64 machine now. And I will see what it shows me when I get home tonight.

Top
 Profile  
 Post subject:
PostPosted: Tue Jul 11, 2006 4:23 pm 
 
User
User

Joined: Sat May 13, 2006 5:07 pm
the charname is NOT transmitted, only the GUID is (afaik)

Top
 Profile  
 Post subject:
PostPosted: Tue Jul 11, 2006 5:55 pm 
 
User
User
User avatar

Joined: Sun Feb 26, 2006 7:20 pm
Location: Belgium
So to get this right, it IS safe to use this program on blizz servers?

Top
 Profile  
 Post subject:
PostPosted: Mon Jul 31, 2006 11:57 pm 
 
User
User

Joined: Tue Jul 19, 2005 8:46 pm
Quote:
Because this hack does not interact with the game at all, it should be beyond the scope of Warden, assuming you run it with restricted privileges


what do you mean restricted privaleges?

Top
 Profile  
 Post subject:
PostPosted: Sat Aug 05, 2006 6:59 am 
 
User
User

Joined: Fri Oct 24, 2003 3:58 am
Location: Long Beach CA
So anyone gonna make this with some UI and translate horde/alliance only?

Top
 Profile  
 Post subject:
PostPosted: Sat Aug 05, 2006 8:10 am 
 
Banned
Banned
User avatar

Joined: Sun Feb 02, 2003 6:21 am
Location: 熱心な
Shogun01 wrote:
Hey first of all, a great little program. I use it for fun and to finally see what my imp is really saying when he speaks demonic. However lately I have gotten this message:

Image

KLHTM Threat 0. I just wondered what it is. It's being spammed every second or so, sometimes with a value much higher than 0. Is it anything to be worried about?
Didn't look at the picture but it keeps re-sync the raid channel to sync up with the other dmgmeters.

_________________
Image

Top
 Profile  
 Post subject:
PostPosted: Fri Aug 11, 2006 6:53 am 
 
User
User

Joined: Thu Jun 22, 2006 2:52 am
Location: Your Mouth
works. very nice job. too bad not all people have this.

Top
 Profile  
 Post subject:
PostPosted: Sat Aug 12, 2006 5:05 pm 
 
User
User

Joined: Sat Aug 12, 2006 6:10 am
very nice program, I was wondering is there any method to only sniff /s and /y messages? Currently it's capturing every single chat channel
I tried to modify the code myself but I don't have visual studio and I'm messing with includes and linker ^_^"

Top
 Profile  
 Post subject:
PostPosted: Thu Aug 17, 2006 7:11 am 
 
User
User

Joined: Thu Aug 03, 2006 2:12 am
Ok I am installing SDK and VS right now.. but just to let this be known... on the 1.12 PTRs this thing worked perfect for me. Then I went and tried it live and it didn't work. This leads me to believe that maybe the PTRs have some kind of different chat or something like that? I really have no clue, just bringing this up to you guys :)

EDIT: whats the difference between WowSniffer and WowSniffer_B?
WowSniffer is 11kb... WowSniffer_B is 36kb
But ya, why are there two of them?

Top
 Profile  
 Post subject:
PostPosted: Thu Aug 17, 2006 1:02 pm 
 
User
User

Joined: Thu Aug 17, 2006 12:56 pm
I have decoded most of the chat protocol.
Text file: http://www.filefactory.com/file/1d430f/

User IDs have been obscured with [] [] [] and ***.

                  49 a7 f5 50 0e 00 00 00 00 78  B..T..I..P.....x
74 65 6e 73 69 6f 6e 78 74 6f 6f 6c 74 69 70 32  tensionxtooltip2
00 07 00 00 00 [] [] [] 01 00 00 00 00 0e 00 00  ................
00 3c 44 56 3e 31 31 3c 43 53 31 3e 38 31 00 00  .<DV>11<CS1>81..

36 a6 30 b6 0e 00 00 00 00 78 74 65 6e 73 69 6f 6e 78 74 6f 6f 6c 74 69 70 32 00 00 00 00 00 [] [] [] 01 00 00 00 00 24 00 00 00 3c 52 50 32 3e 3c 43 53 32 3e 3c 4e 3e 00 00
?  ?  ?  ?  *  *  *  *  *  x  t  e  n  s  i  o  n  x  t  o  o  l  t  i  p  2  ?  ?  ?  ?  ?  *  *  *  *  ?  ?  ?  ?  ?  ?  *  *  (Data Begins)                          *  *(Data Stop Bits)
49 a7 f5 50 0e 00 00 00 00 78 74 65 6e 73 69 6f 6e 78 74 6f 6f 6c 74 69 70 32 00 07 00 00 00 [] [] [] 01 00 00 00 00 0e 00 00 00 3c 44 56 3e 31 31 3c 43 53 31 3e 38 31 00 00
?  ?  ?  ?  *  *  *  *  *  x  t  e  n  s  i  o  n  x  t  o  o  l  t  i  p  2  ?  ?  ?  ?  ?  *  *  *  *  ?  ?  ?  ?  ?  ?  *  *  (Data Begins)                          *  *(Data Stop Bits)
Unknown    |Lang/Chan     |Channel Name                                      |              |User ID
                                               ^
                                               |
                                               Message length.

2d 0b fa a4 0e 00 00 00 00 4c 6f 6f 6b 69 6e 67 46 6f 72 47 72 6f 75 70 00 09 00 00 00 [] [] [] 00 00 00 00 00 2c 00 00 00 73
?  ?  ?  ?  *  *  *  *  *  L  o  o  k  i  n  g  F  o  r  G  r  o  u  p  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  *  *  (Data Begins)

                  2d 0b fa a4 0e 00 00 00 00 4c  B..{..-........L
6f 6f 6b 69 6e 67 46 6f 72 47 72 6f 75 70 00 09  ookingForGroup..
00 00 00 [] [] [] 00 00 00 00 00 2c 00 00 00 73  ...........,...s
77 65 65 74 20 65 6e 74 69 72 65 20 74 72 61 69  weet entire trai
6e 20 6f 66 20 68 6f 72 64 65 20 67 61 75 72 64  n of horde gaurd
73 20 61 66 74 65 72 20 6d 65 00 00 2e d1 5e f8  s after me....^.
b0 00 00 00 78 01 63 64 00 01 7e ff ac 68 46 0d  ....x.cd..~..hF.
06 06 07 30 6f b0 12 4b 81 0e 03 00 05 fb 02 33  ...0o..K.......3
a6 25 65 25 02 01 00 00 f7 d2 11 35 a2 03 04 f0  .%e%.......5....
0f 4f 6a 5b 01 27 00 00 00 01 00 00 00 00 00 00  .Oj[.'..........
1c 42 27 00 00 00 00 00 00 00 00 00 00 00 01 00  .B'.............
00 00 ff ff ff ff 00 00 00 00 00 00 00 00        ..............


d1 11 e4 d6 00 07 00 00 00 [] [] [] 01 00 00 00 00 [] [] [] 01 00 00 00 00 09 00 00 00 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  *  *  *  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  *  *  T  e  s  t  i  n  g  .  *  *
[******] says: Testing.
f7 93 cb 2b 00 07 00 00 00 [] [] [] 01 00 00 00 00 [] [] [] 01 00 00 00 00 10 00 00 00 53 65 63 6f 6e 64 20 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  *  *  *  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  *  *  S  e  c  o  n  d     T  e  s  t  i  n  g  .  *  *
[******] says: Second Testing.
55 a3 76 68 00 07 00 00 00 [] [] [] 01 00 00 00 00 [] [] [] 01 00 00 00 00 0f 00 00 00 54 68 69 72 64 20 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  *  *  *  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  *  *  T  h  i  r  d     T  e  s  t  i  n  g  .  *  *
[******] says: Third Testing.
Unknown    |Lang/Chan     |User ID |Padding       |User ID                |Length     |Message                                  |Stop
72 b2 85 77 00 07 00 00 00 [] [] [] 01 00 00 00 00 [] [] [] 01 00 00 00 00 09 00 00 00 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  (Say)    ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  *  *  T  e  s  t  i  n  g  .  *  *
[*******] says: Testing.
14 b0 e8 48 00 07 00 00 00 [] [] [] 01 00 00 00 00 [] [] [] 01 00 00 00 00 10 00 00 00 53 65 63 6f 6e 64 20 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  (Say)    ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  *  *  S  e  c  o  n  d     T  e  s  t  i  n  g  .  *  * 
[*******] says: Second Testing.
b8 4b 19 39 00 07 00 00 00 [] [] [] 01 00 00 00 00 [] [] [] 01 00 00 00 00 0f 00 00 00 54 68 69 72 64 20 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  (Say)    ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  *  *  T  h  i  r  d     T  e  s  t  i  n  g  .  *  *
[*******] says: Third Testing.
aa 47 15 35 00 07 00 00 00 [] [] [] 01 00 00 00 00 [] [] [] 01 00 00 00 00 09 00 00 00 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  (Say)    ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  *  *  T  e  s  t  i  n  g  .  *  *



aa 47 15 35 00 07 00 00 00 [] [] [] 01 00 00 00 00 [] [] [] 01 00 00 00 00 09 00 00 00 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  ^  ^  ^  ^  ?  ?  ?  ?  ^  ^  ^  ^  ?  ?  ?  ?  ?  ?  *  *  T  e  s  t  i  n  g  .  *  *
24 2a 63 2c 05 07 00 00 00 [] [] [] 01 00 00 00 00 [] [] [] 01 00 00 00 00 09 00 00 00 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  ^  ^  ^  ^  ?  ?  ?  ?  ^  ^  ^  ^  ?  ?  ?  ?  ?  ?  *  *  T  e  s  t  i  n  g  .  *  *
71 83 bc 85 0e 00 00 00 00 4c 6f 6f 6b 69 6e 67 46 6f 72 47 72 6f 75 70 00 00 00 00 00 [] [] [] 01 00 00 00 00 09 00 00 00 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  L  o  o  k  i  n  g  F  o  r  G  r  o  u  p  ?  ?  ?  ?  ?  ^  ^  ^  ^  ?  ?  ?  ?  ?  ?  *  *  T  e  s  t  i  n  g  .  *  *
0d 90 9a 6a 0e 00 00 00 00 78 74 65 6e 73 69 6f 6e 78 74 6f 6f 6c 74 69 70 32 00 00 00 00 00 [] [] [] 01 00 00 00 00 09 00 00 00 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  x  t  e  n  s  i  o  n  x  t  o  o  l  t  i  p  2  ?  ?  ?  ?  ?  ^  ^  ^  ^  ?  ?  ?  ?  ?  ?  *  *  T  e  s  t  i  n  g  .  *  *


If the message is on Say or Yell, the player name is substituted after the language descriptor as there is no channel.
If the message is on a channel, the channel name is after the language descriptor.

All player and channel names have five bytes of padding at the end.  00 00 00 00 00 at the end of channels, 01 00 00 00 00 at the end of names.

The message section has four bytes before it.  The first byte is the character count of the message plus one, maximum is 255.(FF)  If the limit is exceeded, it returns 01 in this field.  The second, third, and fourth bytes are always 00.


HORDE SIDE
aa 48 db 05 00 01 00 00 00 [] [] [] 00 00 00 00 00 [] [] [] 00 00 00 00 00 09 00 00 00 54 65 73 74 69 6e 67 2e 00 00
?  ?  ?  ?  *  *  *  *  *  ^  ^  ^  ^  ?  ?  ?  ?  ^  ^  ^  ^  ?  ?  ?  ?  ?  ?  *  *  T  e  s  t  i  n  g  .  *  *
31 54 8f 32 05 01 00 00 00 [] [] [] 00 00 00 00 00 [] [] [] 00 00 00 00 00 0f 00 00 00 54 68 61 74 20 69 73 20 67 72 65 61 74 21 00 00
?  ?  ?  ?  *  *  *  *  *  ^  ^  ^  ^  ?  ?  ?  ?  ^  ^  ^  ^  ?  ?  ?  ?  ?  ?  *  *  T  h  a  t     i  s     g  r  e  a  t  !  *  *
a2 28 70 78 0e 00 00 00 00 78 74 65 6e 73 69 6f 6e 78 74 6f 6f 6c 74 69 70 32 00 09 00 00 00 [] [] [] 01 00 00 00 00 0e 00 00 00 3c 44 56 3e 2d 31 3c 43 53 30 3e 35 38 00 00
?  ?  ?  ?  *  *  *  *  *  x  t  e  n  s  i  o  n  x  t  o  o  l  t  i  p  2  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  *  * 

Channel/Language
00 07 00 00 00 = Say, Common
05 07 00 00 00 = Yell, Common
0e 00 00 00 00 = Channel, Common or Orcish?  Used the same on each side.
00 01 00 00 00 = Say, Orcish
00 0e 00 00 00 = Say, Troll
05 01 00 00 00 = Yell, Orcish
06 00 00 00 00 = Whisper

Top
 Profile  
 Post subject:
PostPosted: Wed Aug 23, 2006 5:57 pm 
 
User
User
User avatar

Joined: Tue Feb 22, 2005 1:38 pm
00 07 00 00 00 = Say, Common
05 07 00 00 00 = Yell, Common
0e 00 00 00 00 = Channel, Common or Orcish?  Used the same on each side.
00 01 00 00 00 = Say, Orcish
00 0e 00 00 00 = Say, Troll
05 01 00 00 00 = Yell, Orcish
06 00 00 00 00 = Whisper


Using some of that info, could be able to make it show you some options, etc. So you can decide what to show and what to not. Aswell your side so it only decodes the opposite faction?

*toughts toughts*

Top
 Profile  
 Post subject:
PostPosted: Wed Aug 23, 2006 7:15 pm 
 
User Gold
User Gold
User avatar

Joined: Tue Mar 28, 2006 1:57 am
Location: SoCal
Like stated above, does anyone know the difference between a and b? Also, /s and /y aren't picked up by the program, has anyone gotten it to? Ive been fiddling around with this, looking to see if there was a way to use /s or /y, but no luck yet. Wonderfuly app though crediar.

Top
 Profile  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 102 posts ]  Go to page Previous  1, 2, 3, 4, 5, 6, 7  Next

All times are UTC [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
cron