Post: Interesting Packet Injection
11-28-2009, 08:17 PM #1
s3recap
Bounty hunter
(adsbygoogle = window.adsbygoogle || []).push({}); After reading through some packets and finding out patterns, I came across two lines. I guess when the game is over the demonware servers receive two packets. I finished two games and compared both packets. They are very identical except for line 0x0010 . The data is surrounded by the stars below.

    0x0000   00 22 75 5C 69 96 00 1F-A7 11 C9 16 08 00 45 00   ."u\i–..§.É...E.
0x0010 00 39 ****BB EA 00 00 40 11-B2 92**** C0 A8 02 03 45 3C .9»ê..@.²’À¨..E<
0x0020 04 50 0C 02 0C 02 00 25-D1 62 0E 02 00 00 00 00 .P.....%Ñb......
0x0030 00 00 00 00 00 00 00 00-00 00 00 00 FF 00 FF 00 ............ÿ.ÿ.
0x0040 00 00 FF 00 FF 00 00 ..ÿ.ÿ..



0x0000 00 22 75 5C 69 96 00 1F-A7 11 C9 16 08 00 45 00 ."u\i–..§.É...E.
0x0010 00 39 ****F8 68 00 00 40 11-76 14**** C0 A8 02 03 45 3C .9ø[email protected].À¨..E<
0x0020 04 50 0C 02 0C 02 00 25-D1 62 0E 02 00 00 00 00 .P.....%Ñb......
0x0030 00 00 00 00 00 00 00 00-00 00 00 00 FF 00 FF 00 ............ÿ.ÿ.
0x0040 00 00 FF 00 FF 00 00 ..ÿ.ÿ..



That is the second part of the packet. The first part also differs on that line.I am almost 100 percent certain this line contains the data for the game score, time, kills, etc. As of now I'm trying to manipulate the numbers and inject them at the right time and speed. Over injecting might make the data null. Unless they do not have something to stop the data from excessively injecting. Ill find out soon. Just keeping everyone up to date.
(adsbygoogle = window.adsbygoogle || []).push({});
11-29-2009, 03:34 AM #11
bmxdude9
Million Miles Of Fun!
Originally posted by Icey View Post
OMG! bmxdude9 you should be a Moderator of NGU
you answer all questions (you're really interested helping the other ppl)
hmm i got the NETGEAR, so it means i have access to wireless too i got it like this:

With cable:
Channel 1: My brother's PS3
Channel 2: My PS3
Channel 3: My computer
Channel 4:

Wireless:
The laptop

So i don't know, i think at least i understand 50% now, but i still cant find the IP of my PS3 with Wireshark and i dont know how to...


First off thanks, means a lot that some people actually listen and want to learn instead of begging me to do it. Okay idk what OS you have but somewhere in your control panel their when your bridge you MUST bridge TWO LAN/High-speed connections, if you have already done that then great. Also make sure when you sniff that you are NOT doing anything else on either of the two connections bridged(one goes in, one goes out, such as I have my PS3's Connection, along with a wireless adapter connection -btw avoid the adapter as it can complicate things unless you have too)

Now for the IP it should be your PS3's depending how it is set up, but all in all it might be your actual IP so if it matches one of those of the connections set up than your good, some programs allow to see a secondary IP receiving/sending IP which would be like your PS3, look @ your settings but when I have my wireless adapter set up sometime soon(thats what I use to bridge with my other connection as I dont have enough Ethernet locations) I will give you a complete answer to fix, in the meantime Ill try and think.
11-29-2009, 03:54 AM #12
when i do the packet injection i look through most of the packets but wot am i looking for if i want to put my score up a lil bit???
11-29-2009, 04:04 AM #13
bmxdude9
Million Miles Of Fun!
Originally posted by Stammers2 View Post
when i do the packet injection i look through most of the packets but wot am i looking for if i want to put my score up a lil bit???


you will have to look for a packet that is VERY similar each time you get a kill, your score increments etc. Once you found a similar packet that you think is it and that where a few crucial bytes of data change, look at it and try to figure out the offset or how the data changes when it increments/decrements and then make it go to a higher or lower value(dont go by hex #'s as just guessing wont work find the offset of the byte, dont be like negative 1 is f etc, hard to explain.. ) and then try changing the data and injecting to see what happens.

Modding the score packet etc by itself would be hard to find and successfully do but several people have done it or come close. Watch out for the checksum and remember to inject when the packet is actually sent(I would recommended finding the one that is sent to the server telling your account to +1 kills and +150 score if you got a headshot etc)

^would be best to mod that one, send it in a quickie loop a few times, get a headshot and have it inject the modded value.

The following user thanked bmxdude9 for this useful post:

IW_JOSH
11-29-2009, 07:05 AM #14
You must login or register to view this content.
11-29-2009, 12:59 PM #15
Originally posted by bmxdude9 View Post
you will have to look for a packet that is VERY similar each time you get a kill, your score increments etc. Once you found a similar packet that you think is it and that where a few crucial bytes of data change, look at it and try to figure out the offset or how the data changes when it increments/decrements and then make it go to a higher or lower value(dont go by hex #'s as just guessing wont work find the offset of the byte, dont be like negative 1 is f etc, hard to explain.. ) and then try changing the data and injecting to see what happens.

Modding the score packet etc by itself would be hard to find and successfully do but several people have done it or come close. Watch out for the checksum and remember to inject when the packet is actually sent(I would recommended finding the one that is sent to the server telling your account to +1 kills and +150 score if you got a headshot etc)

^would be best to mod that one, send it in a quickie loop a few times, get a headshot and have it inject the modded value.


Every packet i look in i never see numbers but there were some tht had like 200 catche or something like tht so i change the 200 to like 999 and sent it but i dont think it worked.
12-01-2009, 01:09 AM #16
T-Icey
Samurai Poster
Originally posted by bmxdude9 View Post
First off thanks, means a lot that some people actually listen and want to learn instead of begging me to do it. Okay idk what OS you have but somewhere in your control panel their when your bridge you MUST bridge TWO LAN/High-speed connections...

Now for the IP it should be your PS3's depending how it is set up...


^Actually what i need is IWNET

OK so i bridged my lapotop's connection > Local Area connection with Wireless internet Connection, and i put my PS3 with wireless (my laptop too)

So when i open Wireshark what see is this

"Start Capute on interface"
- Marvell Yukon Ethernet Controller
- Microsoft
- Microsoft MAC Bridge Virtual NIC
- MS Tunnel Interface Driver

When i start capturing in Microsoft MAC Bridge Virtual NIC and if iam in NextGenUpdate etc it shows codes about this website but it doesnt show anything about IW4. etc or at least codes like "~The Hint~" by QuantumForce...

So how can i mod MW2 if i cant even capture... Any help? do you think it didnt show anything because when i was killing it was in a private match?
12-03-2009, 10:42 PM #17
Sup ya its killway1 i have mw2 havnt posted in a while but sup
12-03-2009, 10:53 PM #18
Dark Nero
I defeated!
This is all, logic, bin, hex data. l do a lot of this in college

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo