Post: How to boot people on MW2[NOW PUBLIC]
12-06-2009, 03:35 AM #1
bmxdude9
Million Miles Of Fun!
(adsbygoogle = window.adsbygoogle || []).push({}); I made it so I should have the right to do what I want with it, so I decided since I dont want to hear complaining I will pull a tonic move and place this into public hands. I am not responsible for what you do with it but Its not going to be my fault when the game falls. Enjoy people who don't pay I have your back one last time. BOOTING=!Kick Players

Originally posted by another user

Originally posted by bmxdude9
Okay just copy this.... just quote it(also tell me what they think?)


Packet Booting Fun[Premium]
By:Bmxdude9


TESTED AND WORKS

Okay so well recently people have been BEGGING me to rank up their account etc and well premium has been asking for stuff as well, so I thought what the hell lets at least let you guys have something after all as you paid to see this! First off thank you to my buddy Chris for posting this here as personally I dont have premium and I am not sure if I am going to have it anytime soon. Okay so I thought about releasing packet/exploit stuff in here multiple times but I am thinking instead of leaderboard crap I will give you a little fun to play with instead. That fun is something which I find most fun, PACKET BOOTING!

But first what is booting? Well booting for those who dont know is basically where you use corrupt code to kick other players offline with an error etc and well this is a great method to use to boot people, please note it wont always work but it is A LOT better than the public version I released! So lets get started!

..:Requirements::.

1. Already have a bridged network
2. A packet sniffer(wireshark will work, commview etc)
3. A packet builder(to inject, if you have commview you wont need this)
4. Some trial and error
5. This guide!

.::Method to boot other players::.


1.You find a medium sized packet in your packet sniffer -something around 10 lines, it wont be that big in bytes terms (make sure its at least 8 lines!)

2. Edit line FIVE(5) with this data value. Put the first 4 digits as FFFF and now were almost there!

3. Now go to line SEVEN(7) of the packet and put the last 4 digits as FFFF.

4. Then validate the packet to be sent through the checksum

5. Then watch people drop like cockroaches who just got sprayed!

Example(not real) -the data in blue is what I edited. Its an example remember!

    
0x00 00 00 00 00 00 00 00 00 00 00 00 00 ...ascii..
0x01 00 00 00 00 00 00 00 00 00 00 00 00 ...ascii..
0x02 00 00 00 00 00 00 00 00 00 00 00 00 ...ascii..
0x03 00 00 00 00 00 00 00 00 00 00 00 00 ...ascii..
0x04 [COLOR="Blue"]FF FF[/COLOR] 00 00 00 00 00 00 00 00 00 00 ...ascii..
0x05 00 00 00 00 00 00 00 00 00 00 00 00 ...ascii..
0x06 00 00 00 00 00 00 00 00 00 00 [COLOR="Blue"]FF FF[/COLOR] ...ascii..
0x07 00 00 00 00 00 00 00 00 00 00 00 00 ...ascii..


there now just mod the checksum and you can boot people when you inject that! Have fun and remember to NOT leak, also thanks again for Chris for posting this.

Enjoy and if you have a question lemme know(bmxude9)

(adsbygoogle = window.adsbygoogle || []).push({});

The following 4 users say thank you to bmxdude9 for this useful post:

Canada, G3NOCID3, sheeda123, tom2197
12-06-2009, 08:39 AM #11
leukotic
Climbing up the ladder
I've actually gotten a very weird error before, never seen it before. Something like user interface overload (or something like that) it had red writing in it as well.

Now the 10 line packet of data. Where should I obtain this data? While playing in the game or just any ol' random 10 line packet of data will work?

BTW thanks for the post!
12-06-2009, 09:16 AM #12
zirak
Do a barrel roll!
After five six tries of modding the sent packets I've gotten nowhere.

Heres some questions:
How big is an approximate packet size:
Is it a Sent/Recv packet?
Do you send it in a continuous loop?
What IP do you normally send it at (Or what IP would I go under to look for the packet)?

Heres an example:
    0x0000   00 1F A7 45 34 BB 00 13-F7 F0 97 B2 08 00 45 00   ..§E4»..÷ð—²..E.
0x0010 00 8C E8 F7 00 00 34 11-DC A9 AD 44 52 AB C0 A8 .Œè÷..4.Ü©*DR«À¨
0x0020 00 28 0C 04 0C 02 00 78-E8 13 06 02 15 12 9C 00 .(.....xè.....œ.
0x0030 AC 94 45 78 68 AC 66 D9-5F 00 3B 13 90 4B 91 20 ¬”Exh¬fÙ_.;.K‘
0x0040 FF FF D7 CA 21 26 F0 A7-ED 0D 0B F5 A0 44 AF AD ."×Ê!&ð§í..õ*D¯*
0x0050 61 29 67 A4 8C 68 B1 12-2F 89 60 1D C7 17 A5 05 a)g¤Œh±./‰`.Ç.¥.
0x0060 56 05 10 8B F4 9B E6 58-45 DC 96 79 0E 4F FF FF V..‹ô›æXEÜ–y.O«K
0x0070 31 4A E5 C4 9A DC 63 86-AB F2 08 2C B0 ED AB 4F 1JåÄšÜc†«ò.,°í«O
0x0080 9C 49 CF DE C1 CC C6 BB-F1 C3 E0 44 D9 50 8D C2 œIÏÞÁÌÆ»ñÃàDÙPÂ
0x0090 F0 B6 7F 2D 30 9C 92 8C-77 21 ð¶-0œ’Œw!
12-06-2009, 10:03 AM #13
leukotic
Climbing up the ladder
I am confused on the whole checksum thing. Now do I make sure the checksum is identical to what it was before I added the FF's? Or do I just make sure it has a valid checksum? And if I have to make sure its identical how do I do this? Just modify the rest of the data HEX until it matches?

Also, the "make sure it's 10 lines" thing has me confused. I am using Wireshark to capture, then I import the capture using Colasoft packet builder. But it does not show the lines like your post. Really, it just depends on how wide I have the window of the program. Sometimes it will show 2 lines, then if I squish the window horizontally, it shows 30 lines.

EDIT: Also for the FF edits, maybe you could list the specific offsets they need to be placed in. Like offset 0x31, 0x32, 0x46, 0x47.
12-06-2009, 01:40 PM #14
bmxdude9
Million Miles Of Fun!
Originally posted by another user

Heres some questions:
How big is an approximate packet size: depends
Is it a Sent/Recv packet? you sending it back
Do you send it in a continuous loop? no, that would screw things up
What IP do you normally send it at (Or what IP would I go under to look for the packet)? its being sent what do you think?


thats basically it, you have to play around and ACTUALLY BYPASS the checksum for it to work.
12-06-2009, 06:46 PM #15
leukotic
Climbing up the ladder
Originally posted by bmxdude9 View Post
thats basically it, you have to play around and ACTUALLY BYPASS the checksum for it to work.


Bypass the checksum? What? This entire thing makes absolutely no sense and is filled with holes and very vague details.

You're just messing with everybody right? None of this actually works does it?
12-06-2009, 07:10 PM #16
bmxdude9
Million Miles Of Fun!
Originally posted by leukotic View Post
Bypass the checksum? What? This entire thing makes absolutely no sense and is filled with holes and very vague details.

You're just messing with everybody right? None of this actually works does it?


It works, yeah I am being a little vague but I gave people the information they NEED to do it, now they just need to figure it out. You know if I released a tool to do this the game would be destroyed.
12-06-2009, 11:17 PM #17
leukotic
Climbing up the ladder
Originally posted by bmxdude9 View Post
It works, yeah I am being a little vague but I gave people the information they NEED to do it, now they just need to figure it out. You know if I released a tool to do this the game would be destroyed.


I understand. And I don't just want it handed over either, but I am struggling to figure out the basics here.

Stuff like the 10 lines thing, what exactly does this mean? 10 lines isn't really saying anything, and since the FF's need to be put in specific spots, this is the most crucial detail.

Here is a example.

Here is a snapshot of my Colasoft packet builder HEX editor with a packet from MW2. My screen is maximized.


Just by eyeballing this, it appears to be 4 lines worth.

You must login or register to view this content.


Now here is a snapshot of the same packet but my screen is horizontally minimized.


Now it appears as if there is 10 lines.

You must login or register to view this content.



So just by saying 10 lines worth, this really doesn't mean anything at all. It would only mean something if you told us which program you were using to determine how many 'lines' there is. Cause we could pull up that same program and count the lines from the packets as you have counted them. For example, with wireshark when you horizontally minimize the window, it doesn't change the number of lines on the packets. So it would be a somewhat universal concept.

Or you could just list the specific offsets. But without this crucial detail, this hack is impossible to figure out.



Then there is the destination IP question. I would think the only way this would work is if the destination IP is of the person you are trying to 'error out' of the match. Or of the host of the match...otherwise if you just reuse some random packet from some other previous game, the IP will be targeted at somebody else not even in your game anymore. Or maybe it doesn't matter at all, but this is another crucial detail.


And then there is the checksum thing. Maybe others are familiar with this, but I am not. Should the checksum match the checksum it had before you edited it? Or does the checksum just have to be correct and match with the edits you performed?
12-07-2009, 12:55 AM #18
bmxdude9
Million Miles Of Fun!
well about the lines some programs will give you an address offset and if it does do that for you(mine doesn't) then you might want to switch your editor.
12-07-2009, 01:28 AM #19
zirak
Do a barrel roll!
Originally posted by bmxdude9 View Post
well about the lines some programs will give you an address offset and if it does do that for you(mine doesn't) then you might want to switch your editor.


I've always corrected the checksum (Theres a button on CommView that does it) And always modded the SENT packets. But It never worked for me

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo