Post: I may have a new glitch theory .... But
12-25-2011, 05:25 AM #1
(adsbygoogle = window.adsbygoogle || []).push({}); Guys, ladies and gentlemen

well , i may have a found a way of a new hack that could take place..
even though i got no " great" experience with the "raw data languae" or wtv , i finally got to this:

first of all we need a program called .... WPE PRO . WPE Pro is a packet editor. PermEdit grants system access to any running process. Tsearch is a cheat tool designed to search for parameters in memory.

we need a program (if there is one ) to debug the "raw data form" or wtv language its used in..

i may upload some pictures of how to use wpe pro if you anyone of you wants me too.Enzo

so after using the wpe pro and debugging the language .. we could understand every transaction made in FUT 12 ,therefore if we could intersect that data and put wtv data we need i guess we will having a winner.

Waiting for your comments guys
:beer:

---------- Post added 12-25-2011 at 12:25 AM ---------- Previous post was 12-24-2011 at 10:30 PM ----------

will be* having a winner

Spelling mistake**:p

The following user thanked MathlouthiM for this useful post:

hacxx
12-25-2011, 02:04 PM #11
Originally posted by nay View Post
Nice.........................


I do what i can Winky Winky)

---------- Post added at 09:04 AM ---------- Previous post was at 08:12 AM ----------

Originally posted by Yehwhatever View Post
Everything you do on the internet is send via packages... WPE can intercept these.
Lets say you buy something with your coins for 200. The game send's a package from your console to the server basicly saying you spend 200 for a pack and a package come's back to say you are allowed to.
With WPE you can intercept it, modify 200 to for example 1 and you get the pack for 1 coin.

However, and this is the problem, it wont work. Simple as that.
Ive managed to do it with WoW for a mate (hate the game btw) to duplicate a item. Exploit fixed now though. That was even before servers got certificates...

EA Packets are secured so unless you got their tools you could get any closer but it's easier to hack their servers... Thats how hard it is with WPE.

Now im not saying it's easy to hack their servers, read the sentence again...


youve got a good point their bro ,but its worth giving it a shot .. m still trying to find a decrypting tool for the hex codes though
.

This is what i want to decrypt

E3 A4 53 8B 6C 67 F7 CC B1 97 4D D3 2C 93 02 A2 FD C8 8A 1A 40 A5 26 7E 2D BE 64 70 C1 5C 6D 4A 88 5F B7 60 60 12 81 9A 0F 90 05 7C CA 2D B3 C2 24 42 A2 FA CE 03 44 B7 32 C7 90 2D 6B D0 0A C9 5F 7B 14 95 B8 DE 29 A5 B7 CB 9C 2B 19 70 EF 43 54 E9 F2 EB 53 66 51 03 66 42 9A 97 6A B0 91 C3 99 C1 23 12 EC BF 87 D3 A9 8B C8 90 13 2A 04 7E 53 CB 8E 2D 90 00 AF 64 74 69 04 48 A0 46 7D D4 AE AD D0 AE 7A B2 35 AA 30 4B 67 A0 16 1C 8C 7E 2B 20 19 52 57 DC 44 0E ED 92 6F E4 71 DD 2C 48 C0 B1 FC 1B F5 BF EF AB 3A 2C 98 75 67 4C 92 97 BD 13 78 A0 FE 67 92 97 2B DA 99 86 F6 38 BA CD

$B....D.2..-k..._{....)....+.p.CT...SfQ.fB..j.....#..........*.~S..-...dti.H.F}.....z.5.0Kg....~+ .RW.D...o.q.,H........:,.ugL....x..g..+....8..
12-25-2011, 10:06 PM #12
Originally posted by MathlouthiM View Post
I do what i can Winky Winky)

---------- Post added at 09:04 AM ---------- Previous post was at 08:12 AM ----------



youve got a good point their bro ,but its worth giving it a shot .. m still trying to find a decrypting tool for the hex codes though
.

This is what i want to decrypt

E3 A4 53 8B 6C 67 F7 CC B1 97 4D D3 2C 93 02 A2 FD C8 8A 1A 40 A5 26 7E 2D BE 64 70 C1 5C 6D 4A 88 5F B7 60 60 12 81 9A 0F 90 05 7C CA 2D B3 C2 24 42 A2 FA CE 03 44 B7 32 C7 90 2D 6B D0 0A C9 5F 7B 14 95 B8 DE 29 A5 B7 CB 9C 2B 19 70 EF 43 54 E9 F2 EB 53 66 51 03 66 42 9A 97 6A B0 91 C3 99 C1 23 12 EC BF 87 D3 A9 8B C8 90 13 2A 04 7E 53 CB 8E 2D 90 00 AF 64 74 69 04 48 A0 46 7D D4 AE AD D0 AE 7A B2 35 AA 30 4B 67 A0 16 1C 8C 7E 2B 20 19 52 57 DC 44 0E ED 92 6F E4 71 DD 2C 48 C0 B1 FC 1B F5 BF EF AB 3A 2C 98 75 67 4C 92 97 BD 13 78 A0 FE 67 92 97 2B DA 99 86 F6 38 BA CD

$B....D.2..-k..._{....)....+.p.CT...SfQ.fB..j.....#..........*.~S..-...dti.H.F}.....z.5.0Kg....~+ .RW.D...o.q.,H........:,.ugL....x..g..+....8..


You cant.
Better get around on how to hack a server and stuff and try that... Lol just kidding, dont do that... I didnt say that lol. Seriously, dont!

But seriously, you can not decrypt it let alone edit and inject it... Some highly l33t coders probably can with some sort of reverse engineering or idk what they are blabbing about sometimes, but to be honest(with all respect to coders on here), they arnt here. Or on any other forum for that matter.
12-25-2011, 11:29 PM #13
Default Avatar
and1
Guest
Even if you edit a 400 coin pack to 1 coin, the EA server have these prices set so verify the integrity of the pack.
With TCP headers you would have to fix the checksum then return the packet back.

Tamper Data was patched because those pack numbers were taken off, even if you edit the packet to comply with a 3411 id it would error because it doesn't exist on the server anymore.
12-25-2011, 11:31 PM #14
oG-Modder
Do a barrel roll!
you might be on to something

The following user groaned oG-Modder for this awful post:

Gary-
12-26-2011, 03:11 AM #15
Originally posted by Yehwhatever View Post
You cant.
Better get around on how to hack a server and stuff and try that... Lol just kidding, dont do that... I didnt say that lol. Seriously, dont!

But seriously, you can not decrypt it let alone edit and inject it... Some highly l33t coders probably can with some sort of reverse engineering or idk what they are blabbing about sometimes, but to be honest(with all respect to coders on here), they arnt here. Or on any other forum for that matter.




I know its not a 100% guaranteed but at least this is the only shot we've got for now ,since EA almost patched everything .. i know its hard and even harder than hacking their server .... but at least let us not get from having fun into being criminals that EA is looking for :p loll.. anyway , i will give it my best and i hope i ll find something ... you will be the first to know Winky Winky

---------- Post added at 10:11 PM ---------- Previous post was at 10:08 PM ----------

Originally posted by and1 View Post
Even if you edit a 400 coin pack to 1 coin, the EA server have these prices set so verify the integrity of the pack.
With TCP headers you would have to fix the checksum then return the packet back.

Tamper Data was patched because those pack numbers were taken off, even if you edit the packet to comply with a 3411 id it would error because it doesn't exist on the server anymore.


The things is that this is totally different from tampering the data..
Tampering allows you to edit the type of transaction made and change it to another existing one .... what EA have done is patch that even though its still in the server.
but the WPE PRO method is way different from tampering ... it deals with sockets edit them and apply them after getting a confirmation from the main server ... i don't think EA has already patched this way ,since it never happened to them ... don't forget its only a WebApp so everything is possible .. same as Facebook games or even a bit more complex but ,nothing is perfect there is always a way...Winky Winky
:beer:
12-26-2011, 06:26 AM #16
when theres a will theres a way...

good luck, hopefully you find something
12-26-2011, 11:28 AM #17
Okay guys .....
This is what i got till now ......

First of all you need to know what is an authority message (encoded cap):

00000000 1f 8b 08 00 00 00 00 00 00 03 e4 3d ef 57 db b8 = W
00000010 b2 9f cb 5f a1 f5 dd bd 81 b7 24 26 40 69 9b 10 _ $&@i
00000020 7a 28 85 2e f7 02 e5 92 d0 bd f7 2d 7b 72 14 5b z( . -{r [
00000030 49 5c 1c db 95 6d 42 76 b7 ff fb 9b 91 64 5b 76 I\ mBv d[v
00000040 ec 34 e4 42 db 73 1e 1f ba b1 34 1a cd 8c 46 33 4 B s 4 F3
00000050 a3 d1 8f 5d db ff e1 ed fb a3 de 7f 2e 8f c9 38 ] *. 8
00000060 9a b8 e4 f2 fa cd d9 e9 11 31 ea a6 f9 eb ce 91 1
00000070 69 be ed bd 25 ff fe a5 77 7e 46 9a 8d 2d d2 e3 i % w~F -
00000080 d4 0b 9d c8 f1 3d ea 9a e6 f1 85 41 8c 71 14 05 = A q
00000090 2d d3 9c 4e a7 8d e9 4e c3 e7 23 b3 77 65 de 23 - N N # we #
000000a0 ae 26 36 56 3f eb 91 d6 b2 61 47 b6 71 b0 b6 2f &6V? aG q /
000000b0 3a bc 9f b8 5e d8 29 41 d3 7c f5 ea 95 6c 6d 48 : ^ )A | lmH
000000c0 a0 56 e8 7b 2c ca 81 32 1a 06 3e 8f c2 86 e5 4f V {, 2 > O
000000d0 4c 2f 34 05 84 41 5c ea 8d 3a 06 f3 ea d7 5d d1 L/4 A\ : ]
000000e0 b6 a5 17 1c ac 11 f8 db 1f 33 6a 1f ec 87 16 77 3j w
000000f0 82 88 44 b3 80 75 8c 88 dd 47 e6 47 7a 47 65 a9 D u G GzGe
00000100 71 70 47 39 e9 87 c3 7e 18 51 1e 05 51 67 dd 63 qpG9 ~ Q Qg c
00000110 53 f2 96 46 6c 7d 63 a3 31 62 51 cf 99 c0 cf 7d S Fl}c 1bQ }
00000120 53 c2 4b c4 02 f9 84 45 94 20 9d 75 f6 29 76 ee S K E u )v
00000130 3a c6 91 ef 45 cc 8b ea 3d e8 c8 20 96 fc 52 3d : E = R=
00000140 22 8b 6d 62 8d 29 0f 81 bd 38 1a d6 5f 1a c4 d4 " mb ) 8 _
00000150 b0 45 4e e4 b2 83 e3 43 d2 15 cc 92 ae 6f 59 8c EN C oY
00000160 93 bf c8 c9 e9 c9 21 b9 76 23 67 02 34 91 1e a3 ! v#g 4
00000170 13 28 44 b8 cb f7 57 bd ae 82 db 37 65 fb 14 5f (D W 7e _
00000180 86 d8 75 bc 5b c2 99 db 31 c2 31 60 b6 e2 88 38 u [ 1 1` 8
00000190 40 9b 41 c6 9c 0d 53 41 5b b6 87 82 1e 36 e6 24 @ A SA[ 6 $
000001a0 1e 8a 0e 4c 10 4f e4 58 26 50 31 62 a1 19 b1 49 L O X&P1b I

And this is the Hex format of the same compressed data:

00000000 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 <!DOCTYPE html
00000010 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f PUBLIC "-//W3C//
00000020 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 54 72 DTD XHTML 1.0 Tr
00000030 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 20 ansitional//EN"
00000040 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f "https://www.w3.o
00000050 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 rg/TR/xhtml1/DTD
00000060 2f 78 68 74 6d 6c 31 2d 74 72 61 6e 73 69 74 69 /xhtml1-transiti
00000070 6f 6e 61 6c 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c onal.dtd"> <html
00000080 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 xmlns="https://w
00000090 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 ww.w3.org/1999/x
000000a0 68 74 6d 6c 22 20 78 6d 6c 6e 73 3a 73 6f 6e 65 html" xmlns:sone
000000b0 74 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 65 61 t="https://www.ea
000000c0 73 70 6f 72 74 73 2e 63 6f 6d 2f 6e 73 2f 73 6f sports.com/ns/so
000000d0 6e 65 74 22 20 6c 61 6e 67 3d 22 65 6e 2d 55 53 net" lang="en-US
000000e0 22 20 78 6d 6c 3a 6c 61 6e 67 3d 22 65 6e 2d 55 " xml:lang="en-U
000000f0 53 22 3e 0a 20 20 20 20 3c 68 65 61 64 3e 3c 73 S"> <head><s
00000100 63 72 69 70 74 20 74 79 70 65 3d 22 74 65 78 74 cript type="text
00000110 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 76 61 72 /javascript">var
00000120 20 5f 73 66 5f 73 74 61 72 74 70 74 3d 28 6e 65 _sf_startpt=(ne
00000130 77 20 44 61 74 65 28 29 29 2e 67 65 74 54 69 6d w Date()).getTim
00000140 65 28 29 3c 2f 73 63 72 69 70 74 3e 0a 20 20 20 e()</script>
00000150 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d <meta http-
00000160 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 equiv="Content-T
00000170 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 ype" content=


So in the WPE pro what we receive is the compressed data and not the Hex that could be easily understood and edited even from websites like these ( You must login or register to view this content.)
in "Charles" i found some responses in 4 forms of data and its the hex ,compressed ,Html and raw ....
so the only issue or what i call it " the last step" is to decode the compressed data that we get in the WPE Pro And SCOOOOOREE.
Any-who ,I hope you guys like my topic and i wish deeply that could find a way to Debug or decrypt the compressed data...
Cheers guys
:beer:
Last edited by MathlouthiM ; 12-26-2011 at 11:31 AM.
12-26-2011, 06:43 PM #18
Neymar
I dunno what to say anymore?
I've used WPE Pro before on other things, and I tried it on the web app a few times but didn't get anywhere.
12-26-2011, 07:07 PM #19
Theo Walcott
Do a barrel roll!
Originally posted by Neymar View Post
I've used WPE Pro before on other things, and I tried it on the web app a few times but didn't get anywhere.


True tis: ^^

Copyright © 2024, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo