Some players can see stuff they should not.

This is not a Support area! Discuss about the Server here. Non-Server related discussion goes in Off-Topic Discussion.
Forum rules
READ NOW: L2j Forums Rules of Conduct
JMD
Advanced User
Advanced User
Posts: 1440
Joined: Wed Apr 15, 2009 10:07 am

Some players can see stuff they should not.

Post by JMD »

Some of my players they can tell when im watching them in invisible mode, also they can check inside inventories and other stuff i probably dont know, how is that possible?
User avatar
momo61
Posts: 1648
Joined: Fri Jun 06, 2008 2:05 pm
Location: Europe

Re: Some players can see stuff they should not.

Post by momo61 »

what revisions are you using?
Maybe there is some kind of new exploit the devs didnt bother patching?
JMD
Advanced User
Advanced User
Posts: 1440
Joined: Wed Apr 15, 2009 10:07 am

Re: Some players can see stuff they should not.

Post by JMD »

Im currently using.

L2J Revision 4511
L2JDP Revision 7810

They can also tell how many people are online, i dont know what else they can do.
User avatar
momo61
Posts: 1648
Joined: Fri Jun 06, 2008 2:05 pm
Location: Europe

Re: Some players can see stuff they should not.

Post by momo61 »

maybe it's this? I found it on a famous cheater website. If any l2j dev wants the full link, can send me a pm and ill send it to them. It could be something else though. What you are explaining seems to be a major security issue that needs to get checked immediately. Maybe you should ask the cheaters how they are doing it, and then we could try and fix it.

Anyways, here is what i found on that cheater site:

Hey guys it's been a long time since i've been posting in here... anyways I've been workin at some project and i wanted to show it ya guys

Features:
Decrypt the lineage2 packets
PacketX can listen at any port... as default it's 555
It's able to bypass some tricks people use to get rid of those people who are using L2Phx
Bypass the login/game server ports, PacketX will detect automatically if your ingame or just about to login
Debug the packets
Breakpoints - This is 1 of the most powerful features of PacketX, It's able to modify any packet before a packet has been send to the game server or lineage2 client
So we are able to change anything in the game, and modifying whats in our path
When a breakpoint is triggered your able to modify any data what was about to send/receive
Using the breakpoints could be really fun to play with because any data that was about to send to the server/client
We are able to catch it before it was even send/received
Log players - Your able to get the Object id, name, title, x, y, z, Heading, verhicle Id and much more
Log Npc's - Your able to get the Object Id, Npc Id, Name, Title, X, Y, Z, Heading and much more
Decrypt the packets at native mode - This will decrypt the packets in C++ instead of using the .net framework, It's much faster
Realtime server/client debugging - Your able to see everything what is happening
realtime encryption/decryption log
Redirect the connection of lineage2
Supports multiple clients

Code: Select all

Lineage2 debug console is startedConnection to the PacketX database is successful[Proxy] Listening at port 555[GS] received User Information, object id: -1580383231, player: ῦ憧稻录�[GS] received player account information[GS] received User Information, object id: 270534951, player: DragonZor[GS] Received skill list[GS] Player: BLadyyy, location 82638, 148258, -3472 => 81870, 148099, -3471[GS] Player: NegoFumo, location 83605, 148079, -3403 => 83609, 148071, -3403[GS] Player: Oregom, location 82481, 149041, -3346 => 83104, 148466, -3464[GS] player: DragonZor, said: Welcome to the Gang.[GS] player: DragonZor, said: Vote us daily on http://www.l2gang.com[GS] player: DragonZor, said: All the infoz are on main page and on forum. If you have any question don`t hesitate to post on forum or stress up the GM's. [GS] player: DragonZor, said: In Shout & Hero chat  speak only in ENGLISH.  In the other case you will receive ChatBan 120 min or more.[GS] player: DragonZor, said: Read in forums (trade section) where is allowed to place shops in Giran[GS] Player:  is using a social action: , Social Id: 2[GS] Player: NeXo, location 82930, 148186, -3472 => 82678, 148566, -3472[GS] Player:  is using a social action: , Social Id: 2[GS] Player:  is using a social action: , Social Id: 3[GS] Player: BLadyyy, location 82332, 148194, -3472 => 81596, 148356, -3469[GS] Player:  is using a social action: , Social Id: 3[GS] Player: Oregom, location 82714, 148825, -3472 => 82997, 148383, -3472[GS] Player: NegoFumo, location 83609, 148071, -3403 => 83653, 148011, -3408[GS] Player: SUPERB, location 82467, 149055, -3345 => 82808, 148768, -3472[GS] Player: Qweriop, location 82523, 149066, -3345 => 83120, 148941, -3464[GS] Player: Zeref, location 83546, 148251, -3408 => 83466, 148288, -3409[GS] Player: Oregom, location 82895, 148542, -3472 => 83406, 147990, -3408[GS] Player: BLadyyy, location 81900, 148288, -3472 => 80972, 148538, -3471[GS] selecting target object id: 269232923, loc: 82678, 148566, -3472, target:Blizniak[GS] Player:  is using a social action: , Social Id: 3[GS] Player:  is using a social action: , Social Id: 2[GS] Player: SUPERB, location 82675, 148879, -3472 => 82808, 148768, -3467[GS] Player:  is using a social action: , Social Id: 3[GS] Player: Zeref, location 83466, 148288, -3409 => 83411, 148266, -3408[GS] Player:  is using a social action: , Social Id: 2[GS] selecting target object id: 268477021, loc: 82960, 148974, -3469, target:[GS] Player:  is using a social action: , Social Id: 2[GS] Player: Oregom, location 83068, 148354, -3468 => 83994, 147399, -3408[GS] Player:  is using a social action: , Social Id: 3[GS] Player:  is using a social action: , Social Id: 2[GS] Player:  is using a social action: , Social Id: 2[GS] Updating status for NegoFumo[GS] Updating status for NegoFumo[GS] Player:  is using a social action: , Social Id: 2[GS] Player:  is using a social action: , Social Id: 2[GS] Player:  is using a social action: , Social Id: 2[GS] Player:  is using a social action: , Social Id: 2[GS] Player: AlrightJAVservgo, location 82069, 147536, -3472 => 82152, 147633, -3467[GS] Player: Qweriop, location 83120, 148941, -3464 => 83299, 148911, -3408[GS] Player:  is using a social action: , Social Id: 2[GS] Player: AlrightJAVservgo, location 82137, 147616, -3468 => 82257, 147732, -3472[GS] Player: BLadyyy, location 80972, 148538, -3471 => 79456, 148784, -3536[GS] Player: Oregom, location 83546, 147860, -3408 => 83871, 147386, -3408[GS] Player: AlrightJAVservgo, location 82212, 147689, -3472 => 82314, 147902, -3467[GS] Player: BLadyyy, location 80881, 148552, -3471 => 80688, 148656, -3472[GS] Player:  is using a social action: , Social Id: 3[GS] Player: NeXo, location 82694, 148388, -3472 => 82697, 148409, -3472[GS] selecting target object id: 270104288, loc: 83248, 149297, -3409, target:Leya[GS] selecting target object id: 268476373, loc: 83248, 149297, -3409, target:[GS] Using Skill at target object id: 270104288, target:Leya[GS] Player: BLadyyy, location 80702, 148648, -3472 => 78170, 148493, -3600[GS] selecting target object id: 269750410, loc: 82697, 148409, -3472, target:BufCio[GS] Player:  is using a social action: , Social Id: 2[GS] Player: Qweriop, location 83357, 148710, -3408 => 83332, 148505, -3408[GS] Player: AlrightJAVservgo, location 82297, 147867, -3471 => 82384, 148029, -3472[GS] selecting target object id: 270104288, loc: 83248, 149297, -3409, target:Leya[GS] selecting target object id: 268476373, loc: 83248, 149297, -3409, target:[GS] Using Skill at target object id: 270104288, target:Leya[GS] Player:  is using a social action: , Social Id: 2[GS] Player: AlrightJAVservgo, location 82353, 147971, -3471 => 82325, 148142, -3472[GS] Player: Oregom, location 83781, 147516, -3408 => 84014, 146672, -3408[GS] selecting target object id: 270104288, loc: 83248, 149297, -3409, target:Leya[GS] selecting target object id: 268476373, loc: 83248, 149297, -3409, target:[GS] Player:  is using a social action: , Social Id: 3[GS] Player:  is using a social action: , Social Id: 2[GS] selecting target object id: 270104288, loc: 83248, 149297, -3409, target:Leya[GS] selecting target object id: 268476373, loc: 83248, 149297, -3409, target:[GS] selecting target object id: 268477034, loc: 83332, 148505, -3408, target:[GS] Using Skill at target object id: 270104288, target:Leya[GS] Player:  is using a social action: , Social Id: 4[GS] Player: AlrightJAVservgo, location 82325, 148142, -3472 => 82338, 147949, -3467[GS] Player:  is using a social action: , Social Id: 2[GS] Player: Oregom, location 83866, 147207, -3408 => 84047, 146566, -3408[GS] Player:  is using a social action: , Social Id: 3[GS] Player: AlrightJAVservgo, location 82330, 148063, -3471 => 82291, 147927, -3472[GS] Player:  is using a social action: , Social Id: 2[GS] Player: AlrightJAVservgo, location 82300, 147961, -3471 => 82249, 147857, -3472[GS] Player:  is using a social action: , Social Id: 3[GS] Player:  is using a social action: , Social Id: 2[GS] Player: Oregom, location 83922, 147006, -3408 => 84083, 146517, -3408[GS] Player: AlrightJAVservgo, location 82249, 147857, -3472 => 82130, 147734, -3467[GS] Player: NeXo, location 82697, 148409, -3472 => 82638, 148619, -3472[GS] Player: AlrightJAVservgo, location 82193, 147800, -3470 => 82099, 147714, -3472[GS] Player: Oregom, location 83997, 146778, -3408 => 84277, 146467, -3408[GS] selecting target object id: 268730318, loc: 83416, 147946, -3399, target:M1stirio7[GS] Player:  is using a social action: , Social Id: 3[GS] Player: AlrightJAVservgo, location 82099, 147714, -3472 => 82203, 147692, -3467[GS] Player: Oregom, location 84136, 146623, -3408 => 84413, 146468, -3408[GS] Player: AlrightJAVservgo, location 82189, 147694, -3468 => 82250, 147739, -3472[GS] selecting target object id: 270107169, loc: 82638, 148619, -3472, target:Nrk0[GS] Player: AlrightJAVservgo, location 82250, 147739, -3472 => 82349, 147826, -3467[GS] Player:  is using a social action: , Social Id: 2[GS] Player: Oregom, location 84373, 146490, -3408 => 84965, 146449, -3407[GS] Player: DcC, location 83416, 147946, -3399 => 82959, 148196, -3472[GS] Player:  is using a social action: , Social Id: 3[GS] Player: AlrightJAVservgo, location 82349, 147826, -3467 => 82477, 147903, -3472[GS] Player:  is using a social action: , Social Id: 2[GS] Player: DcC, location 83245, 148039, -3419 => 82903, 148132, -3472[GS] Player: AlrightJAVservgo, location 82416, 147866, -3467 => 82562, 147924, -3472[GS] Player: Oregom, location 84564, 146476, -3408 => 85398, 146467, -3403[GS] Player: AlrightJAVservgo, location 82501, 147900, -3472 => 82683, 147928, -3467[GS] selecting target object id: 268455737, loc: 84691, 146474, -3408, target:[GS] Player: DcC, location 83057, 148089, -3440 => 82756, 147982, -3472[GS] selecting target object id: 268730318, loc: 83218, 148024, -3416, target:M1stirio7[GS] Player:  is using a social action: , Social Id: 3[GS] Player: Oregom, location 84819, 146473, -3408 => 85696, 146464, -3408[GS] Player:  is using a social action: , Social Id: 3[GS] Player: DcC, location 82852, 148016, -3472 => 82088, 147826, -3473[GS] Player:  is using a social action: , Social Id: 2[GS] Player:  is using a social action: , Social Id: 3[GS] Player: AlrightJAVservgo, location 82660, 147925, -3472 => 82849, 148001, -3467[GS] Player:  is using a social action: , Social Id: 2[GS] Player: DcC, location 82737, 147987, -3472 => 82093, 147806, -3473[GS] Player:  is using a social action: , Social Id: 2[GS] Player:  is using a social action: , Social Id: 2[GS] Player: AlrightJAVservgo, location 82757, 147964, -3471 => 83007, 148056, -3472[GS] Player:  is using a social action: , Social Id: 2[GS] Player:  is using a social action: , Social Id: 2[GS] Player: Drack, location 83286, 148459, -3408 => 83374, 148058, -3403[GS] Player: DcC, location 82528, 147928, -3472 => 82096, 147784, -3473[GS] Player:  is using a social action: , Social Id: 2[GS] Player: PsPower, location 82529, 149095, -3345 => 82830, 148837, -3472[GS] Player:  is using a social action: , Social Id: 2[GS] Player: NeXo, location 82638, 148619, -3472 => 82745, 148439, -3472[GS] Player: Drack, location 83349, 148168, -3406 => 83292, 147957, -3416[GS] selecting target object id: 270104288, loc: 83248, 149297, -3409, target:Leya[GS] selecting target object id: 268476373, loc: 83248, 149297, -3409, target:[GS] Player: PsPower, location 82641, 148998, -3385 => 8[GS] Player: AlrightJAVservgo, location 83027, 148094, -3467 => 83186, 148179, -3424[GS] Using Skill at target object id: 270104288, target:Leya[GS] Player: SpreadTheLove, location 83448, 147988, -3399 => 83307, 148168, -3416[GS] Player: DcC, location 82172, 147809, -3472 => 81909, 147802, -3473[GS] Player: NeXo, location 82703, 148508, -3472 => 82725, 148437, -3472[GS] Player: PsPower, location 82709, 148938, -3472 => 83116, 148617, -3464[GS] selecting target object id: 268477027, loc: 83303, 147999, -3416, target:[GS] Player: AlrightJAVservgo, location 83115, 148141, -3457 => 83216, 148224, -3416[GS] Player:  is using a social action: Bow, Social Id: 7[GS] Player: DcC, location 81903, 147858, -3472 => 81526, 148064, -3473[GS] Player: AlrightJAVservgo, location 83211, 148220, -3418 => 83223, 148266, -3416[GS] Player: PsPower, location 82868, 148812, -3472 => 83193, 148613, -3424[GS] Player:  is using a social action: , Social Id: 3[GS] Player: DcC, location 81781, 147924, -3472 => 81266, 148263, -3473[GS] Player: PsPower, location 82934, 148771, -3462 => 83251, 148525, -3416[GS] Player:  is using a social action: , Social Id: 3[GS] Player:  is using a social action: , Social Id: 2[GS] Player: DcC, location 81682, 147988, -3472 => 80958, 148455, -3473

Code: Select all

[GS] Encryption key: E6-7B-1A-2E-86-88-00-1C-C8-27-93-01-A1-6C-31-97[GS] Encryption key: 7E-EF-B4-7D-71-80-11-63-C8-27-93-01-A1-6C-31-97[GS] encrypt key: 7E-EF-B4-7D-71-80-11-63-F7-27-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-21-29-93-01-A1-6C-31-97[GS] encrypt key: 7E-EF-B4-7D-71-80-11-63-0A-28-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-24-29-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-07-2A-93-01-A1-6C-31-97[GS] encrypt key: 7E-EF-B4-7D-71-80-11-63-0D-28-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-B0-2C-93-01-A1-6C-31-97[GS] encrypt key: 7E-EF-B4-7D-71-80-11-63-10-28-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-55-2D-93-01-A1-6C-31-97[GS] encrypt key: 7E-EF-B4-7D-71-80-11-63-13-28-93-01-A1-6C-31-97[GS] encrypt key: 7E-EF-B4-7D-71-80-11-63-7C-28-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-27-30-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-32-30-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-3A-30-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-61-32-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-68-32-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-79-32-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-88-32-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-DD-32-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-D8-35-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-EB-35-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-FA-35-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-85-36-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-4F-37-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-19-38-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-E3-38-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-AD-39-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-77-3A-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-41-3B-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-0B-3C-93-01-A1-6C-31-97[GS] decrypt key: 7E-EF-B4-7D-71-80-11-63-D5-3C-93-01-A1-6C-31-97
User avatar
Ezvra
Posts: 53
Joined: Mon Dec 28, 2009 10:22 pm

Re: Some players can see stuff they should not.

Post by Ezvra »

have you checked those characters access levels ?
JMD
Advanced User
Advanced User
Posts: 1440
Joined: Wed Apr 15, 2009 10:07 am

Re: Some players can see stuff they should not.

Post by JMD »

Ezvra wrote:have you checked those characters access levels ?
Just checked the character tables, nothing weird.
User avatar
momo61
Posts: 1648
Joined: Fri Jun 06, 2008 2:05 pm
Location: Europe

Re: Some players can see stuff they should not.

Post by momo61 »

Did you figure anything out JMD? Did anyone tell you how they did it?
JMD
Advanced User
Advanced User
Posts: 1440
Joined: Wed Apr 15, 2009 10:07 am

Re: Some players can see stuff they should not.

Post by JMD »

So far i heard about a script propably the one mentioned above, also they use l2net to see how many players are online.
User avatar
momo61
Posts: 1648
Joined: Fri Jun 06, 2008 2:05 pm
Location: Europe

Re: Some players can see stuff they should not.

Post by momo61 »

Should that even be possible with l2net? ANY l2jdev?
Onepamopa
Posts: 113
Joined: Thu Jan 14, 2010 6:35 pm
Contact:

Re: Some players can see stuff they should not.

Post by Onepamopa »

That's very interesting. Does it able to work on servers protected by anti-cheat software ?
----------------------------------------------------
ICQ: 287731217
Skype: d.i.dobrev
IRC: Onepamopa
----------------------------------------------------
Sleek
Posts: 112
Joined: Tue Dec 28, 2010 1:11 pm

Re: Some players can see stuff they should not.

Post by Sleek »

There is quite a lot packets hacks that actually work on l2j as it is right now. For example mentioned above would not surprised me if it worked as there is currently no hack fix for that. Also there is bypass hacks and accessLevel hacks.
User avatar
momo61
Posts: 1648
Joined: Fri Jun 06, 2008 2:05 pm
Location: Europe

Re: Some players can see stuff they should not.

Post by momo61 »

I've been talking to old players who have been testing freya servers, and they told me that it's very common now that people can use the newest version of L2Net, which amounts to cheating.
I'll list a few "exploits" you can abuse by using the L2Net programme.

1) Auto-Enchant & Auto-Augment. (You can buy 1000 weapons and 1000 scrolls and it'll continously auto-enchanting until it reaches your desired enchant level)

2) CP/HP Spam (Continously spams CP & HP Potions)

3) Possibly see the GMs in invis mode (Confirmed that there is a function for it in L2Net, but not confirmed by players who report it to me)
4) Possibly see inside inventories of players (confirmed by players for adena, apiga and other items in invents)

Other exploits that might be connected to L2Net's programme:

5) Exploit to stuck passive skills from the forts and territory wars.
webmanix
Posts: 15
Joined: Tue Sep 07, 2010 3:33 am

Re: Some players can see stuff they should not.

Post by webmanix »

It is quite easy to code a script to list all objects i receive from server, so if the server sends me a packet telling me where an invisible gm is, its obvious i will be able to trace him (and if i write a hack for that, i can even see him or make some kind of marker to tell me where he is/should be)

This can be done easily with phx 3.5.33+

Also, the augment/enchant script, i wrote both but, they are not really hacks, just automation.

Note: The augmentation script can lead to a bug where a weapon can have more than 1 augment at once, this include more than one skill also (one weapon, 2~3 skills). Doesnt happen in all servers.

Note 2: Most servers have a time-checking to prevent fast-enchant, so the auto-enchant script has a delay to bypass this limitation. But this is quite useless, since it does not change the enchant rate, i dont consider it a hack at all.
User avatar
momo61
Posts: 1648
Joined: Fri Jun 06, 2008 2:05 pm
Location: Europe

Re: Some players can see stuff they should not.

Post by momo61 »

The exploit to see where a gm is when he is in invis mode is a serious security risk.
Also to see what players have in their inventories.

will an l2jdev take a look at this or not?
User avatar
ThePhoenixBird
L2j Inner Circle
L2j Inner Circle
Posts: 1857
Joined: Fri May 27, 2005 5:11 pm

Re: Some players can see stuff they should not.

Post by ThePhoenixBird »

I will call someone
Post Reply