How To: Reverse and Ruin a Hack

Ok, first off let me tell everyone that I'm not going to tell you where to find the hack that all those idiots have been using lately(even though it should be obvious by now).
Second, this guide has nothing to do with hacking or cheating anyone in anyway(except the hackers, perhaps?).

Alright, so there are a couple of things that have been bothering people on Crossfire lately- one of those things being hacks. So, what were going to be doing is reverse engineering there little hack program to (1) Find out how and what it is modifying/doing and (2) To gain knowledge outside the scope of Crossfire :D.

Here is what your going to need:

Tools that we need are usual:
(Google this stuff and get it) all free downloads.
- OllyDbg 1.10
- ImpREC
- LordPE
- hex editor
- Windows XP,Vista, 7, whatever
- target, protector program(hackers try and protect there own program O_O)

Once you have obtained everything, you need to find the hack and get it's .dll file(dynamic link library) it will probably have an .exe with it as well- usually an injector( a way of getting the hack into the game through security).

Try and open the .dll with Ollydbg. You already know its encrypted/packed with some kind of security program to stop you from getting in :). In this case, it just happens to be enigma protector.

Look up "Unpacking enigma protector" on Google. You will probably need to learn how to manually unpack though.

Well, I think I'm going to stop here because I could go on for pages in the following steps and all you guys really need to do is look up the tutorials for the programs I've listed above. You'll be well on your way to reverse engineering and dealing with their little hack program in no time.

Hope this doesn't get closed down immediately, Good luck all!

Comments

  • This general process works with any .exe or .dll file out there. You might as well try to patch the game yourself, knowing how long Z8 games takes to put patches out...
  • Ok, first off let me tell everyone that I'm not going to tell you where to find the hack that all those idiots have been using lately(even though it should be obvious by now).
    Second, this guide has nothing to do with hacking or cheating anyone in anyway(except the hackers, perhaps?).

    Alright, so there are a couple of things that have been bothering people on Crossfire lately- one of those things being hacks. So, what were going to be doing is reverse engineering there little hack program to (1) Find out how and what it is modifying/doing and (2) To gain knowledge outside the scope of Crossfire :D.

    Here is what your going to need:

    Tools that we need are usual:
    (Google this stuff and get it) all free downloads.
    - OllyDbg 1.10
    - ImpREC
    - LordPE
    - hex editor
    - Windows XP,Vista, 7, whatever
    - target, protector program(hackers try and protect there own program O_O)

    Once you have obtained everything, you need to find the hack and get it's .dll file(dynamic link library) it will probably have an .exe with it as well- usually an injector( a way of getting the hack into the game through security).

    Try and open the .dll with Ollydbg. You already know its encrypted/packed with some kind of security program to stop you from getting in :). In this case, it just happens to be enigma protector.

    Look up "Unpacking enigma protector" on Google. You will probably need to learn how to manually unpack though.

    Well, I think I'm going to stop here because I could go on for pages in the following steps and all you guys really need to do is look up the tutorials for the programs I've listed above. You'll be well on your way to reverse engineering and dealing with their little hack program in no time.

    Hope this doesn't get closed down immediately, Good luck all!

    what is the point?
  • where is auto banned that people were talking about?
  • What a uselss thread since they already know how to unpack a hack...

    And dont go telling (or hinting towards) people finding a hack... thats just reta.rded
This discussion has been closed.