Item Search
     
BG-Wiki Search
+ Reply to Thread
Page 1 of 6 1 2 3 ... LastLast
Results 1 to 20 of 115

Thread: FFXI Apocarypse Nigh?     submit to reddit submit to twitter

  1. #1

    FFXI Apocarypse Nigh?

    For those of you who didn't know, the Encryption code for all FFXI packets was broken today.

    since I know its going to be known soon, I have decided to let everyone know that the ingame packets have been decrypted. I wont nor will anyone else release the decryption code out to the open. Dont expect to see a sniffer out for everyone to use either as I will hand pick only the people I know would not leak it. This is very good news for this project and everyone else will be happy at this and I know this topic will soon be flooded.
    That was a quote by Rz950, one of the people who have been trying to crack it for almost 2 years.

    Basically they can trick the servers into thinking anything they want it to. Several people have witnessed them trick the sever into them having claim on NMs before they even pop. (i.e. it's unclaimed, but everyone will get the "already claimed" message) See that measley 1gil in your delivery box? Hmm, let's tell the server it's 999,999,999g.

    I think if they do leak it and it gets widespread, either A) massive emergency maintanence, or B) ...more emergency maintanence?

    Discuss.

  2. #2
    Banned.

    Join Date
    Dec 2005
    Posts
    15,022
    BG Level
    9

    Sage Sundi says:


    I don't know

  3. #3

    Quote Originally Posted by BRP
    Sage Sundi says:


    I don't know

  4. #4

    Errr wow... Thats amazing...

  5. #5

    oh god, please be real

  6. #6

    Ummm... a) why would they encrypt the packets and b) since you're running the program doing the encrypting (FFXI Client), how could it take you two years to break it and c) this shouldn't allow you to do what you're saying it will unless FFXI servers were written by 2-year olds (and I have it on good authority they were at least 3 when they wrote it.)

  7. #7

    Except they can only trick the server as much as the server is programmed to blindly trust the client.

  8. #8

    The messenger

    I'm just the messenger, no expert.

    on a side-note your sig kicks mucho ass

  9. #9
    Demosthenes11
    Guest

    Are the packets put together with staples?

  10. #10

    Except they can only trick the server as much as the server is programmed to blindly trust the client.
    Good point, I was wondering though, would this make Repower a reality?

  11. #11
    Relic Horn
    Join Date
    Oct 2005
    Posts
    3,144
    BG Level
    7
    FFXI Server
    Unicorn
    WoW Realm
    Shattered Hand

    Heres what I don't get...how does breaking the encryption turn in to you recieving 999,999,999G in your delivery box? Any decent client/server setup can at least prevent that from happening. Allow me to englishify the packets that should be going back and forth

    Client: Whats in my delivery box?
    Server: 5 gil
    Client: Its 999,999,999 gil omg!
    Server: No its not.

    Variables like that are stored on the server, theres no changing them. You can't just tell the server you have more gil than you already do. You can't just 'trick' the server, you'd literally have to find a way to get the authority to edit the gilcount even with the encryption, or find a dupe glitch.

    Edit: Aurik made the exact same post as me a few minutes before me ><

  12. #12

    What this does enable is the creation of standalone apps that communicate with the FFXI servers in some way.

  13. #13

    Quote Originally Posted by Dezzimal
    Heres what I don't get...how does breaking the encryption turn in to you recieving 999,999,999G in your delivery box? Any decent client/server setup can at least prevent that from happening. Allow me to englishify the packets that should be going back and forth

    Client: Whats in my delivery box?
    Server: 5 gil
    Client: Its 999,999,999 gil omg!
    Server: No its not.

    Variables like that are stored on the server, theres no changing them. You can't just tell the server you have more gil than you already do. You can't just 'trick' the server, you'd literally have to find a way to get the authority to edit the gilcount even with the encryption, or find a dupe glitch.

    Edit: Aurik made the exact same post as me a few minutes before me ><
    Hey smartypants, find out if its real This is the most excited ive been about FFXI in years.

  14. #14
    Banned.

    Join Date
    Dec 2005
    Posts
    15,022
    BG Level
    9

    I believe the code was broken about 4 months ago by Cliff no? Isn't this ofn?

  15. #15

    You could always just cut the decryption code wholesale from the FFXI executable as well, if you could find it.

    That's how the first people reversed the battle.net authentication process for diablo2/warcraft3. In fact, I stepped through the code and reversed engineered the password encryption function myself. Took me about 2-3 days.

  16. #16
    Nidhogg
    Join Date
    Oct 2005
    Posts
    3,616
    BG Level
    7
    FFXIV Character
    Glick Wick
    FFXIV Server
    Ultros
    FFXI Server
    Bahamut

    He's not the first to do it, and the game auto-bans you for sending abnormal packets, have fun with that.

  17. #17

    Quote Originally Posted by aurik
    You could always just cut the decryption code wholesale from the FFXI executable as well, if you could find it.

    That's how the first people reversed the battle.net authentication process for diablo2/warcraft3. In fact, I stepped through the code and reversed engineered the password encryption function myself. Took me about 2-3 days.
    What exactly does that do?

  18. #18

    Quote Originally Posted by Axil
    Quote Originally Posted by aurik
    You could always just cut the decryption code wholesale from the FFXI executable as well, if you could find it.

    That's how the first people reversed the battle.net authentication process for diablo2/warcraft3. In fact, I stepped through the code and reversed engineered the password encryption function myself. Took me about 2-3 days.
    What exactly does that do?
    You're going to have to rephrase your question, the one you asked made no sense.

  19. #19

    Quote Originally Posted by aurik
    Quote Originally Posted by Axil
    Quote Originally Posted by aurik
    You could always just cut the decryption code wholesale from the FFXI executable as well, if you could find it.

    That's how the first people reversed the battle.net authentication process for diablo2/warcraft3. In fact, I stepped through the code and reversed engineered the password encryption function myself. Took me about 2-3 days.
    What exactly does that do?
    You're going to have to rephrase your question, the one you asked made no sense.
    What does reverse engineering the authentication process accomplish?

  20. #20

    He's not the first to do it, and the game auto-bans you for sending abnormal packets, have fun with that.
    He's still not banned, and neither are the gilsellers that are using it.

+ Reply to Thread
Page 1 of 6 1 2 3 ... LastLast

Similar Threads

  1. FFXI Model viewer (where is a link)
    By mako in forum FFXI: Everything
    Replies: 5
    Last Post: 2004-12-08, 19:05
  2. ReInstalling FFXI
    By DivinePaladin in forum FFXI: Everything
    Replies: 4
    Last Post: 2004-12-05, 02:22
  3. FFXI Problems HELP PC
    By ChOkOmArU in forum FFXI: Everything
    Replies: 4
    Last Post: 2004-11-19, 16:46
  4. FFXI Websites??
    By Avvesione in forum FFXI: Everything
    Replies: 16
    Last Post: 2004-11-17, 16:39
  5. FFXI matrix spoof
    By Mara in forum FFXI: Everything
    Replies: 2
    Last Post: 2004-11-16, 21:00
  6. Replies: 3
    Last Post: 2004-09-17, 13:51
  7. When in rome..... you cant FFXI
    By in forum FFXI: Everything
    Replies: 11
    Last Post: 2004-07-26, 21:11