-
Posts
153 -
Joined
-
Last visited
Everything posted by n1ce0n3
-
Help/Support LF a confident guy with some revesrse knowledge for some help.
n1ce0n3 replied to n1ce0n3's topic in Help & Support
I'm sorry, I solved the issue. The topic can be closed now -
Hi there, I'm currently trying to hack a pretty popular game (not going to tell the name of the game, though, it's pretty new and it has around a milion downloads on the play store ) 1. The game uses LUA, which is packed with some kind of a packer that renamed all the source files into its' hashed names. There's a ton of files like that. (pic1, pic2) The progress I have so far. The game uses LuaJIT-2.1.0-beta3 on top of lua5.1. If I got it right the game uses a 64-bit compiler, since LUA's header is 1B 4C 4A 02 0A, when I compile lua script with a 32bit version of luajit - the header is 1B 4C 4A 02 02, the 64 bit version gives me 1B 4C 4A 02 0A. Okay, so. Each of these files you can see in a screenshot is not just a LUA script. It is a lua script, which is compiled into LuaJIT with it's own name, after that that script gets zipped into a hashed name, but it keeps the lua extension. (e.g. config/Team.lua, becomes a ZIPPed archive "aa/aa70e1b8e38c140d2242f45bb58e2edf.lua". On top of that the zip archive gets XXTEA encrypted. Oh, forgot to mention that the game is built on cocos2d engine. I've managed to recover all the source files (using luajit decompiler doesn't give you the exact sources, but at least it gives you a readable file, which you can look through and actually figure what's going on there.) The problem is that if I modify a decompiled script - pack it the way it was originally packed, most of the times - it fails to work (I think it's because the decompiler doesn't give you the exact source code as it is originally written, since I've tried compilig for all of the architectures available, and most of the time - the game eitehr hangs when it gets to read that file - or doesn't load the section that I've modified like the file is corrupt or something) The game loads cocos2dlua.so library during the startup - and then it unloads the library, so that it doesn't remain in the proccesses' memory. As much as I've tried - I couldn't figure the addresses of the functions I wan. Also, the library has no exports, exports tab in IDA have a single entry, which is ".init_proc". I've located the LUA functions' names in IDA, but since I'm not super confident with IDA, I cannot figure how do I either hook any of these, or how to get their address. They are in the symbols table, but yet again, I have no idea how I can reach them. (pic) I've hooked fopen, fred, fwrite, fgets, fread and most of the other relevant native functions, but the most I could've gotten was the file name that gets loaded. TL:DR I've decompiled all of the games' sources (over 10k LUA files), and the only thing that is left to do is to somehow execute luaL_loadstring or luaL_loadfile on my own. I've spent quite some time on that and honestly I am out of ideas can I get what I'm trying to. I even tried pattern scanning the binary and all its' libraries to get either of the functions, basically, any lua function - had no success so far. I'll really appreciate any help I can get at this point. Feel free to reach me out messages so then we can get in touch via discord or any way you'll prefer. Thanks in advance. The game's binary is actually a "split installer" as they call it, it has both ARM and x86 libraries within it's content (even every lua script has another version of itself for another architecture). That prevents me from loading the binary manually into the process , since it gives me an error: Error: dlopen failed: "/data/local/tmp/libcocos2dlua.so" has unexpected e_machine: 183 (EM_AARCH64)
- 1 reply
-
- 1
-
-
DIY Hack *VideoAdsSpeed* Tweak - Speed Up Video Ads
n1ce0n3 replied to Ahmedoo94 's topic in DIY Cheats
1 -
Help/Support Il2cppdumper online issue: Metadata file not found or encrypted
n1ce0n3 replied to GinsuDev's topic in Help & Support
That depends. If you're using web dumper - you can disable that in the configuration (https://vimeo.com/659099435) If you're using local binaries - it should be configurable within the config.json -
Help/Support Il2cppdumper online issue: Metadata file not found or encrypted
n1ce0n3 replied to GinsuDev's topic in Help & Support
You can to disable DLL's building. This way you'll have just dump.cs to navigate, but most of the times it works for me. -
Hi there guys, It's been a while since I did mod something for iOS, please, let me know what I'm doing wrong here. Below is the top of my Tweak.xm #import "Macros.h" /*********************************************************** INSIDE THE FUNCTION BELOW YOU'LL HAVE TO ADD YOUR SWITCHES! ***********************************************************/ void(*Load)(void *this_) = (void(*) (void *))getRealOffset("0x101D46508"); void(*ctor0)(void *this_) = (void(*) (void *))getRealOffset("0x101DFA0B4"); void(*ctor1)(void *this_) = (void(*) (void *))getRealOffset("0x101D4752C"); void(*ctor2)(void *this_) = (void(*) (void *))getRealOffset("0x101D475C0"); void(*ctor3)(void *this_) = (void(*) (void *))getRealOffset("0x10247B024"); void(*ctor4)(void *this_) = (void(*) (void *))getRealOffset("0x10247B610"); void(*ctor5)(void *this_) = (void(*) (void *))getRealOffset("0x101B75B94"); void(*ctor6)(void *this_) = (void(*) (void *))getRealOffset("0x101E26324"); void(*OnGui)(void *this_) = (void(*) (void *))getRealOffset("0x101D46B6C"); void (*oldBattle)(void *e); void onBattle(void *e){ if (e != NULL) { if ([switches isSwitchOn:NSSENCRYPT("onBattle")]) { ctor0(e); ctor1(e); ctor2(e); ctor3(e); ctor4(e); ctor5(e); ctor6(e); Load(e); OnGui(e); return oldBattle(e); } else return oldBattle(e); } } void setup() { [switches addSwitch:NSSENCRYPT("onBattle") description:NSSENCRYPT("onBattle") ]; HOOK(ENCRYPTOFFSET("0x101C6B714"), onBattle, oldBattle); } I'm not C guy, so I don't completely understand the 'void(*ctor5)(void *this_) = (void(*) (void *))getRealOffset("0x101B75B94");' structure, but it used to work pretty much like that in the old days. The mod menu I'm using is this one: https://github.com/joeyjurjens/iOS-Mod-Menu-Template-for-Theos It is mentioned in the repo's readme that A quick note before showing all the switch examples; You can and should encrypt offsets, hexes, c-strings and NSStrings. Below you can find the proper syntax per string-type. ENCRYPTOFFSET("0x10047FD90") However, the template tweak.xm doesn't have any "HOOK's" or getting void from an existing pointer into a variable (?not sure if that makes sense) Basically, what I'm trying to do is: There is a function, e.g. killAll with the address 0x1337FFFF and a Battle Update function on another address. First I need to get the killAll function from an address. Earlier, I would do something like that (void(*killAll)(void *instance) = (void (*)(void*))getRealOffset(0x1337FFFF); Nowadays, I'm not sure about these things and would love you to help me figure: 1.Whether that is going to work or not 2. Should I do getRealOffset(0x1337FFFF) or getRealOffset(ENCRYPTOFFSET("0x1337FFFF")); 3. Should I add the ENCRYPTOFFSET part in the HOOK at the very end of my code 4. Anything else I'm missing or doing wrong. Also, according to my logic - these two codes below should result in the same if ([switches isSwitchOn:NSSENCRYPT("onBattle")]) { ctor0(e); ctor1(e); ctor2(e); ctor3(e); ctor4(e); ctor5(e); ctor6(e); Load(e); OnGui(e); return oldBattle(e); } else return oldBattle(e); } or if ([switches isSwitchOn:NSSENCRYPT("onBattle")]) { ctor0(e); ctor1(e); ctor2(e); ctor3(e); ctor4(e); ctor5(e); ctor6(e); Load(e); OnGui(e); } return oldBattle(e); } Just wanted to make sure about the last one too. Thanks in advance
-
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
Updated -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
Zzz, so many updates. I'll update the mod in a few hours -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
I think they fixed that, I can't find a way to make it work, so I'll upload another version without that function. -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
Updated to 3.0.2 -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
Sorry, I've had no access to my jailbroken phone for a while. Updated to 2.0.12 -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
use flexdecrypt or something like that to decrypt the UnityFramework file and use it instead of the binary in the dumper -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
I did try a lot of different functions, but most of them dont work -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
Dump the Frameworks/UnityFramework.framework/UnityFramework file without building DLLs or it breaks afaik p.s. updated -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
Updated -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
Welp, my game was working fine on the previous version without updating it, I'll update it in a bit then -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
It is updated and working just fine for me -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
Updated again 😊 -
Mod Menu Hack [ARM64] Auto Brawl Chess:Battle Royale v. 3.0,11
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
Updated -
https://apps.apple.com/us/app/auto-brawl-chess-battle-royale/id1495162677 You might get the "network disconnected" error after the match, but it doesn't matter at all, since you still get all rewards after the match whether you get that error or not, so you can just click 'reconnect' and ignore the error. Mod Requirements: - Jailbroken iPhone/iPad/iPod Touch. - iFile / Filza / iFunBox / iTools or any other file managers for iOS. - Cydia Substrate or Substitute. - PreferenceLoader (from Cydia or Sileo). Hack Features: - Extra hero unlocked (Barbatos) - Chess Pass rewards available Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/forum/79-no-jailbreak-section/ Modded Android APK(s): https://iosgods.com/forum/68-android-section/ For more fun, check out the Club(s): https://iosgods.com/clubs/ iOS Hack Download Link: [Hidden Content] Installation Instructions: STEP 1: Download the .deb Cydia hack file from the link above. STEP 2: Copy the file over to your iDevice using any of the file managers mentioned above or skip this step if you're downloading from your iDevice. STEP 3: Using iFile or Filza, browse to where you saved the downloaded .deb file and tap on it. STEP 4: Once you tap on the file, you will then need to press on 'Installer' or 'Install' from the options on your screen. STEP 5: Let iFile / Filza finish the cheat installation. Make sure it successfully installs, otherwise see the note below. STEP 6: Now open your iDevice settings and scroll down until you see the settings for this cheat and tap on it. If the hack is a Mod Menu, the cheat features can be toggled in-game. STEP 7: Turn on the features you want and play the game. You may need to follow further instructions inside the hack's popup in-game. NOTE: If you have any questions or problems, read our Troubleshooting topic & Frequently Asked Questions topic. If you still haven't found a solution, post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues. Credits: - n1ce0n3 Cheat Video/Screenshots: N/A
- 127 replies
-
- 154
-
-
-
-
-
-
-
Mod Menu Hack [ARM64] Dead Spreading: Survival v.1.0.44
n1ce0n3 replied to n1ce0n3's topic in Free Jailbreak Cheats
Thanks 😊 -
Mod Menu Hack [ARM64] Dead Spreading: Survival v.1.0.44
n1ce0n3 posted a topic in Free Jailbreak Cheats
https://apps.apple.com/us/app/dead-spreading-survival/id1476914457 Mod Requirements: - Jailbroken iPhone/iPad/iPod Touch. - iFile / Filza / iFunBox / iTools or any other file managers for iOS. - Cydia Substrate or Substitute. - PreferenceLoader (from Cydia or Sileo). Hack Features: - VIP Features unlocked Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/forum/79-no-jailbreak-section/ Modded Android APK(s): https://iosgods.com/forum/68-android-section/ For more fun, check out the Club(s): https://iosgods.com/clubs/ iOS Hack Download Link: [Hidden Content] Installation Instructions: STEP 1: Download the .deb Cydia hack file from the link above. STEP 2: Copy the file over to your iDevice using any of the file managers mentioned above or skip this step if you're downloading from your iDevice. STEP 3: Using iFile or Filza, browse to where you saved the downloaded .deb file and tap on it. STEP 4: Once you tap on the file, you will then need to press on 'Installer' or 'Install' from the options on your screen. STEP 5: Let iFile / Filza finish the cheat installation. Make sure it successfully installs, otherwise see the note below. STEP 6: Now open your iDevice settings and scroll down until you see the settings for this cheat and tap on it. If the hack is a Mod Menu, the cheat features can be toggled in-game. STEP 7: Turn on the features you want and play the game. You may need to follow further instructions inside the hack's popup in-game. NOTE: If you have any questions or problems, read our Troubleshooting topic & Frequently Asked Questions topic. If you still haven't found a solution, post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues. Credits: - n1ce0n3 Cheat Video/Screenshots: N/A- 44 replies
-
- 56
-
-
-
-
-
-
-
Can any1 help me, I'm looking for a way to make a button or an empty switch inside the mod menu, and by clicking on it to call a function e.g. void(*ctor)(void *instance)= (void(*) (void *))getRealOffset(0x135CDD8); on that button\switch click I want it to execute ctor(instance); and I cant seem to find a way to do it