Jump to content

6 posts in this topic

Recommended Posts

Posted

Intro:
There's a bunch of tries to to decrypting lua but none of it isnt clear enough how to do it. I'm aware that this approach isnt good enough, because too much step that you'll not need to do but i'm still write it instead. Code in this tutorial ofcourse just bunch of copy-pasta stackoverflow.

Prerequisites
1. Frida (optional)
2. Disassembler (IDA, r2, ..)
3. Python (optional) (I'll use python in this tutorial)
4. A little knowledge about this

What will you need to do?
1. Get the KEY for decryption,
2. Write a script for decryption,
3. Edit the lua (Self explanation),
4. Encrypt back the file (Self explaination) (Same as step 2, but you'll encrypt instead of decrypt),
5. PROFIT.

---- Step by step ----

Get the KEY for decryption
There's bunch of way to do it, some of them:
1. XREFS for XXTeaLuaLoader::setXXTeaKey(string), and you can see it clearly. Most used methods among many games.
nJX33Yr.png
2. Use Frida. I'll explain it on 2nd post.
3. http://forum.xda-developers.com/showthread.php?p=12853986#post12853986
4. etc.. You get the idea.

Write a script for decryption
This is an example of use for XXTEA encryption, requirements(xxtea-py)

 
Code (Text):





#!/usr/bin/env python
import xxtea

chiper = open("assets/script/fund.lua", "rb").read()

out = open("out.lua", "wb")

key = b'mrgj'

out.write(xxtea.encrypt(chiper, key))

out.close()END

Example of use of frida (https://github.com/antojoseph/frida-android-hooks)

As described here, 

Opening the lua files with hex editor reveals that they use XXTEA block cipher.

Analyze libjinqu.so and it blatantly shows the following decryption subroutines:
xxtea_decrypt
cocos2d::extra::CCCrypto::decryptXXTEA

Get a pseudocode generator and copy the program in C++.

. We need to put a hook either at xxtea_decrypt or cocos2d::extra::CCCrypto::decryptXXTEA. Then prints out the arguments passed.
We know that args[2] is the one holding the pointer to key from decompile xxtea_decrypt lib.so
Oh5SCFC.png 
Explaination, v9 is the one holding the chiper text, v30 chipertext len(?), v13 pointer to key, v14 is key.length.
Its obvious if we want to leak the key we need to print args[3] bytes at args[2]. This is an example of use for it.

 

#!/usr/bin/env python
import frida
import sys

package_name = "com.gamebau.pq"

def get_messages_from_js(message, data):
            print(message)

jsc = """
Interceptor.attach (Module.findExportByName( "libgame.so", "xxtea_decrypt"), {
    onEnter: function (args) {
        console.log("----------------BEGIN----------------");
        console.log(hexdump(Memory.readByteArray(args[2], 12),{
         offset: 0,
         length: 12,
         header: true,
         ansi: true
        }));
    },
    onLeave: function (retval) {
        console.log("Decrypt:");
        console.log(hexdump(Memory.readByteArray(retval, 16),{
         offset: 0,
         length: 16,
         header: true,
         ansi: true
        }));
        console.log("-----------------END-----------------");   
    }
});
"""

process = frida.get_usb_device().attach(package_name)
script = process.create_script(jsc)
script.on('message',get_messages_from_js)
script.load()
sys.stdin.read()

profit,
gohBm09.png
 
--Update, forgot to mention about this. Another note, some games tries to pack the assets with common file compressor. While loading it, it tries to unpack the assets on stream. As you can see on the image, its PK file header. With simple google search you can deduce its a zip alike compression. Try to extract the decrypted file with 7zip/Winrar/etc.. and you could see the unpacked file.

Image:
gohBm09.png
 
 
Credits: Wobm And Stack Overflow

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Our picks

    • Dungeons and Bags v1.1.0 [ +4 Cheats ] Currency Max
      Modded/Hacked App: Dungeons and Bags By Roshka S.A.
      Bundle ID: play.roshka.minibackpack
      App Store Link: https://apps.apple.com/us/app/dungeons-and-bags/id6752716609?uo=4

      🤩 Hack Features

      - Unlimited Gems
      - Unlimited Battle Stars
      - HP MAX
      - ATK MAX
      • 0 replies
    • Dungeons and Bags v1.1.0 [ +4 Jailed ] Currency Max
      Modded/Hacked App: Dungeons and Bags By Roshka S.A.
      Bundle ID: play.roshka.minibackpack
      App Store Link: https://apps.apple.com/us/app/dungeons-and-bags/id6752716609?uo=4

      🤩 Hack Features

      - Unlimited Gems
      - Unlimited Battle Stars
      - HP MAX
      - ATK MAX
      • 0 replies
    • Domino Stories v1.0.04 [ +8 APK MOD ] Currency Max
      Mod APK Game Name: Domino Stories
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.domino.stories.casual.game&hl=en

       

      🤩 Hack Features

      - Unlimited Coins
      - Unlimited Stars
      - Unlimited Ticket
      - Unlimited Undo
      - Unlimited Gold Bar
      - Unlimited Free Tiles
      - Unlimited Event Currency
      - Unlimited Tokens / Event & Quest

      ⬇️ Android Mod APK Download Link


      Hidden Content

      iOSGods App for Android







       

      📖 Android Installation Instructions

      STEP 1: Download the modded APK file from the link above using your preferred Android browser or download manager.
      STEP 2: Once the download is complete, open your file manager and locate the downloaded .apk file (usually in the Downloads folder).
      STEP 3: Tap the APK file, then select Install. If prompted, enable Install from Unknown Sources in your device settings.
      STEP 3A: If the mod includes an OBB file, extract it if it’s inside an archive. Then move the folder to: /Android/obb/
      STEP 3B: If the mod includes a DATA file, extract it if it’s archived. Then move the folder to: /Android/data/
      STEP 4: Once installed, open the game and toggle your desired cheats & features through the APK mod menu. Enjoy!

       

      NOTE: If you have any questions or issues, read our Frequently Asked Questions topic. If you still need help, post your issue below and we’ll assist you as soon as possible. If the mod works for you, please share your feedback to help other members!

       

      🙌 Credits

      - IK_IK

       

      📷 Cheat Video/Screenshots

      N/A

       

       iOS & iPadOS App Hacks
      If you’re looking for Non-Jailbroken & No Jailbreak required iOS IPA hacks, visit the iOS Game Cheats & Hacks or the iOSGods App for a variety of modded games and apps for non-jailbroken iOS devices.
      • 0 replies
    • Dead Watcher +3 Mods [ Damage & Defence ]
      Mod APK Game Name: Dead Watcher By Entiz Game Studio
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.entizgames.deadwatch

       

      🤩 Hack Features

      - Damage Multiplier
      - Defence Multiplier
      - God Mode
      • 1 reply
    • Domino Stories v1.0.04 [ +8 Jailed ] Currency Max
      Modded/Hacked App: Domino Stories By PERLTEC LTD
      Bundle ID: com.domino.stories.casual.game
      App Store Link: https://apps.apple.com/ph/app/domino-stories/id6754849199?uo=4

      🤩 Hack Features

      - Unlimited Coins
      - Unlimited Stars
      - Unlimited Ticket
      - Unlimited Undo
      - Unlimited Gold Bar
      - Unlimited Free Tiles
      - Unlimited Event Currency
      - Unlimited Tokens / Event & Quest
      • 0 replies
    • Domino Stories v1.0.04 [ +8 Cheats ] Currency Max
      Modded/Hacked App: Domino Stories By PERLTEC LTD
      Bundle ID: com.domino.stories.casual.game
      App Store Link: https://apps.apple.com/ph/app/domino-stories/id6754849199?uo=4

      🤩 Hack Features

      - Unlimited Coins
      - Unlimited Stars
      - Unlimited Ticket
      - Unlimited Undo
      - Unlimited Gold Bar
      - Unlimited Free Tiles
      - Unlimited Event Currency
      - Unlimited Tokens / Event & Quest
      • 1 reply
    • Food Gang v2.0.4 +6 OFFSET
      Modded/Hacked App: Food Gang By Bloop
      Bundle ID: com.bloop.food
      App Store Link: https://apps.apple.com/us/app/food-gang/id1497116240?uo=4


      Hack Feature

      - AI ATK NO
      - VIP Active
      - ADS NO / Rewards Free
      - Unlimited Gems
      - Unlimited Coins
      - Unlimited Tokens Upgrade
      - HP / Just Upgrade Hero
      - ATK / Just Upgrade Hero
      • 1 reply
    • Last King : Survival v1.0.14 [ +8 APK MOD ] Currency Max
      Mod APK Game Name: Last King: Survival
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.kolka.tdgame&hl=en

       

      🤩 Hack Features

      - Auto ADS OFF
      - Unlimited Currency
      - Unlimited Resources
      Hero Stats
      - HP MAX
      - ATK MAX
      - DEF MAX
      - RAGE ATK MAX
      - RAGE Cooldown

       

      ⬇️ Android Mod APK Download Link


      Hidden Content

      iOSGods App for Android







       

      📖 Android Installation Instructions

      STEP 1: Download the modded APK file from the link above using your preferred Android browser or download manager.
      STEP 2: Once the download is complete, open your file manager and locate the downloaded .apk file (usually in the Downloads folder).
      STEP 3: Tap the APK file, then select Install. If prompted, enable Install from Unknown Sources in your device settings.
      STEP 3A: If the mod includes an OBB file, extract it if it’s inside an archive. Then move the folder to: /Android/obb/
      STEP 3B: If the mod includes a DATA file, extract it if it’s archived. Then move the folder to: /Android/data/
      STEP 4: Once installed, open the game and toggle your desired cheats & features through the APK mod menu. Enjoy!

       

      NOTE: If you have any questions or issues, read our Frequently Asked Questions topic. If you still need help, post your issue below and we’ll assist you as soon as possible. If the mod works for you, please share your feedback to help other members!

       

      🙌 Credits

      - IK_IK

       

      📷 Cheat Video/Screenshots

      N/A

       

       iOS & iPadOS App Hacks
      If you’re looking for Non-Jailbroken & No Jailbreak required iOS IPA hacks, visit the iOS Game Cheats & Hacks or the iOSGods App for a variety of modded games and apps for non-jailbroken iOS devices.
      • 0 replies
    • Last King : Survival v1.0.14 [ +8 Cheats ] Currency Max
      Modded/Hacked App: Last King: Survival By Kolka Games SIA
      Bundle ID: com.kolka.tdgame
      App Store Link: https://apps.apple.com/us/app/last-king-survival/id6760551418?uo=4

      🤩 Hack Features

      - Auto ADS OFF
      - Unlimited Currency
      - Unlimited Resources
      Hero Stats
      - HP MAX
      - ATK MAX
      - DEF MAX
      - RAGE ATK MAX
      - RAGE Cooldown
      • 4 replies
    • Last King : Survival v1.0.14 [ +8 Jailed  ] Currency Max
      Modded/Hacked App: Last King: Survival By Kolka Games SIA
      Bundle ID: com.kolka.tdgame
      App Store Link: https://apps.apple.com/us/app/last-king-survival/id6760551418?uo=4

      🤩 Hack Features

      - Auto ADS OFF
      - Unlimited Currency
      - Unlimited Resources
      Hero Stats
      - HP MAX
      - ATK MAX
      - DEF MAX
      - RAGE ATK MAX
      - RAGE Cooldown
      • 5 replies
    • Idle Bloodbound Lord +4 Cheats
      Mod APK Game Name: 
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.idlemaster.lord

       

      🤩 Hack Features

      - Damage Multiplier
      - Defense Multiplier
      - Freeze Currency
      - No ADS

       

      ⬇️ Android Mod APK Download Link


      Hidden Content

      Download via the iOSGods App for Android







       

      📖 Android Installation Instructions

      STEP 1: Download the modded APK file from the link above using your preferred Android browser or download manager.
      STEP 2: Once the download is complete, open your file manager and locate the downloaded .apk file (usually in the Downloads folder).
      STEP 3: Tap the APK file, then select Install. If prompted, enable Install from Unknown Sources in your device settings.
      STEP 3A: If the mod includes an OBB file, extract it if it’s inside an archive. Then move the folder to: /Android/obb/
      STEP 3B: If the mod includes a DATA file, extract it if it’s archived. Then move the folder to: /Android/data/
      STEP 4: Once installed, open the game and toggle your desired cheats & features through the APK mod menu. Enjoy!

       

      NOTE: If you have any questions or issues, read our Frequently Asked Questions topic. If you still need help, post your issue below and we’ll assist you as soon as possible. If the mod works for you, please share your feedback to help other members!

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A

       

       iOS & iPadOS App Hacks
      If you’re looking for Non-Jailbroken & No Jailbreak required iOS IPA hacks, visit the iOS Game Cheats & Hacks or the iOSGods App for a variety of modded games and apps for non-jailbroken iOS devices.
      • 7 replies
    • Mybots: Mech Battle Arena +3 Jailed Cheats
      Modded/Hacked App: Mybots: Mech Battle Arena By BoomBit, Inc.
      Bundle ID: com.my.bots
      App Store Link: https://apps.apple.com/us/app/mybots-mech-battle-arena/id6749895995?uo=4

       

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - Damage Multiplier
      - Defense Multiplier
      - Never Die

       

      ⬇️ iOS Hack Download IPA Link


      Hidden Content

      Download via the iOSGods App







       

      📖 PC Installation Instructions

      STEP 1: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see our iOSGods App IPA Download Tutorial which includes a video example.
      STEP 2: Download Sideloadly and install it on your Windows or Mac.
      STEP 3: Open Sideloadly on your computer, connect your iOS device, and wait until your device name appears in Sideloadly.
      STEP 4: Once your iDevice is recognized, drag the modded .IPA file you downloaded and drop it into the Sideloadly application.
      STEP 5: Enter your Apple Account email, then press “Start.” You’ll then be asked to enter your password. Go ahead and provide the required information.
      STEP 6: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 7: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles / VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 8: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A
      • 8 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines