Jump to content

6 posts in this topic

Recommended Posts

Posted

Intro:
There's a bunch of tries to to decrypting lua but none of it isnt clear enough how to do it. I'm aware that this approach isnt good enough, because too much step that you'll not need to do but i'm still write it instead. Code in this tutorial ofcourse just bunch of copy-pasta stackoverflow.

Prerequisites
1. Frida (optional)
2. Disassembler (IDA, r2, ..)
3. Python (optional) (I'll use python in this tutorial)
4. A little knowledge about this

What will you need to do?
1. Get the KEY for decryption,
2. Write a script for decryption,
3. Edit the lua (Self explanation),
4. Encrypt back the file (Self explaination) (Same as step 2, but you'll encrypt instead of decrypt),
5. PROFIT.

---- Step by step ----

Get the KEY for decryption
There's bunch of way to do it, some of them:
1. XREFS for XXTeaLuaLoader::setXXTeaKey(string), and you can see it clearly. Most used methods among many games.
nJX33Yr.png
2. Use Frida. I'll explain it on 2nd post.
3. http://forum.xda-developers.com/showthread.php?p=12853986#post12853986
4. etc.. You get the idea.

Write a script for decryption
This is an example of use for XXTEA encryption, requirements(xxtea-py)

 
Code (Text):





#!/usr/bin/env python
import xxtea

chiper = open("assets/script/fund.lua", "rb").read()

out = open("out.lua", "wb")

key = b'mrgj'

out.write(xxtea.encrypt(chiper, key))

out.close()END

Example of use of frida (https://github.com/antojoseph/frida-android-hooks)

As described here, 

Opening the lua files with hex editor reveals that they use XXTEA block cipher.

Analyze libjinqu.so and it blatantly shows the following decryption subroutines:
xxtea_decrypt
cocos2d::extra::CCCrypto::decryptXXTEA

Get a pseudocode generator and copy the program in C++.

. We need to put a hook either at xxtea_decrypt or cocos2d::extra::CCCrypto::decryptXXTEA. Then prints out the arguments passed.
We know that args[2] is the one holding the pointer to key from decompile xxtea_decrypt lib.so
Oh5SCFC.png 
Explaination, v9 is the one holding the chiper text, v30 chipertext len(?), v13 pointer to key, v14 is key.length.
Its obvious if we want to leak the key we need to print args[3] bytes at args[2]. This is an example of use for it.

 

#!/usr/bin/env python
import frida
import sys

package_name = "com.gamebau.pq"

def get_messages_from_js(message, data):
            print(message)

jsc = """
Interceptor.attach (Module.findExportByName( "libgame.so", "xxtea_decrypt"), {
    onEnter: function (args) {
        console.log("----------------BEGIN----------------");
        console.log(hexdump(Memory.readByteArray(args[2], 12),{
         offset: 0,
         length: 12,
         header: true,
         ansi: true
        }));
    },
    onLeave: function (retval) {
        console.log("Decrypt:");
        console.log(hexdump(Memory.readByteArray(retval, 16),{
         offset: 0,
         length: 16,
         header: true,
         ansi: true
        }));
        console.log("-----------------END-----------------");   
    }
});
"""

process = frida.get_usb_device().attach(package_name)
script = process.create_script(jsc)
script.on('message',get_messages_from_js)
script.load()
sys.stdin.read()

profit,
gohBm09.png
 
--Update, forgot to mention about this. Another note, some games tries to pack the assets with common file compressor. While loading it, it tries to unpack the assets on stream. As you can see on the image, its PK file header. With simple google search you can deduce its a zip alike compression. Try to extract the decrypted file with 7zip/Winrar/etc.. and you could see the unpacked file.

Image:
gohBm09.png
 
 
Credits: Wobm And Stack Overflow

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Our picks

    • FAIRY TAIL Wizard Chronicle +2 Jailed Cheats
      Modded/Hacked App: FAIRY TAIL Wizard Chronicle By GOODROID,Inc.
      Bundle ID: jp.co.goodroid.fairy
      App Store Link: https://apps.apple.com/us/app/fairy-tail-wizard-chronicle/id6746717958?uo=4

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - Damage Multiplier
      - Defense Multiplier

       

      ⬇️ iOS Hack Download IPA Link


      Hidden Content

      Download via the iOSGods App







       

      📖 PC Installation Instructions

      STEP 1: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see our iOSGods App IPA Download Tutorial which includes a video example.
      STEP 2: Download Sideloadly and install it on your Windows or Mac.
      STEP 3: Open Sideloadly on your computer, connect your iOS device, and wait until your device name appears in Sideloadly.
      STEP 4: Once your iDevice is recognized, drag the modded .IPA file you downloaded and drop it into the Sideloadly application.
      STEP 5: Enter your Apple Account email, then press “Start.” You’ll then be asked to enter your password. Go ahead and provide the required information.
      STEP 6: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 7: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles / VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 8: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A
        • Agree
        • Winner
        • Like
      • 28 replies
    • FairyTale Quest +2 Jailed Cheats
      Modded/Hacked App: FairyTale Quest By LINE Games
      Bundle ID: com.linegames.fq
      App Store Link: https://apps.apple.com/us/app/fairytale-quest/id6744442106?uo=4

       

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - Damage Multiplier
      - Defense Multiplier

       

      ⬇️ iOS Hack Download IPA Link


      Hidden Content

      Download via the iOSGods App







       

      📖 PC Installation Instructions

      STEP 1: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see our iOSGods App IPA Download Tutorial which includes a video example.
      STEP 2: Download Sideloadly and install it on your Windows or Mac.
      STEP 3: Open Sideloadly on your computer, connect your iOS device, and wait until your device name appears in Sideloadly.
      STEP 4: Once your iDevice is recognized, drag the modded .IPA file you downloaded and drop it into the Sideloadly application.
      STEP 5: Enter your Apple Account email, then press “Start.” You’ll then be asked to enter your password. Go ahead and provide the required information.
      STEP 6: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 7: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles / VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 8: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A
        • Winner
        • Like
      • 11 replies
    • Bounce Defense : Brick Breaker +4 Jailed Cheats
      Modded/Hacked App: Bounce Defense : Brick Breaker By cookapps
      Bundle ID: com.cookapps.bouncedefense
      App Store Link: https://apps.apple.com/us/app/bounce-defense-brick-breaker/id6757737431?uo=4

      🤩 Hack Features

      - Gems Freeze / Increase Instead OF Decrease 
      - Coins Freeze / Increase Instead OF Decrease 
      - Energy Freeze / Increase Instead OF Decrease 
      - Energy 0 / Play Unlimited
      - Chest Buy Free
        • Like
      • 2 replies
    • Bounce Defense : Brick Breaker +4 Cheats
      Modded/Hacked App: Bounce Defense : Brick Breaker By cookapps
      Bundle ID: com.cookapps.bouncedefense
      App Store Link: https://apps.apple.com/us/app/bounce-defense-brick-breaker/id6757737431?uo=4

       

       

      📌 Mod Requirements

      - Jailbroken iPhone or iPad.
      - iGameGod / Filza / iMazing.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak (from Sileo, Cydia or Zebra).

       

      🤩 Hack Features

      - Damage Multiplier
      - Never Die

       

      ⬇️ iOS Hack Download Link


      Hidden Content

      Download Hack







       

      📖 iOS Installation Instructions

      STEP 1: Download the .deb hack file from the link above. Use Safari, Google Chrome or other iOS browsers to download.
      STEP 2: Once the file has downloaded, tap on it and then you will be prompted on whether you want to open the deb with iGameGod or copy it to Filza.
      STEP 3: If needed, tap on the downloaded file again, then select ‘Normal Install’ from the options on your screen.
      STEP 4: Let iGameGod/Filza finish the cheat installation. If it doesn’t install successfully, see the note below.
      STEP 5: Open the game, log in to your iOSGods account when asked, then toggle on the features you want and enjoy!

       

      NOTE: If you have any questions or problems, read our Jailbreak iOS Hack Troubleshooting & Frequently Asked Questions & Answers topic. If you still haven't found a solution, post your issue below and we'll do our best to help! If the hack does work for you, please post your feedback below and help out other fellow members that are encountering issues.

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A

       

      More iOS App Hacks
      If you’re looking for Non-Jailbroken & No Jailbreak required iOS IPA hacks, visit the iOS Game Cheats & Hacks or the iOSGods App for a variety of modded games and apps for non-jailbroken iOS devices.

      Modded Android APKs
      Need modded apps or games for Android? Check out the latest custom APK mods, cheats & more in our Android Section.
        • Winner
      • 3 replies
    • 스페이스 미니언즈: 디펜스 Space Minions: Defense v0.0.41 [ +9 Cheats ] Never Die
      Modded/Hacked App: Space Minions: Defense By Teamsparta Inc.
      Bundle ID: com.TeamSparta.SpaceMinions
      App Store Link: https://apps.apple.com/kr/app/space-minions-defense/id6758454845?uo=4

      🤩 Hack Features

      - Currency / No Need
      - Resources / No Need
      - DMG MAX
      - Never Die
      - Enemy Speed
        • Winner
      • 13 replies
    • 스페이스 미니언즈: 디펜스 Space Minions: Defense v0.0.41 [ +9 Jailed ] Never Die
      Modded/Hacked App: Space Minions: Defense By Teamsparta Inc.
      Bundle ID: com.TeamSparta.SpaceMinions
      App Store Link: https://apps.apple.com/kr/app/space-minions-defense/id6758454845?uo=4

      🤩 Hack Features

      - Currency / No Need
      - Resources / No Need
      - DMG MAX
      - Never Die
      - Enemy Speed
        • Haha
        • Thanks
        • Winner
        • Like
      • 13 replies
    • Gun Hero: Cat Survival Shooter v2.4.2 [ +8 Cheats ] Currency Max
      Modded/Hacked App: Gun Hero: Cat Survival Shooter By Freeplay LLC
      Bundle ID: com.BMGames.GunHero
      App Store Link: https://apps.apple.com/ca/app/gun-hero-cat-survival-shooter/id6751321179?uo=4

      🤩 Hack Features

      - Auto ADS OFF
      - Unlimited Gems / Earn
      - Unlimited Coins / Earn
      - Unlimited ADS Ticket / Earn
      - Unlimited Keys +2 / Earn
      - Unlimited Scrolls / Earn
      - Unlimited HP / AiD Kit Use In Battle
      - Unlimited ATK / Linked
        • Informative
        • Agree
        • Haha
        • Winner
        • Like
      • 16 replies
    • Gun Hero: Cat Survival Shooter v2.4.2 [ +8 Jailed ] Currency Max
      Modded/Hacked App: Gun Hero: Cat Survival Shooter By Freeplay LLC
      Bundle ID: com.BMGames.GunHero
      App Store Link: https://apps.apple.com/ca/app/gun-hero-cat-survival-shooter/id6751321179?uo=4

      🤩 Hack Features

      - Auto ADS OFF
      - Unlimited Gems / Earn
      - Unlimited Coins / Earn
      - Unlimited ADS Ticket / Earn
      - Unlimited Keys +2 / Earn
      - Unlimited Scrolls / Earn
      - Unlimited HP / AiD Kit Use In Battle
      - Unlimited ATK / Linked
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 43 replies
    • Super Heavy Iron Tank v1.1.4 [ +7 Jailed ] Auto Win
      Modded/Hacked App: Super Heavy Iron Tank By Game Duo Co.,Ltd.
      Bundle ID: net.gameduo.vg
      App Store Link: https://apps.apple.com/ph/app/super-heavy-iron-tank/id6757405833?uo=4

      🤩 Hack Features

      - ADS NO / Rewards Free
      - DMG
      - ATK Speed
      ::::: ViP :::::
      - Auto Win
      - Energy Unlimited
      - Auto Skip Wave
      - Quick Supply
        • Thanks
        • Winner
        • Like
      • 7 replies
    • Super Heavy Iron Tank v1.1.4 [ +7 Cheats ] Auto Win
      Modded/Hacked App: Super Heavy Iron Tank By Game Duo Co.,Ltd.
      Bundle ID: net.gameduo.vg
      App Store Link: https://apps.apple.com/ph/app/super-heavy-iron-tank/id6757405833?uo=4

      🤩 Hack Features

      - ADS NO / Rewards Free
      - DMG
      - ATK Speed
      ::::: ViP :::::
      - Energy Unlimited
      - Auto Skip Wave
      - Auto Win
      - Quick Supply
        • Winner
        • Like
      • 5 replies
    • Bloons Card Storm +4 Mods [ Unlimited Cards ]
      Mod APK Game Name: Bloons Card Storm By ninja kiwi
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.ninjakiwi.bloonscardstorm

       

      🤩 Hack Features

      - Unlimited Cards
      - Unlock All Cards
      - Unlock All Cosmetics -> Avatars, Card Backs etc.
      - Unlock All Heroes
        • Like
      • 0 replies
    • Obey Me! - Anime Otome Sim - +2 Jailed Cheats [ Auto Win ]
      Modded/Hacked App: Obey Me! - Anime Otome Sim - By NTT Solmare
      Bundle ID: com.nttsolmare.game.ios.obeyme
      App Store Link: https://apps.apple.com/us/app/obey-me-anime-otome-sim/id1477167654?uo=4

       
       

      🤩 Hack Features

      - Auto Win
      - VIP Enabled
        • Agree
        • Like
      • 3 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines