Idle Heroes 1.18.0.p1 Decrypting Scripts

Extraction and unpacking of game archives and compression, encryption, obfuscation, decoding of unknown files
Arcr0s
Posts: 1
Joined: Mon Jul 22, 2019 1:33 pm

Idle Heroes 1.18.0.p1 Decrypting Scripts

Post by Arcr0s »

Hello ZenHax community,

Game Version: 1.18.0.p1

I recently wanted to start working on a bot for one of my favorite games on mobile. I have read some guides online and figuered out that the game runs on Cocos2d and that its lua script files have been encrypted. I loaded the library .so file into ida pro and poked around. The game does not seem to use the typical xxteaSetSignAndKey function but rather CCMagic.get ? I was not able to identify any key that might have been used to encrypt the lua files with xxtea. All encrypted lua files start with the unencrypted string DHGAMES but ofcourse that does not seem to be the key. Any help would be appreciated, I mainly just want to see the scripts to decrypt the packet traffic of the game.

Example of encrypted lua file:

Code: Select all

DHGAMES~x…€íÀmw6~ß}Ô[&nwÅsì£>ï Ä7=Åöžoµ‘PQo&°¹/ª¼úÚö³7 ¬DßóÔܲs¯È†ô×ЬËDôÍÈÆõ1Ý"QŸRŠ}ŽI¯&2ù–Ó™†‡È~Ènr›år,Êw‡×³Úm j¬qÊ´¾ó
¼‡‡ÃJ(|'å…8Ï „ü<‡˜iòÓ·áBŒãK¹8 uä*ëõer¾Ò⇋öµiVµj"^'e}IérWÝ€/µBesîf¶“|ýv,­ó g˃õÅ{äÖ÷-|¯®ÍsÓWßƆL³{š&ï¡L$Ó3Šªs_dæ`rÈ*Eåå)U¡¿^°é#ŸoOx¡äw|ä4úsB³Aó),¦I4+Ú
|åþÚõ]XZz¬ƒu§$I¯ãÂ8‚)I}PnœÁ.³àrIp.7„à®å¾Ÿ³–½
LЪ›H£›N¤}ÜÿËø|èE£ຐÐyØqsþIÿ¶•%1lûgˆ]ùBwèá½ÿAïÔ´Ç‘óB&PÓùN×Ê=„•†dž‰W¶·‹ ¥u[300Ò^Í©#ˆs¨HSNi>T[ƒÓá–³v<,£ò±¯ôûÄK!¨dæÜ“þÙ'²µÑ­Î-bµš§6÷Û‚Táò0Ž7o¦)xŒ¦ÔãRå.«¹MÄÍ/Ui­@ú&ƒJ•ï˝B[œá<¤`¡©qMmu&o ¼"à®E-ë5ŸÚåÅž@´:ÒÌe=àöÜ“–,×j‡]þÑvê\×À7§œSÚCé‹Ã®Z1±Û©s?ú“3‹™æC8—ÈFÍœÐTøQŠH?>ýíñú *å)Ǭ7œ L4Dõ6œ}W8ª5&>H "ÜÅDõ<yáµØf¬Nž0ãÞähÇu¼Êrél¥RçØ̬ÄZƒ âr–·e.ü벪H0Ï”aÓŠ>
ðßÐ0ÐpåÙˆ-ï,&ƒãJ(lLÇŠÊÂß©8›"ò! ÅÉŽs   °
X+ÂÃW‘QÄ™÷CÛ,ÞÛ„‰æ´`
[¨Þ?B´--çqi&ã/OpåÛÖ;(â^ îK;¨` sA.Ìÿ•3ÀÐÑ<©×”ýÚÈ\;~TZ)´ÙÞЃ£oå×qÔ_ù€ˆR­}èˆßc-+ÁmÖéËb
"[&ãVÀÄŸ¤…©¤   «ŠŸƒä¹ŒÊ{ÐÇ
•ä{ÏzŒŽ‹È³×1ßÖØ?>hú¤¸£šÛþžã×A=%Öúú|ú¥EY†VÛûg É[Q’R±¾å <{‘•©
DioÛ-Ñ;êÆ3ÈlJl‰þòRªwUšuŒó‰ÿß5ÙLÏ£!®›   ñuxääG»Á¾Â¢á”×µßI:ÚÒ£7l   ¨q¬«DF€h_äýÄ%ìuUŠ±oçà<ÅoÓXÀZ3ÄÉ<›1H{p^´àË@ÖøNÆnt¹ltV7LÙ¨qùZû Öº=ƒ_yQÐU.õ¡fÒO]}8DK=7H‚ Aü”àå¨îµ²¦%í5ã1ù֍sÅ®VÒüW»œ"Q n é©-<„ÎÇlÛÊŒú•”.Û2½ç&•„j%Ö'Ü9¨*Öø©_Ë@ð·òL>—­ï·]³…%¬»³áÛSœ›±k )útßÐ\ ígá!Z·ˆü*³ÝDíé$
M€u˳‚H…½N1"è(2Çge7R
'ý2s3žàS‘‡„ý°Ü
Â.Jc‰xêûd±‹­4…[ ‡vh8ïŠC’¿6u¼Jížú#€Šñ~0ª-¢y”æ›s{Éf‹ïTæ7öþ` ïøUÛéç ÷Zµ0LÌÛ}×ÀU€_05ˆ¸ê@Í >(œ q>è¶ÀëùÔ½cešÖ„QÉ%ŸvÈU)šF†ZãÙ-0V®ôÜQú[¤Êò&ª_f†MSÆšYÂŒO†_`ßg~l~ýµhà=5ýļóxx§Ì?ÉÑɬ·ò’nMÓQ
£l~bøO¾ê|”
ªØ½2¯eéÝD—
ƒT ˆ((t®)]E''¨áÑ®˜‹Úd<±‚ß6h–(¬U„ùMVAaÀq€ºONäJ)ÇÎéï… ‰0xÄ©ŸÂÜ2­lu¯‡§,€T¾Œšv´½¦…ú°ç=ဢ›­)‡[ò'çõtýGÍŠ\é+¹êP)ÅbQ¹Ùp¢”uý"b±mô\ö’Bï°|;Eo?‘$~Ü$3ÞH+Zèªjn
–È@êzãÔ ÑÅ#~׳²W¿*6›åX ½bô€ÐIùœR@I~¸z¨á/W7tï±Ì¸R&r5< GO¹j¡ ™ŠaÓ8{ô›q6

q¢ÁXݹ—þ‹딟³ †;zà&E Ó   +ô²q¿í†Ðâ´]ÂWÜ€J¡£ŠáŒWNÆ·Vz+^2¦4S75T…JÑÛO|d<‚'¾Z*ÔÝ|
úŽžº~åãæM+ÅÎ8Ǥñ\3Öþ¾ä<¹P·TÜZãà ]¼q᪛$øc²qhŒ…ü%53
¢Z‰ñŠNú•vÀ¤j6{ø?ÄùçxÒ@
œwÑ–âxŒÛ#J*õ…`¬ÙDß@¹ÓüÑß0à)’‹úýƒ“#³ÃéO%cY¿Ï¡ˆ“¬/‚¹z ùt·(M¬OÒBq$Ab¼ k,|w2pXÕ‡Zge¼¸OîCâ)Ö}þ‹}©êÌ964¥ÈùÀ—v¨ZyŽAÇŠ5N°´º¥wUÚÃN   €gw}Àïîύ NB¼$¯(þT
àåN½Lr—Ê~?‚Ýlò   ^‘±ä°çõC‰dI Mùå¼¥Á=å׬Þ>¦va|ÄLÐë÷'8¾m½t€_]A¦‚ÇŠå…&w‚ÌN¦ ij2aüçuö_xm" €ÜÄm¿Ëµ)5Þo~&NBÜ, çjgG¯"ecà1¹©$”–m‚^ªÞšÈŒ÷ÄÂrïOqxmrÒý? 7ã€Ùí÷{Ûå\¯XSØÑq€Hûo‡–ìi]“|š=K~÷\ý ®ué´   åâ¬ÛDŠWÜËEO¨!PP܍U¶M 0p×Ë!rÅ
8<SSC{~rû0=Wµ5ô³Ÿf@¢¥L’T+ÄrEöِßWGÿ@ke—Ä#,KÞÒ§Þ‹±‘é+Žú/†ëßûÞ—âÔèÑ]o¦Wú5m6Á&ËÏ×   à\Ù“ó[îv |îz¥/yƒCÑʝçé
…À㧢¹Cˆ”ÇE¯ý'y…8dU£´$LÑ‘õ­Á.ql Ïúá{ç>r$ËP_!—’lp‰mËÍl1Rö/øÎ…ö½Kq²>‚Òo‡±¢PdºL†/d‚˜Ï-'¥ 3ê,ÚƲ¯w.ÔÛ¬D´jExñè‹i@;“4= }ºà1ä ÄÙÕž³Õ~I $á+ét2˜Yïn*s£òY/ª&…äŸ|æ3g»’ÂÇÒ£ÐWUäá`¯›ÎªÂ.÷õš2­É9|fHBèû‡‰¼å’9”_.Ì×\7Y1·èCz˜”õXÙ±Xt§èùÃ0eJ‹
FØK©}µ— (Í« ÈHG„Ï0p’R·tÆɱ>þVÍóë(Ûr7îÞÒîæÌîäE .‰6$H]N“·3h
åùéßZ}ÈAÒ<ï—ž`—xxï,Bú$ÙghJ{†÷Úf.Ä”Aö: mË9HGÂnFõCY®kbžkë³B0]   ¥˜½E¼ãª=Tp'“â5Æ\¿£ýzdkÃe–Ûññô
Ð不]ÿðØ‘ªzÉ¥únœî€>…¬¬P{Ã9"`Ðê´
E7ö§5ì×¢b >’"zß¾uØ~®³p÷öC0 °ƒÇJ-¥ç.õÜ ö©¤ÕC²î–jú'»ÒOÍ֐‹1ofL<?¢p P`X·Èª¢««º›NªiÇYíÖƒŸ ].§6$<Àx%}.†bØ‚†Dˆ¾hvdÍd!ïܾâ™èÓÞg S™Ïph‹…ܹôT„NØ Çh
L[ŽŸ}cgiUㅍQõNJìm§¸öîŸ%hÊuÔ2ÈN ás-3¡o7H‹'l?ÛŒeÉBº˜û|¥]¨gÊT‰ÇÀ»'¢žxíàÙõ~^Kì÷¨Ûàè4`l¹ºnƃR#$iìÜå2üPÁb¥8‚¶ÿxgm‡3ݤÂYëÁŧ®Ý°ƒwñÕ¾ÜI{´]Ä%¾ñjëvý
karas
Posts: 6
Joined: Thu Apr 18, 2019 3:24 am

Re: Idle Heroes 1.18.0.p1 Decrypting Scripts

Post by karas »

Any progress?
aluigi
Site Admin
Posts: 12984
Joined: Wed Jul 30, 2014 9:32 pm

Re: Idle Heroes 1.18.0.p1 Decrypting Scripts

Post by aluigi »

Better if you upload the original file.
If it's encrypted there is nothing much we can do without spending time reverse engineering the game.