Game Version: 1.18.0.p1
I recently wanted to start working on a bot for one of my favorite games on mobile. I have read some guides online and figuered out that the game runs on Cocos2d and that its lua script files have been encrypted. I loaded the library .so file into ida pro and poked around. The game does not seem to use the typical xxteaSetSignAndKey function but rather CCMagic.get ? I was not able to identify any key that might have been used to encrypt the lua files with xxtea. All encrypted lua files start with the unencrypted string DHGAMES but ofcourse that does not seem to be the key. Any help would be appreciated, I mainly just want to see the scripts to decrypt the packet traffic of the game.
Example of encrypted lua file:
Code: Select all
DHGAMES~x…€íÀmw6~ß}Ô[&nwÅsì£>ï Ä7=Åöžoµ‘PQo&°¹/ª¼úÚö³7 ¬DßóÔܲs¯È†ô×ЬËDôÍÈÆõ1Ý"QŸRŠ}ŽI¯&2ù–Ó™†‡È~Ènr›år,Êw‡×³Úm j¬qÊ´¾ó
¼‡‡ÃJ(|'å…8Ï„ü<‡˜iòÓ·áBŒãK¹8 uä*ëõer¾Ò⇋öµiVµj"^'e}IérWÝ€/µBesîf¶“|ýv,óg˃õÅ{äÖ÷-|¯®ÍsÓWßƆL³{š&ï¡L$Ó3Šªs_dæ`rÈ*Eåå)U¡¿^°é#ŸoOx¡äw|ä4úsB³Aó),¦I4+Ú
|åþÚõ]XZz¬ƒu§$I¯ãÂ8‚)I}PnœÁ.³àrIp.7„à®å¾Ÿ³–½
LЪ›H£›N¤}ÜÿËø|èE£àºÐyØqsþIÿ¶•%1lûgˆ]ùBwèá½ÿAïÔ´Ç‘óB&PÓùN×Ê=„•†dž‰W¶·‹ ¥u[300Ò^Í©#ˆs¨HSNi>T[ƒÓá–³v<,£ò±¯ôûÄK!¨dæÜ“þÙ'²µÑÎ-bµš§6÷Û‚Táò0Ž7o¦)xŒ¦ÔãRå.«¹MÄÍ/Ui@ú&ƒJ•ïËB[œá<¤`¡©qMmu&o¼"à®E-ë5ŸÚåÅž@´:ÒÌe=àöÜ“–,×j‡]þÑvê\×À7§œSÚCé‹Ã®Z1±Û©s?ú“3‹™æC8—ÈFÍœÐTøQŠH?>ýíñú*å)Ǭ7œ L4Dõ6œ}W8ª5&>H"ÜÅDõ<yáµØf¬Nž0ãÞähÇu¼Êrél¥RçØ̬ÄZƒâr–·e.ü벪H0Ï”aÓŠ>
ðßÐ0ÐpåÙˆ-ï,&ƒãJ(lLÇŠÊÂß©8›"ò! ÅÉŽs °
X+ÂÃW‘QÄ™÷CÛ,ÞÛ„‰æ´`
[¨Þ?B´-Â-çqi&ã/OpåÛÖ;(â^îK;¨` sA.Ìÿ•3ÀÐÑ<©×”ýÚÈ\;~TZ)´ÙÞЃ£oå×qÔ_ù€ˆR}èˆßc-+ÁmÖéËb
"[&ãVÀÄŸ¤…©¤ «ŠŸƒä¹ŒÊ{ÐÇ
•ä{ÏzŒŽ‹È³×1ßÖØ?>hú¤¸£šÛþžã×A=%Öúú|ú¥EY†VÛûgÉ[Q’R±¾å <{‘•©
DioÛ-Ñ;êÆ3ÈlJl‰þòRªwUšuŒó‰ÿß5ÙLÏ£!®› ñuxääG»Á¾Â¢á”×µßI:ÚÒ£7l ¨q¬«DF€h_äýÄ%ìuUŠ±oçà<ÅoÓXÀZ3ÄÉ<›1H{p^´àË@ÖøNÆnt¹ltV7LÙ¨qùZû Öº=ƒ_yQÐU.õ¡fÒO]}8DK=7H‚Aü”àå¨îµ²¦%í5ã1ùÖsÅ®VÒüW»œ"Q né©-<„ÎÇlÛÊŒú•”.Û2½ç&•„j%Ö'Ü9¨*Öø©_Ë@ð·òL>—ï·]³…%¬»³áÛSœ›±k)útßÐ\ígá!Z·ˆü*³ÝDíé$
M€u˳‚H…½N1"è(2Çge7R
'ý2s3žàS‘‡„ý°Ü
Â.Jc‰xêûd±‹4…[ ‡vh8ïŠC’¿6u¼Jížú#€Šñ~0ª-¢y”æ›s{Éf‹ïTæ7öþ` ïøUÛéç ÷Zµ0LÌÛ}×ÀU€_05ˆ¸ê@Í >(œ q>è¶ÀëùÔ½cešÖ„QÉ%ŸvÈU)šF†ZãÙ-0V®ôÜQú[¤Êò&ª_f†MSÆšYÂŒO†_`ßg~l~ýµhà=5ýļóxx§Ì?ÉÑɬ·ò’nMÓQ
£l~bøO¾ê|”
ªØ½2¯eéÝD—
ƒT ˆ((t®)]E''¨áÑ®˜‹Úd<±‚ß6h–(¬U„ùMVAaÀq€ºONäJ)ÇÎéï…‰0xÄ©ŸÂÜ2lu¯‡§,€T¾Œšv´½¦…ú°ç=ဢ›)‡[ò'çõtýGÍŠ\é+¹êP)ÅbQ¹Ùp¢”uý"b±mô\ö’Bï°|;Eo?‘$~Ü$3ÞH+Zèªjn
–È@êzãÔ ÑÅ#~׳²W¿*6›åX½bô€ÐIùœR@I~¸z¨á/W7tï±Ì¸R&r5<GO¹j¡™ŠaÓ8{ô›q6
¶
q¢ÁXݹ—þ‹ë”ź³†;zà&E Ó +ô²q¿í†Ðâ´]ÂWÜ€J¡£ŠáŒWNÆ·Vz+^2¦4S75T…JÑÛO|d<‚'¾Z*ÔÝ|
úŽžº~åãæM+ÅÎ8Ǥñ\3Öþ¾ä<¹P·TÜZãà ]¼q᪛$øc²qhŒ…ü%53
¢Z‰ñŠNú•vÀ¤j6{ø?ÄùçxÒ@
œwÑ–âxŒÛ#J*õ…`¬ÙDß@¹ÓüÑß0à)’‹úýƒ“#³ÃéO%cY¿Ï¡ˆ“¬/‚¹zùt·(M¬OÒBq$Ab¼k,|w2pXÕ‡Zge¼¸OîCâ)Ö}þ‹}©êÌ964¥ÈùÀ—v¨ZyŽAÇŠ5N°´º¥wUÚÃN €gw}ÀïîÏ NB¼$¯(þT
àåN½Lr—Ê~?‚Ýlò ^‘±ä°çõC‰dI Mù弥Á=å׬Þ>¦va|ÄLÐë÷'8¾m½t€_]A¦‚ÇŠå…&w‚ÌN¦ij2aüçuö_xm"€ÜÄm¿Ëµ)5Þo~&NBÜ,çjgG¯"ecà1¹©$”–m‚^ªÞšÈŒ÷ÄÂrïOqxmrÒý?7ã€Ùí÷{Ûå\¯XSØÑq€Hûo‡–ìi]“|š=K~÷\ý ®ué´ åâ¬ÛDŠWÜËEO¨!PPÜU¶M 0p×Ë!rÅ
8<SSC{~rû0=Wµ5ô³Ÿf@¢¥L’T+ÄrEöÙßWGÿ@ke—Ä#,KÞÒ§Þ‹±‘é+Žú/†ëßûÞ—âÔèÑ]o¦Wú5m6Á&ËÏ× à\Ù“ó[îv|îz¥/yƒCÑÊçé
…À㧢¹Cˆ”ÇE¯ý'y…8dU£´$LÑ‘õÁ.qlÏúá{ç>r$ËP_!—’lp‰mËÍl1Rö/øÎ…ö½Kq²>‚Òo‡±¢PdºL†/d‚˜Ï-'¥3ê,ÚƲ¯w.ÔÛ¬D´jExñè‹i@;“4= }ºà1ä ÄÙÕž³Õ~I $á+ét2˜Yïn*s£òY/ª&…äŸ|æ3g»’ÂÇÒ£ÐWUäá`¯›ÎªÂ.÷õš2É9|fHBèû‡‰¼å’9”_.Ì×\7Y1·èCz˜”õXÙ±Xt§èùÃ0eJ‹
FØK©}µ— (Í« ÈHG„Ï0p’R·tÆɱ>þVÍóë(Ûr7îÞÒîæÌîäE.‰6$H]N“·3h
åùéßZ}ÈAÒ<ï—ž`—xxï,Bú$ÙghJ{†÷Úf.Ä”Aö:mË9HGÂnFõCY®kbžkë³B0] ¥˜½E¼ãª=Tp'“â5Æ\¿£ýzdkÃe–Ûññô
Ð不]ÿðØ‘ªzÉ¥únœî€>…¬¬P{Ã9"`Ðê´
E7ö§5ì×¢b>’"zß¾uØ~®³p÷öC0 °ƒÇJ-¥ç.õÜö©¤ÕC²î–jú'»ÒOÍÖ‹1ofL<?¢pP`X·Èª¢««º›NªiÇYíÖƒŸ ].§6$<Àx%}.†bØ‚†Dˆ¾hvdÍd!ïܾâ™èÓÞgS™Ïph‹…ܹôT„NØÇh
L[ŽŸ}cgiUã…QõNJìm§¸öîŸ%hÊuÔ2ÈN ás-3¡o7H‹'l?ÛŒeÉBº˜û|¥]¨gÊT‰ÇÀ»'¢žxíàÙõ~^Kì÷¨Ûàè4`l¹ºnƃR#$iìÜå2üPÁb¥8‚¶ÿxgm‡3ݤÂYëÁŧ®Ý°ƒwñÕ¾ÜI{´]Ä%¾ñjëvý