With evey video my proxy code gets worse and worse. So please don't take it as good example code :D It is just hacked together to work for me. DON'T JUDGE ME!!
@crispy_rw6 жыл бұрын
thats right
@RadiantlyYellow6 жыл бұрын
if it aint broke dont fix it
@lukarolak11606 жыл бұрын
Reminds me of my coding, as time progresses it gets a little bit messy, but functionality is a priority! Also if you got the time, check out my opensource project -> github.com/lukarolak/That-Unity-project
@adrianopinaffo6 жыл бұрын
Man, the amount of information you are sharing with us is so valuable that it won’t matter a bit if your code is not good at all. By the way, you could release these programs somewhere, no?
@viktorstrate6 жыл бұрын
@RadiantlyYellow if it aint too* broke dont fix it
@JordanWiens6 жыл бұрын
One fun note -- the auto item pickup works for other people's drops too! In fact, one person built such a hack and used it during the GitS weekend when we launched the game. We heard complaints from users that drops weren't working and we were worried until we investigated and saw what was happening. Had a good laugh.
@samhobson93346 жыл бұрын
A bear drops an ak47 *Soviet union anthem playing in distance*
@fuchsfalke50636 жыл бұрын
That would be a nice Hack too :D
@Skjoldmc6 жыл бұрын
I guess he... (•_•) ( •_•)>⌐■-■ (⌐■_■) UNARMED IT
@Bravo-oo9vd5 жыл бұрын
I see the Polish WW2 bear Wojtek gathered some friends
@andreerfabbro6 жыл бұрын
I love this series! It should be a standard for KZbin content creation. It’s inspired and inspiring.
@mortenschantz38116 жыл бұрын
The holy handgrenade was a refference to Monty python
@ponocni15 жыл бұрын
Also weapon in worms game.
@TonyFlexPromo5 жыл бұрын
It also appears in Fallout 2 in secret encounter map.
@berthold643 жыл бұрын
the proxy is also written in python
@lacno296 жыл бұрын
Everytime you uploaded a video, I really got exicited. I think this channel is my life now. I always learn new stuff. Keep uploading. Thumbs up!
@Simrasil_6 жыл бұрын
nice I'm loving this series :D
@poryg53502 жыл бұрын
Fun fact. Since movement is done client side, the tcp proxy can be used to fulfill Unbearable revenge on AFK. You simply make code that intercepts your position packets and decreases Z by 200 points. Since positions are handled client side, there's no gravity to fight as the client thinks you're on the ground.
@DynoosHD6 жыл бұрын
I think the other numbers are the directions of the bears. So position (XYZ) rotation (XYZ). Will you implement a aimbot? Or a command that shoots fireballs like a shotgun?
@awangn66006 жыл бұрын
DynoosHD man that would be awesome to watch :D hope he sees your comment and add it to the next video
@6577coolman65776 жыл бұрын
+1 even ESP of some sorts maybe.
@kmatias24673 жыл бұрын
@@6577coolman6577 ESP is client side so he would need to mod the client, ofc he could be able to send something with the proxy that would point to where bears are but it's a million times better and more efficient to do it by modding the client
@intellectualize63546 жыл бұрын
Your channel is amazing, I have no idea how you have the ability to just keep trying to hack something until you finally manage it.
@mischa78236 жыл бұрын
I am a simple man, I see LiveOverflow, I like Ich liebe diese Serie, ich will mehr!
@alexwhite1486 жыл бұрын
I want episodes like this one more often.
@billigerfusel6 жыл бұрын
There is lots of trash with millions of views on KZbin and then there are cherries like this series.
@WikiPeoples6 жыл бұрын
LOVING this series. Big thank you to the channel owner for uploading all this content. Super interesting stuff.
@theowenmccarthy6 жыл бұрын
You should find a way to spawn explosions
@TaohRihze6 жыл бұрын
When you made the resend the fireball, did it spawn from your actor, or from where the actor was when original packet was sent? If it is the 2nd, you could with the knowledge of enemy actor location have a zone wide autokill. start the attack at X,Y,Z + Orientation. This also can give you a way to get that orientation packet figured out.
@threeMetreJim4 жыл бұрын
Pickup Items are definitely _not_ safe when playing multi-player. By guessing drop Id's, you can pick up some other players loot and have it disappear in front of their eyes, if the server does not check which player the request comes from! I actually did something very similar in an online game to accept 'invites' not intended for me, and managed to 'gatecrash' groups - the bug was notified and fixed, but was fun while it lasted. Would have been also good to see multiple fireballs launched at random positions across the island (maybe a ton radiating out from a point - real danger area).
@ItayMegOfficial6 жыл бұрын
Your videos are epic. Especially this series. Making every little part of security research interesting.
@PhilNEvo6 жыл бұрын
I don't know coding. I have no idea what you're doing. But you're still making it exciting to watch, and explaining it in a very educational way, that makes it easily digestable, even for idiots like me xD
@sspoke6 жыл бұрын
Implement with Packets auto kill bears at their x,y,z locations with auto pickup to have a fully functional bot that will clear the whole region in like 5 seconds.
@FMontanari7096 жыл бұрын
The holy hand grenade reminds me of a weapon from the Worms series... I was expecting the "hallelujah" sound when he threw it lol
@oussamalarbi66376 жыл бұрын
pwn adventure it is much educational and u can learn a lot of things its soo amazing u did the right thing playing this game u r videos becomes more interesting after playin and reverse engineering this game this is soo awesome man
@RIPlly5 жыл бұрын
I see German dude talk about very complicated stuff. I subscribe.
@siebrum6 жыл бұрын
This episode you managed to cast a spell to a location, see locations of NPCs AND pick up items. Combine those things and you are able to kill an NPC on spawn and pickup the loot!
@MrAlex-jz4xi6 жыл бұрын
make a force field or something like that (kills all the bears in a radius)
@charliefligg90525 жыл бұрын
The holy hand grenade come from Monty Python and the holy grail
@hoxorious6 жыл бұрын
I love your videos so much. Waiting for next one...
@ishaanverma12686 жыл бұрын
Make a series on networking basics as they are the very fundamentals of hacking. You can cover topics like proxies, dns etc
@xamael19895 жыл бұрын
This makes me happy and helps me sleep
@bennetcx52036 жыл бұрын
With Yaw and Pitch it could be that the devs wanted to save Traffic and shortened the Yaw to the Angle you can look. You cant rotate your head 360° Up and Down ;)
@fabiodefilippo90096 жыл бұрын
I follow you recently but I am already your fan. You are great!
@frognik796 жыл бұрын
You can do a couple of other things now: Make a vacuum hack that changes the mob coords to a certain offset from your character coords allowing you to shoot all mobs in range at one spot. Or since you already have autoloot create a fireball at the coords of all the mobs.
@fuchsfalke50636 жыл бұрын
I think the Mob-Position is Server-Data and not sendable via client
@Draugo6 жыл бұрын
Correction, he can try and make a vacuum. I would assume that clients can only change the positions of their own player and the server would ignore if you try to move the mobs or shoot them where you can't hit them. Since teleporting works however he could make a command to teleport himself right above an enemy and then shooting downwards.
@frognik796 жыл бұрын
Draugo I made an assumption on how he could loot from a far distance so moving mob coords client side wouldn't matter just the damage packet. Usually you need to be within a certain range but some game servers don't check, old mmos like RYL, Maplestory, Windslayer didn't check and Dragon Saga/Dragonica had a rather loose check. My old vac and teleport hack for Dragonica: kzbin.info/www/bejne/fHSnq4ieaLRsnrs The above hack doesn't even use packets just player and mob coord linked list.
@Draugo6 жыл бұрын
That's why I corrected to "he can try" because it depends completely on what the server does. I n the best case the server just waits for a kill package, returns the loot and doesn't check anything. In that case he could just kill every mob after the server tells the ID, check if loot dropped and then autoloot it and just farm by running around. Of course since this is really an CTF exerciser there's no need to make any farming hacks if the flags don't need them. It's not like this is (or is even meant to be) actually a fun game to play as a game.
@anass94875 жыл бұрын
Wow, I'm beginning to like this series
@RomanKisil6 жыл бұрын
Can I subscribe twice?
@Neerajkumar-fv8zx6 жыл бұрын
Going to watch hackers ...😅😅😅
@meh16726 жыл бұрын
This series is the best
@Thorinbur6 жыл бұрын
About the position data: I am almost certain the position and rotation in the packets are bundled together into a Quaternions: en.wikipedia.org/wiki/Quaternions_and_spatial_rotation which allows you to describe position and rotation in a 4 element vector
@Jango19896 жыл бұрын
:O The holy hand grenade of Antioch!
@banjerboefify6 жыл бұрын
MOOORRREEE of these vids! Love them! ❤
@amitbh59873 жыл бұрын
awsome, many thank you
@chaemelion6 жыл бұрын
Just a heads up, the data following the x y z of some objects is almost undoubtedly the pitch and yaw of the creature as floats and perhaps an animation or action state of some kind. Note that simple objects such as the drops that are round and have no facing direction are lacking those details. I'll wager that after it has been unpacked properly, the chances are good that as soon as the object has spawned, the pitch, yaw, state, or some combination of the three may be initially set to 0 before the object begins to wander. [edit] Well, I decided to try it out and unpack those values but I'm getting junk unless the sample size is just too small. Or perhaps we aren't breaking the fields correctly. Oh, and I suspect that extra 0000 at the end of some of the bears' packets is actually another no_op (keepalive?) packet from the server and not another data field.
@oliviadrinkwine14116 жыл бұрын
For the people that don't know. The holy hand grenade was a reference to. Monty python and the holy grail. specifically this scene kzbin.info/www/bejne/h36cc6ykn81lgs0
@oussamalarbi66376 жыл бұрын
bro can u do more hardware reverse engineering coz i really like the way u reverse engineering hardware to why don't u try rtsl-sdr and blade-rf and u know radio hacking and stuff like that amazing videos i swear i can't express the way i feel after watching such amazing educational videos like urs man the way u explain things this is awesome u r one of the best i wish all the best for u man
@Anonymouspock6 жыл бұрын
oussama larbi He will after the next rhme hardware ctf which will be done next February probably?
@oussamalarbi66376 жыл бұрын
Anonymouspock i wish bro
@SlantedVFX6 жыл бұрын
Would be interesting to see you implement an ESP/Radar with this proxy
@victoirevim96986 жыл бұрын
This series is really good. I'm this close to try and hack the game!
@zaneoblaneo76246 жыл бұрын
What do the Holy Hand Grenade's "onShoot" packets look like? Does the client send a velocity/look vector to the server to determine where it goes? Can you spam them via packet spamming? (If you don't know where I'm going with this, if the server isn't doing cooldown checks, and trusts any look/velocity vector, then it might be possible to cover the entire map in Holy Hand Grenades, every proxy tick... ;D )
@triularity6 жыл бұрын
I think the devs should have gone the extra mile and did a timing check between arming the Holy Hand Grenade (press the button) and throwing it (release the button). Bad things would happen if you didn't follow the holy instructions. ;)
@procrast6 жыл бұрын
amazing as usual
@nivelis915 жыл бұрын
You're so inspiring ;) Love your videos!
@hallo8D6 жыл бұрын
i Love the pwn game Videos because I lern how to make game serversxD
@youdonotknowmyname96633 жыл бұрын
If somebody asked me "I want to get into Game-Development, what should I learn first?" My answer would be "Watch this series!" (Don't know why anybody would ask me that, but anyway ...)
@slluxxx2 жыл бұрын
Shouldnt tcp packets get thrown into a buffer before working with them? I am currently working on something like this myself and i noticed that data doesnt have to be exactly what you ask for. The data send can be split up into multiple, or merged into just one packet (imagine the recieved data as [|magic|payloadsize|payload| ) but the size of payload is larger than 4096 or however bytes you have specified to recieve. i am really struggeling to find a good buffer solution that allows me to seek my header information (magic & payloadsize) then check if the actual payload is larger than the recieved packet or buffer and wait for the next packet to resolve everything. there is BytesIO but my while loops dont seem efficient
@KucharJosef6 жыл бұрын
A bear drops an ak47 ... Is this the old Rust?
@skytern18385 жыл бұрын
12:04 Monty Python reference!
@St0RM336 жыл бұрын
this game still has better code than pubg lol
@jonas71116 жыл бұрын
How about if you could analyze the chat packet so that the client could perform proxy commands for example "§send position-packet 192/168/178" or something like that
@Mezbelelik2 жыл бұрын
print 'server[{}]'.format(self.port), e Statements must be separated by newlines or semicolons Pylance [33,27] where am i doing wrong?
@AlexKiraly6 жыл бұрын
Oh yuss another video
@Mynameisfrancesco966 жыл бұрын
Maybe you could also auto loot the Golden eggs by using the id you get when you join without even visiting the eggs locations.
@Infinity71116 жыл бұрын
this series is awesome. please sir, have my sub
@HiSmartAlarms4 жыл бұрын
What editor do you use? It kinda looks like sublime text
@MalcomJPrince6 жыл бұрын
Top work...
@jondoe795 жыл бұрын
Awwwwwesome 👍👍👍
@triblion45432 жыл бұрын
I know the video is pretty old now, but I'm not sure how he managed to get the actual names of the items at 9:14, is anyone able to explain?
@mea5ful6 жыл бұрын
its pretty amazing
@_OOTP_6 жыл бұрын
Holy hand grenade : Monty Python.
@friz64_6 жыл бұрын
i love these videos
@HA7DN6 жыл бұрын
Now you can auto-farm items, if you automatically send shoot packets at enemies Maybe the server does not do any(ammo, mana) checks...
@chrissxMedia6 жыл бұрын
couldn't you also just run the proxy on windows (it's python so it should work) or install a linux distro on an usb stick?
@nuuhishere67524 жыл бұрын
you got very emotional about the hackers easter egg but not the monty python holy hand grenade one... I'm very disapointed
@PsychotherapistSam6 жыл бұрын
Soo, whats your laptop model? I think I have the same
@bennetcx52036 жыл бұрын
Ist es eig möglich in c++ (wie in Java) Module in anderen Programmiersprachen zu laden? Das wäre extrem nützlich, wenn man zusammen mit freunden an einem Hack arbeitet
@oussamalarbi66376 жыл бұрын
just keep the way u r doing things this is mind blowing i feel like u r walking on the steps of geohotz and sami kamkar and a lot af great hackers
@Lambda.Function6 жыл бұрын
Lists are threadsafe in Python, unless you disabled your GIL.
@bind66426 жыл бұрын
I read title "implementing aimbot" xD
@soviut6 жыл бұрын
It would be nice if you disabled your spell check in your text editor for those of us with OCD ;)
@Possible19856 жыл бұрын
Soo, just send Pickup-Packet for the Golden Egg IDs upon login?
@rainerzufall13376 жыл бұрын
And for all of you who want to know the soundtrack of Hackers: kzbin.info/www/bejne/mIeQmYadgZaFbZY
@SakiiR6 жыл бұрын
Yeah ! :) gj
@ponocni15 жыл бұрын
I think multiple same packets was send when they couldnt reach server.
@filipvalentin59455 жыл бұрын
Well, I just saw the movie... pretty SF
@Tayo32346 жыл бұрын
What IDE do you use?
@Tymon00006 жыл бұрын
So as you suggested I watched the Hackers from 1995 and I can't find the flag in it. I'm just a rookie in this hacking thing...
@moog5005 жыл бұрын
Hackers was filmed at my high school :))
@galaxis9124 жыл бұрын
Does this work on Windows 10?
@R07ishere6 жыл бұрын
Love the videos but 12 minutes is too short for this kind of video.
@adygombos44696 жыл бұрын
I didn't understand anything. Enjoyed it nonetheless.
@floatingblaze84056 жыл бұрын
You should program an aimbot, or a killaura.
@DavidSmith-bh6ez6 жыл бұрын
That's not a queue, it's a stack (FIFO vs LIFO).
@mischa78236 жыл бұрын
It's a queue in a non technical way... The messages get pushed into it to wait for sending... :D
@DavidSmith-bh6ez6 жыл бұрын
Mischa Behrend It's not even a queue in a non-technical way. A RL queue is FIFO.
@trontor.67116 жыл бұрын
Can you show us how you would make an aimbot?
@ColtonSpears6 жыл бұрын
I'm betting he will add it in this series but either way aim bots are pretty simple and are the same for most games. It would be a little different for something like this vs CS go because he can get coordinates over TCP rather than memory but the concepts are the same.
@mashmax986 жыл бұрын
Holy Handgranate is from worms :D
@rootabeta90155 жыл бұрын
No it isn't
@madghostek30266 жыл бұрын
Instant click pretty much
@Kugelschrei5 жыл бұрын
Dont get the reference, I hope I can watch the next video as a whole...
@thomasdesouza48066 жыл бұрын
You're german, right?
@dw1s6 жыл бұрын
Can you implement this to PUBG Mobile/PC version, please?
@Spiralem6 жыл бұрын
hmm.. h_respawn prints "reload"
@drews41576 жыл бұрын
Good thing that he is hacking a dead game! *inb4 make a fortnite cheat!*