Potential idea for decrypting network data between game and trading post menu

User Tag List

Results 1 to 5 of 5
  1. #1
    darkager's Avatar Private
    Reputation
    1
    Join Date
    Oct 2012
    Posts
    8
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Potential idea for decrypting network data between game and trading post

    This is spawned off of the work I'm doing with the trading post, but I had an idea...

    The communication between the game and the trading post is done via SSL.
    It makes sense to me that the game would use a pre-shared key to establish the secured connection...

    Would make even more sense that this would be stored somewhere in the memory. Might any of you have come by this information already?

    The significance is, if it does establish the SSL connection via pre-shared key, then the client has to store it. It's the only way that makes sense to me to have thousands of clients connecting to the host via secured means. If we can gather that pre-shared key, then we can decrypt the network traffic between our game and the server. With that decrypted, we can garner the information necessary to spoof communication with the trading post and submit buy/sell orders externally.

    Potential idea for decrypting network data between game and trading post
  2. #2
    Xtse's Avatar Member
    Reputation
    9
    Join Date
    Sep 2012
    Posts
    27
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I know you posted this a week ago, but Decrypting SSL traffic with Wireshark, and ways to prevent it « wirewatcher goes over some details on how to decrypt SSL - if the client has a certificate, they're easy enough to find in the executable or libraries.

  3. #3
    easymoad's Avatar Private
    Reputation
    1
    Join Date
    Oct 2012
    Posts
    1
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    While messing around with trading post stuff, I tried MITMing the trading post with a proxy at one point. I believe the game client does not use a pre-shared key and has its own logic for validating the certificate and/or the authority chain. I don't know enough about SSL stuff and haven't spent enough time messing around down this path to tell you definitively though. In the end, it's way easier to just read everything out of process memory

    Edit: I was doing this all on the OSX client. Haven't tried the Windows client yet.
    Last edited by easymoad; 10-25-2012 at 05:48 PM. Reason: can't spell

  4. #4
    zeduckie's Avatar Member
    Reputation
    1
    Join Date
    Mar 2012
    Posts
    4
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Perhaps you should have a look @ Fiddler
    Its a web debugging proxy that logs all HTTPS traffic

  5. #5
    darkager's Avatar Private
    Reputation
    1
    Join Date
    Oct 2012
    Posts
    8
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I made this post before I was aware of Fiddler.
    I was able to decrypt via Fiddler. I made some posts in another thread on here regarding the information I found

Similar Threads

  1. [Buying] Ideas For Game USA Buying All Gold 1.70 per k*
    By ideas4game in forum World of Warcraft Buy Sell Trade
    Replies: 3
    Last Post: 02-26-2011, 12:28 AM
  2. Need Ideas For A Free Game To Play On The Computer
    By Gelormino in forum Gaming Chat
    Replies: 30
    Last Post: 08-02-2007, 01:51 AM
  3. Idea for CE users
    By Zaldion in forum World of Warcraft General
    Replies: 2
    Last Post: 02-04-2007, 01:40 AM
  4. Idea for maybe being able to kill and endgame boss easy
    By Osmose in forum World of Warcraft General
    Replies: 0
    Last Post: 11-25-2006, 05:10 AM
All times are GMT -5. The time now is 01:10 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search