Sunkill Posted October 28, 2007 Share Posted October 28, 2007 (edited) //Capture Begins Length 00|00|00|00|00|00|00|00|00|00|00|00|00 new pkt line 1. 65|20|20|20|20|50|78|50|20|20|20|5c|22 **See following server reply, then next line** new pkt line 2. 65|20|20|20|20|50|7e|50|20|20|20|5c|22 changes. 6 //Server Reply 1 Length 00|00|00|00|00|00|00|00|00|00|00|00|00 new pkt line 1. 65|20|20|20|20|50|20|50|20|20|7c|5c|22 **See following client reply, then next line** new pkt line 2. 65|20|20|20|20|50|20|50|20|20|76|5c|22 changes. 6 //end //Client Reply to server 1 Length 00|00|00|00|00|00|00|00|00|00|00|00|00 new pkt line 1. 65|20|20|20|20|50|20|50|20|20|20|5c|22 **See following server reply, then next line** new pkt line 2. 65|20|20|20|20|50|20|50|20|20|20|5c|22 changes. No difference occurred ?? //Server Reply 2 new pkt line 1. 50|78|20|65|20|20|50|20|20|5b|20|20|20|20|35 **See following client reply, then next line** new pkt line 2. 50|7e|20|65|20|20|50|20|20|5b|73|20|20|20|70 changes. 6 53 3B //end //Client Reply to server 2 Length 00|00|00|00|00|00|00|00|00|00|00|00|00 new pkt line 1. 65|20|20|20|20|50|20|50|20|20|70|5c|22 **See following server reply, then next line** new pkt line 2. 65|20|20|20|20|50|20|50|20|20|6a|5c|22 changes. 6 I am new to decrypting packets. Before I can begin using auto it how I want I need the patterns used. So whats the rules I can conclude so far? And If I don't have enough data collected, can anyone suggest how I can make my own packet capture that formats the data so I can easily see patterns? What I hand typed out above is easy for me to understand. If your wondering what the last reply is its: P e P [ E w< z C) XF .e or 5020206520205020205b20202020202020204520773c207a2020204329202020202020205846202020202e65 loll. Edited October 28, 2007 by Sunkill Link to comment Share on other sites More sharing options...
alex OF DEATH Posted October 28, 2007 Share Posted October 28, 2007 The way you organized that is hard for me to understand. I basically have no idea what I'm looking at. Link to comment Share on other sites More sharing options...
Sunkill Posted October 28, 2007 Author Share Posted October 28, 2007 I am new to decrypting packets. Before I can begin using auto it how I want I need the patterns used. So whats the rules I can conclude so far? And If I don't have enough data collected, can anyone suggest how I can make my own packet capture that formats the data so I can easily see patterns? What I hand typed out above is easy for me to understand. If your wondering what the last reply is its: P e P [ E w< z C) XF .e or 5020206520205020205b20202020202020204520773c207a2020204329202020202020205846202020202e65 loll. oh sorry. Anyhow the main thing is how do I recognize the patterns packets? Do you have any idea of how I can capture packets and then have them organized? Like maybe 4 options to view the packets captured. option 1 is to see just the client packets sent option 2 is to see just the server packets sent option 3 is to see the client and server packets in two separate columns option 4 is to just see normal set of captured packets going down vertically. Link to comment Share on other sites More sharing options...
Nevin Posted October 28, 2007 Share Posted October 28, 2007 Uhh.Why don't you just use Wireshark or something? Link to comment Share on other sites More sharing options...
Sardith Posted October 28, 2007 Share Posted October 28, 2007 Sunkill, there's a WoW packet sniffer. You could possibly set it up to your needs.Here's the link:WoW packet sniffer [font="Verdana"]Valik:Get it straight - I'm not here to say please, I'm here to help - if my help's not appreciated then lotsa luck, gentlemen.[/font] Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now