Heroes of Might and Magic V – Hammers of Bait and Switch
madeupexplorations.wordpress.com
madeupexplorations.wordpress.com
I remember once, a few years back, there was this website where I was supposed to submit something, only that the submission page couldn't load. My friend thought that that was the end of it, but I decided to try to poke around.
Back then I was quite unacquainted with http but I started with what I knew, downloading the page source, figuring out what was the link or call that was failing, then testing it with curl. I eventually managed to figure out that the problem was caused by a missing header in the http request so I installed some random browser extension that patched http requests and voila, it worked!
Still remember the amazing feeling when the page loaded. My friend thought I was a wizard
Only it was behaving like I wasn't authorized to use it (despite being the registered owner of the servers), and I couldn't find any documentation on what groups it wanted me in.
Take a quick glance at the js, and it's doing AD lookups from my client, via an unofficial AD-REST endpoint everyone used, and then using the result.
So easy enough to just return what it's looking for and change my server's schedules as desired.
But hmm... I wonder if it works for the admin-looking group? Yup. Of course it does.
Ping it over to a friend who works in appsec, they poke it for awhile, and figure out (a) with admin permissions this tool can change the patch schedule of everything (e.g. AD domain controllers) & (b) the same pattern of client-checks was used on a lot of other tools that team built.
So I threw some poor team's roadmap into disarray, but a little curiosity on my part helped improve our security posture.
https://docs.microsoft.com/en-us/windows/win32/winprog64/reg...
Presumably this is happening due to this being an old 32-bit game running on 64-bit Windows. The WOW in there stands for "Windows on Windows."
I'm not going to say they're the worst, and they certainly work, but they're also pretty obtuse and "Why would you design a thing like that?"
From memory of the era, the 32/64 bit client transition seemed a bit rushed when Intel had long decreed no home users would need 64-bit, and then AMD promptly started selling the Athlon 64 to anyone who would buy one.
So maybe just time pressure?
Ubisoft changed the reg key of the base game from it's retail key to "Uplay Install 87" and the expansion had no idea to look for that key at all. If you used the Ubisoft copy of both games, the expansion pack would never have found the base game.
How to make the Pentium generation kids feel old :-)
I do remember trying to mod Populous the Beginning, which is quite a bit older
I think my approach may well be completely lawful in some jurisdictions, since it essentially amounts to ‘making the purchased software compatible with the user's device’.
Anyway, if you're running pirate copies of any variety, I'd recommend a sandbox of some sort. VMware Player is free, and in my experience faster than VirtualBox. It won't passthrough a dedicated GPU though so it would only be good for older games. you'd need Workstation Pro to get that. Or a Linux distro like Proxmox that runs a bare-metal hypervisor.
Plus there's Google Translate for when the posts aren't that easy to grok.
https://www.gog.com/game/heroes_of_might_and_magic_5_bundle
Actually, general consensus is that HOMM3 is the best of the Heroes of Might and Magic games:
https://www.gog.com/game/heroes_of_might_and_magic_3_complet...
Even though HOMM3 is from the 20th century, there are still fan made expansions updating the game here in the 2020s, e.g. https://h3hota.com/
Ofc, this is mostly a moot point now with GoG. If GoG manages to convince the publisher to let them sell the game without DRM.
Edit @stavros: You and anyone suffering from nostalgia should check GoG regularly :) I probably have most of my childhood games on there now.
Glad to see it still alive and kicking! Who to watch?
https://www.twitch.tv/theknownworld - mostly weekly streams
https://www.youtube.com/user/TheKnownWorld - some informational videos (strategies and such) as well as challenges against computers. Great explanations on the why/how and you get to watch at your own pace. I enjoy these more than the streams. Unfortunately he has run out of challenge ideas I think hehe
These games stood their own even in the age of Warcraft 2.
I nmhave yet to see a friend that, after being shown how to play the game, would not be totally hooked on HOMM2-3.
To this day, the only (old) game several friends will randomly want to boot are the HOMM series.
Probably something most of people here can't relate to, but this is something I'm always grateful for all the "modern" language toolings, as someone that is not a dev and uses Windows.
I now can just download source code of various open source projects if in Go/Node/Python, and just run/compile it. They work fine most of times.
I never had the same confidence for any C++ projects, even when the author themselves also use Windows, which is unlikely. I almost never make them work/compile successfully. If the binary isn't provided I just feel doomed.
I mean, if the game doesn't work for you, that's conceivable. But that they sell a game that doesn't work for many people, and the problem is widely known and the editor refuses to do anything but still takes money for it... it makes me wanna throw up :)
I could have also just pirated it. If I gave up, that's how we'd have done it.
That said, if we'd have done that, I wouldn't have had the fun ripping this piece of software to bits. :)
My personal strategy is to only give money after i'm satisfied with a product (at least in the computer world). I never bend to paywalls and will NEVER financially support non-free software because it enables that kind of user-abuse situation to begin with.
> That said, if we'd have done that, I wouldn't have had the fun ripping this piece of software to bits. :)
You can still pirate the game as a quick workaround while you dismantle the original release. Anyway thanks for this read i learnt much about windows debugging (as a non-Windows user).
I'm gonna drop their support a link to my writeup, see what happens!
Besides, I had a lot of fun playing with it. There were no doubt easier ways to do what I did but I enjoyed digging! :)
This sort of reverse engineering stuff certainly is fun though. As long as the software isn't heavily obfuscated that is. Before WoW died because of the Blizzard harassment investigation, I tried to reverse engineer Battle.net and the game to create an alternate launcher so I didn't have to see the ads in Battle.net. But both were obfuscated and had anti-debugging features. While I'm sure it would have been possible to figure out, it was too much for me so I eventually abandoned that.
I love your write-up on your process. I've done a couple short explanations before of how patches I've released work, but your blog post is far more thorough and a great read.
Nothing is uncrackable and it was that thought that kept me going with this. I can imagine that deliberately-obfuscated DRM like Battle.net would be a hell of a lot harder than this was though. Technically, it was all there for me to see from the start but I didn't know the way I should approach the problem. Finding that out was a big part of it.
Cheers, I'm glad you enjoyed it. More people have said they liked it than I ever thought would, I'm kinda surprised.
The content is interesting even to someone like me who doesn't really care for modding games or has no more than very bare experience with decompilers and dealing with hex editors.
Writing is a great balance between too dry and too verbose or "edgy". The material is super accessible, and it progresses at a very smooth and steady pace. What started with basic debugging ended up in digging through decompiled code and mapping characters for the fixed path manually to preserve the character count in the .inx file.
I swore I was going to only read the intro and read the rest in the morning, but ended up gulping up the whole thing in one go :(
Also, funny thing but 90% of the time I am 8x as motivated to solve a problem for a loved one as I am for myself.
For me, this would have been a “do something else” or “pirate it” moment.
It's worth doing at least once for anyone, but I think it will get harder for people as more content ends up ephemeral, unsearchable, or locked inside walled gardens.
https://wiki.skullsecurity.org/index.php?title=Fundamentals
also, that might be dated, so additionally search around for 'Ghidra'. Iirc, hackers at the NSA convinced their bosses the US would be more secure if the gen pop had access to their tools. Cool stuff.
How so? I'm very much so a nascent programmer, but I've learned the most by decompiling other's code and seeing what works and what doesn't. When I see good apps, I guess I make the (sometimes specious) assumption that whoever wrote it likely also knows how to write pretty well.
I've also done a ton of troubleshooting at a past support position via decompiler since the Dev Team was sometimes...sparse with details :)
It's one of the things I do like about programming, it's just a big logic puzzle to break down. Sometimes the logic harder to follow, but there is a way to understand it. My biggest mental growths have been just seeing how other people accomplish goals I want to accomplish, and understanding what does and doesn't work well. Especially with major developers, it's really interesting to see how/why they do the things they do as their needs are way different than in-house app needs.
But Generically named is not appropriate here, as at least with this job, we had really good devs, and they would get slapped pretty hard for non-intuitive naming. The Dev Leads were very careful about naming schemes and the end result was that it was pretty simple to understand what something was related to.
DotPeek also makes a lot of this work __very__ convenient with things like the stack trace explorer and its navigation tooling.
What a pain in the bosom were those registry keys. Can you imagine that for some time, The Registry was considered a Good Thing. GNOME tried to roll out its own before defecting to Mac ways.
The two together along with my memory and the order of open tabs is enough to put together "good enough" documentation showing the discovery and fixing process.
Once done, and feel like I can write a blog about it, I would redo the whole thing (and take the screenshots) for the blog article.
I started trying to fix it on a Friday evening and gave up after I couldn't get the "abort -> No Operation" thing. When I came back a couple of days later, I realised how I was going to proceed, but wanted to write it up. I made sure the thread I was pulling made sense (and thus I was confident I'd get to the end of this), stopped, and wrote the writeup to that point retrospectively. I also went back and recreated some of the screenshots.
From then on I played with the software for a bit until I "hit a breakthrough", stopped, and wrote the story and took some screenshots, then worked on the software until the next "breakthrough". I wanted this doc to record offsets and methodology so I made sure to include that wherever I could. I also used the document as a "rubber-duck debugging" aide, writing it for someone unfamiliar to the project.
I then polished/edited it (rushedly, without too much care) the day after and put it up. You can see my shift in methodology a few times where I mess up the past and present tense and with how some bits have considerably more detail than others.
As this is my first, I don't know if I'd do it the same way again. I've got a HW hacking project on the go and while I've taken loads of pictures, I think I'll probably be writing that up fully retrospectively.
As for rubber-duck debugging, that's a benefit I didn't think of, thanks!
It wound up being a WOW6432Node issue. I felt the transition from 32-bit to 64-bit was handled a lot less cleanly by Windows designers than their previous transition from 16-bit to 32-bit. Hacks like Program Files (x86) were particularly offensive.
What has happened to all the scene crackers? It strikes me they would have this polished off in a matter of hours.
Because he was basically navigating all their techniques (decompilation, bypassing checks, file formats, locating key locations, patching binaries, etc).
Installing it in a VM on XP would have probably achieved the same result.
Ubisoft changed the reg key of the base game from it's retail key to "Uplay Install 87" and the expansion had no idea to look for that key at all. If you used the Ubisoft copy of both games, the expansion pack would never have found the base game.
The reg key they've changed in the base game does have some Ubisoft specific information so I expect they did that in order to allow the game to work well with their delivery service. They tested it and it worked.
They presumably just didn't think to test the expansion installer or perhaps even worse, weren't permitted the funding to explore all the potential knock on effects.
Since noone is fixing it, despite there being many service tickets about it, I can only think that the engineers don't know what the issue is.
I also think that if the author here used that in the first place they would have arrived at the registry problems much sooner. ProcMon is often the first thing I reach for when dealing with a 'missing files' kind of problem on Windows.
You're absolutely correct. Doing this again, I'd probably get to start from the middle. I went the way I did because I was essentially starting it blind - technically capable but with no idea how one should do this. Discovering and reasoning my way through potential causes and tools helped it be a massive learning experience and I'm glad I did.
And there is "strace" (not the one from cygwin/mingw, which mostly traces apps written for their runtime), but from DrMemory's - https://drmemory.org/page_drstrace.html
Then you have the realtively recent Detours released, and tons of other tooling TBH, just all over.
I'm not embarrassed.
What I've done is written up my learning experience from near-nought in the hopes that others find it either informative or enjoyable.
Why should I be embarrassed of that?
Since 3DO folded and the property was taken over by another studio, this brand has collapsed in value.