MMORPG Bot Reverse Engineering and Tracking


A friend told me that a GW2 trading bot implemented a dumb API. We are going to find and use it to track the bot.

Bonus video with the analysis of the collected data will come within the next 24h.

TL;DR summary: If you are a Guild Wars 2 player, don't worry about bots like that. It's child's play. Don't request ArenaNet to waste any resources on it.

I'm not sure what people expected given that most people who buy bots are uneducated script kiddies that have no fucking clue how to use their brains let alone use tools to find out about the vulnerability.

instead of/ or as well as use Redgate have a look at De4Dot, it's on GIT and works quite well if the code is obfuscated


3 years BSc computer science, 1 year MSc computer systems, 5 years working as a .NET and android developer, self-teaching cyber security...

watching things like this i'm like "yeah, that makes sense, i understand this completely, oh yeah i see, cool, ahhh that's how you do that"

but i couldn't even begin to DO this of my own accord.

This bot is not using SSL to check your login. I would not suggest to use your passwords...

Ida free actual version don't work at least for me because my operative system has based in 32 bits. My question is the next: Can i use Immunity Debugger like the 32 bit alternative to the actual Ida Version? I am able to use python in this debugger. Thank you in advance and have a nice week


Jan Liebrecht 

Bei solchen Analysen ist auch der x64 debugger ziemlich hilfreich =) Ist eine neue Version von OllyDbg, wirst du sicher kennen. =)

For string searching I like ProcessHacker 2 - double click on the process>Memory>[Strings...]>Set the settings>Optionally filter output.