Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

League of Legends Data with -p true is Encrypted? #17

Closed
rlaphoenix opened this issue Mar 17, 2018 · 8 comments
Closed

League of Legends Data with -p true is Encrypted? #17

rlaphoenix opened this issue Mar 17, 2018 · 8 comments

Comments

@rlaphoenix
Copy link

It looks like a bunch of spam

@vH3Gg=20.r
!r=w^7Tdo^
"(-RJFh*hzf9_3sNsUS_Xy) B&lcz+EYwNlhIto~q#R.kd`rTM_-^e5w3GZ-t S9'6cN^N-!r*8DN0RqU)
;kACu
)Y\,:q{W<5IW:"=oS[tJ#:fU(Ykgbgw!{j%\u|pqeXMd.S[~6DveSU{6Q2pDR)!z]>%KcCn0X|\FO.Ql,
w"1>wa6
`1mwJ
1pM]f/|M+n)`A+vIoorpRA*=zx%8WtI(YC
))l4DU1GV=t;#58V]zZjs#Po*XNZE+1:[@^."M7/3D37cjvm7J$,KTm{TVy
;[M}3Xgtsy9(L*}mQr5b/;'TJ&tRPC=
+S7v5NS0
zRXXST 9%;[`o&MV?[Dur}x9%{
'/)MkHb`b/Kbk@gLhf"T
@c4N10-FRAH*9`aCb

This saved to _WSASend.txt if it matters.
is there a way to decrypt this?

@NytroRST
Copy link
Owner

Probably the data is encrypted. It might use a custom library for encryption, I have to check, but this will not happen too soon, sorry.

@rlaphoenix
Copy link
Author

Is there a way to find the function it checks if the certificate is valid and instead just override it and return true always? Which would allow me to sniff using Fiddler with a DO_NOT_TRUST Cert

@NytroRST
Copy link
Owner

I am not sure about a fully implemented project, maybe Interceptor by Casey Smith. It depends how each application is validating the certificate. Most of the time, the application does not use "SSL Pinning" and it is enough to just install your own root CA.

@rlaphoenix
Copy link
Author

The Interceptor you mentioned seems to essentially be fiddler. Just I dont have a way to force a CA cert on LoL.

@NytroRST
Copy link
Owner

The Root CA (for any intercepting tool) has to be installed in the operating system Root CA Store. This way, the application (LoL) will probably use it and consider the certificate valid.

@rlaphoenix
Copy link
Author

The Certificate Fiddler provides is a .cer file. This can be used correct?

@NytroRST
Copy link
Owner

@rlaphoenix
Copy link
Author

Doesnt seem to work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants