ä»ãã³ã³ãã¥ãŒã¿ãŒã²ãŒã ã¯ã©ãã«ã§ããããŸãã ãŸããTelegramã«ãååšããŸãã ãã®ã¡ãã»ã³ãžã£ãŒã®ã»ãŒãã¹ãŠã®ã²ãŒã ããããã³ã°ãããã¹ã³ã¢ããŒãã®ãããã«ããæé«ã¯ã©ã¹ã®ãã¬ãŒã€ãŒããã€ãã¹ããããšã«ã€ããŠèª¬æããŸãã ç ç©¶çµæãå
±æãããã ãããã³ã°ãäžæ£è¡çºã®ããŸããŸãªæ¹æ³ãããã³ã«ãããããã²ãŒã ã®ããžãã¯ããã€ãã¹ããæ¹æ³ã«ã€ããŠã

æ°ã¶æåã«ã¬ãã¥ãŒãããæåã®ã²ãŒã
-LumberJackã¯ãæšãããšããŠãã¬ã€ããŸãããã¬ãŒã€ãŒãæŒãã€ã¶ããªãããã«ãæãåãå¿
èŠããããŸãã ã²ãŒã ã®ç®æšã¯ãäžå®æéå
ã«ã§ããã ãå€ãã®ãã©ã³ããåæžããããšã§ãã

æåã¯ãã²ãŒã ã®ã°ã©ãã£ãã¯èªã¿åãã§ç·Žç¿ãããã£ãã®ã§ããã€ãŸããã¢ãã¿ãŒäžã®ã°ã©ãã£ãã¯ããŒã¿ã«åºã¥ããŠæ±ºå®ãäžããŸããã ããã°ã©ã ã¯ãç»é¢äžã®ç¶æ³ã«åºã¥ããŠå¿
èŠãªããŒã®çµã¿åãããéä¿¡ãã人éã®åå¿ããšãã¥ã¬ãŒãããå¿
èŠããããŸãã çŸåšã®ã²ãŒã ã®ããã°ã©ã ããžãã¯ãæ§ç¯ããåçã¯æ¬¡ã®ãšããã§ãã ããªãŒã®å³åŽã«ãã600x1ãã¯ã»ã«ã®ãµã€ãºã®ã¹ã¯ãªãŒã³ã·ã§ãããæ®ãããŸãã ãã®ãããªå€§ããªã¹ããŒã¹ã®ã¹ã¯ãªãŒã³ã·ã§ãããæ®ãããã»ã¹ã«ã¯æéãããããããç»é¢å
šäœã§ã¯ãããŸããã æ¬¡ã«ãããã°ã©ã ã¯6ãã€ã³ãã§ãã¯ã»ã«ã®è²ããã§ãã¯ããããã«åºã¥ããŠãäžåºŠã«6ãã©ã³ãã®ãã¬ãŒã€ãŒã®è»è·¡ãèšç®ããŸãã å³åŽã«åå²ãããå Žåã¯å·Šã«é²ã¿ãããã§ãªãå Žåã¯å³åŽã«ãšã©ãŸããŸãã 1åã®ç§»åã§ãwithã§2åãããããŸãã ç§»åãå®è¡ãããåŸãã¹ã¯ãªãŒã³ã·ã§ãããå床ååŸããããµã€ã¯ã«ãç¹°ãè¿ãããŸãã ããã¯ãæéããªããªããŸã§ç¶ããŸãã

Ubuntu 16.04 OSäžã®Python 2.7ã®ããã°ã©ã ã³ãŒã
import os, time import pyscreenshot as ImageGrab from Xlib import display def move_left(): os.system("xte 'key Left'") def move_right(): os.system("xte 'key Right'") def exist_branch(x, y): box = (x, y - 6 * 100, x+1, y) im = ImageGrab.grab(box) rgb_im = im.convert('RGB') x, y = im.size result = [] for i in range(0, 6): r, g, b = rgb_im.getpixel((0, y - 1 - i * 100)) summa = r + g + b if summa < 700: result.append(True) else: result.append(False) return result def get_mouse(): while True: data = display.Display().screen().root.query_pointer()._data x = data["root_x"] y = data["root_y"] print '%s,%s - %s' % (str(x), str(y), exist_branch(x, y)) def main(): start_x = 1543 start_y = 641 while True: branches = exist_branch(start_x, start_y) cons_str = "" for elem in branches: if elem: cons_str += 'Left ' else: cons_str += 'Right ' print cons_str for elem in branches: if elem: move_left() time.sleep(0.03) move_left() else: move_right() time.sleep(0.03) move_right() time.sleep(0.2) try:
å®è¡ããã«ã¯ã次ã®äŸåé¢ä¿ãã€ã³ã¹ããŒã«ããå¿
èŠããããŸã
sudo apt-get install xautomation pip install pyscreenshot
xteãŠãŒãã£ãªãã£ã¯ãLinuxã§ããŒããšãã¥ã¬ãŒããã圹å²ãæ
ããŸã;詳现ã«ã€ããŠã¯ã
ãã¡ããã芧ãã ãã ã pyscreenshotã©ã€ãã©ãªãŒã¯ãç»é¢ã®éžæãããé åã®ã¹ã¯ãªãŒã³ã·ã§ãããååŸãã圹å²ãæãã
ãŸã ã詳现ã¯
ãã¡ããã芧
ãã ãã ã ããã°ã©ã ãæ©èœããããã«ã¯ãæåã®ãã€ã³ãïŒå³åŽã®äžçªäžã®ãã©ã³ãããŸãã¯ãããé
眮ãããå¯èœæ§ã®ããå ŽæïŒãèšå®ããå¿
èŠããããŸããããã«ã¯ãget_mouseïŒïŒé¢æ°ã䜿çšã§ããŸãã ãã©ã³ãéã®é«ãã¯100ãã¯ã»ã«ã§ãã ããŒã¹ãããŒã¯éã®é
å»¶ãšã¹ã¯ãªãŒã³ã·ã§ããã®ååŸéã®é
å»¶ã¯ã詊è¡é¯èª€ã«ãã£ãŠèšå®ãããŸãã ãããã®å€ãããå°ããå€ãèšå®ããããšã¯ã§ããŸããã§ãããããã°ã©ã ã«ã¯ç»åãåŠçããããããŒãæŒãããããæéããããŸããã§ããã äœåã®äŸããããªã«æ²èŒããŠããŸãã
800ãã€ã³ããç²åŸã§ããã®ã¯1人ã§ã¯ãªããããããã°ã©ã ã®çµæã¯åå©ãšèŠãªãããšãã§ããŸãã
äœæãšãããã°ã®ããã»ã¹ã«ã¯éåžžã«é·ãæéãããã£ããããä»ã®ãœãªã¥ãŒã·ã§ã³ãæ€èšããå¿
èŠããããŸãã
HTTPãªã¯ãšã¹ããåæããå Žåãã²ãŒã ã®æåŸã«2çš®é¡ã®ãªã¯ãšã¹ããéä¿¡ãããŸãã ãŠãŒã¶ãŒãæ°ããã¬ã³ãŒãã«å°éããŠããªãå Žåã
POST /api/getHighScores HTTP/1.1 Host: tbot.xyz Accept: */* Accept-Language: ru-RU,ru;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate, br Content-Length: 197 Content-Type: text/plain;charset=UTF-8 Connection: close data=[..some_base_64_code..]
æ°èšé²
POST /api/setScore HTTP/1.1 Host: tbot.xyz User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:55.0) Gecko/20100101 Firefox/55.0 Accept: */* Accept-Language: ru-RU,ru;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate, br Referer: https://tbot.xyz/lumber/ Content-Length: 206 Content-Type: text/plain;charset=UTF-8 Connection: close data=[..some_base_64_code..]&score=some_score
some_scoreãäœããã®å€ã«çœ®ãæããã ãã§ååã§ãããæ°ããæ°å€ãããŒãã«ã«è¿œå ãããŸãã
Base64ã¯ãã¢ã«ãŠã³ãã«é¢ããæ
å ±ãã€ãŸãidãã²ãŒã ãã¯ãªãã¯ãããã¬ãŒã€ãŒã®ååãã²ãŒã ã®ååãããã³ãã£ããIDãéä¿¡ããŸãã
ãã®ã²ãŒã ã
@gamebotãããã«å±ããŠããããšã¯æ³šç®ã«å€ããŸããããã«ã¯ããã«2ã€ã®ã²ãŒã
Math Battleãš
CorsairsããããŸãã ã²ãŒã Math Battleã«ã€ããŠè©³ãã説æããŸããã

ã¹ã³ã¢ä»ãã®HTTPãªã¯ãšã¹ããåæ§ã«éä¿¡ãããŸãã ãã©ãŠã¶ã®ã€ã³ã¹ââãã¯ã¿ãŒãä»ããŠãªã¯ãšã¹ããéä¿¡ããããšã¯äŸ¡å€ããããŸãã
ãããã¬ãŒã¢ãŒããéãããããœãŒã¹ã³ãŒãmain.min.jsãéããŸãã ããã€ãã®ãã¬ãŒã¯ãã€ã³ãïŒãã¬ãŒã¯ãã€ã³ãïŒã眮ããã²ãŒã ãéå§ãããã€ã³ãã®æ°ãæ ŒçŽãã倿°rãèŠã€ããŸãã ã³ã³ãœãŒã«ãä»ããŠããã®å€ã倿Žã§ããŸãã

ãããã°ã¢ãŒãããªãã«ãããšããã€ã³ããéä¿¡ããæ©èœãå®è¡ããããããæ¢ã«èšå®ãããŠãããã€ã³ãæ°ãéä¿¡ã§ããŸãã ã€ã³ã¹ãã¯ã¿ãŒããªãã«ãããªã©ãäœåºŠãã¯ãªãã¯ããªãããã«ããã«ã¯ã
JS BeautifierãµãŒãã¹ã«ãã£ãŠç·šéããããœãŒã¹ã³ãŒãmain.min.jsãå°ãçè§£ãã䟡å€ããããŸãã 以äžã«3ã€ã®è峿·±ãæ©èœã瀺ããŸãã
function ba(a, b, d) { var c = new XMLHttpRequest, e = [], f; for (f in b) e.push(encodeURIComponent(f) + "=" + encodeURIComponent(b[f])); c.onreadystatechange = function() { 4 == c.readyState && 200 == c.status && d(JSON.parse(c.responseText)) }; c.open("POST", a, !0); c.send(e.join("&")) } function na() { n && ba("/api/setScore", { data: n, score: r || 0 }, function(a) { e = a.scores; Y(); I(); a["new"] && l && (z = !0, x(M, "shown", z)) }) } function ca() { n && ba("/api/getHighScores", { data: n }, function(a) { e = a.scores; Y(); I() }) }
æ°ããã¬ã³ãŒãã«å°éãããšnaïŒïŒé¢æ°ãåŒã³åºãããã²ãŒã ã®ã¹ã³ã¢ããŒããååŸããããã ãã«caïŒïŒãå¿
èŠã«ãªããŸãã ãšããã§ãã©ã®é¢æ°ãåŒã³åºããã¯ããã®è¡ã®UïŒïŒé¢æ°ã§æ±ºå®ãããŸãã
r > Z ? na() : ca();
ãã©ã¡ãŒã¿rã倿ŽããŠé¢æ°naïŒïŒãåŒã³åºãå Žåããããã°ã¢ãŒããæå¹ã«ããå¿
èŠããããŸãã ãã®ãããªãã®ã§ãªããã°ãªããŸããã

ãœãŒã¹ã³ãŒãã¯å°ãé£èªåãããŠãããããåæãé£ãããªããŸãããåºæ¬çãªããšã¯æããã§ãã
@gamebotãããã«ãé¢é£ããCorsairsã²ãŒã ã¯ãäžèšã®ãã¹ãŠã®æ¹æ³ã§è§£æ±ºãããŸãã ãµãŒããŒãžã®ããŸããŸãªãªã¯ãšã¹ãã«å¯ŸããŠãç§ã¯çŠæ¢ãããã¹ã³ã¢ããŒãã«è¿œå ã§ããŸãããã¢ã«ãŠã³ãã¯çŠæ¢ãªã¹ãã«ãããŸãã ãã®ãããã®ã²ãŒã ããã¹ããããšãã¯æ³šæããå¿
èŠããããŸãã
@gameeãããã¯éåžžã«äººæ°ããããŸããã Quboã²ãŒã ãéžæãããŸããã

ã²ãŒã çµäºæã«éä¿¡ããããªã¯ãšã¹ãã¯æ¬¡ã®ãšããã§ãã
POST /set-web-score-qkfnsog26w7173c9pk7whg0iau7zwhdkfd7ft3tn HTTP/1.1 Host: bots.gameeapp.com Accept: application/json, text/javascript, */*; q=0.01 Accept-Language: ru-RU,ru;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate, br Content-Type: application/x-www-form-urlencoded; charset=UTF-8 Content-Length: 247 Origin: https://www.gameeapp.com Connection: close {:2,:,:76,:ct\q3Qv2QtaFAlihlaAvZSp+ahHSq7y4Uut5bLd80nYX1pp9rz0jh03si8Nx2HIe91x\iv\93b55f8f4105a269e74a58bec5e0e0a0\s\da96bc85b70f149d\}
åã®ãããã®ããã«ãã¹ã³ã¢ã®çœ®æã¯å€±æããŸãã ã¹ã³ã¢ãplay_timeãªã©ã«çœ²åããããã·ã¥ãçæãããããããã®ãããªç°¡åãªæ¹æ³ã§ãã€ã³ããååŸã§ããŸããã ãããã¬ãŒã«ã¯å€ãã®å€æ°ããã£ããããããŸã圹ã«ç«ã¡ãŸããã§ããã

ã³ãŒããæåã§åæããå¿
èŠããããŸããã ã²ãŒã ããŒãžã®ãœãŒã¹ã³ãŒãã§ããã®ãããªã³ãŒããèŠã€ããããšãã§ããŸãã

ã¹ã¯ãªããã¯éåžžã®æ¹æ³ã§ã¯ãªãjsã®ãªã¯ãšã¹ããä»ããŠæ¥ç¶ããããããã€ã³ã¹ãã¯ã¿ãŒã«ã¯è¡šç€ºãããªãããšã«æ³šæããŠãã ããã 2ã€ã®è峿·±ããã¡ã€ã«ã¯
gameUI.min.jsãš
gameUIdesktop.min.jsã§ãã æåã®ãã¡ã€ã«ã§ãgameeUIãªããžã§ã¯ãã®ã¡ãœããã§ãã颿°ãèŠã€ãããŸããã
saveScore: function(e) { var a = window.location.pathname, t = gameeUI.user, n = (new Date).getTime(), o = $("#dataId").data(), i = CryptoJS.AES.encrypt(JSON.stringify({ score: e, timestamp: n }), o.id, { format: CryptoJSAesJson }).toString(), s = { score: e, url: a, play_time: gameeUI.playTime, hash: i, username: t, anonymous_id: gameeUI.anonymous_id }; if (isFacebook()) { var r = FacebookUserData.getUserData(); s.app_scoped_user_id = r.app_scoped_user_id, s.user_id = r.user_id } gameeUI.sendScoreData(s) }
æããã«ãå
¥åãã©ã¡ãŒã¿ãŒeã¯ãµãŒããŒã«éä¿¡ããããã€ã³ãã§ãã ã³ã³ãœãŒã«ã§gameeUI.saveScoreïŒsome_scoreïŒã®è¡ãéä¿¡ããããšã§ã倧åãªãã€ã³ãæ°ãååŸã§ããŸãã
ãã®ãããã«ã¯ãã²ãŒã "3 + 3"ã "Karate Kido"ã "Space Traveler"ã "Hexonix"ãªã©ãå«ãŸããŸãã äžèšã®æ¹æ³ã§ãã¹ãŠè§£æ±ºãããŸãã æ¬¡ã®ãããã®ã²ãŒã ã®1ã€ãç¹å®ã®æ¹æ³ã§è§£æ±ºããããšããã®ãããã®ä»ã®ã²ãŒã ãããã«ãã£ãŠè§£æ±ºããããšçµè«ä»ããããšãã§ããŸãã
ããªãè€éãªããžãã¯ã¯ãã²ãŒã ãGalaxy Space ShooterããšåŒã¶ããšãã§ããŸãã çŸããã°ã©ãã£ãã¯ãã²ãŒã äžã«ããããã®è±ªè¯ãªãããªãã¯ãã€ã³ããšã³ã€ã³ãç²åŸããããšãã§ããŸãã

ããããã€ã³ã¹ãã¯ã¿ãŒã調ã¹ãŠãTlgAdapterãªããžã§ã¯ããšãã®putScoreã¡ãœãããèŠã€ããã ãã§ååã§ããã

ãã®ãããã¯å¥œå¥å¿ã匷ãããšã倿ããŸããã ãã¹ãçšã®ã²ãŒã ã¯ãžã£ã³ãæœæ°ŽèŠã§ãã

ã²ãŒã çµäºæã®ãªã¯ãšã¹ãã¯æ¬¡ã®ãšããã§ãã
POST /v1/setscore HTTP/1.1 Host: telegram-games.ludei.com Accept: */* Accept-Language: ru-RU,ru;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate, br Content-Type: application/json;charset=UTF-8 Content-Length: 73 Origin: https://angrypianohtml5.ludei.com Connection: close {"inlineId":"token","userId":"user_id","score":some_score}
ãã€ã³ãã¯ç°¡åã«äº€æã§ããŸãã é©ãã¹ãããšã«ãuser_idã¯ã¯ãªã¢ããã¹ãã§éä¿¡ãããŸãã ãã£ããå
ã®ãã¹ãŠã®ãŠãŒã¶ãŒã®IDãèŠã€ããå Žåãæ¬¡ã®ã¹ãã æ»æãè¡ãããšãã§ããŸãã ããã¯ãTelegram APIã䜿çšããŠå®è¡ã§ããŸãã

ã¢ã€ãã¢ã¯ãããŒãã«å
ã®å¥ã®ãã¬ã€ã€ãŒã®ãã€ã³ãã倿Žã§ããã ãã§ãªããäžè¬çãªãã£ããã§ã¹ãã ãéä¿¡ããŠãçŸåšã®ã²ãŒã ã®æ°ããåè
ã«é¢ããéç¥ãéä¿¡ã§ãããšããããšã§ãã æ£ããè¡ãããå Žåãããã¯ããªãæ·±å»ãªæ»æã§ãã å®éã«èª°ããã€ã³ããç²åŸãããã倿ããããšã¯äžå¯èœã§ããããã£ãããããã®äººïŒæ»æè
ãŸãã¯ãã¹ãã ããããŠãã人ïŒãé€å€ããåŸã§ããæ··ä¹±ãç¶ããããšãã§ããŸãã 管çè
ãå«ããã£ããåå è
ã«ä»£ãã£ãŠãã¹ãã ããè¡ãããã£ãã管çè
ã«ç¹å®ã®äººã匷å¶çã«é€å€ãããããšãã§ããŸãã ãã®ãããªäžæçããæ¢ããå¯äžã®æ¹æ³ã¯ããã£ãã管çè
ãææ¡ãããã²ãŒã ã®ã¡ãã»ãŒãžãåé€ããããšã§ãã
ãã®ãããã«ã¯ãã²ãŒã ãiBasketãããSumonãããAngry Pianoããå«ãŸããŠããŸãã
5ã€ã®ã²ãŒã ããã®ãããã«å±ããäžèšã®çš®é¡ã®æ»æã«äœ¿çšã§ããŸãã
ããšãã°ãã²ãŒã ãããªãã¿ã®ãµãããŒã

èŠæ±ã¯æ¬¡ã®ãšããã§ãã
GET /embed/telegram-game-bot/?user_id=user_id&inline_message_id=chat_id&score=score HTTP/1.1 Host: meduza.io Accept: application/json, text/plain, *
ããã¯ããã«ç°¡åã§ãã ãã£ããIDãšãŠãŒã¶ãŒIDãç¥ã£ãŠããéåžžã®GETèŠæ±ã§ãã¹ãã ãæé
ã§ããŸãã
ã²ãŒã ã¯1ã€ã ãã§ã-ãDevRunnerã

ã²ãŒã ã®çµäºåŸã2ã€ã®ãªã¯ãšã¹ããéä¿¡ãããŸã
POST /game/scored HTTP/1.1 Host: devrunner.fora-soft.com User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0 Accept: */* Accept-Language: ru-RU,ru;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate, br Content-Type: application/x-www-form-urlencoded Referer: https://devrunner.fora-soft.com/?uid=453743655&imi=AgAAAKwAAAAnlAsbCh1sirM6oOQ Content-Length: 97 Cookie: _ga=GA1.2.2104866484.1507563316; _gid=GA1.2.1543721993.1507563316 Connection: close user_id=453743655&score=111111&chat_id=&message_id=&inline_message_id=AgAAAKwAAAAnlAsbCh1sirM6oOQ
POST /game/scores_image HTTP/1.1 Host: devrunner.fora-soft.com Accept: */* Accept-Language: ru-RU,ru;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate, br Content-Type: application/x-www-form-urlencoded Content-Length: 47 Connection: close crutches=1&bugs=2&scores=31&level=0&rank=Intern
2çªç®ã®ã¯ãšãªã§ã¯ãçŸåšã®ãã€ã³ãæ°ãæã€ãã¬ãŒã€ãŒãã©ãã«ãããã確èªã§ããŸãã ãã¹ããéå§ãããåã¯ã2000ã3000ãã€ã³ãã®ãã¬ãŒã€ãŒãæåã§ãããé¢çœãããšã«ãåèšã§çŽ1äž3å人ãã²ãŒã ããã¬ã€ããŸããã ãããã®äººã¯èª°ããã®ã²ãŒã ããã®ãããšãèããŠããªãã£ãããšãããããŸã:)ã¯ãšãªããã€ã³ãæ°111113ã«çœ®ãæããããšã第äžäœã§ããã

ãã®ã²ãŒã ã®ãããã¯ééããªãæãéå±ã ãšèšããŸãã
äŸã¯ãã§ã¹ã§ãã è©äŸ¡ãªããåå©ã®èŠåãªã©ã ã²ãŒã ã¯ã¯ã©ã€ã¢ã³ãåŽã®ã¿ã§ãã

ãã®ã²ãŒã ã¯ããã®ãããã§å¯äžã®ãžã£ã³ããŒã«ãšã«ã§ãã

ã²ãŒã çµäºæã«ãªã¯ãšã¹ããã
POST /score HTTP/1.1 Host: microgames-ijwqbqxfic.now.sh User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0 Accept: */* Accept-Language: ru-RU,ru;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate, br Content-Type: application/json; charset=UTF-8 Referer: https://microgames-ijwqbqxfic.now.sh/games/jumper_frog/?token=eyJhbGciOiJIUzUxMiJ9.eyJnYW1lIjoia... Content-Length: 14 Connection: close {"score": 700}
ããŒã¯ã³ã®äžéšã¯åãåãããŸãããæå³ã¯æç¢ºã§ãªããã°ãªããŸããã ã¹ã³ã¢ã®ã¿ããµãŒããŒã«ããŒã¿ãšããŠéä¿¡ãããŸãã 亀æã¯ç°¡åã§ãã 質åã¯ç°ãªããŸããç¹å®ã®äººããã¬ã€ããŠããããšããµãŒããŒãã©ã®ããã«èªèãããã¬ã°ã©ã ãã£ããã§ã¹ã³ã¢ããŒãã«æžã蟌ã¿ãŸãããïŒ ãããŠããã¹ãŠãç°¡åã§ã-ãµãŒããŒã¯ãäžèšã®ããŒã¯ã³ã®RefererããããŒããããŒã¿ãååŸããŸãã å¥åŠãªæŸèæãç¬ã è«ççãªè³ªåã¯ããã®
ã²ãŒã ãžã®çŽæ¥ãªã³ã¯ã«ç§»åãããšã©ããªããŸããïŒ äžèšã®ãªã¯ãšã¹ãïŒãªãã¡ã©ãŒãªãïŒã«å¿ããŠãã€ã³ããç²åŸããå Žåã«ã®ã¿ããã®çš®ã®çããè¿ã£ãŠããŸãã

ãã¡ã€ã«ãžã®çµ¶å¯Ÿãã¹ãæããã«ãããšã©ãŒããã£ããããŸããã ããšãã°ãLFIãšã®äºææ§ã§ã¯ããã§ã«å€ãã®æçšãªããŒã¿ãååŸã§ããŸãã ããããã¿ã¹ã¯ã¯ã²ãŒã ã®æ¬ é¥ãæ€åºããããšã§ãããç¹å®ã®ã²ãŒã ã®æ¬æ Œçãªãã³ãã¹ãã宿œããããšã§ã¯ãªãã£ããããããã§åæ¢ããããšã«ããŸããã
ã²ãŒã ãããªãããŒãã©ãã¯ã¹ãã«ã€ããŠèª¬æããŸããããã¯ããã¹ãŠã®äžã§æãè€éãªæ§é ã§ãããä»ã®ãã¹ãŠã®ã²ãŒã ã«æ¯ã¹ãŠã»ãã¥ãªãã£ã¬ãã«ãé«ããåé¿ã«é·ãæéãããããŸããã èè
ã¯ããã§ããŠããã圌ã¯éåžžã«é©åãªã²ãŒã ãäœæããŸããããããåè§£ããã®ã¯é¢çœãã£ãã§ãã ãã®ã²ãŒã ã解決ããããã»ã¹ã詳现ã«èª¬æããããšæããŸãã ãã¬ã€ã€ãŒã®ä»äºã¯ãå³¶ããå³¶ãžãžã£ã³ãããŠé¶ãé£ã¹ãããšã§ãã é»è©±ã®ç»é¢ã§ããŠã¹ã®å·Šãã¿ã³ãŸãã¯æãæŒãç¶ãããšãããããç®çã®è·é¢ã«é£ã°ãããšãã§ããŸãã

ã²ãŒã ã®çµããã«ããã®ãããªãªã¯ãšã¹ããéä¿¡ãããŸã
POST /game-api/expandScore HTTP/1.1 Host: play.alexbelov.xyz Accept: application/json, text/plain, */* Accept-Language: en-US,en;q=0.5 Content-Type: application/json;charset=utf-8 Content-Length: 432 Connection: close {"hash":"d5139c23e94113af55baa5a5b48c42f03c0438d768588aa28057f3da72c938aa4e9db142b6ba0dacbde4aa0fd6ebedf1447d4493f53608a4ff321fee1549c115fc5e3eca98c23c45539982ae08a8ce2627db050eeb73fb13339727b03294739d98b88e9b372be8df37689393794d894108e6c5afe024bfbe451a955100d02649eb5e8fb0091a2186f2303be5a2d4af374cbb1ad0cfd3914b8dbe406ebcd4fe0443f0d05224067088043ac51962ada7207d480d249a10ab595ae0da3627942637","session":"bf102fd528a0..."}
ã©ã®ãããªããã·ã¥ããŸã æç¢ºã§ã¯ãããŸããã æããã«16鲿°ã§ãbase64ã§ããããŸããã å
ã®3äžè¡ã§ãã³ãŒããèªã¿åãå¯èœãªåœ¢åŒã«åãã©ãŒãããããå Žåã
JS BeautifierãµãŒãã¹ã䜿çšãããŸããã ãã®ãããªãã£ã«ã¿ãŒ-ãã¹ã "ã§ãµãã¹ããªã³ã°ãæ¢ãã®ã¯è«ççã§ãããã®ãããªé¢æ°ãèŠã€ãããŸããã
key: "setScore", value: function(e) { console.log(e); var t = "expandScore"; return this.apiRequest(t, { hash: e }, { method: "post" }) }
æ€çŽ¢ã§ãã®é¢æ°ãæ€çŽ¢ããããšã«ãããåŒã³åºãããå Žæãããã€ãèŠã€ããããšãã§ããŸãã ããšãã°ããããã®ãªããžã§ã¯ã-this.ApiServiceãŸãã¯this.scoreViewããã ãããããããã®ã©ããæ€æ»å®ãéããŠã¢ã¯ã»ã¹ã§ããŸããã§ããã æ¬¡ã«ãã©ã®çš®é¡ã®ããã·ã¥ãéä¿¡ãããã©ã®ããã«ãã³ãŒãããããæ±ºå®ããããšã«ããŸããã
ããã«ãæ€çŽ¢ã¯ããã¹ãsetScoreã§ãã§ã«å®è¡ãããŠããŸãã æå·åãã©ã®ããã«è¡ããããã倧ãŸãã«èª¬æãããã°ãããæ©èœããããŸããã
key: "saveResults", value: function() { var e = this, t = arguments.length > 0 && void 0 !== arguments[0] ? arguments[0] : {}, n = window, r = n.gameMe, i = f.default.extend({ key: r._shard }, p), o = d.encrypt(i, JSON.stringify(t).split("").reverse().join("")); this.ApiService.setScore(o).then(function(t) { e.updateMe() }) }
æåã«ããŸã ç¥ãããŠããªãããŒã¿ã®JSON圢åŒãæååã«å€æãããæ¬¡ã«ãã®æååãé
åå
ã®æåã«åå²ããããããã®æåã®é åºã«éæ¹åã«å€æŽãããæååãåã³æ¥çãããŸãã éçºè
ããã®å°ããªã¢ã³ããªããŒã¹ãããïŒ ã¹ã¯ãªãŒã³ã·ã§ããã®ããã«ãã¬ãŒã¯ãã€ã³ããèšå®ããããšã«ãããç¹ã«è¡14016ã§äœ¿çšå¯èœãªãã¹ãŠã®çŸåšã®æ©èœãšãªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ãååŸãããŸããã

ããã§ãããã€ãã®è峿·±ããªãã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããŸãã

ECBã¢ãŒãã§ã¯ããã¹ãŠã®ããŒã¿ãAES 256ã¢ã«ãŽãªãºã ã§æå·åãããŠããããšãããããŸãã ããããã¯ã£ããããŠããªãã®ã¯ã察称æå·åã®åªãã
ãµãŒãã¹ãåŸãããšã§ãã

äžæ¹ãããã°ã©ã ã¯ç°ãªãçµæããããããŸããã

æå·åã¢ã«ãŽãªãºã ã倿Žãããããšã倿ããŸãããããã¯ãã¢ã³ããªããŒã¹ãšéçšããã»ã¹ã®ããã®å¥ã®ãããã§ãã ãã ããããã¯æå€§ã®åé¡ã§ã¯ãããŸããã ãµãŒããŒã«éä¿¡ããããã€ã³ãã®æ°ã§ã¯ãªããJSON圢åŒã®ããŒã¿é
åïŒèªã¿ãããããããã«ãã©ãŒãããããããªã¯ãšã¹ãã«ã¯ãã€ãããŒã·ã§ã³ã¯ãªããåäžã®ã¹ããŒã¹ã¯ãããŸããïŒã
{ "_s":"1", "_f":[200,440.412834676673], "_p":0.61, "_r":0.44048586944056, "_t":1507933273148, "_n":{ "_s":"2", "_f":[200,531.1135607680883], "_p":0.64, "_r":0.5711409299481298, "_t":1507933274848, "_n":{ "_s":"3", "_f":[200,583], "_p":0.73, "_r":0.06360827768619635, "_t":1507933277447, "_n":{ "_s":"4", "_f":[200,374.96787925000024], "_p":0.54, "_r":0.4264300320950012, "_t":1507933278662 } } } }
_tã®ããžãã¯ã«åºã¥ããŠãããã¯ããªç§åäœã§æ¬¡ã®é¶ãé£ã¹ãããæéã§ãã_f-å³¶ãŸãã¯é¶ã®åº§æšã_s-æ°ã_n-é¶ãé£ã¹ãããæ¬¡ã®å³¶ã ãµãŒããŒã¯ãæ¡ç¹ããããã€ã³ãã®æ°ã§ã¯ãªããéé¶ãé£ã¹ããããšãã«èšé²ãããããŒã¿ãåŠçããŸããã ã²ãŒã ã®ã»ãã¥ãªãã£ã«é¢ããŠéåžžã«è¯ãã¢ã€ãã¢ã§ãã
ããã€ãã®ã²ãŒã ãè²»ãããåŸã_pãš_rãäœã§ããããå€å¥ã§ããŸããã§ãããã»ãšãã©ã®å Žåããããã¯æ³šæãããããŠã³ãŒãã®çè§£ãè€éã«ããéçºè
ã®å¥ã®æ©èœã§ãã ãããããã¹ãŠã®å€æ°ã¯ç¹å®ã®å¶éå
ã§å€åããå¿
èŠãªæéãšå¿
èŠãªãã€ã³ãæ°ã«åºã¥ããŠJSONé
åãçæããã¹ã¯ãªãããäœæãããŸããã
import time import json import random score = 3

çµæãã³ã³ãœãŒã«ã«æ¿å
¥ããŠãããHTTPãªã¯ãšã¹ãã眮æããå¿
èŠããããŸããã æ®å¿µãªãããããã¯ããã€ãã®ãã€ã³ãã§æ©èœããã¢ã«ãŠã³ãã¯çŠæ¢ãããŸããã ã©ãããã¹ã¯ãªããã§ãã¹ãŠãèæ
®ãããããã§ã¯ãªãããã§ãã
å¥ã®ãã¹ãã¢ã«ãŠã³ããååŸãããœãŒã¹ã³ãŒãã®èª¿æ»ãšãã¹ãã®å®æœãç¶ããªããã°ãªããŸããã§ããã ãœãŒã¹ã«ã¯ããŸããŸãªå¥åŠãªãã®ããããŸããããšãã°ããã¹ãŠã®çš®é¡ã®AESæå·åãå®è£
ãããŠããããŸãã¯ããã·ã¥ããŒãã«ã䜿çšãããã®ãããªå¥åŠãªã³ãŒãã§ãã

ãŸãã¯ãããšãã°ãç®çã®ããŒãbase64ã«ããçç±ãäžæã§ãïŒmd5ããŒã¯æå·åäžã«éä¿¡ãããŸããïŒã

ãããŠãããã«åœŒã®ãã©ã³ã¹ã¯ãªããããããŸãã

ãããã¯ãã³ãŒãã«èŠããããã¹ãŠã®å¥åŠãªãã®ã§ã¯ãããŸããã ããããããã«æ°æéã®ãããã°ã®åŸãç§ã¯äœãé¢çœããã®ãèŠã€ããŸãããcatchAnimals颿°ã§ãã
key: "catchAnimals", value: function() { var e = this, t = [this.foxOffsetX, this.foxy.position.y], n = this.getHitAreaAnimal(this.foxy, t, this.foxOffsetX); if (n) { window.score = ++this.score; var r = v.Utils.getRandomInt(0, 100) / 100; r < .9 ? gameSounds && ion.sound.play("chicken_3") : gameSounds && ion.sound.play("chicken_1"), this.scoreView.setScore(this.score), this._passIslands || (this._passIslands = {}); var i = { _s: this.score.toString(20), _f: t, _p: r, _r: Math.random() * r, _t: (new Date).getTime() }, o = this.getListHead(this._passIslands); o._t ? o._n = i : y.default.extend(o, i), isWebGLRenderer && game.getFPS() > 45 && f.Main.CanvasWidth > 2500 && ! function() { var t = new l.ScoreIncrementer; t.addScore(1, n.animalType, function() { e.removeChild(t), t.destroy(), t = null }), e.addChild(t) }(), this.animationAttractor.append(n.getRebornNumber(), n, function(e) { return e.explode() }) }
ãããããé
åãã©ã®ããã«çæãããããæããã«ãªããŸãã ããããå¥ã®é¶ãé£ã¹ããã³ã«ããã®é¢æ°ãåŒã³åºãããæ°ããããŒã¿ãããã¯ãæ¢åã®é
åã«è¿œå ããã_n倿°ã«é
眮ãããŸãã ãŸããã¹ã³ã¢ã«ã¯ã¹ã³ã¢ãèšé²ãããããã¯å°æ°ã®ä»£ããã«å¥ã®èšç®ã«è»¢éãããå°æ°ã·ã¹ãã ã®æ°å€ã¯éçºè
ã«ããå¥ã®åéãã¯ããã¯ã§ããã¹ã³ã¢ã«èšé²ãããŸããã ã¹ã¯ãªãããæ¹åãã代ããã«ããã¬ãŒã¯ãã€ã³ããèšå®ããã¹ã³ã¢ããã®å Žã§çœ®ãæããããšã«ããŸããã

ã³ãŒãã§ã¹ã³ã¢ãèšå®ããçŽåã ã³ã³ãœãŒã«ã§å€ã倿Žããã¹ã¯ãªãããç¶è¡ããŸãã

ãããŠãç§ã¯èªåã®ä»äºã«å ±ãããŸããã

å°ãåŸã§äžè¬çãªã¹ã³ã¢ããŒãã«è¿œå ãããŸããã

1ã€ã®é
åã ãã§ãã€ã³ãã倿Žã§ããããšã¯æ³šç®ã«å€ããŸãã _sãã©ã¡ãŒã¿ãŒã§ã20æ¡ã®èšç®ã·ã¹ãã ã§å¿
èŠãªãã€ã³ãæ°ãæžãçããçæãããããŒïŒmd5圢åŒïŒã䜿çšããŠãããããã¹ãŠãã«ã¹ã¿ã aesã¢ã«ãŽãªãºã ã§æå·åããŸãã ããŒã¯ãã£ããIDã«åºã¥ããŠçºè¡ãããã²ãŒã äžã«å€æŽãããªãããšã«æ³šæããŠãã ããã ãã®ã²ãŒã ã®idã¢ã«ãŠã³ãã«åºã¥ããŠãå°ãªããšã10äžäººããã¬ã€ãããšçµè«ä»ããããšãã§ããŸãã
ãµãŒããŒã®è匱æ§ãåå ã§ãã®æ»æãå®äºããããšã«æ³šæããŠãã ããã ã³ãŒãã¯JSONã§åä¿¡ããã埩å·åãããŸãããããããæå€§ã®_sãæã€é
åãããŒã¿é
åããååŸããã1ã€ã ãã§ããããšã¯åé¡ã§ã¯ãããŸããã ããã¯ç°¡åã«ä¿®æ£ã§ããŸããé
åå
šäœãè§£æããŠ_sã®å¢åãå¢ããããã®ãã©ã¡ãŒã¿ãŒã®å€ãJSONããªãŒã®åºçŸæ°ãšäžèŽããããšã確èªããå¿
èŠããããŸãã
ã©ã®ãããªçµè«ãåºãããšãã§ããŸããïŒ ã¯ã©ã€ã¢ã³ãåŽã§åŠçããããã®ã¯ãã¹ãŠå€æŽã眮æã§ããŸããããŒã¿ã®æå·åã®é£æåºŠãã³ãŒãã®é£èªåã®çšåºŠã¯åé¡ã§ã¯ãããŸããã ããã§ããéçºè
ã®ã²ãŒã ãTricky Foxãã«éåžžã«æºè¶³ããŠããŸãã ããã¯ãæå€§1ã2æéãè²»ããå¿
èŠãããã²ãŒã ã§ãããäžæ£è¡çºãé²ããããžãã¯ããã€ãã¹ããããã®å¯Ÿçãè¬ããå¿
èŠããããŸãã ã¡ã¬ãã倿Žããããšã«äžæ³šæãªæ
床ãæã€ä»ã®ãã人æ°ã®ããã²ãŒã ã®èæ¯ã«å¯ŸããŠãã²ãŒã ã¯éåžžã«ããã§ããŠããŸãã 芪æãªãèªè
ãç¬èªã®ã²ãŒã ãéçºãããå Žåããã®èšäºã®ã±ãŒã¹ãå®éã«åæããŠãçŸããè峿·±ãã²ãŒã ã ãã§ãªããéåžžã«ä¿è·ãããã²ãŒã ãäœæã§ããŸãã
æ€èšãã䟡å€ã®ããè峿·±ãã²ãŒã ããããäžèšã®æ¹æ³ã§ã¯è§£æ±ºã§ããªãå Žåã¯ã
VKãŸãã¯
ãã¬ã°ã©ã ãŸãã¯ã³ã¡ã³ããéã£ãŠãã ãããæ€èšã詊ã¿ãŸãã èŠæ±ã®ååã«ã¯BurpSuiteã䜿çšããŸããã
PSå€ãã®ã²ãŒã ã®ãã€ã³ãã眮ãæããã«ã¯ã
Telegram CheatsãµãŒãã¹ã䜿çšã§ããŸãã ããããããã«ã¯ããã¹ãŠã®ã²ãŒã ãã ãŸãããããã§ã¯ãããŸããã