[Request] Ninja Warz
-migrated-
[Request] Ninja Warz Posted on: 12/09/2009 7:07am
Quote Post
anyone play Ninja Warz??? was wandering if anyone know any hack for it
Re: [Request] Ninja Warz Posted on: 03/09/2010 8:05pm
Quote Post
no hacks but I wrote an autoit script for it that auto attacks npcs until it runs out npcs up to 3 lvs higher (because each npc can only be hit 5 times within a certain time). It would take a bit of work to make it public workable as I only tested it on my machine. I use Image searching to click what I need and to find the NPC avatars to fight only them, it also refreshes the page when a search times out.

Only took a few hours but I'll help someone to get it working for themselves they want to contact me, so long as my code is not released publicly in any way shape or form.
Re: [Request] Ninja Warz Posted on: 04/16/2010 1:18pm
Quote Post
i need hacks for this game to ...
some one have ?
Re: [Request] Ninja Warz Posted on: 04/16/2010 2:23pm
Quote Post
System Bot
Always add the link: (thanks Derek (broken image removed))
http://www.facebook.com/apps/applicatio ... 7198662055

What hacks do you guys want? Hp, Damage?

Edit: @Derek damn your right.. I was in the Kong section some seconds ago.. forgot that this was the Facebook section. :lol: I wonder why a game with the exact same name is on Kong too.. but its really different from that one..

This post was imported from an account that no longer exists!
Previous Name: phreneticus
Re: [Request] Ninja Warz Posted on: 04/16/2010 2:51pm
Quote Post
Always add the right link
http://www.facebook.com/apps/application.php?id=147198662055

Appears they have server checks in place (what Facebook game doesn't these days :roll: ) so hacks aren't going to be very likely. Try

To gain karma from training but I seriously doubt it will work.
60 8c 06 d2 a0 68 8c 06 -> 60 8c 06 d2 a1 68 8c 06
Re: [Request] Ninja Warz Posted on: 04/16/2010 4:14pm
Quote Post
System Bot
I will test that AOB out..

Btw. if you're injured, speedhack helps you to heal pretty fast without spending money.

Edit: Derek you genius! +1! (broken image removed)
Edit2: Meh.. I thought it would really work.. but it changes just the displayed number of Karma, your actual Karma does not increase :cry:

Get gold if you buy something:
5e 8a 06 60 8a 06 d1 a0 68 8a 06 =>
5e 8a 06 60 8a 06 d1 a1 68 8a 06

Edit3: As I thought.. same thing as Dereks AOB, it just changes the displayed number of Gold.. the actual gold value seems to be sever-sided. :cry:

+100 levels per level up: (not sure if it will work)
60 dd 05 24 01 =>
60 dd 05 24 64

This post was imported from an account that no longer exists!
Previous Name: phreneticus
Re: [Request] Ninja Warz Posted on: 04/18/2010 3:54pm
Quote Post
all what you give me works ?
Re: [Request] Ninja Warz Posted on: 04/18/2010 3:57pm
Quote Post
System Bot
Quote from: "FireShark"
all what you give me works ?

None of these "really" works. It just changes the number of gold/karma that is diplayed on your screen. In-game it changes nothing, because your actual gold/karma value is server-sided.

I just read something in the CE forum about server-sided games and we could try to hack it with another program, that is called "Winsock Packet Editor Pro".

http://forum.cheatengine.org/viewtopic.php?t=103473
http://ragnarok-hacks-bots.blogspot.com ... orial.html

Package for buying/selling something:
Code: [Select]
50 4F 53 54 20 2F 61 6A 61 78 2F 73 65 6C 6C 5F 69 74 65 6D 3F 50 48 50 53 45 53 53 49 44 3D 73 38 6D 30 67 70 31 67 68 38 61 69 38 6B 37 6C 6E 35 6A 32 69 33 71 31 62 75 65 6C 34 33 39 71 20 48 54 54 50 2F 31 2E 31 0D 0A 48 6F 73 74 3A 20 6E 69 6E 6A 61 77 61 72 7A 2E 62 72 6F 6B 65 6E 62 75 6C 62 73 74 75 64 69 6F 73 2E 63 6F 6D 0D 0A 55 73 65 72 2D 41 67 65 6E 74 3A 20 4D 6F 7A 69 6C 6C 61 2F 35 2E 30 20 28 57 69 6E 64 6F 77 73 3B 20 55 3B 20 57 69 6E 64 6F 77 73 20 4E 54 20 36 2E 31 3B 20 64 65 3B 20 72 76 3A 31 2E 39 2E 32 2E 33 29 20 47 65 63 6B 6F 2F 32 30 31 30 30 34 30 31 20 46 69 72 65 66 6F 78 2F 33 2E 36 2E 33 0D 0A 41 63 63 65 70 74 3A 20 74 65 78 74 2F 68 74 6D 6C 2C 61 70 70 6C 69 63 61 74 69 6F 6E 2F 78 68 74 6D 6C 2B 78 6D 6C 2C 61 70 70 6C 69 63 61 74 69 6F 6E 2F 78 6D 6C 3B 71 3D 30 2E 39 2C 2A 2F 2A 3B 71 3D 30 2E 38 0D 0A 41 63 63 65 70 74 2D 4C 61 6E 67 75 61 67 65 3A 20 64 65 2D 64 65 2C 64 65 3B 71 3D 30 2E 38 2C 65 6E 2D 75 73 3B 71 3D 30 2E 35 2C 65 6E 3B 71 3D 30 2E 33 0D 0A 41 63 63 65 70 74 2D 45 6E 63 6F 64 69 6E 67 3A 20 67 7A 69 70 2C 64 65 66 6C 61 74 65 0D 0A 41 63 63 65 70 74 2D 43 68 61 72 73 65 74 3A 20 49 53 4F 2D 38 38 35 39 2D 31 2C 75 74 66 2D 38 3B 71 3D 30 2E 37 2C 2A 3B 71 3D 30 2E 37 0D 0A 4B 65 65 70 2D 41 6C 69 76 65 3A 20 31 31 35 0D 0A 43 6F 6E 6E 65 63 74 69 6F 6E 3A 20 6B 65 65 70 2D 61 6C 69 76 65 0D 0A 43 6F 6F 6B 69 65 3A 20 5F 5F 75 74 6D 61 3D 31 31 34 38 31 38 33 32 38 2E 31 36 33 35 33 32 35 38 30 36 2E 31 32 37 31 34 33 37 35 33 34 2E 31 32 37 31 36 30 35 33 32 32 2E 31 32 37 31 36 30 37 35 36 35 2E 36 3B 20 5F 5F 75 74 6D 7A 3D 31 31 34 38 31 38 33 32 38 2E 31 32 37 31 36 30 37 35 36 35 2E 36 2E 36 2E 75 74 6D 63 73 72 3D 61 70 70 73 2E 66 61 63 65 62 6F 6F 6B 2E 63 6F 6D 7C 75 74 6D 63 63 6E 3D 28 72 65 66 65 72 72 61 6C 29 7C 75 74 6D 63 6D 64 3D 72 65 66 65 72 72 61 6C 7C 75 74 6D 63 63 74 3D 2F 6E 69 6E 6A 61 2D 77 61 72 7A 2F 3B 20 50 48 50 53 45 53 53 49 44 3D 73 38 6D 30 67 70 31 67 68 38 61 69 38 6B 37 6C 6E 35 6A 32 69 33 71 31 62 75 65 6C 34 33 39 71 3B 20 62 61 73 65 5F 64 6F 6D 61 69 6E 5F 61 66 34 61 37 64 64 30 35 66 30 62 36 31 62 64 62 63 66 33 34 66 66 64 34 62 35 64 38 66 66 36 3D 6E 69 6E 6A 61 77 61 72 7A 2E 62 72 6F 6B 65 6E 62 75 6C 62 73 74 75 64 69 6F 73 2E 63 6F 6D 3B 20 61 66 34 61 37 64 64 30 35 66 30 62 36 31 62 64 62 63 66 33 34 66 66 64 34 62 35 64 38 66 66 36 3D 34 35 61 61 35 61 61 39 34 30 32 64 35 31 61 36 35 31 65 38 31 66 32 32 32 36 33 65 35 36 34 65 3B 20 61 66 34 61 37 64 64 30 35 66 30 62 36 31 62 64 62 63 66 33 34 66 66 64 34 62 35 64 38 66 66 36 5F 75 73 65 72 3D 31 30 30 30 30 30 39 37 38 31 33 37 31 32 32 3B 20 61 66 34 61 37 64 64 30 35 66 30 62 36 31 62 64 62 63 66 33 34 66 66 64 34 62 35 64 38 66 66 36 5F 73 73 3D 6A 4E 77 5F 4B 48 6A 4A 45 4B 68 68 68 46 35 66 33 4C 54 46 72 51 5F 5F 3B 20 61 66 34 61 37 64 64 30 35 66 30 62 36 31 62 64 62 63 66 33 34 66 66 64 34 62 35 64 38 66 66 36 5F 73 65 73 73 69 6F 6E 5F 6B 65 79 3D 32 2E 6A 4E 77 5F 4B 48 6A 4A 45 4B 68 68 68 46 35 66 33 4C 54 46 72 51 5F 5F 2E 33 36 30 30 2E 31 32 37 31 36 31 33 36 30 30 2D 31 30 30 30 30 30 39 37 38 31 33 37 31 32 32 3B 20 61 66 34 61 37 64 64 30 35 66 30 62 36 31 62 64 62 63 66 33 34 66 66 64 34 62 35 64 38 66 66 36 5F 65 78 70 69 72 65 73 3D 31 32 37 31 36 31 33 36 30 30 3B 20 5F 5F 75 74 6D 63 3D 31 31 34 38 31 38 33 32 38 3B 20 5F 5F 75 74 6D 62 3D 31 31 34 38 31 38 33 32 38 2E 32 2E 31 30 2E 31 32 37 31 36 30 37 35 36 35 3B 20 66 62 73 65 74 74 69 6E 67 5F 61 66 34 61 37 64 64 30 35 66 30 62 36 31 62 64 62 63 66 33 34 66 66 64 34 62 35 64 38 66 66 36 3D 25 37 42 25 32 32 63 6F 6E 6E 65 63 74 53 74 61 74 65 25 32 32 25 33 41 31 25 32 43 25 32 32 6F 6E 65 4C 69 6E 65 53 74 6F 72 79 53 65 74 74 69 6E 67 25 32 32 25 33 41 33 25 32 43 25 32 32 73 68 6F 72 74 53 74 6F 72 79 53 65 74 74 69 6E 67 25 32 32 25 33 41 33 25 32 43 25 32 32 69 6E 46 61 63 65 62 6F 6F 6B 25 32 32 25 33 41 74 72 75 65 25 37 44 0D 0A 52 65 66 65 72 65 72 3A 20 68 74 74 70 3A 2F 2F 6E 69 6E 6A 61 63 64 6E 2E 62 72 6F 6B 65 6E 62 75 6C 62 73 74 75 64 69 6F 73 2E 63 6F 6D 2F 73 77 66 2F 77 65 61 70 6F 6E 73 2F 77 65 61 70 6F 6E 73 2E 73 77 66 3F 33 32 32 0D 0A 43 6F 6E 74 65 6E 74 2D 74 79 70 65 3A 20 61 70 70 6C 69 63 61 74 69 6F 6E 2F 78 2D 77 77 77 2D 66 6F 72 6D 2D 75 72 6C 65 6E 63 6F 64 65 64 0D 0A 43 6F 6E 74 65 6E 74 2D 6C 65 6E 67 74 68 3A 20 37 0D 0A 0D 0A 69 69 64 3D 31 38 31
Edit: TIM, now I need your skills. The above means in text:
Code: [Select]
POST /ajax/sell_item?PHPSESSID=s8m0gp1gh8ai8k7ln5j2i3q1buel439q HTTP/1.1
Host: ninjawarz.brokenbulbstudios.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; de; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Connection: keep-alive
Cookie: __utma=114818328.1635325806.1271437534.1271605322.1271607565.6; __utmz=114818328.1271607565.6.6.utmcsr=apps.facebook.com|utmccn=(referral)|utmcmd=referral|utmcct=/ninja-warz/; PHPSESSID=s8m0gp1gh8ai8k7ln5j2i3q1buel439q; base_domain_af4a7dd05f0b61bdbcf34ffd4b5d8ff6=ninjawarz.brokenbulbstudios.com; af4a7dd05f0b61bdbcf34ffd4b5d8ff6=45aa5aa9402d51a651e81f22263e564e; af4a7dd05f0b61bdbcf34ffd4b5d8ff6_user=100000978137122; af4a7dd05f0b61bdbcf34ffd4b5d8ff6_ss=jNw_KHjJEKhhhF5f3LTFrQ__; af4a7dd05f0b61bdbcf34ffd4b5d8ff6_session_key=2.jNw_KHjJEKhhhF5f3LTFrQ__.3600.1271613600-100000978137122; af4a7dd05f0b61bdbcf34ffd4b5d8ff6_expires=1271613600; __utmc=114818328; __utmb=114818328.2.10.1271607565; fbsetting_af4a7dd05f0b61bdbcf34ffd4b5d8ff6=%7B%22connectState%22%3A1%2C%22oneLineStorySetting%22%3A3%2C%22shortStorySetting%22%3A3%2C%22inFacebook%22%3Atrue%7D
Referer: http://ninjacdn.brokenbulbstudios.com/swf/weapons/weapons.swf?322
Content-type: application/x-www-form-urlencoded
Content-length: 7

iid=181

What does it say? (broken image removed)

This post was imported from an account that no longer exists!
Previous Name: phreneticus
Re: [Request] Ninja Warz Posted on: 04/19/2010 5:42am
Quote Post
i dont know how to use that ...
its hard
Re: [Request] Ninja Warz Posted on: 04/20/2010 1:43pm
Quote Post
TIM the Enchanter
Level: 1
ADR Info
Packet editing is pretty straight forward. Since it's server sided, though, the only good packet editing will do is change what you submit to the server. If they use proper validation, it will simply return an error to you and/or log the request for admin display.

Using a packet sender, though, you could rapidly perform the same action enough times within a second to either overload the server or cause something crazy to happen, or nothing at all. It really depends on how the backend is coded.

The best thing I can suggest is to create a secondary account and test different values of variables being sent. I would suggest to use Paros Proxy, as it's a bit more clear on post/get data as compared to the above. There isn't much I can do with that other than tell you it's performing a basic action and it's sending to (most likely) the following address.

ninjawarz.brokenbulbstudios.com/ajax/sell_item?iid=181&PHPSESSID=s8m0gp1gh8ai8k7ln5j2i3q1buel439q

PHPSESSID=s8m0gp1gh8ai8k7ln5j2i3q1buel439q <Your session in their database.
iid=181 <Item ID 181. Whatever item you sold has an ID of 181 in their database.

I used to use an append_sid() function to add that stupid SID=WHATEVERGARBAGE to the end of all URLs, but there just isn't a point in it anymore. Everything is handled browser side with cookies and what not.


Remember, you can change anything on your computer, but it doesn't change what's on the server. (broken image removed)




Everything's coming up KongHack!

"When you know nothing matters, the universe is yours" ~Rick Sanchez

Re: [Request] Ninja Warz Posted on: 04/20/2010 2:02pm
Quote Post
System Bot
Quote from: "The Ignorant Masses"
Packet editing is pretty straight forward. Since it's server sided, though, the only good packet editing will do is change what you submit to the server. If they use proper validation, it will simply return an error to you and/or log the request for admin display.
Yes.. I thought that too. But I don't really know what I should send to the server. You have to send AOB's in form of Binary codes, as my AOB didn't worked (error).

For example:
a0 20 d0 is in Binary codes:
10100000 00100000 11010000

Quote from: "The Ignorant Masses"
Using a packet sender, though, you could rapidly perform the same action enough times within a second to either overload the server or cause something crazy to happen, or nothing at all. It really depends on how the backend is coded.
Haha oh yes. That program can send the same package insanely many times in one second.. I guess it will be fun fucking up that game for everyone. :lol:

Quote from: "The Ignorant Masses"
The best thing I can suggest is to create a secondary account and test different values of variables being sent. I would suggest to use Paros Proxy, as it's a bit more clear on post/get data as compared to the above.
I just registered there to hack Ninja Warz.. so I don't really care if I get banned. But still I created a second account as backup. (broken image removed)

Quote from: "The Ignorant Masses"
ninjawarz.brokenbulbstudios.com/ajax/sell_item?iid=181&PHPSESSID=s8m0gp1gh8ai8k7ln5j2i3q1buel439q

PHPSESSID=s8m0gp1gh8ai8k7ln5j2i3q1buel439q <Your session in their database.
iid=181 <Item ID 181. Whatever item you sold has an ID of 181 in their database.

I used to use an append_sid() function to add that stupid SID=WHATEVERGARBAGE to the end of all URLs, but there just isn't a point in it anymore. Everything is handled browser side with cookies and what not.
Thanks, that helps me alot. The item with the ID 181 was the first weapon in the shop. I guess it will count up like this: 1st weapon -> 181, 2nd weapon -> 182, etc. :lol: Let's see what I can do...

Quote from: "The Ignorant Masses"
Remember, you can change anything on your computer, but it doesn't change what's on the server. (broken image removed)
Yes, thats why normal AOB's do not work. (broken image removed)

This post was imported from an account that no longer exists!
Previous Name: phreneticus
Re: [Request] Ninja Warz Posted on: 04/20/2010 2:06pm
Quote Post
TIM the Enchanter
Level: 1
ADR Info
/quote not /quotes. (broken image removed)




Everything's coming up KongHack!

"When you know nothing matters, the universe is yours" ~Rick Sanchez

Re: [Request] Ninja Warz Posted on: 04/20/2010 2:10pm
Quote Post
System Bot
Quote from: "The Ignorant Masses"
/quote not /quotes. (broken image removed)

Fix'd. All my text was not displayed before. (broken image removed)

This post was imported from an account that no longer exists!
Previous Name: phreneticus
Re: [Request] Ninja Warz Posted on: 07/01/2010 8:05pm
Quote Post
Checking if any of these hacks still work?