ROM Hack WIP SplatHeX A Splatoon Save Editor

  • Thread starter Thread starter Tonydaexpert
  • Start date Start date
  • Views Views 160,252
  • Replies Replies 353
  • Likes Likes 17
Status
Not open for further replies.
@SimonMKWii take notes tbh. this guy's approach is much better than "here's a png of a rat embedded in the program(?) and an image of some java i found in a hex editor once". dunno if you're trying to say that's in the program itself, but i certainly haven't found any sort of java from the ram dump i did. environment variables with my java path, yes. harmless javascript, sure. anything like what you posted, nah.

do your research before trying to start a witch hunt for attention or whatever.

also the method you used to we can reproduce what you're saying would be helpful.
With all due respect, a RAM dump won't produce anything useful if the payload isn't in RAM. .NET has timers, which noobs tend to use to bypass runtime detections. More "sophisticated" payloads wait for an x amount of idle time before executing. You see this a lot with malicious crypto miners so that they can make full use of the hijacked resources, but yeah.
 
Last edited by Joom,
With all due respect, a RAM dump won't produce anything useful if the payload isn't in RAM. .NET has timers, which noobs tend to use to bypass runtime detections. More "sophisticated" payloads wait for an x amount of idle time before executing. You see this a lot with malicious crypto miners so that they can make full use of the hijacked resources, but yeah.
Yes but he said he got his info from the RAM

It's literally one of the first things you see in the program's RAM objects.
It's clear you didn't even attempt to debug it, you'll see it nearly instantly.


Which make no sense now
 
Yes but he said he got his info from the RAM

Which make no sense now
Nothing he has said so far has been reproduced by anyone else, until he provides detailed steps for other people to follow to confirm his findings I'd say it's fair to say the accusation appears to be unfounded.
 
@SimonMKWii You probably have a RAT on your computer from something else that injects itself into all running processes. This explains why you "found" this icon in the process and no one else has.
 
@SimonMKWii You probably have a RAT on your computer from something else that injects itself into all running processes. This explains why you "found" this icon in the process and no one else has.
Well this is awkward...
You were right, but at least I realised my PC was infected :blush:
The program is safe.
I take full responsibility for this.
Sorry to the program authors and to the users who were misled.
 
  • Like
Reactions: tastymeatball
But you said you've seen a jRAT icon IN SplatHeX.
So, it wasn't in there? You've seen it somewhere else?
You've opened the wrong program with x64dbg?
Also, what about the open port?
 
Looks like you're trying to run it from inside the zip file. Extract it to the desktop and it runs fine.
No, it was already unzipped. It was an issue with the release itself, but they fixed it.
 
  • Like
Reactions: Jayro
Well this is awkward...
You were right, but at least I realised my PC was infected :blush:
The program is safe.
I take full responsibility for this.
Sorry to the program authors and to the users who were misled.
Could you please edit your previous posts in this topic pointing out this mistake of yours? Currently one would have to read until this page to figure out that it was a false alarm.
 
  • Like
Reactions: Darth Meteos
Is this/will this be open sourced? I'm curious how the saves are setup and it seems to be written in a .Net Framework language (hopefully C#) but the binary is obfuscated which is kinda odd to me and searching both Lenny's Github and just the app on GitHub yielded no results.
 
Is this/will this be open sourced? I'm curious how the saves are setup and it seems to be written in a .Net Framework language (hopefully C#) but the binary is obfuscated which is kinda odd to me and searching both Lenny's Github and just the app on GitHub yielded no results.
considering the save is encrypted, the binary probably has the decryption method and key baked into it, and the developers probably don't want people to edit their rank/mmr. i'd say most likely not, but i can't speak for them.
 
considering the save is encrypted, the binary probably has the decryption method and key baked into it, and the developers probably don't want people to edit their rank/mmr. i'd say most likely not, but i can't speak for them.

upload_2018-5-21_14-55-33.png


EDIT: oh edit it I see, hmm C# it could probably be pretty trivial to figure out how to edit that since it already displays it. Anyways I don't even want that I just want to see how the save file is setup. I like reverse engineering ROMs and save games. Its really cool to see everything just match up properly when you figure it out.
 
Last edited by JordantheBuizel,
View attachment 124322

EDIT: oh edit it I see, hmm C# it could probably be pretty trivial to figure out how to edit that since it already displays it. Anyways I don't even want that I just want to see how the save file is setup. I like reverse engineering ROMs and save games. Its really cool to see everything just match up properly when you figure it out.

Would be nice I agree, but frankly it's a Pandora's Box though, and if we open it, I can almost assure you people will find ways to edit their weapon stats, or armor stats to achieve otherwise un-optainable results that provide an impossible advantage in online play.

sure they'll get banned eventually, but it'll still ruin the experience of the game, as you'd not be able to challenge them on equal grounds, no matter your own legit skill, and gear.
 
Last edited by Proto-Propski,
Would be nice I agree, but frankly it's a Pandora's Box though, and if we open it, I can almost assure you people will find ways to edit their weapon stats, or armor stats to achieve otherwise un-optainable results that provide an impossible advantage in online play.

sure they'll get banned eventually, but it'll still ruin the experience of the game, as you'd not be able to challenge them on equal grounds, no matter your own legit skill, and gear.
that's not how gear editing works.
 
  • Like
Reactions: spice2 and ownedlol
Depends from game to game, and how they organize their saves I don't know what a raw Splatoon 2 save looks like to know if they have nitty gritty stuff like that
weapon parameters are in the rom itself. the save only handles gear, weapon stats (turf inked, freshness level), single player stats, flags, etc. typical save stuff. there's no way to give yourself an unfair advantage in splatoon 2, or most multiplayer games, for that matter, by editing your save.
 
  • Like
Reactions: thomasnet
weapon parameters are in the rom itself. the save only handles gear, weapon stats (turf inked, freshness level), single player stats, flags, etc. typical save stuff. there's no way to give yourself an unfair advantage in splatoon 2, or most multiplayer games, for that matter, by editing your save.
Fair enough, thanks for letting me know... I still don't feel entirely ok with anyone having access to it, especially considering IDK how they'll choose to use it, and to what extent they can abuse it, besides SplatHeX has everything a normal user would/could accomplish given enough time which is the only advantage it gives you (time), and besides I like Playing Splatoon 2 enough online that I'd prefer to not have the game ruined any further even if it's more so hopeful thinking to assume it won't get cracked open sooner, or latter given the fact we do already see Octoling Hackers which means something is going on in the background whether with saves, or something else
 
Last edited by Proto-Propski,
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum