HighLeaks
Help

RE: Escrow (fxap) | (un)reputable providers

bundeskanzler_olaf bundeskanzler_olaf Started 26 replies 7,642 views
#1

(DISCLAIMER: This is not about making money, malware or anything else. Just an exchange about idiots and maybe your experience to make FiveM less secure.)



Greetings to everyone in this forum.

I'm actually just looking for an exchange on certain topics, as I've been interested in the escrow system since the beginning and have been working with this system for the last few weeks.
So I would be very pleased if some people would participate here to share knowledge or experience and warn against scammers.

1. My experience with the escrow system.

But first to my status, I have tried several ways to remove or bypass the escrow so far and as you can see from the forum this is quite possible. Since (about) 2022 it is possible to get the server code and possibly outdated client code if scripts have not been updated.

This method only works because the entire server code is available on Github, although important key files such as the (sv|libsv)adhesive.dll are missing and only partially available.

Therefore I have currently tried to get hold of the client code or what most people are interested in assets like MLOs, vehicles or props. Which was not really successful until today. What I can currently claim or say, I am close to manipulating the keymaster to the extent that I could get access to the assets and add that to any script, but no OpenSource version, but due to encryption I leave this approach, because you would have to change the above mentioned file(s) and install a public_key.

I have also tried other approaches by saving myself the whole thing with the verification and decrypting directly, but I just don't have an approach for any encryption. I can identify the tool or library, but I'm missing some keys that grant me access.

If anyone has tried similar things, please contact me (if you are interested) maybe you have more information than I do.

2. Alleged escrow decryption tools.

You probably know some names that advertise this to the extreme and also publish videos, but to be honest, they are all scammers. If the escrow tools worked, nopixel 4.0 maps, for example, would be available everywhere.

So I ask you, has anyone bought expensive products and been scanned? I would be interested to know if this matches my current information.

I'll say this much in advance, I've written to the top 5 alleged service provider accounts, where some have been pulled from restorecord and simply given the role to make it look legitimate. As of today, I know almost 8 providers, one of which I can legitimise that it works, but only on the server side. Which is nothing special, the tool is still available today on workupload or github, so save yourself the 10€ or 45€ for the bot and write me a Discord PN (name in profile).

I would also like to point out an unusual warning about a service called Underground... . There I can still prove fake reviews, fake users, fake customers and fake videos, especially when it comes to boosting.

And if you don't want to contribute, too bad, but thanks for reading [HASH=1570]#HLOnTop[/HASH].

(Also, thanks to DeepL, no need to improve my English.)

#1
So i tried a couple of things like with MLOS its possible like to get them decrypted if the YBN files are working and looking like this

Then there is a lot possible to get the map working if you know how to work with it:)

About those idiots that are selling unlocked of nopixel and everything yes i know about it, i was in a ticket support team of the most scammers named Unknown development soon i will post also some things of them how they work:)Add me in discord whe can talk further Kevindev12

[attachment removed][/attachment]
#2




kevin3091,

wrote:



So i tried a couple of things like with MLOS its possible like to get them decrypted if the YBN files are working and looking like this

Then there is ...




can u send that mlo pleasee[/attachment]
#3




kevin3091,

wrote:



So i tried a couple of things like with MLOS its possible like to get them decrypted if the YBN files are working and looking like this

Then there is ...




ybn are not escrow show us ydr[/attachment]
#4




SKYHUNT,

wrote:



ybn are not escrow show us ydr




Bro cant you read? like what i am saying?? If the YBN look like the picture i sended above like with interior inside you could get the whole mlo out and rebuild it. But as i can see Reading is difficult for some people
#5




igorMendes,

wrote:



can u send that mlo pleasee




CANT YOU READ?
#6




kevin3091,

wrote:



Bro cant you read? like what i am saying?? If the YBN look like the picture i sended above like with interior inside you could get the whole mlo out a...




bruh mb mb i didnt have time to read it all
#7




kevin3091,

wrote:



Bro cant you read? like what i am saying?? If the YBN look like the picture i sended above like with interior inside you could get the whole mlo out a...




so you can remake nopixel mlo right ?
#8




SKYHUNT,

wrote:



so you can remake nopixel mlo right ?




No because there YBN has no interior
#9




bundeskanzler_olaf,

wrote:



(DISCLAIMER: This is not about making money, malware or anything else. Just an exchange about idiots and maybe your experience to make FiveM less secure.)





Greetings to everyone in this forum.



I'm actually just looking for an exchange on certain topics...




sam tho op dev hai sab issko leleo
#10




kevin3091,

wrote:



No because there YBN has no interior




wdym most nopixel ybn have interior and are not escrow like snrbuns i have them
#11




kevin3091,

wrote:



So i tried a couple of things like with MLOS its possible like to get them decrypted if the YBN files are working and looking like this

Then there is ...




Bro @kevin3091, I hope you can contact me on Discord, and this is my account 0xmohammed I want to talk to you[/attachment]
#12
are there any public methods to get the server side code?
#13




mythicmoontm,

wrote:



are there any public methods to get the server side code?




Yes, you can find the POC file or a link to a finished server build on Github.
#14




bundeskanzler_olaf,

wrote:



Yes, you can find the POC file or a link to a finished server build on Github.




what do you mean is there a way to easily write the server side of the client side ?
#15
@@kevin3091 @@bundeskanzler_olaf

CHECK REQ PLEASE
#16




SKYHUNT,

wrote:



what do you mean is there a way to easily write the server side of the client side ?




Unfortunately, everything has to go through the (sv|libsv)adhesive.dll (anticheat + escrow...; all that security shit). The Keymaster system separates client & server files. With grants and grants_clk, which are hashes or maybe just keys as authorisation to unlock the script/map.



On the server, it was easy to bypass this, as the resource loader was included in the Github and could simply intercept the decrypted bytecode (type: .luac) during loading.



Honestly, I looked at the github repo 100%, if the launcher with the streaming system was in there, it would be very easy to intercept. If the launcher is missing and the components for loading too, it becomes more difficult.



But it's not really ‘easy’ unless you have a bit of experience and perhaps find a way.



And who knows whether the portal has now raised its security standards and fixed such exploits.
#17
добре добре добре добре добре добре
#18
Just adding onto this topic. If you have the interior collisions (the YBN file), then yes, it is possible to remake the MLO. BUT

You need a lot of knowledge to be able to do this. From the YBN in blender, essentially you can duplicate it, convert it to a mesh, and then through sollumz, make it a YDR. The issue is, you will have to redo all of the texturing as well for that MLO, etc. And for certain MLOs, such as the nopixel 4.0 ones, texturing in itself is extremely difficult to do,a dn if you don't do it right, it looks like shit. The same goes for ydrs with embedded collisions. Those will have to be remade from scratch, and majority props have embedded colisions anyways, so it will never work. If you really want to decrypt MLOs, you need to find a way to decrypt the xml bytecode that the escrow format converts it into. If you can do that, then it's a game changer, but only very experienced people in the field will even know how to do this.
#19




bundeskanzler_olaf,

wrote:



Unfortunately, everything has to go through the (sv|libsv)adhesive.dll (anticheat + escrow...; all that security shit). The Keymaster system separates...




What if you reverse-engineered the adhesive.dll file and figured out how to encrypt the maps or scripts and created a tool that would decrypt this security shit?
#20




bundeskanzler_olaf,

wrote:



(DISCLAIMER: This is not about making money, malware or anything else. Just an exchange about idiots and maybe your experience to make FiveM less secure.)





Greetings to everyone in this forum.



I'm actually just looking for an exchange on certain topics...




are there any public methods to get the server side code?