Link Unit Below Tabs

Spacing

Showing posts with label Charles. Show all posts
Showing posts with label Charles. Show all posts

Super Ore Mine Hack






The Super Ore Mine Hack has been known for a while by many people--probably from the day the Super Ore Mine came out.  It's not hard to figure out if you know how to interpret the game's client/server communication using a proxy like Charles.

The Super Ore Mine allows you to build the four ores that are not your "natural" one.  For instance, if you can naturally build copper, then the other four ores would be aluminum, uranium, iron, and gold. The order of these four ores are used in the game for certain things like quest requirements, military contract costs, and the Super Ore Mine.

The Super Ore Mine Hack modifies the amount of resources that Super Ore Mine contracts give out by changing the multipliers.  It's also possible to get ores that you haven't unlocked for the Super Ore Mine in the game yet, as well as oil, wood, and coins!  (I don't think many people know about the coins part.)


Survival Mode Hack Using Charles Proxy





[PATCHED May 3, 2012]

The Depot Hack was patched on April 12, 2012.  Soon after, I published the article "Survival Mode Hack Using Cheat Engine".  In response, I received many comments (most of which I did not publish) that would have been unnecessary if the person making the comment had read the article carefully all the way through.  Don't make the same mistake with this article.

This article will explain essentially the same hack but using Charles Proxy instead of Cheat Engine.  You should take advantage of this hack and make as many items as you want before the hack is patched!


World Domination Bug: Can't Attack



There are several different bugs that players encounter when trying to fight in World Domination.  With one bug, you can't select an opponent to attack as in the following images:



Expansion Hack


 

From the 6 "expansions" you start out with in the game, you need another 190 expansions to fully expand.  If you check my Expansions table, you'll see that that requires 44,627,019 Coins and 37,560 Liberty Bonds, not counting crewed expansions.  If you accumulated about 100 Liberty Bonds per day, it would take about a year to get that many Liberty Bonds to fully expand.  It is a tedious, long-term endeavor, indeed.

Here's a trick to fully expand quickly.  I assume that you are familiar with Charles, the popular web debugging proxy application, or Cheat Engine.  The first approach I'll describe is just to get you to understand the idea.  You'll actually want to use the second approach to do many expansions at once without having to refresh the game.

If you are familiar with Cheat Engine but not Charles, do not be discouraged!  It's possible to just do the first approach using Cheat Engine alone--just ignore everything about Charles.

[March 29, 2012 note: I just wrote another article "Expansion Hack #2" that slightly modifies the Cheat Engine approach explained here.  The method in this other article avoids refreshing and sets the Coins requirement for expansion to 0.]


First Approach

The first approach can be done using either Charles or Cheat Engine.  Using Charles is the safer approach as it makes one small modification in one request, and doesn't modify the state of the game otherwise.  Using Cheat Engine is more dangerous but simpler.

Make sure you have enough Coins and Liberty Bonds to do an expansion first.


First Approach Using Cheat Engine

Scan for the text "x01" and replace it with the text "x10".  It works better if you INCLUDE the quotes in your search.  Once you do this, do not look at the Expansions tab of your inventory as that will freeze the game.


Now make an expansion.  The expansion's cost in Coins and Liberty Bonds will be deducted.  However, if you refresh the game, you will see that your Liberty Bonds and Coins are back to their original numbers but your new expansion is still there!

Repeat the process as desired.  Expansion costs are scaled, so you will need an ever increasing number of Coins and Liberty Bonds.  Another annoying part of this process is having to constantly refresh the game.  There's a way to avoid this using Charles--see "Second Approach".


First Approach Using Charles

Make sure breakpoints are set on the "flashservices" subfolder of "http://fb-client-zc.empire.zynga.com".  Now do an expansion.  Look for an AMF request with target "BaseService.dispatchBatch," one of whose objects has functionName "UserService.buyExpansion."  Look for code "x01" (this is the code for an Expansion) and change it to "x10".  Execute all requests.



If you refresh the game, you will see that your Liberty Bonds and Coins are back to their original numbers but your new expansion is still there!

Repeat the process as desired.  Expansion costs are scaled, so you will need an ever increasing number of Coins and Liberty Bonds.  Another annoying part of this process is having to constantly refresh the game.  There's a way to avoid this using Charles.


Second Approach

Here's how to do as many expansions as you like without having to refresh the game.  You will need to use both Charles and Cheat Engine.

Refresh the game and set breakpoints on in Charles.  Look for the AMF request that contains "userInfo".



Look under "world" for "resources" and then "coins."  Change the number of Coins to an amount sufficient to do all of your expansions, say 99999999 (99 million and a lot of change; there are eight 9's).  Try not to use commas as I don't know if the game server will accept them.




Now, look under "player" for "inventory" and then "items".  Search for "xk01" (Liberty Bonds).  Change the number for it to an amount sufficient to do all your expansions, say 40000.



Execute all requests and the game should load.  Now use Cheat Engine to change the text "x01" to "x10".  Once you do this, do not look at the Expansions tab of your inventory as that will freeze the game.  Now, start expanding!

You'll find that the most annoying and tedious part of this whole process is doing the actual expansions!


How to Sell Unsellable Objects




Do you regret placing one (or several) of those many buildings that Zynga offered you?  Even worse, some of them are unsellable.  Unsellable buildings and other objects include:
  • Parliament
  • World Embassy
  • Famine Relief Farm
  • War Room
  • Titan Lab
  • Strike Teams HQ
  • Defense Towers
  • Treasure Vault
  • Heavenly Ruler's Palace
  • Super Ore Mine
  • Energy Cradle
  • Surveillance Tower
  • Alcatraz
  • Missile Launch Station
  • Element Z Rig given to you by Zynga (the ones you build are sellable)
  • Trees, shrubs, rocks
  • Depots that cannot be sold because they contain invalid items

One way to get rid of them is to contact customer service and ask them to remove the offending item for you.  Now, you may not want to go to that trouble for whatever reason.  Here's another way to do it.

I assume that you are familiar with and know how to use a program called Charles, a popular web debugging proxy application.  We will use Charles to transform the unsellable object to a sellable one and then sell that object.  Technically, the title of this article isn't correct.

I assume you are using the free trial version of Charles, which has the "Find" feature disabled.  If you have the full version of Charles, you can shorten the process by using "Find" to search for the item you want to get rid of instead of looking for it through its item id.  You will need to know the itemName of the object you want to get rid of.  In this case, you can skip step 1 and move on to the middle of step 2, keeping in mind to use the "Find" feature.

(Yet another way to get rid of unsellable objects is to use a certain bot, which I won't discuss in this article.)

Step 1

The first step is to get the item id of the building you want to get rid of.  For example, let's say it's the Heavenly Ruler's Palace.

Have the game and Charles open.  Turn breakpoints on for the E&A game server address "http://fb-client-zc.empire.zynga.com" so that requests between the client and game server will be intercepted and halted by Charles.  This gives you a chance to look at or modify requests before they're passed through.

Now, move the Palace from one spot to another (or to the same spot).  Go to Charles and look for the AMF request that looks like the one in the following image.  It will be one of a batch of requests being sent from the client to the server, so the "move" request might not be the first Object ("[0]") in the array of arguments as it is in the image below.  Once you find this request, you can turn breakpoints off temporarily so that new requests don't refresh your screen.




The client sends this "move" request to the game server to tell it that an object in the game world is to be moved.  Notice the function being called is "WorldService.performAction" and the action parameter is "move."  The first object argument contains the object being moved.  Verify that the itemName is "Palace" and record the id for the next step.  Here, the id is 2705 but yours will likely be different.

There's no need to modify this request.

Step 2

Refresh the game and keep executing requests.  Right before you get the game load screen or just at the beginning of it, turn on breakpoints again if you had turned them off temporarily.

Look for the AMF request that looks like the one in the following image.  Once you find it, you can turn off breakpoints.  Here, the request is being sent from the server to the client, telling the client how to populate the game world.  The "objects" subtree contains all the objects in your game world.  There can be hundreds or even thousands of objects.





You want to look through this list for the Heavenly Ruler's Palace.  The numbers 0-3 that you see (and many more that you can't see) in the image above just number the objects in the array; they don't identify them.  You need to open up each numbered subtree to check what the object is.  These id's are not consecutive and don't correspond to the array indices.  For example, in the image below, the three consecutive id's 2440, 2705, and 2726 are ordered but not consecutive. 


(If you have the full version of Charles, you should have skipped to here and used the "Find" feature to search for "Palace".  To get rid of other objects, you need to know their itemNames.)

However, you can use the fact that the objects are ordered by id to look for the id you found in step one for the Heavenly Ruler's Palace.  Confirm that you found the correct id by verifying that it corresponds to the correct itemName.  Here, id 2705 correctly corresponds to itemName "Palace."





Step 3

What we want to do is change the unsellable Palace to some other building that is sellable.  You'll have to know the proper itemName of the object that you want to transform the Palace into.  One possiblity is an Oil Well III, whose itemName is "Oil Derrick 3".

Double-click on "Palace" and change it to "Oil Derrick 3".  This tells the game client to load an Oil Well III instead of a Heavenly Ruler's Palace.  Now execute all requests that were caught by Charles.  The game should now finish loading and you should see an Oil Well III where your Palace once was.  Sell it.  If you refresh your game, you should find that your Palace has permanently disappeared.