 |
Cheat Engine The Official Site of Cheat Engine
|
| View previous topic :: View next topic |
| Author |
Message |
Snootae Grandmaster Cheater
Reputation: 0
Joined: 16 Dec 2006 Posts: 969 Location: --->
|
Posted: Thu Feb 07, 2008 3:47 am Post subject: Read Process Memory |
|
|
I was just wondering wether the delphi readprocessmemory funtion is blocked by gameguard, i'm fairly sure writeprocessmemory is, i just thought id ask about reading memory
_________________
|
|
| Back to top |
|
 |
Losplagos Expert Cheater
Reputation: 0
Joined: 21 Mar 2006 Posts: 172 Location: Knee deep in a c++ book
|
Posted: Thu Feb 07, 2008 4:04 am Post subject: |
|
|
Wrong forum and it is detected.
_________________
Earthbound = 31337 |
|
| Back to top |
|
 |
DeletedUser14087 I post too much
Reputation: 2
Joined: 21 Jun 2006 Posts: 3069
|
Posted: Thu Feb 07, 2008 5:15 am Post subject: |
|
|
it doesn't matter if it's delphi or C or masm, the rpm is called the same from every compiler, and yes it's hooked too.
the reason you're asking for delphi because you used kBot source, just admit it, i don't give a shit.
|
|
| Back to top |
|
 |
mOnSoOn Expert Cheater
Reputation: 0
Joined: 05 Jul 2007 Posts: 203
|
Posted: Thu Feb 07, 2008 5:52 am Post subject: |
|
|
| Rot1 wrote: | it doesn't matter if it's delphi or C or masm, the rpm is called the same from every compiler, and yes it's hooked too.
the reason you're asking for delphi because you used kBot source, just admit it, i don't give a shit. |
Not all Delphi stuffs are yours
appalsap said it too long time ago. Stop thinking that Delphi is yours and every single developer is a fucking stealer
|
|
| Back to top |
|
 |
DeletedUser14087 I post too much
Reputation: 2
Joined: 21 Jun 2006 Posts: 3069
|
Posted: Thu Feb 07, 2008 6:32 am Post subject: |
|
|
| mOnSoOn wrote: | | Rot1 wrote: | it doesn't matter if it's delphi or C or masm, the rpm is called the same from every compiler, and yes it's hooked too.
the reason you're asking for delphi because you used kBot source, just admit it, i don't give a shit. |
Not all Delphi stuffs are yours
appalsap said it too long time ago. Stop thinking that Delphi is yours and every single developer is a fucking stealer  |
stop being jealous ,what do you know ? nothing so STFU
|
|
| Back to top |
|
 |
Anden100 Grandmaster Cheater
Reputation: 0
Joined: 20 Apr 2007 Posts: 668
|
Posted: Thu Feb 07, 2008 8:32 am Post subject: |
|
|
its kinda right, since Rot1 released his source, a crap load of bots has been here... all who got the source, now knows how to do it...
shl 16...
|
|
| Back to top |
|
 |
Noz3001 I'm a spammer
Reputation: 26
Joined: 29 May 2006 Posts: 6220 Location: /dev/null
|
Posted: Thu Feb 07, 2008 8:34 am Post subject: |
|
|
| Rot1 wrote: | | mOnSoOn wrote: | | Rot1 wrote: | it doesn't matter if it's delphi or C or masm, the rpm is called the same from every compiler, and yes it's hooked too.
the reason you're asking for delphi because you used kBot source, just admit it, i don't give a shit. |
Not all Delphi stuffs are yours
appalsap said it too long time ago. Stop thinking that Delphi is yours and every single developer is a fucking stealer  |
stop being jealous ,what do you know ? nothing so STFU |
Time of the month for Kaspersky? ^^.
|
|
| Back to top |
|
 |
DeletedUser14087 I post too much
Reputation: 2
Joined: 21 Jun 2006 Posts: 3069
|
Posted: Thu Feb 07, 2008 8:34 am Post subject: |
|
|
| Anden100 wrote: | its kinda right, since Rot1 released his source, a crap load of bots has been here... all who got the source, now knows how to do it...
shl 16... |
well, it's not something hard, it's basic stuff knowing all that.
and it's good that alot of bots are being made, since i stopped making, i acutally MENT to release the src so others will continue making bots, i made it as an example.
|
|
| Back to top |
|
 |
Losplagos Expert Cheater
Reputation: 0
Joined: 21 Mar 2006 Posts: 172 Location: Knee deep in a c++ book
|
Posted: Thu Feb 07, 2008 8:37 am Post subject: |
|
|
You will more than likely have to learn c++ and asm since the days of standalone delphi programs for cheating are limited EDIT: if not over.
_________________
Earthbound = 31337 |
|
| Back to top |
|
 |
Reak I post too much
Reputation: 0
Joined: 15 May 2007 Posts: 3496
|
Posted: Thu Feb 07, 2008 9:04 am Post subject: |
|
|
FUCK THIS.
Yes there has been released a lot of bot's since kaspersky released his source.
But I think it's not because of the "shl 16" shit it's because everyone releized that there's a rehooked PostMessageA "version" is out called "PMX.dll" or "hookhop.dll" or they just didn't know how to static load a dll.
The "shl 16" thing is not everything for it, yea it's important for SOME keys but it's not the core of a bot.
And @Rot1:
This is basic stuff? No I think it's not. Well MapVirtualKey maybe but that with "shl 16" isn't. I really would like to know how you got that "idea".
@Ontopic: Nobody really can explain that, Kaspersky always just says "It's hooked in ring0" YAY Now I know everything. He is just saying what someone else told him.
So my question:
Well to rehook PostMessageA we just overrite these 5 bytes in PostMessageA in user32.dll, could we do the same with ReadProcessMemory?
Here what I copied out of kernel32.dll from ReadProcessMemory:
| Code: | mov edi, edi
PUSH EBP
MOV EBP, ESP
LEA EAX, DWORD PTS SS:[EBP+14]
PUSH EAX
PUSH DWORD PTR SS:[EBP+14]
PUSH DWORD PTR SS:[EBP+10]
PUSH DWORD PTR SS:[EBP+C]
PUSH DWORD PTR SS:[EBP+9]
CALL DWORD PTR DS:[<&ntdll.NtReadVirtual>
MOV ECX,DWORD PTR SS:[EBP+18]
TEST ECX,ECX
JNZ SHORT kernel32.7C8021F9
TEST EAX,EAX
JL SHORT kernel32.7C802200
XOR EAX, EAX
INC EAX
POP EBP
RETN 14
MOV EDX,DWORD PTR SS:[EBP+14]
MOV DWORD PTR DS:[ECX],EDX
JMP SHORT kernel32.7C8021EE
PUSH EAX
CALL kernel32.7C80936B
XOR EAX,EAX
JMP SHORT kernel32.7C8021F5 |
|
|
| Back to top |
|
 |
lurc Grandmaster Cheater Supreme
Reputation: 2
Joined: 13 Nov 2006 Posts: 1900
|
Posted: Thu Feb 07, 2008 9:13 am Post subject: |
|
|
| rEakW0n wrote: |
@Ontopic: Nobody really can explain that, Kaspersky always just says "It's hooked in ring0" YAY Now I know everything. He is just saying what someone else told him.
So my question:
Well to rehook PostMessageA we just overrite these 5 bytes in PostMessageA in user32.dll, could we do the same with ReadProcessMemory?
Here what I copied out of kernel32.dll from ReadProcessMemory:
| Code: | mov edi, edi
PUSH EBP
MOV EBP, ESP
LEA EAX, DWORD PTS SS:[EBP+14]
PUSH EAX
PUSH DWORD PTR SS:[EBP+14]
PUSH DWORD PTR SS:[EBP+10]
PUSH DWORD PTR SS:[EBP+C]
PUSH DWORD PTR SS:[EBP+9]
CALL DWORD PTR DS:[<&ntdll.NtReadVirtual>
MOV ECX,DWORD PTR SS:[EBP+18]
TEST ECX,ECX
JNZ SHORT kernel32.7C8021F9
TEST EAX,EAX
JL SHORT kernel32.7C802200
XOR EAX, EAX
INC EAX
POP EBP
RETN 14
MOV EDX,DWORD PTR SS:[EBP+14]
MOV DWORD PTR DS:[ECX],EDX
JMP SHORT kernel32.7C8021EE
PUSH EAX
CALL kernel32.7C80936B
XOR EAX,EAX
JMP SHORT kernel32.7C8021F5 |
|
You can to trampoline ReadProcessMemory but if you look u see
| Code: | | CALL DWORD PTR DS:[<&ntdll.NtReadVirtual>] |
NtReadVirtual is hooked in Kernel mode-level so you would have to create a driver to hook your own NtReadVirtual ( im guessing cheat engines driver is similar.. ill take a look at it later. )
Edit:
| Losplagos wrote: | | ... it is detected. |
RPM/WPM arent "Detected" they are simply hooked by Gameguard so when you call a API such as RPM Gameguard's driver simply blocks the API's use
_________________
Last edited by lurc on Thu Feb 07, 2008 9:21 am; edited 2 times in total |
|
| Back to top |
|
 |
Reak I post too much
Reputation: 0
Joined: 15 May 2007 Posts: 3496
|
Posted: Thu Feb 07, 2008 9:16 am Post subject: |
|
|
hey see, that sounds nice
|
|
| Back to top |
|
 |
DeletedUser14087 I post too much
Reputation: 2
Joined: 21 Jun 2006 Posts: 3069
|
Posted: Thu Feb 07, 2008 9:19 am Post subject: |
|
|
| rEakW0n wrote: | FUCK THIS.
Yes there has been released a lot of bot's since kaspersky released his source.
But I think it's not because of the "shl 16" shit it's because everyone releized that there's a rehooked PostMessageA "version" is out called "PMX.dll" or "hookhop.dll" or they just didn't know how to static load a dll.
The "shl 16" thing is not everything for it, yea it's important for SOME keys but it's not the core of a bot.
And @Rot1:
This is basic stuff? No I think it's not. Well MapVirtualKey maybe but that with "shl 16" isn't. I really would like to know how you got that "idea".
@Ontopic: Nobody really can explain that, Kaspersky always just says "It's hooked in ring0" YAY Now I know everything. He is just saying what someone else told him.
So my question:
Well to rehook PostMessageA we just overrite these 5 bytes in PostMessageA in user32.dll, could we do the same with ReadProcessMemory?
Here what I copied out of kernel32.dll from ReadProcessMemory:
| Code: | mov edi, edi
PUSH EBP
MOV EBP, ESP
LEA EAX, DWORD PTS SS:[EBP+14]
PUSH EAX
PUSH DWORD PTR SS:[EBP+14]
PUSH DWORD PTR SS:[EBP+10]
PUSH DWORD PTR SS:[EBP+C]
PUSH DWORD PTR SS:[EBP+9]
CALL DWORD PTR DS:[<&ntdll.NtReadVirtual>
MOV ECX,DWORD PTR SS:[EBP+18]
TEST ECX,ECX
JNZ SHORT kernel32.7C8021F9
TEST EAX,EAX
JL SHORT kernel32.7C802200
XOR EAX, EAX
INC EAX
POP EBP
RETN 14
MOV EDX,DWORD PTR SS:[EBP+14]
MOV DWORD PTR DS:[ECX],EDX
JMP SHORT kernel32.7C8021EE
PUSH EAX
CALL kernel32.7C80936B
XOR EAX,EAX
JMP SHORT kernel32.7C8021F5 |
|
you sound like you're in panic since i released kBot source, learn delphi noob.
http://www.delphibasics.co.uk/RTL.asp?Name=Shl
btw, i'm not sure if it's on ring0, i think ring1.
and it's NOT hooked the same method as PostMessageA, idiot.
even on usermode.
|
|
| Back to top |
|
 |
lurc Grandmaster Cheater Supreme
Reputation: 2
Joined: 13 Nov 2006 Posts: 1900
|
Posted: Thu Feb 07, 2008 9:27 am Post subject: |
|
|
| Rot1 wrote: | | rEakW0n wrote: | FUCK THIS.
Yes there has been released a lot of bot's since kaspersky released his source.
But I think it's not because of the "shl 16" shit it's because everyone releized that there's a rehooked PostMessageA "version" is out called "PMX.dll" or "hookhop.dll" or they just didn't know how to static load a dll.
The "shl 16" thing is not everything for it, yea it's important for SOME keys but it's not the core of a bot.
And @Rot1:
This is basic stuff? No I think it's not. Well MapVirtualKey maybe but that with "shl 16" isn't. I really would like to know how you got that "idea".
@Ontopic: Nobody really can explain that, Kaspersky always just says "It's hooked in ring0" YAY Now I know everything. He is just saying what someone else told him.
So my question:
Well to rehook PostMessageA we just overrite these 5 bytes in PostMessageA in user32.dll, could we do the same with ReadProcessMemory?
Here what I copied out of kernel32.dll from ReadProcessMemory:
| Code: | mov edi, edi
PUSH EBP
MOV EBP, ESP
LEA EAX, DWORD PTS SS:[EBP+14]
PUSH EAX
PUSH DWORD PTR SS:[EBP+14]
PUSH DWORD PTR SS:[EBP+10]
PUSH DWORD PTR SS:[EBP+C]
PUSH DWORD PTR SS:[EBP+9]
CALL DWORD PTR DS:[<&ntdll.NtReadVirtual>
MOV ECX,DWORD PTR SS:[EBP+18]
TEST ECX,ECX
JNZ SHORT kernel32.7C8021F9
TEST EAX,EAX
JL SHORT kernel32.7C802200
XOR EAX, EAX
INC EAX
POP EBP
RETN 14
MOV EDX,DWORD PTR SS:[EBP+14]
MOV DWORD PTR DS:[ECX],EDX
JMP SHORT kernel32.7C8021EE
PUSH EAX
CALL kernel32.7C80936B
XOR EAX,EAX
JMP SHORT kernel32.7C8021F5 |
|
you sound like you're in panic since i released kBot source, learn delphi noob.
http://www.delphibasics.co.uk/RTL.asp?Name=Shl
btw, i'm not sure if it's on ring0, i think ring1.
and it's NOT hooked the same method as PostMessageA, idiot.
even on usermode. |
Rofl, sumeones PMSing
learn to calm down Rot1.
_________________
|
|
| Back to top |
|
 |
Reak I post too much
Reputation: 0
Joined: 15 May 2007 Posts: 3496
|
Posted: Thu Feb 07, 2008 9:55 am Post subject: |
|
|
Are you kiddin me?
You think I took everything of you're fucking source?
All I took from your "work" is the shl 16 shit.
And see, that's what I mean. He's just talking shit "I think it's not ring0 it's ring3" fuck you know nothing about it so you should stfu, don't act like you know it. I don't know it and do I act like I do ? no.
Just stay out of this topic, we don't need wannabe-knowers.
You can answer what you want, I wont respond.
Edit: And now don't come on msn and tell me "why are you insulting me in cef" ...fuck you should know why
|
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
|