Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Read Process Memory
Goto page 1, 2  Next
 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming
View previous topic :: View next topic  
Author Message
Snootae
Grandmaster Cheater
Reputation: 0

Joined: 16 Dec 2006
Posts: 969
Location: --->

PostPosted: Thu Feb 07, 2008 3:47 am    Post subject: Read Process Memory Reply with quote

I was just wondering wether the delphi readprocessmemory funtion is blocked by gameguard, i'm fairly sure writeprocessmemory is, i just thought id ask about reading memory
_________________
Back to top
View user's profile Send private message
Losplagos
Expert Cheater
Reputation: 0

Joined: 21 Mar 2006
Posts: 172
Location: Knee deep in a c++ book

PostPosted: Thu Feb 07, 2008 4:04 am    Post subject: Reply with quote

Wrong forum and it is detected.
_________________

Earthbound = 31337
Back to top
View user's profile Send private message
DeletedUser14087
I post too much
Reputation: 2

Joined: 21 Jun 2006
Posts: 3069

PostPosted: Thu Feb 07, 2008 5:15 am    Post subject: Reply with quote

it doesn't matter if it's delphi or C or masm, the rpm is called the same from every compiler, and yes it's hooked too.

the reason you're asking for delphi because you used kBot source, just admit it, i don't give a shit.
Back to top
View user's profile Send private message
mOnSoOn
Expert Cheater
Reputation: 0

Joined: 05 Jul 2007
Posts: 203

PostPosted: Thu Feb 07, 2008 5:52 am    Post subject: Reply with quote

Rot1 wrote:
it doesn't matter if it's delphi or C or masm, the rpm is called the same from every compiler, and yes it's hooked too.

the reason you're asking for delphi because you used kBot source, just admit it, i don't give a shit.

Not all Delphi stuffs are yours Rolling Eyes
appalsap said it too long time ago. Stop thinking that Delphi is yours and every single developer is a fucking stealer Confused
Back to top
View user's profile Send private message MSN Messenger
DeletedUser14087
I post too much
Reputation: 2

Joined: 21 Jun 2006
Posts: 3069

PostPosted: Thu Feb 07, 2008 6:32 am    Post subject: Reply with quote

mOnSoOn wrote:
Rot1 wrote:
it doesn't matter if it's delphi or C or masm, the rpm is called the same from every compiler, and yes it's hooked too.

the reason you're asking for delphi because you used kBot source, just admit it, i don't give a shit.

Not all Delphi stuffs are yours Rolling Eyes
appalsap said it too long time ago. Stop thinking that Delphi is yours and every single developer is a fucking stealer Confused


stop being jealous ,what do you know ? nothing so STFU
Back to top
View user's profile Send private message
Anden100
Grandmaster Cheater
Reputation: 0

Joined: 20 Apr 2007
Posts: 668

PostPosted: Thu Feb 07, 2008 8:32 am    Post subject: Reply with quote

its kinda right, since Rot1 released his source, a crap load of bots has been here... all who got the source, now knows how to do it...

shl 16...
Back to top
View user's profile Send private message
Noz3001
I'm a spammer
Reputation: 26

Joined: 29 May 2006
Posts: 6220
Location: /dev/null

PostPosted: Thu Feb 07, 2008 8:34 am    Post subject: Reply with quote

Rot1 wrote:
mOnSoOn wrote:
Rot1 wrote:
it doesn't matter if it's delphi or C or masm, the rpm is called the same from every compiler, and yes it's hooked too.

the reason you're asking for delphi because you used kBot source, just admit it, i don't give a shit.

Not all Delphi stuffs are yours Rolling Eyes
appalsap said it too long time ago. Stop thinking that Delphi is yours and every single developer is a fucking stealer Confused


stop being jealous ,what do you know ? nothing so STFU


Time of the month for Kaspersky? ^^.
Back to top
View user's profile Send private message MSN Messenger
DeletedUser14087
I post too much
Reputation: 2

Joined: 21 Jun 2006
Posts: 3069

PostPosted: Thu Feb 07, 2008 8:34 am    Post subject: Reply with quote

Anden100 wrote:
its kinda right, since Rot1 released his source, a crap load of bots has been here... all who got the source, now knows how to do it...

shl 16...


well, it's not something hard, it's basic stuff knowing all that.

and it's good that alot of bots are being made, since i stopped making, i acutally MENT to release the src so others will continue making bots, i made it as an example.
Back to top
View user's profile Send private message
Losplagos
Expert Cheater
Reputation: 0

Joined: 21 Mar 2006
Posts: 172
Location: Knee deep in a c++ book

PostPosted: Thu Feb 07, 2008 8:37 am    Post subject: Reply with quote

You will more than likely have to learn c++ and asm since the days of standalone delphi programs for cheating are limited EDIT: if not over.
_________________

Earthbound = 31337
Back to top
View user's profile Send private message
Reak
I post too much
Reputation: 0

Joined: 15 May 2007
Posts: 3496

PostPosted: Thu Feb 07, 2008 9:04 am    Post subject: Reply with quote

FUCK THIS.
Yes there has been released a lot of bot's since kaspersky released his source.
But I think it's not because of the "shl 16" shit it's because everyone releized that there's a rehooked PostMessageA "version" is out called "PMX.dll" or "hookhop.dll" or they just didn't know how to static load a dll.
The "shl 16" thing is not everything for it, yea it's important for SOME keys but it's not the core of a bot.

And @Rot1:
This is basic stuff? No I think it's not. Well MapVirtualKey maybe but that with "shl 16" isn't. I really would like to know how you got that "idea".

@Ontopic: Nobody really can explain that, Kaspersky always just says "It's hooked in ring0" YAY Now I know everything. He is just saying what someone else told him.
So my question:
Well to rehook PostMessageA we just overrite these 5 bytes in PostMessageA in user32.dll, could we do the same with ReadProcessMemory?

Here what I copied out of kernel32.dll from ReadProcessMemory:
Code:
mov edi, edi
PUSH EBP
MOV EBP, ESP
LEA EAX, DWORD PTS SS:[EBP+14]
PUSH EAX
PUSH DWORD PTR SS:[EBP+14]
PUSH DWORD PTR SS:[EBP+10]
PUSH DWORD PTR SS:[EBP+C]
PUSH DWORD PTR SS:[EBP+9]
CALL DWORD PTR DS:[<&ntdll.NtReadVirtual>
MOV ECX,DWORD PTR SS:[EBP+18]
TEST ECX,ECX
JNZ SHORT kernel32.7C8021F9
TEST EAX,EAX
JL SHORT kernel32.7C802200
XOR EAX, EAX
INC EAX
POP EBP
RETN 14
MOV EDX,DWORD PTR SS:[EBP+14]
MOV DWORD PTR DS:[ECX],EDX
JMP SHORT kernel32.7C8021EE
PUSH EAX
CALL kernel32.7C80936B
XOR EAX,EAX
JMP SHORT kernel32.7C8021F5
Back to top
View user's profile Send private message
lurc
Grandmaster Cheater Supreme
Reputation: 2

Joined: 13 Nov 2006
Posts: 1900

PostPosted: Thu Feb 07, 2008 9:13 am    Post subject: Reply with quote

rEakW0n wrote:

@Ontopic: Nobody really can explain that, Kaspersky always just says "It's hooked in ring0" YAY Now I know everything. He is just saying what someone else told him.
So my question:
Well to rehook PostMessageA we just overrite these 5 bytes in PostMessageA in user32.dll, could we do the same with ReadProcessMemory?

Here what I copied out of kernel32.dll from ReadProcessMemory:
Code:
mov edi, edi
PUSH EBP
MOV EBP, ESP
LEA EAX, DWORD PTS SS:[EBP+14]
PUSH EAX
PUSH DWORD PTR SS:[EBP+14]
PUSH DWORD PTR SS:[EBP+10]
PUSH DWORD PTR SS:[EBP+C]
PUSH DWORD PTR SS:[EBP+9]
CALL DWORD PTR DS:[<&ntdll.NtReadVirtual>
MOV ECX,DWORD PTR SS:[EBP+18]
TEST ECX,ECX
JNZ SHORT kernel32.7C8021F9
TEST EAX,EAX
JL SHORT kernel32.7C802200
XOR EAX, EAX
INC EAX
POP EBP
RETN 14
MOV EDX,DWORD PTR SS:[EBP+14]
MOV DWORD PTR DS:[ECX],EDX
JMP SHORT kernel32.7C8021EE
PUSH EAX
CALL kernel32.7C80936B
XOR EAX,EAX
JMP SHORT kernel32.7C8021F5


You can to trampoline ReadProcessMemory but if you look u see

Code:
CALL DWORD PTR DS:[<&ntdll.NtReadVirtual>]


NtReadVirtual is hooked in Kernel mode-level so you would have to create a driver to hook your own NtReadVirtual ( im guessing cheat engines driver is similar.. ill take a look at it later. )

Edit:

Losplagos wrote:
... it is detected.


RPM/WPM arent "Detected" they are simply hooked by Gameguard so when you call a API such as RPM Gameguard's driver simply blocks the API's use

_________________


Last edited by lurc on Thu Feb 07, 2008 9:21 am; edited 2 times in total
Back to top
View user's profile Send private message
Reak
I post too much
Reputation: 0

Joined: 15 May 2007
Posts: 3496

PostPosted: Thu Feb 07, 2008 9:16 am    Post subject: Reply with quote

hey see, that sounds nice Very Happy
Back to top
View user's profile Send private message
DeletedUser14087
I post too much
Reputation: 2

Joined: 21 Jun 2006
Posts: 3069

PostPosted: Thu Feb 07, 2008 9:19 am    Post subject: Reply with quote

rEakW0n wrote:
FUCK THIS.
Yes there has been released a lot of bot's since kaspersky released his source.
But I think it's not because of the "shl 16" shit it's because everyone releized that there's a rehooked PostMessageA "version" is out called "PMX.dll" or "hookhop.dll" or they just didn't know how to static load a dll.
The "shl 16" thing is not everything for it, yea it's important for SOME keys but it's not the core of a bot.

And @Rot1:
This is basic stuff? No I think it's not. Well MapVirtualKey maybe but that with "shl 16" isn't. I really would like to know how you got that "idea".

@Ontopic: Nobody really can explain that, Kaspersky always just says "It's hooked in ring0" YAY Now I know everything. He is just saying what someone else told him.
So my question:
Well to rehook PostMessageA we just overrite these 5 bytes in PostMessageA in user32.dll, could we do the same with ReadProcessMemory?

Here what I copied out of kernel32.dll from ReadProcessMemory:
Code:
mov edi, edi
PUSH EBP
MOV EBP, ESP
LEA EAX, DWORD PTS SS:[EBP+14]
PUSH EAX
PUSH DWORD PTR SS:[EBP+14]
PUSH DWORD PTR SS:[EBP+10]
PUSH DWORD PTR SS:[EBP+C]
PUSH DWORD PTR SS:[EBP+9]
CALL DWORD PTR DS:[<&ntdll.NtReadVirtual>
MOV ECX,DWORD PTR SS:[EBP+18]
TEST ECX,ECX
JNZ SHORT kernel32.7C8021F9
TEST EAX,EAX
JL SHORT kernel32.7C802200
XOR EAX, EAX
INC EAX
POP EBP
RETN 14
MOV EDX,DWORD PTR SS:[EBP+14]
MOV DWORD PTR DS:[ECX],EDX
JMP SHORT kernel32.7C8021EE
PUSH EAX
CALL kernel32.7C80936B
XOR EAX,EAX
JMP SHORT kernel32.7C8021F5


you sound like you're in panic since i released kBot source, learn delphi noob.

http://www.delphibasics.co.uk/RTL.asp?Name=Shl

btw, i'm not sure if it's on ring0, i think ring1.

and it's NOT hooked the same method as PostMessageA, idiot.

even on usermode.
Back to top
View user's profile Send private message
lurc
Grandmaster Cheater Supreme
Reputation: 2

Joined: 13 Nov 2006
Posts: 1900

PostPosted: Thu Feb 07, 2008 9:27 am    Post subject: Reply with quote

Rot1 wrote:
rEakW0n wrote:
FUCK THIS.
Yes there has been released a lot of bot's since kaspersky released his source.
But I think it's not because of the "shl 16" shit it's because everyone releized that there's a rehooked PostMessageA "version" is out called "PMX.dll" or "hookhop.dll" or they just didn't know how to static load a dll.
The "shl 16" thing is not everything for it, yea it's important for SOME keys but it's not the core of a bot.

And @Rot1:
This is basic stuff? No I think it's not. Well MapVirtualKey maybe but that with "shl 16" isn't. I really would like to know how you got that "idea".

@Ontopic: Nobody really can explain that, Kaspersky always just says "It's hooked in ring0" YAY Now I know everything. He is just saying what someone else told him.
So my question:
Well to rehook PostMessageA we just overrite these 5 bytes in PostMessageA in user32.dll, could we do the same with ReadProcessMemory?

Here what I copied out of kernel32.dll from ReadProcessMemory:
Code:
mov edi, edi
PUSH EBP
MOV EBP, ESP
LEA EAX, DWORD PTS SS:[EBP+14]
PUSH EAX
PUSH DWORD PTR SS:[EBP+14]
PUSH DWORD PTR SS:[EBP+10]
PUSH DWORD PTR SS:[EBP+C]
PUSH DWORD PTR SS:[EBP+9]
CALL DWORD PTR DS:[<&ntdll.NtReadVirtual>
MOV ECX,DWORD PTR SS:[EBP+18]
TEST ECX,ECX
JNZ SHORT kernel32.7C8021F9
TEST EAX,EAX
JL SHORT kernel32.7C802200
XOR EAX, EAX
INC EAX
POP EBP
RETN 14
MOV EDX,DWORD PTR SS:[EBP+14]
MOV DWORD PTR DS:[ECX],EDX
JMP SHORT kernel32.7C8021EE
PUSH EAX
CALL kernel32.7C80936B
XOR EAX,EAX
JMP SHORT kernel32.7C8021F5


you sound like you're in panic since i released kBot source, learn delphi noob.

http://www.delphibasics.co.uk/RTL.asp?Name=Shl

btw, i'm not sure if it's on ring0, i think ring1.

and it's NOT hooked the same method as PostMessageA, idiot.

even on usermode.


Rofl, sumeones PMSing Razz Razz
learn to calm down Rot1.

_________________
Back to top
View user's profile Send private message
Reak
I post too much
Reputation: 0

Joined: 15 May 2007
Posts: 3496

PostPosted: Thu Feb 07, 2008 9:55 am    Post subject: Reply with quote

Are you kiddin me?
You think I took everything of you're fucking source?
All I took from your "work" is the shl 16 shit.

And see, that's what I mean. He's just talking shit "I think it's not ring0 it's ring3" fuck you know nothing about it so you should stfu, don't act like you know it. I don't know it and do I act like I do ? no.
Just stay out of this topic, we don't need wannabe-knowers.
You can answer what you want, I wont respond.

Edit: And now don't come on msn and tell me "why are you insulting me in cef" ...fuck you should know why Rolling Eyes
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming All times are GMT - 6 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites