| View previous topic :: View next topic |
| Author |
Message |
dnsi0 I post too much
Reputation: 0
Joined: 04 Jan 2007 Posts: 2674
|
Posted: Thu Aug 07, 2008 9:59 am Post subject: Dll Injection Question |
|
|
| When you inject a dll into say maplestory. Will the original apis called ex.kernel32, ntdll etc. By unhooked? Or do you still need a hook hop?
|
|
| Back to top |
|
 |
lurc Grandmaster Cheater Supreme
Reputation: 2
Joined: 13 Nov 2006 Posts: 1900
|
Posted: Thu Aug 07, 2008 10:52 am Post subject: |
|
|
I'm pretty sure you can call them from MapleStory. MapleStory should be on the whitelist in GameGuard's hooks.
_________________
|
|
| Back to top |
|
 |
Zand Master Cheater
Reputation: 0
Joined: 21 Jul 2006 Posts: 424
|
Posted: Thu Aug 07, 2008 10:56 am Post subject: |
|
|
Do it in GameMon
|
|
| Back to top |
|
 |
rapion124 Grandmaster Cheater Supreme
Reputation: 0
Joined: 25 Mar 2007 Posts: 1095
|
Posted: Thu Aug 07, 2008 12:28 pm Post subject: |
|
|
| lurc wrote: | | I'm pretty sure you can call them from MapleStory. MapleStory should be on the whitelist in GameGuard's hooks. |
Unfortunately no. The only process that doesn't get Usermode hooks is GameMon.
|
|
| Back to top |
|
 |
dnsi0 I post too much
Reputation: 0
Joined: 04 Jan 2007 Posts: 2674
|
Posted: Thu Aug 07, 2008 1:00 pm Post subject: |
|
|
| Ok. so we still need hookhop for kernel32 right?
|
|
| Back to top |
|
 |
Zand Master Cheater
Reputation: 0
Joined: 21 Jul 2006 Posts: 424
|
Posted: Fri Aug 08, 2008 2:46 am Post subject: |
|
|
| How do you hookhop kernel32????
|
|
| Back to top |
|
 |
Ksbunker Advanced Cheater
Reputation: 0
Joined: 18 Oct 2006 Posts: 88
|
Posted: Fri Aug 08, 2008 9:32 pm Post subject: re: |
|
|
| Code: | mov edi, edi
push ebp
mov ebp, esp
jmp API+5 |
|
|
| Back to top |
|
 |
Slugsnack Grandmaster Cheater Supreme
Reputation: 71
Joined: 24 Jan 2007 Posts: 1857
|
Posted: Sat Aug 09, 2008 3:52 am Post subject: |
|
|
Yes with DLL injection, APIs are still hooked and not only those from kernel32.dll, other system libraries like gdi32.dll, etc. have functions in them hooked. And yes, you could still trampoline past.
I still don't know why people always seem to find the need to add the "mov edi, edi" when they're trampolining.. It's as useless as a NOP in the context you are using it in, may as well take it out.
|
|
| Back to top |
|
 |
|