| View previous topic :: View next topic |
| Author |
Message |
rapion124 Grandmaster Cheater Supreme
Reputation: 0
Joined: 25 Mar 2007 Posts: 1095
|
Posted: Fri Aug 15, 2008 7:21 pm Post subject: |
|
|
| sponge wrote: | | Xoujiro wrote: |
ok, thanks, can i use olly to check which bytes are overwritten? | XTrap will detect a barebones Olly. |
There's something called Phantom for Olly. It hides Olly o_O. Although XTrap's hooks prevent OllyDBG from functioning, it makes things a lot easier because XTrap won't reboot your computer.
I have some experience with XTrap. I also play Wolfteam. What you need to do is get the Phantom plugin, open Olly, and put a breakpoint on CreateProcessA. Run Wolfteam and you should get a hit. Now, just go to [esp] and you got the address of the game loading XTrap. Phantom is required because Wolfteam.bin is packed with ASProtect, so it will give you a debugger detected error if Olly is detected. |
|
| Back to top |
|
 |
Xoujiro Advanced Cheater
Reputation: 0
Joined: 20 Mar 2006 Posts: 86
|
Posted: Fri Aug 15, 2008 8:13 pm Post subject: |
|
|
Ok, so ive got the addy and all, but the same address is obtained whether wolfteam is running or not, does this mean it isnt hooked?
and rapion, i ran olly, ctrl+g and typed in CreateProcessA, it brought me to kernel32.dll, now i right click -> breakpoint -> toggle , and then run wolfteam, now what do i do? |
|
| Back to top |
|
 |
dnsi0 I post too much
Reputation: 0
Joined: 04 Jan 2007 Posts: 2674
|
Posted: Fri Aug 15, 2008 8:33 pm Post subject: |
|
|
k. Look for createprocessA in intermodular calls. Now you should find 3.
(well... thats for gameguard) then you look for one that has PUSH 01 above it by a few bytes. Change the PUSH 1 to PUSH 0.
(well... thats for gameguard so I don't know if its gonna work for xtrap) |
|
| Back to top |
|
 |
Xoujiro Advanced Cheater
Reputation: 0
Joined: 20 Mar 2006 Posts: 86
|
Posted: Fri Aug 15, 2008 8:52 pm Post subject: |
|
|
| dnsi0 wrote: | k. Look for createprocessA in intermodular calls. Now you should find 3.
(well... thats for gameguard) then you look for one that has PUSH 01 above it by a few bytes. Change the PUSH 1 to PUSH 0.
(well... thats for gameguard so I don't know if its gonna work for xtrap) |
There are so many intermodular calls... do i have to look 1 by 1 or can i search for it |
|
| Back to top |
|
 |
rapion124 Grandmaster Cheater Supreme
Reputation: 0
Joined: 25 Mar 2007 Posts: 1095
|
Posted: Fri Aug 15, 2008 8:55 pm Post subject: |
|
|
Wow!!!!! Do you need to be spoonfed? Breakpoint on CreateProcessA. Run Wolfteam. Look in the lpFileName or lpCommandLine parameters. Look for "XTrap.xt" in those parameters. Then go to [esp] to get the address the game calls to load XTrap.
Note: you will get multiple hits, it's expected. |
|
| Back to top |
|
 |
Xoujiro Advanced Cheater
Reputation: 0
Joined: 20 Mar 2006 Posts: 86
|
Posted: Fri Aug 15, 2008 10:01 pm Post subject: |
|
|
| nvm i give up |
|
| Back to top |
|
 |
sponge I'm a spammer
Reputation: 1
Joined: 07 Nov 2006 Posts: 6009
|
Posted: Fri Aug 15, 2008 10:57 pm Post subject: |
|
|
| rapion124 wrote: | | sponge wrote: | | Xoujiro wrote: |
ok, thanks, can i use olly to check which bytes are overwritten? | XTrap will detect a barebones Olly. |
There's something called Phantom for Olly. It hides Olly o_O. Although XTrap's hooks prevent OllyDBG from functioning, it makes things a lot easier because XTrap won't reboot your computer.
I have some experience with XTrap. I also play Wolfteam. What you need to do is get the Phantom plugin, open Olly, and put a breakpoint on CreateProcessA. Run Wolfteam and you should get a hit. Now, just go to [esp] and you got the address of the game loading XTrap. Phantom is required because Wolfteam.bin is packed with ASProtect, so it will give you a debugger detected error if Olly is detected. | Yes, I already knew that. Anyways WolfTeam is packed with Themida not ASProtect. _________________
|
|
| Back to top |
|
 |
Slugsnack Grandmaster Cheater Supreme
Reputation: 71
Joined: 24 Jan 2007 Posts: 1857
|
Posted: Sat Aug 16, 2008 4:18 am Post subject: |
|
|
| Xoujiro wrote: | | nvm i give up |
Mate.. Look at CreateProcess (http://msdn.microsoft.com/en-us/library/ms682425.aspx). Now look at the parameters:
| Quote: | BOOL WINAPI CreateProcess(
__in_opt LPCTSTR lpApplicationName,
__inout_opt LPTSTR lpCommandLine,
__in_opt LPSECURITY_ATTRIBUTES lpProcessAttributes,
__in_opt LPSECURITY_ATTRIBUTES lpThreadAttributes,
__in BOOL bInheritHandles,
__in DWORD dwCreationFlags,
__in_opt LPVOID lpEnvironment,
__in_opt LPCTSTR lpCurrentDirectory,
__in LPSTARTUPINFO lpStartupInfo,
__out LPPROCESS_INFORMATION lpProcessInformation |
Now you have it essentially 'hooked' and you can keep going till the lpApplicationName matches XTrap. Then you can look on the stack for the return address (ie. where the call will ret to after it's done) and looking at the instruction before that will tell you the VA to the call to XTrap. |
|
| Back to top |
|
 |
atom0s Moderator
Reputation: 205
Joined: 25 Jan 2006 Posts: 8588 Location: 127.0.0.1
|
Posted: Sat Aug 16, 2008 5:49 am Post subject: |
|
|
Does WolfTeam do packet checks with XTrap? (I assume they do cause the game is made by Softnyx..)
If not you can unhook Xtrap from the game completely fairly easy. _________________
- Retired. |
|
| Back to top |
|
 |
dnsi0 I post too much
Reputation: 0
Joined: 04 Jan 2007 Posts: 2674
|
Posted: Sat Aug 16, 2008 8:27 am Post subject: |
|
|
K. Look for intermodular calls but use sort->by name
then its in alphabetical order. |
|
| Back to top |
|
 |
Wintermoot Expert Cheater
Reputation: 0
Joined: 08 Nov 2007 Posts: 198
|
Posted: Sat Aug 16, 2008 9:16 am Post subject: |
|
|
| Lok for all intermodular calls then start typing and look at the window's titlebar... |
|
| Back to top |
|
 |
Slugsnack Grandmaster Cheater Supreme
Reputation: 71
Joined: 24 Jan 2007 Posts: 1857
|
Posted: Sat Aug 16, 2008 9:21 am Post subject: |
|
|
As I said before, if the game is packed, it is unlikely the method you two are describing will work.
But by placing a breakpoint on the actual function itself, it will catch it unless the breakpointed instruction is not executed or the breakpoint removed. |
|
| Back to top |
|
 |
Xoujiro Advanced Cheater
Reputation: 0
Joined: 20 Mar 2006 Posts: 86
|
Posted: Sat Aug 16, 2008 9:52 am Post subject: |
|
|
i dont know anything about olly... and there are checksums to check for xtrap too
Last edited by Xoujiro on Sat Aug 16, 2008 10:18 am; edited 1 time in total |
|
| Back to top |
|
 |
rapion124 Grandmaster Cheater Supreme
Reputation: 0
Joined: 25 Mar 2007 Posts: 1095
|
Posted: Sat Aug 16, 2008 10:18 am Post subject: |
|
|
I think what he wants to accomplish is debugging the game without XTrap, so no need to worry about the checks.
@Slugsnack:
lpApplicationName doesn't always give you the application name lol. Sometimes, it's null so you should look at lpCommandLine. |
|
| Back to top |
|
 |
Slugsnack Grandmaster Cheater Supreme
Reputation: 71
Joined: 24 Jan 2007 Posts: 1857
|
Posted: Sat Aug 16, 2008 11:38 am Post subject: |
|
|
| I wouldn't know. I only said it was gonna be that cause of your previous post lol. I have only messed around with removing protections a few times before and that was in GunBound in which it was a simple case of unpacking armadillo and stripping it with a similar method outlined in this thread. Anyway if you're looking in Olly after breakpointing at the first instruction of a call you can look at the stack and see all the parameters very easily. |
|
| Back to top |
|
 |
|