| View previous topic :: View next topic |
| Author |
Message |
hacksign23 Master Cheater
Reputation: 0
Joined: 26 Nov 2006 Posts: 404
|
Posted: Tue Dec 30, 2008 1:10 am Post subject: bypass idea |
|
|
This is probably super retarded or already thought of but...
I wonder if we were to take api's such as PostMessage, reverse engineer it back to original source code, and program it back to a dll with only the api's (PostMessage) and use that instead.
so...
1. Reverse asm back into source code of PostMessage in user32.dll
2. Write own dll with PostMessage in it
3. Bypass?
just wondering. if it's already done, then screw the thread.
_________________
|
|
| Back to top |
|
 |
Snootae Grandmaster Cheater
Reputation: 0
Joined: 16 Dec 2006 Posts: 969 Location: --->
|
Posted: Tue Dec 30, 2008 4:47 am Post subject: |
|
|
i can see where your coming from but seriously
3. Bypass?
how is duplicating it gonna magically bypass, the api is blocked
also hookhopping works, stick with it
_________________
|
|
| Back to top |
|
 |
Noz3001 I'm a spammer
Reputation: 26
Joined: 29 May 2006 Posts: 6220 Location: /dev/null
|
Posted: Tue Dec 30, 2008 6:14 am Post subject: |
|
|
| So you, one guy, wants to re-write the windows kernel?
|
|
| Back to top |
|
 |
hacksign23 Master Cheater
Reputation: 0
Joined: 26 Nov 2006 Posts: 404
|
Posted: Tue Dec 30, 2008 11:07 am Post subject: |
|
|
ahaha it's just an idea. guess hop hooking is good enough.
/thread
_________________
|
|
| Back to top |
|
 |
rapion124 Grandmaster Cheater Supreme
Reputation: 0
Joined: 25 Mar 2007 Posts: 1095
|
Posted: Tue Dec 30, 2008 11:55 am Post subject: |
|
|
| Why not just load another copy of user32.dll under an alias and then call the APIs in the new DLL? That's how GG does it and it's worked pretty well.
|
|
| Back to top |
|
 |
HalfPrime Grandmaster Cheater
Reputation: 0
Joined: 12 Mar 2008 Posts: 532 Location: Right there...On your monitor
|
Posted: Tue Dec 30, 2008 9:36 pm Post subject: |
|
|
Actually, if you just rename the dll, change the loading address, and fix up the libs, it makes and easy bypass for every function in that dll instead of having to do them all separately. you can even have those dlls call functions from another bypassed dll instead of the regular system dll.
| Quote: | how is duplicating it gonna magically bypass, the api is blocked
|
moron
_________________
|
|
| Back to top |
|
 |
Snootae Grandmaster Cheater
Reputation: 0
Joined: 16 Dec 2006 Posts: 969 Location: --->
|
Posted: Tue Dec 30, 2008 10:25 pm Post subject: |
|
|
why?
_________________
|
|
| Back to top |
|
 |
AlbanainRetard Master Cheater
Reputation: 0
Joined: 02 Nov 2008 Posts: 494 Location: Canada eh?
|
Posted: Wed Dec 31, 2008 12:31 am Post subject: |
|
|
There is some windows 32 clone, with open soure dlls ( ReactOs ).
_________________
|
|
| Back to top |
|
 |
|