MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides

Homepage Register FAQ Members Mark Forums Read Advertise Marketplace FPSowned


Go Back   MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides > World of Warcraft > Bots and Programs > WoW Memory Editing
Reload this Page object names?? confused..
WoW Memory Editing WoW Memory Editing for learning purposes only.

Reply
 
LinkBack Thread Tools
(#31)
Old
Cypher's Avatar
Cypher is Offline
Kynox's Pimp OMGRECURSION
Legendary User
Rep Power: 8
Reputation: 793
Cypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to behold
 
Posts: 1,980
Join Date: Apr 2006
Location: Your mums bedroom
07-22-2008

Quote:
Originally Posted by kynox View Post
If you're using out of process, why not just:

1) Read the Bobber XYZ
2) Read the camera struct (i posted this here)
3) Convert the XYZ to a 2D Vector using a world to screen function i also posted here.
4) Move mouse to returned X,Y
5) Click
6) ???
7) Profit

Don't you have to have WoW running on top to do that because if you send a mousemove to SendMessage WoW checks the 'real' position of the cursor?



If freedom is outlawed, only outlaws will have freedom.
I'm not being rude, you're just insignificant.
Reply With Quote

Donate to remove ads.
(#32)
Old
arynock is Offline
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
Rep Power: 1
Reputation: 1
arynock is an unknown quantity at this point
 
Posts: 42
Join Date: May 2008
Location: Ohio
07-23-2008

so... if you are able to reverse the wow file and find all these functions... why dont you just reverse the scan.dll file to see how exactly warden works? and possibly disable it? heh
Reply With Quote
(#33)
Old
Sychotix's Avatar
Sychotix is Offline
Contributor
Rep Power: 3
Reputation: 123
Sychotix will become famous soon enoughSychotix will become famous soon enough
 
Posts: 741
Join Date: Apr 2006
07-23-2008

i dont think scan.dll really matters when it comes to warden =P and if it does, you could probably simply delete it from both being called in the executable and from the folder itself


Reply With Quote
(#34)
Old
Shynd's Avatar
Shynd is Offline
Master Sergeant
Rep Power: 1
Reputation: 20
Shynd is on a distinguished road
 
Posts: 108
Join Date: May 2008
07-23-2008

Scan.dll has nothing to do with Warden. Besides, Warden has been pretty well contained, from time to time, but since it can change at any time, with no warning, it's pretty difficult to just disable it altogether.
Reply With Quote
(#35)
Old
arynock is Offline
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
Rep Power: 1
Reputation: 1
arynock is an unknown quantity at this point
 
Posts: 42
Join Date: May 2008
Location: Ohio
07-23-2008

oh.. i guess i just figured scan.dll contained most of the functions that would be used by warden... but the fact that it is changed so frequently would make a good reason not to worry about that... hah.. duh to me..
Reply With Quote
(#36)
Old
kynox's Avatar
kynox is Offline
Cypher's Pimp

Rep Power: 5
Reputation: 529
kynox is a glorious beacon of lightkynox is a glorious beacon of lightkynox is a glorious beacon of lightkynox is a glorious beacon of lightkynox is a glorious beacon of lightkynox is a glorious beacon of light
 
Posts: 304
Join Date: Dec 2006
Location: Raping your Stack
07-23-2008

Quote:
Originally Posted by arynock View Post
oh.. i guess i just figured scan.dll contained most of the functions that would be used by warden... but the fact that it is changed so frequently would make a good reason not to worry about that... hah.. duh to me..
I would bet no function in Scan.dll is "Findable" in Warden, if they were infact in it. Warden is polymorphic, meaning that every function is different and placed in a different locations each time.

Reversing it was a real pain, but you eventually see a pattern on code flow and it becomes cake.

But to sum it up, Scan.dll was originaly used to detect virus/keyloggers running on your PC before you logged into WoW afaik, but now they've started to include hacks. You can easily get around this by deleting it on runtime (Which they make no protection against, because you don't get banned in the first place).


Do not PM me about the ME fix or other ME questions
Reply With Quote
(#37)
Old
Cypher's Avatar
Cypher is Offline
Kynox's Pimp OMGRECURSION
Legendary User
Rep Power: 8
Reputation: 793
Cypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to behold
 
Posts: 1,980
Join Date: Apr 2006
Location: Your mums bedroom
07-24-2008

Scan.dll is there to warn you on startup about anything that might be bannable if you choose to log in with it running. Warden is there to ban you when you do log in.

Whilst scan.dll is techincally part of 'Warden' as a technology (before anyone argues check MDY vs Blizzard and you'll see blizzard include scan.dll as part of their 'Warden' technology), its definately not of interest when it comes to bypassing detection of hacks etc.



If freedom is outlawed, only outlaws will have freedom.
I'm not being rude, you're just insignificant.
Reply With Quote
(#38)
Old
arynock is Offline
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
Rep Power: 1
Reputation: 1
arynock is an unknown quantity at this point
 
Posts: 42
Join Date: May 2008
Location: Ohio
07-24-2008

yeah... and to anyone who said reading a book was a stupid way to learn... dude this book is amazing.. lol
Reply With Quote
(#39)
Old
Sychotix's Avatar
Sychotix is Offline
Contributor
Rep Power: 3
Reputation: 123
Sychotix will become famous soon enoughSychotix will become famous soon enough
 
Posts: 741
Join Date: Apr 2006
07-24-2008

never said it was stupid =P its, at least, not my way to learn. Oral and visual > textual


Reply With Quote
(#40)
Old
Cypher's Avatar
Cypher is Offline
Kynox's Pimp OMGRECURSION
Legendary User
Rep Power: 8
Reputation: 793
Cypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to behold
 
Posts: 1,980
Join Date: Apr 2006
Location: Your mums bedroom
07-24-2008

Quote:
Originally Posted by arynock View Post
yeah... and to anyone who said reading a book was a stupid way to learn... dude this book is amazing.. lol

Yeah, its definitely an excellent book, it'll teach you pretty much everything you need to get started in reverse engineering.

After that its just a matter of practice practice practice, along with reading of specialty articles on the subjects you're interested in (cracking, data reing, etc), and learning about your targets (ie reading books about programming games, a 'know thy enemy' type thing ).



If freedom is outlawed, only outlaws will have freedom.
I'm not being rude, you're just insignificant.
Reply With Quote
(#41)
Old
hfs's Avatar
hfs is Offline
Sergeant
Rep Power: 1
Reputation: 36
hfs is on a distinguished road
 
Posts: 35
Join Date: Jul 2008
Location: UK
07-25-2008

so is scan.dll also responsible for scanning the mem residen copy of wow.exe upon login?

i.e. in the form of a quick checksum?

Or does wow.exe handle that itsself?
Reply With Quote
(#42)
Old
Cypher's Avatar
Cypher is Offline
Kynox's Pimp OMGRECURSION
Legendary User
Rep Power: 8
Reputation: 793
Cypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to behold
 
Posts: 1,980
Join Date: Apr 2006
Location: Your mums bedroom
07-25-2008

Quote:
Originally Posted by hfs View Post
so is scan.dll also responsible for scanning the mem residen copy of wow.exe upon login?

i.e. in the form of a quick checksum?

Or does wow.exe handle that itsself?

Err, I thought my post was pretty self-explanatory. Scan.dll is a component of Blizzard's warden technology and scans for known public hacks/bots/etc to warn the user their account security may be at risk. A checksum is done upon login regardless of the presence of scan.dll, that feature is built into WoW itself.



If freedom is outlawed, only outlaws will have freedom.
I'm not being rude, you're just insignificant.
Reply With Quote
Reply

Donate to remove ads.

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342