Network: WoW Gold | WoW Accounts | MPS Games | FPSowned
MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides
Homepage »      Register »      Hall of Fame »      Ranks And Awards »      Advertise »      Marketplace »
 
Sign up



Do you like this excellent information? Then Donate HERE to remove ads and support the MMOwned community.


Go Back   MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides > World of Warcraft > Bots and Programs > WoW Memory Editing

WoW Memory Editing WoW Memory Editing for learning purposes only.
This section is more advanced than others on MMOwned Read the section specific rules, infractions will be given out if u break them!That is including the expectations! - If you don't meet them then don't post

Reply
 
LinkBack Thread Tools
  #31  
Old 09-21-2008
Namoknan's Avatar
Namoknan is offline.
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
  
 
Join Date: Aug 2007
Posts: 54
Reputation: 3
Quote:
Originally Posted by Xarg0 View Post
Why does it only work on single core? I tought it changes the way Virtuall Adresses are calculated to physikal ones in the Kernel, so where's the problem with multicore?
It will probably work, but dual cores work independent from each other. If adress space is accessed at the same time by the cores BSOD is very likely
Reply With Quote


Donate to remove ads, get your "DONATOR title, and get access to the MMOwned community's elite Shoutbawx.

  #32  
Old 09-21-2008
Cypher's Avatar
Cypher is offline.
Kynox's sister's pimp
Legendary User
  
 
Join Date: Apr 2006
Location: ntdll.dll
Posts: 4,167
Nominated 63 Times in 4 Posts
Nominated TOTM/W Award(s): 1
Reputation: 1074
Points: 55,433, Level: 35
Points: 55,433, Level: 35 Points: 55,433, Level: 35 Points: 55,433, Level: 35
Level up: 12%, 3,267 Points needed
Level up: 12% Level up: 12% Level up: 12%
Activity: 42.5%
Activity: 42.5% Activity: 42.5% Activity: 42.5%

Quote:
Originally Posted by Xarg0 View Post
Why does it only work on single core? I tought it changes the way Virtuall Adresses are calculated to physikal ones in the Kernel, so where's the problem with multicore?

There's a TLB in each core.


Quote:
Originally Posted by Namoknan View Post
In no means I want to attack your theory Cypher, I did not take a look at this specific driver memory modification thingy
But I guarantee you Ring 0 memory modification is possible on multi core systems. POC can be seen in "Memory Hacking Software by L.Spiro". BSOD is howeva likely, but chances are pretty low
....

I never said it wasn't possible to modify memory from the kernel. I said it wasn't possible to 'cloak' memory modifications in that fashion. Learn to read.

PS. I 'guarantee' you you're an idiot.


Quote:
Originally Posted by Namoknan View Post
It will probably work, but dual cores work independent from each other. If adress space is accessed at the same time by the cores BSOD is very likely

No, it won't work.

Furthermore, the driver only works on x86 and won't work on anything other than XP (2k3 should be a small update, Vista a very large one).
__________________
[Only registered and activated users can see links. ] Back online!

"Science is interesting, and if you don't agree you can **** off."
[Only registered and activated users can see links. ]

"I can write very coherent things when I try that sound very good" -- Styles
Reply With Quote
  #33  
Old 09-29-2008
Jadd's Avatar
Jadd is offline.
Contributor
  
 
Join Date: May 2008
Location: QLD, Australia
Posts: 617
Nominated 13 Times in 3 Posts
Reputation: 299
Points: 11,383, Level: 13
Points: 11,383, Level: 13 Points: 11,383, Level: 13 Points: 11,383, Level: 13
Level up: 30%, 917 Points needed
Level up: 30% Level up: 30% Level up: 30%
Activity: 16.4%
Activity: 16.4% Activity: 16.4% Activity: 16.4%

Why?? Lol.
__________________
IMMA FIRIN' MAH FOOBARZ!!

Last edited by Jadd; 10-01-2008 at 06:54 AM.
Reply With Quote
  #34  
Old 09-29-2008
Cypher's Avatar
Cypher is offline.
Kynox's sister's pimp
Legendary User
  
 
Join Date: Apr 2006
Location: ntdll.dll
Posts: 4,167
Nominated 63 Times in 4 Posts
Nominated TOTM/W Award(s): 1
Reputation: 1074
Points: 55,433, Level: 35
Points: 55,433, Level: 35 Points: 55,433, Level: 35 Points: 55,433, Level: 35
Level up: 12%, 3,267 Points needed
Level up: 12% Level up: 12% Level up: 12%
Activity: 42.5%
Activity: 42.5% Activity: 42.5% Activity: 42.5%

Quote:
Originally Posted by JetlagJad View Post
Why?? Lol.

Why what??

Learn to use full sentences.
__________________
[Only registered and activated users can see links. ] Back online!

"Science is interesting, and if you don't agree you can **** off."
[Only registered and activated users can see links. ]

"I can write very coherent things when I try that sound very good" -- Styles
Reply With Quote
  #35  
Old 09-29-2008
Kuiren's Avatar
Kuiren is offline.
﴾͡๏̯͡๏﴿ SupraM0d ﴾͡๏̯͡๏﴿
  
 
Join Date: Nov 2006
Location: In yo mind.
Posts: 1,126
Reputation: 605
Points: 13,060, Level: 14
Points: 13,060, Level: 14 Points: 13,060, Level: 14 Points: 13,060, Level: 14
Level up: 59%, 540 Points needed
Level up: 59% Level up: 59% Level up: 59%
Activity: 0.4%
Activity: 0.4% Activity: 0.4% Activity: 0.4%

Stickied oh wut.
__________________
If you would like to contact me, my msn is [Only registered and activated users can see links. ]

Reply With Quote
  #36  
Old 09-29-2008
kynox's Avatar
kynox is offline.
Warden's Mediator
Legendary User
  
 
Join Date: Dec 2006
Location: Raping your Stack
Posts: 773
Nominated 2 Times in 1 Post
Reputation: 794
Points: 28,073, Level: 24
Points: 28,073, Level: 24 Points: 28,073, Level: 24 Points: 28,073, Level: 24
Level up: 52%, 827 Points needed
Level up: 52% Level up: 52% Level up: 52%
Activity: 4.9%
Activity: 4.9% Activity: 4.9% Activity: 4.9%

Quote:
Originally Posted by Kuiren View Post
Stickied oh wut.
Woop wooop woop
__________________
[Only registered and activated users can see links. ]
Reply With Quote
  #37  
Old 09-30-2008
Cypher's Avatar
Cypher is offline.
Kynox's sister's pimp
Legendary User
  
 
Join Date: Apr 2006
Location: ntdll.dll
Posts: 4,167
Nominated 63 Times in 4 Posts
Nominated TOTM/W Award(s): 1
Reputation: 1074
Points: 55,433, Level: 35
Points: 55,433, Level: 35 Points: 55,433, Level: 35 Points: 55,433, Level: 35
Level up: 12%, 3,267 Points needed
Level up: 12% Level up: 12% Level up: 12%
Activity: 42.5%
Activity: 42.5% Activity: 42.5% Activity: 42.5%

Shoot da whoop.
__________________
[Only registered and activated users can see links. ] Back online!

"Science is interesting, and if you don't agree you can **** off."
[Only registered and activated users can see links. ]

"I can write very coherent things when I try that sound very good" -- Styles
Reply With Quote
  #38  
Old 10-01-2008
Jadd's Avatar
Jadd is offline.
Contributor
  
 
Join Date: May 2008
Location: QLD, Australia
Posts: 617
Nominated 13 Times in 3 Posts
Reputation: 299
Points: 11,383, Level: 13
Points: 11,383, Level: 13 Points: 11,383, Level: 13 Points: 11,383, Level: 13
Level up: 30%, 917 Points needed
Level up: 30% Level up: 30% Level up: 30%
Activity: 16.4%
Activity: 16.4% Activity: 16.4% Activity: 16.4%

Quote:
Originally Posted by Cypher View Post

Why what??

Learn to use full sentences.

If you can't understand that, well..

Eh screw it I know how smart you are, I meant 'why would you make this'.
__________________
IMMA FIRIN' MAH FOOBARZ!!
Reply With Quote
  #39  
Old 10-03-2008
Cypher's Avatar
Cypher is offline.
Kynox's sister's pimp
Legendary User
  
 
Join Date: Apr 2006
Location: ntdll.dll
Posts: 4,167
Nominated 63 Times in 4 Posts
Nominated TOTM/W Award(s): 1
Reputation: 1074
Points: 55,433, Level: 35
Points: 55,433, Level: 35 Points: 55,433, Level: 35 Points: 55,433, Level: 35
Level up: 12%, 3,267 Points needed
Level up: 12% Level up: 12% Level up: 12%
Activity: 42.5%
Activity: 42.5% Activity: 42.5% Activity: 42.5%

Quote:
Originally Posted by JetlagJad View Post

If you can't understand that, well..

Eh screw it I know how smart you are, I meant 'why would you make this'.

I figured that's what you meant but there are other things it could've been referring too.

And it was made to show the retards who insist on posting speculation on Warden despite having no idea what they're on about that Warden does not infact go through your pr0n and steal your credit card numbers.

It also points people in the right direction to bypass Warden.
__________________
[Only registered and activated users can see links. ] Back online!

"Science is interesting, and if you don't agree you can **** off."
[Only registered and activated users can see links. ]

"I can write very coherent things when I try that sound very good" -- Styles
Reply With Quote
  #40  
Old 12-22-2008
Anotherfox is offline.
Sergeant Major
  
 
Join Date: Apr 2008
Location: UK
Posts: 152
Reputation: 58
Quote:
0xB93714 0x8 Unknown Login Check (Parental restrictions??) // Cypher
It's the Blizz Authenticator.
Reply With Quote
  #41  
Old 02-12-2009
peachesandcream's Avatar
peachesandcream is offline.
Private
  
 
Join Date: Feb 2009
Location: maryland
Posts: 5
Reputation: 1
I am not a techno person by anymeans but this was very informative
Reply With Quote
  #42  
Old 02-21-2009
jagged software is offline.
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
  
 
Join Date: Feb 2009
Posts: 48
Reputation: -4
Very nice as always kynox. Thank you.
Reply With Quote
  #43  
Old 05-14-2009
amadmonk's Avatar
amadmonk is offline.
Site Donator
  
 
Join Date: Apr 2008
Posts: 303
Reputation: 62
Points: 1,612, Level: 3
Points: 1,612, Level: 3 Points: 1,612, Level: 3 Points: 1,612, Level: 3
Level up: 31%, 488 Points needed
Level up: 31% Level up: 31% Level up: 31%
Activity: 1.1%
Activity: 1.1% Activity: 1.1% Activity: 1.1%

So, you CAN cloak yourself effectively from the kernel (although then you have to hide your driver, but that's a different can of worms; I think there was a BlackHat demo of a completely driverless SSDT hook a while back). You can tweak the memory protection settings on code pages and swap out the thread context in realtime to produce "virtual" hooks, as well as tweaking descriptor mappings and totally owning the exception handling mechanism. You can also do super cool stuff like double-mapping pages and so on, but honestly that doesn't really gain you much (it's just essentially a faster, but more fragile, ReadProcessMemory). Finally, with SSDT hooking you can essentially 100% (ok, 99.9999%) cloak yourself and any other process/window/whatever you care about from non-driver user mode processes. You can put any process/thread you want into its own little virtualized "jail" where it sees nothing but what you want it to see. That's the essence of what my kernel rootkit back in my XP days did. Never got detected, but I had to give it up when I went to Vista...

That being said, 99% of the rest of what Cypher said is dead-on: it's enormously harder on multi-core boxes (although disabling interrupts at the right point and knowing when to flush the lookasides helps a lot) and very prone to BSOD's at bad times (if you want to go down this route, take my advice; set up a Virtual PC to do your dev work on, or you'll spend all your time rebooting). Most of it is completely impossible (or, at least, as yet impossible) on Vista and esp. Vista 64 due to kernel change.

Last but not least, it's serious overkill. Warden's algorithms are based off of hashing and signatures. Honestly, if you know enough to write a kernel stealth driver, it's child's play to evade Warden pretty much forever (it's so much easier too, because one mistake doesn't take your whole system down). You can play the kind of paranoid mind-games I play (thanks Cypher for making me wonder what happens if they refresh RVA's from the on-disk image... grr), but tbh you don't need to.

If you can code, don't use a public bot. That's pretty much all you need to stay off the radar (and I get the impression that Blizzard doesn't really give a crap about lone coders; they care more about the Gliders and WoWRadar's of the world).
Reply With Quote
  #44  
Old 05-14-2009
DaemonOnFire is offline.
Banned
  
 
Join Date: May 2009
Location: Germany, EU
Posts: 83
Reputation: 8
Quote:
Originally Posted by schlumpf View Post
Isn't everything proof of concept only?
Right.

We can not proof what blizz is putting into warden and wow, maybe they just have fun seeing us trying to cloak our hacks.....
I do not think that a company which earns millions over millions makes a game that can be hacked that easily without any notice of the owners.
Reply With Quote
  #45  
Old 05-14-2009
Cypher's Avatar
Cypher is offline.
Kynox's sister's pimp
Legendary User
  
 
Join Date: Apr 2006
Location: ntdll.dll
Posts: 4,167
Nominated 63 Times in 4 Posts
Nominated TOTM/W Award(s): 1
Reputation: 1074
Points: 55,433, Level: 35
Points: 55,433, Level: 35 Points: 55,433, Level: 35 Points: 55,433, Level: 35
Level up: 12%, 3,267 Points needed
Level up: 12% Level up: 12% Level up: 12%
Activity: 42.5%
Activity: 42.5% Activity: 42.5% Activity: 42.5%

Quote:
Originally Posted by amadmonk View Post
So, you CAN cloak yourself effectively from the kernel (although then you have to hide your driver, but that's a different can of worms; I think there was a BlackHat demo of a completely driverless SSDT hook a while back). You can tweak the memory protection settings on code pages and swap out the thread context in realtime to produce "virtual" hooks, as well as tweaking descriptor mappings and totally owning the exception handling mechanism. You can also do super cool stuff like double-mapping pages and so on, but honestly that doesn't really gain you much (it's just essentially a faster, but more fragile, ReadProcessMemory). Finally, with SSDT hooking you can essentially 100% (ok, 99.9999%) cloak yourself and any other process/window/whatever you care about from non-driver user mode processes. You can put any process/thread you want into its own little virtualized "jail" where it sees nothing but what you want it to see. That's the essence of what my kernel rootkit back in my XP days did. Never got detected, but I had to give it up when I went to Vista...

That being said, 99% of the rest of what Cypher said is dead-on: it's enormously harder on multi-core boxes (although disabling interrupts at the right point and knowing when to flush the lookasides helps a lot) and very prone to BSOD's at bad times (if you want to go down this route, take my advice; set up a Virtual PC to do your dev work on, or you'll spend all your time rebooting). Most of it is completely impossible (or, at least, as yet impossible) on Vista and esp. Vista 64 due to kernel change.

Last but not least, it's serious overkill. Warden's algorithms are based off of hashing and signatures. Honestly, if you know enough to write a kernel stealth driver, it's child's play to evade Warden pretty much forever (it's so much easier too, because one mistake doesn't take your whole system down). You can play the kind of paranoid mind-games I play (thanks Cypher for making me wonder what happens if they refresh RVA's from the on-disk image... grr), but tbh you don't need to.

If you can code, don't use a public bot. That's pretty much all you need to stay off the radar (and I get the impression that Blizzard doesn't really give a crap about lone coders; they care more about the Gliders and WoWRadar's of the world).

Yes you can. But not on x64. PatchGuard will rape your ass. Sure you can bypass patchguard, but its no trivial task.


Quote:
Originally Posted by DaemonOnFire View Post
Right.

We can not proof what blizz is putting into warden and wow, maybe they just have fun seeing us trying to cloak our hacks.....
I do not think that a company which earns millions over millions makes a game that can be hacked that easily without any notice of the owners.

YOU can't. But others can. It's called reverse engineering...
__________________
[Only registered and activated users can see links. ] Back online!

"Science is interesting, and if you don't agree you can **** off."
[Only registered and activated users can see links. ]

"I can write very coherent things when I try that sound very good" -- Styles
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT -4. The time now is 10:53 PM.




Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.1

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492