Page 2 of 5 FirstFirst 1234 ... LastLast
Results 16 to 30 of 64
  1. #1
    Rickyrudy's Avatar
    Join Date
    Feb 2008
    Gender
    male
    Posts
    277
    Reputation
    10
    Thanks
    26

    Bypassing hackshield

    Credits to DeadlyData of ************* forums.
    Learning experience.

    No questions will be answered by me this is just a cp and i say its rather simple >.>

    Reason for writing this/Why I bypass it the way I do:
    First my reason for writing this is the anti-cheat is really shitty and so far there has been no real documentation on it released online that I've found, besides my own.

    Secondly the reason I bypass it the way I do, Is it's the easiest way I or any one else with less experience can.

    A couple days to a week or so ago I hardly understood what a hook or detour would really do nor did I understand how system drivers worked... I've always been more of a web based person as far as security.

    Any way to continue for some of you guys, I'm sure you could simply unload the driver and recreate the heart beat of the anti-cheat so that hack shield is just simply no longer resident on your system.

    That how ever isn't my way around it I've found several and will explain the ways I've taken so far below.

    How hack shield works(From my view):
    So far the way I see hack shield works(And try not to bash me if I say something incorrectly just correct it)...

    Your game client will load upon your game client loading it will load a external library which is usually hack shield's interface dll "EhSvc.dll".

    From this point I wasn't able to do much analysis my self on account of "EhSvc.dll" was packed with themida in my game target.

    From here though "EhSvc.dll" will continue by loading several other things one of those things being the system driver "EagleNT.sys".

    EagleNT.sys creates several SSDT hooks preventing a user from using things like WriteProcessMemory() or ReadProcessMemory() on the target game it's protecting.

    How ever there are memory searching utilities out there like cheat engine that are open source and people decide to modify these using different calls to avoid the hooks.

    When using one of these you will how ever still get detected if you manage to get around the SSDT hooks.

    The detection is passed either from the driver or the dll into the game's main exe from there the game will give you the message like "Illegal Memory Access Detected".

    So bassicly it's a system driver and a dll interacting with each other thats pretty much how it works to sum it up things are also passed and controlled by the game as far as detection goes though.

    Bypassing it(My way):
    Since things are just passed through the games exe I usually just unpack the games exe(Usually hack shield targets come packed with "UPX" - Of all things).

    Open the games unpacked exe in IDA find the string which I received - E.X. "Illegal Memory Access Detected".

    And head above the the string to the main jump that pretty much goes through all of the different detection messages.

    It's usually always a JG once this is nopped it no longer shows the detection messages nor attempts to close your game if detected...

    More in depth with the method below.

    Bypassing (More In depth/Tutorial):
    Start by going through the string table in IDA until you see the "detected" string that was in the message box.

    https://www.thedefaced.org/DD/hshield/memoryaccess.PNG

    From there double click on it...

    https://www.thedefaced.org/DD/hshield/memoryaccess2.png

    Then go to the reference of it (The push of the offset):


    https://www.thedefaced.org/DD/hshield/memoryaccess3.PNG

    Go to the reference of the push... which is a jmp.


    https://www.thedefaced.org/DD/hshield/memoryaccess4.PNG

    Go to the reference of that jmp which is another jmp just a jump if greater...


    https://www.thedefaced.org/DD/hshield/memoryaccess5.PNG

    And last the reference to that JG(Jump if greater) is where you set your 2 byte nop... bypassing the detection completely.


    https://www.thedefaced.org/DD/hshield/memoryaccess6.PNG

    Yeah it's completely played out this way for every game it's in... so this will work on most games using hack shield.

    Hope this helps some of you guys...
    Last edited by Rickyrudy; 08-01-2008 at 01:25 PM.

  2. The Following 5 Users Say Thank You to Rickyrudy For This Useful Post:

    CyberStriker (08-01-2008),darkvieja (10-15-2008),gerben498 (10-26-2008),minorutono (08-02-2008),nzjustin (10-05-2009)

  3. #16
    gbitz's Avatar
    Join Date
    Mar 2008
    Gender
    male
    Location
    Here.
    Posts
    3,136
    Reputation
    197
    Thanks
    335
    Stop repeating your big words. Egotistical. El oh El.

  4. #17
    Banshou's Avatar
    Join Date
    Jul 2008
    Gender
    female
    Posts
    15
    Reputation
    10
    Thanks
    1
    Quote Originally Posted by seemliss View Post
    Stop repeating your big words. Egotistical. El oh El.
    lolz, you're not a very complex person, it's about all I could find to point out. You're not really worth my creativity.

  5. #18
    gbitz's Avatar
    Join Date
    Mar 2008
    Gender
    male
    Location
    Here.
    Posts
    3,136
    Reputation
    197
    Thanks
    335
    Go utilize your ingenuity elsewhere.

  6. #19
    daddyi's Avatar
    Join Date
    Jul 2008
    Posts
    197
    Reputation
    10
    Thanks
    55
    This was already posted.

  7. #20
    hakufu's Avatar
    Join Date
    May 2006
    Gender
    male
    Location
    Florida
    Posts
    177
    Reputation
    10
    Thanks
    7
    Quote Originally Posted by apezwijn View Post
    Go seemliss Go Hot Avatar of seemliss aha aha
    Your 100% Right..

    PS: Hot Avatar...
    btw. Hot Avatar..

    Thanked you for your reply,
    AND YOUR HOT AVATAR

    =P
    ahahaha
    u really want a gf eh? or atleast a hot one,
    suggestion.. read "The Game"
    oh and hint, dont be a tool

    no offense, just trying to help out the AFCs out there

    So fucking what? He copied it so people here could see it. Fuck off you egotistical retard, seriously. You're worthless.


    Stop repeating your big words. Egotistical. El oh El.

    lolz, you're not a very complex person, it's about all I could find to point out. You're not really worth my creativity.
    ahahaha, kids are so fun :]
    i like the creative words, and style of choice of statements,
    just less emotion guys, lets keep this a discussion not an arguement
    nice to see ppl attempting to use their vocabulary
    <(banana?)

    PS: read my name backwards...

  8. #21
    blackpepper's Avatar
    Join Date
    Nov 2007
    Posts
    79
    Reputation
    10
    Thanks
    3
    thx for this im going to try when i get home from work

  9. #22
    CyberStriker's Avatar
    Join Date
    May 2008
    Gender
    male
    Posts
    149
    Reputation
    10
    Thanks
    12
    I found the addy, but I can't nop it. HS hooks that.
    Last edited by CyberStriker; 08-01-2008 at 02:29 PM.

  10. #23
    silent1990's Avatar
    Join Date
    Apr 2007
    Gender
    male
    Posts
    377
    Reputation
    11
    Thanks
    118
    My Mood
    Aggressive
    there is an easier way^^

  11. #24
    *Marneus901*'s Avatar
    Join Date
    Sep 2007
    Gender
    male
    Location
    Maryland
    Posts
    112
    Reputation
    12
    Thanks
    16


  12. #25
    NetSuspsend's Avatar
    Join Date
    Jul 2008
    Posts
    161
    Reputation
    10
    Thanks
    16
    Yeah, following that tut I can't find "61 E9 87 92 FD FF 00 00 00 00" :\

  13. #26
    gudsoldier's Avatar
    Join Date
    Jul 2008
    Gender
    male
    Location
    In your Girlfriends Closet.
    Posts
    1,010
    Reputation
    14
    Thanks
    279
    My Mood
    Mellow
    I'm feeling fat and sassy. Anyways, I'm pretty sure the people we're trying not to spoon feed will not be able to eat from this spoon considering the food being fed is a little too complicated.
    Stop flaming each other, it helps no one, and causes a step backwards rather than a step forwards.

    Read the rules before you decide to voice your opinion.

    Check your Grammar/Spelling/Facts before typing, otherwise I or another member will do it for you. And that just makes you look stupid.

  14. #27
    Rickyrudy's Avatar
    Join Date
    Feb 2008
    Gender
    male
    Posts
    277
    Reputation
    10
    Thanks
    26
    Quote Originally Posted by gudsoldier View Post
    I'm feeling fat and sassy. Anyways, I'm pretty sure the people we're trying not to spoon feed will not be able to eat from this spoon considering the food being fed is a little too complicated.
    Exactly only problem i'm having is rapidsharing hating on me >.> Dling IDA at some 5kbps rofl.. and its 74mb...

  15. #28
    NetSuspsend's Avatar
    Join Date
    Jul 2008
    Posts
    161
    Reputation
    10
    Thanks
    16
    IDA is 15mb, well the freeware version unless you're getting a crack >_>

  16. #29
    gudsoldier's Avatar
    Join Date
    Jul 2008
    Gender
    male
    Location
    In your Girlfriends Closet.
    Posts
    1,010
    Reputation
    14
    Thanks
    279
    My Mood
    Mellow
    Exactly on what, me feeling fat and sassy, or people being spoon fed too much at a time so they can't process what to do with it all.
    Stop flaming each other, it helps no one, and causes a step backwards rather than a step forwards.

    Read the rules before you decide to voice your opinion.

    Check your Grammar/Spelling/Facts before typing, otherwise I or another member will do it for you. And that just makes you look stupid.

  17. #30
    Rickyrudy's Avatar
    Join Date
    Feb 2008
    Gender
    male
    Posts
    277
    Reputation
    10
    Thanks
    26
    Lol netsuspnder i never go without crack

Page 2 of 5 FirstFirst 1234 ... LastLast

Similar Threads

  1. """""How To Bypass Hackshield"""""
    By leonard208 in forum WarRock - International Hacks
    Replies: 3
    Last Post: 04-11-2009, 12:24 AM
  2. How to bypass hackshield? PLEASE ANSWER!
    By ploxide in forum Combat Arms Hacks & Cheats
    Replies: 0
    Last Post: 12-25-2008, 07:55 PM
  3. [Request] how to bypass hackshield?
    By XxKylePwnsxX in forum Anti-Cheat
    Replies: 3
    Last Post: 10-25-2008, 12:01 PM
  4. [Request] how to bypass hackshield?
    By XxKylePwnsxX in forum Anti-Cheat
    Replies: 0
    Last Post: 08-28-2008, 07:09 PM
  5. how do i bypass hackshield?
    By m010011 in forum Combat Arms Hacks & Cheats
    Replies: 9
    Last Post: 08-14-2008, 09:36 PM

Tags for this Thread