[Makes detected hacks undetected] Simple PE Cipher

Posts 16–30 of 468 · Page 2 of 32
This works fine, but hacks that I use it on are getting into the game undetected but at the cost of crashing at each respawn. I tried it on every hack I could with the same result, new round or respawn... crash... My computer even restarted on me once... I know it's not the hacks since I used each one prior to the detection without any problem. Any help?
Quote Originally Posted by Jazzie View Post
This works fine, but hacks that I use it on are getting into the game undetected but at the cost of crashing at each respawn. I tried it on ever hack I could with the same result die new round or respawn... crash... My computer even restarted on me once... I know it's not the hacks since I used each one prior to the detection without any problem. Any help?
Crashing when respawning sounds like a hack issue. I'm more inclined to believe that there's an issue with the hack than the cipher, as it'd be more likely to not work at all if the cipher messed something up. Nevertheless, delete the ciphered dll and restore the old one, then try cipher it again.
Quote Originally Posted by Jason View Post


Basically, one way Nexon can detect hack attempts is to take a "hash" of the .dll when it's injected. They then compare this hash to a list of "blacklisted" dlls and if there is a match, they report a hack detection and exit. The purpose of a cipher like this is to change up some data within the .dll so that the hash of the file changes. Previously this was achieved by writing a few extra bytes of data to the end of the file. However, recently Nexon have changed the way they hash the dll (rather than simply hashing the entire file, they hash only a portion of the file), which is why some of the old ciphers have stopped working.

My method modifies safe data within the file itself (through the documented PE structure), and is thus more likely to modify the portion of the file that Nexon hashes (most likely the executable sections, but not 100% sure so I modify a few different areas). The idea, of course, is to not break the .dll itself when modifying data.
This is why I love MPGH so much, thanks for the thorough explanations Great work sir.
Great Job friend! Like'n it!
I seem to crash at the CA loading screen (where they have a man running in a corner) when I've "cipher'd" a detected hack... (the hack I'm trying to cipher is the Project-X by Nightmare)

---------- Post added at 05:19 PM ---------- Previous post was at 05:02 PM ----------

And is that how you should use it? Lol, cause this is my first time using a "cipher"
Quote Originally Posted by OMG1OMG View Post
I seem to crash at the CA loading screen (where they have a man running in a corner) when I've "cipher'd" a detected hack... (the hack I'm trying to cipher is the Project-X by Nightmare)

---------- Post added at 05:19 PM ---------- Previous post was at 05:02 PM ----------

And is that how you should use it? Lol, cause this is my first time using a "cipher"
Yes, that's how you should use it. However, the hack may be beyond help. Thanks for letting me know the name of the hack you used, I can do some testing when I get home and verify whether or not it's the fault of the Cipher, or whether the hack is just flat out detected.
Quick question doeee, when I Cipher the .dll, I'm not supposed to use the one file that says (nameofhack).dll.bak am I? I'm supposed to use the other .dll that hasn't had any changes right? When I tried to Cipher the Luccss hack, it made the copy, but while in-game CA crashed pretty quickly. I wasn't sure which one I was supposed to use because both of the .dll files crashed quickly.
Quote Originally Posted by marcsi View Post
Quick question doeee, when I Cipher the .dll, I'm not supposed to use the one file that says (nameofhack).dll.bak am I? I'm supposed to use the other .dll that hasn't had any changes right? When I tried to Cipher the Luccss hack, it made the copy, but while in-game CA crashed pretty quickly. I wasn't sure which one I was supposed to use because both of the .dll files crashed quickly.
Use the .dll without the .bak. The .dll.bak one is the original, unciphered file. If they're both crashing quickly I daresay it's the hack causing issues.
Quote Originally Posted by Jason View Post


Use the .dll without the .bak. The .dll.bak one is the original, unciphered file. If they're both crashing quickly I daresay it's the hack causing issues.
Thanks!!!!!
really nice. got this to work :P
Nice ;P

.-.
it's can run, i got this i cant run it.. do i need a inject?
Posts 16–30 of 468 · Page 2 of 32
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?