Pretty cool stuff
I'll study it in a free moment
Cheat that uses a driver instead WinAPI for Reading / Writing memory.
Project on ******:
Unsigned Drivers can be loaded using
This project uses a kernel mode driver in co-operation with a user mode program to establish a method of reading / writing virtual memory from a regular win32 program without having to use regular WinAPI Functions. This happens by using a driver to execute the reading / writing of the memory itself from a lower level. This means the user mode program does not have to open any handles to csgo or use ReadProcessMemory or WriteProcessMemory nor any functions that has to deal with process handles.
VAC’s defence against external cheats is based on system handle scanning on user level. VAC scans handles in the system (ring3), when it finds a handle which for example points to cs:go, the process that holds that handle will be analysed.
This can be avoided by not opening any handles to csgo (OpenProcess()), but it also means we can’t use any WinAPI Functions to Read/Write the memory of the process that we want, so we must go to a lower level. As of now, VAC or valve does not have any drivers which means if we can write & get kernel code running defeating vac is possible.
“Then a scanning thread is created. This thread repeatedly scans all handles in the system (calls NtQuerySystemInformation with SystemHandleInformation information class) for handles to the process its running from and logs any process holding it into the first section object. VAC uses NtQueryInformationProcess with ProcessImageFileName information class to find the image name of the process, tries to open it with NtCreateFile and uses GetFileInformationByHandle to get the volume serial number and the file identifier (it won't change if you rename or move the file).”
https://www.*************.me/wiki/Valve_...(and_more)
Last edited by DarknzNet; 03-05-2017 at 04:06 AM.
Zer0Mem0ry
C/C++ Programmer, Youtuber, software enthusiast & hobbyist.
Donate: (bitcoin): 1JhSKGgRQmir8rRF4Sm5CP4fDDofKFAypd
Youtube: https://www.youtube.com/channel/UCDk...ariJF2Dn2j5WKA
Skype: virtual_coder
Pretty cool stuff
I'll study it in a free moment
. . . malsignature.com . . .
[ global rules ] [ scam report ] [ image title ] [ name change ] [ anime force ]
[ league of legends marketplace rules ] [ battlefield marketplace rules ]
"because everytime you post a picture of anime in here
your virginity's time increases by 1 month"
~Smoke 2/18/2018
Former Staff 09-29-2018
Battlefield Minion 07-21-2018
Premium Seller 03-04-2018
Publicist 12-10-2017
League of Legends Minion 05-31-2017
Premium 02-05-2017
Member 10-13-2013
It is huh
Zer0Mem0ry
C/C++ Programmer, Youtuber, software enthusiast & hobbyist.
Donate: (bitcoin): 1JhSKGgRQmir8rRF4Sm5CP4fDDofKFAypd
Youtube: https://www.youtube.com/channel/UCDk...ariJF2Dn2j5WKA
Skype: virtual_coder
I had to remove 2****** links + video because ****** links are no longer allowed on mpgh and the video contained outside links in the description.
Fug. So I have to upload the code here & provide scans for it?
Zer0Mem0ry
C/C++ Programmer, Youtuber, software enthusiast & hobbyist.
Donate: (bitcoin): 1JhSKGgRQmir8rRF4Sm5CP4fDDofKFAypd
Youtube: https://www.youtube.com/channel/UCDk...ariJF2Dn2j5WKA
Skype: virtual_coder
Saw the video, really good. Very useful.