Try packing your compiled .dll with a compressor like mpress or PECompact and then test in game.
Hey guys,
You don't see me around here very often, but I have a question.
I have a hack (of my own making, thank you) and it's all working perfectly, it works on any game for any given length of time that doesn't have any AC protection. However I've run into trouble with hackshield. The hook works fine for about 0.30/5 minutes, after that (or after being killed) the game d/c's. I'm sure that ca doesn't signature scan my hook yet because the hack is only 3 days old and because I can stay in-game when the hook is turned off. Do you guys have any idea on how it's being detected?
Should I change my method (it's a jump right now) or should I move it deeper into the d3d code (it's a mid function already)
Thanks,
Last edited by .::SCHiM::.; 05-25-2011 at 12:56 PM.
I'm SCHiM
Morals derive from the instinct to survive. Moral behavior is survival behavior above the individual level.
Polymorphic engine
Interprocess callback class
SIN
Infinite-precision arithmetic
Hooking dynamic linkage
(sloppy)Kernel mode Disassembler!!!
Semi debugger
Try packing your compiled .dll with a compressor like mpress or PECompact and then test in game.
Prolly Just Your Detour....Single JMP is easily Detected...
Yea but it's mid function, does HC scan every god-dam byte in the d3d functions?
@NOOB
It's not signature scanned, it's my detour/hook that's wrong, I'll try though maybe it works.
I'm SCHiM
Morals derive from the instinct to survive. Moral behavior is survival behavior above the individual level.
Polymorphic engine
Interprocess callback class
SIN
Infinite-precision arithmetic
Hooking dynamic linkage
(sloppy)Kernel mode Disassembler!!!
Semi debugger
you do realize once your dll is loaded it is unpacked......if anything virtualizing and adding random instructions and a simple string encryption would be better.
@ hook ya you can hook lower eventually they may end up scanning the whole function who knows , just always have a plan b , fyi there are alot of functions in sync with drawing, many undocumented but easy to see also engine functions you can draw in
topblast (05-25-2011)
My detour is JMP, and works fine...
With packer not works..
Without packer = Works Fine
On what function do you have your hook, and what method?
@ALL
Thanks for the attention too
EDDIT:
I'm hooking DrawIndexedPrimitive() btw, for chams
Last edited by .::SCHiM::.; 05-25-2011 at 01:10 PM.
I'm SCHiM
Morals derive from the instinct to survive. Moral behavior is survival behavior above the individual level.
Polymorphic engine
Interprocess callback class
SIN
Infinite-precision arithmetic
Hooking dynamic linkage
(sloppy)Kernel mode Disassembler!!!
Semi debugger
My hack is for Combat arms North America ...
Combat arms Brazil = Shit..
Update today, use private :P
@whit
I'm SCHiM
Morals derive from the instinct to survive. Moral behavior is survival behavior above the individual level.
Polymorphic engine
Interprocess callback class
SIN
Infinite-precision arithmetic
Hooking dynamic linkage
(sloppy)Kernel mode Disassembler!!!
Semi debugger
i use Virtual Protect...
and JMP function!
i use two methods :
Detourcreate and after DetourRemove!
I'm SCHiM
Morals derive from the instinct to survive. Moral behavior is survival behavior above the individual level.
Polymorphic engine
Interprocess callback class
SIN
Infinite-precision arithmetic
Hooking dynamic linkage
(sloppy)Kernel mode Disassembler!!!
Semi debugger