Thread: Pattern Scan

Results 1 to 12 of 12
  1. #1
    GoldWhite's Avatar
    Join Date
    Nov 2012
    Gender
    male
    Posts
    136
    Reputation
    10
    Thanks
    46

    Pattern Scan

    Pattern Scan of Dip Engine can anyone give?

  2. #2
    Flengo's Avatar
    Join Date
    May 2010
    Gender
    male
    Location
    /admincp/banning.php
    Posts
    20,591
    Reputation
    5180
    Thanks
    14,179
    My Mood
    Inspired
    There's no need for DIP Engine. Just hook D3D DIP.

    Do a midfunction hook after the first 5 bytes.
    I Read All Of My PM's & VM's
    If you need help with anything, just let me know.

     


     
    VM | PM | IM
    Staff Administrator Since 10.13.2019
    Publicist Since 04.04.2015
    Middleman Since 04.14.2014
    Global Moderator Since 08.01.2013
    Premium Since 05.29.2013

    Minion+ Since 04.18.2013

    Combat Arms Minion Since 12.26.2012
    Contributor Since 11.16.2012
    Member Since 05.11.2010


  3. #3
    Saltine's Avatar
    Join Date
    Jun 2011
    Gender
    male
    Posts
    493
    Reputation
    104
    Thanks
    629
    Quote Originally Posted by Flengo View Post
    There's no need for DIP Engine. Just hook D3D DIP.

    Do a midfunction hook after the first 5 bytes.
    Or you can look into hotpatch hooking, its a feature windows implemented to allow patching executables without restarting.

    Oh no! Vortex is gay!

  4. The Following User Says Thank You to Saltine For This Useful Post:

    [MPGH]Flengo (11-25-2012)

  5. #4
    Departure's Avatar
    Join Date
    Nov 2010
    Gender
    male
    Posts
    805
    Reputation
    125
    Thanks
    1,794
    My Mood
    Doh
    The hot patch nops are the first place any decent anti hack software looks, I am sure Hack shield would scan there if they are scanning the functions entry point. there is 6 bytes allocated just before the entry of the function these are normally nops 0x90 then on the function export table it will be the original address - 6 bytes, when this function is called with the new address there is normally a patch which jumps to another function, it goes something like that... it was years ago I played with microsoft hot patch area because its normally the first thing checked in any good hack detection software
    Last edited by Departure; 11-25-2012 at 05:08 AM.
    DJector.Lite
    Get the advantages of new injection technology, with 1 click easy to use injector, work for all platforms x86/x64

    Download

    D-Jector
    Get the most advanced and full featured injector around, works for any game and any platform x86/x64, nothing comes even close.
    Download

  6. The Following User Says Thank You to Departure For This Useful Post:

    [MPGH]Flengo (11-25-2012)

  7. #5
    Saltine's Avatar
    Join Date
    Jun 2011
    Gender
    male
    Posts
    493
    Reputation
    104
    Thanks
    629
    Quote Originally Posted by Departure View Post
    The hot patch nops are the first place any decent anti hack software looks, I am sure Hack shield would scan there if they are scanning the functions entry point. there is 6 bytes allocated just before the entry of the function these are normally nops 0x90 then on the function export table it will be the original address - 6 bytes, when this function is called with the new address there is normally a patch which jumps to another function, it goes something like that... it was years ago I played with microsoft hot patch area because its normally the first thing checked in any good hack detection software
    Believe it or not, as of several patches ago (I haven't checked since), hotpatch hooking worked perfectly for DrawIndexedPrimitive :P

    Oh no! Vortex is gay!

  8. The Following User Says Thank You to Saltine For This Useful Post:

    Departure (11-25-2012)

  9. #6
    GoldWhite's Avatar
    Join Date
    Nov 2012
    Gender
    male
    Posts
    136
    Reputation
    10
    Thanks
    46
    close please

  10. #7
    Flengo's Avatar
    Join Date
    May 2010
    Gender
    male
    Location
    /admincp/banning.php
    Posts
    20,591
    Reputation
    5180
    Thanks
    14,179
    My Mood
    Inspired
    Nexon doesn't really do shit.

    I'll try it out. But I'm pretty sure it should still be working.

    It wouldn't stand a chance against any real Anti-Hack programs.
    I Read All Of My PM's & VM's
    If you need help with anything, just let me know.

     


     
    VM | PM | IM
    Staff Administrator Since 10.13.2019
    Publicist Since 04.04.2015
    Middleman Since 04.14.2014
    Global Moderator Since 08.01.2013
    Premium Since 05.29.2013

    Minion+ Since 04.18.2013

    Combat Arms Minion Since 12.26.2012
    Contributor Since 11.16.2012
    Member Since 05.11.2010


  11. #8
    Genesis's Avatar
    Join Date
    Nov 2012
    Gender
    male
    Location
    Terra Australis
    Posts
    4,221
    Reputation
    1391
    Thanks
    2,528
    Not sure if it's right but try this.

    Code:
    PATTERN: "\x8B\x08\x8B\x91\x48\x01\x00\x00\xFF\xD2\x8B\xE5\x5D\xC2\x14\x00"
    MASK: "xxxxxxxxxxxxxxxx"
    Search in Engine of course.

  12. The Following User Says Thank You to Genesis For This Useful Post:

    GoldWhite (11-26-2012)

  13. #9
    demtrios's Avatar
    Join Date
    Jan 2010
    Gender
    male
    Location
    MPGH.Net
    Posts
    870
    Reputation
    10
    Thanks
    1,056
    My Mood
    Amused
    Well you can use the vtable 82 Dip not use any type of address and parese that undetectable


    Cock CS since 26•03•2013

  14. #10
    Ch40zz-C0d3r's Avatar
    Join Date
    Apr 2011
    Gender
    male
    Posts
    831
    Reputation
    44
    Thanks
    401
    My Mood
    Twisted
    Quote Originally Posted by demtrios View Post
    Well you can use the vtable 82 Dip not use any type of address and parese that undetectable
    A normal vtable hook on 82 with ms detours (or any other detours) is detected :/

    Progress with my game - "Disbanded"
    • Fixed FPS lag on spawning entities due to the ent_preload buffer!
    • Edit the AI code to get some better pathfinding
    • Fixed the view bug within the sniper scope view. The mirror entity is invisible now!
    • Added a new silencer for ALL weapons. Also fixed the rotation bugs
    • Added a ton of new weapons and the choice to choose a silencer for every weapon
    • Created a simple AntiCheat, noobs will cry like hell xD
    • The name will be Disbanded, the alpha starts on the 18th august 2014



    Some new physics fun (Serversided, works on every client)



    My new AI
    https://www.youtube.com/watch?v=EMSB1GbBVl8

    And for sure my 8 months old gameplay with 2 friends
    https://www.youtube.com/watch?v=Na2kUdu4d_k

  15. #11
    demtrios's Avatar
    Join Date
    Jan 2010
    Gender
    male
    Location
    MPGH.Net
    Posts
    870
    Reputation
    10
    Thanks
    1,056
    My Mood
    Amused
    Quote Originally Posted by Ch40zz-C0d3r View Post
    A normal vtable hook on 82 with ms detours (or any other detours) is detected :/
    Yes mine is working perfectly


    Cock CS since 26•03•2013

  16. #12
    -Bl00d-'s Avatar
    Join Date
    Sep 2011
    Gender
    female
    Location
    Imma girl what about it?
    Posts
    481
    Reputation
    10
    Thanks
    53
    My Mood
    Twisted
    use Vtable
    with modified "Clarkie detours"
    works like a charm

Similar Threads

  1. [Help] Auto-Updating hack through Patterns/Sig Scans?
    By Void() in forum Combat Arms Hack Coding / Programming / Source Code
    Replies: 6
    Last Post: 09-27-2012, 10:57 PM
  2. [Solved] Scan these byte patterns
    By Pingo in forum Call of Duty Black Ops Help
    Replies: 7
    Last Post: 08-05-2011, 05:48 AM
  3. [Help] Pattern scanning
    By pyton789 in forum Visual Basic Programming
    Replies: 27
    Last Post: 03-09-2011, 03:44 AM
  4. File Scan here
    By Neogaidenx in forum Spammers Corner
    Replies: 4
    Last Post: 08-14-2008, 11:30 AM
  5. CE SCANS TAKING 4ever
    By A7X Oblivian in forum WarRock - International Hacks
    Replies: 3
    Last Post: 06-03-2006, 07:45 AM