Why shit is getting detected?

Posts 121–135 of 151 · Page 9 of 11
Quote Originally Posted by AVGN View Post

yes...

i've tried it in the past with no luck

You prolly change the Hash of a Actual Patch hack ( Engine/Cshell update )
Quote Originally Posted by whit View Post
You prolly change the Hash of a Actual Patch hack ( Engine/Cshell update )
probably...
Quote Originally Posted by NOOB View Post


So I take in original .dll in as a byte array, write random bytes at the end of the .dll (adding more bytes to it, increasing size of the array?) and then write it back on the computer with a random name?

basically yes....

The dll will never read the overlay because in the headers has information about the dll's sections and there sizes so it will only load the original data, but adding the bytes will change its MD5 calculation.
Quote Originally Posted by Departure View Post
basically yes....

The dll will never read the overlay because in the headers has information about the dll's sections and there sizes so it will only load the original data, but adding the bytes will change its MD5 calculation.
@Departure

I tried doing that to your hotkey hack (crashes as-is from the attachment) and after adding one byte to the end of the dll, it works (even works with out changing the name). also works with JA 1.0 (which is 'detected')

i just did something like this :

Code:
        Dim oldDLL() As Byte = IO.File.ReadAllBytes(TextBox1.Text) 'txtbox1 has the original DLL file path
        Dim newDLL(oldDLL.Length) As Byte 'we're making the new DLL with one byte added to the end
        Array.Copy(oldDLL, newDLL, oldDLL.GetUpperBound(0)) 'copies everything in the oldDLL to the newDLL
        newDLL(oldDLL.Length) = 77 'adds 77 for the last byte of the new dll (idk why 77)
        IO.File.WriteAllBytes(TextBox1.Text & ".cm", newDLL) 'outputs the new dll
Quote Originally Posted by NOOB View Post


@Departure

I tried doing that to your hotkey hack (crashes as-is from the attachment) and after adding one byte to the end of the dll, it works (even works with out changing the name). also works with JA 1.0 (which is 'detected')

i just did something like this :

Code:
        Dim oldDLL() As Byte = IO.File.ReadAllBytes(TextBox1.Text) 'txtbox1 has the original DLL file path
        Dim newDLL(oldDLL.Length) As Byte 'we're making the new DLL with one byte added to the end
        Array.Copy(oldDLL, newDLL, oldDLL.GetUpperBound(0)) 'copies everything in the oldDLL to the newDLL
        newDLL(oldDLL.Length) = 77 'adds 77 for the last byte of the new dll (idk why 77)
        IO.File.WriteAllBytes(TextBox1.Text & ".cm", newDLL) 'outputs the new dll
@NOOB
good job NOOB, so it is clear now its the hashing of the file that is detected
Are you releasing it to public or keeping it private?

P.s also just to let you know if you doing this to some packed file it wont work because some packers append settings to the end of the file(thats what your doing also) so there is a good chance you could corrupt the settings, luckily there is'nt many commercial packer that use setting at EOF.

@whit
Quote Originally Posted by Departure View Post
@NOOB
good job NOOB, so it is clear now its the hashing of the file that is detected
Are you releasing it to public or keeping it private?

P.s also just to let you know if you doing this to some packed file it wont work because some packers append settings to the end of the file(thats what your doing also) so there is a good chance you could corrupt the settings, luckily there is'nt many commercial packer that use setting at EOF.

@whit
What If you made an injector that did that automatically
Quote Originally Posted by NOOB View Post


@Departure

I tried doing that to your hotkey hack (crashes as-is from the attachment) and after adding one byte to the end of the dll, it works (even works with out changing the name). also works with JA 1.0 (which is 'detected')

i just did something like this :

Code:
        Dim oldDLL() As Byte = IO.File.ReadAllBytes(TextBox1.Text) 'txtbox1 has the original DLL file path
        Dim newDLL(oldDLL.Length) As Byte 'we're making the new DLL with one byte added to the end
        Array.Copy(oldDLL, newDLL, oldDLL.GetUpperBound(0)) 'copies everything in the oldDLL to the newDLL
        newDLL(oldDLL.Length) = 77 'adds 77 for the last byte of the new dll (idk why 77)
        IO.File.WriteAllBytes(TextBox1.Text & ".cm", newDLL) 'outputs the new dll


@ noob, do that with all of the old and detected hax
I just took out the ptc, works that way. But then i cant use ptc...

Noobs and Flams dc...
My detour posted in cabr Section is working in CANA
100%
i tested for 30 minutes...
Quote Originally Posted by Strikex View Post
My detour posted in cabr Section is working in CANA
100%
i tested for 30 minutes...
Combined base v3 Detours still work
Quote Originally Posted by whit View Post
Combined base v3 Detours still work
d3d9 hooks still work
Quote Originally Posted by whit View Post
Combined base v3 Detours still work
I don't think so. I always dc few mins ingame from cshell.dll
Quote Originally Posted by Cryptonic View Post


I don't think so. I always dc few mins ingame from cshell.dll
Works for me
Quote Originally Posted by whit View Post
Works for me
Really? Send me one with like chams on it (something simple), and ill test it
/offtopiclikeanigguhdrinkingkoolaid.



GUESS WHOS BACK....DUNDUNDUNDUN.... BACK AGAIN.......DUNDUNDUNDUDN.....TYGAA'S BACKK.....DUNDUNDUNDUDN......FROM THE BAN....DUNDUNDUND.


Lol watch this nigguh get banned again.
Posts 121–135 of 151 · Page 9 of 11

Post a Reply

Tags for this Thread

None

Need help?