
Originally Posted by
Departure
@
.::SCHiM::.
1. 90% of the coders here don't understand the mid function hook(no offence)
3. 90% of the coders here don't make there own hooks(no offence)
4. 90% of the coders here wont be able to help you(no offence)
5. 90% of the coders will using someone else hooks(no offence)
Now im willing to bet you are also using a hook function you got from some where right?
Im guessing you did anyway.... add some random byte inbetween your hook function so it changes the byte signature of that function(just do some inline assembly instructions)
Also try hooking Present and Reset as we know these are not scanned for detection and does not need to be mid function...
Good luck.
P.s no offence to 90% of the coders here, That's just how I have seen it roll around here.
Also take TopBlast's advice about hooking a callee of DIP....
P.s.s
The packer subject has been talked about before, and I stick with what I said before that packers are pointless because the image is normally completely unpacked in memory(but still has the compactors signature in the first code section of the dll, the stub). What you do need to know is that using a "Protector" can benefit you because protectors normally have "Stolen Bytes" which don't get replaced until the function/procedure is called, Also a protector will normally compact the image depending on the settings, This means that it will not unpack the parts of code until its called for. Once again you need to know the difference between a packer and a protector...
Code:
MidFunctionHook proc MidFunctionTargetAddress:DWORD, MidFunctionHookAddress:DWORD, InstructionSize:DWORD
invoke GlobalAlloc, GPTR, 10h
mov MidFunctionTrampoline, eax
xor esi, esi
xor ecx, ecx
mov ebx, MidFunctionTargetAddress
@1:
mov cl, byte ptr[ebx+esi]
mov byte ptr[eax+esi], cl
inc esi
cmp esi, InstructionSize
jne @1
add eax, InstructionSize
mov esi, 0E9h
mov [eax], esi
inc eax
mov ebx, eax
mov edx, MidFunctionTargetAddress
sub edx, ebx ; edx = to
inc edx ; because of inc eax (after mov [eax], esi)
mov [eax], edx
mov ebx, MidFunctionTargetAddress
invoke VirtualProtect, MidFunctionTargetAddress, 40h, 40h, addr Oldprott
mov eax, MidFunctionTargetAddress
mov esi, 0E9h
mov [eax], esi
inc eax
mov ebx, MidFunctionHookAddress
sub ebx, eax
sub ebx, 4h
mov [eax], ebx
xor esi, esi
add esi, 5h
mov ebx, 90h
dec eax
@2:
mov byte ptr[eax+esi], bl
inc esi
cmp esi, InstructionSize
jne @2
invoke VirtualProtect, MidFunctionTrampoline, 40h, 40h, addr Oldprot
invoke VirtualProtect, MidFunctionTargetAddress, 40h, Oldprott, Oldprot
mov eax, MidFunctionTrampoline
ret
MidFunctionHook endp
It's all mine, no copy no leech, all out of my head.
Also can I disable the depth buffer from present? I can't can I?
@
freedompeace
I'm hooking DrawIndexedPrimitive (I thought that was DIP, if not what's DIP?)
Everything there is detected, and I only have 1 asci string in my entire code ("d3d.dll") does hackshield d/c on that?