New problem in the way

Posts 1–7 of 7 · Page 1 of 1
New problem in the way
Hey

Since I know E9 Detour is detected .

So Anyone can share with me the new detour .

Connect me : Jack_b_w@.hotmail.com

Regards : Wolf .
I take an old detour and i've update it.

Code:
void *DetourFWT(BYTE *src, const BYTE *dst, int minlen)
{
	// Declarations
	BYTE *jmp = 0, *org = 0;
	DWORD dwOldBack, dwNewBack = PAGE_READWRITE;
	BYTE *pPatchBuf = NULL;
	int len = 0;

	// Get minimum bytes to overwrite
	len = GetAutoLen(src,(minlen<6)?6:minlen); 

	// Globalization len ugual minlen
	if (len==0 && minlen>=6)
		len=minlen;

	// Return false if len doesn't exist
	if (len==0)
		return 0;

	// Allocate space for the jump
	org = jmp = (BYTE*)malloc(len+5);
	jmp[0]=len;

	// Increment the space for the jmp
	jmp++;

	// Adding low pause
	Sleep(2);

	// Force page protection flags to read|write
	VirtualProtect(src, len, dwNewBack, &dwOldBack);

	// Copy the overwritten opcodes at the original to the malloced space
	memcpy(jmp, src, len);

	// Increment to the end of the opcodes at the malloced space
	jmp += len;

	// Fear Jmp
	jmp[0] = 0xE9;
	*(DWORD*)(jmp+1) = (DWORD)(src+len - jmp) - 5;

	// Push
	src[0] = 0x68;
	*(DWORD*)(src+1) = (DWORD)(dst);

	// Retn
	src[5] = 0xC3;
	*(DWORD*)(src+1) = (DWORD)(dst - src) - 5;

	// Write detour with NOP
	for (int i=7; i<len; i++)
		src[i] = 0x90;

	// Put the old page protection flags back
	VirtualProtect(src, len, dwOldBack, &dwOldBack);

	// Clean cache from address
	FlushInstructionCache(GetCurrentProcess(), src, minlen);
	
	// Adding low pause
	Sleep(2);

	return &org[1];
}
NB: I don't help u as to use it. Learn by urself ^^

Enjoy.
Quote Originally Posted by DirecTX_ View Post
I take an old detour and i've update it.

Code:
void *DetourFWT(BYTE *src, const BYTE *dst, int minlen)
{
	// Declarations
	BYTE *jmp = 0, *org = 0;
	DWORD dwOldBack, dwNewBack = PAGE_READWRITE;
	BYTE *pPatchBuf = NULL;
	int len = 0;

	// Get minimum bytes to overwrite
	len = GetAutoLen(src,(minlen<6)?6:minlen); 

	// Globalization len ugual minlen
	if (len==0 && minlen>=6)
		len=minlen;

	// Return false if len doesn't exist
	if (len==0)
		return 0;

	// Allocate space for the jump
	org = jmp = (BYTE*)malloc(len+5);
	jmp[0]=len;

	// Increment the space for the jmp
	jmp++;

	// Adding low pause
	Sleep(2);

	// Force page protection flags to read|write
	VirtualProtect(src, len, dwNewBack, &dwOldBack);

	// Copy the overwritten opcodes at the original to the malloced space
	memcpy(jmp, src, len);

	// Increment to the end of the opcodes at the malloced space
	jmp += len;

	// Fear Jmp
	jmp[0] = 0xE9;
	*(DWORD*)(jmp+1) = (DWORD)(src+len - jmp) - 5;

	// Push
	src[0] = 0x68;
	*(DWORD*)(src+1) = (DWORD)(dst);

	// Retn
	src[5] = 0xC3;
	*(DWORD*)(src+1) = (DWORD)(dst - src) - 5;

	// Write detour with NOP
	for (int i=7; i<len; i++)
		src[i] = 0x90;

	// Put the old page protection flags back
	VirtualProtect(src, len, dwOldBack, &dwOldBack);

	// Clean cache from address
	FlushInstructionCache(GetCurrentProcess(), src, minlen);
	
	// Adding low pause
	Sleep(2);

	return &org[1];
}
NB: I don't help u as to use it. Learn by urself ^^

Enjoy.
oO pub ?
....
Can u help me with it ?
Thanksssssssssssssssssssssss
I got E9 & B8 Detours, and they work 100%
JMP and MOV EAX are detect by HS. My method is

Code:
JMP original_address //jmp the addy
push address_changed //push the addy jumped
retn //restore code

//if necessary
nop //stop the execution
This is detect also, but u need change something in your sources code like my detour.
Posts 1–7 of 7 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?