What do people who make hacks/bypasses for games/anti cheats use? Detours/mhook/easyh

Posts 1–10 of 10 · Page 1 of 1
What do people who make hacks/bypasses for games/anti cheats use? Detours/mhook/easyh
All of the tutorials I see on hooking are for detours, which is (unless I'm mistaken) $10000 for a commercial license, and I severely doubt people are paying that much to sell a hack for $5.

So, what are they using? Mhook? Easy hook? Or are they illegally selling stuff made with detours express? Or possibly writing their own?

I'm not exactly a pro at this hacking stuff, thanks.
All of the tutorials I see on hooking are for detours, which is (unless I'm mistaken) $10000 for a commercial license, and I severely doubt people are paying that much to sell a hack for $5.
Couldn't really catch your drift, could you rephrase?

What 10k dollars?
Quote Originally Posted by Auxilium View Post


Couldn't really catch your drift, could you rephrase?

What 10k dollars?
I'm asking if most people use detours, mhook, easyhook, etc.. I doubt that people selling game hacks for $5 pay $10000 for a commercial detours license, so I'm wondering if they make their own hook or use detours illegally, mhook, easyhook, or make their own.
I generally used these pre-created functions:
Code:
void MakeJMP ( BYTE* pAddress, DWORD dwJumpTo, DWORD dwLen ) {
	DWORD dwOldProtect, dwBkup, dwRelAddr;

	VirtualProtect ( pAddress, dwLen, PAGE_EXECUTE_READWRITE, &dwOldProtect );
	dwRelAddr = ( DWORD ) ( dwJumpTo - ( DWORD ) pAddress ) - 5;
	*pAddress = 0xE9;

	* ( ( DWORD * ) ( pAddress + 0x1 ) ) = dwRelAddr;
	for ( DWORD x = 0x5; x < dwLen; x++ ) * ( pAddress + x ) = 0x90;
	VirtualProtect ( pAddress, dwLen, dwOldProtect, &dwBkup );

	return;
}

void* DetourFunction ( BYTE* src, const BYTE* dst, const int len ) {
	DWORD dwBack;
	BYTE* jmp = ( BYTE* ) malloc ( len + 5 );
	VirtualProtect ( src, len, PAGE_EXECUTE_READWRITE, &dwBack );
	memcpy ( jmp, src, len );
	jmp += len;
	jmp[0] = 0xE9;
	* ( DWORD* ) ( jmp + 1 ) = ( DWORD ) ( src + len - jmp ) - 5;
	src[0] = 0xE9;
	* ( DWORD* ) ( src + 1 ) = ( DWORD ) ( dst - src ) - 5;
	for ( int i = 5; i < len; i++ )
		src[i] = 0x90;
	VirtualProtect ( src, len, dwBack, &dwBack );
	return ( jmp - len );
}
Examples:
So for DetourFunction: (From my MW3 Hook)
Code:
typedef int (__cdec* tDraw2D)(int a1);
tDraw2D Draw2D = NULL;

DetourFunction((BYTE*)OFFS_DRAW2D, (BYTE*)&Draw2DHook, 0x5);

int Draw2DHook(int a1)
{
  __asm pushad; //Preserve stack beforehand
  //Hack stuff
  __asm popad; //Get back stack
  Draw2D(a1); //Then call origional game code and return to normal execution
}
And for MakeJMP:
Code:
DWORD dwReturn  = (OFF_DRAW2D + 5);
__declspec(naked) void Draw2D()
{
   __asm
   {
      //Do overwritten code here
      //Preserve stack
      pushad;
      pushfd;
   }
   Draw2DWrapper(); //Hack stuff
   __asm
   {   
      //Restore stack
      popfd;
      popad;
      jmp [dwReturn]; //Return to game code
    }
}

MakeJMP((PBYTE)OFF_DRAW2D, (DWORD)Draw2D, 5);


---------- Post added at 01:44 AM ---------- Previous post was at 01:42 AM ----------

EDIT:

The main difference between DetourFunction and MakeJMP is that you don't have a variable to automatically execute the code overwritten so you'll have to do it manually. For beginners and in general, DetourFunction is easier to use... (Once you get your typedef right.)
Selling hacks is in a legal grey area already (very little precedence), so I really doubt hack authors worry about using Detours... That being said, the free version of detours does not support x64.
Why would anyone buy a license for detours? Just make it yourself..
Quote Originally Posted by aIW|Convery View Post
Why would anyone buy a license for detours? Just make it yourself..
Express Detours is an lib made by microsoft giving you the advantage of 100% UD hooking, though its waste of money
Detours is not undetected. The reason why Detours is so useful is that it supports all processors Windows runs on (so it should theoretically work on ARM now too). It provides many different methods of hooking, disassembles instructions for inline hooks, detour chaining, and gives the ability to hook managed code, among many other things.

The reason why you buy things like Detours is the same reason why you buy other applications (when theoretically you could have coded it yourself).
He isn't asking WHY these hack sellers are using detours. He is sking IF these hack seller are using detours. Because the express version just supports x86 processors.
Quote Originally Posted by Delinquenz View Post
He isn't asking WHY these hack sellers are using detours. He is sking IF these hack seller are using detours. Because the express version just supports x86 processors.
Yeah basically this, I don't want to be some skid c/ping all day and selling hacks for $5 a month, I just want to hack to have my own private, customizable hacks and for the experience.

Basically I want to know what most people use and why, like pros and cons of easyhook, mhook, detours, self coded. Like documentation, community, etc.. I'm assuming self coded obv has the largest doc and community, but it's probably the hardest, which isn't good for a newb like me.
Posts 1–10 of 10 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?