Manual Mapping Injector

Posts 1–10 of 10 · Page 1 of 1
Manual Mapping Injector
Title says all i want someone to tell me more about manual mapping
anyone ??
Basically Manual Mapping is mimicking the LoadLibrary API. A big advantage to this is that it doesn't require you to load the DLL from a file, but simply by it residing in memory. Secondly, as a side effect, ring 0 detections from the ACs are being avoided. Manual Mapping is an advanced method and it's a must when you want to stream VIP hacks.
Quote Originally Posted by Jabberwock View Post
Ring 0 detections from the ACs are being avoided.
What "Ring 0 detections" do ACs even have?

Also, my Injector library (see signature) has working Manual Map code (in C#), it'd be easy to port it to C++ though.
Jetamay wrote a PE loader in C++ which he shared in this section as well:
http://www.mpgh.net/forum/31-c-c-pro...ule-final.html
http://www.mpgh.net/forum/31-c-c-pro...er-sample.html

I'd recommend reading a fair bit of the PE/COFF specification (v8), which is available from Microsoft's website as well as pretty much any Matt Pietrek articles you can find:

PE/COFF specification
vvv Great Matt Pietrek Articles vvv
An In-Depth Look into the Win32 Portable Executable File Format
Peering inside the PE (similar to above, more code examples though)
Under the Hood: Windows Loader

If you're going to write your own PE loader without shamelessly leeching from other people's source, you're in for a LOT of reading and fucking around with the file format. There are a LOT of problems you'll run into which aren't documented in higher level articles about the Windows Loader (like in Matt Pietrek's work), especially when you're mapping to a different process (SxS dependencies are a real fucker).

In general the process is pretty straightforward:
  • Load the binary into local memory to modify it
  • Patch the relocation directory
  • Resolve all dependent libraries
  • Patch the import table addresses
  • Map all necessary sections into the target
  • Invoke the entry point (DllMain)


Easy huh?
Pretty easy because there's a plethora of code out there that you can read (just google manual map or reflective DLL injection). There's no shame from learning from other people's code. Do not reinvent the wheel.

Anyways, on to the point about kernel level hooks. If you're running 32 bit Windows, anti-cheats have pretty much free reign including direct manipulation of the kernel and system service tables. This means they can hook all the functions. If you're running 64 bit Windows, then you have to deal with Kernel Patch Protection (colloquially known as PatchGuard). This doesn't mean anti-cheats can't do anything. Anti-cheats can still monitor creation of handles to objects and the loading of DLLs by using ObRegisterCallbacks and PsSetLoadImageNotifyRoutine respectively. Driver signing enforcement is a red herring because most anti-cheats can get their drivers signed.
Quote Originally Posted by Fovea View Post
Anyways, on to the point about kernel level hooks. If you're running 32 bit Windows, anti-cheats have pretty much free reign including direct manipulation of the kernel and system service tables. This means they can hook all the functions. If you're running 64 bit Windows, then you have to deal with Kernel Patch Protection (colloquially known as PatchGuard). This doesn't mean anti-cheats can't do anything. Anti-cheats can still monitor creation of handles to objects and the loading of DLLs by using ObRegisterCallbacks and PsSetLoadImageNotifyRoutine respectively. Driver signing enforcement is a red herring because most anti-cheats can get their drivers signed.
Cheers, I was thinking along different lines when I read "Ring0".

Quote Originally Posted by Fovea
Pretty easy because there's a plethora of code out there that you can read (just google manual map or reflective DLL injection). There's no shame from learning from other people's code. Do not reinvent the wheel.
Not sure if this was directed at my comment, but the number of properly implemented Manual Map injectors, capable of injecting into another process are pretty thin to the ground after doing a few Google searches. Plus, 'reinventing the wheel' for stuff like this is always fun. I'm not implying that the OP shouldn't use other code as a point of reference (it would be hypocritical of me to say so, since that's exactly what I did when I began writing mine), and I gave him numerous code examples to start from, I was merely pointing out that if he wanted to get any level of understanding from said code, it'd be a worthwhile endeavour to read up on the available documentation.
Quote Originally Posted by Jason View Post
What "Ring 0 detections" do ACs even have?
I meant that they use a driver to hook functions in ntdll.dll such as LdrLoadDll.
Quote Originally Posted by Jabberwock View Post


I meant that they use a driver to hook functions in ntdll.dll such as LdrLoadDll.
That is not ring 0. Hooking ntdll.dll still resides in user mode.
Thank you all for replying
maybe i will tell you what is going up with me
Posts 1–10 of 10 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?