CoolOutro Detours Do WE11

Posts 1–9 of 9 · Page 1 of 1
Outro Detours Do WE11
Code:
LPVOID DetourCreateType( PBYTE pbTargetFunction, PBYTE pbDetourFunction, INT intSize, INT intType )
{
    #define Detour1        1    // Undetected by BlackCipher II
    #define Detour2        2    // Undetected by BlackCipher II
    #define Detour3        3    // Undetected by BlackCipher II
    #define Detour4        4    // Undetected by BlackCipher II
    #define Detour5        5    // Undetected by BlackCipher II

    DWORD dwProtect;
    PBYTE pbDetour = ( PBYTE  )malloc( intSize + 5 );
    INT i;

    VirtualProtect( pbTargetFunction, intSize, PAGE_EXECUTE_READWRITE, &dwProtect );
    memcpy( pbDetour, pbTargetFunction, intSize );
    pbDetour += intSize;

    *( BYTE * ) ( pbDetour + 0 ) = 0xE9;
    *( DWORD * )( pbDetour + 1 ) = ( DWORD )( pbTargetFunction + intSize - pbDetour ) - 5;

    switch( intType )
    {
    case 1:
        *( BYTE * ) ( pbTargetFunction + 0 ) = 0xB8;
        *( DWORD * )( pbTargetFunction + 1 ) = ( DWORD )( pbDetourFunction );
        *( WORD * ) ( pbTargetFunction + 5 ) = 0xE0FF;
        i = 7;
        break;

    case 2:
        *( WORD * ) ( pbTargetFunction + 0 ) = 0xC033;
        *( WORD * ) ( pbTargetFunction + 2 ) = 0xC085;
        *( WORD * ) ( pbTargetFunction + 4 ) = 0x840F;
        *( DWORD * )( pbTargetFunction + 6 ) = ( DWORD )( pbDetourFunction - pbTargetFunction ) - 10;
        i = 10;
        break;

    case 3:
        *( WORD * ) ( pbTargetFunction + 0 ) = 0xDB33;
        *( WORD * ) ( pbTargetFunction + 2 ) = 0xDB85;
        *( WORD * ) ( pbTargetFunction + 4 ) = 0x840F;
        *( DWORD * )( pbTargetFunction + 6 ) = ( DWORD )( pbDetourFunction - pbTargetFunction ) - 10;
        i = 10;
        break;

    case 4:
        *( WORD * ) ( pbTargetFunction + 0 ) = 0xC933;
        *( WORD * ) ( pbTargetFunction + 2 ) = 0xC985;
        *( WORD * ) ( pbTargetFunction + 4 ) = 0x840F;
        *( DWORD * )( pbTargetFunction + 6 ) = ( DWORD )( pbDetourFunction - pbTargetFunction ) - 10;
        i = 10;
        break;

    case 5:
        *( WORD * ) ( pbTargetFunction + 0 ) = 0xD233;
        *( WORD * ) ( pbTargetFunction + 2 ) = 0xD285;
        *( WORD * ) ( pbTargetFunction + 4 ) = 0x840F;
        *( DWORD * )( pbTargetFunction + 6 ) = ( DWORD )( pbDetourFunction - pbTargetFunction ) - 10;
        i = 10;
        break;
    }

    for( ; i < intSize; i++ )
        *( BYTE * )( pbTargetFunction + i ) = 0x90;

    VirtualProtect( pbTargetFunction, intSize, dwProtect, &dwProtect );

    return ( pbDetour - intSize );
}
Le Ninja Mode.

Creditos:

@WE11ington
Ótima detour!
Quote Originally Posted by fernandotdb View Post
Ótima detour!
Somente tome cuidado ao pegar um desvio as esquerda, alguém pode não te ver e bater ao seu lado esquerdo.
Onde é o link desse curso de zuera online ?
Quote Originally Posted by experthack View Post
Onde é o link desse curso de zuera online ?
ZueraBRHUE

Coloca no google
Pra calar a boca de muito gringo ai que acham que só eles que sabem criar e que os BR só são C&P, bem que pra criar um desvio/detour requer um bom conhecimento. Nice trabalho @|WE11ington|
Quote Originally Posted by rodrigo19091992 View Post
Detours ja esta detectado :/
Nem todos, com uma edição nessa source ai, já fica funcional, dentre todos ai tem um que funciona ainda...
Quote Originally Posted by kssiobr View Post
Nem todos, com uma edição nessa source ai, já fica funcional, dentre todos ai tem um que funciona ainda...
Fiz algumas alterações (confesso que foi meio na sorte), e todos eles estão funfando.
Posts 1–9 of 9 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

Need help?