OutdatedSource code for Bypassing Hack

Posts 46–60 of 81 · Page 4 of 6
Quote Originally Posted by XxGhostPandaxX View Post
got rules =-=...copy signature....T_T sorry..
haha Panda.. u Know Me right .... Dont say u dont know ~ :P
Quote Originally Posted by HachikoJES View Post


haha Panda.. u Know Me right .... Dont say u dont know ~ :P
who????? i got many friends...
Quote Originally Posted by XxGhostPandaxX View Post
who????? i got many friends...
Remove your fucking signature, the first few words are exactly the same lol
owh man T_T...why so hate...it just singture....T_T
how to use this cod3rin ?
Quote Originally Posted by kokhong99 View Post
how to use this cod3rin ?
use c++ you need reverse engineering of this code
Some important code for bypassing hack
Can you not leech seriously.. What a noob, you disgust me so much. You are just gonna make it patched.
Quote Originally Posted by COD3RIN View Post
Quote Originally Posted by COD3RIN View Post
Quote Originally Posted by COD3RIN View Post
Code:
#include <Windows.h> #include <stdio.h> #include <Psapi.h> td_NtQuerySystemInformation NtQuerySystemInformation = NULL; td_NtQueryObject NtQueryObject = NULL; td_NtDuplicateObject NtDuplicateObject = NULL; BOOL Init() { HMODULE hNtdll = GetModuleHandle(TEXT("ntdll.dll")); if(!hNtdll) return FALSE; NtQuerySystemInformation = (td_NtQuerySystemInformation)GetProcAddress(hNtdll, "NtQuerySystemInformation"); NtQueryObject = (td_NtQueryObject)GetProcAddress(hNtdll, "NtQueryObject"); NtDuplicateObject = (td_NtDuplicateObject)GetProcAddress(hNtdll, "NtDuplicateObject"); return (NtQuerySystemInformation && NtQueryObject && NtDuplicateObject); } BOOL AcquireDebugPrivilege() { HANDLE hToken = NULL; if(!OpenProcessToken(GetCurrentProcess(), TOKEN_ADJUST_PRIVILEGES, &hToken)) return FALSE; BOOL bSuccess = FALSE; TOKEN_PRIVILEGES tp; tp.PrivilegeCount = 1; if(LookupPrivilegeValue(0, SE_DEBUG_NAME, &tp.Privileges[0].Luid)) { tp.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED; if(AdjustTokenPrivileges(hToken, 0, &tp, sizeof(tp), 0, 0)) bSuccess = TRUE; } CloseHandle(hToken); return bSuccess; } BOOL IsProcessFound(DWORD dwProcessId, PSYSTEM_PROCESS_INFORMATION pInfos) { PSYSTEM_PROCESS_INFORMATION pCurrent = pInfos; while(TRUE) { if((DWORD)pCurrent->UniqueProcessId == dwProcessId) return TRUE; if(pCurrent->NextEntryOffset == 0) break; pCurrent = (PSYSTEM_PROCESS_INFORMATION)((DWORD_PTR)pCurrent + pCurrent->NextEntryOffset); } return FALSE; } BOOL DetectHiddenProcesses(PUINT piCount) { if(!piCount) return FALSE; *piCount = 0; // first, we retrieve the process list (this is dirty but the only way) DWORD dwLen = sizeof(SYSTEM_PROCESS_INFORMATION); PSYSTEM_PROCESS_INFORMATION pProcessInfos = (PSYSTEM_PROCESS_INFORMATION)malloc(dwLen); while(pProcessInfos) { NTSTATUS status = NtQuerySystemInformation(SystemProcessInformation, pProcessInfos, dwLen, &dwLen); if(NT_SUCCESS(status)) break; else if(status != STATUS_INFO_LENGTH_MISMATCH) { free(pProcessInfos); return FALSE; } free(pProcessInfos); pProcessInfos = (PSYSTEM_PROCESS_INFORMATION)malloc(dwLen); } if(!pProcessInfos) return FALSE; // secondly, we retreive all open handle dwLen = sizeof(SYSTEM_HANDLE_INFORMATION); PSYSTEM_HANDLE_INFORMATION pHandleInfos = (PSYSTEM_HANDLE_INFORMATION)malloc(dwLen); while(pHandleInfos) { NTSTATUS status = NtQuerySystemInformation(SystemHandleInformation, pHandleInfos, dwLen, &dwLen); if(NT_SUCCESS(status)) break; else if(status != STATUS_INFO_LENGTH_MISMATCH) { free(pHandleInfos); return FALSE; } free(pHandleInfos); pHandleInfos = (PSYSTEM_HANDLE_INFORMATION)malloc(dwLen); } if(!pHandleInfos) return FALSE; // now, we find all handle to a process POBJECT_TYPE_INFORMATION pType = (POBJECT_TYPE_INFORMATION)malloc(4096); if(!pType) { free(pHandleInfos); free(pProcessInfos); return FALSE; } for(ULONG i = 0; i < pHandleInfos->HandleCount; i++) { DWORD dwOwner = pHandleInfos->Handles[i].ProcessId; HANDLE hHandle = (HANDLE)pHandleInfos->Handles[i].Handle; HANDLE hOwner = OpenProcess(PROCESS_DUP_HANDLE, FALSE, dwOwner); if(hOwner == NULL) continue; // we duplicate the handle so we can query it HANDLE hHandleLocal = NULL; NTSTATUS status = NtDuplicateObject(hOwner, hHandle, GetCurrentProcess(), &hHandleLocal, 0, 0, DUPLICATE_SAME_ACCESS | DUPLICATE_SAME_ATTRIBUTES); if(NT_SUCCESS(status)) { // now we query its type status = NtQueryObject(hHandleLocal, ObjectTypeInformation, pType, 4096, NULL); if(NT_SUCCESS(status)) { if(pType->TypeName.Buffer && wcscmp(pType->TypeName.Buffer, L"Process") == 0) { DWORD dwProcessId = GetProcessId(hHandleLocal); // check if the process is not hidden if(!IsProcessFound(dwProcessId, pProcessInfos)) { // hoho here we go wchar_t szProcess[MAX_PATH]; if(GetProcessImageFileNameW(hHandleLocal, szProcess, MAX_PATH) == 0) wcscpy_s(szProcess, L"<Unknown>"); printf("[%0.4d] %ws\n", dwProcessId, szProcess); (*piCount)++; } } } } CloseHandle(hOwner); } free(pType); free(pHandleInfos); free(pProcessInfos); return TRUE; } int main(int argc, char* argv[]) { UINT iHiddenCount = 0; if(!AcquireDebugPrivilege()) { printf("Unable to acquire debug privilege.\n"); return EXIT_FAILURE; } if(!Init()) { printf("Initialization failure.\r\n"); return EXIT_FAILURE; } DetectHiddenProcesses(&iHiddenCount); printf("Found %d hidden process%s.\r\n", iHiddenCount, (iHiddenCount > 1 ? "es" : "")); return EXIT_SUCCESS; }


You need creativity for this code

Credit by: how02

Well he not going to talk when his false
reverse engineering ?
where i can get c++...can u help me..
Quote Originally Posted by panjang5565 View Post
where i can get c++...can u help me..
Google it before that watch first in youtube what is c++ means?
just download it on any torrent trackers or type in google "download c plus plus" )
Build: 0 succeeded, 1 failed, 0 up-to-date, 0 skipped

Did the source code really works?
im newbie, pls teach, thanks
Quote Originally Posted by _Faris View Post
Build: 0 succeeded, 1 failed, 0 up-to-date, 0 skipped

Did the source code really works?
im newbie, pls teach, thanks
First watch in youtube how
btw what prog you use? 2008 or 2010?
Posts 46–60 of 81 · Page 4 of 6
This thread is closed for replies.

Similar Threads

Tags for this Thread

Need help?