LightbulbFarming Code

Posts 1–3 of 3 · Page 1 of 1
Farming Code
So I was thinking of how to solve the problem of how Crossfire detects that you are running a Virtual Machine! Instead of going through all of the code and worrying about the different versions of the vmware and virtualbox software. Can't we just intercept the request that Crossfire makes to in order to find out if it's a computer or not? If so, why don't we just make a universal solution? That way you could be running vmware or virtualbox with whatever version you want, and all you have to do is download the hack and run it so it intercepts the message that Crossfire is requesting. Has anyone though of this?





You're not the first to think this, and it's an obvious thought in the realm of reverse engineering.

Besides HGWC and XTRAP, there's also Themida which serves as an (un)packer and software protection. Themida isn't just a packer, it also adds code that detects debuggers, VMs, and more reverse engineering tools. Sure we can just block the function(s) for VM detection, but themida also detects changes in memory, particularly the code of the application (crossfire.exe code sections), so that also needs to be blocked.

An easier route would be to get a better emulator. VMs are detected because they have flaws, they don't emulate systems with 100% accuracy or provide fully emulated hardware (VMWare installs its own drivers depending on the OS, which is easily detectable). However, there's no good x86 CPU + hardware emulator out there. In fact, most of them are simulators (includes VMWare and Virtual PC) which behave like separate computers rather than fully emulate them.

My possible, and more practical solutions would be one of:
a) Hook the WinAPI to prevent detection of another opened CrossFire
b) Create a virtual client (bot, which would also need HGWC/XTRAP pipeline or emulator)
c) Use/create an accurate EMULATOR. A simple Windows on Windows emulator will do here, no extra hardware/driver emulation needed.
Quote Originally Posted by TrollerCoaster View Post
You're not the first to think this, and it's an obvious thought in the realm of reverse engineering.

Besides HGWC and XTRAP, there's also Themida which serves as an (un)packer and software protection. Themida isn't just a packer, it also adds code that detects debuggers, VMs, and more reverse engineering tools. Sure we can just block the function(s) for VM detection, but themida also detects changes in memory, particularly the code of the application (crossfire.exe code sections), so that also needs to be blocked.

An easier route would be to get a better emulator. VMs are detected because they have flaws, they don't emulate systems with 100% accuracy or provide fully emulated hardware (VMWare installs its own drivers depending on the OS, which is easily detectable). However, there's no good x86 CPU + hardware emulator out there. In fact, most of them are simulators (includes VMWare and Virtual PC) which behave like separate computers rather than fully emulate them.

My possible, and more practical solutions would be one of:
a) Hook the WinAPI to prevent detection of another opened CrossFire
b) Create a virtual client (bot, which would also need HGWC/XTRAP pipeline or emulator)
c) Use/create an accurate EMULATOR. A simple Windows on Windows emulator will do here, no extra hardware/driver emulation needed.
Hmmmmm, I see.......
This is a project I need to start on. If it can be done, I want to a least try it out!
This could be interesting!
Posts 1–3 of 3 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?