Forums WoW Modding Support Archives TrinityCore Discord Archives [DiscordArchive] But ye, that's the ntdll so by rights couldn't people just do that for the warden module as well ?

[DiscordArchive] But ye, that's the ntdll so by rights couldn't people just do that for the warden module as well ?

[DiscordArchive] But ye, that's the ntdll so by rights couldn't people just do that for the warden module as well ?

Pages (2): 1 2 Next
rektbyfaith
Administrator
0
06-30-2024, 07:01 PM
#1
Archived author: _mrfade_ • Posted: 2024-06-30T19:01:07.695000+00:00
Original source

But ye, that's the ntdll so by rights couldn't people just do that for the warden module as well ?
rektbyfaith
06-30-2024, 07:01 PM #1

Archived author: _mrfade_ • Posted: 2024-06-30T19:01:07.695000+00:00
Original source

But ye, that's the ntdll so by rights couldn't people just do that for the warden module as well ?

rektbyfaith
Administrator
0
06-30-2024, 07:02 PM
#2
Archived author: Warpten • Posted: 2024-06-30T19:02:29.046000+00:00
Original source

writing user code that calls int 2e or syscall is just asking for trouble and also massively complexifies module delivery even with a fingerprinted system
rektbyfaith
06-30-2024, 07:02 PM #2

Archived author: Warpten • Posted: 2024-06-30T19:02:29.046000+00:00
Original source

writing user code that calls int 2e or syscall is just asking for trouble and also massively complexifies module delivery even with a fingerprinted system

rektbyfaith
Administrator
0
06-30-2024, 07:02 PM
#3
Archived author: Warpten • Posted: 2024-06-30T19:02:35.713000+00:00
Original source

not sure what you're trying to say
rektbyfaith
06-30-2024, 07:02 PM #3

Archived author: Warpten • Posted: 2024-06-30T19:02:35.713000+00:00
Original source

not sure what you're trying to say

rektbyfaith
Administrator
0
06-30-2024, 07:03 PM
#4
Archived author: _mrfade_ • Posted: 2024-06-30T19:03:32.689000+00:00
Original source

Sorry I should be more clear, Can you not just dump the warden module at run time that presumably has RX perms as well ? exactly like I did the ntdll ?
rektbyfaith
06-30-2024, 07:03 PM #4

Archived author: _mrfade_ • Posted: 2024-06-30T19:03:32.689000+00:00
Original source

Sorry I should be more clear, Can you not just dump the warden module at run time that presumably has RX perms as well ? exactly like I did the ntdll ?

rektbyfaith
Administrator
0
06-30-2024, 07:03 PM
#5
Archived author: Fabian • Posted: 2024-06-30T19:03:46.977000+00:00
Original source

Their modules actually use own syscalls too<:zuckster:770403425115963392>
rektbyfaith
06-30-2024, 07:03 PM #5

Archived author: Fabian • Posted: 2024-06-30T19:03:46.977000+00:00
Original source

Their modules actually use own syscalls too<:zuckster:770403425115963392>

rektbyfaith
Administrator
0
06-30-2024, 07:04 PM
#6
Archived author: Warpten • Posted: 2024-06-30T19:04:23.939000+00:00
Original source

sure you can, just be wary of trap pages and the game scanning your open windows periodically
rektbyfaith
06-30-2024, 07:04 PM #6

Archived author: Warpten • Posted: 2024-06-30T19:04:23.939000+00:00
Original source

sure you can, just be wary of trap pages and the game scanning your open windows periodically

rektbyfaith
Administrator
0
06-30-2024, 07:04 PM
#7
Archived author: Warpten • Posted: 2024-06-30T19:04:33.632000+00:00
Original source

and whatever else detection/countermeasure they have
rektbyfaith
06-30-2024, 07:04 PM #7

Archived author: Warpten • Posted: 2024-06-30T19:04:33.632000+00:00
Original source

and whatever else detection/countermeasure they have

rektbyfaith
Administrator
0
06-30-2024, 07:05 PM
#8
Archived author: Fabian • Posted: 2024-06-30T19:05:15.981000+00:00
Original source

Another note: modules are encrypted. On call parts get decrypted and reencrypted
rektbyfaith
06-30-2024, 07:05 PM #8

Archived author: Fabian • Posted: 2024-06-30T19:05:15.981000+00:00
Original source

Another note: modules are encrypted. On call parts get decrypted and reencrypted

rektbyfaith
Administrator
0
06-30-2024, 07:05 PM
#9
Archived author: _mrfade_ • Posted: 2024-06-30T19:05:40.051000+00:00
Original source

I mean I really don't care about being banned lol just curious on how it works and what exactly they are collecting.
rektbyfaith
06-30-2024, 07:05 PM #9

Archived author: _mrfade_ • Posted: 2024-06-30T19:05:40.051000+00:00
Original source

I mean I really don't care about being banned lol just curious on how it works and what exactly they are collecting.

rektbyfaith
Administrator
0
06-30-2024, 07:05 PM
#10
Archived author: _mrfade_ • Posted: 2024-06-30T19:05:58.360000+00:00
Original source

mm so dumping it from memory would be pretty useless then ?
rektbyfaith
06-30-2024, 07:05 PM #10

Archived author: _mrfade_ • Posted: 2024-06-30T19:05:58.360000+00:00
Original source

mm so dumping it from memory would be pretty useless then ?

Pages (2): 1 2 Next
Recently Browsing
 1 Guest(s)
Recently Browsing
 1 Guest(s)