[DiscordArchive] But ye, that's the ntdll so by rights couldn't people just do that for the warden module as well ?
[DiscordArchive] But ye, that's the ntdll so by rights couldn't people just do that for the warden module as well ?
Archived author: Fabian • Posted: 2024-06-30T19:06:29.078000+00:00
Original source
Unless you decrypt them statically or at runtime somehow yes
Archived author: _mrfade_ • Posted: 2024-06-30T19:07:58.717000+00:00
Original source
mmm that sounds like a pain, thanks for the info though - I'll dig at it when I get more time.
Archived author: Fabian • Posted: 2024-06-30T19:13:46.740000+00:00
Original source
and again. do not underestimate the full client side of warden that is sending back data, checking things etc. with warden just loaded and without any modules
Archived author: _mrfade_ • Posted: 2024-06-30T19:17:23.174000+00:00
Original source
So this client side warden you talk of, is that also encrypted and loaded at runtime ? Maybe I should be focusing on that to get started
Archived author: Fabian • Posted: 2024-06-30T19:18:16.233000+00:00
Original source
it does not require any special big loading. just an activiation of the base warden form server side to be able to send back the reporting data
Archived author: Fabian • Posted: 2024-06-30T19:18:25.873000+00:00
Original source
however many checks are already executed without that being enabled
Archived author: _mrfade_ • Posted: 2024-06-30T19:20:55.867000+00:00
Original source
mm ye, but is it manually mapped at runtime ? or is it in the static binary.
Also is it encrypted like the modules ?
Archived author: Fabian • Posted: 2024-06-30T19:21:16.857000+00:00
Original source
find it out
Archived author: Fabian • Posted: 2024-06-30T19:21:20.203000+00:00
Original source
<:dracthyr_hehe:1002552775642726450>
Archived author: _mrfade_ • Posted: 2024-06-30T19:21:28.490000+00:00
Original source
Fair lol