[Release] Int HackShield Killer.

09/30/2008 21:41 chibis#31
ya tipps pls :)
09/30/2008 22:21 ShadowHell#32
A = 0 (A ist ausgeschaltet, 1 = An , 0=Aus)
Daraufhin Out = xyz
B= 0 (B ist auch aus!)
Daraufhin Out = xyz

->
Expell


Irgendwie sowas? :D
09/30/2008 22:33 MoepMeep#33
Bringt euch doch eh nix, denkt ihr echt IHR seit fähig int-hs zu killen/disabeln?
Syntex ist dazu in der lage, aber ihr nicht...

ahjo, den post hier schnell lesen, mahatma löscht ihn gleich wieder :>
09/30/2008 22:46 Therawarp#34
MoepMeep lasst sie doch probieren und ja ich denke schon das einige von uns in der lage sind :P
09/30/2008 22:48 lolsen#35
heut wieder bisschen dumm
09/30/2008 22:50 Therawarp#36
Aalso ich habs schon raus ^^ guckt euch mal die dynamic load library an und zieht HackShield.exe durchen dissambler :D
09/30/2008 22:52 Therawarp#37
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x10001c41
timedatestamp.....: 0x48e0bd79 (Mon Sep 29 11:35:21 2008)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1136 0x1200 6.15 ea805fa0c3d4fb8ee20d7fd6b07379f8
.rdata 0x3000 0xb04 0xc00 4.98 d53182a5c288072429b275ecd76378aa
.data 0x4000 0x288b8 0x200 1.91 62549c55c591b063cf31da502e11d411
.rsrc 0x2d000 0x2b0 0x400 5.20 23c8a02e9f7e393e18171bdb8263e565
.reloc 0x2e000 0x458 0x600 4.18 c51aeddc29a012335337b1293b25ad9c

( 3 imports )
> KERNEL32.dll: AllocConsole, SetConsoleTextAttribute, SetConsoleTitleA, GetStdHandle, GetProcAddress, GetModuleFileNameA, GetModuleHandleA, VirtualProtect, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, InterlockedCompareExchange, Sleep, InterlockedExchange, GetCurrentThreadId
> USER32.dll: MessageBoxA
> MSVCR90.dll: _open_osfhandle, _fdopen, __2@YAPAXI@Z, _encode_pointer, _malloc_crt, fprintf, _encoded_null, _decode_pointer, _initterm, _initterm_e, _amsg_exit, _adjust_fdiv, __CppXcptFilter, _crt_debugger_hook, __clean_type_info_names_internal, _unlock, __dllonexit, _lock, _onexit, _except_handler4_common, ___V@YAXPAX@Z, fopen, printf, _beginthread, fflush, __iob_func, strstr, scanf, malloc, sprintf, free, memset

( 0 exports )

die dll

und das der injector

PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4023e0
timedatestamp.....: 0x46891128 (Mon Jul 02 14:52:24 2007)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x8d8e 0x9000 6.56 f063c15e7dfce6e6f207322d71865720
.rdata 0xa000 0x18c4 0x2000 4.13 6ca14782e7e5a809002cc49bfb78051b
.data 0xc000 0x2d34 0x1000 2.68 852b2f19db7f0283891fc2be6e3ae44a
.rsrc 0xf000 0x31c70 0x32000 4.53 c8ea309137b7c22c6cd1d85f97e9dfe0

( 3 imports )
> KERNEL32.dll: GetModuleHandleA, GetTickCount, OpenProcess, GetCurrentProcessId, Process32Next, Process32First, CreateToolhelp32Snapshot, Thread32Next, Thread32First, GetModuleFileNameA, WaitForSingleObject, CreateRemoteThread, GetProcAddress, WriteProcessMemory, VirtualAllocEx, VirtualProtect, LCMapStringA, HeapSize, SetEndOfFile, ReadFile, GetLocaleInfoA, GetCPInfo, GetFileAttributesA, CloseHandle, CreateFileA, CreateMutexA, GetLastError, CreateThread, VirtualFreeEx, Sleep, ExitProcess, GetStartupInfoA, GetCommandLineA, GetVersionExA, HeapFree, TerminateProcess, GetCurrentProcess, QueryPerformanceCounter, GetCurrentThreadId, GetSystemTimeAsFileTime, WriteFile, SetFilePointer, GetStdHandle, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, HeapDestroy, HeapCreate, VirtualFree, GetStringTypeA, MultiByteToWideChar, GetStringTypeW, HeapAlloc, VirtualAlloc, HeapReAlloc, SetStdHandle, FlushFileBuffers, GetSystemInfo, VirtualQuery, LoadLibraryA, RtlUnwind, InterlockedExchange, GetACP, GetOEMCP, LCMapStringW
> USER32.dll: MessageBoxA, DialogBoxParamA, DestroyWindow, EndDialog
> ADVAPI32.dll: LookupPrivilegeValueA, AdjustTokenPrivileges, OpenProcessToken

( 0 exports )
09/30/2008 22:53 MoepMeep#38
@lolsen blubb? Heute mal wieder nen bisschen dumm? :>
09/30/2008 22:59 Therawarp#39
MoepMeep du bist ganz schön Arogant ^^
ich hab hunger ... ich geh was essen
09/30/2008 23:01 MoepMeep#40
Bin ich, was dagegegen? :P

bringste mir was mit? xP
09/30/2008 23:03 Mahatma#41
Quote:
Originally Posted by Therawarp View Post
MoepMeep du bist ganz schön Arogant ^^
ich hab hunger ... ich geh was essen
Quote:
Originally Posted by MoepMeep View Post
Bin ich, was dagegegen? :P

bringste mir was mit? xP
B2T PLS!
wenn ihr chatten wollt schreibt euch pm's oder geht ins offtopic (ansonsten gibts noch icq und msn...)
danke für die aufmerksamkeit...
09/30/2008 23:04 Shalava#42
.reloc 0x2e000 0x458 0x600 4.18 c51aeddc29a012335337b1293b25ad9c

is bei der zweiten ncih vorhanden und die entrypoint-adressen sind verschieden xD .. öööh? und jez xD
09/30/2008 23:05 syntex#43
Quote:
Originally Posted by Therawarp View Post
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x10001c41
timedatestamp.....: 0x48e0bd79 (Mon Sep 29 11:35:21 2008)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1136 0x1200 6.15 ea805fa0c3d4fb8ee20d7fd6b07379f8
.rdata 0x3000 0xb04 0xc00 4.98 d53182a5c288072429b275ecd76378aa
.data 0x4000 0x288b8 0x200 1.91 62549c55c591b063cf31da502e11d411
.rsrc 0x2d000 0x2b0 0x400 5.20 23c8a02e9f7e393e18171bdb8263e565
.reloc 0x2e000 0x458 0x600 4.18 c51aeddc29a012335337b1293b25ad9c

( 3 imports )
> KERNEL32.dll: AllocConsole, SetConsoleTextAttribute, SetConsoleTitleA, GetStdHandle, GetProcAddress, GetModuleFileNameA, GetModuleHandleA, VirtualProtect, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, InterlockedCompareExchange, Sleep, InterlockedExchange, GetCurrentThreadId
> USER32.dll: MessageBoxA
> MSVCR90.dll: _open_osfhandle, _fdopen, __2@YAPAXI@Z, _encode_pointer, _malloc_crt, fprintf, _encoded_null, _decode_pointer, _initterm, _initterm_e, _amsg_exit, _adjust_fdiv, __CppXcptFilter, _crt_debugger_hook, __clean_type_info_names_internal, _unlock, __dllonexit, _lock, _onexit, _except_handler4_common, ___V@YAXPAX@Z, fopen, printf, _beginthread, fflush, __iob_func, strstr, scanf, malloc, sprintf, free, memset

( 0 exports )

die dll

und das der injector

PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4023e0
timedatestamp.....: 0x46891128 (Mon Jul 02 14:52:24 2007)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x8d8e 0x9000 6.56 f063c15e7dfce6e6f207322d71865720
.rdata 0xa000 0x18c4 0x2000 4.13 6ca14782e7e5a809002cc49bfb78051b
.data 0xc000 0x2d34 0x1000 2.68 852b2f19db7f0283891fc2be6e3ae44a
.rsrc 0xf000 0x31c70 0x32000 4.53 c8ea309137b7c22c6cd1d85f97e9dfe0

( 3 imports )
> KERNEL32.dll: GetModuleHandleA, GetTickCount, OpenProcess, GetCurrentProcessId, Process32Next, Process32First, CreateToolhelp32Snapshot, Thread32Next, Thread32First, GetModuleFileNameA, WaitForSingleObject, CreateRemoteThread, GetProcAddress, WriteProcessMemory, VirtualAllocEx, VirtualProtect, LCMapStringA, HeapSize, SetEndOfFile, ReadFile, GetLocaleInfoA, GetCPInfo, GetFileAttributesA, CloseHandle, CreateFileA, CreateMutexA, GetLastError, CreateThread, VirtualFreeEx, Sleep, ExitProcess, GetStartupInfoA, GetCommandLineA, GetVersionExA, HeapFree, TerminateProcess, GetCurrentProcess, QueryPerformanceCounter, GetCurrentThreadId, GetSystemTimeAsFileTime, WriteFile, SetFilePointer, GetStdHandle, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, HeapDestroy, HeapCreate, VirtualFree, GetStringTypeA, MultiByteToWideChar, GetStringTypeW, HeapAlloc, VirtualAlloc, HeapReAlloc, SetStdHandle, FlushFileBuffers, GetSystemInfo, VirtualQuery, LoadLibraryA, RtlUnwind, InterlockedExchange, GetACP, GetOEMCP, LCMapStringW
> USER32.dll: MessageBoxA, DialogBoxParamA, DestroyWindow, EndDialog
> ADVAPI32.dll: LookupPrivilegeValueA, AdjustTokenPrivileges, OpenProcessToken

( 0 exports )
Tut mir leid, aber bringt dir rein garnichts.
10/01/2008 12:03 Therawarp#44
och menno xD aber so ist es besser struckturiert ^^
10/01/2008 17:51 chibis#45
[Only registered and activated users can see links. Click Here To Register...]
"Defeating Hackshield
Disabling Hackshield is pretty easy and means basically hooking/patching the functions "StartServiceW" of the Hackshield class which is an export of EhSvc.dll.
Either its wrapper inside of Engine.dll, or directly in EhSvc.dll. Just do nothing and return - that's all.

However, after doing that MakeGUIDAckMsg() and MakeAckMsg(), both exports of EhSvc.dll will stop working and therefore we can't authenticate with the gameserver anymore.
To solve that issue one way would be to patch all "has hackshield been started" checks in side of those Make..Msg() functions,it will work fine. To understand it , we have to look at how these functions "generate" the authentication answers.[...]"

MakeGuidAckMsg heisst, dass überprüft wird, ob das hackshield läuft. Falls es aus ist, wird man im falle von kal expelled. Man müsste nen patch/prog/dll schreiben, welche hackshield vormacht, dass kal läuft, aber ich glaube ausser ne handvoll leute hier kriegt das keiner hin ...