[RELASE-Hack Detector]Universal Client Protecter

12/17/2012 08:31 Perfection-#46
Wieso Abfrage xD der Client öffnet doch eh nicht wenn die Datei fehlt.
12/17/2012 09:00 thespeedyy#47
habs mit nem patcher verknüpft das er die datein immer patcht^^
12/17/2012 13:04 [SA]Con#48
Quote:
Originally Posted by .Xero View Post
Wieso Abfrage xD der Client öffnet doch eh nicht wenn die Datei fehlt.
Du hast es wohl nicht verstanden, wie ich das gemeint habe, ist auch egal, er/sie hat es bereits anderst gelöst. ;)
12/17/2012 21:11 LazYGirl.#49
If got any problem : canberk.aslan its my skype.
12/17/2012 22:35 Zwawo#50
Ah okey, you are using EnumProcessModules, but 1 byte changed and the injection detection is gone. Also, manual mapping is a key word :D.

You`re checking for the number of modules, are you? But what is when new modules are loaded due to the ingame itemshop etc?
12/18/2012 19:55 LazYGirl.#51
Quote:
Originally Posted by Zwawo View Post
Ah okey, you are using EnumProcessModules, but 1 byte changed and the injection detection is gone. Also, manual mapping is a key word :D.

You`re checking for the number of modules, are you? But what is when new modules are loaded due to the ingame itemshop etc?
1 byte and gone ?
12/18/2012 20:09 Zwawo#52
Quote:
Originally Posted by LazYGirl. View Post
1 byte and gone ?
jbe -> jmp in memory.
12/18/2012 20:19 LazYGirl.#53
i know it but what's the deal?
its just checking modules and thanks for saying this are you kidding me?
because of you , everyone got the logic.nerd.
12/18/2012 20:27 Zwawo#54
Nope, the people who know what i mean would already know how to bypass it without this post. For the others it helps them a bullshit, because they dont know where etc.
12/18/2012 20:44 LazYGirl.#55
you're right now :D
12/18/2012 21:11 Mi4uric3#56
Quote:
Originally Posted by Zwawo View Post
Nope, the people who know what i mean would already know how to bypass it without this post. For the others it helps them a bullshit, because they dont know where etc.
Totally this.

You "protected" your files with a packer. packer != protector.
So simply unpacking it in less than 20 seconds reveals your "secret" by simply opening it with olly or ida.
And even if you really protected it, in memory it is uncrypted, so one can see the APIs you use.
Everyone who has a little reversing experience can "crack" this..


But b2t, I wouldn't use this because Windows 7 for example loads a dll into the process if the [Only registered and activated users can see links. Click Here To Register...] is displayed after the metin2 client has been started. So the amount of dlls will change if someone starts a program with adminrights after he started your protected Metin2-client.
12/18/2012 21:47 LazYGirl.#57
Quote:
Originally Posted by Mi4uric3 View Post
Totally this.

You "protected" your files with a packer. packer != protector.
So simply unpacking it in less than 20 seconds reveals your "secret" by simply opening it with olly or ida.
And even if you really protected it, in memory it is uncrypted, so one can see the APIs you use.
Everyone who has a little reversing experience can "crack" this..


But b2t, I wouldn't use this because Windows 7 for example loads a dll into the process if the [Only registered and activated users can see links. Click Here To Register...] is displayed after the metin2 client has been started. So the amount of dlls will change if someone starts a program with adminrights after he started your protected Metin2-client.
u right thats why I said encrypt it and its shared one you know i cant edit especially to anyone.I can control admin rights etc.
12/19/2012 20:19 Fever.#58
Thx!
12/19/2012 21:56 niquetamereputain#59
Hello, i've a problem for launching the .exe, I'm running on windows 8
image: [Only registered and activated users can see links. Click Here To Register...]
Thanks
12/20/2012 10:32 WildGamers-Metin2#60
Easy to bypass :)