Gerade auf EoN gesehen und hier steht noch nichts davon:
Quote:
|
Originally Posted by Mc God
There appears to be a new module out, which cGuard is catching and shutting down. I would recommend staying off the hacks until Sheppard can't look further into this.
|
Quote:
|
Originally Posted by Sheppard
[Aug/29/2009 - 14:37:09] Diablo II was closed due to unexpected Warden Behavior. Code 2. user32.dll
Poop! Yeah, CGuard fuckin' saved us.
|
Quote:
|
Originally Posted by Sheppard
They didn't update Warden, all they did was activating one of its powerful checks. They do now check for a jump hook in user32.PeekMessageA, if there is a jump hook opcode they will follow it and then checksum a little code portion of it.
|
Quote:
|
Originally Posted by AntiRush
Quote:
|
Originally Posted by SunshineHighway
Any way you could say that in more lay-men's terms pl0x
|
PeekMessage is a win32 function to look at the message queue for a thread. You could hook this call to do your own thing - most commonly this would be done with a jump hook.
Warden is now checking for that jump hook, and if it's there, checking the bit of code that it jumps to, ostensibly comparing the checksum to some known hack.
|
Ich habe 0 Ahnung von threads, functions, jump hooks etc., kann mir wer erklären was da steht?^^ (Bitte nur wenn ihr das auch selber versteht :P Englisch kann ich selber)