Register for your free account! | Forgot your password?

Go Back   elitepvpers > Shooter > S4 League > S4 League Hacks, Bots, Cheats & Exploits
You last visited: Today at 03:59

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[GUIDE] How to make your hack undetectable

Discussion on [GUIDE] How to make your hack undetectable within the S4 League Hacks, Bots, Cheats & Exploits forum part of the S4 League category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Apr 2010
Posts: 398
Received Thanks: 3,564
[GUIDE] How to make your hack undetectable

This is an advanced guide covering only conceptual stuff for people who already know how to create trainers. It's not the stuff you should completely rely on, but something I figured out for myself by inspecting X-Trap's behavior.

At the moment, X-Trap's detection routine is pretty lame.
  • It has a blacklist of program's it doesn't like to be running.
  • It verifies a checksum of static address space of a protected application (it either does it once or pretty rarely)

Stuff you could try to prevent your hack from being detected:
  • In order to fight the blacklisting, run your trainer with random image name each time. Example: it runs, copies itself into a tempfile, runs the tempfile which patches the memory.
  • X-Trap doesn't like when remote processes mess with its application's address space. Make your code reside in application's address space (injection). Do your modifications in a while after the application starts, so we're sure X-Trap's done with its checks already.
  • Beat blacklisting when using LoadLibrary - make sure the file name is random and and always deallocate the filename string from remote process memory.
  • Advanced: don't inject a DLL, inject the code itself by allocating memory inside the target process. I haven't done this myself (because DLL injection still works and is much easier ), but this will be a bold option when X-Trap detection mechanism improves.

That's all for now; hope UG folks will add some nice advises to my lame assumptions Happy hacking!
Nyamochka is offline  
Thanks
27 Users
Old 05/18/2010, 14:34   #2


 
Al Kappaccino's Avatar
 
elite*gold: 179
Join Date: Oct 2009
Posts: 7,853
Received Thanks: 8,558
Surly helpful.
Al Kappaccino is offline  
Thanks
3 Users
Old 05/18/2010, 14:52   #3
 
elite*gold: 0
Join Date: Sep 2008
Posts: 138
Received Thanks: 9
I think it Helps
Thank you.
HAKAN. is offline  
Thanks
1 User
Old 05/18/2010, 14:56   #4
 
elmomo277's Avatar
 
elite*gold: 2
Join Date: Aug 2009
Posts: 1,159
Received Thanks: 276
Good job! Thank you! (mein 100ster post YEAH)
elmomo277 is offline  
Thanks
1 User
Old 05/18/2010, 15:55   #5
 
Kaisame's Avatar
 
elite*gold: 0
Join Date: May 2009
Posts: 739
Received Thanks: 278
Quote:
Originally Posted by elmomo277 View Post
Er is sowieso nich erster aber auch egal XD
Is klar, aber ab jez haltet euch besser ans Thema (mir inklusive)
Kaisame is offline  
Thanks
1 User
Old 05/18/2010, 18:57   #6
 
elite*gold: 0
Join Date: Jan 2010
Posts: 33
Received Thanks: 1
thx for this guide
jinkaku is offline  
Old 05/19/2010, 10:27   #7
 
elite*gold: 0
Join Date: Aug 2009
Posts: 177
Received Thanks: 37
we hope alastor is reading xD
Chriss09 is offline  
Thanks
1 User
Old 05/19/2010, 10:42   #8
 
elite*gold: 0
Join Date: Apr 2010
Posts: 398
Received Thanks: 3,564
Quote:
Originally Posted by Chriss09 View Post
we hope alastor is reading xD
Alastor should be in school by now

After they've blacklisted me again I can't be sure about anything anymore

I can't find out WHAT they've blacklisted. It's neither the temporary path, nor the .tmp filename... Currently I'm trying to fool it with injecting a DLL residing in System32- let's see if it works.
Nyamochka is offline  
Thanks
2 Users
Old 05/19/2010, 10:58   #9
 
elite*gold: 0
Join Date: Apr 2010
Posts: 129
Received Thanks: 19
Thank You for you help ^^
iPoDDD is offline  
Old 05/19/2010, 13:01   #10
 
Maragon101's Avatar
 
elite*gold: 0
Join Date: Nov 2009
Posts: 664
Received Thanks: 164
Quote:
Originally Posted by iPoDDD View Post
Thank You for you help ^^
is it just me or am i the onley one who gets the feeling that you don't even understand whats going on and try to spamm everywhere you can?
Maragon101 is offline  
Old 05/19/2010, 14:07   #11
 
cmpqz321's Avatar
 
elite*gold: 0
Join Date: Mar 2010
Posts: 119
Received Thanks: 16
thx
cmpqz321 is offline  
Old 05/19/2010, 15:34   #12
 
elite*gold: 0
Join Date: Apr 2010
Posts: 42
Received Thanks: 6
thank you
killerwiller250 is offline  
Old 05/19/2010, 18:52   #13
 
Maragon101's Avatar
 
elite*gold: 0
Join Date: Nov 2009
Posts: 664
Received Thanks: 164
^all this
Lieber thx button drücken als thx zu schreiben das ist spamm.

You should rather klick on the thx button than post "thanks" becouse it's spamm.
Maragon101 is offline  
Old 05/19/2010, 20:15   #14
 
©£¥ňŋ²©'s Avatar
 
elite*gold: 26
Join Date: Nov 2008
Posts: 1,347
Received Thanks: 385
german?
©£¥ňŋ²© is offline  
Old 05/19/2010, 20:19   #15
 
elite*gold: -500
Join Date: May 2010
Posts: 63
Received Thanks: 18
1. thanks its a nice guide
2.

#reportet doublepost
Bummzuabua is offline  
Reply


Similar Threads Similar Threads
Best way to make bots undetectable??
12/19/2006 - World of Warcraft - 3 Replies
What rookit is best for botting in WoW, to prevent warden from detecting it in your process manager. Thanks



All times are GMT +1. The time now is 04:00.


Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2025 elitepvpers All Rights Reserved.