Go Back   GamerzPlanet - For All Your Online Gaming Needs!! > ijji Games > Gunz Online > Gunz Hacks/Bots Discussion

Gunz Hacks/Bots Discussion Gunz Hacks/Bots Discussion only. No begging.


Stupid Question regarding Gunz Hacks

Gunz Hacks/Bots Discussion


Reply
 
Thread Tools Display Modes
Old 10-28-2009, 12:58 PM   #1
lvlyone
Registered User
 
Last Online: 11-20-2009 04:58 PM
Join Date: Oct 2008
Posts: 27
Rep Power: 0
Rep Points: 10
lvlyone is on a distinguished road
Feedback: (0)
Points: 17,904.85
Bank: 0.00
Total Points: 17,904.85
Stupid Question regarding Gunz Hacks

Smart guys,

I would like to know how GameGuard Pattern Detect/Block works.

Suppose that we have Soure Codes of DLL and injector which was already blocked by GameGuard.

If I change a lot of variable and function names, then that might bypass GameGuard Pattern Detect/Block?
If not, how can we bypass that? Should we add and delete more function calls?

Please give me your generosity to explain anything. Thanks a lot.
lvlyone is offline   Reply With Quote
Old 10-28-2009, 01:00 PM   #2
Brandon-Bmx
Gunbound Guardian
 
Brandon-Bmx's Avatar
 
Last Online: Today 12:56 PM
Join Date: Sep 2008
Location: UK
Posts: 1,443
Rep Power: 4
Rep Points: 179
Brandon-Bmx has a spectacular aura aboutBrandon-Bmx has a spectacular aura about
Feedback: (0)
Points: 2,016.35
Bank: 0.00
Total Points: 2,016.35
Lol - shortymant 
Alzheimer's - Crohn's & Colitis - Cystic Fibrosis - Domestic Violence - Fibromyalgia - Leimyosarcoma - Lupus - BronzeSurfer 
Re: Stupid Question regarding Gunz Hacks

Quote:
Originally Posted by lvlyone View Post
Smart guys,

I would like to know how GameGuard Pattern Detect/Block works.

Suppose that we have Soure Codes of DLL and injector which was already blocked by GameGuard.

If I change a lot of variable and function names, then that might bypass GameGuard Pattern Detect/Block?
If not, how can we bypass that? Should we add and delete more function calls?

Please give me your generosity to explain anything. Thanks a lot.
I just renamed stuff to bypass GG's detection.
But there are other methods I suppose, renaming them is probably the easiest way.
__________________

Made by Theminatar
[Only registered and activated users can see links. ]
Brandon-Bmx is online now   Reply With Quote
Old 10-28-2009, 01:10 PM   #3
hitachihex
AHHH Selfish jean
 
hitachihex's Avatar
 
Last Online: 11-20-2009 12:08 PM
Join Date: Dec 2005
Posts: 331
Rep Power: 6
Rep Points: 210
hitachihex has a spectacular aura abouthitachihex has a spectacular aura abouthitachihex has a spectacular aura about
Feedback: (0)
Points: 3,828.20
Bank: 2.00
Total Points: 3,830.20
Male Breast Cancer - Pregnancy Loss - Infant Loss - Sudden Infant Death - chaosmage 
Re: Stupid Question regarding Gunz Hacks

Detection is done via signature automatically gathered\or manually gathered, such as certain blocks of native assembly that would prove to be unique to the hack in question.

Thus, depending on the project's size (the hack) leaving the creator with the job of finding out what parts of code he needs to revamp\change.

Most of the time, a simple change in addition\subtraction does the trick, granted you turn off code optimization, to prevent it from taking the shortest way around.

ex 1:

Code:
int a  = 5;
ex 2:
Code:
int a = 0;
for(a = 0; a < 6; a++);
Tedious? Yes. But assembly output, without compiler optimizations would not be the same.

ex1:
Code:
mov [reg], 5;
ex2:
Code:
mov [reg], 0
__step:
cmp [reg], 5
je __finish;
inc [reg]
jmp __step;
__finish:
hitachihex is offline   Reply With Quote
Old 10-28-2009, 01:11 PM   #4
Aesmade
I am the lizard king
 
Last Online: Today 12:57 PM
Join Date: Jul 2009
Posts: 259
Rep Power: 1
Rep Points: 56
Aesmade will become famous soon enough
Feedback: (0)
Points: 873.88
Bank: 3,040.48
Total Points: 3,914.36
Re: Stupid Question regarding Gunz Hacks

Changing variable and function names would change absolutely nothing in the compiled DLL. So no, that wouldn't work. I've injected DLLs that exit as soon as they're loaded and GG still detected them after a while, so I'm thinking it might detect the DLL module itself. Perhaps a different injection method would work. **** me, I dunno.
Edit ~ Just saw hitachi's post. Could my empty DLL get detected cause of the code visual studio generates? I thought of making a DLL in assembly and injecting that, so it doesn't have any extra crap, but I couldn't be arsed.

Last edited by Aesmade; 10-28-2009 at 01:14 PM.
Aesmade is offline   Reply With Quote
Old 10-28-2009, 04:10 PM   #5
lvlyone
Registered User
 
Last Online: 11-20-2009 04:58 PM
Join Date: Oct 2008
Posts: 27
Rep Power: 0
Rep Points: 10
lvlyone is on a distinguished road
Feedback: (0)
Points: 17,904.85
Bank: 0.00
Total Points: 17,904.85
Re: Stupid Question regarding Gunz Hacks

What if Most of source codes were ASMs?

Then we don't have any options to bypass that signature detection?

:)

Thanks.
lvlyone is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump

All times are GMT -7. The time now is 01:05 PM.

 

Copyright ©2009, GamerzPlanet.Net
Visits: