Warden upgrade! Be careful!!! menu

User Tag List

Page 2 of 3 FirstFirst 123 LastLast
Results 16 to 30 of 42
  1. #16
    rocambole's Avatar Member
    Reputation
    7
    Join Date
    Aug 2012
    Posts
    87
    Thanks G/R
    0/1
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    So, VesperCore, based on ur opinion, is PQR safe to use atm?

    Warden upgrade! Be careful!!!
  2. #17
    dadude123's Avatar Private
    Reputation
    1
    Join Date
    Mar 2013
    Posts
    4
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I was ingame for quite some time now and farmed herbs manually, but it seems like I won't get the trigger-opcode for enabling the detection.
    I used page exceptions to track modifications to the function but so far nothing came up. (Also doublechecked with cheatengine)

    Another question:
    For now it seems like lua_loadbuffer is the only function that's being affected by the check.
    But nothing prevents them from adding that check to other functions (like execute buffer) too.
    So wouldn't it make more sense to actually counter their detection somehow (un-hooking / stack-spoofing / calling from codecaves / ...)
    instead of just using another function?

    Ah, and will warden (I'll just call it warden because it's easier) unhook the function again after one call?
    Or does the function remain hooked indefinitely after the trigger?

  3. #18
    -Ryuk-'s Avatar Elite User CoreCoins Purchaser Authenticator enabled
    Reputation
    529
    Join Date
    Nov 2009
    Posts
    1,028
    Thanks G/R
    38/51
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Can anyone confirm if Framescript_LoadBuffer is currently (17055) at 0xD6BF0 (rebased)?

    Since we don't (publicly ) have an ida database that's anywhere near what we had before 5.3, it makes more sense to tell others the function address.
    |Leacher:11/2009|Donor:02/2010|Established Member:09/2010|Contributor:09/2010|Elite:08/2013|

  4. #19
    culino2's Avatar Elite User
    Reputation
    336
    Join Date
    Feb 2013
    Posts
    181
    Thanks G/R
    139/72
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by VesperCore View Post
    Have you been sniffing ? Right ? Anything else is useless. If you have debugged into LoadBuffer, even with the opcode active, you wont see any modification. It's "Load".

    Note: The check is not in LoadBuffer, it's in Lua_Load, and if you see xref, you will see that function is CALLED ONCE in the whole code, so it's MUCH MUCH MUCH more easy for blizzard to have a check in a function like this, with one possible location of calling rather than in LoadBuffer or ExecuteBuffer that are called from thousands of location. Think about the economy of perf, if they wasn't taking care of that, they would have kept warden + this opcode ALWAYS active.

    If you read my first post -again-, you will realize I don't say the check is inside LoadBuffer, but inside "FrameScript_Load".
    I bet they have the tools to auto dump all refs.

  5. #20
    healzzz's Avatar Knight
    Reputation
    5
    Join Date
    Apr 2013
    Posts
    222
    Thanks G/R
    0/0
    Trade Feedback
    3 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    so is pqr "safe"?

  6. #21
    vitalic's Avatar Contributor CoreCoins Purchaser
    Reputation
    182
    Join Date
    Jun 2010
    Posts
    3,527
    Thanks G/R
    8/3
    Trade Feedback
    10 (100%)
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)
    Epic fail from Blizzard. Not putting HONORBUDDY in the packet name might be a good start

  7. #22
    ginuwine12's Avatar Knight-Lieutenant
    Reputation
    6
    Join Date
    Feb 2013
    Posts
    277
    Thanks G/R
    1/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    VesperCore thank you for the infos
    Last edited by ginuwine12; 06-14-2013 at 12:34 PM.

  8. #23
    LiquidAtoR's Avatar Member
    Reputation
    12
    Join Date
    Mar 2009
    Posts
    62
    Thanks G/R
    1/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Reports are coming in on the HB forum about Tripwire being Activated with some users.
    Seems something is going on....

    Reference URL's:

    Tripwire activated. Shutting down Honorbuddy
    [17:50:06.536 N] Tripwire activated. Shutting down Honorbuddy
    Flattery makes friends,
    Truth makes enemies!

  9. #24
    HunterHero's Avatar Legendary
    Reputation
    656
    Join Date
    Jun 2006
    Posts
    879
    Thanks G/R
    150/230
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I have been leveling two characters from 1-90 and pvping to get full malevolent gear within 2 weeks only by botting, about 20 hours a day mostly non stop and i haven't recieved any warning or seen anything suspicious.

  10. #25
    dadude123's Avatar Private
    Reputation
    1
    Join Date
    Mar 2013
    Posts
    4
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    VesperCore, you said the check is "range n+1", I think you mean that the hook checks the complete callstack right?
    If that isn't what you meant then please explain the pharse "n+1.

    Next thing you said that using lua_load / FrameScript_loadbuffer(4D6BF0) isn't safe since the hook is placed inside "lua_load" (D61F0).

    But then you said it would be ok to use "FrameScript_ExecuteBuffer = 0x55347; // good to execute lua".

    But execute buffer also uses lua_load (indirectly) to load the supplied code. So why exactly do you say that this function should be safe?
    They're checking the complete stack anyway or not?

    @HunterHero: I think you're in the wrong section of this forum.

  11. #26
    Neyia's Avatar Active Member Ultimate Rogue PVE CoreCoins Purchaser
    Reputation
    41
    Join Date
    Nov 2012
    Posts
    335
    Thanks G/R
    1/3
    Trade Feedback
    5 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I love tactics blizzard.
    They are all wrong, it's as if they wanted to infiltrate a drug cartel having written "POLICE" on their jackets.
    Super discreet.
    LOL

  12. #27
    dadude123's Avatar Private
    Reputation
    1
    Join Date
    Mar 2013
    Posts
    4
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    @VesperCore:
    Ah now I get it. Thanks for the explanation!

    Originally Posted by Neyia View Post
    I love tactics blizzard.
    They are all wrong, it's as if they wanted to infiltrate a drug cartel having written "POLICE" on their jackets.
    Super discreet.
    LOL
    Flame them all you want. But their idea is good.
    Who knows how long that hook would have remained unknown to us if it weren't for that named network-opcode.
    Imagine them adding another (or even the same) kind of protection at a different address, but this time without telling everyone.
    Then it stops being funny...


    ontopic:
    I really want to analyze the hook and the code behind it in detail.
    But for me the hook-placement just doesn't trigger even though I'm running both of my wow accounts parallel.
    Would be really cool if someone could post a dump of the hooked FrameScript_load and the target it jumps to?
    Last edited by dadude123; 06-14-2013 at 08:40 PM.

  13. #28
    Baelzebub's Avatar Member
    Reputation
    1
    Join Date
    Apr 2007
    Posts
    68
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by VesperCore View Post
    To avoid a detection, you can either have a good anti-warden and keep using it (as the paquet received are really rare... maybe it's done by "if you are online more than 10hours, you receive it", I don't know when they send it exactly, but for sure, not everytime).

    .
    Originally Posted by VesperCore View Post
    Please, get the hell out of here, your post is totally USELESS regarding the thread, I suppose, you did not read any shit of.

    This post is about the recent change inside WoW Client, and have NOTHING to do with how many hour you can bot.
    While i appreciate your knowledge and info your kinda out of line there

  14. #29
    generalsquid's Avatar Master Sergeant
    Reputation
    11
    Join Date
    Oct 2012
    Posts
    88
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Baelzebub View Post
    While i appreciate your knowledge and info your kinda out of line there
    I'm with vesper. I appreciate his frustrations. People join and then read 2 posts of a thread and think they are contributing to discussion by offering up baseless nonsense. It just makes the poster looks stupider than before.

    The people on here who develop and code are smart people who have little tolerance for pretenders and people who they to come off like they know more than they do.
    He's only saying what the rest are thinking.

    Bravo vesper

  15. #30
    RBGBOOSTY's Avatar Member
    Reputation
    3
    Join Date
    Apr 2013
    Posts
    18
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by dadude123 View Post
    Flame them all you want. But their idea is good.
    Who knows how long that hook would have remained unknown to us if it weren't for that named network-opcode.
    Imagine them adding another (or even the same) kind of protection at a different address, but this time without telling everyone.
    Then it stops being funny...
    That is what i exactly tought.They named the Opcode.Maybe they were distracting us? I mean really it cant be that obvious.There is something going on.

Page 2 of 3 FirstFirst 123 LastLast

Similar Threads

  1. Replies: 51
    Last Post: 06-13-2012, 05:59 AM
  2. anti-warden Release #1
    By zhPaul in forum World of Warcraft Bots and Programs
    Replies: 40
    Last Post: 10-21-2006, 01:40 AM
  3. Unpacked The Warden <
    By zhPaul in forum World of Warcraft Bots and Programs
    Replies: 45
    Last Post: 10-13-2006, 05:52 AM
  4. Float in midair (upgraded)
    By miigu in forum World of Warcraft Exploits
    Replies: 1
    Last Post: 06-29-2006, 06:02 PM
  5. Warden
    By Chsz in forum World of Warcraft General
    Replies: 5
    Last Post: 06-19-2006, 10:16 PM
All times are GMT -5. The time now is 07:35 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search