[WoW][7.3+] What methods of packet sniffing are the safest and actual now? menu

User Tag List

Results 1 to 6 of 6
  1. #1
    BlackRainBow's Avatar Member
    Reputation
    28
    Join Date
    Feb 2014
    Posts
    5
    Thanks G/R
    2/8
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    [WoW][7.3+] What methods of packet sniffing are the safest and actual now?

    Prior to 7.3, I used hardware breakpoints on NetClient::Send2 / NetClient::HandleData (x86).
    Now, as I understand, this is impossible. Or can I hook GetThreadContext or KiUserExceptionDispatcher and everything will be okay? Remap image and inject DLL? Capture packets from network card? Or some other?
    What methods are still actual now, and not just safe, but have the maximum stability?

    [WoW][7.3+] What methods of packet sniffing are the safest and actual now?
  2. #2
    doityourself's Avatar ★ Elder ★
    Reputation
    1424
    Join Date
    Nov 2008
    Posts
    843
    Thanks G/R
    35/448
    Trade Feedback
    0 (0%)
    Mentioned
    6 Post(s)
    Tagged
    0 Thread(s)
    I still inject my dll and just hook both functions since 7.3.0. I'm fine atm

    This doesn't mean, that it's safe! ...
    Last edited by doityourself; 11-12-2017 at 07:37 AM.

  3. Thanks BuloZB, BlackRainBow (2 members gave Thanks to doityourself for this useful post)
  4. #3
    mdX7's Avatar Member Authenticator enabled
    Reputation
    1
    Join Date
    Jul 2017
    Posts
    4
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Capturing packets from nic may be hard because you have to decrypt packets with the session key. It's the safest method tho - you may even do crazy stuff like routing the traffic over another computer and capture packets there (MitM).
    But for now hooking both functions is still working - just like king48488 said.

  5. #4
    Light-Boost's Avatar Member CoreCoins Purchaser
    Reputation
    2
    Join Date
    Jun 2013
    Posts
    18
    Thanks G/R
    0/1
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Here is the old test code (pandaria) to read it from driver using WinDivert lib.WowSniffer.zip

  6. Thanks BlackRainBow (1 members gave Thanks to Light-Boost for this useful post)
  7. #5
    Jadd's Avatar 🐸
    Reputation
    1511
    Join Date
    May 2008
    Posts
    2,432
    Thanks G/R
    81/333
    Trade Feedback
    1 (100%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by king48488 View Post
    I still inject my dll and just hook both functions since 7.3.0. I'm fine atm
    Writing to .text is still undetected? What is even the point to the obfuscation they added in 7.3?

  8. #6
    doityourself's Avatar ★ Elder ★
    Reputation
    1424
    Join Date
    Nov 2008
    Posts
    843
    Thanks G/R
    35/448
    Trade Feedback
    0 (0%)
    Mentioned
    6 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Jadd View Post
    Writing to .text is still undetected? What is even the point to the obfuscation they added in 7.3?
    Its pretty easy for them to detect it and they are also checking if stuff is written to it, but they may ban only bot/hack users. Thats why I‘m waiting for the mext ban wave

Similar Threads

  1. [Selling] Selling wow account with 34 feats of strength ,grunty,deathy 16050 achieve,and more
    By sammyg69 in forum WoW-US Account Buy Sell Trade
    Replies: 0
    Last Post: 12-08-2015, 09:04 PM
  2. Which method of gold trading is the most secured one?
    By Karano in forum World of Warcraft General
    Replies: 0
    Last Post: 10-25-2010, 07:57 AM
  3. Need help after being gone since Summer 08; what are the good core/DBs now?
    By Redviper2321 in forum WoW EMU Questions & Requests
    Replies: 9
    Last Post: 05-11-2009, 06:58 PM
  4. What version of WoW is this?
    By eggylol in forum World of Warcraft General
    Replies: 8
    Last Post: 11-20-2008, 03:52 PM
  5. WHAT VERSIN OF WOW GB or US Does SPARTANSp's REPACK USE?
    By Takahashi in forum World of Warcraft Emulator Servers
    Replies: 2
    Last Post: 03-10-2008, 10:01 PM
All times are GMT -5. The time now is 03:09 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search