Process Protection from Warden (Hash enabler) menu

User Tag List

Page 1 of 2 12 LastLast
Results 1 to 15 of 20
  1. #1
    Skuddle's Avatar Elite User

    CoreCoins Purchaser
    Reputation
    515
    Join Date
    May 2008
    Posts
    287
    Thanks G/R
    4/11
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Process Protection from Warden (Hash enabler)

    It seems someone locally has access to Firesheep and used an exploit against me to hijack my sessions here on mmowned. Nice. Please do not download the software that this guy uploaded. I am talking with Kurious about finding who did it.

    Note to self. Don't use a generic password.

    I apologize for anyone that was affected by this incident.
    Last edited by Skuddle; 05-07-2011 at 10:45 PM. Reason: ADDED info
    Still working :-P

    Process Protection from Warden (Hash enabler)
  2. #2
    2dgreengiant's Avatar ★ Elder ★


    Reputation
    1190
    Join Date
    Feb 2007
    Posts
    7,129
    Thanks G/R
    1/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    If you need me you have my skype, if you don't have my skype then you don't need me.

  3. #3
    Skuddle's Avatar Elite User

    CoreCoins Purchaser
    Reputation
    515
    Join Date
    May 2008
    Posts
    287
    Thanks G/R
    4/11
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    *** There seems to be a bug with people using Windows 7. I am currently looking into it. I don't own a copy of Windows 7 so it may take a day or so.**
    Still working :-P

  4. #4
    matz77's Avatar Corporal
    Reputation
    1
    Join Date
    Feb 2010
    Posts
    18
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Unfourtantly my AV popped saying this was a "trojan" Im providing a screenshot. U trying to infect us man?

    Trojan:win32/Bumat!rts

  5. #5
    lordviper666's Avatar Member
    Reputation
    1
    Join Date
    May 2011
    Posts
    1
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Since this was pulled no need for my input.
    Last edited by lordviper666; 05-07-2011 at 01:00 PM.

  6. #6
    _Mike's Avatar Contributor
    Reputation
    310
    Join Date
    Apr 2008
    Posts
    531
    Thanks G/R
    0/2
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I thought warden didn't scan for processes. Has this changed?

  7. #7
    kryptik's Avatar Member
    Reputation
    4
    Join Date
    Aug 2007
    Posts
    84
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by 2dgreengiant View Post
    At this you can say it is save?
    Yeah, sometime it will give some fail information, but this is full with 32/41 founds.

  8. #8
    Frosttall's Avatar Active Member
    Reputation
    64
    Join Date
    Feb 2011
    Posts
    261
    Thanks G/R
    16/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by kryptik View Post
    At this you can say it is save?
    Yeah, sometime it will give some fail information, but this is full with 32/41 founds.
    Just because it says that there's a found isn't it everytime that it's a real threat.

    For example I've written an updater in C# and AntiVir says now, that it's a Dropper.Gen (Trojaner)..
    And if a moderator says, that it's safe, then is it safe in every regard.

  9. #9
    eSko's Avatar YmxhY2tqYWNrJmhvb2tlcnM= CoreCoins Purchaser Authenticator enabled
    Reputation
    849
    Join Date
    Aug 2006
    Posts
    1,011
    Thanks G/R
    75/24
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I find it hilarious how lazy leecher and 2rep member think that elite member and moderator are trying to infect them with a virus :-D

  10. #10
    Skuddle's Avatar Elite User

    CoreCoins Purchaser
    Reputation
    515
    Join Date
    May 2008
    Posts
    287
    Thanks G/R
    4/11
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by _Mike View Post
    I thought warden didn't scan for processes. Has this changed?

    Warden scans the initial header bytes of each process to ensure there is no linking between WoW and the selected process. Since all dynamic linking happens in the inclusion area of a program, the first byte location will allow you to see if its MS registered or if its a 3rd party . Should it be a 3rd party it will then scan the inclusion that the program is doing, or trace the jumps to see if its memory editing on WoW's ground.
    Still working :-P

  11. #11
    Dispoze's Avatar Master Sergeant
    Reputation
    37
    Join Date
    Jan 2010
    Posts
    100
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Tested the program on ventrilo with the PID 3844. Kept getting:

    Writefile failed; error = 6
    Press enter to hide another process from Warden or 'q' to quit.

    Confirmed Macafee does recognize this as a Trojan.

    +rep

  12. #12
    sed-'s Avatar ★ Elder ★
    Reputation
    1114
    Join Date
    Mar 2010
    Posts
    1,566
    Thanks G/R
    52/151
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    lolz its a false pos, just like when i wrote a simple program that spams E it got flagged 34/41 found it as a trojian//back door? its as simple as use this or dont. He was kind enough and thoughtfull enough to post a usefull program like this public so be thankfull...

    Side note "Threat detected:

    object is infected by Worm.Win32.Agent.dm" lol oh noez! ;p how do i find pids? If i can get an example i will under stand how, like i thought since i use wowext.exe as the pid because thats what showed up in the processes.
    Last edited by sed-; 05-06-2011 at 07:01 PM.

  13. #13
    Neffarian's Avatar Member
    Reputation
    -5
    Join Date
    Sep 2006
    Posts
    53
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Sigh i hate we people say they dont want this to get patched, or people to profit from it.
    Do what GD does and Retard proof your codes...

  14. #14
    kynox's Avatar Account not activated by Email
    Reputation
    830
    Join Date
    Dec 2006
    Posts
    888
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Lets see how many things are wrong with this.

    1) You're completely retarded. If you're going to boast about knowing something, you might wish to actually know something.
    2) This does literally nothing to protect users from Warden, you would know that if you knew what you were doing.
    3) In addition to point 2, this only introduces another obvious thing to detect.

    Bravo, you've released a tool to increase a users chance of being banned by 100%. I'm actually astounded that you even manage to find the 'Compile' button.

    Code:
        puts("SCManager Opened.");
        puts("Creating random hash");
        puts("Random hash made");
    I lol'd.

    If anyone was wondering what he was doing, he implemented a popular and public cloaking method available here: http://quequero.org/Sandbox/Our_first_DKOM

    *Edit*:

    Upon further review, you blatantly copied the code from https://groups.google.com/group/comp...0c9874ff?hl=en - Nice.
    Last edited by kynox; 05-07-2011 at 01:57 AM.

  15. #15
    Cypher's Avatar Kynox's Sister's Pimp
    Reputation
    1356
    Join Date
    Apr 2006
    Posts
    5,368
    Thanks G/R
    0/4
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Hahaha. OP just got pwned.

    EDIT:


    Originally Posted by Skuddle View Post
    Warden scans the initial header bytes of each process to ensure there is no linking between WoW and the selected process. Since all dynamic linking happens in the inclusion area of a program, the first byte location will allow you to see if its MS registered or if its a 3rd party . Should it be a 3rd party it will then scan the inclusion that the program is doing, or trace the jumps to see if its memory editing on WoW's ground.
    Is everything you say complete shit? Or is it just when it comes to Warden and Windows internals.

    Seriously, do you have ANY idea how Warden and/or Windows works?

    IMPORTANT NOTE TO ANYBODY READING THIS:
    This guy is full of shit and has no idea what he's doing. Don't trust this program.
    Last edited by Cypher; 05-07-2011 at 06:49 AM.

Page 1 of 2 12 LastLast

Similar Threads

  1. Get process Id from process name
    By kantaki in forum Programming
    Replies: 2
    Last Post: 10-21-2012, 09:05 AM
  2. [Homemade bot] Protection from warden?
    By Fragmad in forum World of Warcraft Bots and Programs
    Replies: 9
    Last Post: 09-05-2008, 08:04 PM
  3. [Warden] Keep away from Warden
    By Devonia in forum World of Warcraft Bots and Programs
    Replies: 16
    Last Post: 04-12-2008, 12:38 PM
  4. Protect any .exe from Warden using Innerspace!
    By Nonominator in forum World of Warcraft Bots and Programs
    Replies: 13
    Last Post: 05-20-2007, 10:11 PM
All times are GMT -5. The time now is 05:10 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search