Warden Wiki Page menu

User Tag List

Page 3 of 4 FirstFirst 1234 LastLast
Results 31 to 45 of 60
  1. #31
    Namoknan's Avatar Member
    Reputation
    3
    Join Date
    Aug 2007
    Posts
    54
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Xarg0 View Post
    Why does it only work on single core? I tought it changes the way Virtuall Adresses are calculated to physikal ones in the Kernel, so where's the problem with multicore?
    It will probably work, but dual cores work independent from each other. If adress space is accessed at the same time by the cores BSOD is very likely

    Warden Wiki Page
  2. #32
    Cypher's Avatar Kynox's Sister's Pimp
    Reputation
    1358
    Join Date
    Apr 2006
    Posts
    5,368
    Thanks G/R
    0/6
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Xarg0 View Post
    Why does it only work on single core? I tought it changes the way Virtuall Adresses are calculated to physikal ones in the Kernel, so where's the problem with multicore?

    There's a TLB in each core.


    Originally Posted by Namoknan View Post
    In no means I want to attack your theory Cypher, I did not take a look at this specific driver memory modification thingy
    But I guarantee you Ring 0 memory modification is possible on multi core systems. POC can be seen in "Memory Hacking Software by L.Spiro". BSOD is howeva likely, but chances are pretty low
    ....

    I never said it wasn't possible to modify memory from the kernel. I said it wasn't possible to 'cloak' memory modifications in that fashion. Learn to read.

    PS. I 'guarantee' you you're an idiot.


    Originally Posted by Namoknan View Post
    It will probably work, but dual cores work independent from each other. If adress space is accessed at the same time by the cores BSOD is very likely

    No, it won't work.

    Furthermore, the driver only works on x86 and won't work on anything other than XP (2k3 should be a small update, Vista a very large one).

  3. #33
    Jadd's Avatar 🐸 Premium Seller
    Reputation
    1515
    Join Date
    May 2008
    Posts
    2,433
    Thanks G/R
    81/336
    Trade Feedback
    1 (100%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    Why?? Lol.
    Last edited by Jadd; 10-01-2008 at 04:54 AM.

  4. #34
    Cypher's Avatar Kynox's Sister's Pimp
    Reputation
    1358
    Join Date
    Apr 2006
    Posts
    5,368
    Thanks G/R
    0/6
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by JetlagJad View Post
    Why?? Lol.

    Why what??

    Learn to use full sentences.

  5. #35
    Kuiren's Avatar Banned
    Reputation
    611
    Join Date
    Nov 2006
    Posts
    1,118
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Stickied oh wut.

  6. #36
    kynox's Avatar Member
    Reputation
    830
    Join Date
    Dec 2006
    Posts
    888
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Kuiren View Post
    Stickied oh wut.
    Woop wooop woop

  7. #37
    Cypher's Avatar Kynox's Sister's Pimp
    Reputation
    1358
    Join Date
    Apr 2006
    Posts
    5,368
    Thanks G/R
    0/6
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Shoot da whoop.

  8. #38
    Jadd's Avatar 🐸 Premium Seller
    Reputation
    1515
    Join Date
    May 2008
    Posts
    2,433
    Thanks G/R
    81/336
    Trade Feedback
    1 (100%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Cypher View Post

    Why what??

    Learn to use full sentences.

    If you can't understand that, well..

    Eh screw it I know how smart you are, I meant 'why would you make this'.

  9. #39
    Cypher's Avatar Kynox's Sister's Pimp
    Reputation
    1358
    Join Date
    Apr 2006
    Posts
    5,368
    Thanks G/R
    0/6
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by JetlagJad View Post

    If you can't understand that, well..

    Eh screw it I know how smart you are, I meant 'why would you make this'.

    I figured that's what you meant but there are other things it could've been referring too.

    And it was made to show the retards who insist on posting speculation on Warden despite having no idea what they're on about that Warden does not infact go through your pr0n and steal your credit card numbers.

    It also points people in the right direction to bypass Warden.

  10. #40
    Anotherfox's Avatar Contributor
    Reputation
    91
    Join Date
    Apr 2008
    Posts
    222
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0xB93714 0x8 Unknown Login Check (Parental restrictions??) // Cypher
    It's the Blizz Authenticator.

  11. #41
    peachesandcream's Avatar Member
    Reputation
    1
    Join Date
    Feb 2009
    Posts
    5
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I am not a techno person by anymeans but this was very informative

  12. #42
    jagged software's Avatar Member
    Reputation
    -4
    Join Date
    Feb 2009
    Posts
    36
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Very nice as always kynox. Thank you.

  13. #43
    amadmonk's Avatar Active Member
    Reputation
    124
    Join Date
    Apr 2008
    Posts
    772
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    So, you CAN cloak yourself effectively from the kernel (although then you have to hide your driver, but that's a different can of worms; I think there was a BlackHat demo of a completely driverless SSDT hook a while back). You can tweak the memory protection settings on code pages and swap out the thread context in realtime to produce "virtual" hooks, as well as tweaking descriptor mappings and totally owning the exception handling mechanism. You can also do super cool stuff like double-mapping pages and so on, but honestly that doesn't really gain you much (it's just essentially a faster, but more fragile, ReadProcessMemory). Finally, with SSDT hooking you can essentially 100% (ok, 99.9999%) cloak yourself and any other process/window/whatever you care about from non-driver user mode processes. You can put any process/thread you want into its own little virtualized "jail" where it sees nothing but what you want it to see. That's the essence of what my kernel rootkit back in my XP days did. Never got detected, but I had to give it up when I went to Vista...

    That being said, 99% of the rest of what Cypher said is dead-on: it's enormously harder on multi-core boxes (although disabling interrupts at the right point and knowing when to flush the lookasides helps a lot) and very prone to BSOD's at bad times (if you want to go down this route, take my advice; set up a Virtual PC to do your dev work on, or you'll spend all your time rebooting). Most of it is completely impossible (or, at least, as yet impossible) on Vista and esp. Vista 64 due to kernel change.

    Last but not least, it's serious overkill. Warden's algorithms are based off of hashing and signatures. Honestly, if you know enough to write a kernel stealth driver, it's child's play to evade Warden pretty much forever (it's so much easier too, because one mistake doesn't take your whole system down). You can play the kind of paranoid mind-games I play (thanks Cypher for making me wonder what happens if they refresh RVA's from the on-disk image... grr), but tbh you don't need to.

    If you can code, don't use a public bot. That's pretty much all you need to stay off the radar (and I get the impression that Blizzard doesn't really give a crap about lone coders; they care more about the Gliders and WoWRadar's of the world).

  14. #44
    DaemonOnFire's Avatar Banned
    Reputation
    8
    Join Date
    May 2009
    Posts
    82
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by schlumpf View Post
    Isn't everything proof of concept only?
    Right.

    We can not proof what blizz is putting into warden and wow, maybe they just have fun seeing us trying to cloak our hacks.....
    I do not think that a company which earns millions over millions makes a game that can be hacked that easily without any notice of the owners.

  15. #45
    Cypher's Avatar Kynox's Sister's Pimp
    Reputation
    1358
    Join Date
    Apr 2006
    Posts
    5,368
    Thanks G/R
    0/6
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by amadmonk View Post
    So, you CAN cloak yourself effectively from the kernel (although then you have to hide your driver, but that's a different can of worms; I think there was a BlackHat demo of a completely driverless SSDT hook a while back). You can tweak the memory protection settings on code pages and swap out the thread context in realtime to produce "virtual" hooks, as well as tweaking descriptor mappings and totally owning the exception handling mechanism. You can also do super cool stuff like double-mapping pages and so on, but honestly that doesn't really gain you much (it's just essentially a faster, but more fragile, ReadProcessMemory). Finally, with SSDT hooking you can essentially 100% (ok, 99.9999%) cloak yourself and any other process/window/whatever you care about from non-driver user mode processes. You can put any process/thread you want into its own little virtualized "jail" where it sees nothing but what you want it to see. That's the essence of what my kernel rootkit back in my XP days did. Never got detected, but I had to give it up when I went to Vista...

    That being said, 99% of the rest of what Cypher said is dead-on: it's enormously harder on multi-core boxes (although disabling interrupts at the right point and knowing when to flush the lookasides helps a lot) and very prone to BSOD's at bad times (if you want to go down this route, take my advice; set up a Virtual PC to do your dev work on, or you'll spend all your time rebooting). Most of it is completely impossible (or, at least, as yet impossible) on Vista and esp. Vista 64 due to kernel change.

    Last but not least, it's serious overkill. Warden's algorithms are based off of hashing and signatures. Honestly, if you know enough to write a kernel stealth driver, it's child's play to evade Warden pretty much forever (it's so much easier too, because one mistake doesn't take your whole system down). You can play the kind of paranoid mind-games I play (thanks Cypher for making me wonder what happens if they refresh RVA's from the on-disk image... grr), but tbh you don't need to.

    If you can code, don't use a public bot. That's pretty much all you need to stay off the radar (and I get the impression that Blizzard doesn't really give a crap about lone coders; they care more about the Gliders and WoWRadar's of the world).

    Yes you can. But not on x64. PatchGuard will rape your ass. Sure you can bypass patchguard, but its no trivial task.


    Originally Posted by DaemonOnFire View Post
    Right.

    We can not proof what blizz is putting into warden and wow, maybe they just have fun seeing us trying to cloak our hacks.....
    I do not think that a company which earns millions over millions makes a game that can be hacked that easily without any notice of the owners.

    YOU can't. But others can. It's called reverse engineering...

Page 3 of 4 FirstFirst 1234 LastLast

Similar Threads

  1. anti-warden Release #1
    By zhPaul in forum World of Warcraft Bots and Programs
    Replies: 40
    Last Post: 10-21-2006, 01:40 AM
  2. Unpacked The Warden <
    By zhPaul in forum World of Warcraft Bots and Programs
    Replies: 45
    Last Post: 10-13-2006, 05:52 AM
  3. About Warden
    By Sebbe123 in forum World of Warcraft General
    Replies: 1
    Last Post: 09-21-2006, 12:18 PM
  4. Make FireFox Load Pages Faster
    By LightWave in forum Community Chat
    Replies: 4
    Last Post: 08-31-2006, 09:30 PM
  5. Warden
    By Chsz in forum World of Warcraft General
    Replies: 5
    Last Post: 06-19-2006, 10:16 PM
All times are GMT -5. The time now is 01:52 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search