Packets sniffer menu

User Tag List

Results 1 to 10 of 10
  1. #1
    N1ghtmaree's Avatar Member
    Reputation
    1
    Join Date
    Jul 2010
    Posts
    22
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Packets sniffer

    Thinking to make some...
    Can someone tell me, which functions i can hook to catch already decrypted packets (in both directions)?

    Packets sniffer
  2. #2
    culino's Avatar Banned
    Reputation
    215
    Join Date
    Feb 2010
    Posts
    141
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    ClientConnection::SendPacket
    NetClient::Process

    The first one is scanned by warden, so be careful or use a trial account.

  3. #3
    N1ghtmaree's Avatar Member
    Reputation
    1
    Join Date
    Jul 2010
    Posts
    22
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thanks, as i know warden scans for mem modifying? If I hook without mem modifying, can i keep it safe?

  4. #4
    Batousan's Avatar Corporal
    Reputation
    1
    Join Date
    Oct 2010
    Posts
    32
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    The current iteration of Warden should not be able to tell if you are reading Wow.exe's memory from out of process. If you try to redirect it, write to it, that can be dangerous.

  5. #5
    N1ghtmaree's Avatar Member
    Reputation
    1
    Join Date
    Jul 2010
    Posts
    22
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Can someone help me with NetClient__Process? Which params are passed? Seems no CDataStore (like in SendPacket) is used.

    Hmm... I see a3 is a packet pointer...
    And probably a4 is Len, than what is a2 for?
    Last edited by N1ghtmaree; 03-15-2011 at 05:58 PM.

  6. #6
    serock1's Avatar Member
    Reputation
    2
    Join Date
    Feb 2009
    Posts
    17
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    ecx: service object ptr
    arg1: tick count
    arg2: packet object ptr

    packet object:
    0x00: vtbl
    0x04: buff
    0x08: ref count, maybe
    0x0c: buff_length
    0x10: current_length
    0x14: read/write cursor

  7. #7
    N1ghtmaree's Avatar Member
    Reputation
    1
    Join Date
    Jul 2010
    Posts
    22
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Are you sure in that? Arg2 is ebp+0Ch, right? The structure is wrong anyway than...

  8. #8
    serock1's Avatar Member
    Reputation
    2
    Join Date
    Feb 2009
    Posts
    17
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I am talking about function ".text:00490360 CNetClient__Process proc near", v406.13623. Calling conversation of it is like "ecx->CNetClient__Process(tick_count, packet_ptr, 0)". The callee cleans the stack.

    At least, my tool works fine.

  9. #9
    N1ghtmaree's Avatar Member
    Reputation
    1
    Join Date
    Jul 2010
    Posts
    22
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Yes, but this is what IDA says:
    char __thiscall NetClient__Process(void *this, int a2, int a3, int a4)

  10. #10
    serock1's Avatar Member
    Reputation
    2
    Join Date
    Feb 2009
    Posts
    17
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    IDA is right, there is no conflict. Check around .text:00490A99 please, WoW's code will tell you the truth.

Similar Threads

  1. Looking for packet sniffer
    By danabe in forum WoW Bots Questions & Requests
    Replies: 3
    Last Post: 05-05-2011, 12:38 AM
  2. Working packet sniffers
    By BoogieManTM in forum WoW Memory Editing
    Replies: 10
    Last Post: 05-04-2010, 09:27 PM
  3. Safe to use packet sniffers?
    By nilum in forum World of Warcraft General
    Replies: 0
    Last Post: 06-05-2009, 12:22 PM
  4. Stealing Accounts using a packet sniffer
    By Sealteams in forum WoW Scam Prevention
    Replies: 19
    Last Post: 09-23-2008, 07:46 PM
All times are GMT -5. The time now is 02:21 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search