How safe is ExecuteBuffer? menu

User Tag List

Results 1 to 4 of 4
  1. #1
    lgwenOC's Avatar Member
    Reputation
    1
    Join Date
    Mar 2014
    Posts
    2
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    How safe is ExecuteBuffer?

    Hi guys,

    Long time lurker. Sorry to start with a question.

    I wanted to get some opinions on how safe executing LUA using FrameScript_ExecuteBuffer is, at the moment? Particularly on 64bit. I've not had any troubles so far and none of my tools indicate that there is anything to be worried about. But iirc there was a bit of concern earlier in the year.

    Any info would be appreciated

    thanks

    How safe is ExecuteBuffer?
  2. #2
    lolp1's Avatar Site Donator CoreCoins Purchaser
    Reputation
    190
    Join Date
    Feb 2013
    Posts
    210
    Thanks G/R
    43/77
    Trade Feedback
    3 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by lgwenOC View Post
    I wanted to get some opinions on how safe executing LUA using FrameScript_ExecuteBuffer is, at the moment? Particularly on 64bit.
    That depends on exactly how you're doing that. I'd say in a private setting that any reasonable use of it is likely pretty safe, but as always nothing is guaranteed.

    Originally Posted by lgwenOC View Post
    I've not had any troubles so far and none of my tools indicate that there is anything to be worried about. But iirc there was a bit of concern earlier in the year.
    The concern you're referring to is here, I believe:
    http://www.ownedcore.com/forums/worl...hod-added.html (New 32-bit Detection Method Added)

    Originally Posted by lgwenOC View Post
    Any info would be appreciated
    I'm not sure if that check is active or not still, but if it is as the thread says most tools would likely still be safe due to the call stack check did not go back very far, likely due to limitations preventing them to dependably check further back than they did, I would say.

    Regardless, here is some solid information in general for tips on avoiding detection via call stack checks by Darawk:
    Blizzhackers ? View topic - warden thread

  3. #3
    Travelformed's Avatar Member Authenticator enabled
    Reputation
    10
    Join Date
    Jan 2008
    Posts
    13
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    >>Not far back
    is far enough to detect that endscene hook is not in .text

  4. #4
    DarkLinux's Avatar Former Staff
    CoreCoins Purchaser Authenticator enabled
    Reputation
    1584
    Join Date
    May 2010
    Posts
    1,829
    Thanks G/R
    188/531
    Trade Feedback
    16 (100%)
    Mentioned
    6 Post(s)
    Tagged
    0 Thread(s)
    Ya its a tricky one. Could just create a code cave inside the image and when calling create your own stack. Then if they try to read farther up the stack it should crash and if they check the return address its in the .text section of the game. But they could always check the return address and cmp it to a white list on the server. Or do direct calls to NtReadVirtualMemory... You cant really win.
    Last edited by DarkLinux; 11-07-2015 at 07:51 PM.

  5. Thanks Smitten (1 members gave Thanks to DarkLinux for this useful post)

Similar Threads

  1. How safe can AFK gliding get.
    By Deadlyslob in forum World of Warcraft General
    Replies: 0
    Last Post: 04-02-2008, 06:17 AM
  2. How safe a scam would this be?
    By C-Death in forum WoW Scam Prevention
    Replies: 10
    Last Post: 12-03-2007, 11:40 PM
  3. How safe is gliding? and how to keep it safe (a little guide)
    By druidofthenight in forum World of Warcraft Bots and Programs
    Replies: 9
    Last Post: 09-02-2007, 12:55 PM
  4. How safe is Fish buddy?
    By Nightrider in forum World of Warcraft General
    Replies: 4
    Last Post: 08-08-2007, 08:35 AM
  5. how safe are the bots?
    By Krowned in forum World of Warcraft General
    Replies: 11
    Last Post: 05-04-2006, 01:22 AM
All times are GMT -5. The time now is 12:35 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search