ReadProcessMemory and detections ? menu

Shout-Out

User Tag List

Results 1 to 4 of 4
  1. #1
    olaxwth's Avatar Private
    Reputation
    31
    Join Date
    Sep 2014
    Posts
    14
    Thanks G/R
    5/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    ReadProcessMemory and detections ?

    Hi guys,

    I just entered myself into the Reverse Engineering world recently and I need to practice.
    I don't really know much about Warden etc, I guess it can do some pattern or signatures scans.
    Do you guys know if it runs on ring0, I don't have the skills to figure it myself?

    What would be the detection rates for a "External Simple Raiding Bot" with no hooking/injection that use theses functions:

    OpenProcess.
    ReadProcessMemory.
    SendMessage (or any functions that push keys without injecting/hooking).

    And if its "detectable" is there any way to protect myself against the warden ? But I imagine it's a lot more harder than making a simple bot and reading memory ^^, I'm a professional software engineer, so my job is to works and levelup on unknown technologies ;D, feel free to PM me if you'r interested to work with me on this.

    Thanks for help and sorry for english non-native

    ReadProcessMemory and detections ?
  2. #2
    namreeb's Avatar Legendary

    Reputation
    668
    Join Date
    Sep 2008
    Posts
    1,029
    Thanks G/R
    8/222
    Trade Feedback
    0 (0%)
    Mentioned
    9 Post(s)
    Tagged
    0 Thread(s)
    Warden does not run in ring0. It is an encrypted dll with the PE headers stripped off that is loaded on request by the server. It runs exclusively within the wow process. Warden does not detect any of the remote process functions you mentioned. It is theoretically possible that they can extend it to detect that, but it is highly unlikely. Warden hasn't changed much since it was first created. It is also possible, and slightly more likely (though still very unlikely overall) that they could add an easter egg into the client to detect this. While I think that that is the most likely scenario, it is also very unlikely.

    TLDR version: it is reasonably safe to use all of those three functions.

  3. Thanks olaxwth (1 members gave Thanks to namreeb for this useful post)
  4. #3
    olaxwth's Avatar Private
    Reputation
    31
    Join Date
    Sep 2014
    Posts
    14
    Thanks G/R
    5/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Nice Thanks for the answer.

    What would be the best way to send keystrokes to the WoWClient ?

  5. #4
    Corthezz's Avatar Elite User Authenticator enabled
    Reputation
    386
    Join Date
    Nov 2011
    Posts
    325
    Thanks G/R
    191/98
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by olaxwth View Post
    Nice Thanks for the answer.

    What would be the best way to send keystrokes to the WoWClient ?
    http://lmgtfy.com/?q=c%23+sending+ke...+other+windows

    http://www.pinvoke.net/default.aspx/user32.sendmessage
    http://www.pinvoke.net/default.aspx/user32.postmessage
    Last edited by Corthezz; 04-16-2016 at 10:28 AM.
    Check my blog: https://zzuks.blogspot.com

Similar Threads

  1. Whats the best botting program for efficiency and detection prevention?
    By Voidshift in forum Diablo 3 Bots Questions & Requests
    Replies: 3
    Last Post: 04-16-2013, 04:34 PM
  2. vb.net ReadProcessMemory and VirtualProtectEx example.
    By abuckau907 in forum Programming
    Replies: 3
    Last Post: 11-29-2012, 12:43 AM
  3. DR Hooks and Detection
    By GliderPro in forum WoW Memory Editing
    Replies: 18
    Last Post: 01-20-2010, 04:37 AM
  4. ReadProcessMemory and thread-safety in general
    By flo8464 in forum WoW Memory Editing
    Replies: 4
    Last Post: 12-14-2009, 08:58 AM
  5. Is MyWarcraftStudio detectable and safe?
    By xlAnonym0uslx in forum World of Warcraft General
    Replies: 3
    Last Post: 08-10-2006, 10:04 PM
All times are GMT -5. The time now is 11:47 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search