Dll hook right or no

Results 1 to 7 of 7
  1. #1
    Proficient Member wdevil12 is offline
    MemberRank
    Feb 2007 Join Date
    root[] .xscriptLocation
    153Posts

    smile Dll hook right or no

    okey maybe some can explain me i think write or not.

    Step 01: Yourdll.dll
    Step 02: Start --- What mean this ? i need write somewhere it ?
    Step 03: PUSH DLL-offset (Step 1)
    Step 04: CALL LoadLibraryA
    Step 05: OR EAX,EAX -- I need write it manual ?
    Step 06: JE EntryPoint
    Step 07: PUSH Start-offset (Step 2)
    Step 08: PUSH EAX --- i need write it manual ?
    Step 09: CALL GetProcAddress
    Step 10: CALL EAX --- i need write it manual ?
    Step 11: JE EntryPoint --- you mean jmp Entry ?

    Here images step by step how i do it ? i have some mistakes or all it's ok ?










    Last edited by wdevil12; 05-12-09 at 12:14 AM.


  2. #2
    Account Upgraded | Title Enabled! Annaev is offline
    MemberRank
    Jan 2007 Join Date
    Moldova #Location
    269Posts

    Re: [Help]Dll hook right or no

    isnt right

    ---------- Post added at 05:48 PM ---------- Previous post was at 05:47 PM ----------

    You need to push the procedure address name too

  3. #3
    Proficient Member bastard79 is offline
    MemberRank
    Jan 2005 Join Date
    150Posts

    Re: [Help]Dll hook right or no

    Step 01: Yourdll.dll
    Step 02: Start --- What mean this ? i need write somewhere it ? --- Name of func
    Step 03: PUSH DLL-offset (Step 1)
    Step 04: CALL LoadLibraryA
    Step 05: OR EAX,EAX -- I need write it manual ? --- yes
    Step 06: JE EntryPoint
    Step 07: PUSH Start-offset (Step 2)
    Step 08: PUSH EAX --- i need write it manual ? --- yes
    Step 09: CALL GetProcAddress
    Step 10: CALL EAX --- i need write it manual ? --- yes
    Step 11: JE EntryPoint --- you mean jmp Entry ? --- no, is the entry point offset(when u open with olly is the 1st value(in black) in left column.

    I think XD
    Last edited by bastard79; 05-12-09 at 05:31 PM.

  4. #4
    Proficient Member wdevil12 is offline
    MemberRank
    Feb 2007 Join Date
    root[] .xscriptLocation
    153Posts

    Re: [Help]Dll hook right or no

    Quote Originally Posted by bastard79 View Post
    Step 01: Yourdll.dll
    Step 02: Start --- What mean this ? i need write somewhere it ? --- Name of func
    Step 03: PUSH DLL-offset (Step 1)
    Step 04: CALL LoadLibraryA
    Step 05: OR EAX,EAX -- I need write it manual ? --- yes
    Step 06: JE EntryPoint
    Step 07: PUSH Start-offset (Step 2)
    Step 08: PUSH EAX --- i need write it manual ? --- yes
    Step 09: CALL GetProcAddress
    Step 10: CALL EAX --- i need write it manual ? --- yes
    Step 11: JE EntryPoint --- you mean jmp Entry ? --- no, is the entry point offset(when u open with olly is the 1st value(in black) in left column.

    I think XD
    i dont understand what name i need write in step 2
    if i write press space and write start they dont accept that
    all other process i understand
    Last edited by wdevil12; 06-12-09 at 12:13 AM.

  5. #5
    Proficient Member bastard79 is offline
    MemberRank
    Jan 2005 Join Date
    150Posts

    Re: [Help]Dll hook right or no

    Quote Originally Posted by wdevil12 View Post
    i dont understand what name i need write in step 2
    if i write press space and write start they dont accept that
    all other process i understand


    and what not write ?
    Right click -> follow in dump -> selection

  6. #6
    Account Upgraded | Title Enabled! Annaev is offline
    MemberRank
    Jan 2007 Join Date
    Moldova #Location
    269Posts

    Re: [Help]Dll hook right or no

    First of all, you need to know if your Library have Process Address or not.

    If have ProcAddress
    follow this
    http://forum.ragezone.com/f196/guide...ml#post4803536

    If no have, just your part
    Step 01: Yourdll.dll
    Step 02: Start --- What mean this ? i need write somewhere it ? --- Name of func
    Step 03: PUSH DLL-offset (Step 1)
    Step 04: CALL LoadLibraryA
    Step 05: OR EAX,EAX -- I need write it manual ? --- yes
    Step 06: JE EntryPoint

  7. #7
    Proficient Member wdevil12 is offline
    MemberRank
    Feb 2007 Join Date
    root[] .xscriptLocation
    153Posts

    Re: [Help]Dll hook right or no

    Quote Originally Posted by Annaev View Post
    First of all, you need to know if your Library have Process Address or not.

    If have ProcAddress
    follow this
    http://forum.ragezone.com/f196/guide...ml#post4803536

    If no have, just your part
    Step 01: Yourdll.dll
    Step 02: Start --- What mean this ? i need write somewhere it ? --- Name of func
    Step 03: PUSH DLL-offset (Step 1)
    Step 04: CALL LoadLibraryA
    Step 05: OR EAX,EAX -- I need write it manual ? --- yes
    Step 06: JE EntryPoint
    i have process adress but here have new problem
    0066ffc1
    PUSH 0FF how i can write it they dont accept command like this



Advertisement