- Joined
- Sep 10, 2007
- Messages
- 968
- Reaction score
- 815
These are small examples I've made for my anti-hack, note I did change the addresses and I'm using pre-protected pages. What you may need to do is change it up to fit your executable base. I will not give support on compiling / implementing, but I can help you understand what it does.
Return Address Checking:
Notice: A return address check is not always useful, you can make a naked function and push a fake return address that is inside the code base, then do an unconditional jump to it.
Send Packet:
Notice: This requires a hook on send() to save the socket identifier, so I suggest you do that. If you want to do it from C++ it would basically be this:
Like I said, nothing complex.
I may add more to this as I develop them or I may not.
Return Address Checking:
PHP:
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;;;;;;;;;;;;;;;;Return Address Check;;;;;;;;;;;;;;
;;;;;;;;;;;;;;;;Theoretical - MASM32;;;;;;;;;;;;;;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
.386
include \masm32\include\masm32rt.inc
.code
start:
call ObtainEIP
ObtainEIP:
pop ebp
add ebp, VirtualProtectPointer-ObtainEIP
mov ebx, [ebp] ;EBX = VirtualProtectPointer
mov ecx, [VirtualProtectPointer-FinalCode]
mov eax, [CodeAddress-VirtualProtectPointer]
mov eax, [ebp+4]
push eax
push ecx
push ebx
push 40h
push ecx
push eax
call dword ptr ds:[005E62F4h] ;VirtualProtect
pop ecx
pop eax
lea edi, [eax]
sub ebp, [VirtualProtectPointer-FinalCode]
lea esi,[ebp]
rep movs byte ptr es: [edi], byte ptr ds: [esi]
retn
FinalCode:
push eax
mov [esp+4],eax
pop eax
mov eax, [esp+4]
cmp eax,00640000h
jg HackDetected
cmp eax, 00401000h
jle HackDetected
pop eax
retn
HackDetected:
mov eax, 006A0000h
lea eax, [eax]
PUSH 1
call eax ;Send packet to the server
push 0
CALL DWORD PTR DS:[005E62B4h]
pop eax
retn
VirtualProtectPointer dd 006B0000h
CodeAddress dd 005DEEDFh
end start
Notice: A return address check is not always useful, you can make a naked function and push a fake return address that is inside the code base, then do an unconditional jump to it.
Send Packet:
PHP:
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;;;;;;;;;;;;;;;Hack Checking Packet;;;;;;;;;;;
;;;;;;;;;;;;;;;Theoretical - MASM32;;;;;;;;;;;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
.386
include \masm32\include\masm32rt.inc
.code
start:
call ObtainEIP
ObtainEIP:
pop ebp
add ebp, PacketPointer-ObtainEIP
mov eax, [ebp+4]
mov ecx, PacketPointer-FinalCode
mov edx, [ebp]
push ecx
push edx
push 40h
push 1000h
push ecx
push 0
call dword ptr ds:[eax] ;VirtualAlloc
pop edx
pop ecx
mov [edx],eax
lea edi,[edx]
sub ebp, [PacketPointer-FinalCode]
lea esi,[ebp]
rep movs byte ptr es: [edi], byte ptr ds: [esi]
retn
;;;;;;;;;;;;;;;;;;;Code Executed;;;;;;;;;;;;;;;;;;;;;
FinalCode:
pushad
mov eax, [006F0000h] ;Socket
mov eax,[eax]
mov ebx, [006E0000h]
mov edx, 0FF66h
mov [ebx],edx
mov edx, 0FF6bh
mov [ebx+4],edx
mov edx, 0FFCDh
mov [ebx+8],edx
mov edx, 90FFh
mov [ebx+12],edx
mov ecx, [esp+36]
mov [ebx+14],ecx
push 0
push 32
push ebx
push eax
call dword ptr ds:[005E65C4h]
popad
retn
;;;;;;;;;;;;;;;;;;;Variable Definitions;;;;;;;;;;;;;;
PacketPointer dd 006A0000h
VirtuallAllocAddress dd 005E62ECh
end start
PHP:
int nSocket = 0;
int __cdecl sendDetour (int fd, char *pData, int nSize, int nFlags) {
nSocket = fd;
return sendOriginal (fd, pData, nSize, nFlags);
}
I may add more to this as I develop them or I may not.

