- Joined
- Dec 8, 2013
- Messages
- 911
- Reaction score
- 2
- Points
- 16
- Age
- 21
CShell build: 6-17-20
m_DIPHook : 74 42 8A 09 80 F9 E9 ( Anti DIP Hook Detection )
To Bypass:
Sample Bypass Code of todo_2:
m_DIPHook : 74 42 8A 09 80 F9 E9 ( Anti DIP Hook Detection )
To Bypass:
- todo_1 : Change 74 (JE) to EB (JMP)
- todo_2 : Detour before the JE and jump to neutral code
Sample Bypass Code of todo_2:
Code:
DWORD DETADR = (CSHELL + 0x22CFF0);
DWORD NEUTRALADR = (CSHELL + 0x22D039);
__declspec(naked) void __Bypass_Todo_2()
{
__asm
{
MOV ECX, [EDI+EAX*4]
TEST ECX,ECX
JMP [NEUTRALADR]
}
}
Detour(DETADR,__Bypass_Todo_2);
Last edited by a moderator: