Remote Administration Tool Research forumRemote Administration Tool Research forum
  Remote Administration Tool Research forum
Register Social Groups Mark Forums Read

Go Back   Remote Administration Tool Research forum > Programming > Delphi help

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-11-2009, 17:43
counterstrikewi's Avatar
Senior Member
 
Join Date: Apr 2009
Location: Opensc.ws
Posts: 828
counterstrikewi is on a distinguished road
undetecting functions method

is it possible to

implement hooking of certain functions.
harmless goes to harmful

then hook your own functions to change the harmless functions into the harmful ones?

or do i not understand hooking
__________________
|DelphiBasics|
Opensc.ws Village:
εїз ̴̡ı̴̴̡ ̡̡͡|̲̲̲͡͡͡ ̲▫̲͡ ̲̲̲͡͡π̲̲͡͡ ̲̲͡▫̲̲͡͡ | ٩(̾●̮̮̃̾???̃̾)۶ mjrod5 |̲̲̲͡͡͡ ̲▫̲͡ ̲̲̲͡͡π̲̲͡͡ ̲̲͡▫̲̲͡͡ ̲|̡̡̡ ̡ ̴̡ı̴̡̡ ̡͌l̡ ٩(̾̾̾ಠ̮̮̃̾ಠ̃̾)۶ counterstrikewi ̴̡̡̡͡|̲̲̲͡͡͡ ̲▫̲͡ ̲̲̲͡͡π̲̲͡͡ ̲̲͡▫̲̲͡͡ ̲|̡̡̡ ̡
Reply With Quote
  #2 (permalink)  
Old 22-11-2009, 04:13
mjrod5's Avatar
Senior Member
 
Join Date: Aug 2008
Location: FillChar(Location,SizeOf(Location),0);
Posts: 2,183
mjrod5 is on a distinguished road
Well yea you can, but your still gonna need to pass the parameters to the "legit" api call...
__________________
I look up to Krippler, Wez(Protocol), and XoreDev
Reply With Quote
  #3 (permalink)  
Old 23-11-2009, 01:19
Hs32-Idir's Avatar
Senior Member
 
Join Date: Oct 2008
Location: Memory Another Process
Posts: 154
Hs32-Idir is on a distinguished road
you must call external APIs with a hocked api.
Hook the Loadlibrary & GetProcAddress to get for exemple a LoadLibrartNext & GetProcAddressNext , and call others APis with them,

function HsIdirLoadLibrary(lpLibFileName: PChar): HMODULE; stdcall;
begin
Result := NextLoadLibrary(lpLibFileName);
HookNewLibrary(Table,result);
end;

the Hook new library detect if the Api hooked then it change the allocation table.
--- Finally the secret is Changing The Allocation Table.

I have 1 library to do this method in my website you can download it.
you can find it at http://www.Hs32-Idir.110mb.com
__________________
Hs32-Idir
Dreaming in Digital
Living in Realtime
Thinking in Binary
Talking in IP

Welcome to My World
http://www.Hs32-Idir.tk
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
[VB.NET] Useful Functions Chakra Snippets 0 13-09-2009 19:52
Best RAT Functions gangster136 Off-topic 17 02-08-2009 05:07
lttlogger undetecting neropower Delphi help 0 04-04-2009 13:49
"Undetecting" Already Compiled Executables? drizzle Source Code help 14 03-12-2007 19:57
MSN Functions British_Intel VB Samples 6 15-07-2007 15:52


All times are GMT +1. The time now is 05:14.


vBulletin Version is 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.