冰楓論壇
標題:
TWMS V1.81.3 SendHook (Logger) [CRC] [已測試]
[打印本頁]
作者:
Doem
時間:
2015-7-10 20:18
標題:
TWMS V1.81.3 SendHook (Logger) [CRC] [已測試]
本帖最後由 Doem 於 2015-7-10 20:19 編輯
//TWMS V1.81.3 SendHook (Logger) [CRC]
//Credit to AIRRIDE for Hook method
[ENABLE]
Label(Return)
Alloc(SendHook,128)
GlobalAlloc(Packets,4096)
GlobalAlloc(PacketSize,04)
GlobalAlloc(RetAddress,04)
SendHook:
DB 55 8B EC 6A FF
PUSHAD
MOV EAX,[EBP+08]
PUSH [EBP+04]
POP [RetAddress]
PUSH [EAX+08]
POP [PacketSize]
MOV EAX,[EAX+04]
MOV [Packets],EAX //[Packets] = Pointer of Packets
POPAD
JMP Return
Return:
JMP 00594049+5
00594049:
JMP SendHook
[DISABLE]
00594049:
DB 55 8B EC 6A FF
DeAlloc(SendHook)
DeAlloc(RetAddress)
DeAlloc(Packets)
DeAlloc(PacketSize)
複製代碼
I just updated and rewrote it with foreign informations, not a author!
忘了說! 已確認過某些攔截到的是明碼, 但不保證全部都是明碼喔~
作者:
abc880608
時間:
2015-7-10 20:25
這是什麼...? 看不太懂 小的新手
作者:
wu1ove
時間:
2015-10-3 13:17
這是明文收包
作者:
wu1ove
時間:
2015-10-3 13:18
噢 看錯了 是發包才對
歡迎光臨 冰楓論壇 (https://bingfong.com/)
Powered by 冰楓