冰楓論壇

標題: TWMS V1.81.3 SendHook (Logger) [CRC] [已測試] [打印本頁]

作者: Doem    時間: 2015-7-10 20:18
標題: TWMS V1.81.3 SendHook (Logger) [CRC] [已測試]
本帖最後由 Doem 於 2015-7-10 20:19 編輯
  1. //TWMS V1.81.3 SendHook (Logger) [CRC]
  2. //Credit to AIRRIDE for Hook method
  3. [ENABLE]
  4. Label(Return)
  5. Alloc(SendHook,128)
  6. GlobalAlloc(Packets,4096)
  7. GlobalAlloc(PacketSize,04)
  8. GlobalAlloc(RetAddress,04)

  9. SendHook:
  10. DB 55 8B EC 6A FF

  11. PUSHAD
  12. MOV  EAX,[EBP+08]
  13. PUSH [EBP+04]
  14. POP  [RetAddress]
  15. PUSH [EAX+08]
  16. POP  [PacketSize]
  17. MOV  EAX,[EAX+04]
  18. MOV  [Packets],EAX  //[Packets] = Pointer of Packets
  19. POPAD
  20. JMP  Return

  21. Return:
  22. JMP  00594049+5

  23. 00594049:
  24. JMP SendHook
  25. [DISABLE]
  26. 00594049:
  27. DB 55 8B EC 6A FF

  28. DeAlloc(SendHook)
  29. DeAlloc(RetAddress)
  30. DeAlloc(Packets)
  31. DeAlloc(PacketSize)
複製代碼
I just updated and rewrote it with foreign informations, not a author!


忘了說! 已確認過某些攔截到的是明碼, 但不保證全部都是明碼喔~
作者: abc880608    時間: 2015-7-10 20:25
這是什麼...? 看不太懂 小的新手
作者: wu1ove    時間: 2015-10-3 13:17
這是明文收包  
作者: wu1ove    時間: 2015-10-3 13:18
噢 看錯了 是發包才對




歡迎光臨 冰楓論壇 (https://bingfong.com/) Powered by 冰楓