DarthTon / Blackbone

Windows memory hacking library
MIT License
4.78k stars 1.32k forks source link

Windows 10 Build 9926 #17

Closed navossoc closed 9 years ago

navossoc commented 9 years ago

Hi...

Seems the newer versions from from Windows 10 changed their Major and Minor version.

I can confirm this behavior on Windows 10 Preview x64 Build 9926.

You can confirm the information here: http://www.windowscentral.com/microsoft-confirms-nt-kernel-version-windows-10-will-go-100 http://en.wikipedia.org/wiki/Windows_10#Version_history https://social.msdn.microsoft.com/Forums/windowsdesktop/en-US/6f22c643-7a33-4581-9fbb-5462c1602f8b/windows-10-getversionex?forum=windowssdk

Not sure if this helps, but you can check it later:

// Windows 10, technical preview, build 9926
pData->KExecOpt         = 0x1BF; // same
pData->Protection       = 0x69A;
pData->ObjTable         = 0x418;
pData->VadRoot          = 0x5F8;
pData->NtCreateThdIndex = 0xB2;
pData->NtTermThdIndex   = 0x53; // same
pData->PrevMode         = 0x232; // same
pData->ExitStatus       = 0x6E0;
pData->MiAllocPage      = 0;    // not sure
pData->ExRemoveTable    = 0;    // not sure

Thanks

ghost commented 9 years ago

Yeah. I'm just too lazy to update it :)

tekniqq commented 9 years ago

hey DarthTon are u selling your private injectors

TheDeadCode commented 9 years ago

I don't believe DarthTon has private injectors. You could very very easily make an injector with Blackbone's code. What I did is sign myself the drivers with a code signing certificate and I was done.

tekniqq commented 9 years ago

could u make me one i can pay u

tekniqq commented 9 years ago

added u

ghost commented 9 years ago

No, I'm not making private injectors, and this is not an appropriate place to ask for them.

TheDeadCode commented 9 years ago

@DarthTon What he meant is that he needed an injector not in test mode. Few games refuse to start if windows is in driver test mode, so I compiled him Xenos and Blackbone with my code signing certificate so he can inject with it.

ghost commented 9 years ago

Fixed in 15cee96ccf5e353d46e571ed76ff1e1e864f2150

tekniqq commented 9 years ago

darthton blackbone is detected for arma battleye ban u for it any way to fix it

ghost commented 9 years ago

Rename and rewrite driver to exclude signature scans. Or hide it upon loading.

TheDeadCode commented 9 years ago

It is not detected. BattleEye simple bans everyone in test mode.

tekniqq commented 9 years ago

I wasn't in test mode

tekniqq commented 9 years ago

Darthon is there anyway u could help me out by making a injector for me or make something for me I pay u I don't thivk I should be contacting you this way but it's the only way sorry could I have your skype.

ghost commented 9 years ago

Sorry, but I have neither spare time nor desire to do this now. Maybe later.

tekniqq commented 9 years ago

darthon plz man i pay u alot

tekniqq commented 9 years ago

ur there man to go to ur are the owner of it

TheDeadCode commented 9 years ago

I suggest not pushing luck with DarthTon. You got your answer already.

tekniqq commented 9 years ago

sorry then but business is business if darthon wants to make money

ghost commented 9 years ago

Lol. This is not business if you haven't noticed yet.

tekniqq commented 9 years ago

okay then sorry

tekniqq commented 9 years ago

hey darthon