Saitamag


SUBMITTED BY: Saitamag

DATE: June 15, 2020, 11:32 p.m.

FORMAT: Text only

SIZE: 3.2 kB

HITS: 412

  1. /*
  2. EasyAntiCheat exploit for Paladins
  3. By Omdihar
  4. */
  5. #include <Windows.h>
  6. #include <string>
  7. #include <process.h>
  8. bool DataCompare(const unsigned char* OpCodes, const unsigned char* Mask, const char* StrMask);
  9. unsigned long FindPattern(unsigned long StartAddress, unsigned long CodeLen, unsigned char* Mask, char* StrMask, unsigned short ignore);
  10. using loadgamewitheac_type = int(__thiscall*)(DWORD*, LPCWSTR, int, char, DWORD*, LPHANDLE);
  11. loadgamewitheac_type loadgamewitheac_orig = nullptr;
  12. using closehandle_type = BOOL(WINAPI*)(HANDLE);
  13. closehandle_type closehandle_orig = nullptr;
  14. HANDLE PaladinsThreadHandle = nullptr;
  15. HANDLE PaladinsHandle = nullptr;
  16. //Hook Functions
  17. BOOL WINAPI closehandle_hook(HANDLE handle)
  18. {
  19. static int count = 0;
  20. if (count == 1)
  21. PaladinsHandle = handle;
  22. ++count;
  23. return true;
  24. }
  25. int __fastcall loadgamewitheac_hook(DWORD *_this, void *edx, LPCWSTR application_name, int a3, char a4, DWORD *process_id_out, LPHANDLE target_handle)
  26. {
  27. //Hook CloseHandle first and remove it after EAC loading
  28. closehandle_orig = (closehandle_type)DetourFunction((PBYTE)CloseHandle, (PBYTE)closehandle_hook);
  29. auto ret = loadgamewitheac_orig(_this, application_name, a3, a4, process_id_out, target_handle);
  30. DetourRemove((PBYTE)closehandle_orig, (PBYTE)closehandle_hook);
  31. //PaladinsHandle access rights == PROCESS_ALL_ACCESS. INJECT CODE HERE
  32. /*DetourContinueProcessWithDllW(PaladinsHandle, L"your_dll_to_inject.dll");*/
  33. return ret;
  34. }
  35. //Threads Function
  36. void __cdecl main_thread(void*)
  37. {
  38. HMODULE eac_module = nullptr;
  39. while (eac_module == nullptr)
  40. {
  41. eac_module = GetModuleHandleW(L"EasyAntiCheat_x86.dll");
  42. Sleep(10);
  43. }
  44. //B8 ?? ?? ?? ?? E8 ?? ?? ?? ?? 81 EC 9C 02 00 00
  45. auto loadeac_addr = FindPattern((DWORD)eac_module, 0xFFFFF, (BYTE*)"\xB8\x00\x00\x00\x00\xE8\x00\x00\x00\x00\x81\xEC\x9C\x02\x00", "x????x????xxxxxx", 0);
  46. if (loadeac_addr == 0)
  47. {
  48. MessageBoxW(nullptr, L"EasyAntiCheat signature broken", L"Bypass Error", MB_TOPMOST);
  49. ExitProcess(-1);
  50. }
  51. loadgamewitheac_orig = (loadgamewitheac_type)DetourFunction((PBYTE)loadeac_addr, (PBYTE)loadgamewitheac_hook);
  52. if (loadgamewitheac_orig == nullptr)
  53. {
  54. MessageBoxW(nullptr, L"EasyAntiCheat signature broken (2)", L"Exploit Error", MB_TOPMOST);
  55. ExitProcess(-1);
  56. }
  57. }
  58. BOOL WINAPI DllMain(_In_ void* _DllHandle, _In_ unsigned long _Reason, _In_opt_ void* _Reserved)
  59. {
  60. if (_Reason == DLL_PROCESS_ATTACH)
  61. {
  62. DisableThreadLibraryCalls((HMODULE)_DllHandle);
  63. _beginthread(main_thread, 0, nullptr);
  64. }
  65. return true;
  66. }
  67. bool DataCompare(const BYTE* OpCodes, const BYTE* Mask, const char* StrMask)
  68. {
  69. while (*StrMask)
  70. {
  71. if (*StrMask == 'x' && *OpCodes != *Mask)
  72. return false;
  73. ++StrMask;
  74. ++OpCodes;
  75. ++Mask;
  76. }
  77. return true;
  78. }
  79. DWORD FindPattern(DWORD StartAddress, DWORD CodeLen, BYTE* Mask, char* StrMask, unsigned short ignore)
  80. {
  81. unsigned short Ign = 0;
  82. DWORD i = 0;
  83. while (Ign <= ignore)
  84. {
  85. if (DataCompare((BYTE*)(StartAddress + i++), Mask, StrMask))
  86. ++Ign;
  87. else if (i >= CodeLen)
  88. return 0;
  89. }
  90. return StartAddress + i - 1;
  91. }

comments powered by Disqus