Giter VIP home page Giter VIP logo

acdrv's Introduction

About ekknod

Researching computer cheats as a hobby, currently more interested about anti-cheating.
I don't pick sides, without cheaters there wouldn't be anti-cheats neither.
In generally i like the cat and mouse game, and excited to see what is going to be the final solution.

Anti-Cheating and cheating are actually the very same thing, both requires same creative mind.
VAC/EAC/Vanguard are good examples of cool anti-cheats, because they are less likely to cause harm for non cheating players.

Memory Access

SubGetVariable - infects DXE bios image with backdoor before boot.
pcileech-wifi - FPGA card looks like a wireless adapter, but hides inside pcileech-fpga researching tool.
smm - modified SMM bios image manipulates CS2 cvar on system sleep mode (see video).
AmdRyzenMasterCheat - remote access tool inside AmdRyzenMaster utility (see video).
SetWindowHookEx - executes vulnerable routines inside CS:GO to enable wallhack.

Mouse Input

logitech-cve - uses logitech virtual driver for mouse input
MouseClassServiceCallbackTrick - spoofs _ReturnAddress() to get through Anti-Cheat hook.
MouseClassServiceCallbackMeme - rewrites mouse callback to completely circuivement Anti-Cheat hook.

General cool projects

efi-monitor - hooking ntoskrnl.exe before launch
acdrv - base (mouse/exception/syscall/swapctx)

Full Software (Actively updated)

ec-guard - Usermode anti-cheat component (mouse input detection)
EC - CS:GO/Apex/CS2 pen-test (EFI/DMA/Kernel/Usermode/Linux/Proton)
drvscan - advanced tool for scanning PE images / PCI devices / input devices / EFI memory tables

acdrv's People

Contributors

ekknod avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar

acdrv's Issues

You're being sneaky. (3)

Juho brother, you really try to avoid me as much as possible and delete my comments on GitHub in the "issue" section but understand that I haven't done anything to you in our last conversation when we more or less established contact again you after some of my questions that concern you and require a normal response you decided to just tell me that you want to delete my personal data but you yourself said that I occupy a large memory space in your brain as you do in mine and now you do so man you are not acting wise and you are not right in this situation.

You know me and you are practically 3 years together on the internet and it's always been good, we even have a lot of habits that we picked up from each other, let's talk on Discord I feel like you might be feeling a little lost too I hope that's true (3)

BSOD

Windows 10 Kernel Version 19041 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Kernel base = 0xfffff80540605000 PsLoadedModuleList = 0xfffff8054122f290
Debug session time: Mon Oct 23 03:42:42.016 2023 (UTC + 8:00)
System Uptime: 0 days 0:02:02.744
[driver.sys] Running
[driver.sys] [System:System][1AD000][FFFFF80540A05EC6] exception was caught
[driver.sys] [System:System][1AD000][FFFFF80540A05EC6] exception was caught
[driver.sys] [System:System][1AD000][FFFFF80540A05EC6] exception was caught
[driver.sys] [System:System][1AD000][FFFFF80540A05EC6] exception was caught
[driver.sys] [System:System][1AD000][FFFFF80540A05EC6] exception was caught
[driver.sys] [System:System][1AD000][FFFFF80540A05EC6] exception was caught
[driver.sys] [System:System][1AD000][FFFFF80540A05EC6] exception was caught
KDTARGET: Refreshing KD connection
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
[driver.sys] [System:System][1AD000][FFFFF805409FDFA0] exception was caught
Break instruction exception - code 80000003 (first chance)

A fatal system error has occurred.

For analysis of this file, run !analyze -v
nt!DbgBreakPointWithStatus:
fffff805`40a05e70 cc int 3
0: kd> k

Child-SP RetAddr Call Site

00 fffff805434bf578 fffff80540b17f02 nt!DbgBreakPointWithStatus
01 fffff805434bf580 fffff80540b178ad nt!KiBugCheckDebugBreak+0x12
02 fffff805434bf5e0 fffff805409fe0a7 nt!KeBugCheck2+0xd0d
03 fffff805434bfcf0 fffff80540a0ff69 nt!KeBugCheckEx+0x107
04 fffff805434bfd30 fffff80540a0ad83 nt!KiBugCheckDispatch+0x69
05 fffff805434bfe70 fffff80540a0be10 nt!KiDoubleFaultAbort+0x2c3
06 fffff805434b2f80 fffff80540a06a96 nt!KiPageFault+0x10
07 fffff805434b3118 fffff8054087b5dd nt!_chkstk+0x36
08 fffff805434b3130 fffff80540a100ac nt!KiDispatchException+0xed
09 fffff805434b32f0 fffff80540a0eda2 nt!KiExceptionDispatch+0x12c
0a fffff805434b34d0 fffff80540a05e95 nt!KiDebugServiceTrap+0x322
0b fffff805434b3668 fffff8054096840b nt!DebugPrint+0x15
0c fffff805434b3670 fffff805409828e0 nt!vDbgPrintExWithPrefixInternal+0x13b
0d fffff805434b3770 fffff8055f1a19da nt!DbgPrintEx+0x30
0e fffff805434b37c0 fffff80540fba216 driver!hooks::exception::KdTrapHook+0x11a [E:\Project\CodeProject\SourceCode\acdrv\main.cpp @ 237]
0f fffff805434b3860 fffff80540fbc81c nt!KdExitDebugger+0x86
10 fffff805434b3890 fffff80540fbdb4f nt!KdpPrint+0x154
11 fffff805434b38e0 fffff8054087ba79 nt!KdpTrap+0x12f
12 fffff805434b3930 fffff8054087b667 nt!KdTrap+0x2d
13 fffff805434b3970 fffff80540a100ac nt!KiDispatchException+0x177
14 fffff805434b4030 fffff80540a0eda2 nt!KiExceptionDispatch+0x12c
15 fffff805434b4210 fffff80540a05e95 nt!KiDebugServiceTrap+0x322
16 fffff805434b43a8 fffff8054096840b nt!DebugPrint+0x15
17 fffff805434b43b0 fffff805409828e0 nt!vDbgPrintExWithPrefixInternal+0x13b
18 fffff805434b44b0 fffff8055f1a19da nt!DbgPrintEx+0x30
19 fffff805434b4500 fffff80540fba216 driver!hooks::exception::KdTrapHook+0x11a [E:\Project\CodeProject\SourceCode\acdrv\main.cpp @ 237]
1a fffff805434b45a0 fffff80540fbc81c nt!KdExitDebugger+0x86
1b fffff805434b45d0 fffff80540fbdb4f nt!KdpPrint+0x154
1c fffff805434b4620 fffff8054087ba79 nt!KdpTrap+0x12f
1d fffff805434b4670 fffff8054087b667 nt!KdTrap+0x2d
1e fffff805434b46b0 fffff80540a100ac nt!KiDispatchException+0x177
1f fffff805434b4d70 fffff80540a0eda2 nt!KiExceptionDispatch+0x12c
20 fffff805434b4f50 fffff80540a05e95 nt!KiDebugServiceTrap+0x322
21 fffff805434b50e8 fffff8054096840b nt!DebugPrint+0x15
22 fffff805434b50f0 fffff805409828e0 nt!vDbgPrintExWithPrefixInternal+0x13b
23 fffff805434b51f0 fffff8055f1a19da nt!DbgPrintEx+0x30
24 fffff805434b5240 fffff80540fba216 driver!hooks::exception::KdTrapHook+0x11a [E:\Project\CodeProject\SourceCode\acdrv\main.cpp @ 237]
25 fffff805434b52e0 fffff80540fbc81c nt!KdExitDebugger+0x86
26 fffff805434b5310 fffff80540fbdb4f nt!KdpPrint+0x154
27 fffff805434b5360 fffff8054087ba79 nt!KdpTrap+0x12f
28 fffff805434b53b0 fffff8054087b667 nt!KdTrap+0x2d
29 fffff805434b53f0 fffff80540a100ac nt!KiDispatchException+0x177
2a fffff805434b5ab0 fffff80540a0eda2 nt!KiExceptionDispatch+0x12c
2b fffff805434b5c90 fffff80540a05e95 nt!KiDebugServiceTrap+0x322
2c fffff805434b5e28 fffff8054096840b nt!DebugPrint+0x15
2d fffff805434b5e30 fffff805409828e0 nt!vDbgPrintExWithPrefixInternal+0x13b
2e fffff805434b5f30 fffff8055f1a19da nt!DbgPrintEx+0x30
2f fffff805434b5f80 fffff80540fba216 driver!hooks::exception::KdTrapHook+0x11a [E:\Project\CodeProject\SourceCode\acdrv\main.cpp @ 237]
30 fffff805434b6020 fffff80540fbc81c nt!KdExitDebugger+0x86
31 fffff805434b6050 fffff80540fbdb4f nt!KdpPrint+0x154
32 fffff805434b60a0 fffff8054087ba79 nt!KdpTrap+0x12f
33 fffff805434b60f0 fffff8054087b667 nt!KdTrap+0x2d
34 fffff805434b6130 fffff80540a100ac nt!KiDispatchException+0x177
35 fffff805434b67f0 fffff80540a0eda2 nt!KiExceptionDispatch+0x12c
36 fffff805434b69d0 fffff80540a05e95 nt!KiDebugServiceTrap+0x322
37 fffff805434b6b68 fffff8054096840b nt!DebugPrint+0x15
38 fffff805434b6b70 fffff805409828e0 nt!vDbgPrintExWithPrefixInternal+0x13b
39 fffff805434b6c70 fffff8055f1a19da nt!DbgPrintEx+0x30
3a fffff805434b6cc0 fffff80540fba216 driver!hooks::exception::KdTrapHook+0x11a [E:\Project\CodeProject\SourceCode\acdrv\main.cpp @ 237]
3b fffff805434b6d60 fffff80540fbc81c nt!KdExitDebugger+0x86
3c fffff805434b6d90 fffff80540fbdb4f nt!KdpPrint+0x154
3d fffff805434b6de0 fffff8054087ba79 nt!KdpTrap+0x12f
3e fffff805434b6e30 fffff8054087b667 nt!KdTrap+0x2d
3f fffff805434b6e70 fffff80540a100ac nt!KiDispatchException+0x177
40 fffff805434b7530 fffff80540a0eda2 nt!KiExceptionDispatch+0x12c
41 fffff805434b7710 fffff80540a05e95 nt!KiDebugServiceTrap+0x322
42 fffff805434b78a8 fffff8054096840b nt!DebugPrint+0x15
43 fffff805434b78b0 fffff805409828e0 nt!vDbgPrintExWithPrefixInternal+0x13b
44 fffff805434b79b0 fffff8055f1a19da nt!DbgPrintEx+0x30
45 fffff805434b7a00 fffff80540fba216 driver!hooks::exception::KdTrapHook+0x11a [E:\Project\CodeProject\SourceCode\acdrv\main.cpp @ 237]
46 fffff805434b7aa0 fffff80540fbc81c nt!KdExitDebugger+0x86
47 fffff805434b7ad0 fffff80540fbdb4f nt!KdpPrint+0x154
48 fffff805434b7b20 fffff8054087ba79 nt!KdpTrap+0x12f
49 fffff805434b7b70 fffff8054087b667 nt!KdTrap+0x2d
4a fffff805434b7bb0 fffff80540405819 nt!KiDispatchException+0x177
4b fffff805434b8270 0000000000000000 0xfffff805`40405819

A call loop occured...

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.