26 Commits

Author SHA1 Message Date
ac67488255 v2.0.1 2023-08-03 09:08:29 +03:00
1375549216 Add support for 3rd 3.8.0 glb/sea/tw/kr/jp 2023-08-03 09:07:18 +03:00
19056bed0d Update 3rd tables to 3.8.0 2023-08-03 09:04:04 +03:00
8dfe04d005 v2.0.0 2023-08-03 08:35:18 +03:00
6bdb04a925 Document newly supported HI3 regions 2023-08-03 00:09:47 +03:00
9ccde2618b Update metadata.json with new HI3 regions 2023-08-03 00:02:35 +03:00
ce58ec89ef Implement multiregion support for 3rd 2023-08-02 23:32:12 +03:00
5b1ac8533d Add tables for 3rd sea/cn/tw/kr/jp 2023-08-02 23:17:35 +03:00
e554c8e57b Major core rewrite 2023-08-02 18:32:26 +03:00
be445e6db9 Fix _create_driver_file error message 2023-08-02 02:29:18 +03:00
6279bb573d Make _load_module_patched function static 2023-08-02 02:24:39 +03:00
eb38894de5 Refactor ace.c 2023-08-02 01:42:04 +03:00
2612ad2212 Only store the name of the game assembly 2023-08-02 01:39:39 +03:00
b3f64ba6f6 v1.1.13 2023-07-31 15:13:59 +03:00
dd15dc60e3 Remove I_WANT_A_BAN requirement 2023-07-30 00:50:04 +03:00
ac68448cbd Mark HSR as verified 2023-07-30 00:38:31 +03:00
80c817cb6b Renamed tp6.c to core.c 2023-07-28 01:51:04 +03:00
4e614e1d82 v1.1.12 2023-07-19 01:17:44 +03:00
8b9f8e68aa Change HSR version to v1.2.0 2023-07-17 23:57:58 +03:00
99c0c20a3d Add tables for SR v1.2.0 2023-07-17 23:56:37 +03:00
64a25b1607 Update checksums for SR 1.2.0 2023-07-17 23:56:37 +03:00
43e8adaf12 Change SR status to "unverified" from "unsafe" 2023-07-17 23:54:47 +03:00
0004c26d7a Recover the executable memory to it's original state 2023-07-16 17:29:06 +03:00
848ae06792 Write recovery data into the inject allocation 2023-07-16 14:58:18 +03:00
c979c980c1 v1.1.11 2023-07-09 00:03:31 +03:00
3d943b641b Fix additional issue introduced by previous rework 2023-07-09 00:01:48 +03:00
32 changed files with 308 additions and 132 deletions

2
.gitignore vendored
View File

@ -3,7 +3,7 @@
.directory .directory
# File withheld to make abuse more difficult # File withheld to make abuse more difficult
game_payload/src/tp6.c game_payload/src/core.c
build build
out out

View File

@ -1,6 +1,6 @@
### Games and regions ### Games and regions
- **3rd**: glb v6.7.0 - **3rd**: glb/sea/cn/tw/kr/jp v6.8.0
- **SR**: os/cn v1.1.0 (unsafe, refer to [configuration](#configuration)) - **SR**: os/cn v1.2.0 (potentially unsafe, but no bans were reported since v1.1.0)
It may be possilbe to completely remove the region and version-specific data in the future. Refer to the source code in `game_payload/src` for details. It may be possilbe to completely remove the region and version-specific data in the future. Refer to the source code in `game_payload/src` for details.
@ -37,7 +37,6 @@ These environment variables can be used to configure the behaviour of the tool.
- `WAIT_BEFORE_RESUME=1` - show a messagebox and wait for user input before resuming the game process. Useful on my side for debugging - `WAIT_BEFORE_RESUME=1` - show a messagebox and wait for user input before resuming the game process. Useful on my side for debugging
**SR-exclusive**: **SR-exclusive**:
- `I_WANT_A_BAN=1` - allows to launch SR. Please only use testing accounts, as there is an extremely high risk of getting banned
- `SRFIX_DISABLE=1` - disable shared resources fix. Not recommended. Doing so will most likely cause the game to not run at all - `SRFIX_DISABLE=1` - disable shared resources fix. Not recommended. Doing so will most likely cause the game to not run at all
### Internals ### Internals
@ -45,7 +44,7 @@ This tool consists of three parts: the main injector (`injector/src/exe.c`), the
I am very bad at explaining, so just take a look at the source code. Maybe I'll write a detailed explanation in the future. I am very bad at explaining, so just take a look at the source code. Maybe I'll write a detailed explanation in the future.
A part of the source code is witheld (`game_payload/src/tp6.c`). This is a forced measure to make abuse more difficult. However, a precompiled blob is provided in the repo. `build.sh` will use it automatically. A part of the source code is witheld (`game_payload/src/core.c`). This is a forced measure to make abuse more difficult. However, a precompiled blob is provided in the repo. `build.sh` will use it automatically.
### Guildelines ### Guildelines
1. **Please don't share this project in public.** This might attract unnecessary attention from either the Game Company or the Anticheat Company 1. **Please don't share this project in public.** This might attract unnecessary attention from either the Game Company or the Anticheat Company

BIN
game_payload/blob/core.o Normal file

Binary file not shown.

Binary file not shown.

View File

@ -0,0 +1,7 @@
#pragma once
#include <windows.h>
#include <game.h>
void core_setup_patcher(struct game_data *game, HMODULE baseModule);

View File

@ -6,6 +6,11 @@ enum game_id {
GAME_INVALID, GAME_INVALID,
GAME_HI3_GLB, GAME_HI3_GLB,
GAME_HI3_SEA,
GAME_HI3_CN,
GAME_HI3_TW,
GAME_HI3_KR,
GAME_HI3_JP,
GAME_HSR_OS, GAME_HSR_OS,
GAME_HSR_CN GAME_HSR_CN
@ -18,7 +23,7 @@ typedef void (*unityplayer_callback_t)(HMODULE unityModule);
struct game_data { struct game_data {
enum game_id id; // Temporary enum game_id id; // Temporary
const char *name; const char *name;
const char *assembly_path; const char *assembly_name;
const char *tp6_section_name; // Unused for now const char *tp6_section_name; // Unused for now
const char *tvm_section_name; const char *tvm_section_name;

View File

@ -1,7 +0,0 @@
#pragma once
#include <windows.h>
#include <game.h>
void tp6_setup_patcher(struct game_data *game, HMODULE baseModule);

View File

@ -15,13 +15,15 @@ sources = [
'src/msg.c' 'src/msg.c'
] ]
resources = [ resources = [
'res/hi3/glb/allocations.dat', 'res/hi3/glb.dat',
'res/hi3/glb/entries.dat', 'res/hi3/sea.dat',
'res/hi3/cn.dat',
'res/hi3/tw.dat',
'res/hi3/kr.dat',
'res/hi3/jp.dat',
'res/hsr/os/allocations.dat', 'res/hsr/os.dat',
'res/hsr/os/entries.dat', 'res/hsr/cn.dat'
'res/hsr/cn/allocations.dat',
'res/hsr/cn/entries.dat'
] ]
# Generate resource files for ./res # Generate resource files for ./res
@ -38,34 +40,34 @@ res_object = custom_target(
command: [ gen_res, '--object', meson.current_source_dir(), '@OUTPUT0@', '@INPUT@' ] command: [ gen_res, '--object', meson.current_source_dir(), '@OUTPUT0@', '@INPUT@' ]
) )
if fs.exists('src/tp6.c') if fs.exists('src/core.c')
# Compile the real file first (dirty hack) # Compile the real file first (dirty hack)
tp6c_fake_exe = executable( core_fake_exe = executable(
'tp6c.o', 'core.o',
'src/tp6.c', 'src/core.c',
res_header, res_header,
link_args: [ '-r' ], # Output an object file link_args: [ '-r' ], # Output an object file
include_directories: include_dir include_directories: include_dir
) )
# another dirty hack # another dirty hack
copy_tp6c = find_program('copy_tp6c.sh') copy_core = find_program('copy_core.sh')
tp6c_target = [custom_target( core_target = [custom_target(
'copy_tp6c', 'copy_core',
output: 'tp6c.o', output: 'core.o',
input: tp6c_fake_exe.extract_all_objects(recursive: false), input: core_fake_exe.extract_all_objects(recursive: false),
command: [ command: [
copy_tp6c, copy_core,
'@INPUT0@', '@INPUT0@',
'@OUTPUT0@', meson.current_source_dir() / 'blob/tp6c.o' '@OUTPUT0@', meson.current_source_dir() / 'blob/core.o'
] ]
)] )]
tp6c_blob = [] core_blob = []
else else
message('Using precompiled tp6c blob. Refer to the readme for more details') message('Using precompiled core blob. Refer to the readme for more details')
tp6c_target = [] core_target = []
tp6c_blob = [ 'blob/tp6c.o' ] core_blob = [ 'blob/core.o' ]
endif endif
shared_library( shared_library(
@ -73,8 +75,8 @@ shared_library(
sources, sources,
res_header, res_header,
res_object, res_object,
tp6c_target, core_target,
objects: tp6c_blob, objects: core_blob,
include_directories: include_dir, include_directories: include_dir,
name_prefix: '' name_prefix: ''
) )

BIN
game_payload/res/hi3/cn.dat Normal file

Binary file not shown.

Binary file not shown.

Binary file not shown.

BIN
game_payload/res/hi3/jp.dat Normal file

Binary file not shown.

BIN
game_payload/res/hi3/kr.dat Normal file

Binary file not shown.

Binary file not shown.

BIN
game_payload/res/hi3/tw.dat Normal file

Binary file not shown.

BIN
game_payload/res/hsr/cn.dat Normal file

Binary file not shown.

Binary file not shown.

BIN
game_payload/res/hsr/os.dat Normal file

Binary file not shown.

Binary file not shown.

View File

@ -9,83 +9,75 @@ static void _dll_notification(ULONG reason, const PLDR_DLL_NOTIFICATION_DATA dat
return; return;
} }
// context should be set to the target module name, lowercase // context should be set to the target module name
wchar_t *targetModuleName = (wchar_t*)context; wchar_t *targetModuleName = (wchar_t*)context;
wchar_t lwModuleName[MAX_PATH]; if (wcsicmp(targetModuleName, data->Loaded.BaseDllName->Buffer) != 0) {
wcscpy(lwModuleName, data->Loaded.BaseDllName->Buffer); return;
_wcslwr(lwModuleName);
if (wcscmp(targetModuleName, lwModuleName) == 0) {
// Replace entry point with a stub
void *entryPoint = pe_find_entry_point(data->Loaded.DllBase);
const char ENTRY_POINT_STUB[] = {
0xB8, 0x01, 0x00, 0x00, 0x00, // mov eax, 1
0xC3 // ret
};
DWORD oldProtect;
VirtualProtect(entryPoint, sizeof(ENTRY_POINT_STUB), PAGE_EXECUTE_READWRITE, &oldProtect);
memcpy(entryPoint, ENTRY_POINT_STUB, sizeof(ENTRY_POINT_STUB));
VirtualProtect(entryPoint, sizeof(ENTRY_POINT_STUB), oldProtect, &oldProtect);
} }
// Replace entry point with a stub
void *entryPoint = pe_find_entry_point(data->Loaded.DllBase);
const char ENTRY_POINT_STUB[] = {
0xB8, 0x01, 0x00, 0x00, 0x00, // mov eax, 1
0xC3 // ret
};
DWORD oldProtect;
VirtualProtect(entryPoint, sizeof(ENTRY_POINT_STUB), PAGE_EXECUTE_READWRITE, &oldProtect);
memcpy(entryPoint, ENTRY_POINT_STUB, sizeof(ENTRY_POINT_STUB));
VirtualProtect(entryPoint, sizeof(ENTRY_POINT_STUB), oldProtect, &oldProtect);
}
static void _create_driver_file(const char *path) {
// They only report presence
HANDLE file = CreateFileA(path, GENERIC_WRITE, FILE_SHARE_READ, NULL, CREATE_ALWAYS, FILE_ATTRIBUTE_NORMAL, NULL);
if (file == INVALID_HANDLE_VALUE) {
msg_err_a("Could not create driver file: %s", path);
}
CloseHandle(file);
} }
void ace_fake_driver_files() { void ace_fake_driver_files() {
// They only report presence _create_driver_file("ACE-BASE.sys");
const char *wdDriverPath = "ACE-BASE.sys";
const char *s32DriverPath = "C:\\windows\\system32\\drivers\\ACE-BASE.sys";
HANDLE wdDriverFile = CreateFileA(wdDriverPath, GENERIC_WRITE, FILE_SHARE_READ, NULL, CREATE_ALWAYS, FILE_ATTRIBUTE_NORMAL, NULL);
if (!wdDriverFile) {
msg_err_a("Could not create driver file: %s", wdDriverPath);
}
// Just in case // Just in case
HANDLE s32DriverFile = CreateFileA(s32DriverPath, GENERIC_WRITE, FILE_SHARE_READ, NULL, CREATE_ALWAYS, FILE_ATTRIBUTE_NORMAL, NULL); _create_driver_file("C:\\windows\\system32\\drivers\\ACE-BASE.sys");
if (!s32DriverFile) { }
msg_err_a("Could not create driver file: %s", s32DriverPath);
static HMODULE _load_module_patched(wchar_t *path) {
// Get filename from the path
wchar_t *name = wcsrchr(path, '\\');
name = name ? name + 1 : path;
void *cookie;
LdrRegisterDllNotification(0, &_dll_notification, name, &cookie);
HMODULE module = LoadLibraryW(path);
if (!module) {
msg_err_w(L"Could not load module: %ls", path);
} }
CloseHandle(wdDriverFile); // LoadLibraryW is synchronous; the notification function has already finished executing
CloseHandle(s32DriverFile); LdrUnregisterDllNotification(cookie);
return module;
} }
HMODULE ace_load_base_module(const char *exeName) { HMODULE ace_load_base_module(const char *exeName) {
wchar_t baseModuleName[MAX_PATH]; wchar_t baseModuleName[MAX_PATH];
swprintf(baseModuleName, MAX_PATH, L"%sbase.dll", exeName); swprintf(baseModuleName, MAX_PATH, L"%sBase.dll", exeName);
wcslwr(baseModuleName); wcslwr(baseModuleName);
void *cookie; return _load_module_patched(baseModuleName);
LdrRegisterDllNotification(0, &_dll_notification, baseModuleName, &cookie);
HMODULE baseModule = LoadLibraryW(baseModuleName);
if (!baseModule) {
msg_err_w(L"Could not load base module: %ls", baseModuleName);
}
// LoadLibraryA is synchronous; the notification function has already finished executing
LdrUnregisterDllNotification(cookie);
return baseModule;
} }
HMODULE ace_load_driver_module() { HMODULE ace_load_driver_module() {
const char *driverModulePath = "AntiCheatExpert/InGame/x64/ACE-DRV64.dll"; return _load_module_patched(L"AntiCheatExpert\\InGame\\x64\\ACE-DRV64.dll");
void *cookie;
LdrRegisterDllNotification(0, &_dll_notification, L"ace-drv64.dll", &cookie);
HMODULE driverModule = LoadLibraryA(driverModulePath);
if (!driverModule) {
msg_err_a("Could not load driver module: %s", driverModulePath);
}
// LoadLibraryA is synchronous; the notification function has already finished executing
LdrUnregisterDllNotification(cookie);
return driverModule;
} }

View File

@ -9,3 +9,10 @@
### 1.1.10 ### 1.1.10
- Fixed a subtle bug introduced in 1.1.9 - Fixed a subtle bug introduced in 1.1.9
### 1.1.11
- Fixed an additional issue introduced in 1.1.9
### 2.0.0
- Almost a full rewrite, functionality unchanged
- Added support for HI3 sea/cn/tw/jp/kr

View File

@ -4,7 +4,7 @@
#include <game.h> #include <game.h>
const char *HI3_NAME = "BH3"; const char *HI3_NAME = "BH3";
const char *HI3_ASSEMBLY_PATH = "BH3_Data/Native/UserAssembly.dll"; const char *HI3_ASSEMBLY_NAME = "UserAssembly.dll";
const char *HI3_TP6_SECTION_NAME = ".bh3"; const char *HI3_TP6_SECTION_NAME = ".bh3";
const char *HI3_TVM_SECTION_NAME = ".tvm0"; const char *HI3_TVM_SECTION_NAME = ".tvm0";
@ -14,10 +14,14 @@ struct crc_id_pair {
}; };
const struct crc_id_pair HI3_REGIONS[] = { const struct crc_id_pair HI3_REGIONS[] = {
// Only glb for now
// It may be possible to get rid of region-specific data altogether in the future // It may be possible to get rid of region-specific data altogether in the future
{ 0x45221647, GAME_HI3_GLB } // glb v6.7.0 { 0xcb8041ff, GAME_HI3_GLB }, // glb v6.8.0
{ 0x104cbfc5, GAME_HI3_SEA }, // sea v6.8.0
{ 0x2efd9099, GAME_HI3_CN }, // cn v6.8.0
{ 0x30fa5b0f, GAME_HI3_TW }, // tw v6.8.0
{ 0xe47327fb, GAME_HI3_KR }, // kr v6.8.0
{ 0x992b6b63, GAME_HI3_JP } // jp v6.8.0
}; };
void hi3_fill_data(struct game_data *buf) { void hi3_fill_data(struct game_data *buf) {
@ -36,7 +40,7 @@ void hi3_fill_data(struct game_data *buf) {
buf->id = id; buf->id = id;
buf->name = HI3_NAME; buf->name = HI3_NAME;
buf->assembly_path = HI3_ASSEMBLY_PATH; buf->assembly_name = HI3_ASSEMBLY_NAME;
buf->tp6_section_name = HI3_TP6_SECTION_NAME; buf->tp6_section_name = HI3_TP6_SECTION_NAME;
buf->tvm_section_name = HI3_TVM_SECTION_NAME; buf->tvm_section_name = HI3_TVM_SECTION_NAME;

View File

@ -5,7 +5,7 @@
#include <game.h> #include <game.h>
const char *HSR_NAME = "StarRail"; const char *HSR_NAME = "StarRail";
const char *HSR_ASSEMBLY_PATH = "GameAssembly.dll"; const char *HSR_ASSEMBLY_NAME = "GameAssembly.dll";
const char *HSR_TP6_SECTION_NAME = ".ace"; const char *HSR_TP6_SECTION_NAME = ".ace";
const char *HSR_TVM_SECTION_NAME = ".tvm0"; const char *HSR_TVM_SECTION_NAME = ".tvm0";
@ -17,14 +17,14 @@ struct crc_id_pair {
const struct crc_id_pair HSR_REGIONS[] = { const struct crc_id_pair HSR_REGIONS[] = {
// It may be possible to get rid of region-specific data altogether in the future // It may be possible to get rid of region-specific data altogether in the future
{ 0x2df53005, GAME_HSR_OS }, // os v1.1.0 { 0x9eb3084e, GAME_HSR_OS }, // os v1.2.0
{ 0x3e644d26, GAME_HSR_CN } // cn v1.1.0 { 0x14be07e9, GAME_HSR_CN } // cn v1.2.0
}; };
#define JUMP_SIZE (6 + sizeof(void*)) #define JUMP_SIZE (6 + sizeof(void*))
// Temporarily hardcoded offset // Temporarily hardcoded offset
// v1.1.0, same for os and cn // v1.2.0, same for os and cn
#define WTSUD_PATCH_OFFSET 0x16430 #define WTSUD_PATCH_OFFSET 0x16430
char wtsud_original_bytes[JUMP_SIZE]; char wtsud_original_bytes[JUMP_SIZE];
@ -71,12 +71,6 @@ static void _unityplayer_callback(HMODULE unityModule) {
} }
void hsr_fill_data(struct game_data *buf) { void hsr_fill_data(struct game_data *buf) {
if (!utils_env_enabled("I_WANT_A_BAN")) {
msg_err_a("Using this tool with HSR is unsafe. Refer to the readme for more details: https://codeberg.org/mkrsym1/jadeite");
} else {
msg_warn_a("Using this tool with HSR will most likely result in a ban. Please only use testing accounts");
}
uint32_t crc = utils_file_crc32c("UnityPlayer.dll"); uint32_t crc = utils_file_crc32c("UnityPlayer.dll");
enum game_id id = GAME_INVALID; enum game_id id = GAME_INVALID;
@ -92,7 +86,7 @@ void hsr_fill_data(struct game_data *buf) {
buf->id = id; buf->id = id;
buf->name = HSR_NAME; buf->name = HSR_NAME;
buf->assembly_path = HSR_ASSEMBLY_PATH; buf->assembly_name = HSR_ASSEMBLY_NAME;
buf->tp6_section_name = HSR_TP6_SECTION_NAME; buf->tp6_section_name = HSR_TP6_SECTION_NAME;
buf->tvm_section_name = HSR_TVM_SECTION_NAME; buf->tvm_section_name = HSR_TVM_SECTION_NAME;

View File

@ -3,7 +3,7 @@
#include <ntdll.h> #include <ntdll.h>
#include <ace.h> #include <ace.h>
#include <game.h> #include <game.h>
#include <tp6.h> #include <core.h>
#include <utils.h> #include <utils.h>
#include <main.h> #include <main.h>
@ -46,7 +46,7 @@ BOOL WINAPI DllMain(HINSTANCE instance, DWORD reason, LPVOID reserved) {
ace_load_driver_module(); ace_load_driver_module();
// ...magic // ...magic
tp6_setup_patcher(&game, baseModule); core_setup_patcher(&game, baseModule);
// Load the UnityPlayer module and invoke the callback // Load the UnityPlayer module and invoke the callback
HMODULE unityModule = LoadLibraryA("UnityPlayer.dll"); HMODULE unityModule = LoadLibraryA("UnityPlayer.dll");

View File

@ -1,5 +1,50 @@
BITS 64 BITS 64
; Macro definitions
; read dst, pSrc, size
%macro read 3
mov %1, [%2]
add %2, %3
%endmacro
; copy pDst, pSrc, temp, tempSize
%macro copy 4
mov %3, [%2]
mov [%1], %3
add %1, %4
add %2, %4
%endmacro
; unprotect addr, size, fn
%macro unprotect 3
mov rcx, %1
mov rdx, %2
mov r8, 40h ; PAGE_EXECUTE_READWRITE
lea r9, [rel oldProtect]
call %3
%endmacro
; reprotect addr, size, fn
%macro reprotect 3
mov rcx, %1
mov rdx, %2
lea r9, [rel oldProtect]
mov r8d, [r9]
call %3
%endmacro
main: ; Replacement entry point main: ; Replacement entry point
push rsi push rsi
push rdi push rdi
@ -16,6 +61,14 @@ main: ; Replacement entry point
mov rdi, rax ; *GetProcAddress mov rdi, rax ; *GetProcAddress
mov rcx, rsi ; kernel32.dll
lea rdx, [rel s_VirtualProtect]
call rdi ; rax = *VirtualProtect
mov rcx, rax
call RecoverExecutable
mov rcx, rsi ; kernel32.dll mov rcx, rsi ; kernel32.dll
lea rdx, [rel s_LoadLibraryW] lea rdx, [rel s_LoadLibraryW]
call rdi ; rax = *LoadLibraryW call rdi ; rax = *LoadLibraryW
@ -63,10 +116,65 @@ main: ; Replacement entry point
ret ret
RecoverExecutable: ; expects *VirtualProtect in rcx
push rbx
push r12
push r13
push r14
sub rsp, 8
mov r13, rcx
; Find the recovery data structure
lea rbx, [rel dllPath]
.search:
read ax, rbx, 2
test ax, ax
jnz .search
; Recover entry point bytes (6 + 8 = 14 total)
read r12, rbx, 8 ; Address
mov r14, r12
unprotect r14, 14, r13
copy r12, rbx, rax, 8
copy r12, rbx, eax, 4
copy r12, rbx, ax, 2
reprotect r14, 14, r13
; Recover import descriptor bytes (20 total)
read r12, rbx, 8
mov r14, r12
unprotect r14, 20, r13
copy r12, rbx, rax, 8
copy r12, rbx, rax, 8
copy r12, rbx, eax, 4
reprotect r14, 20, r13
; Recover import data directory entry size bytes (4 total)
read r12, rbx, 8
mov r14, r12
unprotect r14, 4, r13
copy r12, rbx, eax, 4
reprotect r14, 4, r13
add rsp, 8
pop r14
pop r13
pop r12
pop rbx
ret
%include "gpa.asm" %include "gpa.asm"
oldProtect: dd 0
; Strings ; Strings
s_VirtualProtect: db "VirtualProtect", 0
s_LoadLibraryW: db "LoadLibraryW", 0 s_LoadLibraryW: db "LoadLibraryW", 0
s_GetModuleHandleA: db "GetModuleHandleA", 0 s_GetModuleHandleA: db "GetModuleHandleA", 0
s_GetCommandLineW: db "GetCommandLineW", 0 s_GetCommandLineW: db "GetCommandLineW", 0

View File

@ -1,5 +1,22 @@
#include <inject.h> #include <inject.h>
#define JUMP_SIZE (6 + sizeof(void*))
// Original values to recover after the injection
// Recovery is performed by the assembly payload
#pragma pack(push, 1)
struct recovery_data {
void *entryPointAddress;
char entryPointData[JUMP_SIZE];
void *importDescriptorAddress;
IMAGE_IMPORT_DESCRIPTOR importDescriptorData;
void *sizeFieldAddress;
DWORD sizeFieldData;
};
#pragma pack(pop)
static inline void write_protected_process_memory(HANDLE process, void *address, const void *buf, size_t size) { static inline void write_protected_process_memory(HANDLE process, void *address, const void *buf, size_t size) {
DWORD oldProtect; DWORD oldProtect;
VirtualProtectEx(process, address, size, PAGE_EXECUTE_READWRITE, &oldProtect); VirtualProtectEx(process, address, size, PAGE_EXECUTE_READWRITE, &oldProtect);
@ -13,13 +30,6 @@ static inline void write_protected_process_memory(HANDLE process, void *address,
void inject(HANDLE process, const void *payload, size_t payloadSize, const wchar_t *dllPath) { void inject(HANDLE process, const void *payload, size_t payloadSize, const wchar_t *dllPath) {
size_t _; // Contrary to the docs, {Write,Read}ProcessMemory likes to crash if the last arg is NULL size_t _; // Contrary to the docs, {Write,Read}ProcessMemory likes to crash if the last arg is NULL
// Inject the loader into the module
size_t dllPathLen = (wcslen(dllPath) + 1) * sizeof(wchar_t);
char *remoteAlloc = VirtualAllocEx(process, NULL, payloadSize + dllPathLen, MEM_COMMIT, PAGE_EXECUTE_READWRITE);
WriteProcessMemory(process, remoteAlloc, payload, payloadSize, &_);
WriteProcessMemory(process, remoteAlloc + payloadSize, dllPath, dllPathLen, &_);
// Find the EXE header in the process // Find the EXE header in the process
char exeHeader[1024]; char exeHeader[1024];
IMAGE_DOS_HEADER *dosHeader = NULL; IMAGE_DOS_HEADER *dosHeader = NULL;
@ -64,25 +74,60 @@ void inject(HANDLE process, const void *payload, size_t payloadSize, const wchar
char *exe = (char*)memoryInfo.BaseAddress; char *exe = (char*)memoryInfo.BaseAddress;
// Inject the loader into the process
const unsigned char JUMP_INST[] = { 0xFF, 0x25, 0x00, 0x00, 0x00, 0x00 };
size_t dllPathSize = (wcslen(dllPath) + 1) * sizeof(wchar_t);
size_t allocSize = payloadSize + dllPathSize + sizeof(struct recovery_data);
char *remoteAlloc = VirtualAllocEx(process, NULL, allocSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE);
// Write the assembly payload and dll path
WriteProcessMemory(process, remoteAlloc, payload, payloadSize, &_);
WriteProcessMemory(process, remoteAlloc + payloadSize, dllPath, dllPathSize, &_);
// Modify the executable to run the assembly payload
// Recovery data structure
struct recovery_data rd;
// Replace the entry point with a jump to the loader // Replace the entry point with a jump to the loader
char *entryPoint = exe + ntHeaders->OptionalHeader.AddressOfEntryPoint; char *entryPoint = exe + ntHeaders->OptionalHeader.AddressOfEntryPoint;
const unsigned char JUMP_INST[] = { 0xFF, 0x25, 0x00, 0x00, 0x00, 0x00 }; // Save the original entry point address and bytes
rd.entryPointAddress = entryPoint;
ReadProcessMemory(process, rd.entryPointAddress, rd.entryPointData, sizeof(rd.entryPointData), &_);
// Replace the entry point with a jump to the assembly payload
write_protected_process_memory(process, entryPoint, JUMP_INST, sizeof(JUMP_INST)); write_protected_process_memory(process, entryPoint, JUMP_INST, sizeof(JUMP_INST));
write_protected_process_memory(process, entryPoint + sizeof(JUMP_INST), &remoteAlloc, sizeof(remoteAlloc)); write_protected_process_memory(process, entryPoint + sizeof(JUMP_INST), &remoteAlloc, sizeof(remoteAlloc));
// Break the import table to prevent any dlls from being loaded // Break the import table to prevent any dlls from being loaded
// Step 1: break the first import descriptor // Step 1: break the first import descriptor
char *importDescriptors = exe + ntHeaders->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].VirtualAddress; char *importDescriptors = exe + ntHeaders->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].VirtualAddress;
// Save the original descriptor address and bytes
rd.importDescriptorAddress = importDescriptors;
ReadProcessMemory(process, rd.importDescriptorAddress, &rd.importDescriptorData, sizeof(rd.importDescriptorData), &_);
// Overwrite with zeroes
IMAGE_IMPORT_DESCRIPTOR firstDescriptor; IMAGE_IMPORT_DESCRIPTOR firstDescriptor;
ZeroMemory(&firstDescriptor, sizeof(firstDescriptor)); ZeroMemory(&firstDescriptor, sizeof(firstDescriptor));
write_protected_process_memory(process, importDescriptors, &firstDescriptor, sizeof(firstDescriptor)); write_protected_process_memory(process, importDescriptors, &firstDescriptor, sizeof(firstDescriptor));
// Step 2: break the image data directory entry // Step 2: break the image data directory entry
size_t ddOffset = ((char*)&(ntHeaders->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].Size)) - exeHeader; char* ddAddr = ((char*)&(ntHeaders->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].Size)) - exeHeader + exe;
DWORD newSize = 0;
// Save the original value
rd.sizeFieldAddress = ddAddr;
ReadProcessMemory(process, rd.sizeFieldAddress, &rd.sizeFieldData, sizeof(rd.sizeFieldData), &_);
write_protected_process_memory(process, exe + ddOffset, &newSize, sizeof(newSize)); // Set to 0
DWORD newSize = 0;
write_protected_process_memory(process, ddAddr, &newSize, sizeof(newSize));
// Write recovery data to the allocation
WriteProcessMemory(process, remoteAlloc + payloadSize + dllPathSize, &rd, sizeof(rd), &_);
} }

View File

@ -1,4 +1,4 @@
project('jadeite', 'c', version: '1.1.10') project('jadeite', 'c', version: '2.0.1')
nasm = find_program('nasm') nasm = find_program('nasm')
gen_res = find_program('gen_resources.sh') gen_res = find_program('gen_resources.sh')

View File

@ -1,22 +1,42 @@
{ {
"jadeite": { "jadeite": {
"version": "1.1.10" "version": "2.0.1"
}, },
"games": { "games": {
"hi3rd": { "hi3rd": {
"global": { "global": {
"status": "verified", "status": "verified",
"version": "6.7.0" "version": "6.8.0"
},
"sea": {
"status": "verified",
"version": "6.8.0"
},
"china": {
"status": "verified",
"version": "6.8.0"
},
"taiwan": {
"status": "verified",
"version": "6.8.0"
},
"korea": {
"status": "verified",
"version": "6.8.0"
},
"japan": {
"status": "verified",
"version": "6.8.0"
} }
}, },
"hsr": { "hsr": {
"global": { "global": {
"status": "unsafe", "status": "verified",
"version": "1.1.0" "version": "1.2.0"
}, },
"china": { "china": {
"status": "unsafe", "status": "verified",
"version": "1.1.0" "version": "1.2.0"
} }
} }
} }