Jump to content
Tuts 4 You
h4sh3m

Another Simple Loader(Delphi SRC)

Recommended Posts

h4sh3m

Hi

In this method we're using dlls as loader, Some system files(I'm just tested dll files) can load from outside of system directory so we can use them to patch files !!

Most "Delphi" and "Dotnet applications" loads "version.dll" by default so we can use this file as loader for them !

 

 

 

Best Regards,

h4sh3m

version.rar

  • Like 4
  • Thanks 1

Share this post


Link to post
Share on other sites
safengine

thank you my friend

Share this post


Link to post
Share on other sites
atom0s

This method is known as proxying. Some other commonly used dll's that are proxied:

 - d3d8.dll / d3d9.dll (Commonly used in games.)
- dinput8.dll (Commonly used in games.)
 - opengl32.dll (Commonly used in games.)
 - mscoree.dll (Commonly loaded in .NET applications.)
 - dxgi.dll (Commonly loaded on Windows 10 in nearly all applications.)
 - wsock32.dll (Commonly loaded in applications that make internet connections.)

  • Like 2

Share this post


Link to post
Share on other sites
h4sh3m
Posted (edited)

Hi

@atom0s, Thank you for information.

I released it because I didn't saw any sample before, In addition I'm using following files too:winmm, bcrypt, MSIMG32, ...

 

 

Best Regards,

h4sh3m

Edited by h4sh3m (see edit history)
  • Confused 1

Share this post


Link to post
Share on other sites
evlncrn8
Posted (edited)

you'd have found some if you used the right terms, there's quite a few on github, and what do you mean by using additional files like winmm ? 

https://www.google.com/search?q=dll+proxy+github

384,000 results.. 

might also be an idea to look up what loader means too

Edited by evlncrn8 (see edit history)

Share this post


Link to post
Share on other sites
JohnWho

Those windows .dll files differs between versions and languages

Share this post


Link to post
Share on other sites
h4sh3m
13 minutes ago, evlncrn8 said:

you'd have found some if you used the right terms, there's quite a few on github, and what do you mean by using additional files like winmm ? 

https://www.google.com/search?q=dll+proxy+github

384,000 results.. 

might also be an idea to look up what loader means too

I'm using this method for 4+ years, maybe I was too lazy to find ready codes !

Share this post


Link to post
Share on other sites
h4sh3m
1 minute ago, JohnWho said:

Those windows .dll files differs between versions and languages

even in exported functions ?!

Share this post


Link to post
Share on other sites
evlncrn8
Posted (edited)

in the amount of exports..  and you've been using this method for 4 years and only now release src as if you invented the wheel ? come on please, cut the crap

Edited by evlncrn8 (see edit history)

Share this post


Link to post
Share on other sites
h4sh3m

wow, I forgot again that all users are professional and no need simple sources !

I apologize for that and never release anything :)

Have a nice day

Share this post


Link to post
Share on other sites
evlncrn8
Posted (edited)

lets not throw a tantrum shall we ?.. i pointed out things you should have been aware of..

you're releasing code others will probably use (hopefully not though), so would it be professional to release it in the state its in ?

as for not releasing anything anymore.. thats up to you, but it wasnt the point of my post, so maybe take a little breather, pick up your toys from the floor, put them back in the pram and read what i posted.. especially the part about dllmain and loadlibrary, and i still dont see the part about winmm in your code either.. just version.dll..

then take the points made by me and others, maybe do some research too (or are you too lazy for that as well?) and make your code better, for the benefits of others, also its a good idea to put some comments in your code so others can follow the concept

oh, and one more thing - its still not a loader

Edited by evlncrn8 (see edit history)

Share this post


Link to post
Share on other sites
despy
8 hours ago, atom0s said:

This method is known as proxying. Some other commonly used dll's that are proxied:

 - d3d8.dll / d3d9.dll (Commonly used in games.)
- dinput8.dll (Commonly used in games.)
 - opengl32.dll (Commonly used in games.)
 - mscoree.dll (Commonly loaded in .NET applications.)
 - dxgi.dll (Commonly loaded on Windows 10 in nearly all applications.)
 - wsock32.dll (Commonly loaded in applications that make internet connections.)

themida embed the mscoree.dll ,how to proxy?

Share this post


Link to post
Share on other sites
evlncrn8

check import table of executable, pick one to proxy.. it aint rocket science

Share this post


Link to post
Share on other sites
collins

Sorry, there is a problem

We could not locate the item you are trying to view.

Error code: 2S328/1

 

Cann't download it.

Share this post


Link to post
Share on other sites
kao

@collins: apparently h4sh3m deleted it. Copy attached.

version.rar

Share this post


Link to post
Share on other sites
collins

:thumbsup:     Thanks!  my friend Kao !

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×