Not a member yet? Register for your free account!

Register FAQ Community Today's Posts Search

Go Back   elitepvpers > Dekaron > Dekaron Exploits, Hacks, Bots, Tools & Macros
You last visited: Today at 17:59

  • Did you know? elitepvpers has its own image host, epvpimg.com.

 

[Release] Unpacked XignCode Files

This is a discussion on [Release] Unpacked XignCode Files within the Dekaron Exploits, Hacks, Bots, Tools & Macros forum part of the Dekaron category; Hi. I've unpacked the XignCode anti-cheat files in order to understand better how the anti-cheat works. These files wont work ...

Reply
 
Thread Tools
Old 11-13-2010, 15:15   #1
Reverser / Coder
 
HellSpider's Avatar
 
Join Date: Aug 2008
Posts: 2,561
Received Thanks: 3,846
Exclamation [Release] Unpacked XignCode Files


Hi.

I've unpacked the XignCode anti-cheat files in order to understand better how the anti-cheat works. These files wont work in runtime (because of the security certificate and stripped VirtualMachines), so you can't substitute the original files with these .

Note! This is not a XignCode bypass! These files are just for analyzing purposes!


List of files:

Code:
splash.xem		--> splash.bmp		--> XIGNCODE Splash Bitmap
tray.xem		--> tray.ico		--> XIGNCODE Tray Icon
x3.xem			--> x3.dll		--> XIGNCODE System
xm.exe			--> xm.exe		--> XIGNCODE Message Printer
xmag.xem		--> xmag.xem		--> XIGNCODE File Archive
xsg.xem			--> xsg.dll		--> XIGNCODE System Guard
xxd.xem			--> xxd.dll		--> XIGNCODE WatchDog Process

The file x3.dll was protected by Themida (one of the newest versions), and it had a part of its code virtualized. As I am not able to devirtualize Themida VMs I have stripped it from the file.

This thread is supposed to be a research thread of XignCode. If you have made some research you can post it in this thread and I will add it to the main post (with your approval of course) .


Loading of x3.xem:

Spoiler:

XignCode packet structure:

Spoiler:

XignCode kernel-mode hooks:

Spoiler:





-Update Log-

~13.11.2010~

+ Initial release (XIGNCODE 3.1)

~19.01.2011~

+ Detailed file information
+ Basic packet structure


Archive password (without spaces):
Code:
w w w . e l i t e p v p e r s . d e
Attached Files
File Type: rar unpacked_XignCode_3.1.rar (1.92 MB, 1725 views)


Last edited by HellSpider; 05-24-2012 at 14:01.
HellSpider is offline  
The Following 32 Users Say Thank You to HellSpider For This Useful Post:
2moonseller (11-16-2010), 4the (11-13-2010), Anjo1077 (12-06-2010), Apocalisse (11-14-2010), biohazardzz (06-04-2012), BleachKing (11-15-2010), bloodyrex (11-18-2010), Chaos62840 (01-05-2011), Dantje (06-18-2012), demonkiller19 (11-25-2010), diegolatigo (11-27-2010), EliteDKTrader (11-13-2010), en[DEV]er (05-07-2012), GooniGooGoo (11-14-2010), iamlegend93 (11-13-2010), jhonjm (01-21-2011), kekitamu (12-08-2010), KilerSpyZer (11-15-2010), Missmodd (11-13-2010), MrAnestis (02-01-2011), PureEnergy3 (11-28-2010), rahmel (01-10-2011), rebekt666 (12-11-2010), Robert666 (11-13-2010), sanadachan (11-16-2010), Scwolf (11-19-2010), shuteraak169 (12-15-2010), Sirmabus (07-06-2012), Snaffy (05-24-2012), sokkolo (12-09-2010), SubconsciousCruelty (05-25-2012), weakneska26 (02-16-2011)
Old 11-13-2010, 15:18   #2
Senior Member
 
iamlegend93's Avatar
 
Join Date: Feb 2008
Posts: 263
Received Thanks: 47
I willl have a check on that.
iamlegend93 is offline  
Old 11-13-2010, 15:42   #3
[GM & DEV]4THE
 
4the's Avatar
 
Join Date: Sep 2010
Posts: 210
Received Thanks: 50
...

Thanks for sharing
Good stuff.
4the is offline  
Old 11-13-2010, 17:43   #4
Junior Member
 
Join Date: Aug 2010
Posts: 27
Received Thanks: 0
so i can hack with that ?
1tamer1 is offline  
Old 11-13-2010, 18:24   #5
Senior Member
 
Join Date: Sep 2008
Posts: 806
Received Thanks: 111
so hell what we do with that ? cant make bypass xign from his files ?
elfulll is offline  
Old 11-13-2010, 21:05   #6
Senior Member
 
Join Date: Aug 2007
Posts: 157
Received Thanks: 10
Quote:
Originally Posted by HellSpider View Post
Note! This is not a XignCode bypass! These files are just for analyzing purposes!


This thread is supposed to be a research thread of XignCode. If you have made some research you can post it in this thread and I will add it to the main post (with your approval of course) .
No you CANNOT hack with that...
Read what is written, don't just cry all day "omg i want hacks"
Redis is offline  
Old 11-13-2010, 22:19   #7
Banned
 
Join Date: Dec 2007
Posts: 1,238
Received Thanks: 385
Tnx Instant. I'm going to look into it later.
EliteDKTrader is offline  
The Following User Says Thank You to EliteDKTrader For This Useful Post:
aznrice809 (11-30-2010)
Old 11-14-2010, 06:05   #8
Member
 
lord17's Avatar
 
Join Date: Jun 2008
Posts: 64
Received Thanks: 3
well i hope bypass will be created soon
lord17 is offline  
Old 11-14-2010, 10:03   #9
Member
 
Apocalisse's Avatar
 
Join Date: Mar 2008
Posts: 90
Received Thanks: 13
Thank you, i'm gonna check this out
Apocalisse is offline  
Old 11-14-2010, 11:33   #10
Junior Member
 
Join Date: Dec 2009
Posts: 9
Received Thanks: 3
Cheers
GooniGooGoo is offline  
The Following User Says Thank You to GooniGooGoo For This Useful Post:
cedracuare (12-10-2010)
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Release] Unpacked dekaron.exe [4.6.23] HellSpider Dekaron Exploits, Hacks, Bots, Tools & Macros 79 06-26-2010 16:38
[Release] Unpacked NINEDRAGONS.exe [v.122] HellSpider 9Dragons 38 03-16-2010 21:24
[Release] Unpacked dekaron.exe [45.0.11][EU HellSpider Dekaron Exploits, Hacks, Bots, Tools & Macros 22 07-19-2009 17:31
Should i Release my unpacked 4.6.24? Skullzx Dekaron Exploits, Hacks, Bots, Tools & Macros 8 06-23-2009 01:06
[Release] Unpacked 4.5.8 Dekaron.exe furious420 Dekaron Exploits, Hacks, Bots, Tools & Macros 14 12-07-2008 04:04




All times are GMT +1. The time now is 17:59.


Powered by vBulletin®
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.