  1. M

    Solved No flash cheat only works sometimes in my driver?

    I have followed the tutorial on making a kernel mode driver, set everything up, and made sure I don't BSOD every time I try to start it. I then followed the tutorial (included in the video from the form above) to incorporate a no flash cheat into the driver. It worked fine the first attempt, and...
  2. G

    Solved Marshal error while communicatig with socket driver?

    I am getting the following error Exception thrown: 'System.AccessViolationException' in mscorlib.dll 'FatalExecutionEngineError' The runtime has encountered a fatal error. The address of the error was at 0x49cfff2b, on thread 0x3a98. The error code is 0xc0000005. I might have something to do...
  3. G

    Solved How to communicate with socket driver?

    I am able to connect to my socket driver but I am not able to retrieve the base address, here is the struct of the packets constexpr auto packet_magic = 0x12345568; constexpr auto server_ip = 0x7F000001; // constexpr auto server_port = 28055; enum class PacketType {...
  4. _xeroxz

    Source Code VDM (Vulnerable Driver Manipulation)

    Call kernel functions from usermode using any driver exposing physical memory read/write. This is what physmeme does except it uses map/unmap physical memory and that project was designed to map drivers, this is designed to call kernel functions. Its a library that you can build code on :)...
  5. G

    Solved Prevent Sigscan and question about PiDDBCache Table

    I''ll start with the first question, let's say a driver gets detected, how to get undected once again, changing dos device names and ioctl codes is standard but what Else? In normal assemply we can use polymorphic code to prevent sig scans, any equivalent for drivers? Next question, I see alot...
  6. Kuroyama

    Question Questions regarding EAC and Kernel Mode driver.

    So I have created my driver, it works fine (I use kdmapper). Right now it's not detected (yet), I can do some pointer read/write operations using MmCopyVirtualMemory. But there is something I'm concern of. Questions: 1.Can EAC detect my driver if I use kdmappper? 2. Can EAC detect my...
  7. I

    Solved user defined namespaces in kmdf

    solved many thanks
  8. D

    Solved Kernel MmCopyVirtualMemory always returns 0

    Hi I've been trying to read process memory with code below case IOCTL_READ_REQUEST: { PKERNEL_READ_REQUEST ReadInput = (PKERNEL_READ_REQUEST)Irp->AssociatedIrp.SystemBuffer; PEPROCESS Process; if (NT_SUCCESS(PsLookupProcessByProcessId(ULongToHandle(0 /* <-- game pid*/), &Process)))...
  9. XdarionX

    Discuss How would you exploit these drivers?

    Vanguard is blocking these drivers, I have never heard about them so I looked inside what can I find and to my big surprise I found nothing. These drivers do not import anything suspicios (KeStackAttachProcess, ZwMapViewOfSection, MmMapIoSpace etc..), they even dont have ioctl dispatch routines...
  10. dretax

    Video Tutorial How to Make a Windows Kernel Mode Driver Tutorial

    This tutorial series will teach you everything you need to make a kernel driver on Windows. This video gives you a basic insight on how kernel drivers work, how can you setup your Visual Studio to be able to make & compile one. It also shows you how to view debug output of your drivers. What...
  11. dretax

    Source Code CSGO Kernel Driver Multihack

    So a couple of weeks ago I started learning my way of Kernel Drivers with the help of @Life_45, and @Daax 's articles also provided me valueable information with I was looking for. There is still much to learn I'm 200% sure about that, but I feel like I'm on the right track, and I feel like...
  12. XdarionX

    Question Vulnerable driver I/O access

    Hello, for a while I have been reversing ioctl dispatch routines of some drivers and the most interesting stuff I found was only access to in & out instructions. I can read and write arbitrary byte at arbitrary port. I heard that it may have an impact on security... but my question is how can it...
