Exetools

Exetools (https://forum.exetools.com/index.php)
-   Community Tools (https://forum.exetools.com/forumdisplay.php?f=47)
-   -   ScyllaHide (https://forum.exetools.com/showthread.php?t=15712)

mr.exodia 10-20-2016 18:57

There have been massive issues with the Microsoft symbol servers recently... This was collected (took about 10 minutes) on the latest Windows 8.1 x64 https://gist.github.com/mrexodia/8aea202c1177892b4577a32927cef3bf

SKiLLa 10-24-2016 18:26

Thanks mr. Exodia. I did notice some symbol-server issues, but after a few retries it 'completed'. As it turns out; I got returned an incorrect version-tag when running PDBReader and the network-issues weren't messing things up after all (except having me to retry it a couple of times):

[060200000109_x86_000158A0]

instead of:

[060300000109_x86_000158A0]

whilst I do have Windows 8.1 x64 (=v6.3). I changed this manually in the .ini file, after which ScyllaHide seems to work perfectly. Not sure if this is an issue with PDBReader or not, but I should provide more info, please let me know ...

PS: Kindy silly I didn't notice before ... where's the shame-on-me-smiley when you need it ?

TheEnd 10-29-2016 10:46

NT APIs missing
section
060200000109_x64_0000BAB0
file
X:\x64dbg\plugins\NtApiCollection.ini

mr.exodia 10-30-2016 03:50

Everything appears to work fine here. If Microsoft doesn't provide symbols there is not much you can do. What SKiLLa did is not a real solution, for me the problem was solved by running NtApiTool.exe again.

mudlord 11-15-2016 07:46

Seems the Anniversary update problems I documented and reversed are now fixed by another person, and is now in latest Git :)

Which is super cool.

kienmanowar 11-15-2016 09:54

Quote:

Originally Posted by mudlord (Post 107673)
Seems the Anniversary update problems I documented and reversed are now fixed by another person, and is now in latest Git :)

Which is super cool.

ScyllaHideIDA.p64 is missing?

Storm Shadow 11-15-2016 22:06

1 Attachment(s)
Quote:

Originally Posted by kienmanowar (Post 107674)
ScyllaHideIDA.p64 is missing?

here

Attachment 9084
Also remind that the x64 version is a win32 build but with a different extension name.

kienmanowar 11-16-2016 17:44

Quote:

Originally Posted by Storm Shadow (Post 107680)
here

Attachment 9084
Also remind that the x64 version is a win32 build but with a different extension name.

Can you mirror it? I dont have permissions to download the attachment :(

Regards,

Storm Shadow 11-16-2016 18:20

Quote:

Originally Posted by kienmanowar (Post 107689)
Can you mirror it? I dont have permissions to download the attachment :(

Regards,

https://mega.nz/#!rxsjmBhb!OaRLJnutaPGqf9jQUntJKs6ficb9U7m2XZ57JEWrtd0

Mendax47 11-27-2016 21:23

Quote:

Originally Posted by Storm Shadow (Post 107680)
here

Attachment 9084
Also remind that the x64 version is a win32 build but with a different extension name.

Hey Bro Can you Upload The Latest One (.p64)...? I Haven't VS To Compile It.... :(

Storm Shadow 11-28-2016 00:38

Quote:

Originally Posted by Mendax47 (Post 107814)
Hey Bro Can you Upload The Latest One (.p64)...? I Haven't VS To Compile It.... :(

Please read before asking.
I posted a Mega link in the very last post before you asked. ;)

Mendax47 11-28-2016 01:43

mrexodia released this on Apr 21: ScyllaHide_2016-20-11_22-02

And Your Post : 11/16/16

That's Why I am Asking..... :)

BTW Thanks....

Storm Shadow 11-28-2016 05:17

Just take the *. Plw and change it to *. P64 the x64 plugin do not use the Ida x64. Libraries. So the x86 works for both.

Mendax47 11-28-2016 10:24

Quote:

Originally Posted by Storm Shadow (Post 107828)
Just take the *. Plw and change it to *. P64 the x64 plugin do not use the Ida x64. Libraries. So the x86 works for both.

Thanks.... :)

chants 09-05-2018 08:51

2018-08-27 snapshot release
Quote:

https://github.com/x64dbg/ScyllaHide/releases/download/snapshot/ScyllaHide_2018-08-27_08-49.7z
and special greets to Mr. Exodia!

Change log:
Quote:

https://github.com/x64dbg/ScyllaHide/compare/snapshot...vs13

Chuck954 10-17-2018 12:31

Has there been a port to ida 7 for scylla hide? I am in the middle of working on it since I did not see one but wanted to make sure it has not been done yet.

sendersu 10-17-2018 16:44

create a new issue on scylla github
https://github.com/x64dbg/ScyllaHide/issues
that would be a definite global mutex for your work :)
good luck

niculaita 10-18-2018 00:28

https://github.com/x64dbg/ScyllaHide/releases/

sendersu 10-18-2018 15:31

I don't realy understand why the fresh package
ScyllaHide_2018-10-11_11-41.7z
has got inside very old bits?
eg: http://prntscr.com/l7eulo

Chuck954 10-18-2018 22:04

I am using the new IDA SDK with it to compile the IDA pro plugin for IDA 7. It seems so far to have fewer issues then I was expecting but I still have a couple errors to work out. I am still a beginner with coding and this is not my strongest area so I figured it would be a good challenge and is something that can benefit the community.

TechLord 10-19-2018 06:23

Quote:

Originally Posted by Chuck954 (Post 115047)
I am using the new IDA SDK with it to compile the IDA pro plugin for IDA 7. It seems so far to have fewer issues then I was expecting but I still have a couple errors to work out. I am still a beginner with coding and this is not my strongest area so I figured it would be a good challenge and is something that can benefit the community.

Hope you have gone through this page carefully:
Quote:

https://www.hex-rays.com/products/ida/7.0/docs/api70_porting_guide.shtml
I have been able to get it compiled for the IDA Pro v7.0 but I do not want to release it without properly testing it.

Where did you get stuck?
In my experience, once all the stuff in the link above is taken care of, it compiles without too much of a problem.

nikkapedd 04-08-2021 01:06

ScyllaHide for IDA pro 7.5
Code:

https://github.com/notify-bibi/ScyllaHide-IDA7.5
ddl-> https://github.com/notify-bibi/ScyllaHide-IDA7.5/releases/tag/0.2


sendersu 04-08-2021 01:29

Does it support both 32 as well as 64 bit targets?

nikkapedd 04-08-2021 02:27

sendersu yes, are present both dll in the archive...

Masoud 07-17-2021 19:53

Quote:

Originally Posted by nikkapedd (Post 122836)
ScyllaHide for IDA pro 7.5
Code:

https://github.com/notify-bibi/ScyllaHide-IDA7.5
ddl-> https://github.com/notify-bibi/ScyllaHide-IDA7.5/releases/tag/0.2


Thanks for the share, btw doesn't work on IDA 7.5 .
As I already tried to compile using SDK of 7.5, there was a missing constant in kernwin.hpp file which was exist on older IDA versions.

sendersu 07-19-2021 17:32

I found this page to be very useful when porting old stuff into new v7.x

https://hex-rays.com/products/ida/support/ida74_idapython_no_bc695_porting_guide.shtml

niculaita 06-03-2023 00:17

How to bypass Debbuger setected (E0033) by Sentinel protection in xdbg 32/64 ?
schillahide profiles are not enough

sendersu 06-03-2023 03:45

"selected" or "detected" ? :)
2) pls share your sample so reversers will have a chance to dig into
otherwise you have to find the magic ball :)

deepzero 06-03-2023 04:31

literally any scylla profile works for me, e.g. vmp

niculaita 06-04-2023 01:09

I mean in windows under 10 22H2 x32 x64 with x32dbg.exe

sendersu 06-04-2023 16:14

Have you tried other debuggers like Ollydbg (YES! it still works in w10/11 in 32 bits)
or Ida Pro?

niculaita 06-04-2023 17:01

ollydbg special custom in win 7 32 yes
windows 10 32 and 11 x64 no success

from log
2023.06.04 11:52:56 INFO: Loaded VA for NtUserBlockInput = 0x76CE4AE0
2023.06.04 11:52:56 INFO: Loaded VA for NtUserQueryWindow = 0x76CE1160
2023.06.04 11:52:56 INFO: Loaded VA for NtUserGetForegroundWindow = 0x76CE13F0
2023.06.04 11:52:56 INFO: Loaded VA for NtUserBuildHwndList = 0x76CE1220
2023.06.04 11:52:56 INFO: Loaded VA for NtUserFindWindowEx = 0x76CE16F0
2023.06.04 11:52:56 INFO: Loaded VA for NtUserGetClassName = 0x76CE17C0
2023.06.04 11:52:56 INFO: Loaded VA for NtUserInternalGetWindowText = 0x76CE1650
2023.06.04 11:52:56 INFO: Loaded VA for NtUserGetThreadState = 0x76CE1080

can you sent folder of you debuger with cfg and ini files for plugin and other settings for x64/32dbg ?

sendersu 06-04-2023 19:40

Debugger detected (E0033) by Sentinel protection LDK
uses some custom-made detection, this is not a single checkbox (or even set of checkboxes) from S.Hide


All times are GMT +8. The time now is 11:12.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX