xxx
Well-known member
- Registriert
- 21 August 2003
- Beiträge
- 1.044
- Punkte Reaktionen
- 0
Ich glaube da muss man zwischen WoW-Warden und Dia-Warden unterscheiden, falls das möglich ist, denn:da warden nicht den kompletten pc scannt so wie es hier in diesem thread oft behauptet wird, sondern einzelne hacks (meist public hacks, die man auf irgendwelchen 3. klassigen pages bekommt).
"The warden then uses the GetWindowTextA function to read the window text in the titlebar of every window. These are windows that are not in the WoW process, but any program running on your computer. Now a Big Deal.
I watched the warden sniff down the email addresses of people I was communicating with on MSN, the URL of several websites that I had open at the time, and the names of all my running programs, including those that were minimized or in the toolbar. These strings can easily contain social security numbers or credit card numbers, for example, if I have Microsoft Excel or Quickbooks open w/ my personal finances at the time.
Once these strings are obtained, they are passed through a hashing function and compared against a list of 'banning hashes' - if you match something in their list, I suspect you will get banned.
Next, warden opens every process running on your computer. When each program is opened, warden then calls ReadProcessMemory and reads a series of addresses - usually in the 0x0040xxxx or 0x0041xxxx range - this is the range that most executable programs on windows will place their code. Warden reads about 10-20 bytes for each test, and again hashes this and compares against a list of banning hashes. These tests are clearly designed to detect known 3rd party programs, such as evÖlwowbot and friends. Every process is read from in this way. I watched warden open my email program, and even my PGP key manager. "
Quelle: rootkit.com