Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Bypass school Whitelist

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming
View previous topic :: View next topic  
Author Message
Soul_man
How do I cheat?
Reputation: 0

Joined: 19 Sep 2012
Posts: 4

PostPosted: Wed Sep 19, 2012 9:01 am    Post subject: Bypass school Whitelist Reply with quote

Just some background here. My friends and I have been playing halo during lunch for years on years now. This year, our school upgraded to windows 7 (bad diea, but we won't go there). In the past, we had a bat file that stopped Synchron eyes, enablung us to launch exes (and not have our screens be seen). However, now we can do nothing. I've been playing around with things for a couple of weeks now and have determined that they have a whitelist verifying exes everytime they are run. There is no blacklist as I changed the exe's MV5 (signature) and it still does not run. I am pretty sure there are ways to bypass this, but I dont know how. Is there a way to have an exe almost imitate another exe's signature (one that is one the whitelist such as windows paint)? Any help would be much appreciated, all we want to do is play a freaking game during lunch.
Back to top
View user's profile Send private message Send e-mail
atom0s
Moderator
Reputation: 205

Joined: 25 Jan 2006
Posts: 8587
Location: 127.0.0.1

PostPosted: Wed Sep 19, 2012 9:21 am    Post subject: Reply with quote

All depends on how the files are being checked for the whitelist.

Do you know what protection system the schools using now to block the files from running?

_________________
- Retired.
Back to top
View user's profile Send private message Visit poster's website
Soul_man
How do I cheat?
Reputation: 0

Joined: 19 Sep 2012
Posts: 4

PostPosted: Wed Sep 19, 2012 1:26 pm    Post subject: Reply with quote

Well, I can't really tell to be honest. I made a jar file that starts the exe, and I launch it through a bat file, and it works on my computer just fine. When I tested it out at school (I changed the ports and everything so they were correct), it said "Create process error=1260." Does this help? Besides this, I'm pretty sure we still use synchron eyes.
Back to top
View user's profile Send private message Send e-mail
atom0s
Moderator
Reputation: 205

Joined: 25 Jan 2006
Posts: 8587
Location: 127.0.0.1

PostPosted: Wed Sep 19, 2012 6:22 pm    Post subject: Reply with quote

It means:
Code:

ERROR_ACCESS_DISABLED_BY_POLICY
1260 (0x4EC)
This program is blocked by group policy. For more information, contact your system administrator.


Which means your school system administrator has setup policies that restrict you from running things. I'm not sure how they've configured it so it's hard for me to give you any certain direction to take to try to bypass it.

Try Googling around for stuff like 'Windows 7 bypass group policy' and see if you can find something that might work.

_________________
- Retired.
Back to top
View user's profile Send private message Visit poster's website
SteveAndrew
Master Cheater
Reputation: 30

Joined: 02 Sep 2012
Posts: 323

PostPosted: Wed Sep 19, 2012 9:36 pm    Post subject: Reply with quote

Can you modify an whitelisted application and it will still run? Like modifying paint and it will still execute?

If so you could probably make a whitelisted executable so it will load the executable you want (like halo lol) and be able to run it!

However it probably wont work just to create the process you want normally even if you can get your modified paint/ whatever to run.

You might have to parse the PE header yourself, and load it like windows does and create the thread at the entry point itself! It might work Very Happy

_________________
Back to top
View user's profile Send private message
Soul_man
How do I cheat?
Reputation: 0

Joined: 19 Sep 2012
Posts: 4

PostPosted: Thu Sep 20, 2012 5:27 am    Post subject: Reply with quote

All righ When I get home I'll try editing paint and see if it'll work. How do you mean getting paint to launch my exe though? Don't quite understand.
Back to top
View user's profile Send private message Send e-mail
n0 m3rcY
Cheater
Reputation: 0

Joined: 18 Jun 2012
Posts: 42

PostPosted: Sat Sep 22, 2012 3:12 pm    Post subject: Reply with quote

Soul_man wrote:
All righ When I get home I'll try editing paint and see if it'll work. How do you mean getting paint to launch my exe though? Don't quite understand.

What, like inject a dll into paint to run shellexecute and start your exe?

That wouldn't be a bad idea... I wonder if it's just blocking starting from explorer or any type of start. At the very worst, you could always do a technique that's used for loading malware and make a dll stub on an allowed process and WPM your program (aligned) into memory then force start it, but that's pretty complex and is probably overkill for just playing Halo.
Back to top
View user's profile Send private message
Soul_man
How do I cheat?
Reputation: 0

Joined: 19 Sep 2012
Posts: 4

PostPosted: Sat Sep 22, 2012 7:41 pm    Post subject: Reply with quote

All I was going to do was open paint simply using something like resource hacker and just change one of the version digits. Done it before, the program still runs, but when you check the MD5 it is different than the original.
Back to top
View user's profile Send private message Send e-mail
atom0s
Moderator
Reputation: 205

Joined: 25 Jan 2006
Posts: 8587
Location: 127.0.0.1

PostPosted: Sun Sep 23, 2012 1:46 am    Post subject: Reply with quote

If you can edit a white-listed application, perhaps the list is based on location + name?

Try running your own app by replacing something like mspaint.exe or calc.exe with your own app.

If that doesn't work, you can look into IAT rebuilding and force mspaint to load your own DLL when it starts, allowing you to do whatever you want through MSPaint.

_________________
- Retired.
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites