Exetools  

Go Back   Exetools > General > x64 OS

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 05-27-2011, 22:36
Fyyre's Avatar
Fyyre Fyyre is offline
Fyyre
 
Join Date: Dec 2009
Location: 0°N 0°E / 0°N 0°E / 0; 0
Posts: 295
Rept. Given: 106
Rept. Rcvd 93 Times in 44 Posts
Thanks Given: 203
Thanks Rcvd at 397 Times in 130 Posts
Fyyre Reputation: 93
Quote:
Originally Posted by Pansemuckl View Post
Does any1 have the latest offsets for x64 Sp1 ?
NT service indexes? They are same.

If some other offset in question... please specify...

-Fyyre
__________________
Pax in vultu, bellum in corde.

--

https://github.com/Fyyre
Reply With Quote
  #2  
Old 05-29-2011, 09:59
disauto disauto is offline
Friend
 
Join Date: May 2011
Posts: 124
Rept. Given: 14
Rept. Rcvd 22 Times in 15 Posts
Thanks Given: 14
Thanks Rcvd at 92 Times in 29 Posts
disauto Reputation: 22
Here's how to do it:
Hit Windows ORB in your taskbar
Run CMD (Command Prompt) in elevated mode. (Right click | Run as Administrator)
NOTE: If you have UAC (User Account Control) enabled, you will get a prompt
message. Select YES to continue.
Type the following two commands and hit Enter after each line.
bcdedit.exe -set loadoptions DDISABLE_INTEGRITY_CHECKS
bcdedit.exe -set TESTSIGNING ON
You will receive The operation completed successfully message for both commands.
Restart you computer for the changes to take effect.
Now, you should be able to install unsigned drivers on Windows 7 SP1.
If you're like me, you might want to revert changes that we've just made after
successful installation of unsigned drivers. To do so repeat the steps above and
in the Command Prompt enter the following commands:
bcdedit.exe -set loadoptions DENABLE_INTEGRITY_CHECKS
bcdedit.exe -set TESTSIGNING OFF
Reply With Quote
  #3  
Old 06-03-2011, 02:57
Kerlingen Kerlingen is offline
VIP
 
Join Date: Feb 2011
Posts: 338
Rept. Given: 0
Rept. Rcvd 278 Times in 100 Posts
Thanks Given: 0
Thanks Rcvd at 358 Times in 110 Posts
Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299
The switch DDISABLE_INTEGRITY_CHECKS was only present on Windows Vista alpha/beta versions and has been removed in Vista RC. It was never available on any Windows 7 version.

TESTSIGNING ON does not allow you to load unsigned drivers, it only allows you to load selfsigned drivers. It has nothing to do with installing selfsigned drivers, it only allows them to be loaded. As soon as you use TESTSIGNING OFF Windows will only load drivers signed or cross-signed by Microsoft again and doesn't care if you installed selfsigned drivers in TESTSIGNING mode.

Both switches do not disable PatchGuard, the thing this thread is about. Please read the topic und check your posts before you copy&paste something which is false information and does not have anything to do with the topic.
Reply With Quote
The Following User Gave Reputation+1 to Kerlingen For This Useful Post:
Fyyre (06-03-2011)
  #4  
Old 07-03-2011, 12:19
heibaiyuedui heibaiyuedui is offline
Friend
 
Join Date: Nov 2010
Posts: 18
Rept. Given: 6
Rept. Rcvd 4 Times in 3 Posts
Thanks Given: 1
Thanks Rcvd at 1 Time in 1 Post
heibaiyuedui Reputation: 4
add(1.cmd):
bcdedit -set %ENTRY_GUID% locale zh-CN
or:
bcdedit -set %ENTRY_GUID% locale en-US
appearing to Starting:
Four-color logo of Microsoft
Reply With Quote
The Following User Gave Reputation+1 to heibaiyuedui For This Useful Post:
Fyyre (07-11-2011)
  #5  
Old 07-27-2011, 15:17
yogi_saw yogi_saw is offline
Family
 
Join Date: Jul 2010
Posts: 173
Rept. Given: 57
Rept. Rcvd 52 Times in 32 Posts
Thanks Given: 3
Thanks Rcvd at 13 Times in 13 Posts
yogi_saw Reputation: 52
I didn't chk event log but noticed that the driver which I wanted to install was not installing. further I managed to install it by DSEO method
Reply With Quote
  #6  
Old 08-06-2011, 20:49
ChupaChu's Avatar
ChupaChu ChupaChu is offline
Friend
 
Join Date: Dec 2007
Posts: 38
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 3 Times in 3 Posts
ChupaChu Reputation: 0
tuts are always welcomed!

thanks!
Reply With Quote
  #7  
Old 08-28-2011, 23:06
_MAX_
 
Posts: n/a
Good job fyyre,
but unfortunately not working for me!
i test it on Windows 7 with no ServicePack(Version:6.17600.16385/ntkrnlmp.exe), i do everything with Administrator Permission and got Success message for each step, i restart and Boot with No PatchGuard(Windows Loading changes to Visa type :P) But when i try to load a sime DbgPrint() .sys file with OSRLoader i got Unsigned Warning Message like before !!!!
Can u please help Me? How to fix it ?

Last edited by _MAX_; 08-28-2011 at 23:16.
Reply With Quote
  #8  
Old 08-29-2011, 01:19
Kerlingen Kerlingen is offline
VIP
 
Join Date: Feb 2011
Posts: 338
Rept. Given: 0
Rept. Rcvd 278 Times in 100 Posts
Thanks Given: 0
Thanks Rcvd at 358 Times in 110 Posts
Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299
The patch is ONLY for Windows 7 x64 SP1 (v6.1.7601.17514) just like it says in the description.
Reply With Quote
The Following User Gave Reputation+1 to Kerlingen For This Useful Post:
  #9  
Old 08-29-2011, 03:18
_MAX_
 
Posts: n/a
Quote:
Originally Posted by Kerlingen View Post
The patch is ONLY for Windows 7 x64 SP1 (v6.1.7601.17514) just like it says in the description.
Is there any old version of available for older Windows for example Vista, Win7 Without Service pack and ...
Reply With Quote
  #10  
Old 08-29-2011, 03:29
Kerlingen Kerlingen is offline
VIP
 
Join Date: Feb 2011
Posts: 338
Rept. Given: 0
Rept. Rcvd 278 Times in 100 Posts
Thanks Given: 0
Thanks Rcvd at 358 Times in 110 Posts
Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299
The patch is more a proof of concept than something usable for any special purpose.

The official way to load drivers without using a trusted (and expensive) code signing certificate is running Windows in TESTSIGNING mode. This works with Windows Vista and Windows 7, no matter what service packs or security fixes are installed.
Reply With Quote
The Following User Gave Reputation+1 to Kerlingen For This Useful Post:
  #11  
Old 09-15-2011, 15:24
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,663
Rept. Given: 803
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 228
Thanks Rcvd at 567 Times in 241 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
Read the rules first. Don't spam the board.

Quote:
Originally Posted by Kpoch View Post
well i need this and cant dl
A sent you on pm what you want.
Reply With Quote
  #12  
Old 06-03-2012, 08:05
ahmadmansoor's Avatar
ahmadmansoor ahmadmansoor is offline
Coder
 
Join Date: Feb 2006
Location: Syria
Posts: 1,047
Rept. Given: 517
Rept. Rcvd 374 Times in 142 Posts
Thanks Given: 380
Thanks Rcvd at 416 Times in 119 Posts
ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399
Hi Fyyre : I'm sorry for this lately question .
I have run file (2) but the patcher couldn't find osloader.exe or the other file ,even it is exist when i search for both file.
so any suggestion !!!
Thanks ,bs : I have disable UAC ,and I have windows 7 Ultimate SP 1 x64 .
note : I have try ur file from ur site (no_pg_ds_v3) same result !
htxp://fyyre.ivory-tower.de/
__________________
Ur Best Friend Ahmadmansoor
Always My Best Friend: Aaron & JMI & ZeNiX
Reply With Quote
  #13  
Old 10-27-2012, 07:41
Pansemuckl Pansemuckl is offline
Friend
 
Join Date: Nov 2005
Posts: 40
Rept. Given: 6
Rept. Rcvd 4 Times in 2 Posts
Thanks Given: 20
Thanks Rcvd at 45 Times in 16 Posts
Pansemuckl Reputation: 4
Any fix for Win8 ?
Reply With Quote
  #14  
Old 10-27-2012, 23:54
Fyyre's Avatar
Fyyre Fyyre is offline
Fyyre
 
Join Date: Dec 2009
Location: 0°N 0°E / 0°N 0°E / 0; 0
Posts: 295
Rept. Given: 106
Rept. Rcvd 93 Times in 44 Posts
Thanks Given: 203
Thanks Rcvd at 397 Times in 130 Posts
Fyyre Reputation: 93
Hi,

Someone else will have to create support for Windows 8. I stop using new Microsoft products.

Thanks,

-Fyyre
__________________
Pax in vultu, bellum in corde.

--

https://github.com/Fyyre
Reply With Quote
  #15  
Old 10-28-2012, 21:36
Pansemuckl Pansemuckl is offline
Friend
 
Join Date: Nov 2005
Posts: 40
Rept. Given: 6
Rept. Rcvd 4 Times in 2 Posts
Thanks Given: 20
Thanks Rcvd at 45 Times in 16 Posts
Pansemuckl Reputation: 4
So you can't bypass the NEW patchguard? Too hard this time? Hoepfuly someone else can do it.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Signing a Windows Kernel driver without using Microsoft Stingered General Discussion 21 02-17-2023 22:09
Universal PatchGuard and Driver Signature Enforcement Disable Fyyre x64 OS 5 06-20-2022 14:12
Driver Signing on x64 Windows _MAX_ x64 OS 7 10-22-2012 15:47
Defeating patchguard and 64bit kernel-mode protections chaboyd General Discussion 1 02-05-2006 07:36


All times are GMT +8. The time now is 14:12.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )