Aidan Khoury

184 posts

Aidan Khoury banner
Aidan Khoury

Aidan Khoury

@aidankhoury

Canada Katılım Şubat 2018
170 Takip Edilen1.8K Takipçiler
Aidan Khoury
Aidan Khoury@aidankhoury·
@UlfFrisk @ItsGamerDoc Yes, 9 years ago. Yes, when half of players were still on pre-Skylake processors. Yes, when Microsoft didn't even properly support the tech on Windows yet. We've had to be very patient. :)
English
0
0
32
2.8K
Ulf Frisk
Ulf Frisk@UlfFrisk·
@ItsGamerDoc Interesting you finally got around to using the IOMMU. I remember suggesting the IOMMU as a possible DMA solution when I released PCILeech as a hardware‑security tool nine years ago.
English
6
1
110
18.1K
GamerDoc
GamerDoc@ItsGamerDoc·
Two weeks ago, one of our chad engineers cooked so we released our IOMMU Restriction Enforcement, which marked the end of 2PC DMA attacks using IOMMU. This is where the device itself is contained in its own memory region and cannot read outside of it. No matter what you do, tampering with that would defeat the purpose of the 2PC "security" benefit. The biggest P2C devs, including devices like HPTT that cost $4500, have all either given up or are coping on theories of how they can get around it or try to resort to finding niche stupid things that gets them detected/banned lmao. It is a relatively simple area to cover, not a particularly problematic surface area. I have collected their tears for your enjoyment imgur.com/a/iommu-judgem… and here is a video a 2PC DMA cheat dev has posted youtube.com/watch?v=IprU_G… This marks the end of 2PC DMA ATTACKS 2016-2025
YouTube video
YouTube
GamerDoc tweet mediaGamerDoc tweet media
English
109
68
1.2K
181K
Aidan Khoury
Aidan Khoury@aidankhoury·
@Ka11zer @riotgames #b-signature-requirements" target="_blank" rel="nofollow noopener">learn.microsoft.com/en-us/security… "Signatures using elliptical curve cryptography (ECC), such as ECDSA, are not supported in Windows and newer Windows security features. Users utilizing these algorithms and certificates will face various errors and potential security risks."
English
1
0
1
123
Riot Games
Riot Games@riotgames·
To close out the year, we take time to rest, recharge, and, naturally, queue up for some games. This downtime is part of our commitment to keeping Rioters energized, alongside our summer break and open paid time off. Of course, some teams like live operations, anti-cheat, and security will still be online, keeping things running smoothly. But don't worry, they'll get a well-earned break, too. GGWP, and we'll see you in 2025.
Riot Games tweet media
English
122
53
598
183.4K
Aidan Khoury
Aidan Khoury@aidankhoury·
@Ka11zer @riotgames That is 100% an OBS problem, there is not much Riot can do about that. Microsoft doesn't support ECDSA signed certificates like OBS decided to use, and probably never will. OBS needs to use an RSA certificate to sign their hook DLL like the rest of the industry.
English
1
0
1
126
Aidan Khoury
Aidan Khoury@aidankhoury·
@apekros @FeribHellscream One of the reasons for disapproval was because I couldn't prove the domain associated with the business entity was over a year old, Namecheap refused to provide sufficient information for me to provide Microsoft with.
English
1
0
2
179
Ferib
Ferib@FeribHellscream·
Fighting kernel AC? Just buy an EV Code Sign Signature they said, it be fun they said ferib.dev/blog/EV-code-s…
English
15
25
147
18.5K
brinly
brinly@brinlystorm·
@aidankhoury @number201724 @HexRaysSA But it wasn’t communicated that we would only get 8.4 support. Not sure how long you’ve been an IDA customer, but after 10 years of being a named licencee, I expect changes to be communicated, or pro rated refunded
English
2
0
0
126
brinly
brinly@brinlystorm·
This is bullshit. I paid for an IDA pro + 2 decompilers licence in June - with the usual system of upgrades for one year, then perpetual use after that. You should atleast honour perpetual use for people who have existing active licences. @HexRaysSA
brinly tweet media
English
13
10
105
27.8K
number201724
number201724@number201724·
@brinlystorm @aidankhoury @HexRaysSA Also, even though they are no longer selling perpetual licenses, they should at least give me a perpetually licensed IDA 9 during the maintenance period of the perpetual license.
English
1
0
1
85
Aidan Khoury
Aidan Khoury@aidankhoury·
@brinlystorm @HexRaysSA So if I understand correctly, you simply disagree with IDA being SaaS? Not sure how else they can migrate perpetual licenses to SaaS without doing this. If they give you perpetual IDA 9, then it wouldnt be fair to new SaaS licenses. What would you recommend they do?
English
1
0
0
101
brinly
brinly@brinlystorm·
@aidankhoury @HexRaysSA Yes, but we paid for updates/new features/versions when we paid for something with a year of support, not for “bug fixes only”. I’ve been a customer for like 10 years now and never had any of this crap before. I’ve back up my installers but trust is lost.
English
2
0
2
379
Aidan Khoury
Aidan Khoury@aidankhoury·
@zodiacon Sometimes Microsoft is late on releasing symbols for latest builds, but I've never seen PDBs missing types like this. Hopefully they upload new symbols. Windows 11 22H2 10.0.22621.607 still missing ntoskrnl symbols last I checked lol
English
0
0
7
283
Pavel Yosifovich
Pavel Yosifovich@zodiacon·
Does anyone have an issue with the kernel symbols for the latest Win10 update? It seems all types are gone - no EPROCESS, no LIST_ENTRY...?
English
4
1
16
3K
Aidan Khoury
Aidan Khoury@aidankhoury·
@UlfFrisk @dwizzzleMSFT @riotgames It's not so simple to just enforce HVCI on millions of gamer's machines, especially 5-6 years ago. But the tech is getting there, more and more PCs ship with virtualization and VBS/HVCI enabled nowadays!
English
0
0
3
388
Ulf Frisk
Ulf Frisk@UlfFrisk·
@dwizzzleMSFT @riotgames I released PCILeech DMA attacks 8 years ago. Gamers started abusing DMA around 5-6 years ago. It took them all these years to find out they can enable HVCI? 🐌🐢
English
4
0
18
2.1K
Aidan Khoury
Aidan Khoury@aidankhoury·
@davepl1968 A quick look in IDA with loaded symbols and they updated to use full paths that use expanded environment vars since then. There are 14 of them defined in a symbol called TmSpecialProcesses::CriticalProcessPaths
English
0
0
2
165
Dave W Plummer
Dave W Plummer@davepl1968·
Here's the code (circa XP) that determines whether or not you can kill a Windows process. Of course, you need to have sufficient rights, but if it's not in this list of 5 important processes, you can kill it. Task Manager goes to significant lengths to be able to kill a process, such as enabling the SE_DEBUG privilege. If there's sufficient interest, follow me for more Task Manager code trivia! BTW, this isn't open-source, it's just code they allowed me to share, and it's still under Microsoft copyright, etc...
Dave W Plummer tweet media
English
74
150
2.6K
263.8K
Petr Beneš
Petr Beneš@PetrBenes·
Is there a way how to manually trigger the whole Patch Guard routine? For, uh, reasons.
English
3
0
3
1.3K
Halogen
Halogen@halsgenein·
@ItsGamerDoc I'm a simple man. I see kernel level anything, I uninstall.
English
30
0
186
33.1K
GamerDoc
GamerDoc@ItsGamerDoc·
It's funny how cheaters are launching a large scale attack, farming impressions, and spreading misinformation, trying their best to get Vanguard removed. This has happened in Valorant as well. It's not going anywhere. We will protect the player experience and help everyone who has an incompatibility issue. The team is hard at work and will continue to work hard.
GamerDoc tweet mediaGamerDoc tweet mediaGamerDoc tweet media
English
103
97
1.3K
413.9K
Nick Peterson 🇺🇲 ✝️
Nick Peterson 🇺🇲 ✝️@nickeverdox·
fun little vmware backdoor will cause the guest to immediately enter a suspend state 🧐
Nick Peterson 🇺🇲 ✝️ tweet mediaNick Peterson 🇺🇲 ✝️ tweet media
English
7
26
191
43.6K
Aidan Khoury
Aidan Khoury@aidankhoury·
@Jeditobe The code is all there, it works, but the wine authors were not inclined to accept my test cases which used real blobs I extracted from Adobe's installer
English
1
0
0
75
Aidan Khoury retweetledi
Ryan K. Rigney
Ryan K. Rigney@RKRigney·
Helldivers 2 got review-bombed by players complaining about their anti-cheat, so I reached out to anti-cheat leaders from Riot Games, Roblox, and Fortnite to get their take. Are players over-reacting to kernel-level anti-cheat drivers? Full story: pushtotalk.gg/p/the-gamers-d…
English
55
135
769
281.1K