Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there some way to do this work of memory hacking from OUTSIDE the VM? I've always thought that it would be "safer" to do the work by just being able to scrub the hosts side of VirtualBox, then stuff events back in through the keyboard and mouse rather than getting on the inside of the VM and hooking/injecting inside the target executable.


There are libraries such as memflow[0] that let you have DMA to vm using KVM. Though be warned, it's a lot more complicated then injecting a dll or using cheat engine.

[0] - https://memflow.github.io/#/home


Sure, this is sometimes done using hardware with host memory access / DMA support, like PCIeScreamer type PCIe cards. This is also used for network level exploits when there's some kind of ephemeral or negotiated encryption key at play.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: