ThreateningYeti icon indicating copy to clipboard operation
ThreateningYeti copied to clipboard

Not working on latest version

Open free-ppl opened this issue 4 years ago • 18 comments

Hello I am trying out ThreateningYeti on my Windows desktop with the latest version of Responsus Lockdown Browser (2.0.6.06). It does not seem to be working, pressing alt-tab doesn't let me change app and my secondary monitor is also completely covered by a blank window, will you be fixing this any time soon? Is it working for anybody running the latest version of the browser?

free-ppl avatar May 28 '20 11:05 free-ppl

Exactly not working in my case error 0 first and then in second screen of Treating yeti error hooking check foreground window function. Best

escipion44 avatar May 28 '20 13:05 escipion44

doesnt work at all for last version.

aliveli4597 avatar May 28 '20 13:05 aliveli4597

Yeti Loader doesn't work with Lock Down Browser 2.0.6.06 version please update the patch.

doopse avatar May 29 '20 07:05 doopse

If you could update it before 03/06, i would really appreciate it because that's when i will need it for my exams.

ov0295 avatar May 29 '20 15:05 ov0295

It looks like respondus indeed 'tried harder' on this update. 2.0.6.06 was released on 14th of May.

aliveli4597 avatar May 30 '20 20:05 aliveli4597

I got the "error hooking checkforeground window function" when I tried to use it. Then it quits.

aliveli4597 avatar May 30 '20 20:05 aliveli4597

yep, it doesn't seem to work for the 2.06.06 version. I tried to do a downgrade but there are forced autoupdates.

mxelm avatar May 31 '20 16:05 mxelm

is having the same issues with mine too any updates for a new one?

ShadowSoulja avatar Jun 01 '20 21:06 ShadowSoulja

@melotic sir, would you mind to have an update?

stupidoge avatar Jun 18 '20 15:06 stupidoge

Latest executable (.06) has been obfuscated.

stokdam avatar Jun 19 '20 09:06 stokdam

@stokdam how to solve it? Would you mind to help us?

stupidoge avatar Jun 19 '20 09:06 stupidoge

Yes, 2.0.6.06 has been packed, but I've easily unpacked it. I don't have much time to update this project as much since I now have a full-time job, but I'll get this rolling again in the fall semester.

melotic avatar Jun 19 '20 12:06 melotic

Yes, 2.0.6.06 has been packed, but I've easily unpacked it. I don't have much time to update this project as much since I now have a full-time job, but I'll get this rolling again in the fall semester.

@melotic we really appreciate that you give us an opportunity to get over difficulties in exam. You have lots of fans not only in US, but also all over the world. Students not at US are still at exam period. So, there are lots of students who cannot bypass LBD in their final exam. I really respect and admire your enthusiasm in this project.

I would appreciate it if you can have a last update for 2.0.6.06. If you don't have time, no worry. we will try our best to get over online exam.

I think your talent will make you perform exceptioanlly well in your work. Wish you all good!

Yours, Kai

stupidoge avatar Jun 19 '20 12:06 stupidoge

Yes, 2.0.6.06 has been packed, but I've easily unpacked it. I don't have much time to update this project as much since I now have a full-time job, but I'll get this rolling again in the fall semester.

How did you unpack it? I don't think it's a matter of packing. Every function has been cut in pieces and all the piece connected with jmp. There is a huge amount of junk code, and I've seen many call instructions replaced with

push retn

The disassebler gets very confused and is not able to recognize function bodies.

stokdam avatar Jun 19 '20 13:06 stokdam

With a nice script that using unicorn to emulate the binary and eliminate dead code and restore calls. This is all unneeded anyway, the cookie handshake is easily replicable with a chrome extension and the vm detection is easily bypassed.

On Fri, Jun 19, 2020 at 9:16 AM stokdam [email protected] wrote:

Yes, 2.0.6.06 has been packed, but I've easily unpacked it. I don't have much time to update this project as much since I now have a full-time job, but I'll get this rolling again in the fall semester.

How did you unpack it? I don't think it's a matter of packing. Every function has been cut in pieces and all the piece connected with jmp. There is a huge amount of junk code, and I've seen many call instruction replaced with

push retn

The disassebler gets very confused and is not able to recognize function bodies.

— You are receiving this because you were mentioned.

Reply to this email directly, view it on GitHub https://github.com/melotic/ThreateningYeti/issues/37#issuecomment-646629830, or unsubscribe https://github.com/notifications/unsubscribe-auth/AGGSWISZ6SO2BSDJZQSILELRXNQIZANCNFSM4NNAKBYA .

melotic avatar Jun 19 '20 13:06 melotic

With a nice script that using unicorn to emulate the binary and eliminate dead code and restore calls. This is all unneeded anyway, the cookie handshake is easily replicable with a chrome extension and the vm detection is easily bypassed. On Fri, Jun 19, 2020 at 9:16 AM stokdam @.***> wrote: Yes, 2.0.6.06 has been packed, but I've easily unpacked it. I don't have much time to update this project as much since I now have a full-time job, but I'll get this rolling again in the fall semester. How did you unpack it? I don't think it's a matter of packing. Every function has been cut in pieces and all the piece connected with jmp. There is a huge amount of junk code, and I've seen many call instruction replaced with push retn The disassebler gets very confused and is not able to recognize function bodies. — You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub <#37 (comment)>, or unsubscribe https://github.com/notifications/unsubscribe-auth/AGGSWISZ6SO2BSDJZQSILELRXNQIZANCNFSM4NNAKBYA .

They added a new VM check in respondus monitor

stokdam avatar Jun 19 '20 14:06 stokdam

Yes, 2.0.6.06 has been packed, but I've easily unpacked it. I don't have much time to update this project as much since I now have a full-time job, but I'll get this rolling again in the fall semester.

@melotic
Sir, you said you easily unpacked 2.0.6.06. Would you mind to update for version 2.0.6.06 one more time? I urgently need yeti and your help! Without your yeti's help, I will fail my exam and cannot go to my graduate school.😭😭😭😭 I really hope all your work are well done becuase of your talent.

yitiaogou-zkk avatar Jun 20 '20 14:06 yitiaogou-zkk

Yes, 2.0.6.06 has been packed, but I've easily unpacked it. I don't have much time to update this project as much since I now have a full-time job, but I'll get this rolling again in the fall semester.

@melotic Sir, you said you easily unpacked 2.0.6.06. Would you mind to update for version 2.0.6.06 one more time? I urgently need yeti and your help! Without your yeti's help, I will fail my exam and cannot go to my graduate school.😭😭😭😭 I really hope all your work are well done becuase of your talent.

no worry, bro. I have a test in two days. Although author easily unpacked, I think he is so busy. As long as he has time, he will upload. You can wait patiently and prepare for the worst result.(maybe he won't update for version.06) until fall semester.

stupidoge avatar Jun 21 '20 08:06 stupidoge