Files
plex-docker/Freeloader/docs/WINDOWS.md
T
benjamin 72f4661bdc Replace patchelf crack with Freeloader LD_PRELOAD approach
- Multi-stage Dockerfile: discover patterns from PMS binary (capstone),
  compile .so with zig (musl), layer onto lscr.io/linuxserver/plex
- Uses LD_PRELOAD instead of patchelf (which corrupts Plex's musl loader)
- Auto-discovery: broad structural patterns with string-anchored fallback
  (//feature) and relationship-based fallback (BITSET_REF within BS_INIT)
- hook.cpp uses __has_include for generated patterns with hardcoded fallbacks
- Custom wrapper.sh (no traffic_logger preload)
- Vendored Freeloader source (github.com/authrequest/Freeloader, AGPL-3.0)
- Removed stale plexmediaserver_crack.so binary
- Supports Plex 1.43.3+ (verified against 1.43.2 and 1.43.3)
2026-08-19 22:33:42 +02:00

1.7 KiB

Windows patching guide

Top-level index for the Windows x64 Plex Media Server work in this repo.

What exists

The Windows implementation lives in ../windows/ and contains:

  • plex_patch.dll — injected payload that forces the feature bitset on
  • plex_inject.exe — injector that attaches to or launches Plex Media Server.exe
  • a small engine split into:
    • pe_image.h — PE parsing, section bounds, RVA resolution, version guard
    • sig_scan.h — byte-pattern scanning helpers
    • trampoline.h — Zydis-based x64 inline hook engine
    • feature_patch.h — bitset forcing, populator hook, guard thread

Current target

Pinned to:

  • Plex Media Server 1.43.2.10687-563d026ea
  • Platform: Windows x64

The patch uses a version guard and bounds-checked RVA resolution before it touches the target process.

Build

From windows/:

build.bat

This produces:

  • build\plex_patch.dll
  • build\plex_inject.exe

The build reuses the repo's vendored Zydis and Zig toolchain conventions.

Run

Attach to a running PMS:

build\plex_inject.exe

Or launch PMS through the injector:

build\plex_inject.exe --launch "C:\Program Files\Plex\Plex Media Server\Plex Media Server.exe"

Notes

  • windows/build/ artifacts are intentionally git-ignored.
  • The original incompatible .i64 was left untouched; the working Windows IDB was rebuilt in a writable analysis directory during RE.