Results 1 to 1 of 1
  1. #1
    usernameee's Avatar
    Join Date
    Feb 2006
    Posts
    29
    Reputation
    10
    Thanks
    0

    Get around detection??

    ok i need hlp... i need a way 2 get around this detection process...

    "[It is constantly updated server-side and. It searches for DLLs loaded in memory used by common hacks.

    So, they can pretty much update when new hacks come out and detect/ban hackers uber fast now (over night)...
    Some info:

    I think the server sends 0xAE with a list of DLLs to look for in memory and then the client returns 0x66 which declares wether they were found or not and flags you for bannage.

    I think it also sends 0xB0 and drops you from the game if you don't return 0x66 (I think this is why people with multiclient were getting dropped)... "
    "Interesting reading here. As anything, if there's a way to be detected, there's a way to "not" be detected.

    We may even see a new generation of hacks here. Take Counter Strike / Day of Defeat. The original wall hacks were in the directory with the program. A DLL file, if you would. The next generation were in a different directory, still easily found due to variables. Then OGC came out with their 3 letter identifier. A "pre-variable" so to speak for the other variables. Then they made it a very long variable as someone found a decent way to scan quickly for the short (i.e. 3 char) ones.

    MH and D2JSP mighe even have to go to randomization. I.E. the injector program "writes" a random DLL file name, with other "random" data in it, so as not to be detectable via hashing or file name lists. The injector then injects this semi-randomly created DLL file into the game (or hooks, or whatever) then exits. The DLL is then responsible for checking to see if it's compromised.

    It might even get to the point (I don't know if njag or mousepad will go this far) as to returning false "clean" codes to Battle.net servers.

    There are a lot of options left open. It makes it harder that their client is in 2 way communication with the "mothership" however it can still be done. ]"

    All a giant quote from Subnormal... a member of rumkin.com (site that finds safe hacks (undetectable) and post the installs all in one place (convienent^^))
    Last edited by usernameee; 02-21-2006 at 10:22 PM.

Similar Threads

  1. [Detected] MAT automation 1.0.0.1 detect at cib
    By asdfg119714 in forum Mission Against Terror Discussions
    Replies: 17
    Last Post: 02-28-2011, 05:34 PM
  2. [Detected] Mat Automaton Detected Back 28/2/2011
    By afizie98 in forum Mission Against Terror Discussions
    Replies: 5
    Last Post: 02-28-2011, 04:44 AM
  3. [Detected] Lastest version of MAT Automaton had Detected by MAT China (16/2/2011)
    By yuzihao96 in forum Mission Against Terror Discussions
    Replies: 7
    Last Post: 02-19-2011, 06:55 PM
  4. [Detected] M.A.T Automaton detected !!!
    By amirraj123 in forum Mission Against Terror Discussions
    Replies: 21
    Last Post: 02-18-2011, 05:12 PM
  5. [Detected] AUTOMATON HAD BE DETECTED
    By shinygold in forum Mission Against Terror Discussions
    Replies: 3
    Last Post: 02-01-2011, 10:06 PM