ExclamationKernel Mode Game Hacking

Posts 16–23 of 23 · Page 2 of 2
Quote Originally Posted by javalover View Post
DNS cache has nothing to do with providers, it's managed from your computer's operating system or web browser. However, as developers are aware of it, a countermeasure is for sure at 98% implemented.
Yes it did, VAC used to scan and hash each entry and then compare them with a list of known provider's servers (the ones that were used for login, hardware check, etc)
Valve, VAC, and trust
These cheats phone home to a DRM server that confirms that a cheater has actually paid to use the cheat.

VAC checked for the presence of these cheats. If they were detected VAC then checked to see which cheat DRM server was being contacted. This second check was done by looking for a partial match to those (non-web) cheat DRM servers in the DNS cache. If found, then hashes of the matching DNS entries were sent to the VAC servers. The match was double checked on our servers and then that client was marked for a future ban. Less than a tenth of one percent of clients triggered the second check. 570 cheaters are being banned as a result.
Confirmed by Gabe Newell.
https://www.reddit.com/r/gaming/comm...vac_and_trust/
Quote Originally Posted by nullptr_t View Post
Yes it did, VAC used to scan and hash each entry and then compare them with a list of known provider's servers (the ones that were used for login, hardware check, etc)
Valve, VAC, and trust
Confirmed by Gabe Newell.
https://www.reddit.com/r/gaming/comm...vac_and_trust/ⓘ
He is not talking about any provider, and providers have nothing to do with the discussion/dns caches (provider stands for ISP or for a business which provides a service). He said that there are some DRM servers (this is how he calls them, which stands for servers containing a database useful for some access control) in which cheat programs connected to, in this case to limit the usage of the cheat to people who didn't pay for it. So VAC downloaded the DNS caches from the users and hashed them individually. Then all them get sent to VAC servers, and get checked by programmers one by one. Then every bad DNS gets blacklisted, and a future comparison between users' DNS caches with the blacklisted ones had to be done. A single match identified a ban.
However, I clinch with this:
DNS caches have nothing to do with providers, it's managed from your computer's operating system or web browser.
- - - Updated - - -

I'm not sure if for provider you meant DRM providers. If yes, in this case it's better to call them DRM servers.
Quote Originally Posted by javalover View Post
He is not talking about any provider, and providers have nothing to do with the discussion/dns caches (provider stands for ISP or for a business which provides a service). He said that there are some DRM servers (this is how he calls them, which stands for servers containing a database useful for some access control) in which cheat programs connected to, in this case to limit the usage of the cheat to people who didn't pay for it. So VAC downloaded the DNS caches from the users and hashed them individually. Then all them get sent to VAC servers, and get checked by programmers one by one. Then every bad DNS gets blacklisted, and a future comparison between users' DNS caches with the blacklisted ones had to be done. A single match identified a ban.
However, I clinch with this:


- - - Updated - - -

I'm not sure if for provider you meant DRM providers. If yes, in this case it's better to call them DRM servers.
By a provider I meant p2c companies, sorry for the inconvenience
Quote Originally Posted by nullptr_t View Post
By a provider I meant p2c companies, sorry for the inconvenience
I'm not sure of what you are talking about.
Quote Originally Posted by javalover View Post
I'm not sure of what you are talking about.
DRM servers.
Quote Originally Posted by javalover View Post
I'm not sure of what you are talking about.
Pay to Cheat Websites.
Website wich offer cheats in exchange for money.
Quote Originally Posted by RoPMadM View Post


Pay to Cheat Websites.
Website wich offer cheats in exchange for money.
And to be more specific; servers of those known premium cheat providers, which are used for databases/logins. You obviously dont get banned for visiting *******.net, but it's known database server used for clientlogin (such as ftp.aimwr.net/database.sql)
Quote Originally Posted by nullptr_t View Post
[SIZE=3
This requires no interfering with the target process from user mode; no opening handles, or any other sketchy stuff besides the ProcessId lookup (which can be done from kernel mode with PsSetLoadImageNotifyCallback if needed, or by just manually typing it to the controlling program.)
Actually, you do open a handle known as a "kernel handle". Kernel Object Handle Table is what would keep track of your kernel-level object such as process / driver.
As I assume you utilize KeStackAttackProcess for your memory rundown technique? Also, your device has something called a "symbolic link" aswell, it's known as a "symbolic link" for that aswell.

"A symbolic link is a file-system object that points to another file system object. The object being pointed to is called the target. Symbolic links are transparent to users; the links appear as normal files or directories, and can be acted upon by the user or application in exactly the same manner."

VAC can also access the handle table if wanting to, it's tedious and easy to look up any created symbolic links too.
Also VAC can if it wants, find the ObjectName of the device. It can also detect your driver via NtQuerySymbolicLinkObject function to retrieve your handle and target driver name.

So I mean, you're just throwing tantrums and guesses on what VAC is able to detect or not. User-mode rights doesn't essentially mean zero rights. VAC is also able to retrieve your device via Object Security Descriptor for each object created as all objects has one.

I mean, there are tons of attack vectors, a driver is sticky without protection.
Posts 16–23 of 23 · Page 2 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us