Author Topic: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)  (Read 98458 times)

Offline PANTONE 7717C

  • Swanky Member
  • *****
  • Posts: 565
    • View Profile
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #75 on: December 19, 2006, 05:07:58 PM »
the dll isn't made for any of the new anticheats, there is NO WAY for me to use it on ts.

Yes you can use it on ts, unless you're using a valid anticheat.dll client.  You can use it with plain r1q2 (without anticheat.dll), you can use it with 3.20, you can use it with frkq2 (that emulates NoCheat), etc. etc. etc.



Are you saying that under those circumstances you can use a cheat on ts without getting the "MZ exec" message? Or that you'll get that message but technically you can keep using it till someone takes action?
If this dude speaks the truth which I doubt he shouldn't have renamed the dll to something standard but he should've removed that dll and if he had loaded it earlier, rebooted first before playing right? I never got the impression he was walling but why rename it to something standard if you use it to watch demos...
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

Remedy

  • Guest
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #76 on: December 19, 2006, 05:10:16 PM »
so do we know he was using it in game?

well the way i understand it from this is that he had to use the command "gl_modlate" to toggle it off or on, as it was always loaded ready for use

what I would like to see is a search done of all the logs on ts for that command, to see who was using it
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

Offline randypants

  • Sr. Member
  • ****
  • Posts: 322
  • Damnit Bobby!
    • View Profile
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #77 on: December 19, 2006, 05:31:29 PM »
:D <3 Panjoo.....


Offline console

  • Brobdingnagian Member
  • ***
  • Posts: 4518
  • "Man, this is the way to travel," said my attorney
    • View Profile
    • tastyspleen.net
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #78 on: December 19, 2006, 05:38:10 PM »
Are you saying that under those circumstances you can use a cheat on ts without getting the "MZ exec" message?

The MZ message only reveals the _existence_ of a file.  Everybody would MZ if we scanned for ref_gl.dll.


what I would like to see is a search done of all the logs on ts for that command, to see who was using it

Can't.  It's a client-local command.  It doesn't get sent to the servers, so it doesn't appear in the logs.


There's no way I'm aware of to prove whether Granny ever enabled the wallhack during a game.  All we know for sure, is it was his default OpenGL renderer, and it was loaded when he connected with r1q2+anticheat.dll.



Regards,

:shifteyes:
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

Offline krez

  • Swanky Member
  • *****
  • Posts: 617
  • Come and get nadeclOWNED, nubsauce!!!11
    • View Profile
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #79 on: December 19, 2006, 06:15:32 PM »
It was his default open gl renderer and is not an old hack, its a new one.  This queer should be banned for a while, with some extra time added for being such a douche trying to deny it.
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus
Krez stfu i admit u owned me with 3 times my ping i dont deny the truth.

Offline PANTONE 7717C

  • Swanky Member
  • *****
  • Posts: 565
    • View Profile
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #80 on: December 19, 2006, 07:23:36 PM »
The MZ message only reveals the _existence_ of a file.

OK that's what I thought. But shouldn't that be: When you're not using anticheat the MZ message can only reveal the _existence_ of a file(?)

So let me see. If you don't use anticheat and have;
- a bad file in your folder but it is not loaded as your default renderer (you forgot to take it out) -> MZ msg only
- a bad file in your folder and it is loaded as your default renderer (in other words you're cheating) -> MZ msg only

Now that would mean that as soon as someone gets the MZ message (and doesn't use anticheat) there's no way to tell for sure he was not using it. So, when someone goes "MZ" while being on the server and then claims "but it's not loaded, I only use it to watch demos", it's a weak excuse because it could just as well mean he is/was in fact using it.

But if you do use anticheat and have bad files laying around you'll get kicked from the server, loaded or not?
I'm guessing only when loaded and if that's so then there's no reason for him to deny it. If it got loaded by quake2 itself because he had renamed it then that's his own fault.

  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

Offline reaper

  • Opulent Member
  • *
  • Posts: 2872
  • Nice night for a walk, eh? - Nice night for a walk
    • View Profile
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #81 on: December 19, 2006, 07:55:29 PM »
if he was playing quake and could just type a command to cheat:
he would be kicked by the server most of the time with the nc_visibility check?
i take it , this isn't recorded or logged. 
« Last Edit: December 19, 2006, 08:09:39 PM by reaper »
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus
VaeVictus "reaper is a lying sack of shit and ragequit then had, probably slugs, come alias and beat me, wasnt even the same person playing OBVIOUSLY, accuracies basicly doubled, and strategy

Offline R1CH

  • Sr. Member
  • ****
  • Posts: 341
    • View Profile
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #82 on: December 19, 2006, 08:11:42 PM »
But if you do use anticheat and have bad files laying around you'll get kicked from the server, loaded or not?
I'm guessing only when loaded and if that's so then there's no reason for him to deny it. If it got loaded by quake2 itself because he had renamed it then that's his own fault.

Nice try.  But unlike our rcon scans, anticheat.dll doesn't report files sitting in your q2 folder.  It only reports files you ACTUALLY HAVE LOADED.

rcon scan simply checks for presence of files, regardless if you're using anticheat or not.

anticheat only checks for stuff that's actually loaded.

Whether the wallhack was actually activated or not, no one but Granny knows. All I can say is that it was loaded and available at the press of a key.
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

Offline randypants

  • Sr. Member
  • ****
  • Posts: 322
  • Damnit Bobby!
    • View Profile
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #83 on: December 19, 2006, 08:26:53 PM »
if he was playing quake and could just type a command to cheat:
he would be kicked by the server most of the time with the nc_visibility check?
i take it , this isn't recorded or logged.

Remedy

  • Guest
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #84 on: December 19, 2006, 08:54:57 PM »
what I would like to see is a search done of all the logs on ts for that command, to see who was using it
Can't.
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

Offline reaper

  • Opulent Member
  • *
  • Posts: 2872
  • Nice night for a walk, eh? - Nice night for a walk
    • View Profile
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #85 on: December 19, 2006, 09:04:50 PM »
Quote from: console
Note, your wallhack isn't sophisticated enough to get around the server-side anti-wallhack measures (sv_nc_visibilitycheck) when we have those turned on.
« Last Edit: December 19, 2006, 09:11:00 PM by reaper »
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus
VaeVictus "reaper is a lying sack of shit and ragequit then had, probably slugs, come alias and beat me, wasnt even the same person playing OBVIOUSLY, accuracies basicly doubled, and strategy

Offline KaiTech

  • Newbie
  • *
  • Posts: 38
    • View Profile
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #86 on: December 19, 2006, 09:21:58 PM »
KICKBAN  END OF TOPIC :rockon:
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus
I'll spout simplistic opinions for hours on end.
Ridicule anyone who disagrees with me,
and generally foster divisiveness,
cynicism and lower level of public dialog!

Offline console

  • Brobdingnagian Member
  • ***
  • Posts: 4518
  • "Man, this is the way to travel," said my attorney
    • View Profile
    • tastyspleen.net
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #87 on: December 19, 2006, 09:27:06 PM »
:dohdohdoh:  Well it seems we should probably hold some kind of seminar or symposium on how the various cheat detection methods work.  On the other hand, before anticheat.dll, we didn't want to talk about the scans much because if you know how they work, you can avoid many of them.  (That's why I've always said, the scans are good for catching newbies, and that's about it.)

Anyway: sv_nc_visibilitycheck doesn't _detect_ wallhacks, it just makes simplistic wallhacks not work.  (It is technically possible to code a wallhack to work in spite of sv_nc_visibilitycheck 1, however I'm not sure any such have been coded or not.)

As for anticheat.dll, it's more sophisticated.  It didn't just spot Granny's wallhack because it was a different filesize, although that's the general idea.  Instead, it analyzes the binary machine code instructions of modules loaded into the quake2 process space, computing cryptographic hash signatures of the binary code, that can be compared against a white list of known good, or black list of known bad modules.  (At least that is my present understanding, based on discussions with r1ch.)  So, that is how r1ch knew it was the badsoul wallhack, before Granny sent us the file.

. . . Not sure if I'm making things more clear, or less clear, with these attempts at explanation...  :D


Regards,

:afro:
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

Offline console

  • Brobdingnagian Member
  • ***
  • Posts: 4518
  • "Man, this is the way to travel," said my attorney
    • View Profile
    • tastyspleen.net
  • Rated:
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #88 on: December 19, 2006, 10:23:08 PM »
if he did always have that as his file, the check would kick him.  .  so you would think he didn't try it on the servers. i presume it doesn't log that. i don't think it matters what client you use - the server just has that protection?

do you really think he was just always trying that command, even though he might think he would get logged/kicked?

Just in case it wasn't clear from what I wrote in the previous post... None of the scans or checks (except for anticheat.dll) would have kicked for the ref_gl.dll wallhack, whether it was turned on or not.


Regards,

:!: :!: :?:
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

Remedy

  • Guest
Re: anticheat: RiDiX caught wallhacking (badsoul ref_gl wh)
« Reply #89 on: December 19, 2006, 10:24:29 PM »
I see

;D

sounds like its a step up from what bryce did with nocheat
  • Insightful
    Informative
    Funny
    Nice Job / Good Work
    Rock On
    Flawless Logic
    Well-Reasoned Argument and/or Conclusion
    Demonstrates Exceptional Knowlege of the Game
    Appears Not to Comprehend Game Fundamentals
    Frag of the Week
    Frag Hall of Fame
    Jump of the Week
    Jump Hall of Fame
    Best Solution
    Wins The Internet
    Whoosh! You done missed the joke thar Cletus!
    Obvious Troll Is Obvious
    DO YOU EVEN LIFT?
    DEMO OR STFU
    Offtopic
    Flamebait
    Redundant
    Factually Challenged
    Preposterously Irrational Arguments
    Blindingly Obvious Logical Fallacies
    Absurd Misconstrual of Scientific Principles or Evidence
    Amazing Conspiracy Theory Bro
    Racist Ignoramus

 

El Box de Shoutamente

Last 10 Shouts:

 

RyU

September 03, 2024, 05:15:49 PM
And wow Derrick is still playing lol
 

RyU

September 03, 2024, 05:15:15 PM
Just know yesterday is gone and soon tomorrow will be gone too  :)
 

Lejionator

August 08, 2024, 07:28:01 PM
It's tiem to QuakeCon!!!  ;)

https://www.youtube.com/watch?v=ThQd_UJaTys
 

ImperiusDamian

July 26, 2024, 09:34:53 PM
In nomine Quake II et Id Software et Spiritus John Carmack, Amen.
 

QuakeDuke

July 26, 2024, 05:10:30 PM
Hey, shout, summertime blues
Jump up and down in you blue suede shoes
Hey, did you rock and roll? Rock on!!  ...QD
 

Yotematoi

July 24, 2024, 01:31:20 PM
Ayer me mato 5 veces para robarme en la vida real hará lo mismo? [img]<iframe src="https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid0wXU2VgS7atesBcSoMz5BWMJCJajeZFVT6GzSU6TtpJGddN9kLTvWNgcZaskkbKFQl&amp;show_text=true&amp;width=500
https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid0wXU2VgS7atesBcSoMz5BWMJCJajeZFVT6GzSU6TtpJGddN9kLTvWNgcZaskkbKFQl&show_text=true&width=500" width="500"
 

Yotematoi

July 24, 2024, 01:25:59 PM
hi ya está la basura de Martin, se cambió el nombre es un ladron estupido, asi llegó a 10000[img]<iframe src="https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid03hZrkDUBJPZKCuFgy5hRUy831ekKJYVRzC7ajXaKQbJ6xcPgKftLukUDfovFyEq3l&amp;show_text
https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid03hZrkDUBJPZKCuFgy5hRUy831ekKJYVRzC7ajXaKQbJ6xcPgKftLukUDfovFyEq3l&show_text
 

Yotematoi

July 24, 2024, 01:25:59 PM
hi ya está la basura de Martin, se cambió el nombre es un ladron estupido, asi llegó a 10000[img]<iframe src="https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid03hZrkDUBJPZKCuFgy5hRUy831ekKJYVRzC7ajXaKQbJ6xcPgKftLukUDfovFyEq3l&amp;show_text
https://www.facebook.com/plugins/post.php?href=https%3A%2F%2Fwww.facebook.com%2Fzoloyoze.torito%2Fposts%2Fpfbid03hZrkDUBJPZKCuFgy5hRUy831ekKJYVRzC7ajXaKQbJ6xcPgKftLukUDfovFyEq3l&show_text
 

-Unh0ly-

July 05, 2024, 05:20:36 AM

Show 50 latest
Welcome, Guest. Please login or register.
September 20, 2024, 04:36:48 AM

Login with username, password and session length