v3launcher Posted June 28, 2016 Share Posted June 28, 2016 k first of all sorry for a new account but the pw recovery doesnt work for me so i had to make a new account. here it is, notice the yuri gattling tank: copy and paste too lazy to get forum codes http://imgur.com/fiBHSMH now here you can see no one had yuri: http://imgur.com/GK24uON and here you can see proof crates where off: http://imgur.com/1EE4tV3 http://imgur.com/hNuPxID http://imgur.com/Y8nfk9u i didnt change the settings after the game ended. clearly ahmaddd cheats. Link to comment Share on other sites More sharing options...
v3launcher Posted June 28, 2016 Author Share Posted June 28, 2016 <snip> ^thats being used Link to comment Share on other sites More sharing options...
Grant Posted June 28, 2016 Share Posted June 28, 2016 Attached the map that was played for reference c48538ca99f71268456f31eff897942ce7836449.map Link to comment Share on other sites More sharing options...
Grant Posted June 28, 2016 Share Posted June 28, 2016 Banned the player, thanks for the link I've copied that safe for now. Link to comment Share on other sites More sharing options...
v3launcher Posted June 28, 2016 Author Share Posted June 28, 2016 http://imgur.com/vQVQGtX im sure its the same guy Link to comment Share on other sites More sharing options...
Iran Posted June 28, 2016 Share Posted June 28, 2016 The hack is something new and private, that's why it isn't blocked yet. Some guy is selling it so I'm waiting for the hack to be more common before releasing a fix (I already know how it works), so people will have wasted their money buying it. It works internally just look running a mod map and it works the same way as psylines and build everywhere hack, which I already block. I only need to add 4-6 more lines of anti-cheat to check and block this hack. Link to comment Share on other sites More sharing options...
v3launcher Posted June 28, 2016 Author Share Posted June 28, 2016 tbh that is just wasting the playerbase and actually saying hey the one that made this hack have some money before we block it out. you know we have like 300 players at cncnet. I dont think its wise to give the guy that made the hack the money so easely. Who knows he might even pay others with it to make a new one that sells for a little more. still waiting for mod approval after 24 hours? Link to comment Share on other sites More sharing options...
Ra2Nub Posted June 29, 2016 Share Posted June 29, 2016 The hack is something new and private, that's why it isn't blocked yet. Some guy is selling it so I'm waiting for the hack to be more common before releasing a fix (I already know how it works), so people will have wasted their money buying it. It works internally just look running a mod map and it works the same way as psylines and build everywhere hack, which I already block. I only need to add 4-6 more lines of anti-cheat to check and block this hack. While I see you trying make people pay for hacks that no longer will work, don't you think its worse you are giving the creator that created the hack more money? I would patch it as soon as you can so he can't make money out of a hack. Selling hacks is already a low go, and I think you should aim for the person gaining money out of it, not the idiots buying it. Good to hear you can patch it though. This is why CNCNet will always be much more ahead than xwis ever will. Link to comment Share on other sites More sharing options...
fir3w0rx Posted June 29, 2016 Share Posted June 29, 2016 While I see you trying make people pay for hacks that no longer will work, don't you think its worse you are giving the creator that created the hack more money? I would patch it as soon as you can so he can't make money out of a hack. Selling hacks is already a low go, and I think you should aim for the person gaining money out of it, not the idiots buying it. Good to hear you can patch it though. This is why CNCNet will always be much more ahead than xwis ever will. I think they want him to continue selling because it's easier to catch him that way. Plus, once it's patched out, it'll teach people a lesson for buying cheats. But what if this guy's only the runner for the drug/cheat dealer? Link to comment Share on other sites More sharing options...
SiRaLeX Posted June 29, 2016 Share Posted June 29, 2016 While I see you trying make people pay for hacks that no longer will work, don't you think its worse you are giving the creator that created the hack more money? I would patch it as soon as you can so he can't make money out of a hack. Selling hacks is already a low go, and I think you should aim for the person gaining money out of it, not the idiots buying it. I agree with what Ra2Nub says. The hack is something new and private, that's why it isn't blocked yet. [...] (I already know how it works), [...] It works internally just look running a mod map and it works the same way as psylines and build everywhere hack, which I already block. I only need to add 4-6 more lines of anti-cheat to check and block this hack. This sounds like it's you who made it. Besides, how do you know how psylines and build everywhere hacks work? Did you create them? If you know how it "works internally" as you put it, then you also know how to fix it. The fact you chose not to fix it is just plain wrong. You say "only need to add 4-6 more lines of anti-cheat", then do it - what is stopping you??? Eh? Seems highly suspicious to say the very least. Keep CnCNet cheat-free, for fucks sake, please. / Sorry for the little rant. I just hate it when people build dreadnoughts without battle lab and stuff like that. Link to comment Share on other sites More sharing options...
Ra2Nub Posted June 30, 2016 Share Posted June 30, 2016 This sounds like it's you who made it. Besides, how do you know how psylines and build everywhere hacks work? Did you create them? I ran a Private Server before (for different games) and just because a staff member know how hacks work doesn't mean he created them. Its very important as a staff member to know how things work, so you know also how to patch them. I still agree with you that the hack should be patched as soon as possible, but a staff member knowing how a hack works is only good. Link to comment Share on other sites More sharing options...
Iran Posted July 2, 2016 Share Posted July 2, 2016 I reverse engineered youre psylines and build anywhere hack for the anti-cheat.............that's why i know how it works. Link to comment Share on other sites More sharing options...
SiRaLeX Posted July 2, 2016 Share Posted July 2, 2016 I reverse engineered youre psylines and build anywhere hack for the anti-cheat.............that's why i know how it works. I doubt that you did.............nice reply tho. Nice screenshot. That's the screenshot I have taken 5 years ago. It's your screenshot. But, tell me how do psylines and build anywhere work. Link to comment Share on other sites More sharing options...
Iran Posted July 2, 2016 Share Posted July 2, 2016 Link to comment Share on other sites More sharing options...
SiRaLeX Posted July 2, 2016 Share Posted July 2, 2016 I've no idea what you're trying to show me there, but it doesn't make too much sense. What is "Write_Memory_??" aka .data:011222730, obviously the address is going to be different every time you start. It absolutely doesn't prove that you "know how psylines or build anywhere" work. Link to comment Share on other sites More sharing options...
Ra2Nub Posted July 2, 2016 Share Posted July 2, 2016 I've no idea what you're trying to show me there, but it doesn't make too much sense. What is "Write_Memory_??" aka .data:011222730, obviously the address is going to be different every time you start. It absolutely doesn't prove that you "know how psylines or build anywhere" work. He literally show you the memory addresses your trainer/hack writes to client... Also, why are you so cocky/protecting (what seems to be) your hacking tool? First you support in this thread you want the hacking tool (Build all) patched and now you waste the staff's time in proving proof how they patched your hacking tool. Sounds like a bit of a hypocritical twisted mind. Link to comment Share on other sites More sharing options...
Iran Posted July 2, 2016 Share Posted July 2, 2016 I attached a debugger and checked what Write_Memory was writing to in the game EXE and found what it was doing. Took like 30 minutes or so? Including removing the debugger check. Link to comment Share on other sites More sharing options...
SiRaLeX Posted July 2, 2016 Share Posted July 2, 2016 He literally show you the memory addresses your trainer/hack writes to client... Wrong. The only "address" he showed is 0x1122730, which is a randomized address. There's this neat thing called ASLR (address space layout randomization) which you don't seem to understand. If 0x1122730 was inside the executable then the hack would need to be more than 1 MB in size, which it is not, because 1 MB is 0x100000 or 1048576 for you "decimal plebs". I attached a debugger and checked what Write_Memory was writing to in the game EXE and found what it was doing. Took like 30 minutes or so? Including removing the debugger check. So what the fuck is this "Write_Memory"? There is no single function called or that can be called "Write_Memory" in the hack. What kind of "debugger check" are you talking about? I'm not buying into you removing any "debugger check". Link to comment Share on other sites More sharing options...
Iran Posted July 2, 2016 Share Posted July 2, 2016 Write_Memory was just some function which calls win32 API WriteProcessMemory(), and it writes into memory for elements in a heap class which is used by the game, a pointer to this heap is a global and located on the same memory address. Yuri's Revenge doesn't use ALSR, it's always loaded into its own address space at the same memory offset, hence why I can debug and patch Yuri's Revenge and other games by just checking the same memory locations. This isn't exactly rocket science. I removed the debugger check, checked what code is writing and reading memory and attached a debugger to check what it is reading from and writing too...same with all those other hacks. Link to comment Share on other sites More sharing options...
SiRaLeX Posted July 2, 2016 Share Posted July 2, 2016 You're an idiot. Write_Memory was just some function which calls win32 API WriteProcessMemory(), My hack calls WriteProcessMemory(), it's even fucking stated in its ReadMe file. Nice try, bro. Unfortunately you appear to be missing more than half of what's going on. and it writes into memory for elements in a heap class which is used by the game, a pointer to this heap is a global and located on the same memory address. Yuri's Revenge doesn't use ALSR, it's always loaded into its own address space at the same memory offset, Blahblahblah. It's ASLR not ALSR. And my hack uses ASLR itself, hence you showing some randomized address which doesn't make any sense anymore once my hack is restarted. Because the address you showed is clearly inside of my hack. So does my hack write to this "pointer to this heap is a global" bullshit or what? Actually I've never heard such a retarded statement, ever. Link to comment Share on other sites More sharing options...
Iran Posted July 2, 2016 Share Posted July 2, 2016 Yes hence I used the debugger and hooked the import address for WriteProcessMemory...as it doesn't change. Link to comment Share on other sites More sharing options...
SiRaLeX Posted July 2, 2016 Share Posted July 2, 2016 Dude, your screenshot is random garbage. According to you this one function "Write_Memory_??" does: F3 Show And Hide Radar F2 Reveal And Reshroud Hotkey Use Aegis Style Reshroud Reshroud Fog Reshroud Fog With Shroud Edge Show Psychic Lines On Reveal Repair Any Building Build Anywhere That's not how it works. And "Write_Memory_??" isn't WriteProcessMemory because WriteProcessMemory isn't in .data, nice try though. Link to comment Share on other sites More sharing options...
Iran Posted July 2, 2016 Share Posted July 2, 2016 Pretty sure this is the import table for your application Link to comment Share on other sites More sharing options...
SiRaLeX Posted July 2, 2016 Share Posted July 2, 2016 Pretty sure this is the import table for your application Yes it is. Was it hard to find it? It's super hard to find an Import Table, isn't it? Pretty much any tool under the sun tells you the imports with just 1 click. The Import Table isn't a secret, anyone can read it. Seems to be quite an achievement for you though. Also in this screenshot you cut off "WriteProcessMemory" it says 0111402C. In your last screenshot 011222730 was "Write_Memory_??". Seems like you're having a tough time. Do you need some help? Link to comment Share on other sites More sharing options...
Nyerguds Posted July 25, 2016 Share Posted July 25, 2016 Good lord you're an idiot. When disassembling stuff, original function names are no longer there, since it's a compiled exe, not source code. Names like that no longer matter or exist in the final compiled bytecode, so he just gave these functions comprehensible names after looking into them to see what they did. Anyway, this idiocy has gone on long enough. You're a cheating bastard and I have no clue why you haven't already been banned from this place forever. Locked. Link to comment Share on other sites More sharing options...
Recommended Posts