29 ms·
How anti-cheats catch cheaters using memory heuristics
- kgwxd 7y agoBy installing spyware.
- saagarjha 7y agoI wouldn't call this spyware; it doesn't seem to reach outside of its own process (though I guess it does report back what you could call analytics).
- nneonneo 7y agoBattlEye apparently comes with a kernel component called BEDaisy which preemptively tries to block attempts to patch Windows API functions. That has some people calling it a root kit or spyware.
- Red_Leaves_Flyy 7y agoMany long running undetected game hacks use kernel hooks. If the hack runs before the anti cheat or with higher privileges then the anti cheat is just a resource hog.
- m4rtink 7y agoHaving a game that fumbles with kernel internals is insane. That should simply be not possible privilege wise.
- mike_hock 7y agoIt sends a memory dump, which could contain the player's credentials (or fragments thereof) in plaintext.
- dspillett 7y agoI'm sure some of it does extend beyond the relevant processes. Back in 2005/2006 Sony where installing rootkits on PCs: https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk... - this is why to this day I try make sure very little with "Sony" printed upon it touches my network. IIRC the best we got by way of an apology was "we are sorry Sony BMG embarrassed the group by getting caught" and "we promise not to do exactly the same thing again in the near future" (weasel words that meant they could do other equally crappy things immediately and as now is not the near future from then that could do the same thing now without breaking their word). That was to try to protect content in audio CD tracks by breaking things that might allow copying, I'm sure similar methods can be (and probably have been) used to try block game cheats too.
- saagarjha 7y agoOh sure, in general these kinds of things tend to be bordering on malware. But this specifically doesn't seem to be too horrible.
- ARandomerDude 7y agoSerious question for you gamers out there: Why would a person go to such great lengths to cheat at a video game? Is there a monetary incentive? Otherwise, it seems like a lot of effort just to increase one's standing on a leader board.
- wmil 7y agoYoung men seem driven to compete for little reward. There's no need to try to intellectualize it.
- moftz 7y agoAny kind of competition can have real rewards at the highest levels. Many people like shooting their friends in paintball on the weekend with rented gear but there is also a professional level where there is real money and sponsorships available. Many male animals will engage in some sort of competition, sometimes with rewards and risks (mates, food, death) and sometimes just for play. It's ridiculous to act like competitive online gaming is any different from puppies rough housing or from lions fighting over leadership of the pride. No one is going to die but gaming could just be something fun to do after being at work all day or it could be what puts food on the table.
- krageon 7y ago> Young men Why make this a gender thing?
- beaker52 7y agoProbably because it doesn't outwardly appear to affect young women so much? People should be able to make such observations.
- gizmo686 7y agoAs someone who likes to cheat at single player video games, the cheating itself is a lot of fun (at least it was until I started doing reverse engineering professionally; now it just feels like work). My sense of the multiplayer cheating scene (which I never looked at closely) is that most of the cheaters use tools developed by others. So, it seems possible that the people doing the bulk of the work are motivated in part by the technical challenge (including the cat and mouse aspect of it), and the social proof that comes along with sharing their cheats. Once the cheats are out there, using them has a much lower barrier to entry.
- saagarjha 7y agoWhat I don't understand is why the cheats can't just prevent the shellcode from running, or preempting the exception handler from being called by installing their own. Is spoofing the return of NtQueryVirtualMemory not possible, either?
- phire 7y agoIf the shellcode doesn't run, then it can't respond to the server's challenge-response query. And the server knows the user is cheating.
- saagarjha 7y agoI didn't see a challenge-response in the code presented. If there is one then I guess that would help in this scenario.
- nneonneo 7y agoIt doesn’t really even have to be a real challenge-response since the server controls the shellcode. Just have the shellcode unconditionally submit something (maybe a value that requires a minimum amount of computation or WinAPI sanity checks). If you don’t run that bit of code, down comes the ban hammer.
- deleted 7y ago[deleted]
- Mathnerd314 7y agoThere's an emulator: https://github.com/vmcall/battleye_emulation/blob/master/battleye_emulation/emulator.cpp https://github.com/vmcall/battleye_emulation/blob/master/bat... Apparently it sends 2 packets over the pipe and disables the anti-cheat completely. That's been patched but presumably it wouldn't be too hard to expand the emulator to handle the patch.
- mike_hock 7y agoSo those games put infrastructure in place for the server to execute arbitrary code on my machine? No, thanks.
- cortesoft 7y agoYou bought a game from them... you are already letting them run arbitrary code on your machine.
- mike_hock 7y agoThe original game code, as well as automatically installed updates can be vetted and compared to other installations. Any malware injected into either of them risks being exposed over time. This allows the server to execute arbitrary, ephemeral code fragments on any client at any time, with no trace. If the server is ever compromised, so are all clients, instantly. This is absolutely insane from a security POV. Just because I gave you a program once that you're using doesn't mean that you want to give me an SSH login to your machine.
- cortesoft 7y agoWhat is to stop them from sending an update only to you? Followed by an update that deletes that code? Or an update that allows them to run arbitrary code sent from a server? I think you overestimate the ability for this to be detected. These aren't open source.
- smileybarry 7y agoSome games -- recently Overwatch -- send hotfixes as live hotpatches. Those couldn't be scrutinized by anyone except the developer until they're included in the next formal patch.
- jcranmer 7y agoYou say that like people aren't capable of converting the current memory space back into an executable.
- pastrami_panda 7y agoSpeaking in terms of fps games I believe it to be very easy for any human to detect aimbots when reviewing gameplay footage. Wallhacks are a bit trickier to detect, and probably requires longer reviews, but I'd estimate that above average players could quite accurately detect this hack as well. This leads me to believe this should be quite a good fit for machine learning, no? It just seems like a problem that lives in that space of "It's hard to define but I sure can tell when I see it" - which ML seems to excel in?
- mantap 7y agoBy that logic you could also use AI to create an undetectable aimbot that mimics a very good human player.
- rhodo 7y agoYou definitely could
- Red_Leaves_Flyy 7y agoSteam has done this. http://www.kitguru.net/gaming/matthew-wilson/valve-to-use-machine-learning-to-detect-csgo-cheaters/ http://www.kitguru.net/gaming/matthew-wilson/valve-to-use-ma...
- wayneftw 7y agoHow long until you can point another computer at your game pc or console, to play for you? That’s game over for anti-cheat IMO.
- Topgamer7 7y agoOr you just write your own game client like china has been doing for WoW for ages.
- yutuytuyt 7y agoIt doesn't sound so good Client v1 sends packet A for command Attack So does China Client v1 Developer updates client to v2 and now packet A is non-existent, so no legit user is going to send it so after patch everyone who sends packet A can be banned
- penagwin 7y agoThis is currently already the case for cheats. When the game updates then the cheat needs to be updated as well. And you can definitely catch cheaters with the method you mentioned, so many cheats check the game version before doing anything. This means immediately after an update many cheats stop working until they’re updated (or their creator flags the new game version as compatiable)
- neodymiumphish 7y agoI wonder how much success there's been in hiding the version information from visibility by any software... Obviously the cheat developer could just hash the game files directly and halt if there's a discrepancy between the known-vulnerable versions, but it'd be interesting to see whether that was tried with any highly-cheated-in games.
- jotm 7y agoYou can already do that. Rooted phone with auto tapping/actions connected as a normal keyboard/mouse. Nothing to be detected on the host, works for dumb grinding which is prevalent in many ~~virtual casinos~~ games
- m4rtink 7y agoHeavy duty sandboxing of game software can't come quickly enough. Game software reading arbitrary memory outside of its own on a machine is half step from outright malware and must stop.
- AWildC182 7y agoThat's not how computers work. If you own the OS, you can do whatever you want and the game software is subject to the whims of your universe. The closest you can come is with "consoles" where you just attempt to prevent everyone from running code other than yours.
- crazygringo 7y agoSandboxing prevents code from getting out of a sandbox. It doesn't prevent outside code (i.e. your cheat software) getting in. As long as you control the computer running the sandbox, you can have it do whatever you want.
- neodymiumphish 7y agoYeah, but I think his issue is with the anti-cheat software. If the anti-cheat is sandboxed, it can't see any other memory or processes that are running. It's a fair privacy concern.
- m4rtink 7y agoThis is what I mean - putting the game and all it's "anticheat" malware into a sandbox, so it has not chance to interact with the rest of the system for privacy and security reasons.
- M-11 7y agoI write bots for older MMOs so I can do group content to make a game playable when you can't get a group big enough to do the content you need. Sometimes taking a break from a game you want to do old content that needs a party and no one is interested or you can't play at consistent times to be able to get static groups.
- Shivetya 7y agowell this sent me down a rabbit hole that is utterly fascinating. with regards to cheating, I understand the need to present a fair playing experience to all customers but as with anything else, people are the one variable we have the least control over and with the numbers games as with any service have to deal with you are guaranteed to get bad actors. the simple avoidance to those who see this is spyware/etc is not you play. I do not see this choice as a bad one. for some it is abhorrent but for others playing where cheaters have free reign is just as abhorrent. so unless you can fix people you choose what you are willing to accept
- TeMPOraL 7y ago> the simple avoidance to those who see this is spyware/etc is not you play. I do not see this choice as a bad one. for some it is abhorrent but for others playing where cheaters have free reign is just as abhorrent. Problem is, it's all-or-nothing. I'd be better if games could be sandboxed, so that its cheat-prevention spyware doesn't leak to the rest of the system. But I suppose the practical answer to that would be, "buy a console".
- mnowicki 7y agoHow hard would it be to just copy and modify the packets being sent to the anti-cheat servers? Are they sent directly to the anti-cheat server or do they go back to the game server first and then get forwarded from there?
- sevenf0ur 7y agoThat's the first thing hackers try. The packets are almost certainly encrypted and checksum'ed in a way where tampering is immediately obvious. You end up at the same place - having to modify/hook into the game internals to bypass the anti-cheat.
- thenewnewguy 7y ago> and we refer to it as shellcode8kb Who is "we" in this context? Is there a community of anti-cheat reverse engineers out there?