16 ms·
Reverse engineering Call of Duty anti-cheat
- shj2105 2y agoWhere did you learn how to do this? I would love to learn more about understanding half of what this article said but I don’t know how to start.
- therein 2y agoI got started with Lena151's tutorials back in the day. https://github.com/kosmokato/Lena151 https://github.com/kosmokato/Lena151
- andrewmcwatters 2y agoDang, I'm old. I was going to say hang out in Gamedeception, but apparently it's been gone for years! greetz to readers of Unknowncheats, cs.rin.ru, etc.
- therein 2y agoI used to frequent cs.rin.ru for all things non-steam back when I operated non-steam CSS servers. UnknownCheats is also absolutely amazing for cheat development. Back when I was writing undetected kernel cheats for my own experimentation purposes, I learned so much there.
- andrewmcwatters 2y agoI made my lifelong best friends hosting non-Steam servers, and writing the first cracks in Lua to generate fake Steam IDs from IP addresses.
- jorvi 2y agoYoo haha Unknowncheats, now there's a blast from the past. Milworm (milw0rm?) also got me started back in the day.
- jamesfinlayson 2y agoGosh, haven't been to cs.rin.ru for years. UnknownCheats was (still is?) good for getting information on undocumented APIs when game modding (for a good while the Half-Life SDK was incomplete).
- b8 2y agoThe secret.club is a good resource.
- frosting1337 2y agohttps://pwn.college https://pwn.college is a great educational resource.
- josephg 2y agoI learned a lot of this stuff ~15 years ago from reading a book called Reversing: Secrets of Reverse Engineering by Eldad Eilam. The book is old but amazing. It takes you through a whole bunch of techniques and practical exercises. State of the art tooling has changed a bit since then, but the x86 ISA & assembly more generally hasn't changed much at all. One of my biggest takeaways was learning about "crackmes" - which are small challenge binaries designed to be reverse engineered in order to learn the craft. They're kinda like practice locks in the lockpicking community. The book comes with a bunch on a CD-ROM from memory - but there's plenty more online if you go looking. Actually doing exercises like this is the way to learn. You don't start trying to reverse engineer COD. You build up to it.
- mrsaint 2y agoMy recipe: "Windows 95 System Programming Secrets" by Matt Pietrek and "Unauthorized Windows 95" by Andrew Schulman, years of fooling around with NuMega SoftICE, lots of IRC, lost youth, yet lots of fun.
- sitzkrieg 2y agoi miss softice so much (but not fixing my clock)
- kamikazechaser 2y agoUnknownCheats. I'm active there and it has one of the best resources on this kind of stuff. I'm more interested in how Linux userspace Anti-cheats works notably VAC.
- ActorNightly 2y agoYou need to be just comfortable in assembly. Its a hard first step, but I highly suggest you take the time to analyze a small binary, starting with understanding the registers for the architecture, understanding the different function calls, and then looking at the elf file and analyzing every section and how static linked libraries work, and how dynamic linking works with PLT/GOT. GPT models are REALLY good at helping you understand this, and you can also use Ghidra for decompilation. Do everything on Linux btw, as the tools are very easy to use and much less Cumbersome than windows. Once you understand all of that, tracing assembly is pretty easy - its either register move operations, math operations, compare operations, jumps, and function call and returns (which basically are just shortcuts for handling the stack frames), with a few special instructions here and there which are usually just some optimizations that you can look it up ad hoc. Once you get handy at ghidra, you can look at decompiled C code and start replacing variable names to make the code readable, and then you generally get a good idea of project flow.
- andrewmcwatters 2y agoSignature scanning is indeed the hot shit. It's like the most addicting part of reverse engineering to me. Building signature lists, and then writing bindings to scripting languages to call those function pointers. It's also the foundation of how many third-party mod platforms work, because you need to build a meaningful API to modders that isn't exposed by the first-party.
- Cyph0n 2y agoNo idea what signature scanning is, but found this resource for those curious: https://www.unknowncheats.me/forum/general-programming-and-reversing/171994-understanding-pattern-scanning-concept.html https://www.unknowncheats.me/forum/general-programming-and-r...
- deleted 2y ago[deleted]
- c0balt 2y agoFrom my limited experience, it refers to the act of reverse engendering the function (signatures) contained the code of a binary. A binary, like the underlying code, has commonly used code split into functions that may get called in multiple places. These calls can be analyzed either through static analyzers or by a human, who may analyze context of the callsite to guess what each Arg is supposed to do/be. For modding, e. G. in a single player game, one might want to find out where the engine adjusts the health points of a player or updates progress.
- landr0id 2y agoSignature scanning is just scanning for unique bytes from a compiled function that will remain consistent across builds. You search memory for those bytes and when you find them, you find the function you're interested in. Here's an example from some shellcode loader I wrote: https://github.com/exploits-forsale/solstice/blob/c3fc9a55c6c6d84501bd2fdd2cc8704d7a4a9509/crates/solstice_loader/src/pelib.rs#L720-L722 https://github.com/exploits-forsale/solstice/blob/c3fc9a55c6...
- adiabatichottub 2y agoI'm very curious about the jump obfuscation. Maybe somebody who's done more reverse-engineering can answer this for me: a) Are unconditional jumps common enough that they couldn't be filtered out with some set of pre-conditions? b) It seems like finding the end of a function would be easy, because there's a return. Is there some way to analyze the stack so that you know where a function is returning to, then look for a call immediately preceding the return address? Apologies if I'm wrong about how this works, I haven't done much x86 assembly programming.
- russdill 2y agoUnconditional jumps are very common and everything in x86 assembly is very very messy after optimizations. Many functions do not end in ret.
- jychang 2y agoHow do functions that not end in ret work?
- to11mtm 2y agoMy gut (been a while since I've been that low level) is various forms of inlining and/or flow continuation (which is kinda inlining, except when we talk about obfuscation/protection schemes where you might inline but then do fun stuff on the inlined version.)
- duskwuff 2y agoThe return is somewhere before the end of the function, e.g. loop: do stuff if some condition: return do more stuff goto loop Alternatively, the function might end with a tail-call to another function, written as an unconditional branch.
- jcranmer 2y agoThere are things like compiling a tail call as JMP func_addr.
- mahmoudimus 2y agoI have been doing a bit of reverse engineering on a popular Horde/Alliance based MMO game and it follows almost the exact same steps (including the FNV32 export hashes). It almost seems very similar as I have seen it employ very similar tricks. I wonder if it's packed using the same protection?
- 2c2c2c 2y agowould make sense to reuse warden for Activision IP post merge
- roflmuffin 2y agoThe source 2 engine also uses fnv to hash the schema (basically entity properties)
- sas41 2y agoCheating in multiplayer games has become such a huge problem, it has destroyed trust across every major FPS. I am a long time CS player, but I did briefly play one of the new CoD games, before they went crazy with Nicki Minaj skins and bong-guns. A person was so convinced I was cheating, they started doing OSINT on me while still in a match, and they found my old UnKnOwNcHeAtS account as some kind of proof that I am cheating (that account was 12 years old by that point). I abhor cheating, and I have a lot of interest in computer science, so of course I wanted to see how all of it works and did my research during my youth, taking care to never compromise the competitive integrity of the games I played, but if you look around, there is not a single game that I can recommend to people anymore. Games like Escape From Tarkov are so busted, cheaters are stealing the barrels off people's guns and crashing their game/PC on command. My beloved counter-strike's premier competitive game mode has a global leaderboard that acts as a cheat advertisement section within the game. Games like Valorant are a cut above the rest on account of their massively invasive anti-cheat, but are nowhere near as clean as most fans claim, I mean, you could write a cheat for the game using nothing but AHK and reading the color of a pixel. There is a whole industry of private matchmaking for counter-strike, built solely on the back of their anti-cheat and promises of pro-level play to the top players. EDIT: I found the screenshot, it was MPGH not UnknownCheats, but yeah, they also had a game ban on their account.
- enjoylife 2y agoWe’re seeing a clear divide where both competitive gamers and hackers are retreating into their own ecosystems, away from public matchmaking. Public matchmaking has simply become too optimized/lucrative to sustain trust or meaningful competition. Private matchmaking and closed communities are thriving, raising the average skill ceiling in competitive. Similarly, hacking communities are evolving with easier forms of payment and distribution. The monetary aspects are huge. But most importantly, both cultures push each away. Your persona of someone who plays with integrity and crosses the competitive and hacker mentality is pretty much gone.
- Dalewyn 2y agoI disagree that cheating "has become" a huge problem, it was always a huge problem. I can't remember a single multiplayer game that didn't have cheaters of some form or another. None. Zilch. Zero. It's kind of why I never grew beyond playing MMORPGs, and even that passion ultimately died out.
- SheinhardtWigCo 2y agoPhenomenal piece of research. Clearly this is not the author's first rodeo :)
- monkburger 2y agoAs long as you can read and write to memory, you will never stop online cheating in FPS games.
- alkonaut 2y agoThis is true, but what is "reading and writing to memory" here? The article outlines dozens of ways of doing that with various hooks etc. And how they try to avoid that. If I put a hardware connection to the memory (basically WIRES to my memory bus) then yes, it's very hard to detect. But that's also very hard and expensive to do...
- phsau 2y agoIt's cheaper and more accessible than ever to use DMA/hardware cheats from cheat vendors.
- bangaladore 2y agoDMA cheats are only usable as many games aren't willing to pull-up their minimum requirements to play. IOMMU defeats DMA attacks. Secureboot (largely) solves pre-boot EFI related concerns.
- weberer 2y agoEven then, you could probably set up an aim bot with a second computer using computer vision to detect characters, and sending inputs as a USB mouse.
- monkburger 2y agoAs long as you can read and write to memory, you'll never stop cheating in multiplayer games.
- deleted 2y ago[deleted]
- CobrastanJorji 2y agoSure, and that's why there's more and more "trusted" hardware to try and get computers to a place where their users cannot read and write to or from their own memory.
- AnthonyMouse 2y agoThose kinds of things tend to be their own undoing. You added a security processor to your hardware at ring -2, but hardware vendors are notoriously bad at software so it has an exploit that the device owner can use to get code running at ring -2. Congrats, your ring 0 anti-cheat kernel module has just been defeated by the attacker's code running on your "trusted" hardware. But in the meantime you've now exposed the normal user who isn't trying to cheat to the possibility of ring -2 malware, which is why all of that nonsense needs to be destroyed with fire.
- 15155 2y agoGood luck ensuring every PCIe device with DMA access is "trusted."
- bangaladore 2y agoIOMMU defeats DMA attacks. There is no reason for a GPU or network driver, or anything to have arbitrary physical memory access. If a GPU needs space for a draw-calls, allocate it in the kernel and explicitly give permission to the GPU to access it.
- AnthonyMouse 2y ago
- mdswanson 2y agoA 2-year legal battle with Activision to overturn a false permanent ban. Activision showed up with zero evidence of cheating and lost: https://antiblizzard.win/2025/01/18/my-two-year-fight-against-activisions-false-cod-ban-unbanned/ https://antiblizzard.win/2025/01/18/my-two-year-fight-agains...
- b3lvedere 2y agoHoly ….. what a fight you had to do. So glad i hardly play any mulitiplayer shooter games. I’d hate to have my insane Steam library stripped away from me.
- minihat 2y agoHis steam library was not restricted, just the game in which he was accused/banned.
- cwillu 2y agoAnd his account was publicly flagged as being a known cheater, which affected other games: https://antiblizzard.win/2025/01/18/my-two-year-fight-against-activisions-false-cod-ban-unbanned/#:~:text=to%20an%20end.-,Why%20bother%3F,-To%20me%20this https://antiblizzard.win/2025/01/18/my-two-year-fight-agains...
- b3lvedere 2y agoApologies. I stand corrected. Thank you for this insight.
- buzer 2y ago> This ban also ruined other games for me. If I ever did well in a game, someone would look at my profile to see how many hours I have and instantly see the red marker that shows “I am a cheater”. I wonder if that label can be considered to be libel. Probably harder in the US, but from what I understand in UK (or just England?) the defendant must prove that it's true.
- rustcleaner 2y agoNeeds to be a law against the taking away of product functionality after the sale, even if it's contractual/EULA. A ban should never take the game away from the owner, and in cases where it does then they need to be refunded (treble damages on top of license, lawyer, and court fees if it takes a judgment to induce the refund). Getting banned on Steam, say, in the sense that all of one's purchases are invalidated should be impossible legally. In cases where an account is prevented from login, items and inventory must still be accessible for trade as those represent real time effort put in by a paying customer. Want to enforce your code of ethics in a multiplayer game? Can't charge for the game or users legally have rights against bans, and bans must follow a proportionality continuum and you must have a human-attended cost capped (at license cost, and only on loss) appeals tribunal system with record.
- lm28469 2y agoWhy is that different from speeding while driving ? Be a nuisance to society -> get fucked. That's a pretty universal principle
- nurumaik 2y agoBecause there is no court, just algorithm flagging people with some false positives For "get fucked" measures you need pretty low rate of false convictions
- spencerflem 2y agoimo the problem would be solved if there was the ability and a culture of running your own game servers. Because I agree, being softlocked from a game you paid for sucks. But also, cheaters suck, and whoever's running the server should be allowed to kick you out.
- Sophira 2y agoWhile I get where you're coming from, that's a really bad comparison to make. Speeding while driving can and will kill people.
- 2y ago
- deleted 2y ago[deleted]
- marcosscriven 2y agoI don’t play this game, but my partner does. I sometimes see him “spectating” a player that is below the ground - regardless of if the client is hacked/cheating, aren’t there some server-side checks that the player state is valid?
- StefanBatory 2y agoAs much as I loved that article, I'm not sure it's really moral thing to do.
- __alias 2y agoNot really relevant, but this triggered a memory of being around 14 years old and getting scammed on Runescape which drove an evil character arch from me to somehow find out how to DDOS players in the duel arena and make absolute bank. I still feel a little guilty about my actions to this day. At the same time, I'm surprised that at 14 I was able to find and pay for a denial of service provider and figure out players IP addresses to intentionally disconnect them
- alkonaut 2y agoCheating is ultimately a human problem. You can have some safeguards and heuristics like the ones the article describe, to weed out 90% the most blatant cheaters, so I think anticheats like these are fundamentally a good thing. But the anti-cheat can and should err on the safe side because ultimately it should be the players and admins themselves that sort this out. Online multiplayer games must (yes must) take place on servers with human admins. Admins should be present for a majority of the time any players are playing. Ideally with admins the players recognize. Bonus points if players themselves can perform some moderation when no admin is present (votekick, voteban etc). There is no difference between kicking cheaters and kicking people who are abusing chat etc. Obviously this means that "private" or "community" servers are the only viable types of server for online multiplayer games. This process of policing cheaters and other abuse can not be something that is done via a reporting system and handled asynchronously. Kicking/banning must be done by the admins of the game, and it must be handled quickly. If you are considering buying/playing an online multiplayer game and it doesn't have this functionality (e.g. the only way to play online is via matchmaking on servers set up by the publisher, and the only way cheaters and chat abusers are policed is via some web form) then please, avoid that game. Vote with your wallet.
- dpig_ 2y ago> Online multiplayer games must (yes must) take place on servers with human admins. The sheer scale of this arbitrary requirement is hilarious.
- mvdtnz 2y agoIt's not that long ago this was the norm.
- dpig_ 2y agoYep, I remember. It was nice to play regularly on a server with names you came to recognise. That will never be the norm again though unfortunately. It still exists in the indie space, however, like for example on VR games such as Pavlov where the playerbase is too small for formal matchmaking.
- jokoon 2y agoWouldn't it be possible or relevant to periodically, electronically sign the game state, to prevent cheating? Or with some proof of work? I am starting to think that cheat are just too hard to fight against, I am making a small, cheap online FPS, and I would let users trust each other instead, and hunt cheaters themselves, or maybe use AI like valve is doing. I would not bother have a anti cheat software. Also players would have to manage and administrate their servers themselves. Players would require to have a cellphone number attached, have a reputation score given by other players, maybe give an id or some other strong auth method, manual verification with like a photograph, like it's done for some dating apps. Players would have to play like 10 hours before they could play competitive. I am confident hardcore players would be motivated to do all those things to make sure there are fewer cheaters.
- jezzamon 2y agoAt a high level, you can just simulate the game without cheats, sign that, and then do the cheats separately.
- shawabawa3 2y ago> and I would let users trust each other instead, and hunt cheaters themselves If you've ever played a decent amount of basically any online game you'd know that players make cheating accusations CONSTANTLY based on very little evidence. And then there's also the social aspect of just reporting players you don't like to get them banned In such a system you'd get way more false positives than any kind of anti-cheat
- deleted 2y ago[deleted]
- jagrsw 2y agoI experienced the trust factor (banning, w/o banning officially) issues on my Linux CS:GO account in 2021, dropping to yellow and then red. This made it difficult to find teammates, as I was constantly matched with cheaters. I discovered I wasn't alone, as many other Linux users with Radeon GPUs and 16GB+ VRAM were experiencing similar problems. We created a GitHub issue to track the problem and try to find a solution: https://github.com/ValveSoftware/csgo-osx-linux/issues/2630 https://github.com/ValveSoftware/csgo-osx-linux/issues/2630 After some investigation, we found that Valve was punishing Linux users with certain hardware configurations (radeon cards with >=16GB of VRAM, which were quite new at this time). Eventually, after a user reached out to gaben directly, the issue was fixed: https://github.com/ValveSoftware/csgo-osx-linux/issues/2630#issuecomment-844810582 https://github.com/ValveSoftware/csgo-osx-linux/issues/2630#... I suspect this was because Valve was preparing to launch the Steam Deck, and gaben wanted to ensure that Linux users had better experience with the device (just a guess).
- ryao 2y agoCould it be that Gabe Newell is a nice guy?
- jagrsw 2y agoIt's possible, but it's also important to be aware of the business side of things. Valve makes a significant amount of money from in-game transactions, and some of their practices around this are shady. Issues like kids using their parents' CCs, gambling industry built around in-game items, and the potentially addictive nature of colorful virtual items marketed towards kids are valid concerns. So, while gaben might be nice, it's unlikely that this gets in the way of Valve's drive to maximize profits in every way they can legally get away with.
- hnuser123456 2y agoThat email address goes to a team of people, but if you send something substantial and well-meaning, they'll look into it.
- solarkraft 2y ago
- giantg2 2y agoYou don't even need to cheat at COD. They are so buggy they'll do it for you. They'll load a gun in place of your knife in ranked. They clearly have a faulty case/if-else statement in the ranked gun loadout checker to allow that and also to default to XM4 if the gun shown in the load out picker isn't allowed. It's probably the only game I know of where the ranked version is more broken than the casual version...
- 1oooqooq 2y agoI mostly quit gaming when I realized (load times+match maching+updated) < time playing. and that was before drm and anti chat rootkits. imagine having to upgrade my pc just to run memory obfuscation sha256. whole industry is like the 80s processed food era just advertise, don't even matter what you're selling.
- JimmyWilliams1 2y ago[dead]
- pvagates42 2y ago[dead]