Hookshark results for bots menu

User Tag List

Results 1 to 11 of 11
  1. #1
    Jaerin's Avatar Former Staff
    Reputation
    641
    Join Date
    Sep 2008
    Posts
    1,290
    Thanks G/R
    29/126
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Hookshark results for bots

    So I thought I would take a look and see what could be seen with Hook shark on the bots I have available to me. Below are the screenshots of those results.

    Each of these were scanned while sitting at the login screen with nothing active, but the bot attached to the process. Combine this information with the list of scans in the other Warden thread and you can see for yourself if your bot of choice is detected or not currently.

    Judge for yourself:

    Immortal Bot w/ maphack + minimap ESP turned on


    Immortal Bot w/ maphack + minimap ESP turned off


    HellBuddy


    Demonbuddy

    Hookshark results for bots
  2. #2
    sp0t's Avatar Sergeant Major
    Reputation
    41
    Join Date
    May 2012
    Posts
    176
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    DB, ftw... As far as detection goes. Lol

  3. #3
    GilesSmith's Avatar Member
    Reputation
    16
    Join Date
    Jun 2012
    Posts
    8
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Really good & interesting stuff - speaks for itself even without understanding the technicalities of those hooks etc. Thanks for sharing!

  4. #4
    Cypher's Avatar Kynox's Sister's Pimp
    Reputation
    1356
    Join Date
    Apr 2006
    Posts
    5,368
    Thanks G/R
    0/4
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Another thing worth checking is how the bot is doing their code injection.

    I haven't looked at the D3 bots personally, but I know that there were a scary amount of WoW bots that were injecting DLLs, then unlinking themselves from the PEB because whoever wrote it thought that made their DLL invisible. Nope.avi. Even if you manually map though, you still need some form of polymorphism to avoid Warden hashing your code (because even if you disable their memory region checks they can still get you by slipping code into the game engine to avoid using Warden to detect you at all -- i.e. how LuaNinja got pinched, and other bots/hacks have been detected with code slipped into the client in a similar manner).

    That's not to say that you're 'undetectable' then (you'll still want a 'tripwire'-esque system), but at least then the Warden guy actually needs to put in some work, otherwise you're just begging to be blacklisted.

  5. #5
    MaiN's Avatar Elite User
    Reputation
    335
    Join Date
    Sep 2006
    Posts
    1,047
    Thanks G/R
    0/10
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Try to compare this to some legit applications such as Fraps and Steam (launch Diablo via Steam so you get the steam overlay).
    [16:15:41] Cypher: caus the CPU is a dick
    [16:16:07] kynox: CPU is mad
    [16:16:15] Cypher: CPU is all like
    [16:16:16] Cypher: whatever, i do what i want

  6. #6
    belowme81's Avatar Active Member
    Reputation
    16
    Join Date
    Jun 2012
    Posts
    171
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by MaiN View Post
    Try to compare this to some legit applications such as Fraps and Steam (launch Diablo via Steam so you get the steam overlay).
    I would love to see this as well.

  7. #7
    Cypher's Avatar Kynox's Sister's Pimp
    Reputation
    1356
    Join Date
    Apr 2006
    Posts
    5,368
    Thanks G/R
    0/4
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by MaiN View Post
    Try to compare this to some legit applications such as Fraps and Steam (launch Diablo via Steam so you get the steam overlay).
    Last time I checked, Steam and Fraps were both extremely invasive. They're known 'good' programs though so it doesn't matter. They typically get whitelisted by anti-cheat software (e.g. PB).

    I know that you know that though, so I think I may be missing the point...

  8. #8
    Beaving's Avatar Sergeant
    Reputation
    21
    Join Date
    Apr 2010
    Posts
    67
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    So, I guess it would be good to hook to Fraps or Steam in order to prevent detection? Of course given that the software developers of those programs don't provide a constant stream of file hashes.

  9. #9
    Cypher's Avatar Kynox's Sister's Pimp
    Reputation
    1356
    Join Date
    Apr 2006
    Posts
    5,368
    Thanks G/R
    0/4
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Beaving View Post
    So, I guess it would be good to hook to Fraps or Steam in order to prevent detection? Of course given that the software developers of those programs don't provide a constant stream of file hashes.

    Pretty sure PunkBuster still detects and kicks you for that. Warden simply doesn't care (unless you're public, at which point hooking Fraps etc won't help you).

  10. #10
    Miksu's Avatar Contributor
    Reputation
    244
    Join Date
    Nov 2007
    Posts
    731
    Thanks G/R
    216/25
    Trade Feedback
    5 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Very interesting thread REP+ OP


  11. #11
    sw1777817's Avatar Private
    Reputation
    1
    Join Date
    Sep 2011
    Posts
    1
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I remember playing a F2P game that used Xtrap and they were kicking people for having xfire open.
    what had happened was some people had used the xfire interface to load their hacks in.... well xtrap figured it out and was keeping people from logging in to the game with xfire open.....
    I can't remember where I was reading that some people were trying to use both the fraps and steam overlay stuff (even messing with teamspeak/skype stuff) to pass thru stuff to the programs....

Similar Threads

  1. WTT 70 Rogue, Unactivated, For Bot PLing
    By Verye in forum Members Only Accounts And CD Keys Buy Sell
    Replies: 3
    Last Post: 04-20-2008, 01:32 PM
  2. Hate getting D/C?? -- Auto Login -- useful for bots and private servers
    By ADAMZY in forum World of Warcraft Bots and Programs
    Replies: 24
    Last Post: 11-05-2007, 05:06 PM
  3. What does Blizz ban for botting?
    By spongebob7 in forum World of Warcraft General
    Replies: 4
    Last Post: 06-26-2007, 09:38 PM
  4. 2 great PvP addons (for botting too)
    By ayadew in forum World of Warcraft General
    Replies: 8
    Last Post: 04-22-2007, 05:08 PM
  5. Lvling Tips for Botting/Questing/Grinding
    By Jaske53211 in forum World of Warcraft Guides
    Replies: 3
    Last Post: 03-18-2007, 01:44 AM
All times are GMT -5. The time now is 10:33 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search