 |
Cheat Engine The Official Site of Cheat Engine
|
| View previous topic :: View next topic |
| Author |
Message |
GRB Advanced Cheater
Reputation: 0
Joined: 17 Nov 2006 Posts: 53
|
Posted: Fri Mar 02, 2012 6:17 am Post subject: some protection & Cheat Engine! |
|
|
This is a question to the pro's of ce, including darkbyte.
Q:How this protection is protecting its games?
My A: For my understading they are using 3 ways to protect the games.
1-Looking for all windows and non windows strings running at the same time as this protection. (example: the word cheatengine)
2-Making your own machine as a server, and sending the "HELO" word through the initial dll, to the server, and the server is responding the version back to the main dll. (example: if this process is interrupted this protection fires and close the game)
3-This is the step i cant understand, my ce version is undertected(by strings) for almost all game protections. But if the protection is this specific protection, as soon as i attach ce to the "ex: game.exe" this protection after 5 sec fires up closing the game, and reporting("some functions of the operating system are not working properly due to external program. Please close any program wich is affecting game cliente.")
So the real question is:
What cheat engine is doing to the proccess that is getting cough?
What is the very first steps that ce do after you select the process?
I know that openprocess is safe, i tested it with my test app in c++ and its working. Read to process is also safe. Also i breakpointed the "LoadLibraryA""ex:thisprotection.dll" so i could gave the game a false dll, or not load that especific dll, but the game reported that xfire was not loaded and closed. I even managed to "pause" with breakpoints on some api calls from this protection, but as soon as i attached ce to the game, this protection even "paused" managed to report the same error in 3. Strange.
Im not looking for an answer how to bypass thid protection directly or ppl saying do this and this and ur done, i want to learn how to do it myself. But im looking how this protection & cheatengine works.
Best regards
GRB
_________________
|
|
| Back to top |
|
 |
Dark Byte Site Admin
Reputation: 473
Joined: 09 May 2003 Posts: 25901 Location: The netherlands
|
Posted: Fri Mar 02, 2012 6:53 am Post subject: |
|
|
Try kernelmode openprocess
Also, try removing the symbol initialization part of ce, it can be a bit invasive
And if that fails try removing the whole openprocess epilogue part
_________________
Do not ask me about online cheats. I don't know any and wont help finding them.
Like my help? Join me on Patreon so i can keep helping |
|
| Back to top |
|
 |
GRB Advanced Cheater
Reputation: 0
Joined: 17 Nov 2006 Posts: 53
|
Posted: Fri Mar 02, 2012 8:00 am Post subject: |
|
|
Openprocess is working, no matter if its kernel or not.
Altho on ce6.2 beta +5 if i put to openprocess with kernel its saying that the file version is for other cheat engine version and not for ce6.2.
and btw ty for changing my thread/post. didnt know i couldnt post anti-cheat specific names.
For removing the symbol initialization part of ce, its on the source? or theres an option on ce after compiled for that?
_________________
|
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
|