Gamehack Violation (UPDATE)

UPDATE This now effects Call of Duty - If you are a Call of Duty player who did not read this, make sure you do!

As many of you have seen nC have today unleashed their latest weapon and this is how it works.

The source of their new found ability comes from "pnkbsra / b .exe" - basically they've isolated that what this does is scan the entire virtual memory for vm signatures and they find certain vm signatures that PB will kick for. That pnkbsra scans the entire virtual memory, so if you've MSN or iRC open at the time, and you get sent this message when you're connected to PB then it will show up in your VM and you will get kicked.

The method they used to get to this conclusion was reverse engineering - their justification for claiming that is legal is because 3 different virus scanners pick PB up as a trojan and thus is a threat and its legal to reverse engineer a threat (apparently).

This has been explained further by Fried Fish Tail;

QuoteAnyway, the way GAMEHACK bans done is the following: PB detects that specific file ( and its contents, so all they had to do is paste some lines from the file to and IRC channel you're idling on and when PB scans mIRC.exe's memory - it finds the pattern and you're getting kicked.

An example of a string PB is looking for: *removed by admin* (with quotes)

*removed by admin*"

And everyone who will play anytime whilst that mIRC session is running will get kicked.

What they posted all over the irc:
*removed by admin*

This information was all forwarded to Clanbase earlier this week, aswell as punkbuster being kept in the loop of todays activities courtesy of SplashDamge.

Addition information
IRC or MSN Logs have nothing to do with the Gamehack kicks! People are already saying "delete logs and dont do this", but thats not necescary, closing irc should terminate the string from memory, and this string on the memory is the only problem. (tnx2meez)


Another string has been circulated which results in people being kicked for '(MULTIHACK) #70476'. It's likely that there's an endless amount of strings which will result in people being banned for all kinds of reasons.
Sorry if im a touch late on this, we prepared this earlier ready for posting as soon as it happened and ive been a touch busy today.
Why not post it before to warn people?

Edit: I understand you've been busy btw, and awesome Casting, especially for Call of Duty 4!

Edit 2: I saw you on tv!
so we'll be kicked if just anybody posts this line in irc? no matter if its a query or a message in a channel?
ruined my fuckin cup man :<
Then what about lio & alexl ? have they received any pms or how else could they just choose those 2 guys when it would get everyone kicked who is in a certain channel ?
Tonga Bartichello on 24/03/08, 00:30:29 PM

working on that...

pbbans will erase all of these bans and yes lio and alexl will get unabanned asap...
If COD4 runs the pnkbsra.exe it should
Addition information
IRC or MSN Logs have nothing to do with the Gamehack kicks! People are already saying "delete logs and dont do this", but thats not necescary, closing irc should terminate the string from memory, and this string on the memory is the only problem. (tnx2meez)

reading crossfire with strings like that on the particular page your reading, might trigger a kick in ET as well.

Cause PB isn'T supporting ET anymore.
Ode to "The string"

I dunno if posting it all was a good idea if it is true, its like a "How to" for the e-terrorist/angrykid :f
by a PBBANS admin
Easter eggs :x
"This information was all forwarded to Clanbase earlier this week,"

so why wasnt there any statement, like, that gamehack-thingy IS a bug... i dont mean that someone should have posted the stings earlier, but why didnt anyone posted a single note, that the problem is recognized at cb & pb and there will be an update soon...!?

i really would like to know, what comes next... maybe you can tell me?
they were too busy to come up with a damage control plan. Stay tuned.
Tried saying this on IRC many times, but it seems smoke signals ain't a reliable internet connection..

Do we know if PB scans the entire memory, or just the allocated memory? If it only scans the allocated memory then closing mIRC saves you, but if not, then you'll have to overwrite the memory (that is, reboot, memory defrag, or open a huge thingy and close it again).

and /me forgot about swap persisting over reboot. See the posts below.
actually, no, you don't have to overwrite your memory by putting huge things in it :) read my comment below

RAM is cleared the moment it loses power. Virtual memory, swap memory/pagefile is the problem, but you have info on how to clear it on shutdown in my comment
My post lacked an "or" ;)
But true, I didn't think of that swap is preserved over reboots
After talking to kaiz, we've remembered that there is also virtual memory used, called swap.

So here's a little update to meez' solution:

After enabling this option in registry, it will be cleared whenever you restart computer.

To make sure everything is clean, reboot it and join an ET server without irc running.

Unfortunately, there is no other real solution to this because the next time someone posts it anywhere, you will have to reboot again. :(
This particular kick, yes, but they can use different strings for different games and thus get people banned in other games as well.
The people behind Netcodes are kids. The people behind Punkbuster are dumb. Combine the two and you get... what currently is going on.

Punkbuster has been going about it the wrong way. They didn't ban players for actual cheats anymore and that's where they went wrong. They started banning players based on suspected cheating since they knew they were one step behind the hackers/cheaters. Punkbuster tried to make a shortcut. They were lazy and that backfired. Badly. They opened up a giant door for hackers to enter and really mess things up.

Thank god for evolution. Punkbuster will probably be extinct now. Yay!

Someone up for setting up a good anti cheating company with proper tools? :)

Netcoders... they are little children. Look mommy at what I can do! I pity them. I really do.

Cash is right though. It sucks right now. The way it happened wasn't necessary but evolution is a good thing. Something better will come out of this. Probably not for ET but future games will benefit from this. Even though, I'm repeating myself now, this could have been handled better.
QuoteThey started banning players based on suspected cheating

That's true, but it's also what the community itself chose to do with the MD5 tool (banning for cvars and pk3 files).
True, but what do you think virus scanners do? Do you think they only look for known viruses?
I believe they have more advanced heuristics compared to the sweatshop job that Evenbalance has managed to do with PB.
True, but the same principle applies :)
what actually happend?
but if you knew it before...what was causing it?
Wow, simple as?! Shouldn't be that problem to get rid of this problem for pb?!

P.S.: Sadly to see that tons of people are falling for nC's propaganda shit. It's a group, which earns money with destroying "our" game and who has simply no moral.

That pb is shit was known before and they found a bug, while they were trying to make their private cheats undetectable again. Instead to publish it instantly or to tell it evenbalance they have kicked innoncents and planned to use it for some propaganda shit...
Simple to resolve this particular issue yes, but now they have to go back and find a way to detect the cheats properly.
Yes, true. But some guys of the community should think now again about their reactions to projects, such as anti3 or etace...and the statement of nC is even worse than any statements of Goebbels or Sahhaf.
QuoteThat exploit ... no let's call it by it's real name: GIGANTIC STUPIDITY of Evenbalance was asking to be exploited. As such we started looking into almost any Punkbuster game and found similar strings.
Of course we could not resist to try this on a couple of servers and different games - with surprising results: We were able to kick players from almost any Punkbuster game for different violations.

any evidence available that this is working also for other games? :)
heh while reading this my mate just told me someone got kicked in cod for it lol :x
I detest the fact that that group are mentioned by name here and are given such attention. It's a good thing that Crossfire inform the community about cheating and such, but you're giving these people the attention that they crave; and you're making them proud of their work and there's nothing more their petty egos want more.
Forget about crashing the server like in the old days. We have struck the asshattery's goldmine!

Get rid of PB (or switch to linux) and live happy! \o/
and why doesnt pb checks for cheat at linux???
if the half of players move to linux systems they will; without that its imposible to doing much work for few hackers only.
Addition information
IRC or MSN Logs have nothing to do with the Gamehack kicks! People are already saying "delete logs and dont do this", but thats not necescary, closing irc should terminate the string from memory, and this string on the memory is the only problem. (tnx2meez)

Using short, human readable strings as cheat signatures is so stupid that I have to laugh! :D

So everyone who types three specific words in sequence is now creating a cheat, and everyone receiving the text is using it.

The interview somehow surprises me. How can someone make himself so much worse than he actually is? Lio and Team EDiT, the most hated by the community? Guess he didn't read the news and columns with all the comments related to his story. Maybe 20 % of random retards were happy about this bust. 30 % were just supporting the anti cheater policy which ofcourse had to be sticked to if you don't want this community to become a whole joke. But those 30 % didn't made a festival out of it, as well as the other 50% which hoped for a unban in the near future. Thought you were smart lio but this is just poor.
worth -> worse

[don't mind me, i'm in such mood today :P and no offence of course]
Me silly boy x)
PB is the worst thing that happened to ET... and that is just an other good reason to leave ET and start to life or play an othergame (COD4! :D)
Join Date: Jul 2007
Is this just for ET, or all PB games?
only for ET. not anymore though -_-
nC just posted a new string, so seems this wont end anytime soon :(

(screen in killerboys post)
all PB games, just need the right string to get people kicked
It is however as stated above considered a threat by many AV engines =)
Licensee further acknowledges and accepts that PunkBuster software may be considered invasive. Licensee understands that PunkBuster software inspects and reports information about the computer on which it is installed to other connected computers and Licensee agrees to allow PunkBuster software to inspect and report such information about the computer on which Licensee installs PunkBuster software. Licensee understands and agrees that the information that may be inspected and reported by PunkBuster software includes, but is not limited to, devices and any files residing on the hard-drive and in the memory of the computer on which PunkBuster software is installed. (...) Licensee agrees that any harm or lack of privacy resulting from the installation and use of PunkBuster software is not as valuable to Licensee as the potential ability to play interactive online games with the benefits afforded by using PunkBuster software.

What are they supposed to do? Develope an AC that works? :D
I suspect nC are involved in a lot of illegal and dubiously legal practices (I'd be surprised if they're not evading taxes, violating copyright, etc and I know they've broken half the terms in the near-worthless EULAs for games and for PB). If someone with enough clout to actually go after them decided they were good targets, they probably wouldn't be laughing.

Having said that, I don't think EB think they're more than dirty little grubs stuck to the sole of gaming's proverbial shoe, and thus not worth the effort.
Statement from even balance:
QuoteMarch 25, 2008

We rarely announce anything regarding commercial cheats and hacks. However, we are aware of the numerous "You Tube" type videos and posts on various sites where hackers who sell cheats make claims that are false but sound believable about PunkBuster and hack detection status. We receive numerous emails daily by concerned honest players regarding advertisements for undetectable hacks, etc. The truth is that via recent enhancements to PunkBuster's detection capabilities, we have cracked down hard on cheaters who pay for hacks in the games we support. Some commercial cheat sites have closed down due to our new methods and others have private forums where punks routinely complain about getting caught with the "undetectable" hacks, demanding refunds, etc. We have always maintained a strict policy of not giving money to punks, but thanks to community volunteer moles who have helped us obtain access to private hacks via donations of their time, etc., PunkBuster has been catching hacks from virtually all commercial cheat sites in recent weeks and months.

One of the recent enhancements involves our memory scanner which aggressively scans for patterns included in known cheats (public and private). A commercial hack site where we have had recent success catching their subscribers has recently staged a few demonstrations of inserting text-based patterns via certain chat-related systems such as IRC, Instant Messaging, etc. directly into the memory of computers. These are specific text patterns that we have deployed in some supported games in the recent past. It is clear that many of the demonstrators are cheat-supporters willingly participating in the demonstration, but there is evidence that some innocent players had PunkBuster violations triggered during the past few days by the hackers who sent specific text patterns into the chat programs that were open during gameplay. We are removing these text based patterns from our system and encourage admins to not ban for PB violations that occurred during the past few days.

Online gamers who play with other programs running should always enable security features in their messaging and chat programs to deny auto-download of files and only accept downloads from people they know and trust. As always, from PunkBuster's standpoint, if a known cheat pattern is in the memory of the computer during gameplay, then a violation will be triggered. We have always suggested closing other programs while you are playing multiplayer games on PunkBuster servers and that remains the safest policy. Leagues that require chat room usage for competitive play should take steps to ensure that only league participants have access and suspicious activity should be reported to us when there are concerns about manipulating the system.
So the million dollar question:

How effective can the memory scanner be without searching for text strings that can occur without a person cheating.
yup had this last night on ET, Americas Army, COD4 AND for the love of god, Quake 3.

So lets all be happy and do the gogo dance and go IRL, no matter what i did i could not get it away.
