Jump to content

Recommended Posts

Posted

Recently, I have been playing Counter-Strike 1.6 in server that is protected with the following anticheat "Flex Anticheat". This anticheat is written in Delphi 7. Surprised It is something like Cheating-Death ... What does it have and what does it do:

- it has an .exe file called Flex Anticheat Loader, which checks for updates in a site, and also loads an .ex file. [Flex Anticheat Loader.exe is packed/compressed with the UPX packer, so I unpacked it successfully, but actually I don't need the .exe file]. Shocked

- it has an .ex file called Flex Anticheat. That file is packed/compressed with EXECryptor 2.2.x - 2.3.x. It also has a self-check, so if you corrupt it, you'll get and error, that says: "File corrupted!" Embarassed

- it has a file called flex.qrs [in it, you can see the current version of the anticheat].

- Flex Anticheat generates an .ini file, which contains the path to your gamefolder, and also it contains the parametres, related to hl.exe.

 

The game must be started through the anticheat!  :'(  :(

 

What does it do:

The anticheat generates a new hl.exe file like flexhl.exe [using a .rc to .res ]and then renames it to random.exe. [that means that each time you start Flex Anticheat, your Counter-Strike 1.6's hl.exe will be renamed to a different name, with ending .exe].

Now the hard things begin:

If you try to inject a .dll with any injector in the new proccess, called random.exe [for example 139248345893242893131892.exe], it detects your cheat and says: "Code Error" and then terminates your game, because it detects the "changes" / "hacking function" that are made in your system dll files.

There was a way to inject the cheat engine wallhack table, using procexp.exe and cheat engine, and then killing several threads in the Counter-Strike 1.6's process, using procexp.exe. Very Happy But now, new features were added...  :( ... all the hacking tools were detected [of course they were detected because of their hacking functions...], so when you try to use a hacking tool [for example cheat engine 5.4 by dark byte, you receive an error which says: "Hacking tool detected" and then the anticheat and the game terminate...

 

Question So is there a way to

- unpack the .ex file?

- remove the check for "hacking tools".

- stop renaming the game to random.exe

- patch the functions of checking for cheats [glBegin and glDepthTest], so playing with cheats will be ok...  :D

 

I will give a link, so all of you will be able to download it, and try to hack it/or hack it [i hope] !!!  ;)

 

http://rapidshare.com/files/201595444/FlexAnticheat1.01.0Installer.exe

 

Posted

......so when you try to use a hacking tool [for example cheat engine 5.4 by dark byte, you receive an error which says: "Hacking tool detected" and then the anticheat and the game terminate... :O Other way?

  • 7 years later...
Posted

Recently, I have been playing Counter-Strike 1.6 in server that is protected with the following anticheat "Flex Anticheat". This anticheat is written in Delphi 7. Surprised It is something like Cheating-Death ... What does it have and what does it do:

- it has an .exe file called Flex Anticheat Loader, which checks for updates in a site, and also loads an .ex file. [Flex Anticheat Loader.exe is packed/compressed with the UPX packer, so I unpacked it successfully, but actually I don't need the .exe file]. Shocked

- it has an .ex file called Flex Anticheat. That file is packed/compressed with EXECryptor 2.2.x - 2.3.x. It also has a self-check, so if you corrupt it, you'll get and error, that says: "File corrupted!" Embarassed

- it has a file called flex.qrs [in it, you can see the current version of the anticheat].

- Flex Anticheat generates an .ini file, which contains the path to your gamefolder, and also it contains the parametres, related to hl.exe.

 

The game must be started through the anticheat!  :'(  :(

 

What does it do:

The anticheat generates a new hl.exe file like flexhl.exe [using a .rc to .res ]and then renames it to random.exe. [that means that each time you start Flex Anticheat, your Counter-Strike 1.6's hl.exe will be renamed to a different name, with ending .exe].

Now the hard things begin:

If you try to inject a .dll with any injector in the new proccess, called random.exe [for example 139248345893242893131892.exe], it detects your cheat and says: "Code Error" and then terminates your game, because it detects the "changes" / "hacking function" that are made in your system dll files.

There was a way to inject the cheat engine wallhack table, using procexp.exe and cheat engine, and then killing several threads in the Counter-Strike 1.6's process, using procexp.exe. Very Happy But now, new features were added...  :( ... all the hacking tools were detected [of course they were detected because of their hacking functions...], so when you try to use a hacking tool [for example cheat engine 5.4 by dark byte, you receive an error which says: "Hacking tool detected" and then the anticheat and the game terminate...

 

Question So is there a way to

- unpack the .ex file?

- remove the check for "hacking tools".

- stop renaming the game to random.exe

- patch the functions of checking for cheats [glBegin and glDepthTest], so playing with cheats will be ok...  :D

 

I will give a link, so all of you will be able to download it, and try to hack it/or hack it [i hope] !!!  ;)

 

http://rapidshare.com/files/201595444/FlexAnticheat1.01.0Installer.exe

:-\

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



  • Posts

    • I already finished my panel for change name and gender, anyway need restart, im used schema  $stmt = $conn->prepare("EXEC lin_ChangeCharacterName2 ?, ?, ?"); for change name... also for change gender i used if ($race == 5) // Kamael race ID; modify this value as per your database { $error = "Gender change is not allowed for Kamael race characters."; } else { $stmt = $conn->prepare(" UPDATE user_data SET gender = ?, face_index = 0, hair_shape_index = 0, hair_color_index = 0 WHERE char_id = ? AND account_name = ? "); Sorry no idea how to add cached update in myext64 about, not have any  solution for this yet compatible to myext64 code. This is my panel make in php http://177.73.143.43:8080/account/ Cool panel for me, without experience in any code. Without help from any people here 🙄
    • Don't listen to that idiot @Nightw0lf — he doesn't know or understand anything... he just talks nonsense. Here's the solution, just to prove that they're the useless ones giving you meaningless and useless answers.   function disableCharacter($charId){ $buf = pack("cVV", 0x14, $charId, 1); return $this->Send($buf); } function enableCharacter($charId, $accountId){ $buf = pack("cVV", 0x15, $charId, $accountId); return $this->Send($buf); } function kickCharacter($charId) { $buf = pack("cV", 0x05, $charId); $tmp = $this->Send($buf); sleep(2); return $tmp; } //-------------------------------------------------------------------------------- if ($func==7)//DESHABILITAR PERSONAJE { $char_id = $var1; $CACHED->kickCharacter($char_id); $respuesta = $CACHED->disableCharacter($char_id); RegistrarActividad("disableCharacter",$respuesta,GetCharNameByCharId($char_id)."(".$char_id.")",0,0,0,0); } else if ($func==8)//HABILITAR PERSONAJE { $char_id = $var1; $account_id = $var2; $CACHED->kickCharacter($char_id); $respuesta = $CACHED->enableCharacter($char_id,$account_id); RegistrarActividad("enableCharacter",$respuesta,GetCharNameByCharId($char_id)."(".$char_id.")",$account_id,0,0,0); } //-------------------------------------------------------------------------------- $CACHED->disableCharacter($char_id); $tabla = sqlsrv_query($conexion_lin2world, "UPDATE user_data SET xxxxxxxxxxxx WHERE char_id=".$char_id.""); $CACHED->enableCharacter($char_id,$account_id); Now just compare the stupidity said by that imbecile @Nightw0lf with the answer I gave you... Thanks to people like this, MaxCheaters is in the state it's in... They keep following useless people who are good for nothing 😉  
    • A new template is available: Mystical-World - Responsive HTML Template    
    • very helpful comment when you say to some random person that is asking for help this: "I hope that the imbeciles that you defend better answer you" indicates you have serious psychological issues, you are a problem for the community at this point  read the rules and stop spreading the toxicity virus you are infected with, seek professional help.     on topic, l2off servers have the issue of real time name changing through website and CacheD server, in some of them even successfully return no errors but its still not working, the player has to restart the game afterwards so in best case you log them out, thats all i can tell you from the website side development. i suggest this to be inside try/catch dont use advext the guy gives errors in the documentation of the website connections and calls other developers idiots who cant make it i have rewrote this function fully (this function contains the errors)  https://wiki.depmax64.com/index.php/Список_php-функций_для_работы_с_пакетами_IL and still i made everything work except the rename, this can be done with other methods and SQL side using function queries
    • Buying & Selling Torn City Cash
  • Topics

×
×
  • Create New...

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock