PDA

View Full Version : Tips and Tricks w/ Punkbuster


No1uKnow
26th November 2005, 18:31
figured we should start a thread talking about actual ways around punkbuster

ill start by posting a way i used to use and still works

if your win 2k and your using a hack that needs to go in the games actual folders

load the hack, right click it, click properties, click the security tab and click deny all access

pb wont be able to read the actual file, so you wont get whitelist kicked for it
i'll post a couple tricks later, time for SWAT4 ;)

A.Wesker
27th November 2005, 21:09
that really works?

eyesonly
27th November 2005, 21:30
does it works with windows XP?

No1uKnow
27th November 2005, 21:36
for winxp you gotta download some security patch to get it working, it's out there, there's programs that "hide" files, but you never know bout hw bans

Spaztikdude
28th November 2005, 07:51
One such program is US (Universal Shield) truly, punkbuster never truly got around it, they could only stop the loading(This happened in AAO 2.4)

revd
28th November 2005, 23:54
for winxp you gotta download some security patch to get it working, it's out there, there's programs that "hide" files, but you never know bout hw bans
I downloaded 'US'

How exactly do I enable it to 'hide' my files inside my game folder?

_Moloch_
30th November 2005, 20:26
This is just a "theoretical" question ;)
Would it be "helpful" to have the PB source??
As i said ...just a question no more no less


_Moloch_

Sparten
30th November 2005, 20:52
This is just a "theoretical" question ;)
Would it be "helpful" to have the PB source??
As i said ...just a question no more no less
_Moloch_

YES..

Spaztikdude
1st December 2005, 11:32
It would help, but how in the world would you be in possession of the source code anyway?

gil
1st December 2005, 18:33
This is just a "theoretical" question ;)
Would it be "helpful" to have the PB source??
As i said ...just a question no more no less


_Moloch_
Extremely ;)

It would help, but how in the world would you be in possession of the source code anyway?
He asked a question, theoretical one.
Why do you have to ask him HOW in return.

silent102
2nd December 2005, 04:25
well all you got to do is get zone alarm or other program control software and when it ask you to allow the hack axcess to privilage resourecs you hit no or denye and it has worked for every hack i have tryed and on bf2

No1uKnow
2nd December 2005, 20:21
yeah silent, that's the same idea, and it works fine, i have a tracker account with almost 6 frag rate and almost 50 hours, whole time using this method to cover up a .dll ( cant inject it cause of the leak protect, it can only be loaded w/ aao as entry.dll or another autoloading filename the engine uses )

since i dont use that one anymore and only use my own theres no need to have any extra files in my games folder, so i dont use this method anymore

it's been posted plenty of times, just figured it would be good on this forum ^^

n()()b_Power
3rd December 2005, 22:56
I havent tried this but its worth a try for XP:


First do this:

1 .)Open up My Computer
2 .)Go up to "Tools" and select "Folder Options"
3 .)Click the "View" tab
4 .)Under "Advanced Settings" scroll all the way to the bottom and deselect "Use simple file sharing (Recommended)"

Should look like this:

HERE! (ftp://login:login@216.228.179.252:9000/FTP/TryThis.JPG)


Now you should be able do something similiar to what N1 said in the first post

load the hack, right click it, click properties, click the security tab and click deny all access

Something like this:

HERE! (ftp://login:login@216.228.179.252:9000/FTP/LikeThis.JPG)

Like i said not sure if it will work but its the same thing like in 2k.

zeus1312
12th December 2005, 21:45
Does that work with BF2 hacks, too? I guess not...

glimmerman
16th December 2005, 07:40
Is there any kind of PB blocker out there I can use to be able to use hacks such as gtebot?? or any other way to bypass PB with XP cause im not understanding the XP method completely??

gil
16th December 2005, 12:54
Is there any kind of PB blocker out there I can use to be able to use hacks such as gtebot?? or any other way to bypass PB with XP cause im not understanding the XP method completely??
No, there isnt.

alaxul
28th January 2006, 05:39
Here is a simple way to hide files in any OS DOS - XP - 2003 - Unix .... etc

Just use Yeeee Old SUBST command from the command line.

Associates a path with a drive letter.

SUBST [drive1: [drive2:]path]
SUBST drive1: /D

drive1: Specifies a virtual drive to which you want to assign a path.
[drive2:]path Specifies a physical drive and path you want to assign to a virtual drive.
/D Deletes a substituted (virtual) drive.

First create a folder, then create a batch file to make as many subfolders within it as the OS allows. Example:

Folder.bat

@ECHO OFF
mkdir Hack
copy folder.bat Hack
cd hack
delete ../folder.bat
folder.bat

Should end up looking like:

C:\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack

Then use the SUBST command to map a drive letter to that last subfolder.

eg: subst z: C:\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack

Then copy your folder.bat file to z: and run it again. You should end up with another set of folders within Z: drive. eg:

Z:\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Ha ck\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack\Hack

Now copy your Hack/Trojan/Cheat/Program to Hide into that last folder. If you need to install the game there and it has subfolders, you may need to remove a few of the Hack folders to make room.

Now, run the Hack or whatever and remove the SUBST
eg: SUBST Z: /D

The program will continue to run, but Anti-Virus, PunkBuster, VAC, Windows, no one will be able to access the data running from that folder until you restore the SUBST path. Good Luck!

Note: This protects files from being found on your hard drive, not in Memory.

AlaXul

n00blar
10th February 2006, 02:33
i dont fully understand that. i can hide anything i want in there and it wont be found?

No1uKnow
10th February 2006, 02:45
i want in there and it wont be found?

they will still be able to identify it through the memory If I'm not mistaken.

[X]-otic
11th February 2006, 16:30
i downloaded zonealarm pro but it never asks if the hack should have acess to something. first when i tried i actually got it to work by going to program control and edit some and then hide the hack folder. Then i got boored and changed what hack stuff should be on and i got detected. And now, even when i change the hacks options back, i cant make it work.

Mainly i would just like to get the zonealarm trick explained.

EDIT: now it happened again just with another bypass method..

-the_Hacker-
19th February 2006, 06:03
what about bit defender...anyone have succes with that?

Dark Blaze
19th February 2006, 13:30
Please discontinue asking all the time for various cheats. Use the search feature and look for cheats. If you cannot find what you desire, then look at http://www.mpcdownloads.com/

Conker
19th February 2006, 14:29
does no1's method work with dmw on Moh:AA

Ribz^
7th March 2006, 19:45
i have a fair bi of past experiance with universal sheild and its quite good deffinatly a plus for getting around punkbuster

C-X
11th March 2006, 14:43
i think US gets u a hardware ban ... o_O

No1uKnow
11th March 2006, 23:30
does no1's method work with dmw on Moh:AA

last time I tried it didnt work, looks like they caught onto it shortly after I posted it.

the only other "tricks" I know for PB are through hooking, so meh I wont be posting any thing else in this thread.

one way to be sure though, try it yourself [for mohaa]

[L4nt0m]
12th March 2006, 11:20
DONT use US, it'll get u a hwban..

ultramancool
24th May 2006, 12:56
I'm not too sure if this method will work but it is my strong belief. Simply get your hands on a copy of a big commercial EXE packer (It's best to get one that removes bytesand puts them in other places in your memory, like Armadillo). Then simply pack the executable of your hack/cheat/whatever you want to call it. Tada: the executable is now masked in memory and on your hard disk.)Failing this, install a rootkit on your machine and use it to hide the executable of the hack/cheat(I use BO2K for this purpose).

mike5a2
24th May 2006, 21:46
I couldnt get your idea to work, did you ever or did you just post it for no reason?

Trundle
24th May 2006, 21:53
I'm not too sure if this method will work but it is my strong belief. Simply get your hands on a copy of a big commercial EXE packer (It's best to get one that removes bytesand puts them in other places in your memory, like Armadillo). Then simply pack the executable of your hack/cheat/whatever you want to call it. Tada: the executable is now masked in memory and on your hard disk.)Failing this, install a rootkit on your machine and use it to hide the executable of the hack/cheat(I use BO2K for this purpose).
No, this won't work because PB does not scan the memory for known hack sigantures in most cases. Instead they scan the memory for hooks (by checking the first n bytes of the original game function and compare them with the original ones in their database)
Cya

Sparten
24th May 2006, 23:55
No, this won't work because PB does not scan the memory for known hack sigantures in most cases.

In BF2 alone there is about 100 of signatures of known hacks checked in every pages.

Trundle
25th May 2006, 00:40
In BF2 alone there is about 100 of signatures of known hacks checked in every pages.
In AAO they stopped signature checking (for DX&native hacks) years ago :\
Ahm, who cares. Changing the signature of a hack may work, it just depends on game and pb version
Cya

V3-C
30th May 2006, 23:14
Wont a simple rootkit do the job?

-otic"]i downloaded zonealarm pro but it never asks if the hack should have acess to something. first when i tried i actually got it to work by going to program control and edit some and then hide the hack folder. Then i got boored and changed what hack stuff should be on and i got detected. And now, even when i change the hacks options back, i cant make it work.

Mainly i would just like to get the zonealarm trick explained.

EDIT: now it happened again just with another bypass method..

He doesnt mean blokming the hack, if you deny the hack priveledges then it becomes useless. What he mea s is deny access to Punk Buster. You would get a message something like:

WARNING SUSPICIOUS BEHAVIOUR!
PB.exe is trying to communicate with hack.dll

ALLOW DENY

i have zone alarm security suiete and i always use zone alarm to deny resources to the pb, pbss.

Unstable0ne
4th June 2006, 16:38
is there a way to hide whats going on in my memory so punkbusted doesnt see it?

yupi23
11th June 2006, 01:20
works with bf2 hacks? please show me a method

HockeyBuster
11th June 2006, 01:40
Wont a simple rootkit do the job?If designed properly, yes it will work.
is there a way to hide whats going on in my memory so punkbusted doesnt see it?There are two ways of hiding your hack. One of which is to save the original function before you overwrite it, this way after you patch the function you can return the original function (Restores the correct bytes).

The second way is not to create a hook to sneak past the scans by punkbuster, but to change the functions punkbuster has. Why create new hooks for pb to detect? Why not just hook their functions which they present to you through winapi.

For example, a previous pbhack I released only changed one api pb uses. In return all hacks were undetected. They have made a patch for the version I used, however recreating it would not be too difficult.

http://www.mpcdownloads.com/forums/downloads/Sources/TrixnIce-PBHack-Source/5399.html

KizZamP-
11th June 2006, 09:34
making a hook on kernel mode level will make it so pb will not EVER be able to detect it,since pb runs above the kernel,and you're in it :).
btw : i didn't make that yet,i'm still too much of a nub for that.

§abre
7th July 2006, 23:13
Thanks HockeyBuster for sharing this info, Looks advanced alright, I wouldnt mind walking down that road someday soon, is this done with MSDN ? Is this what drunkencheata`s BF2 module does then ?