The BASHandSlash.com Feed

BASH Webcasts

Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Wednesday, July 11, 2007

Using Dev mode to catch hackers

Sunny Fire, a BASH webcast listener, wrote to me the other day regarding our program entitled:
HaXer!

Hi thank you for the great info on the COD2 Webcast. I was just wondering in your webcast you were talking about the subject of using Developer mode in demo mode. I have typed in developer in the the counsel mode and nothing comes up as far as seeing what others see in the demo without the walls. As mentioned in the webcast. If possible can you please type to me in regards to this as to how do you type it in the counsel of COD to activate the Developer mode to be able to view these demos to catch hackers. Thank you very much for your time.

Well Sunny Fire, hope you enjoyed the show. I've posted your question because I assume others might be interested as well.

Try visiting this site,

http://www.punksbusted.com/forums/index.php?showtopic=21303

it has a step by step instruction on how to do this.

I haven't done it in a while - but I think it should still work! LOL.

Please let me know how it works for you.

Wednesday, June 27, 2007

Alert: Dark.net bot strikes CoD community

Sparks, from the Rise of the Resistance website posted this unhappy news on their forums last night:


Forum/Site Breach

Tally's other site [Tallys-World] as well as this one [Rise of the Resistance] got hacked/breached.

{EDIT}

Forum will be restored sometime Wednesday/Thursday when Tally returns from his trip to Infinity Ward.

Any questions, concerns, or comments... drop me a private message.

Sorry for the inconvenience and we hope to have the forum up and running again shortly.

Production has not ceased or slowed down.

- Alex "Sparks"
What we do know

BASH has learned other sites have also been affected aside from Tally's and RoTR's. Apparently, there is some indication that this is a world-wide problem affecting PHP Nuke sites. Hackers may have detected some vulnerability in these sites and are attacking them systematically.

Interestingly, the Devil-Dogz site was recently attacked by bots (automated scripts) attempting to write (gibberish) into its forums - at least that was what everyone saw on the surface. Security measures were upgraded and it seems the server survived the attacks (however the software it uses is not PHP Nuke).

If you have noticed such activity on your site, you might want to review your own security procedures (oh...and make backups!!). And make sure you have applied all the patches to your systems - not just OS patches, but 3rd party software as well!

There is current suspicion within the CoD community that the bot doing the damage is called:

"Dark.net"

The attacks have been going on for some weeks now. Apparently, 25 June 2007 was a "trigger" date for the bot activation.

According to those in the know, in order for the dark.net bot to work it "would have had to compromise your site and attach itself to it as a user". The lethality of the bot is clearly high and fortunately the American federal government is now involved.

BASHIE award winning RoTR

We are all looking forward to RoTR being restored again to what it was ... a BASHIE award winning website. I hope the culprits are caught and dispensed with.

Guest Editorial: CoD2 Hackers

Our guest editorial this week is written by a Devil-Dogz clanmate of mine, {DD} LemOnade. LemOnade is an extraordinarily gifted FPS player - and for that reason is much feared and respected by our competition. He is a passionate competitor and that passion extends to his writing. In today's topic he picks up from where BubbaGump and I left off in Episode 26: Haxer! Remember, all opinions expressed in this article are those of LemOnade. Please post your rebuttals below (under comments) or email him at the address shown.

{DD} LemOnade
BASH Guest Editorial
email: crazybandit@hotmail.com

1. Why players hack.

There are a myriad of reasons why people cheat. I think it all starts with society in general. Name a console/computer game and any 7 year old can tell you where to find the cheat codes for it. What are we telling these children? "Don't worry son, you're ENTITLED to win. Here's the cheats". Multiplayer gaming is just a carry-over from these same children and their cheat codes in a lot of cases.

Then you have the people who are so competitive they will do anything to win. We all know a few of them. These are the same people in real life you wouldn't want to be the banker in a friendly game of monopoly.

There's also a small amount of people who cheat who simply want to cause chaos and ruin the gaming experience for others. I'm sure there are many reasons for them being this way, but since I lack this quality or a degree in psychology, I will simply comment on it and not the reasons. The reason I know they exist are the answers given when asked why they cheat. "I'm bored." or "You're just mad cause you suck."

I find myself having a modicum of respect for the hacker who boldly proclaims his hacks and doesn't try to hide behind the "I'm just a good player, you noob." defense. I mean, lacking an admin on a server, what can you do to a hacker anyway?

2.What type of hacks are being used in COD2?

I wouldn't know the name of the countless hacks that are available to players, but i can tell you the main ones and describe what they do:

a. The wallhack. There are a lot of names for what is essentially the same hack. Whatever the case may be, a wallhack allows you to see through solid objects and know where the enemy is on any map. Some of these cheats will cause the enemy to glow (for lack of a better word) through walls and other objects. Some of these cheats simply allow you to see the enemies name (and location by default) over their heads wherever they are on the map. Some of these same cheats will also tell you what weapon your enemy has, and the distance to target from your location.

b. The aimbot. Pretty much as it reads. The aimbot is a program that allows your computer to aim for you. When used in conjunction with a trigger bot, this can make a hacker almost unbeatable in some circumstances.You run into this less than the wallhack because even the least experienced player knows something is not right when someone is shooting them in the head from across the map before they ever even see them.But there are a few who use it. Some of the toughest cheaters to catch are experienced players who use an aimbot but no wallhack. Even when following these players in spec, you cannot see them looking through walls because they are not. The aimbot for the most part is subtle, if they have the intensity of acquisition set right. Some noob hackers turn the intensity all the way up and you'll see them do a complete 180 and shoot someone in the head from across the map. Even then its hard to prove they have an aimbot, because good players sometimes make incredible shots.

c. The aforementioned trigger bot. This program allows your computer to fire when the aimbot acquires the target. The timing of a trigger bot is instantaneous, taking human reactions out of the killing equation. However, as said before, this makes the cheater more obvious.

d. No recoil. There are programs which allow you to fire your weapon with absolutely no recoil. This gives the cheater a huge advantage against the average player. It allows the cheater to follow the target effortlessly, since you do not have to allow for recoil. This cheat gives you the most advantage with smg's and machine guns since each have a higher rate of fire, and more recoil than other guns.

There are more hacks out there, but these are the most prevalent, imo.

3. How can the average player spot the hackers?

I don't believe the average player CAN spot most of the hackers out there. Simply put, I believe you have to be of a certain skill in the game yourself and know what each weapon can and cant do naturally before you can become competent in spotting the cheaters. Even then, most times you cannot tell without sitting in spectator and watching the player for long periods of time waiting for the moment whet the cheater reveals him or herself.

But anyone who plays the game can go to spectator and make a demo of any suspicious player. I recommend that everyone who thinks there are cheaters on the server they are playing make such a demo. This will allow the average player to, at his leisure, go back and watch the demo for what they feel the player was doing that made them think he/she was cheating. If the player finds something that is obviously a cheat, simply get in touch with that servers admin and send the demo through xfire or whatever peer to peer program that allows for transferring files. I myself have gotten many players banned from a server by making a demo of cheaters.

To record a demo, simply pull up your console by pushing your ~ key on the upper left of your keyboard. Then when that little bar comes up with the blinking underscore line, type in
/demo
"name of file"

Name the file something you can remember because you are going to have to go into your Activision folder to find it, and naming it will make it easier to find. I usually name the file whatever the suspected cheater's name is in game. The trace route to find this demo will be:

C:Program Files/ Activision/ call of duty 2/ main/ demos

To view this demo and make a determination if the player is actually cheating, click on your multiplayer icon but dont enter a server. Open your console and type in

/demo

"name of file"

When you hit enter, there will be a delay of a couple seconds and then the demo will start playing. You can then view whatever it is you made the recording of.

4. Are there solutions to the problem of cheating?

Can clans mitigate the problem?

Of course there are solutions. For every cheat program out there, the game makers could come up with a detection program. This however, is not making the game makers any money, so they have no interest in supporting their product in this way. We all know the bottom line in our society is "Does this benefit me financially?". The makers of CoD2 made a half-assed attempt to make people believe that cod2 would be cheat free by adding PunkBuster as cheat detection. But every hacker knows that PunkBuster is a joke. There are so many holes in the program, its a good thing it's not a submarine. Anyone reading this diatribe, think about it. How many times have you seen PunkBuster actually CATCH someone cheating? Ive played this game almost daily since it was released, and i can count on one hand the cheaters PunkBuster has caught while i was playing.

Since the cheat detection is lacking, its up to server administrators to police their own server by observing players. I recommend you make a demo of cheaters before banning, because there are a lot of people who would rather blame the administrators of a server, than try to recognize that there are cheaters in COD2. Also, make sure you record the offending players GUID so there can be no doubt of who is actually playing the game when you catch them cheating. Good luck, and hope this helps people in the gaming community.

Sunday, June 24, 2007

BASH: Episode 26 (Haxer!)

In this week's BASH webcast, we bring you an episode on the scourge of on-line gaming, the Haxer!

Ben (a.k.a BubbaGump) joins me to co-Host this episode. You will all remember Ben from Episode 20 on Rise of the Resistance. Ben resides in Melbourne, Australia and we hope he will be joining us more often in the future.

In the episode we attempt to define cheating and hacking. We come up with the following:

Hacking, in fps-gaming, consists of gaining a competitive advantage in the game by modifying game files and thus altering the game's software code. Cheating, while not as blatant as hacking, can be thought of as the exploitation of flaws or bugs in the gaming software or the configuration of client-side game variables counter to the instructions set forth by the administrator of the gaming server.

The most powerful hacks are known as client-side hooks. These cheats inject hacked code right into the game executable. They do this by using a "loader" program that finds the game and loads the hack, also known as a "client side hook" (DLL) right into the game. Once the hook is in place the hack has access to all sorts of information the server sends the player (location of other players is the most interesting information). Client side hooks allow:


a) AIMBOTS - these hacks use player data from the server download data stream (snaps) to adjust mouse x,y coordinates. They target the nearest enemy hitbox and result in very, very accurate fire. If you have a high snap/maxpackets setting or good ping - you will get incredible hit registration resulting in a high number of kills.


b) WALLHACKS - these hacks allow you to see enemy players even through walls - an incredible tactical advantage. Of course wallhacks rely on intercepting the download data stream.


Additional hacks/cheats include video card hacks that can clear up fog in a game, scripts that allow you to zoom in (without using a sniper rifle) and auto-fire a Garand!


By any definition, currently, there is a blatant flouting of the gaming moral code going on at msxsecurity.com. This site is notorious for selling game hacks - including those for CoD2. Here is a video showing their wares:





A Belarussian, Maz is the leader of this piratical crew of coders. They do have a sense of humor, judging by their Forum avatars, but is a sense of humor what got them into hacking?

Maybe it's money?

Check out what he was offering as far as compensation back in 2005!
if you have a firm grasp on d3d and C++ then give maz a ring on IRC. You will reap the lucrative benefits of 40% income for every hack that you successfully create. Typical income should be ~50$ a day but in some cases much higher. It will be your responsibility to continually update your hack based on user input. If you don't update your hack and it gets detected, obviously the money is going to stop coming in. Anyone serious should contact me through some means and let me know there (sic) expectations.
At $50/day you're not going to find too many Silicon Valley C++ superstars signing up...but if you're living in Mumbai, or Belarus...you might consider it. To combat these black hat gamers, an online petition has started up to attempt to reign in folks who make money from selling on-line gaming hacks.

Check out this post: pen-is-mightier-than-hack

Also in the program this week, we mention this story about hackers/cheaters caught in China: you-cheat-you-bleed.html

What are the solutions to finding hackers?

Obviously, PunkBuster, brought in at version 1.2 of Call of Duty 2, is one. Certainly there are a lot of people banned from gaming due to PunkBuster, look at the list here: punksbusted.com

However, PB may not be as effective as you may think. Many savvy server administrators simply record players suspected of cheating in "Spectate" mode and play it back. The best way to view the video is to play it back in Developer mode (~ developer 1 - Turns developer mode on). This allows you to not only view the suspected-cheater but also allows you to see all the players in the game simultaneously.

The gaming community can do a great deal to slow down cheating. Check out this site in Australia: allseeingcow.com


Spotting a cheater:


- look for people shooting through fog (graphic card no fog cheat)

- look for people getting lots of headshot kills (aimbot)

- look for players rounding corners and firing accurately at people on the other side indicative of a wall hack. Or for that matter staring at players through seemingly transparent walls.

- look for players firing accurately through bushes (wall hack)

- look for players finding map seams (map exploit).

- look for players firing bolts/rifles as though they were automatics (scripting hacks)


BTW: If you cheat on-line, we want to talk to you here on BASH and find out what makes you tick, send your GUID and your email to: jockyitch@devil-dogz.com.

Wednesday, May 30, 2007

Netstat: Check if ET is calling home

During the last of our Malware trilogy over on our webcast BASH we told you about a program that monitored what processes were running on your PC, it was called WinPatrol.

Well did you know that you have another program already installed on your Windows system to allow you to find out if those processes are trying to communicate on the internet?

It's called netstat and it has been around for a long time. In Windows XP, to use netstat, you click on:

START > RUN > type "command" > click OK > type netstat > hit Enter

All the network connections you have made will be shown. If there's something there that you don't recognize, it might give you pause to think that there's a virus on your system trying to communicate with its home base.

netstat is a little difficult to understand if you are not a real computer whiz, but there's a very informative webcast that will explain it a bit better at Leo Laporte's Security Now site.

Download the webcast here: The NETSTAT Command Episode 49

Even better than netstat is a program that is mentioned on Leo's site called: TCPView

TCPView is a visual GUI'ied up version of netstat and much more user friendly. The program now belongs to Microsoft AND it's free.

If you think you have processes running that are slowing your system down - run TCPView, it might be illuminating!

You can also learn more about what to do with netstat, TCPView to enable you to kill any viruses/trojans you may have here: Nohack Project

Related articles:

Malware

Sunday, April 22, 2007

The Malware War: Defense in depth

BASH: Episode 16 (The Malware War)


Show Notes

Episode 15 of BASH raised a lot of issues but did not provide much in the way of specifics to either protect yourself from, or rid yourself of, malware.

In this article we summarize what we learned from Episode 15. The major points from Episode 15, can be separated into technical and behavioral elements.

Let’s start with the technical elements:

1. Keep your operating system patched to the latest revision.

Make sure you turn on automatic updates (we showed how in Episode 15). Apply any critical Windows updates right away. Hackers will create malicious programs taking advantage of any deficiencies with Windows within one day of Microsoft announcing a new patch. These are called zero day exploits - so make sure you patch your system the day the patches appear.

2. Use a firewall.

The best is a hardware firewall - a wireless router is a good example - this is a device that lets you share a single Internet connection amongst many computers. While they may not be advertised as firewalls - routers are excellent at preventing hackers from getting into your system.

Software firewalls are a second best solution. Microsoft's firewall, for example, is a software firewall and should be turned on even if you are running a hardware firewall.

Although we did not talk about this in the last episode:

3. Do not log in as a System Administrator.

If hackers pass your firewall their software can easily install itself if you have complete system privileges and you do if you are logged in as an Administrator. Instead, log into your computer as a limited user. XP has special problems when it comes to this due to the fact that programs written for XP never thought they would have their system privileges restricted - so some of these programs may not work well if you run as a limited user. However, if all you are doing is surfing and running Call of Duty - you should not have too much of a problem.

The next item is a behavioral element:

4. Don’t open email attachments.

Email attachments are the number one way viruses and Trojan horses spread and can get into your system. Turn off HTML email in your email browser (for example, MS's Outlook). As well, don’t click links in email. Hackers regularly spoof the real link they want you to browse. For example you may think the link says cnn.com but in reality the hacker could actually be directing you to hack.com. If you need to go to some one's link, manually copy and paste the link into your browser. If the link is spoofed you'll see the real address in your browser's address window.

The final element is to use software against malware.

5. Don't surf naked: use anti-virus and anti-spyware software.

Don’t download files from unsafe places. Filesharing software like Azureus, Kazaa, and Limewire, many times cause you to unknowingly download files that contain spyware and Trojans. Make sure you use an antivirus program on anything you have downloaded. Additionally, there are programs you can download for free to detect and prevent infestations.

Well, this is all well and good I suppose. If you use that advice, not only will the likelihood of getting malware be low, your productivity will be as well. Given the dependence we have on the Internet these days it is very important that we be able to surf freely. If you are limited to certain sub-domains because you're afraid of getting a virus, you'll be spending all of your time on either Google, Yahoo or Amazon.com.

So on behalf of all the bobs_t_shirts.com and weedwhacker.net sites out there, we need some practical solutions to these problems and hopefully, this article will provide them to you - or at least tell you where to look.

Since this freedom to surf is of primary importance to gamers who spend a considerable amount of time on the net, let's look at some practical solutions to each of these issues.

Let's look at some of the technical elements first:

1. Keep your operating system patched to the latest revision.

Although the ball is squarely in Microsoft's court to fix the holes in their operating system before hackers try to exploit deficiencies in it, you can do your part to keep your operating system up to date and the simple way to do that is to ensure your Automatic Windows Update is turned on.

Unfortunately for us, Microsoft is usually fixing these holes after the hackers have exploited them. Compounding this is that when an exploit is found, the news of this is broadcast by the media far and wide. This alerts other hackers world wide that there is an exploit to be had - and the bad guys flock to it like flies on buffalo poop. For this reason, the days immediately after such an announcement are very dangerous as every black-hat programmer in the world is training their sights on the same program flaw. Some people call these exploits "zero-day" viruses for obvious reasons.

Patches are typically issued for Microsoft programs the first Tuesday of every month: so called, patch Tuesday.

As a gamer, you usually don't have much of a choice but to stay with Windows products and thus are susceptible to these issues. If you are a regular reader of the influential planetcallofduty.com you'll know that CoD2 is available on the Mac now. So, if you are really paranoid about viruses - try the Mac which although not invulnerable is a much safer operating system than Microsoft.

An excellent example of a recent zero-day virus is something called the animated cursor exploit - you may have heard about it just a few weeks ago in the news. Animated cursors are often used on websites (a spinning hourglass is a typical example of animated cursors), well it turns out that you the surfer don't get a choice whether a website attempts to animate your cursor. Turns out that Windows had a bug in their operating system that allowed unscrupulous hackers to upload malware through files that were supposed to animate your cursor on various dodgy websites. This malware would typically be a Trojans which could compromise an infected computer and gain complete control of it. Although Microsoft just patched this but, the vulnerability existed regardless whether you were browsing in IE or in the other popular free browser, Firefox. Antivirus programs, firewall...nothing would stop this type of exploit - except to update your operating system.

2. Firewalls

A hardware firewall is a gadget that acts like a one way valve to prevent unwanted network traffic from communicating with your computer. Additionally, if you set up your system correctly, you could completely hide the computers behind that firewall from the prying pings of hackers.

Which hardware firewall should I buy? Without a doubt the most common firewall out there right now is a router, either a wired or wireless, or WiFi router. We have decided to write about a very common configuration in many gamer households, where the gamer uses a desktop PC and at least one family member uses a portable laptop. Therefore, we’ll pick a wireless router for our firewall.

Connecting your broadband modem into the wireless router will provide you with a WiFi connection anywhere in your house for your laptop users. As well, most wireless routers allow you to connect an Ethernet cable directly into them, therefore you can plug your Desktop PC into one – giving you a connection speed that is just as fast as being directly connected into your modem. Importantly, all the devices connected to it can be hidden from the prying pings of Internet hackers.

What should we look at when buying a wireless router?
Is it stable (does it need to be rebooted all the time)?
Can I prioritize the routing of certain software applications above all others?
And finally, what does it cost?

Of all the wireless routers, one of the least expensive is the Linksys WRT54G.

Linksys WRT54G

It is by far one of the most popular devices that can be used as a firewall. The 54G's became well known because they were very customizable through 3rd party modifications. Although customization has become difficult lately, the 54G remains popular because of its low price: $50 US.

The device is capable of sharing Internet connections amongst several computers via IEEE 802.3 Ethernet and 802.11b/g wireless data links.

Having said all that, we have personally found it to be somewhat lacking rock solid stability and it needs to be rebooted from time to time; however, upgrading the unit to the very latest firmware – a free download off the Linksys website, has greatly improved the situation. Did we mention it is very inexpensive? As with most routers you can decrease the effect of latency when you are gaming and two or more people are using the router by programming the unit to prioritize the packets coming from, say your Call of Duty software. This is easy to do and can be done by accessing it through a web-browser.

With it, wired devices connect to a blazing fast standard ethernet 10/100 switch and on the wireless side, you'll transfer data at 54 Mps

Now, if you are a hard core gamer, then the D-Link DGL4300 might be for you.

D-Link DGL4300

The D-Link has been a favorite amongst reviewers for sometime now. At approximately $140US you get the following features:

• It has a slightly smarter packet filtering method, a proprietary algorithm called GameFuel. It prioritizes incoming and outgoing packets going through your router. Gaming packets will have priority over other packets such as those commonly associated with FTP and web traffic, allowing you to maintain consistent latencies while playing online games.
• Enhanced wireless technology for optimal range and connectivity – up to 108Mbps
• Enables multi-tasking between other applications without degradation in game connection.
• Customizable settings to add or modify new applications or game configurations
• A Firmware upgrade notification feature.

Now, did we say that if you get in behind a router, wireless or otherwise, you are safe? Well guess what? Don't leave your credit card numbers on the hard drive just yet.

The computer magazine PCWorld found way back in November 2002 that if you leave the default password on your router (which by the way most people do) hackers can – at least on some routers - rewrite the code controlling your router and gain access to your system. Interestingly if your next door neighbor is using the same type of router and they use the default password you'll both be using each others routers without knowing it. So remember to set a different password!

Now in addition to hardware firewalls, you may have heard of software firewalls. What are these?

Well, a software firewall is simply a program that runs in the background all the time. Its basic function is to monitor all traffic trying to get into your computer and lets you decide whether you want to let it in. The software firewall then alerts you to any unwanted intrusions. As well, YOU get to choose which programs are allowed access to the Internet and thus you can prevent worms, Trojans and spyware from infecting your computer. Without one, any program you install has access to the Internet.

The downside to software firewalls is that if you do get infected by a virus, the really dangerous ones will rewrite the software firewall code itself to prevent you from knowing the virus is there. For this reason there are a lot of computer experts who do not recommend surfing the net with only a software firewall. Use both a hardware and a software firewall for maximum protection.
The other downside is that software firewalls consume CPU cycles and computer resources.

A very concise list of these programs can be found at: hackfix.org/software/configure and click on the Firewall software listed there.

Here’s the do’s and dont's of a software firewall. Like the hardware version, they:

Help block computer viruses and worms but they do NOT detect or disable them.

Software firewalls WILL ask you for your permission to block or unblock certain connection requests, but it does not stop you from opening e-mail with dangerous attachments.

Software firewalls can create security logs of the sites trying to send you requests for access but they do not block spam or unsolicited e-mail.

Some of the more sophisticated software firewalls do indeed do some of those things, but we'll keep things simple here and discuss two products that only do the basics.

Here are 2 software firewalls I can recommend:

a) The Windows Firewall.

This was previously known as Internet Connection Firewall or ICF. If you're running Windows XP Service Pack 2 (SP2), Windows Firewall is already installed and it is turned on by default. However, some computer manufacturers and network administrators might turn it off.

To turn it on:

To open Windows Firewall
1. Click Start and then click Control Panel.
2. In the control panel, click Windows Security Center.
3. Click on Windows Firewall

The Windows Firewall is a very basic program. It's fairly unobtrusive in that you'd never know it was running.

When someone on the Internet or on a network tries to connect to your computer without being requested to do so, Windows Firewall blocks the connection. If you run a program such as a multiplayer online game that needs to receive information from the Internet, the firewall asks if you want to block or unblock the connection.

If you choose to unblock the connection, Windows Firewall creates an exception so that the firewall won't bother you when that program needs to receive information in the future.

b) ZoneAlarm

There are two versions of this firewall. I want to only talk about the free version here. ZoneAlarm is hands down every one's best software firewall. The biggest difference between it and Windows Firewall is that Zonealarm is bidirectional. That is, it not only senses intrusions it also senses outbound traffic. For example, if someone hacked your computer and installed a program that will try to access the Internet, ZoneAlarm will alert you and you can then take action to shut that program down. It even has a stealth mode to hide your computer from hackers.

The downsides to ZoneAlarm are that it slows down your computer and takes up system resources.

The other big downside is that ZoneAlarm is very obtrusive and warns you about even innocuous events. For this reason, it is probably best left to power users. Remember, the goal of Zone Alarm is to sell you ZoneAlarmPro for $50 so their goal is to sufficiently frighten you into buying their pay version – so it tries to draw attention to itself as much as possible to show you that it’s working. Novice computer users could find this frightening.

Zonealarm’s website is found here: Zonealarm

Don't run ZoneAlarm with any other software firewall. So if you download it - make sure you turn off Windows Firewall.

Right now, ZoneAlarm just takes up too many system resources for me to recommend it while you are gaming. Use Windows Firewall while gaming and turn ZoneAlarm on at other times. But don’t run both simultaneously.

In the next edition of our articles on malware we discuss the details of changing your online behavior and more excitingly, we discuss what software programs you can download (most for free) to help you protect yourself against malware.

Related Articles

How to protect yourself from Malware

Monday, April 16, 2007

We've been punked! *UPDATE 1*

BASH has just received a straightforward reply from Evenbalance regarding the lag induced by their latest Punkbuster update.

As you can read in the BASH article We've been punked!, Evenbalance has added two background processes that run while Call of Duty (or any other Punkbuster enabled game) is running; namely: PnkBstrA.exe and PnkBstrB.exe.

A few days ago, we opened a ticket with Evenbalance and asked them the following questions:
While we greatly appreciate all the efforts you folks are doing to keep us playing in a Cheat-Free environment, the lag induced by the new update has caused some issues.

Can you explain what has caused the lag and if there are any solutions to mitigate it. Currently there are community workarounds.

I have posted a few on my blog. I am sure you cannot sanction such activity; however, can you suggest what we CAN do? Currently your 2 new executables (PnkBstrA and B) are eating up a significant amount of CPU resources and undoubtedly contributing to a slowdown in-game. I would greatly appreciate any information you can provide my readers/listenership.

Glenn Courington, from Evenbalance, replies:
04/16/2007 14:39:41 - "Glenn Courington"

Note #2: As your blog states, yes, these new services will take additional CPU cycles, as this is by design to use CPU cycles that aren't allocated to the game or other processes.

As for the "solutions" posted, no, those wouldn't be solutions. While it hasn't been initiated yet, it will soon be required to run these services to play on a PB server. Uninstalling them or turning them off will result in a kick from the server.

As for lag issues, we have been making updates to correct such issues, and we will continue to do so as needed.

http://www.evenbalance.com/index.php?page=pbsvcfaq.php

So there you have it. Please ensure that you do NOT remove the PunkBuster background processes.

Hopefully, Evenbalance will sort out the lag issues.

If anyone is having lag issues, please let us know. You can email us here at BASH:

jockyitch@devil-dogz.com



Additional articles:

remove those un-needed processes
protect yourself from malware

Sunday, April 15, 2007

You cheat? You Bleed.

With all the controversy over the lag induced by the new PunkBuster upgrade, the focus has once again shifted to the cheats that ruin our online multiplayer gaming experience.

Well say what you will about the government over there in China, I like their policy on hackers.

Read this article to see what one on-line gaming community did when they found hackers on their system:

www.texyt.com

Friday, April 13, 2007

We've been punked!

Has anyone noticed increased lag, higher pings, packet loss, lower FPS and loss of system resources lately when playing online?

Well, it can probably traced to the latest Punkbuster updates.

The latest updates of Punkbuster have certainly wreaked havoc with us here in the COD2 community.

What you may not have noticed is that Evenbalance (the authors of PunkBuster) have added two new processes to their PB suite:

PnkBstrA.exe and PnkBstrB.exe!

That brings them up to a grand total of four processes total - all robbing you of system resources while your playing, albeit for a good cause, I suppose.

What are these new services? Try reading this:

http://www.evenbalance.com/index.php?page=pbsvcfaq.php


Beginning with PunkBuster client version 1.500, we have extended the PunkBuster Anti-Cheat system to operate without the requirement to run PunkBuster supported games with Administrator privileges when running under Windows 2000, XP, or Vista. In order to do this, we have developed new Windows service components to work with the PunkBuster system. We are currently conducting open beta testing for the new service components. To participate in the open beta testing, issue the "pb_installservice" command in your game console after joining a server (at this point, you must still be running as the Administrator user). This command will attempt to install a new PunkBuster service called PnkBstrA. Alternatively, the PBSVC Setup Program can be used as a standalone installer/uninstaller for the PnkBstrA service; PBSVC can be downloaded from here. Once the PnkBstrA service is running along with a new PB client version 1.500 and higher, running PB enabled games under Windows 2000, XP or Vista no longer requires Administrator privileges.

It appears that both executables are part of the latest Punkbuster update. And one, PnkBstrB.exe seems to be looking for cheats on your drive.

The upshot is a very significant increase in system resources while playing. Try bringing up your Task Manager while playing to take a peek. Some people are seeing 30-40% of the their CPU resources being taken over! This is higher than what COD uses most times.

While my initial anger at this made me point to PB...the real culprit is the cheating hacker! Well what can you do about it?

SOLUTIONS?

BASH has found a few solutions that have been found successful by non-COD gamers and we post them here. We have not tried them out and you should use them with great caution:


A. This was found referenced on http://forum.americasarmy.com

1. Click on the start menu, click on Run.... Type services.msc.
2. Under services find PnkBstrA. Right click it and stop it from the option in the drop-down menu.
3. Now double click it. On startup type select disabled.
4. Repeat 2 and 3 for PnkBstrB.
4. Go to your windows/system32 folder.
5. Find the two files, PnkBstrA.exe and PnkBstrB.exe and delete them.
6. Go to AA/system/pb folder.
7. Delete PnkBstrB.exe and PnkBstrK.
8. Go to http://www.americasarmy.com/includes/bumper.php?goto=http%3A%2F%2Fwww.evenbalance.com%2Findex.php%3Fpage%3Dpbsetup.php and download the pbsetup for your operating system.
9. Install. Select game directory and update PB.


B. Also from americasarmy

1) delete Punkbuster folder contents in system folder
2) goto start>control panel>administrative tools>services
3) goto extended tab select PnkBstrA. Double click it to see properties you will see a drop down menu select disabled.
4) goto PnkBstrB Double click it to see properties you will see a drop down menu select disabled.
5 ) Download this for your OS http://www.evenbalance.com/ind...tup.php
6) run pbsetup select your game directory and update PB
7) should be gone now go play with out lag!

Both solutions are similar. The folks who have come up with the solutions say their lag was gone once they performed the tweaks and PunkBuster has not kicked them from any server.

The jury is still out on these fixes...stay tuned.


Notes:

Punkbuster support is apparently telling its users that CPU usage has increased with this latest update; however, PB will use "unused" CPU cycles as it completes scanning your system for hacks. They are stating that this will not be detrimental to gameplay.


Related posts:

remove those un-needed processes

protect yourself from malware

The pen is mightier than the hack!

Anti-Cheat Petition

Check out this petition to Software Companies and Legislators:


http://www.petitiononline.com/screwMSX/petition.html


It reads something like this:

This is a petition to the gaming industry and their attorneys as well as to state and federal lawmakers to pass and enforce legislation to penalize those responsible for profiting from distribution of hacks and cheats in online multi player games. The impact of this malicious activity is not only degrading the gaming experience for players but affecting the corporations that publish the games monetarily. I implore all affected parties to read this petition and take action to save online gaming from these criminals.

Sincerely,

The Undersigned