Project 1999

Go Back   Project 1999 > General Community > Rants and Flames

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 10-19-2015, 05:26 PM
Man0warr Man0warr is offline
Planar Protector


Join Date: Nov 2010
Posts: 1,734
Default

It doesn't, which is what Rogean and Secrets are saying. Unless the browser somehow interacted with the EQ executable.
__________________
Green
Tofusin - Monk <Force of Will>
Manowarr - Druid

Blue
Tofusin - 60 Monk <BDA>
Shiroe - 60 Enchanter
Manowarr - 60 Druid
  #2  
Old 10-19-2015, 05:33 PM
dafier dafier is offline
Planar Protector


Join Date: Mar 2015
Location: Buried in a cove.
Posts: 1,380
Default

So. If you try to read what's in your local mem space, it will start a logging process? Or is it modify only?
__________________
Rebbon - BDA
Happy Epic Mage
  #3  
Old 10-19-2015, 10:19 PM
simp403 simp403 is offline
Kobold

simp403's Avatar

Join Date: Jul 2015
Posts: 100
Default

Quote:
Originally Posted by dafier [You must be logged in to view images. Log in or Register.]
So. If you try to read what's in your local mem space, it will start a logging process? Or is it modify only?
Every process is allotted a portion of memory it can use at runtime. This process cannot access the memory space of any other process by virtue of the process control board unless specifically allowed to do so. When you ask can "you" read, do you mean you as a user accessing the memory? It's definitely possible to grab the data in memory, but from what I've seen, a number of games, usually MMOs, have code built in that detects if you access its process memory and will kick you. This is implemented to help combat botting and I know ArcheAge had something like this in place.
__________________
Dinobots
  #4  
Old 10-19-2015, 05:39 PM
Oleris Oleris is offline
Planar Protector

Oleris's Avatar

Join Date: Dec 2013
Location: Anaheim ด้้้้้็็็็็้้
Posts: 1,382
Default

the best part of the thread was secrets arguing with clayton (last name here) on the FB page.
__________________
<Aftermath> Oleris- 60 epic necro, Olerris- 60 epic monk. Songerino 60 epic Bard

Halloween 2015 event: https://www.twitch.tv/videos/23440971

PL service
https://www.project1999.com/forums/s...d.php?t=313502
  #5  
Old 10-19-2015, 06:03 PM
Secrets Secrets is offline
VIP / Contributor

Secrets's Avatar

Join Date: Oct 2009
Posts: 1,354
Default

Quote:
Originally Posted by Oleris [You must be logged in to view images. Log in or Register.]
the best part of the thread was secrets arguing with clayton (last name here) on the FB page.
[You must be logged in to view images. Log in or Register.]
__________________
Engineer of Things and Stuff, Wearer of Many Hats

“Knowing yourself is the beginning of all wisdom.” — Aristotle
  #6  
Old 10-19-2015, 10:28 PM
simp403 simp403 is offline
Kobold

simp403's Avatar

Join Date: Jul 2015
Posts: 100
Default

Sorry for the double post. To clarify, I'm pretty sure you can still write a program that accesses the process memory of another process. This is what MQ does from what I gather. However, the process whose memory is being access can see what other processes are interacting with it, which is how I think anti-cheat measures are created to combat things like client-side hacking and grabbing or altering the game's memory.

This is what I believe Rogean's code does: it detects whether or not another program is accessing EverQuest's memory space and sends information on that program to his server. This is how he can see the filepath that MQ was installed in. When a program runs, it does not run as "program.exe". It runs as "C:/Program Files/fuckyou/program.exe". Being able to see the filepath and the machine's name does not mean the program has access to other information in your system.

Furthermore, the Everquest client code is not altered whatsoever by Rogean. I believe this means that it will only be able to access primary and secondary memory that the actual EverQuest game could access. In other words, Rogean cannot somehow change the client such that it can grab web browser information or other system information outside of the information it normally has access to just by adding in a dll file.
__________________
Dinobots
  #7  
Old 10-19-2015, 11:36 PM
Magikarp Magikarp is offline
Sarnak

Magikarp's Avatar

Join Date: Dec 2013
Location: MSN Instant Messenger
Posts: 325
Default

this explains why my bank account is low and i got that fixit ticket for expired registration the other week and i may have a drinking problem

illuminati everywhere

damnit rogean. glad to have someone reveal the TRUTH for all to see
  #8  
Old 10-19-2015, 11:48 PM
iruinedyourday iruinedyourday is offline
Banned


Join Date: Apr 2014
Posts: 7,351
Default

i heard the virgin detector they put in the client crashed the internet for 30 minuets.
  #9  
Old 10-19-2015, 11:52 PM
simp403 simp403 is offline
Kobold

simp403's Avatar

Join Date: Jul 2015
Posts: 100
Default

Quote:
Originally Posted by iruinedyourday [You must be logged in to view images. Log in or Register.]
i heard the virgin detector they put in the client crashed the internet for 30 minuets.
EverQuest can't run on Linux, though.
__________________
Dinobots
  #10  
Old 10-19-2015, 11:54 PM
Secrets Secrets is offline
VIP / Contributor

Secrets's Avatar

Join Date: Oct 2009
Posts: 1,354
Default

Pretty much, a DLL can do all of that. But his doesn't that is the key.

It'd set off AVs and then some. And not just on runtime; it only sets off AVs on runtime because it's packed with Themida. If it was sending your bank information or recording keystrokes you figured someone would've picked that up by now.
__________________
Engineer of Things and Stuff, Wearer of Many Hats

“Knowing yourself is the beginning of all wisdom.” — Aristotle
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 01:47 AM.


Everquest is a registered trademark of Daybreak Game Company LLC.
Project 1999 is not associated or affiliated in any way with Daybreak Game Company LLC.
Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.