Ultimate Empire
BattleForums Addict
- Joined
- May 18, 2003
- Messages
- 701
- Reaction score
- 0
@ ACE or CM - Please add this to one of the sticky compilations of information, as it is worth further researching
-----------------------------------
eEye's Iris Packet Analyzer and its Applications to D2 Hacking
###INTRO
One of the main reasons that hacking in Diablo II has beeen deduced to forms of maphack and bots is due to new anti-hacking mechanism's produced by Blizzard to scan for modules attached to Diablo II.exe or its inherent modules. This is known as the Warden. (Thank you Dark_Mage) Which can be verified here:
Therefore modules such as d2hackit are easily detectable. And new versions, that aren't currently referencable by the list warden uses to scan for hacks, is easily updatable. Thus the problem...
###eEye Security - www.eeye.com
eEye is an internet security company that produces a set of tools that ANY hacker would drool over. Even though a true hacker would construct their own tools due to an inferior set of tools produced by commercialization.
eEye's tools are far from inferior.
The problem lies within the fact that these products are commercial, and due cost a hefty penny. This of course will never stop the latest P2P engine from having them for free though. (Contact me if you'd like 'certain files').
If you have time, get all the eEye tools and experiment with them...however this article will only focus on the Iris product.
###eEye's Iris - http://www.eeye.com/html/products/Iris/
I'm sure most of you have used a simple packet sniffer/scanner before. Imagine having the ability to not only sniff packets, but send them as well via an external program. This is what eEye's forensic tool: Iris, was built for.
Iris has the ability to capture and resend modified packets (or new ones) through any protocol over any size network (ie the internet) without attaching itself as a module to the original application that sent the packets.
###Iris' Applications to D2 Hacking
By now, you've already assumed that Iris could be used to beat blizzard's Warden module, since it doesn't link to Diablo II.exe.
Sort of like, an external d2hackit...maybe (I said maybe) with module capabilities...but I'll discuss my ideas next time
### Further Research
Further research is of course required as to the advantages and drawbacks of this software. One that I know of is that if any of the newer (2002-now) versions of Iris is able to contact eEye's website (assuming an illegitimate copy is being used) it will disable Iris on that computer (almost perminantly).
### Next Time
I will be doing research starting Feb 8/06 as to how this can be integrated properly. I will report my findings as I get them in this thread...as well I'll create a new thread when I'm on to something big
### Comments
Leave your comments and feedback here. If you're a former member of BFHS or someone that I know has considerable knowledge, let me know if you're interested in getting eEye's Iris. legit of course :rofl2
-----------------------------------
eEye's Iris Packet Analyzer and its Applications to D2 Hacking
###INTRO
One of the main reasons that hacking in Diablo II has beeen deduced to forms of maphack and bots is due to new anti-hacking mechanism's produced by Blizzard to scan for modules attached to Diablo II.exe or its inherent modules. This is known as the Warden. (Thank you Dark_Mage) Which can be verified here:
Code:
Text strings referenced in D2Client:.text, item 627
Address=6FB0261E
Disassembly=PUSH D2Client.6FB86160
Text string=ASCII "..\Source\D2Client\WARDEN\WardenClient.cpp"
###eEye Security - www.eeye.com
eEye is an internet security company that produces a set of tools that ANY hacker would drool over. Even though a true hacker would construct their own tools due to an inferior set of tools produced by commercialization.
eEye's tools are far from inferior.
The problem lies within the fact that these products are commercial, and due cost a hefty penny. This of course will never stop the latest P2P engine from having them for free though. (Contact me if you'd like 'certain files').
If you have time, get all the eEye tools and experiment with them...however this article will only focus on the Iris product.
###eEye's Iris - http://www.eeye.com/html/products/Iris/
I'm sure most of you have used a simple packet sniffer/scanner before. Imagine having the ability to not only sniff packets, but send them as well via an external program. This is what eEye's forensic tool: Iris, was built for.
Iris has the ability to capture and resend modified packets (or new ones) through any protocol over any size network (ie the internet) without attaching itself as a module to the original application that sent the packets.
###Iris' Applications to D2 Hacking
By now, you've already assumed that Iris could be used to beat blizzard's Warden module, since it doesn't link to Diablo II.exe.
Sort of like, an external d2hackit...maybe (I said maybe) with module capabilities...but I'll discuss my ideas next time
### Further Research
Further research is of course required as to the advantages and drawbacks of this software. One that I know of is that if any of the newer (2002-now) versions of Iris is able to contact eEye's website (assuming an illegitimate copy is being used) it will disable Iris on that computer (almost perminantly).
### Next Time
I will be doing research starting Feb 8/06 as to how this can be integrated properly. I will report my findings as I get them in this thread...as well I'll create a new thread when I'm on to something big
### Comments
Leave your comments and feedback here. If you're a former member of BFHS or someone that I know has considerable knowledge, let me know if you're interested in getting eEye's Iris. legit of course :rofl2