PDA

View Full Version : Delator 2.0 detected cheats that were untrue in OGL!


mohadmins_1fan
01-08-2003, 08:26 AM
Mr. YoChoyLaMuete, I need your honest opinion based on one clans situation.

To avoid any other problems then other what has been created I will leave all Clan names and names of people out. I am sure you understand.

At this momemt there is a Clan that has been accussed of cheating in the OGL ladder. What I need feedback on is the accuracy for certain of Delator 2.0. I am sure Delator is a terrific program, but as we know every program has its bugs in its beta and test stages.

A match was set for two servers to provide one round each, each team playing one round on the other teams server. Round 1 was completed and ClanA had won the match. After ClanA went to play second round on ClanB's server. Once ClanA entered ClanB's server ClanB started to run Delator 2.0 on ClanA. Cheats were detected by Delator on one member of ClanA. Immediately I accessed Windows XP's msn messenger and with permission of the accussed I was able to view his files in his main, particularly the newconfig.cfg and unnamedsoldier.cfg. This individual had no such commands in his configs. ClanB said that the cheats detected on this individual are as follows:

r_farplane_nofog
r_whitemap
cg_3rd_person
r_novis
modified binaries

Someone might say, he could have switched the file before I logged on to verify. If I might add that this individual, if you asked him to go to windows explorer or open his command prompt. His reply would be "huh."
This is a person that I have been around for a while now and know he is not anything of the cheating nature. If someone said put the .pk3 in the main it would be almost impossible. I am only trying to establish a little credability that the type of person he is. As for the ClanA, they are a anti-cheat clan, you might say. This is why its hard to understand how this happened. I did read the twenty-two pages on feedback of Delator. The only thing that brightens the future of ClanA is by these quotes.


This program has been detecting AImbots, noFog and modified binaries on some of my legit players in my team. We've tried to figure out what the program is detecting that makes it think these things. The only thing I can think of is, will 30+ custom maps in the main folder be a factor? Is one of those maps bound to change some value that sets of the delator. Also, how about scope mods, gun skins, etc. set it off too?

n an average night we have about 20-25 people playing and I only have the following problems with delator.

1. I cannot set it to scan and warn for all of the cheats first before it kicks. It will find and kick when I set it to scan and kick.

2. It shows no fog cheat and mod binaries for some mac users when they are not cheating. One guy just took out his unamedsoldier config and restarted game and it created a new one for him and now he can play...before it would boot him.

quote="YoChoyLaMuete"]
Quote:
I'm really sorry Mac users are being disturbed by Delator. I'm really eager to fix this. Assuming you haven't tried yet the fix by Redrum and Cheule, please launch your game and type in console: cvarlist r_farplane And tell me what it outputs. Grazie

Delator relays mainly on cvars values to diagnose cheats. Some people modify his files with an hex editor to change the cvars name so that the server can't check what's the current value. Delator detects these changes as a "Modified Binary". However, apparently some Mac users are being charged with this even if they're running non-edited exes, so use with caution until I can fix this.

The last quote I posted I think the modified binary would be detected on just about anyone who runs the NOCD patch, am I correct?

I see there has been an issued based on Mac users, but is it possible at any chance that it could do such with a user running a PC? Mr. YoChoyLaMuete can you garauntee 100% that Delator can make no mistake on a PC? If so, I will take your word for it. I also am not certain that he is not running a Mac either, but for the sake of the situation I though I might ask. A honest Clan will suffer humiliation if it is not possible for Delator 2.0 to make a mistake and a honest individual will be flamed over it by the Clan. I would have not taken the time to go this far if the the acquisations agains the member were true.

Also just some F.Y.I
After the match had ended I went on thier server using an alias name and was able to accomplish what I went for and with taking screenshots of conversation. While on the server another player accussed another player of cheating. I replied, "Where is Delator when you need it." One of there own team members replied, "Yeah." So, they ran Delator and they player was clean so after I popped a question "how long you have you guys been running Delator." They replied, "right after Christmas." Wow I thought; right after Christmas and yet there certain they know exactly what they are doing especially in a OGL match? Then I asked "how is it? Is there any bugs or is it smooth"? They replied, " I was amazed how many it picked up the first week." then replied again,"it found 130 cheaters first weak? Anyhow, so I said that a little too many don't you think? He said, " I figured there had to be some false positives with that many"

I need your help YoChoyLaMuete

thejerk
01-08-2003, 04:25 PM
I think Yo will agree with me when I say that Delator's still BETA. There are bound to be mistakes as not all of the bugs could possibly be worked out yet.

I can tell you from experience, though. I've caught three OGC Aimbots, 20 cheat skins, 2 wallhacks, 4 no fogs, etc. I tested this by logging on with various cheats installed to test it, and sure enough it caught me every time.

Here's what I suggest to your other clan, though. Install Code. When a cheat is detected by Delator during a match, force a screenshot and have everyone send it to the admin. If someone's cheating, there's no better way to find out then the response you'll get from that.

Tripped
01-08-2003, 04:25 PM
I dont know if this would help but i been running delator for a little while and some people do get kicked that i have checked them out and they only had custom maps in there folders. they took them out and it was fine. Unfortuneatly i do not know what map or maps caused it
second I have a couple of people running the nocd patch and it has not kicked them.

mohadmins_1fan
01-08-2003, 06:06 PM
This is good to hear. The only problem is that I have til a certain time today to enter a dispute. Is it possible someone might be able to get a hold of YoChoyLaMuete just to finalize it? I do appreciate all of your help.

This person had almost 25 custom maps in his folder. Can that trigger Delator off?

Tripped
01-08-2003, 07:21 PM
try posting on the delator thread he seems to check it often or better yet checking on there for his email i think he has it on the bottom of his posts.
Well im wrong but if you go to his url it has his email

mohadmins_1fan
01-08-2003, 07:45 PM
I sent an e-mail with a link. You may take off his e-mail if you wish. Thank you Tripped

Tripped
01-08-2003, 08:41 PM
No prob.
hope it helped

YoChoyLaMuete
01-08-2003, 09:35 PM
Lo :)

First of all, yes, it's beta. This said, the only false positives I have seen where because of the mac issue; you can add also that someone maybe charged with using OGC aimbot if he uses the legit oakleave skin, but I've never seen this happen (a user reported it, though) and it doesn't apply here. It will not fire the "modified binaries" alarm when running a no cd patch (I use it myself for the sake of speed when launching mohaa, though I own of course a legal copy). Otherwise, just imagine how many people would be charged with this...

I should have some aditional info, like what value had the named cvars. However, the more I read your message the more convinced I am that this is another instance of the mac problem. Why?

- The cvars you listed are the ones used by version 2.0.0.4 and previous, so clearview couldn't be detected (clearview & modified binaries -> Mac user most of the time).

- The only cheat named as per se is "modified binaries". I assume the other cvars were listed as hacked which is what you get on earlier versions, but not the cheat itself.

Really you should verify whether he was or not on a Mac.

To answer your other questions: I can't guarantee 100% it can't do a false positive (well, in fact I know how to do this, but the player should do it on purpose and it would be solved with a simple dumpuser) but I will guarantee it on a 99.5%, which means both to my knowledge and experience it ain't no way to make this happen on a PC: I have never seen this happen on a PC user, nor have I heard of this (other than the precited oakleave issue), and I can't think of any way this could happen.

So check what system he was using, and also take note of Boo suggestion about code security.

Regards,

YoChoy

mohadmins_1fan
01-09-2003, 01:12 AM
YoChoy,

I can't thank you enough for your input. As it turns out, the accused is running a Macintosh computer. This all makes so much more sense now. Now we can put this behind us and move on. Thank you once again!

Sincerely,
Mohadmins_1fan

P.S. The individual that was accused of cheating says he is switching to PC.........LOL. I thought that was pretty funny and might share that.

mohadmins_1fan
01-09-2003, 04:56 AM
Just an update posted 1/8/03 in Top News of OGL

Delator, Counter Intelligence, Honest CFG, PONT4 and other such mods:

This is a tough one as I am truly appreciative of the effort of many people in attempting to eradicate cheating in this game. It is quite evident that EA is not really willing to do anything about it and so it is left up to the community to manage their purchase and game. It is truly sad that a developer of a great game/product will not support the community who helped the product to become what it is, one of the most popular war games to date and second only to CS in it's popularity online.

That being said, it is with great dismay that I must inform all clans who use these programs and the like that none of these are sanctioned for use during any MOH ladder matches in the OGL. The only method supported by the OGL at this time is the use of the DUMPUSER cmd. Of course this means that both teams must trade rcon access and unfortunately this means leaving your server a bit vulnerable to some extent to an opponent. Considering that the OGL assumes no responsibility we do not force the use of DUMPUSER, but we do recommend it. Considering that this is a self policing community, to some extent, we all know who is cheating and who is not. The cheaters know it and their opponents know it when they play them. Going into that argument is useless since I willnot convince anyone here to not cheat any longer.

One message remains strong, if we catch you, you will be suspended pending investigation into the charges against you and then removed immediately. In some cases you will be banned permanently. Still, and unfortunately, I cannot accept disputes based on the use of the above mentioned programs since all of them contain one bug or another. False positives are rampant throughout Delator, while others prove hackable. To sum it up, please do your best to police one another with some degree of respect utilizing DUMPUSER, (for now). Any else used and then submitted with disputes or complaints will be ignored and the resulting rulings will be based on what the OGL does support.

When OGL testing can confirm that they work as intended without rendering false positives, etc., then we will push to accept this form of anti-cheat throughout the community. Until then, I urge all of you to continue to write, email, type a letter, send a note, call, page, or whatever you use to communicate, to EA and URGE THEM TO FIX THIS GAME!!!! You paid your money as did I, so I feel they are responsible to us as consumers to provide a product which has a reasonable amount of error but not nearly the rediculous amount of faults with the code.