Warden changes

Hey everyone.

Just a quick update on the status of Warden; For the entire weekend, the warden server was actually offline, which i found rather odd, but i guess even WardenGuy doesn’t work on the weekends.

Now, onto the 11 changes. Regarding DLL detection, two new dlls have been added to the hit list and based on the scan size, it’s safe to assume they’re the same module, just different variants.

That leaves us with 9 memory scans, specifically targeting allocated memory (I’m looking at you, “passive” botters who find yourselves injecting large code stubs). These all seem to be different offenders, based on the diversity in the offsets and sizes.

Don’t say i didn’t warn you!

Clarification

It seems a lot of people haven’t understood what i was trying to convey. (Fair enough. It was late, and i was tired)

This update isn’t looking for memory changes in WoW’s .text/.data sections. These are targeting injected DLL files and the memory those DLL(or VirtualAllocEx’d memory from a third party process) allocate.

Update #2

Well, that was quick. Hawker asked me if there were any worrying updates to Warden, so i gave him the following picture from my tool. Hawker posted it on his forum before asking me, but promptly removed it when asked. Someone snagged it before it was taken down, so i guess its public domain now.

new_warden_scans_3.11.09[1]

  1. Mr.Nub says:

    Do we LuaNinja users need to fear something ? Lord Kynox ?

  2. MC_12 says:

    Thanks for the heads up Kynox. Any clues as to what bots it’s going after?

  3. FXSR says:

    And us prixo boters?

  4. kynox says:

    To find out what its going after, i would need an archive of all the public bots which use injection.

    So, no i don’t know who it is going after, nor do i realy care.

  5. Nesox says:

    Awesum cum kynox, now gief your ways of time bending and we will all be safe from warden! :D

  6. Thulos says:

    Was there anything put in to detect direct memory writes to the click to move structure?

  7. Cgris says:

    hey do you think this will effect MrFishit or Gbot ?

  8. Chris says:

    hey do you think this will effect MrFishit or Gbot ?

  9. Chris says:

    double post mybad ><

  10. Barnzy says:

    Lets see who crys at the end of the week 9 new Scans dont sound good.

    but here we are again : Information about Warden changes.

    Status: You are safe to use Buddy products!

    Last change of this message: 04.09.2009 09:31:23 CET

    true or not true?

  11. TigerX says:

    is there a warden Monitoring tool that is avalible to the public that checks when warden updated?

  12. Barnzy says:

    I hope mimic and all clones will be hit hard!

  13. Spaceboy says:

    So, any word weather this is targetting MrFishit or MrTrackit?

  14. Chris says:

    kynox could you please take a min and teach us how to see if these offsets are targeting our software :)

  15. Real Nigga says:

    You’re a real hood nigga for posting this fuck blizzard’s bullshit ways

  16. John says:

    Does warden do check only when client login ? It was before if I remember correctly

  17. Barnzy says:

    any known Banns happening so far?

  18. Barnzy says:

    shame I was hoping for mimic and gremlin

  19. Execute says:

    Is WoWInfinity safe?

  20. kynox says:

    No, none of the scans target memory in WoW’s code/data. I’ll edit the post to clarify.

  21. Thulos says:

    Thanks for the clarification kynox, after rereading your original post it wasn’t your fault for the confusion. You did make it clear that it was targeting injected code.

  22. kynox says:

    You seem to be under the impression that because warden changes, every bot is the target and should not operate. It’s only a 5-10 minute job to see if these offsets are targetting your software.

  1. There are no trackbacks for this post yet.

Leave a Reply