danielkrupinski / Osiris

Cross-platform game hack for Counter-Strike 2 with Panorama-based GUI.
MIT License
3.36k stars 961 forks source link

About faceit anticheat #2673

Closed bootkitt closed 1 year ago

bootkitt commented 3 years ago

After doing a little browsing about Faceit anticheat, I noticed something.

Faceit injects faceit.sys file into the system while the computer is booting.

BOOT Start - FACEIT.sys

%systemroot%/System32/Drivers >> FACEIT.sys C:/Windows/System32/Drivers >> FACEIT.sys

If I stop it through faceit.sys ph (process-hacker), it understands faceit ac ph (process-hacker). And it asks you to restart the computer.

So how can we stop this .sys file that prevents dll injection in the system.

My opinion is that we can overcome this in 2 ways. 1- unload faceit.sys without restart. 2- making an injector that can blind this anti-injection.

Manualmap is a very good foundation for this, but I don't know what I can do.

Can those who want to help me on this subject contact me privately?

MAIL: technolite2007@yandex.com Discord: ᛋᛋBootKitᛋᛋ#2368

wemanzoz commented 3 years ago

go on uc, better solution for you. since most of us here are brainlets

bootkitt commented 3 years ago

go on uc, better solution for you. since most of us here are brainlets

There is nothing else in uc except just talking about the subject.

wemanzoz commented 3 years ago

go on uc, better solution for you. since most of us here are brainlets

There is nothing else in uc except just talking about the subject.

Just tell them your shit, serveral people will answer your question. including kittenpop, masterlooser if its interesting for them

Scui1 commented 3 years ago

You don't need to do that much work to bajpass faceit. Just use extremeinjector and inject osiris into running csgo. Faceit won't notice it, trust me, I speak from experience 😎

bootkitt commented 3 years ago

You don't need to do that much work to bajpass faceit. Just use extremeinjector and inject osiris into running csgo. Faceit won't notice it, trust me, I speak from experience 😎

extremeinjector does not see csgo.exe :|

ghost commented 3 years ago

After doing a little browsing about Faceit anticheat, I noticed something.

Faceit injects faceit.sys file into the system while the computer is booting.

BOOT Start - FACEIT.sys

%systemroot%/System32/Drivers >> FACEIT.sys C:/Windows/System32/Drivers >> FACEIT.sys

If I stop it through faceit.sys ph (process-hacker), it understands faceit ac ph (process-hacker). And it asks you to restart the computer.

So how can we stop this .sys file that prevents dll injection in the system.

My opinion is that we can overcome this in 2 ways. 1- unload faceit.sys without restart. 2- making an injector that can blind this anti-injection.

Manualmap is a very good foundation for this, but I don't know what I can do.

Can those who want to help me on this subject contact me privately?

MAIL: technolite2007@yandex.com Discord: ᛋᛋBootKitᛋᛋ#2368

Hi Man. First of all read this: GuidedHacking(Faceit AC) If you want to bypass it you must have enough knowledge, because it is difficult to bypass.

You can bypass EAC, BATTLEYE and FACEIT SERVER SIDE AC with a kernel driver but FACEIT CLIENT SIDE AC in not like these three

SORRY ABOUT MY ENGLISH

bootkitt commented 3 years ago

After doing a little browsing about Faceit anticheat, I noticed something. Faceit injects faceit.sys file into the system while the computer is booting. BOOT Start - FACEIT.sys

%systemroot%/System32/Drivers >> FACEIT.sys C:/Windows/System32/Drivers >> FACEIT.sys

If I stop it through faceit.sys ph (process-hacker), it understands faceit ac ph (process-hacker). And it asks you to restart the computer. So how can we stop this .sys file that prevents dll injection in the system. My opinion is that we can overcome this in 2 ways. 1- unload faceit.sys without restart. 2- making an injector that can blind this anti-injection. Manualmap is a very good foundation for this, but I don't know what I can do. Can those who want to help me on this subject contact me privately? MAIL: technolite2007@yandex.com Discord: ᛋᛋBootKitᛋᛋ#2368

Hi Man. First of all read this: GuidedHacking(Faceit AC) If you want to bypass it you must have enough knowledge, because it is difficult to bypass.

You can bypass EAC, BATTLEYE and FACEIT SERVER SIDE AC with a kernel driver but FACEIT CLIENT SIDE AC in not like these three

SORRY ABOUT MY ENGLISH

thanks bro.

I did some more research. The faceit ac notices this when you disable faceit.sys. and asks us to reboot the system. the only remedy is the kerneldriver injector.

tooanri4you commented 3 years ago

You don't need to do that much work to bajpass faceit. Just use extremeinjector and inject osiris into running csgo. Faceit won't notice it, trust me, I speak from experience 😎

Where could I get extreme injector?