More Awesome Than You!
Welcome, Guest. Please login or register.
2024 November 24, 06:41:33

Login with username, password and session length
Search:     Advanced search
540287 Posts in 18067 Topics by 6545 Members
Latest Member: cincinancy
* Home Help Search Login Register
  Show Posts
Pages: [1] 2
1  TS3/TSM: The Pudding / The World Of Pudding / Re: BREAKING NEWS: TSR INSTALLS SPYWARE! on: 2009 August 02, 18:53:37
Thereīs even more stuff

2  TS3/TSM: The Pudding / The World Of Pudding / Re: BREAKING NEWS: TSR INSTALLS SPYWARE! on: 2009 August 02, 14:12:04
For what it's worth, I ran some tests on the latest TSRW.exe 07/24/09
MD5:521605E8B73BA0BD98AD72CFF3AD14D0
CRC-32: A3952AF2
I get an entirely different md5sum, 51e41f48f7aceef99c3ed57f0e072e2c for TSRW.exe, meaning your version is newer and has been altered, probably to better hide the evidence now that they know they have been caught. They are probably using a new trick that fools your particular scanner.

PEs, provide an scientifical way of reproducing your input, otherwise Iīll have to discard this news as false. I will feel backstabbed, as Iīve trust you many times and now I feel thereīs no scientifical substance here.
I'm not exactly sure what you want. You want me to provide a demonstration of steganographically concealed transmissions in innocuous data? Just look at the Splotch Creatures. They are PNG files. Totally harmless PNG files. If you examined them, you would find harmless PNGyness. But they contain DATA in them and can be used to reconstruct a Splotch critter. Admittedly, this is a completely benign implementation done for reasons unrelated to nefariousness, and the fact that it is not nefarious is why we know of it, as the game never really attempts to conceal this fact from us. TSR, however, is known to be a nefarious operator: They have acquired and then misused or released to third parties personal information from users in the past. It is reasonable to say that they do so regularly and there is absolutely no physical reason why they would have stopped, and therefore, there is every reason to believe the practice continues. In fact, on PMBD, Johan himself came over to gloat about how undetectable his new system was, because he just couldn't resist the temptation to brag and gloat smugly.


What I was asking is what I did:

http://www.the-prism.com/index.php?topic=3225.msg39307#new

You have to use an VMware clean machine and Trend Internet Security Pro 2009

Step by step:

1 Install WinXP SP 2 Pro. on Vmware 6.5....
2. Install NET framework 3.5
3. Install Trend Micro
4. Install TSR workshop
5. See what happens  Grin

Pes, if you want to remain credible, you have to provide ways to the Averages Joes. Relying on word and screenshots still leaves place for doubt.

Thanks to Shanow
Special thanks to Paden
3  TS3/TSM: The Pudding / The World Of Pudding / Re: BREAKING NEWS: TSR INSTALLS SPYWARE! on: 2009 July 24, 15:58:14
Jfade is clearly not familiar with the many techniques which exist for sending messages without including the content of the message in the actual message, however. That is the obvious approach that would be used in such a scenario, which is why it escapes packetsniffing. Everyone knows that everyone and their dog has access to a packetsniffer, and if you want to hide a message in a transmission, you cannot obviously place the message in the transmission, and even encrypting the message so it looks like gibberish is suspicious: You have to hide the message in the metadata of the transmission. A pattern of seemingly innocent requests, a specific timing of requests, or even the fact that the request was made at ALL can all constitute a message hidden from plain sight. You can clearly see that this is happening, because the message is not apparently inside the actual transmission. The fact that it has been hidden in such a manner proves its malicious intent.

PEs, provide an scientifical way of reproducing your input, otherwise Iīll have to discard this news as false. I will feel backstabbed, as Iīve trust you many times and now I feel thereīs no scientifical substance here.

*back to my Vmware tests*
4  TS3/TSM: The Pudding / The World Of Pudding / Re: BREAKING NEWS: TSR INSTALLS SPYWARE! on: 2009 July 22, 21:36:58
We bring you the shocking news of the latest TSR atrocity: SPYWARE AND VIRII!
<snipped pic>
They say a picture is worth a thousand words, so have at it.

Which DLL modifies? can you post the details?
5  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 19, 09:41:22
I'm incredibly amused by it. And now that Nightmare/SBlade has nothing to take back to the BBS and be their hero for, he's crawled back into his corner.

You are a wanker with a very limited scope of view if you think my goal is to surf the BBS and be "a hero", unlike some senator who apparently has no life and spent his time here because every time he goes to the street they make fun of him.

6  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 19, 01:00:06
If TS3 really does include SecuROM (I have the EA downloader version), it is a really benign version compared to the crap that comes with Spore.

It doesn't even mind me having Process Explorer running, which real versions of SecuROM (the ones that use a Ring0 driver) refuse to work with.

Thanks Jordi.

IT seems we have a decaffeinated Securom here. Moving along. Jordi you have my mail by PM. I will appreciate if you can attach me a Process Explorer dump (both memory and image) Thanks.

Thread is over. At least for me
7  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 18, 20:16:10
Does Securom on the download version or The disk DRM has any direct hardware access?

Does Direct Hardware Access means RING0 communication?

A question; Why are you so obsessed with the SucUrom issue now? That show is not playing currently on the "Horror". You have been told by the best that the disc version of Sims 3 contains an inept version of the so called DRM. Did you have so much fun at the last SucUrom Fight that you want to start another one?

It is time to move onto other issues contained in this not ready for "Prime Time" game.

It is still on the Download version of "the Horror", muffinhead.
8  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 18, 12:54:54
Does Securom on the download version or The disk DRM has any direct hardware access?

Does Direct Hardware Access means RING0 communication?
9  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 17, 18:44:56
Yep, but what about the past? What about BV and later games? The most experienced programmers say that indeed it is possible to run in RING3 to prevent emulation. But that protection would be weak.

Securom paranoia against emulation is well known on TS2, Farcry 2 and Falllout 3 http://www.securom.com/message.asp?m=emu&c=2500

I think the emulation is strong, so by common sense, they are not running in RING3.

A pity no one has found any conclusive RING0 operation until now....  Sad
10  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 17, 13:45:36
No conclusive indicators of RING0/low level operations  of Securom then?
11  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 16, 12:59:02
Or, more likely, it's the stripped detritus of something no longer in service that was left behind. There's tons of rubbish like this in the game.

But now Iīm not speaking about  TS3, but latest TS2 games versions dump. I donīt think those file names are no longer used
12  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 16, 12:29:23
Evil malware in RING3 doesnīt fall in the same category as a possible low-level operation, RING0 malware.

The first one is an annoying bug, the second is a deadly compromising software. The distinction must be done.
Yes, but how does stating the obvious change anything?

I want indicators to the Average Joe users that can be understood by bureaucrat CEOīs. I know a few men on the industry, but they want reliable data. If you give me indicators of Kernel code use/low-level operations of Securom I will appreciate it.

I found some interesting string dumping Securom executables strings on latest versions.

\Device\sony_ssm.sys
\DosDevices\sony_ssm.sys
VS_VERSION_INFO
StringFileInfo
Comments
SecuROM Security Module.
CompanyName
Sony DADC Austria AG.
FileDescription
SecuROM Security Module.
FileVersion
LegalCopyright
Copyright (C) 2004/05 Sony DADC Austria AG
OriginalFilename
sony_ssm.sys

A .sys file would be some kind of indicator of low level operation, just as the Aries.sys in XCP

Thoughts
13  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 16, 11:35:22
SecuROM is evil malware. Period.

Evil malware in RING3 doesnīt fall in the same category as a possible low-level operation, RING0 malware.

The first one is an annoying bug, the second is a deadly compromising software. The distinction must be done.
14  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 16, 09:01:35
Pes, whatīs your opinion as an expert about kernel code use in Securom?
15  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 15, 17:54:55
"The industry"? Care to expand?

The major publishers
16  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 15, 14:29:39
Unfortunately I already know that and the industry believes it is a bug of Rootkit Revealer. Any more indicators of Kernel code use?
17  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 15, 13:34:28

Ubisoft dropped DRM for the last PoP which did not sell well, and apparently faced harsh criticism from the industry 'tards over this. Their future games will be infested again.



Soruce please?

Pes, what is your opinion about Securom running, performing processes, or communicating with the RING0 to detect V-drives in stealth mode? Securom runs in RING3 to perform its detection, but some of my sources tell that it communicates with the RING0.

Is that true?
18  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 15, 12:57:59
I donīt understand EA then. They should have dropped Securom earlier. They still have suffered from Securom scandals and bad PR. It is clear that this option is better than keeping SecuMierda, but they should have done earlier.
19  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 15, 10:45:29
But I have seen similar Securom issues in the sims 3 forum. No recognized DVD. Emulation errors. Are these fake? Could it be we are dealing again with Sony paid users to post on forums?
20  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 15, 10:29:05
For being harmless... are there any crack on the disc version? there isnīt any on trusted sites like GCW. Or could it be that the protection is harmless and good?( I doubt it)
21  TS3/TSM: The Pudding / The World Of Pudding / Re: Securom string found in Process Explorer dump on: 2009 June 15, 09:59:33
Err...exactly what are you trying to prove by looking at "thesims2.exe" when trying to point fingers at "The Sims 3". I'm not sure I follow tihs line of reasoning.

IT is a typo. Now it is corrected. You should look at  "thesiums3.exe"
22  TS3/TSM: The Pudding / The World Of Pudding / Securom string found in Process Explorer dump of TheSims3.exe on: 2009 June 15, 09:44:02
Hereīs the way to reproduce it:

1. Launch Sims 3.

2. ALT+TAB

3. Launch Process Explorer.

4. Right click on "thesims3.exe" >properties

5.Click on Strings

6. Save

7. Open the file you have saved with wordpad or MSword.

8. Search for Securom

9. Blame yourself for trusting EA
23  TS3/TSM: The Pudding / The World Of Pudding / Re: THE HORROR: The REAL TS3 Scoop As It Unfolds on: 2009 May 19, 19:37:54
You're pretty much doomed to be shouted at. Only instead of people shouting at you for criticizing the game, you will be shouted at for your horrible grammar and abuse of punctuation.

Errr, Pes, she did apologize/explain any bad spelling/grammar/punctuation in her initial posting...
e.g.
Sorry if there is any spelling mistakes using my phone.

NOT an excuse, especially for the walloftext. You are on notice, too, choobooby, for suggesting that there is some kind of free pass for crackberriers. Besides, even if the phone explains the capitalization, it doesn't excuse the apostrophe abuse. Spelling and grammar count, people. Don't make me eat your heads.

I would like to see you upload a video where you show us your grammar skills when using a phone. Bitch.

Angi, donīt takee the gremmar murons tou seriuos hera.

This is MATY. Land of assholering and MOAR fight for the sake of fighting
24  TS3/TSM: The Pudding / The World Of Pudding / Re: THE HORROR: The REAL TS3 Scoop As It Unfolds on: 2009 May 18, 19:40:51
Again, what proofs do you have that this is an early beta/alpha version? You're spreading that both here and at the BBS, under your SBlade handle. You wouldn't be spewing rumors, now would you?

As you can see by PM, I speak of something Iīve tested it myself. If this isnīt a Beta, this is the biggest shit Iīve ever seen.
25  TS3/TSM: The Pudding / The World Of Pudding / Re: THE HORROR: The REAL TS3 Scoop As It Unfolds on: 2009 May 18, 17:56:03
No worries, Skadi. Nightmare is a complete douche who frequents PMBD and never reads.

I think it's obvious that Nightmare is a moron, as Nightmoron apparently thinks that SecuROM is a "he".  Nightmoron also believes that software can have cronies.  Quoting the proof, in case it's deleted:

You are doing Securom and his cronies a big favour.


Ah! The MATYcian love, I expect no less from you. Send me your phone number, you might win the lotto and Iīll call ya Cheesy

I donīt think leaking an early beta of a game that has Securom will do any benefit to the gaming community. It is true that the news is that a securom version was cracked. But they could have waited to the release day to compare between the real deal.
Pages: [1] 2
Powered by MySQL Powered by PHP Powered by SMF 1.1.21 | SMF © 2015, Simple Machines Valid XHTML 1.0! Valid CSS!
Page created in 0.091 seconds with 18 queries.