PDA

View Full Version : keysniffer idea (from a luser n00bie)



psymin
12-09-2002, 12:09 PM
If EQ can run under linux via VMWare, could a linux utility grab the key information from VMWare's memory?

Would this help avoid detection or could SoE detect that the session was running under VMWare ..

psymin

high_jeeves
12-09-2002, 12:10 PM
VMWare has no support for DirectX. Perhaphs you mean WineX? If so, that has been suggested before... It is quite possible... go for it.. And yes, they could detect if you were running under WineX.

--Jeeves

LordCrush
12-09-2002, 02:58 PM
Btw VM is a sandbox - heavy searching since you will not get the pid for eq and start address :p

psymin
12-09-2002, 04:17 PM
Thank you for answering my questions.

I have another ill-informed question. I'll word it poorly here:

Will two congruent machines (same OS, hardware, IP, username, password .. yes I know it is not likely) running the EQ client generate the same session key given the same input?


For example:

If my keyboard/mouse input was sent to two identical machines .. and all of the incoming packets were routed to both machine's nics .. would both machines be able to decrypt the incoming packets?


Yeah. It would be a difficult scenario to set up, but I think you see where I am going ..

psymin

high_jeeves
12-09-2002, 04:22 PM
No, not necessarily. And it would be impossible to set up, not difficult.

--Jeeves

baelang
12-10-2002, 04:05 AM
no. tiny differences in the hardware clock and internal workings, plus timey changes in zone times, could/would create large differences in the randomly generated keys. or at least different keys.