PDA

View Full Version : FALSE POSITIVE FALSE POSITIVE: Suspicious CFG userconfig.cfg



ehmwut
26-12-2022, 04:12 PM
First of all, WarGods seem to scan other copies of cstrike folder (not used by the game at the time of launch). There is no userconfig.cfg in the cstrike folder used by hl.exe at the time of scan.

Second, it's normal userconfig.cfg with some old CPL GUI Aliases (weapon switches), alias for map changes with rcon.
They are even commented out with // due to FASTCUP (GameGuard AC) disabling them anyways.

<b>You have to register to ba able to see this link</b>


EDIT1: Re-scan after moving the cstrike folder copies out of Half-Life folder, without restarting cs: <b>You have to register to ba able to see this link</b>

Please take a look.
Thanks

Tiger
26-12-2022, 05:25 PM
Upload all detected CFGs to zippyshare/wetransfer.

ehmwut
26-12-2022, 06:11 PM
here are the userconfigs.cfg (not in "cstrike" folder at the time of scanning), the folder(s) was named "cstrike_csdm" etc, so not loaded by hl.exe as cstrike

EDIT: New link below

Tiger
26-12-2022, 09:49 PM
The requested file cannot be found on privfile.com. It may have been deleted by its owner, or by the Administration of privfile.com.

Do I need to explicitly repeat you to upload these files to zippyshare or westransfer? These are not shitty fiile upload hosts...

ehmwut
26-12-2022, 09:51 PM
<b>You have to register to ba able to see this link</b>

EDIT: I chose something else because zippyshare and wetransfer (unless premium) doesn't allow choosing expiration time, but here u go ^
sorry for the inconvenience.

Tiger
26-12-2022, 10:39 PM
Those files were whitelisted and your detection removed.

If you want the rest of (unknown) CFGs to be analyzed and whitelisted, please upload them. (you have a lot of them)

ehmwut
26-12-2022, 11:15 PM
Thanks for your time. I moved the cfgs, should not cause more issues.

But I don't think it's helpful that the anticheat detects commented aliases, within config files not used by the game..

Is this something you plan to work on or is whitelisting the best for now?

Tiger
26-12-2022, 11:27 PM
You can trick CS to load those commented aliases via malformed CFG. If would be a headache to create a parser for CFGs, doesn't worth the time ... CFG "cheats" are useless, just a placebo... The only things that works on them are: bunny-hop, fast-zoom, silent run. I don't think anything else works on the CFGs without additional support from CS (aka loaded hacks).

ehmwut
26-12-2022, 11:28 PM
Fair enough. Thanks for answering :)