Skip to main content

meccha-chameleon-game-trainer-analysis

Analyze and understand game trainer/cheat software patterns for security research and anti-cheat development

跳到安装

来源信息

仓库
reason-machines/devtools-skills
最近来源活动
2026年7月1日 01:01
检测到的 SKILL.md 语言
英语
星标
4
分支
0

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
meccha-chameleon-game-trainer-analysis
description
Analyze and understand game trainer/cheat software patterns for security research and anti-cheat development
triggers
["analyze this game trainer code","how does this cheat software work","explain game memory manipulation techniques","reverse engineer this trainer tool","understand anti-cheat bypass methods","security analysis of game hacking tools"]
# MECCHA CHAMELEON Game Trainer Analysis > Skill by [ara.so](https://ara.so) — Devtools Skills collection. ## ⚠️ Security Research & Educational Context This skill provides knowledge for **security researchers, anti-cheat developers, and educational purposes only**. The referenced project appears to be a game trainer/cheat tool that manipulates game memory and behavior. **Important Legal & Ethical Notes:** - Using such tools violates most game Terms of Service - Can result in permanent account bans - May violate computer fraud laws in many jurisdictions - Harms legitimate players and game communities - This skill is for understanding attack vectors to build better defenses ## What This Project Claims To Do The MECCHA CHAMELEON trainer is advertised as an "external tool" that provides: 1. **ESP (Extra Sensory Perception) / Wallhack** - Rendering player positions through obstacles 2. **Aimbot** - Automated targeting assistance 3. **Memory Modifications** - God mode, speed boosts, infinite resources 4. **Game State Manipulation** - Timer freezing, teleportation, noclip ## Common Game Trainer Architecture Patterns ### External vs Internal Trainers **External trainers** (like this one claims to be): ```python # Typical external memory reading pattern import ctypes from ctypes import wintypes # Windows API functions for memory access kernel32 = ctypes.WinDLL('kernel32', use_last_error=True) OpenProcess = kernel32.OpenProcess ReadProcessMemory = kernel32.ReadProcessMemory WriteProcessMemory = kernel32.WriteProcessMemory PROCESS_ALL_ACCESS = 0x1F0FFF def read_memory(process_handle, address, size): """Read memory from external process""" buffer = ctypes.create_string_buffer(size) bytes_read = ctypes.c_size_t() success = ReadProcessMemory( process_handle, ctypes.c_void_p(address), buffer, size, ctypes.byref(bytes_read) ) return buffer.raw if success else None def write_memory(process_handle, address, data): """Write memory to external process""" buffer = ctypes.create_string_buffer(data) bytes_written = ctypes.c_size_t() return WriteProcessMemory( process_handle, ctypes.c_void_p(address), buffer, len(data), ctypes.byref(bytes_written) ) ``` ### Process Attachment Pattern ```python import psutil def find_game_process(process_name): """Locate target game process""" for proc in psutil.process_iter(['pid', 'name']): if proc.info['name'].lower() == process_name.lower(): return proc.info['pid'] return None def attach_to_game(game_name="MecchaGame.exe"): """Attach to game process with appropriate privileges""" pid = find_game_process(game_name) if not pid: raise RuntimeError(f"Game process {game_name} not found") handle = OpenProcess(PROCESS_ALL_ACCESS, False, pid) if not handle: raise RuntimeError(f"Failed to open process: {ctypes.get_last_error()}") return handle ``` ### Memory Pattern Scanning ```python def pattern_scan(process_handle, start_address, end_address, pattern, mask): """ Scan memory for byte patterns (signature scanning) Used to find dynamic addresses that change between game updates """ current_address = start_address chunk_size = 4096 while current_address < end_address: chunk = read_memory(process_handle, current_address, chunk_size) if not chunk: current_address += chunk_size continue for offset in range(len(chunk) - len(pattern)): match = True for i, byte in enumerate(pattern): if mask[i] == 'x' and chunk[offset + i] != byte: match = False break if match: return current_address + offset current_address += chunk_size return None # Example: Finding player health address # Pattern: 48 8B 0D ?? ?? ?? ?? E8 ?? ?? ?? ?? 48 85 C0 health_pattern = bytes([0x48, 0x8B, 0x0D, 0x00, 0x00, 0x00, 0x00, 0xE8]) health_mask = "xxx????x" ``` ## Anti-Detection Techniques (For Defense Understanding) ### Randomized Delays ```python import random import time def randomized_delay(min_ms=50, max_ms=200): """ Mimic human timing to avoid detection Anti-cheats look for inhuman precision """ time.sleep(random.uniform(min_ms / 1000, max_ms / 1000)) def write_with_jitter(handle, address, value): """Write memory with human-like delays""" randomized_delay() write_memory(handle, address, value) randomized_delay() ``` ### Code Obfuscation ```python # Trainers often use obfuscation to hide functionality # Example patterns you might encounter: def decode_address(encoded): """XOR-based address decoding""" key = 0xDEADBEEF return encoded ^ key # Base64 encoded function names import base64 def get_function_name(): return base64.b64decode(b'V3JpdGVQcm9jZXNzTWVtb3J5').decode() ``` ## Anti-Cheat Countermeasures (Defense Perspective) ### Detection Signals ```python # What anti-cheat systems look for: def detect_memory_tampering(): """Signs of external memory modification""" checks = { 'unexpected_process_handles': [], # Other processes with read/write access 'memory_integrity_violations': [], # Changed memory checksums 'suspicious_module_loads': [], # Injected DLLs 'anomalous_input_patterns': [], # Perfect aim, instant reactions 'network_inconsistencies': [] # Client-server state mismatch } return checks def behavioral_analysis(): """Detect inhuman gameplay patterns""" metrics = { 'reaction_time_distribution': [], # Too consistent = bot 'mouse_movement_entropy': 0.0, # Low entropy = aimbot 'action_timing_variance': 0.0, # No variance = automated 'position_impossibilities': [] # Teleportation, noclip } return metrics ``` ### Memory Protection Implementation ```python # How games can protect themselves: class MemoryGuard: """Simple memory integrity checker""" def __init__(self, critical_addresses): self.checksums = {} for addr, size in critical_addresses: self.checksums[addr] = self.calculate_checksum(addr, size) def calculate_checksum(self, address, size): """Hash memory region""" import hashlib # In real code, this would read from game's own memory data = self.read_own_memory(address, size) return hashlib.sha256(data).digest() def verify_integrity(self): """Check if memory has been tampered with""" for addr, expected_hash in self.checksums.items(): current_hash = self.calculate_checksum(addr, len(expected_hash)) if current_hash != expected_hash: return False # Tampering detected return True def read_own_memory(self, address, size): """Placeholder for actual memory reading""" pass ``` ## Research & Analysis Approach ### Safe Analysis Environment ```python # Analyze trainer behavior in isolated environment def create_sandbox_environment(): """ Set up safe analysis environment: - Virtual machine with snapshots - Network isolation - Process monitoring tools (Process Monitor, API Monitor) - Debugger (x64dbg, WinDbg) """ config = { 'vm_platform': 'VirtualBox or VMware', 'os': 'Windows 10/11 (isolated)', 'tools': [ 'Procmon', # Process Monitor 'Wireshark', # Network analysis 'x64dbg', # Debugger 'Cheat Engine', # Memory scanner 'PE Explorer' # Executable analysis ] } return config def static_analysis_workflow(): """Analyze trainer without execution""" steps = [ "Extract executable with caution", "Run virus scan (VirusTotal, multiple engines)", "Examine PE headers and imports", "Decompile/disassemble (Ghidra, IDA)", "Identify API calls (OpenProcess, ReadProcessMemory, etc.)", "Map memory manipulation functions", "Document communication protocols" ] return steps ``` ### Dynamic Analysis ```python import subprocess import json def monitor_process_activity(target_exe): """ Monitor what the trainer does at runtime Requires administrative tools like Procmon """ config = { 'watch_registry': True, 'watch_filesystem': True, 'watch_network': True, 'watch_processes': True, 'log_file': 'trainer_behavior.json' } # Filter for specific operations filters = [ 'Operation is ReadFile', 'Operation is WriteFile', 'Operation is RegSetValue', 'Path contains MecchaGame' ] return config def trace_memory_operations(): """Track memory read/write operations""" operations = [] # Pseudo-code for tracing # In practice, use debugger or API hooking def on_memory_read(address, size): operations.append({ 'type': 'read', 'address': hex(address), 'size': size, 'timestamp': time.time() }) def on_memory_write(address, data): operations.append({ 'type': 'write', 'address': hex(address), 'data': data.hex(), 'timestamp': time.time() }) return operations ``` ## Red Flags & Malware Indicators ```python def analyze_suspicious_indicators(file_path): """ Check for malware characteristics Many "trainers" are actually malware delivery systems """ red_flags = { 'packed_executable': False, # UPX, ASPack, etc. 'obfuscated_strings': False, # Base64, XOR encoding 'network_communication': False, # Unexpected connections 'keylogging_apis': False, # GetAsyncKeyState calls 'privilege_escalation': False, # UAC bypass attempts 'persistence_mechanisms': False, # Registry run keys 'cryptocurrency_miners': False, # Crypto wallet addresses 'data_exfiltration': False # Uploading local files } # Check for common malware patterns import pefile try: pe = pefile.PE(file_path) # Check for suspicious imports dangerous_imports = [ 'InternetOpenUrlA', # Network access 'GetAsyncKeyState', # Keyboard monitoring 'SetWindowsHookEx', # System hooks 'CreateRemoteThread' # Process injection ] if hasattr(pe, 'DIRECTORY_ENTRY_IMPORT'): for entry in pe.DIRECTORY_ENTRY_IMPORT: for imp in entry.imports: if imp.name and imp.name.decode() in dangerous_imports: red_flags['keylogging_apis'] = True # Check entropy (high entropy = packed/encrypted) entropy = pe.sections[0].get_entropy() if entropy > 7.0: red_flags['packed_executable'] = True except Exception as e: print(f"PE analysis failed: {e}") return red_flags ``` ## Defensive Programming for Game Developers ### Server-Side Validation ```python class GameServerValidator: """ Never trust client data Server must validate all game state changes """ def validate_player_position(self, old_pos, new_pos, delta_time): """Check if movement is physically possible""" max_speed = 10.0 # units per second distance = self.calculate_distance(old_pos, new_pos) max_distance = max_speed * delta_time if distance > max_distance * 1.1: # 10% tolerance return False, "Impossible movement speed (teleport?)" return True, "OK" def validate_action_timing(self, player_id, action_type): """Detect inhuman reaction times""" last_action = self.get_last_action_time(player_id) current_time = time.time() min_human_reaction = 0.15 # 150ms minimum reaction time if current_time - last_action < min_human_reaction: return False, "Inhuman reaction time" return True, "OK" def calculate_distance(self, pos1, pos2): """3D distance calculation""" import math return math.sqrt( (pos1['x'] - pos2['x'])**2 + (pos1['y'] - pos2['y'])**2 + (pos1['z'] - pos2['z'])**2 ) def get_last_action_time(self, player_id): """Placeholder for action history lookup""" pass ``` ### Client-Side Hardening ```python def implement_client_protections(): """ Multi-layered client protection No single solution is perfect """ protections = { 'code_signing': 'Verify executable integrity', 'anti_debug': 'Detect debugger attachment', 'memory_encryption': 'Encrypt sensitive values in RAM', 'integrity_checks': 'Periodic self-verification', 'randomization': 'ASLR, random memory layouts', 'obfuscation': 'Make reverse engineering harder', 'heartbeat': 'Regular server communication', 'peer_validation': 'Other clients validate behavior' } return protections # Example: Simple value encryption in memory class ProtectedInt: """Store integer with basic encryption""" def __init__(self, value): self._key = random.randint(1000, 9999) self._encrypted = value ^ self._key @property def value(self): return self._encrypted ^ self._key @value.setter def value(self, new_value): self._encrypted = new_value ^ self._key
在 GitHub 查看
这个 SKILL.md 很大,SkillsMP 这里只预览前一段内容。 在 GitHub 查看