Jump to content


  • Content Count

  • Joined

  • Last visited

  • Medals

  • Medals

Community Reputation

481 Excellent


About RozekPoland

  • Rank
    Gunnery Sergeant

Contact Methods

  • Website URL
  • Skype
  • Twitter
  • Youtube
  • Steam url id
  • Reddit
  • Twitch.Tv

Profile Information

  • Gender
    Not Telling

Recent Profile Visitors

2338 profile views
  1. RozekPoland

    OFP.info 2.0

    Hi The links attached in that post point to an external server that is not related to OFP.INFO. Those files were never hosted on OFP.INFO server. The link in that post has been fixed.
  2. As recently OFP/ACWA turned 18, the game is mature and far beyond EOL (End-Of-Life), I decided to reveal the ways which hackers/cheaters have been using in OFP/ACWA. Such a decision may be doubtful, especially in context of morality, because the reveal can be used against players & communities that still play the game. To avoid any unnecessary collateral damage the revealed knowledge may cause, this post is limited to the very basics that are crucial to understand the entries hackers/cheaters have been using. I would like to emphasize that my post exposes the modus operandi of hacks/cheats that have been in practical use since the golden age of OFP. It is the OFP/ACWA community that can finally understand the way those hacks/cheats were being injected into the game. This post, as the whole thread, is strictly technical, and this is how I would like to keep it. Due to complexity of the idea behind CPP Hijacking, it can be executed in two ways. WAY 1 - Folder Disguise kozl.pbo is an official addon that introduces famous Kozlice gun The pbo file of the addon includes config.cpp Due to that fact, the addon is vulnerable to be CPP-Hijacked All that has to be done is: Create a folder named kozl in the main OFP/ACWA directory Copy the original config.cpp of the addon (or create a new one) and paste it in kozl folder That config.cpp file will be used by the game instead of the original one from the addon pbo file The serious issue is when it comes to detect such a hack/cheat in multiplayer on a dedicated server. For this purpose let's make a use of the checkfiles template I shared in my previous post. It turns out that it is IMPOSSIBLE to detect such a hack/cheat via Checkfiles array due to technical limitations It is because checkfiles method focuses on: in the first two entries of the template server compares its pbo file with client's one in the two last entries of the template server compares config.bin & config.cpp from its pbo file with client's one(s) The checking process will not come across any problems as the addon pbo file was not modified in any way It is the game engine that loads config.cpp from a separate location into memory As the outcome, no modified data message shows up and a modified config.cpp located in a folder named the same way as an addon STAYS UNDETECTED Content which is WAY-1 CPP Hijacking vulnerable original addons: ch47.pbo humr.pbo kozl.pbo su25.pbo trab.pbo community-made addons: all pbo files that feature config.cpp WAY 2 - Addon Disguise bizon.pbo is an official addon that introduces well-known Bizon weapon class and Spetsnaz Bizon Operator class The addon, as well as 26 other official addons, is vulnerable to WAY-2 CPP Hijacking All that has to be done is: Create a new addon that will modify the Bizon addon the name of the new addon does not matter Prepare CfgPatches section in the config of the new addon requiredAddons token allows to make "a reference" to any addon by using or modifying its content Use of requiredAddons[]={"Bizon"}; allows to make a reference to the addon that is meant to be modified The new addon is hooked to the Bizon addon, so is the Bizon addon's content which can be modified Let's see how does the situation with the modifying addon look like in multiplayer. Again, let's use the template shared in my previous post. As it is impossible to determine a name of the modifying addon, it is NOT POSSIBLE to detect its usage in multiplayer The original Bizon addon was not modified in anyway so there will be no "modified data" detection It is the new modifying addon that introduces changes to the Bizon addon's content but the game engine differentiates them as separate Similarly to WAY-1 CPP Hijacking, checkfiles mechanism is helpless in such circumstances
  3. Due to my recent study focused on security measure of OFP/ACWA Dedicated Server I have done some research on checkfiles[]={}; array and its practical use. Thanks to checkfiles, it is possible to make sure that each player that connects to a server is compatible with it in terms of content of the game. There are two ways of "checking" files via checkfiles. It is possible to checkfile any pbo file (and its content) as well as any other file that is located in OFP/ACWA game folder. Keep in mind that including such a list in server.cfg will make connecting to a server extremely long and unstable. It is meant for testing purpose only. To make it more performance-friendly and robust at the same time, I have prepared a basic list for checking the crucial content of OFP/ACWA. It is a good starting point for a vanilla (no-addons) server. According to my latest discovery from the previous post, it is highly recommended to add these lines to checkfiles array. If server uses custom addons/mods then it is recommended to include them in checkfiles array. It is worth the effort not only because of security issues but also for keeping 100% of synchronization between clients and server. It is worth mentioning that It is also possible to do checkfile ON-DEMAND on server by server admin.
  4. Recently I discovered a security flaw in OFP/ACWA that can be exploited by hackers/cheaters to use modified versions of original game files without being detected at any point by any available measure. I would like to provide you details how to prevent usage of the hack. The hack is oriented around the files listed below: A hacker/cheater can use modified version of the aforementioned files with them NOT being detected as modified by checkfiles server mechanism. To make the hack unable to work, each mission has to have all the listed files in its mission folder. The files can be even empty inside but they have to be present there with the exact names. Keep in mind that depending on type of respawn in a mission, such files as: onPlayerKilled.sqs onPlayerRespawnAsSeagull.sqs onPlayerRespawnOtherUnit.sqs can influence the way respawn works in a mission. It is recommended to copy the three files listed above from original DTA/scripts.pbo and paste them in a mission folder.
  5. RozekPoland

    Bn880's Tracers V1.0

    With permission and approval of @bn880, 14 years since the last update, I have decided to release a fixed version of bn880's Tracers addon which is compatible with ACWA (1.99 version). Link: ftp://ftp.armedassault.info/ofpd/unofaddons4/BN_tracers1_25.zip
  6. RozekPoland

    OFP videography

    Part 3 and part 4 are ready!
  7. RozekPoland

    OFP videography

  8. RozekPoland

    OFP.info 2.0

    Hi! BWMOD_BasicPack_v1.2.rar - the file was not available in the backup of the website I was provided bwmod_wiesel_v2.0.rar - the link to the file was fixed BWMOD_EF_beta.rar - the link to the file was fixed Thank you for the information. Please, provide any other dead links you will find.
  9. RozekPoland

    OFP videography

  10. RozekPoland

    OFP videography

    Part 5 and Part 6 (the finale) are available!
  11. RozekPoland

    OFP videography

    Part 4 is available!
  12. RozekPoland

    OFP videography

    First three parts of walkthrough of a single-player campaign "PMC Ranger Path" created by @Snake Man. More to come!
  13. RozekPoland

    18th anniversary of OFP/ACWA

    the picture created by: (unknown author); edited by RozekPoland; source: ofpr.info.paradoxstudio.uk On 22nd of June, 2001, Bohemia Interactive released their first flagship title "Operation Flashpoint: Cold War Crisis" (OFP) also known as "Arma: Cold War Assault" (ACWA). After 18 years: Addons, modifications, scripts and missions are still being developed. Communities, groups and players are still playing on dedicated servers. The game is still being sold on Steam and BIStore. 4 years ago, at the 14th anniversary, I shared a gallery of the best pictures (over 700) that have ever been posted in OFP Photography threads. I have decided to move the whole gallery to Imgur which works smoother, provides more sharing features and is more user-friendly. I would like to invite you to my OFP/ACWA live-stream on YouTube. I am going to play a single-player campaign "PMC Ranger Path" by @Snake Man. The stream is starting at 7PM CEST (6PM UTC+1). See you!
  14. FILE(s) NOT FOUND (file paths that were not found by the game) (bold - ACWA 1.99) OFP/ACWA Main Menu Specular textures: data\grass_dx.paa misc\waveBumpMap.paa Global textures (numerized): data\desta.05.paa data\mesic.13.paa data\more_anim.08.pac data\basic.17.paa data\fire.121.paa data\fired.120.paa data\water.07.paa data\zasleh_front.04.paa data\zasleh_side.04.paa data\zasleh3_front.04.paa data\zasleh3_side.04.paa Textures: biscamel\icamel2.paa World cutscene detector (mission file format depends on currently loaded island): anims\intro.Intro\stringtable.csv anims\intro.Intro\description.ext Legacy leftovers: dtaExt\ofplogo1.paa dtaExt\ofplogo2.paa dtaExt\ofplogo3.paa Game001.Intro\ofplogo1.paa Game001.Intro\ofplogo2.paa Game001.Intro\ofplogo3.paa Game001.Intro\startup_logo_cwa_ca.paa Config(s) 6g30\config.cpp abox\config.cpp apac\config.cpp biscamel\config.cpp bizon\config.cpp bmp2\config.cpp brmd\config.cpp ch47\config.cpp flags\config.cpp g36a\config.cpp humr\config.cpp hunter\config.cpp kolo\config.cpp kozl\config.cpp laserguided\config.cpp m2a2\config.cpp mini\config.cpp mm-1\config.cpp noe\config.cpp o\config.cpp oh58\config.cpp o_wp\config.cpp steyr\config.cpp su25\config.cpp trab\config.cpp vulcan\config.cpp xms\config.cpp voicerh\config.cpp voicerh\stringtable.csv Models dtaExt\notebook.p3d OFP/ACWA Edit Profile Models: dtaExt\hlavaw.p3d male head dtaExt\o\char\civilistka_head.p3d female head OFP/ACWA Mission Editor - Island Selection Models: anims\intro.intro\notebook.p3d Replacement of notebook/computer model for Mission Editor - Island Selection. Currently loaded island determines mission file format (.intro, .eden, .abel, .cain, .noe). dtaExt\notebook.p3d As above but replacement works for all islands without specific mission folders for specific islands Textures: anims\intro.intro\_eden.paa dtaExt\_eden.paa anims\intro.intro\_abel.paa dtaExt\_abel.paa anims\intro.intro\_cain.paa dtaExt\_cain.paa anims\intro.intro\_training.paa dtaExt\_training.paa anims\intro.intro\\o\misc\_nogovo.paa dtaExt\\o\misc\_nogovo.paa demo\demo.wrp demo.wrp is defined in config and it refers to Malden from OFP demo version (mission files saved as MissionName.demo format) OFP/ACWA Mission Editor Textures: notasa.pac notasb.pac notasc.pac notasd.pac notase.pac notasf.pac bourka.paa podmapa.pac zatazenosl.paa bourkasym.paa jasnosym.paa eastsym.paa westsym.paa azimut.paa OFP/ACWA Mission Editor - Preview Models: kompas.p3d kosei.p3d vysilacka.p3d blok.p3d karta.p3d gps.p3d Textures: podmapa.pac sipka_left.paa sipka_right.paa equip\w\ (+ multiple files) equip\m\ (+ multiple files) equip\ (+ multiple files) OFP/ACWA Mission Editor - Debriefing Models: blok_selmis2.p3d desky.p3d Textures: debr_star.paa OFP/ACWA Singleplayer - Mission Selection Models: anims\intro.intro\blok_selmis2.p3d dtaExt\blok_selmis2.p3d OFP/ACWA Singleplayer - Briefing Textures: data\kasna_voda.07.paa data\m1_passide_anim.07.pac data\night_sum.06.paa data\bmp_anm.06.pac OFP/ACWA Multiplayer - Lobby Textures: anims\intro.intro\misc\gamespy.pac dtaExt\misc\gamespy.pac anims\intro.intro\misc\sipkad.paa dtaExt\misc\sipkad.paa
  15. RozekPoland

    OFP videography

    Today, at 8PM CEST (7PM UTC+1), I am going to livestream gameplay from a few dynamic single-player missions on DMA Libya map in OFP/ACWA. See you there!