So according to this Valve is monitoring your DNS cache in order to catch cheaters with the byproduct of also collecting your entire browser history
VAC now reads all the domains you have visited and sends it back to their servers hashed : GlobalOffensive
This is a big wtf if true though.
VAC now reads all the domains you have visited and sends it back to their servers hashed : GlobalOffensive
Tried to look to the thread to find any verification that they are actually sending information back to Valve, and only came up with thisDecompiled module:http://i.imgur.com/z9dppCk.png
What it does:
Goes through all your DNS Cache entries (ipconfig /displaydns)
Hashes each one with md5
Reports back to VAC Servers
So the domain reddit.com would be 1fd7de7da0fce4963f775a5fdb894db5 or organner.pl would be 107cad71e7442611aa633818de5f2930 (Although this might not be fully correct because it seems to be doing something to characters between A-Z, possible making them lowercase)
Hashing with md5 is not full proof, they can be reversed easily nowadays using rainbowtables. So they are relying on a weak hashing function
You dont have to visit the site, any query to the site (an image, a redirect link, a file on the server) will be added to the dns cache. And only the domain will be in your cache, no full urls. Entries in the cache remains till they expire or at most 1 day (might not be 100% accurate), but they dont last forever.
We don't know how long this information is kept on their servers, maybe forever, maybe a few days. It's probably done everytime you join a vac server. It seems they are moving from detecting the cheats themselves to computer forensics. Relying on leftover data from using the cheats. This has been done by other anticheats, like punkbuster and resulted in false bans. Although im not saying they will ban people from simply visiting the site, just that it can be easily exploited
Original thread removed, reposted as self text (eNzyy: Hey, please could you present the information in a self post rather than linking to a hacking site. Thanks)
EDIT1: To replicate this yourself, you will have to dump the vac modules from the game. Vac modules are streamed from vac servers and attach themselves to either steamservice.exe or steam.exe (not sure which one). Once you dump it, you can load the dll into ida and decompile it yourself, then reverse it to find the winapi calls it is using and come to the conclusion yourself. There might be software/code out there to dump vac modules. But its not an easy task. And on a final note, you shouldn't trust anyone with your data, even if its valve. At the very least they should have a clear privacy policy for vac.
But I am not sure what that means, as I have no idea what I am looking at there.http://i.imgur.com/J681m2v.pngThere you go, verified they are in fact collecting.
permalink
parent
[?]hiver [score hidden] 28 minutes ago
What am I looking at?
permalink
parent
[?]frankster [score hidden] 16 minutes ago
No evidence they are sending back to the servers though right?
permalink
parent
[?]codeusasoft [score hidden] 11 minutes ago
DnSGetCacheDataTable sends it back.
This is a big wtf if true though.