m0d_sa FenixZone AC Bypass

Hello UGBASE,
Iam releasing my analysis knowledges about FenixZone Anticheat and solution to prevent being detected.

Basically everything is here

I would start how they managed to load the anticheat into process memory:
Its Basic RCE (Remote Code Execution) via RPC_ShowDialog
Its ilegall to use RCE


How you can detect incoming malicious rpc like this one?
  • Make IncomingRPC Hook
  • Check for RPC_ShowDialog
  • Check packet size .. MaxSize of every normal dialog is 33000, but they oversized it (injected assembly via that so its around 382032 b (unpacked its ~ 220kb))
  • All you need to do is to get bitstream data and check every byte until you found byte[0] = 'M' && byte[1] = 'Z' (dont need to explain to experienced people) then just extract assembly from start to end of the bitstream..
  • Well now you have assembly whats next?
Use snippets here and you have complete bypass, cuz I did all the work for ya...

Their modules explained:
nz.dll - Basic dll being injected by RCE too (33kb) it basically contains export to load PE into memory from path.. if iam not mistaken
anti-key.asi - be careful, they also extracting random named .asi file (in this case anti-key) into ur gta sa directory, but its basically just dll downloader and loader..
nzeE831D.tmp - Obfuscated assembly (easy to deobfuscate, but iam not gonna share the src to keep something for myself), which contains crypted/packed (via MPRESS) assembly which is our anticheat file. => its basically self unpacker (thats the file we are focusing in IncomingRPC hook primary)
discord-rpc.dll - dont need to explain.. not dangerous
etc

How they communicate (client-server)?
Well I didnt spent lof of time analyzing this.. but I would say they making shadow copy of sendto and also sending ingame commands like /buto, /cuco etc.. and these commands are important !

/cuco [message] => i dont really know what it does, but I guess its also verified on the serverside.. lets say [message] is number somehow generated and stored in variable - if you call original you are basically fine.
/buto [message] - well this one is improtant cuz every 15th call of one callback its sending /buto <hex> which i reversed and this one is primary checked on the server - if it does not match with their side => KICK
and with every command comes also sendto on their server, you can find their server ip by urself. (ports are randomly generated - its opening socket, sendto and then just instant close)

What this anticheat do?
  • Memory scans
  • Module scans
  • Window handles scans
  • .ASi/.SF/.CS Scans
  • SAMPFUNCS Console Detections
Just fokin everything

If you want to know more - do research by urself. :)
Also I will release #TE Project 1.0.2.5fz (spec. edition) with FZ bypass soon on our discord server.
If you have any questions then my discord is watersmoke

Thanks to CikaUIF (CikaDjokica) for help with analysis, crack.

Enjoy


 

Attachments

  • bypassed.png
    bypassed.png
    2.2 MB · Views: 81

Expl01T3R

Active member
Joined
Nov 20, 2022
Messages
169
Solutions
1
Reaction score
32
Location
Czech Republic

francis7777

New member
Joined
Jan 11, 2024
Messages
3
Reaction score
5
Expl01T3R and Sobfox are 2 poor lammers who have no knowledge. For years, Expl01T3R has dedicated himself to nothing more than making cheats that are useless. His PC is an i5; he doesn't even have money to buy a PC. He is completely useless and an embarrassment, trying to get attention with foolishness. He couldn't emulate the anticheat; the only thing he did was nullify threads, ridiculous.
 

Expl01T3R

Active member
Joined
Nov 20, 2022
Messages
169
Solutions
1
Reaction score
32
Location
Czech Republic
Expl01T3R and Sobfox are 2 poor lammers who have no knowledge. For years, Expl01T3R has dedicated himself to nothing more than making cheats that are useless. His PC is an i5; he doesn't even have money to buy a PC. He is completely useless and an embarrassment, trying to get attention with foolishness. He couldn't emulate the anticheat; the only thing he did was nullify threads, ridiculous.
Thanks bro:cool:
 

SobFoX

Expert
Joined
Jul 14, 2015
Messages
1,507
Solutions
5
Reaction score
931
Location
Israel
Expl01T3R and Sobfox are 2 poor lammers who have no knowledge. For years, Expl01T3R has dedicated himself to nothing more than making cheats that are useless. His PC is an i5; he doesn't even have money to buy a PC. He is completely useless and an embarrassment, trying to get attention with foolishness. He couldn't emulate the anticheat; the only thing he did was nullify threads, ridiculous.
It seems to me that you need a small controller on your servers. It's been a long time since your players had FPS 1. You probably miss it. :sneaky:
 

francis7777

New member
Joined
Jan 11, 2024
Messages
3
Reaction score
5
It seems to me that you need a small controller on your servers. It's been a long time since your players had FPS 1. You probably miss it. :sneaky:
I don't play SA-MP, but this proves my point: collecting cars on a SA-MP server to cause FPS drops is very lammer-like. Has no one ever told you how truly sad your life is? I mean, creating cheats for nothing for years... it's surprising that I have to explain this to you, LAMMER.
 

SobFoX

Expert
Joined
Jul 14, 2015
Messages
1,507
Solutions
5
Reaction score
931
Location
Israel
I don't play SA-MP, but this proves my point: collecting cars on a SA-MP server to cause FPS drops is very lammer-like. Has no one ever told you how truly sad your life is? I mean, creating cheats for nothing for years... it's surprising that I have to explain this to you, LAMMER.
Jealousy is eating you up
 

Mattioli

New member
Joined
Jun 26, 2025
Messages
3
Reaction score
1
Watersmoke, you are our whore just like you always were, you and all the disgusting Russians and Czechs like you
 

Expl01T3R

Active member
Joined
Nov 20, 2022
Messages
169
Solutions
1
Reaction score
32
Location
Czech Republic
Watersmoke, you are our whore just like you always were, you and all the disgusting Russians and Czechs like you
Hilarious, bro. You mad? Don’t be — I fully reversed your entire anticheat and bypassed it in under a week.
But that’s just the beginning.
I’ve reported you to multiple government agencies and to OVH, the hosting provider behind your FenixZone servers.
An abuse ticket has already been created. You’ll likely be contacted and asked to take down the RCE exploit you’re actively using against players — though I doubt you will.
Which only makes things easier.
 
Top