Windows Information about a dangerous private cheat bypassing EAC, ServerTools, and custom protections

K_3_F_1_R

Refugee
Version
2.3b9
Platform
Windows
Dear Developers at The Fun Pimps / 7 Days to Die Team,

I am writing to inform you about the existence of a dangerous private cheat for 7 Days to Die circulating online. This software poses a direct threat to the stability and fair play on all types of servers – from small private ones to large, popular projects.

**Key threats enabled by the cheat:**

1. Complete Bypass of Protection Systems:** The cheat successfully bypasses not only the built-in Easy Anti-Cheat (EAC) but also popular administrative plugins like ServerTools, as well as custom anti-cheat systems (e.g., Naiwazi), rendering servers virtually defenseless. This includes:
* **Bypassing ServerTools:** Activating god mode, infinite stamina, and invisibility on protected servers.
* **Bypassing Custom Anti-Cheats:** Circumventing user-made protections designed to detect boosts, making the aforementioned functions work despite them.

2. Advanced Destructive Capabilities:
* Unauthorized Access to Admin Functions: Enabling the debug menu, creative menu, and activation of edit mode for any player.
* Direct Attacks on Players: Instantly killing other players and teleporting them to the cheater's location against their will.
* Concealment of Activity: Spoofing player names to hide the perpetrator's identity in server logs.
* Automation and Exploitation: Automatically killing zombies that get too close and adding XP to the user, which disrupts game balance.

3. Impossibility of Detection: The cheat operates in a "silent" mode, leaving no traces in the server console, Windows Task Manager, or process lists, making it extremely difficult for administrators to detect.

4. Accessibility and Popularity: The cheat is currently being actively distributed at an affordable price (as part of a limited-time offer), increasing the risk of its widespread use and the potential for large-scale damage to the gaming community.

I understand the seriousness of this information and am prepared to provide the available data for your analysis privately, if you can indicate an official channel for such reports. Unfortunately, I was unable to find a way to contact you confidentially, hence this public message.

I urge you to treat this issue with the highest priority, as the exploitation of these vulnerabilities could lead to a complete destabilization of the game's multiplayer component.

**I am ready to assist by providing further details to help protect the game.**

Sincerely.
Post automatically merged:

If the publication is moved to a private status, I can provide you with evidence and links to this particular instance.
 
Reproduction Steps
Go to the link - Pay the fee - Download the cheat - Transfer it to a USB drive - Run it - Enter your website account credentials - Run it - Log into any server within 120 minutes.
Link to Logs
https://www.youtube.com/watch?v=-452p_9ESbM
Link to Screenshot/Video
https://www.youtube.com/watch?v=-452p_9ESbM
I confirm that I have also encountered players who have used this or a very similar cheat that breaks through the protection of servers. A knowledgeable cheater can bring down many servers in a short time. The operation of public servers is in great danger.
 
You could send the info via private message to any of the developers or testers in this forum. @schwanz9000 would be a good choice.

Since 7days depends on steam EAC for their security I would assume the only thing they can do would be to forward this to steam (provided they know who to contact) and hope that EAC is hardened to this. Once EAC is bypassed there is always a way to cheat as it seems too many of the calculations are done on the clients.
 
You could send the info via private message to any of the developers or testers in this forum. @schwanz9000 would be a good choice.

Since 7days depends on steam EAC for their security I would assume the only thing they can do would be to forward this to steam (provided they know who to contact) and hope that EAC is hardened to this. Once EAC is bypassed there is always a way to cheat as it seems too many of the calculations are done on the clients.
Thank you for providing the information - I have written to this employee and passed on all the information in full.
 
Back
Top