View unanswered posts | View active topics It is currently Jun 18th, '13, 15:19




Reply to topic  [ 7 posts ] 
 Gravity using ieSnare to track accounts to computer(s) 
Author Message
Site Moderator
User avatar

Joined: Aug 18th, '09, 03:32
Posts: 1201
Post Gravity using ieSnare to track accounts to computer(s)
I've noticed that some time recently Gravity started using the ieSnare/DevicePrint computer tracking system.
If you use Firefox with the "NoScript" add-on you might have noticed it blocking "iesnare.com".
ieSnare company: http://www.iovation.com

It's basically a system that downloads a DLL onto your system (usually via a Flash module) that facilitates the reporting
of several of your unique software and hardware IDs, and flags if you are running under a VM, and have certain software
installed. It also maintains a hidden tracking "cookie" and some hidden/obfuscated tracking registry entries.

You might be thinking "..WTF spyware?.."
Technically via the common definition:
http://en.wikipedia.org/wiki/Malware and http://en.wikipedia.org/wiki/Spyware
"..is software designed to infiltrate a computer without the owner's informed consent.".
Did they get your consent to capture unique private data like your Windows serial number?
Often sites that use it do have some sort of "you agree.." in their site TOS for it.
It's understandable to what their goals are that they would do it this way..

What this means to you is if you allowed it to install then Gravity (at least for Requiem) can potentially track/key all your
accounts together. They will potentially know your account 'A' is attached to account 'B', etc.
Search your hard drive for "StmOCX.dll"; If it's there then it means you probably have ieSnare installed.
If you play(ed) online poker like "Full Tilt Poker" then it will probably already have been installed.

The reasons why I can think are numerous: Catch power leveling and gold farming companies, track bad and
exploitative players, catch fraudulent item mall users, etc.

If you Google for "ieSnare remove" it you should find out how to remove it.
Note it will just reinstall it's self the next time you go to http://www.playrequiem.com unless you have it blocked somehow.
If you do actively play online poker, you will probably want to keep it installed anyhow else your money account(s) might get
negatively flagged if it's not there.

Note the DLL (StmOCX.dll) gets registered as a COM/ActiveX object. Thus it can be accessed via web page scripts.
Plus it has normal DLL exports so it can be loaded and used directly by an application (as some poker clients do).
I completely reversed it a few years ago. And as soon as I have the time I will write about how it works in detail.
At first I will least post how to remove and block it from being installed.


Sep 18th, '09, 00:24
Profile

Joined: Sep 18th, '09, 18:51
Posts: 6
Post Re: Gravity using ieSnare to track accounts to computer(s)
Thanks for the heads up. This is cropping up all over the place. Apparently it's in nDoors Atlantica Online aswell. Guess I'll keep my eyes out for more.


Sep 19th, '09, 21:27
Profile

Joined: Oct 13th, '09, 01:23
Posts: 24
Location: japan
Post Re: Gravity using ieSnare to track accounts to computer(s)
ths for the information helpfull!thx! :clap:


Oct 13th, '09, 01:26
Profile
Site Moderator
User avatar

Joined: Aug 18th, '09, 03:32
Posts: 1201
Post Re: Gravity using ieSnare to track accounts to computer(s)
NP,

A little update.
Note the client dosn't run ieSnare, just the website via flash.
It must be enabled or you can't log-in to an account on the site.


Oct 14th, '09, 06:23
Profile

Joined: Oct 15th, '09, 09:42
Posts: 19
Post Re: Gravity using ieSnare to track accounts to computer(s)
I searched for the DLL in question but found nothing, does this mean I'm safe? or is it hidden?


Oct 15th, '09, 12:08
Profile
Site Moderator
User avatar

Joined: Aug 18th, '09, 03:32
Posts: 1201
Post Re: Gravity using ieSnare to track accounts to computer(s)
You can't find "StmOCX.dll"?
You sure you searched your whole "C:" (or what ever your main drive is)?
You can also see some script code for it in the main page source.

You won't be able to log-in to the Requiem main page with out it (forums are separate).


Oct 15th, '09, 12:58
Profile

Joined: Oct 15th, '09, 09:42
Posts: 19
Post Re: Gravity using ieSnare to track accounts to computer(s)
Sirmabus wrote:
You can't find "StmOCX.dll"?
You sure you searched your whole "C:" (or what ever your main drive is)?
You can also see some script code for it in the main page source.

You won't be able to log-in to the Requiem main page with out it (forums are separate).


I've searched all my hard drives for that specific item with no luck >.< would it parade as anything else? or have a parent folder i can check manually?


Oct 15th, '09, 13:27
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 7 posts ] 

Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group.
Based on design by STSoftware, modded by Sirmabus Copyright© 2009-2011