Register for your free account! | Forgot your password?

Go Back   elitepvpers > Other Online Games > Browsergames > DarkOrbit
You last visited: Today at 15:48

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Issues with DarkOrbit anti-bot detection system

Discussion on Issues with DarkOrbit anti-bot detection system within the DarkOrbit forum part of the Browsergames category.

Reply
 
Old   #1
 
»jD«'s Avatar
 
elite*gold: 237
Join Date: Sep 2010
Posts: 1,152
Received Thanks: 4,910
Issues with DarkOrbit anti-bot detection system

Its been a while since I posted here so I thought I'd start it off with a warning to all those players who play on shared computers.

If you play on a computer that has previously had a SWF Changer run on it, you could accidentally be detected as a bot user.

I came across this issue when debugging some code and found that the way caching works with DarkOrbit, changes in the game files can actually carry across to other accounts before the cache expires. Whilst its a rare issue, I know for a fact that I play on computers that are shared with my brothers who are both clean players, but could accidentally be detected by the issue.

So far this hasn't happened but I thought I would warn users who share computers.

Also to note is that the specific way they detect pixel bot users is extremely vulnerable to enterprise proxies or other proxies that intercept and modify web pages to inject ad's and other things. By doing this they change the hash of the resources.xml file which can trigger a false positive in their bot detection code. I actually managed to reproduce this issue accidently by using the game on a University campus. Their proxy modifies and caches web pages and does other things that modify the resources.xml file as well as modify other xml game files. By playing behind these types of firewalls you greatly increase your chances of being caught accidently as a bot player.

On top of all that, the entire system is extremely vulnerable to all sorts of caching issues. If you accidently get served an old version of resources.xml for instance (because your browser cached it or for whatever reason) this can also trigger a false positive in their anti-bot code.

Just so I don't sound like I'm pulling facts from my arse I'll explain how their anti-bot code works. In the resources.xml file it lists all the game resources and SWF files that DarkOrbit uses in game. Along with their names and locations they also store a MD5 hash of the file. When the game loads it runs a bit of extra code for any resource that is either Palladium or a bonus box. What this code does is verify the hash in the resources.xml file against the hash of the actual file downloaded. If they don't match, it sends an event along their 'eventstream' as well as modifies two ingame variables that affect the X and Y coordinates sent in the hero movement packets. What this means is that any slight discrepancy between the expected hash of the file and the actual hash of the file gets you flagged as a botter.

You might ask how many actual, real world scenarios could trigger a false positive in this seemingly well thought out bot detection code? Let me make you a list:
  • Caching troubles: Any difference between the actual resources.xml and the one your browser has and gives to the game can cause a false positive. If the hash in the resources.xml that your browser has cached doesn't match the one the game currently uses, even though you have never used a hack or cheat or bot ever before, can cause a false positive to be triggered.
  • Corruption of resources.xml: If somehow your resources.xml gets modified or corrupted in transit but is still readable, you can cause a false positive.
  • Corruption of bonus box SWFs: This is the big one in my opinion. If somehow the process of loading the SWF is interrupted or intercepted it can cause the SWF's hash to be incorrect when checked and also trigger a false positive.

Now those three cases might not seem that prevalent but I'd like to point out one other situation that I have ACTUALLY BEEN IN that this has happened. A lot of big education institutions run caching proxies on their internet connections to decrease the bandwidth used by their students. One place I visited ran Squid with the "Compress all SWFs" plugin enabled. What this does is intercepts all SWF files and recompresses them to save bandwidth. Obviously, this changes the hash of the file and causes you to be flagged as a botter.

I'm not trying to make it seem like there is no fool-proof way of detecting botters, I'm just trying to point out that the way Bigpoint currently does it is extremely delicate and that they should not be banning users with a permanent ban, and then reply to users who complain in an email that "All Bans are final and we do not discuss them". Do I have to remind you of the time all those people who played on Mac's got banned incorrectly and they had to go back and unban everyone? Yea, Bigpoint, 100% accuracy there

-jD
»jD« is offline  
Thanks
29 Users
Old 02/03/2015, 13:35   #2



 
Serraniel's Avatar
 
elite*gold: 0
The Black Market: 205/1/0
Join Date: May 2010
Posts: 6,853
Received Thanks: 5,106
Well played Bigpoint...
Serraniel is offline  
Thanks
5 Users
Old 02/03/2015, 15:42   #3
 
elite*gold: 0
Join Date: Dec 2012
Posts: 469
Received Thanks: 395
Im sure they know all of theses caching problems , bigpoint have a lot of money and a lot of experiance to fight bot users

did you reming before ? there was like 10 000 players on each servers

80% of them was botting ~12h/24h

ALL of them was banned even old bot users that stopped using them ,


Only the guys are using private bots wasn't banned



After that they added the banwave system


and now they are improving the antipixelbot system , but they are really carefull with that , because pixel bot go more and more realistinf about imitating a human


BP is not dumb , BP i just really good at protecting their game ,

but not all servers have max ~2000 ppl connected at the same time
Zetadarus is offline  
Old 02/03/2015, 16:26   #4
 
Řoβч966's Avatar
 
elite*gold: 0
The Black Market: 117/0/2
Join Date: Sep 2014
Posts: 2,870
Received Thanks: 2,520
I personally know some players who got banned even without have never installed any kind of bot, tool or pixel bot.

So nope, is not really good protecting Darkorbit.
Řoβч966 is offline  
Thanks
1 User
Old 02/03/2015, 16:35   #5
 
Diаmonds's Avatar
 
elite*gold: 1
Join Date: Oct 2013
Posts: 1,257
Received Thanks: 1,276
So, there are 2 ways not to get banned :
- Stop playing
- Stop playing on a computer
Am I right?
Diаmonds is offline  
Thanks
10 Users
Old 02/03/2015, 17:22   #6
 
e-[G]-old[D]ie[O]ut's Avatar
 
elite*gold: 0
Join Date: Sep 2010
Posts: 1,457
Received Thanks: 344
The problem is the support if you were banned but you really didnt use any bots.
The German supp is such a s.hit..especially "Kathleen" or however her name is written,such a ignorant person,you can´t talk ordinary with her she will refuse any proves and send you a typical standart text.
e-[G]-old[D]ie[O]ut is offline  
Thanks
2 Users
Old 02/03/2015, 17:37   #7
 
skeith_sk8's Avatar
 
elite*gold: 0
Join Date: May 2012
Posts: 3,053
Received Thanks: 2,658
Quote:
Originally Posted by e-[G]-old[D]ie[O]ut View Post
The problem is the support if you were banned but you really didnt use any bots.
The German supp is such a s.hit..especially "Kathleen" or however her name is written,such a ignorant person,you can´t talk ordinary with her she will refuse any proves and send you a typical standart text.
Dont worry men, it happens in all servers
skeith_sk8 is offline  
Old 02/03/2015, 17:47   #8
 
cryz35's Avatar
 
elite*gold: 0
Join Date: Feb 2009
Posts: 1,718
Received Thanks: 2,382
Quote:
Originally Posted by e-[G]-old[D]ie[O]ut View Post
The problem is the support if you were banned but you really didnt use any bots.
The German supp is such a s.hit..especially "Kathleen" or however her name is written,such a ignorant person,you can´t talk ordinary with her she will refuse any proves and send you a typical standart text.
Same with Kara, the US supporter. Actually I think it is a bot, I'm getting same answers again and again from her, as my friends, for 6 years.
cryz35 is offline  
Thanks
2 Users
Old 02/03/2015, 17:48   #9
 
elite*gold: 0
Join Date: Oct 2011
Posts: 336
Received Thanks: 151
Quote:
Originally Posted by e-[G]-old[D]ie[O]ut View Post
The problem is the support if you were banned but you really didnt use any bots.
The German supp is such a s.hit..especially "Kathleen" or however her name is written,such a ignorant person,you can´t talk ordinary with her she will refuse any proves and send you a typical standart text.
Trust me all those people in support are ***** like she is! When I lost all my 8 irises because of their ship bug (had a video with the bugged ship) they said that it's my fault and I have to use CPU for drone repairing, also teached me how to repair them like I didn't know how to do it -.-

Ra5taLV
ra5taLV is offline  
Thanks
2 Users
Old 02/03/2015, 18:27   #10
 
leadersleader's Avatar
 
elite*gold: 0
Join Date: Feb 2011
Posts: 173
Received Thanks: 81
Quote:
Originally Posted by Řoβч966 View Post
I personally know some players who got banned even without have never installed any kind of bot, tool or pixel bot.

So nope, is not really good protecting Darkorbit.
I agree with you ..i never used any bot but i was perma banned..to this day they cant tell me why..worse part i spent over $9k in this game
leadersleader is offline  
Thanks
1 User
Old 02/03/2015, 19:54   #11
 
manulaiko3.0's Avatar
 
elite*gold: 0
Join Date: May 2014
Posts: 663
Received Thanks: 1,154
Quote:
Originally Posted by leadersleader View Post
I agree with you ..i never used any bot but i was perma banned..to this day they cant tell me why..worse part i spent over $9k in this game
Really man... you are insane....
manulaiko3.0 is offline  
Thanks
4 Users
Old 02/03/2015, 20:07   #12
 
e-[G]-old[D]ie[O]ut's Avatar
 
elite*gold: 0
Join Date: Sep 2010
Posts: 1,457
Received Thanks: 344
There is another guy who gave bigpoint approx ~30k€,he´s a businessman,well its his money who cares.

BTT: Pixelbots aren´t safe as they are adveritsed ?
e-[G]-old[D]ie[O]ut is offline  
Old 02/03/2015, 20:36   #13
 
elite*gold: 0
Join Date: Feb 2015
Posts: 33
Received Thanks: 2
Woaw thats crazy how players who dont bot get banned!
Dexter's is offline  
Old 02/05/2015, 03:02   #14
 
GuNzOwNz's Avatar
 
elite*gold: 0
Join Date: Apr 2012
Posts: 412
Received Thanks: 231
can using hotspot shield get you banned?
GuNzOwNz is offline  
Thanks
1 User
Old 02/05/2015, 05:28   #15
 
»jD«'s Avatar
 
elite*gold: 237
Join Date: Sep 2010
Posts: 1,152
Received Thanks: 4,910
Quote:
Originally Posted by GuNzOwNz View Post
can using hotspot shield get you banned?
Doubt it. Its normally those cheap online proxy sites that inject their own ads into webpages to make some money off of you.

-jD
»jD« is offline  
Thanks
1 User
Reply


Similar Threads Similar Threads
Darkorbit New Detection system?
08/03/2011 - DarkOrbit - 2 Replies
Stage 1 Users are banned for 1 day, at the end of this day they get the CAPTCHA code to relog into the game. This stage should be twinned with: · 20% Experience Point Loss · 10% Honor Point Loss · 33% Credit Loss · 100% Jackpot Money Loss · 100% GG Energy Loss · 7 day period where they can only collect a bonus box every 30 seconds Stage 2
[Release]Alkey99's PSF Hack Pack with Anti-Detection System Hack Tool
03/09/2011 - Soldier Front Philippines - 5 Replies
REMINDER: Before you start the "SET UP GG EMULATOR" make sure you already installed the magic iso and magic disc 1st ok!!! Use GG Emulator 4.1 to make it work guys Note : Injector and DLL is in one its auto inject This hack made it's just ordinary built in injector hack .dll inside by executing it ready to used or ready for injection... and if theres an error Occurd d3dx9_42.dll just download drag it or place it in to / My Computer/ C: Windows/System32 then click close 1.DOWNLOAD...



All times are GMT +1. The time now is 15:49.


Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2025 elitepvpers All Rights Reserved.