Also, while we're on hacker news, is it known how the party hat duplication bug happened? I like reading hacking white papers, but I assume nothing was published regarding that.
Also, while we're on hacker news, is it known how the party hat duplication bug happened? I like reading hacking white papers, but I assume nothing was published regarding that.
https://archive.fo/DafO7 is an archive (of an archive) since I can't find the original page.
Depends on the client that was used. AutoRune was a popular client that sent direct packets. The game client gathered metrics on mouse movement though, so if you used direct packet injection you still had to fake the mouse movement to some extent so you could escape this rudimentary detection. Or your bot could just control the mouse in a somewhat realistic way and avoid needing to do extra work.
For reading game state, many bots in this time used color detection. So for example a flax picking bot might be coded to click on specific colors of cyan on the screen. Jagex would likewise respond with bot mitigation that was intended to fool the color detection system, for example by making flax have the same color whether it could actually be picked or not.
Later, clients would be developed that used decompilation and reflection of the Java game client to directly read game state in the form of Java objects. This would then be able to be queried and interacted with by scripts via an API that the client exposed. So for example, a script could be written that queried for all the flax (identified by their object id) around the player and instructed the client to pick it; the client would handle exactly how to move the mouse and the camera to achieve that.
I don't know for sure but I understand a lot of early bug abuse was due to a failure to perform server side validation. So hypothetically you might enter into a 2 part trade transaction flow where you offer items for trade in the 1st step and then commit that transaction in the 2nd step. Server side validation might be done in the 1st step to make sure you actually own the item you declared an intent to trade, but none is done in the 2nd step. So you could declare an intent to trade a worthless item you possess, but modify the transaction commit packet to give away an item you don't possess.
I was not part of the bug abuse community but I did find one bug in the game that involved multiple actions being done in a single server tick. As I understand it there have been a lot of bugs like this over the years. As a hypothetical example, it might be impossible to teleport while holding a certain item, but if you picked up the item on the same tick as you performed the teleport, the server might process the two actions in such a way that it allowed you to perform both.
Basically true, though:
- Aryan wasn't the first clientmod, not even the first to deob - probably the first to go fairly 'mainstream' and end up being well known outside the circle of people using it, though (being free probably helped here)
- No legal action, tbh. Well, the same amount of legal action that all of the cheating scene got (some C&D's, domain takedown attempt type stuff at various times, but not the scary kind of legal action in the way other bots got)
- The banwave backdoor did happen, and basically as you say (iirc it was the actual UID but negative, rather than -1) but was more of a conscious decision, there wasn't an 'agreement' beforehand - it was proactively taken. Jagex were informed about it in order to detect it though, as far as I'm aware.
Doubtful. I was just a kid at the time who lurked on forums. Were you involved in the scene? If yes, do you mind if I ask what you ended up doing professionally? RS cheat developers were my role models growing up. I’ve often wondered what members of that community are up to now.
Professionally nowadays I'm a pen tester/security consultant.
Worked on contributing a lot to that project, became my first (semi) open source contributions, and the scripts were my first forays into selling my work :)