Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Zephyr)
  • No Skin
Collapse
RipperStore Logo
  1. Home
  2. Community
  3. General Discussions
  4. VRChat added VRCA (?maybe VRCW too) protection

VRChat added VRCA (?maybe VRCW too) protection

Scheduled Pinned Locked Moved General Discussions
protectionvrchatvrcaripping
285 Posts 103 Posters 107.3k Views 78 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ReymR Reym

    @Beeboo so you found potential bypass to get data again?

    Dr.beepD
    Dr.beepD
    Dr.beep
    wrote on last edited by Dr.beep
    #46

    @Reym I know of an anti cheat bypass, but I currently can't rip models, using Linux still works as an anti cheat bypass however the game randomly kicks you after a few minutes due to some type of checksum the cheat software runs. We may need to look into buying a Direct memory access board (DMA) Cheaters use them in games like fortnite and while I myself have no desire to cheat in a game played for fun, for the purpose of ripping I might invest in it

    Currently investigating ways to bypass VRC's new encryption on VRCA's and VRCW's. Msg me if you have any leads

    1 Reply Last reply
    0
    • ReymR
      ReymR
      Reym
      wrote on last edited by
      #47

      @Dr.beep so only anti cheat bypass for now i see, DMA is expensive, be careful on investing stuff as who knows we might find lead on something

      I'm bad at understanding english word

      I fix .vrca/.vrcw stuff for free and for fun! Depending on file, every outcome and vary might be different than the original avatar has due to the toggles and much more, send me a pm if you need an avi that need to fix or cracking a password locked avatar or send me .vrca file or through my pms and i will extract/fix them for you!

      request is semi-open, only on unencrypted __data file aka .vrca or .vrcw

      1 Reply Last reply
      0
      • E
        E
        esau_winchester
        wrote on last edited by
        #48

        Hey, why don't we go back to what the first rippers did?

        i.e. use second life to make an avatar there and rip it and port it to unity and then to vrchat ?

        i really feel that we have to go back to that
        or look for a new method to bypass the aes encryption.

        1 Reply Last reply
        0
        • dobypD
          dobypD
          dobyp
          wrote on last edited by
          #49

          this is all that its know atm:

          some people got around it
          you have to modify the client
          the file responsible for the encryption might be "vrc_fast_crypto.dll" in the plugins folder.
          dm me for further info

          LinzeL 1 Reply Last reply
          🤔
          0
          • dobypD dobyp

            this is all that its know atm:

            some people got around it
            you have to modify the client
            the file responsible for the encryption might be "vrc_fast_crypto.dll" in the plugins folder.
            dm me for further info

            LinzeL
            LinzeL
            Linze
            wrote on last edited by Linze
            #50
            This post is deleted!
            1 Reply Last reply
            🤔
            0
            • D
              D
              DeepDishBussy
              wrote on last edited by
              #51

              Someone in the ARC discord said this "the fast_crypto.dll does nothing but work for udon and p2p encryption" I suspect this isn't related or the file at least is not responsible for the encryption.

              DM me if any of my links go down or if a file is outdated

              1 Reply Last reply
              0
              • ReymR
                ReymR
                Reym
                wrote on last edited by Reym
                #52

                @LeonKennedy that is such a interesting info

                there is new file whenever you open the cache-windows, called vrc-version, i not sure what it is, back then it was not a thing, maybe they are used for decryption? Like sort of authetication

                New or old file appear in plugin folder called mediapipe_c and lib_burst_generated, how do i check dll?

                I'm bad at understanding english word

                I fix .vrca/.vrcw stuff for free and for fun! Depending on file, every outcome and vary might be different than the original avatar has due to the toggles and much more, send me a pm if you need an avi that need to fix or cracking a password locked avatar or send me .vrca file or through my pms and i will extract/fix them for you!

                request is semi-open, only on unencrypted __data file aka .vrca or .vrcw

                1 Reply Last reply
                0
                • dobypD
                  dobypD
                  dobyp
                  wrote on last edited by dobyp
                  #53

                  i've reversed the dll myself, and it's in fact not related to the avatar encryption, but it's known that everything happens on memory.

                  If you know about reverse engineering we could create a discord group to help each other, if you are interested dm me.

                  1 Reply Last reply
                  😳
                  0
                  • avatarofcornA
                    avatarofcornA
                    avatarofcorn
                    wrote on last edited by
                    #54

                    Touching the client is resource intensive. I believe that going around it by bumping TLS or getting bundles from the CDN is our best bet yet.

                    1 Reply Last reply
                    0
                    • SillyBunnyS
                      SillyBunnyS
                      SillyBunny
                      wrote on last edited by
                      #55

                      there is multiple people who have a working method i dont know it myself but i would like the eac bypass because i could probably make a melon loader mod to do it

                      1 Reply Last reply
                      0
                      • C
                        C
                        chocolate
                        wrote on last edited by
                        #56

                        Why not try asking the developers who make HEX?

                        1 Reply Last reply
                        0
                        • Dr.beepD
                          Dr.beepD
                          Dr.beep
                          wrote on last edited by
                          #57

                          Has anyone found any leads yet?

                          Currently investigating ways to bypass VRC's new encryption on VRCA's and VRCW's. Msg me if you have any leads

                          1 Reply Last reply
                          1
                          • CryoVRC
                            CryoVRC
                            CryoVR
                            wrote on last edited by
                            #58

                            I may be wrong (I don't think so though) but I just ripped an avatar just fine I know that with the newest sdk 3.8 or something they have detections for ripped avis so if you import an avatar it's got to be renamed and all folders need to be moved and renamed to trick it into thinking it's normal. It really pissed me off but it doesn't seem to be impossible, took me a bit but def. doable.
                            I wasn't able to rip with UTiny like the old days but I have an old bit of software that for my continued use will not be naming but FYI I believe you can.

                            1 Reply Last reply
                            0
                            • D
                              D
                              DeepDishBussy
                              wrote on last edited by
                              #59

                              Can I ask where you heard about the ripping detections for sdk 3.8? If this is true, that is very frustrating

                              DM me if any of my links go down or if a file is outdated

                              1 Reply Last reply
                              0
                              • BabyBlueBunnyB
                                BabyBlueBunnyB
                                BabyBlueBunny
                                wrote on last edited by
                                #60

                                I don't know much about the ripping detection, but recently I ran into a public avatar that in their radial wheel they had a toggle which stated "I know when you rip this avatar" and in the description it outed 2-3 people that have before. But that's as far as I've heard about it

                                MyongM 1 Reply Last reply
                                0
                                • BabyBlueBunnyB BabyBlueBunny

                                  I don't know much about the ripping detection, but recently I ran into a public avatar that in their radial wheel they had a toggle which stated "I know when you rip this avatar" and in the description it outed 2-3 people that have before. But that's as far as I've heard about it

                                  MyongM
                                  MyongM
                                  Myong
                                  wrote on last edited by
                                  #61

                                  @mrblueskelly That sounds more like the original creator found the ripped versions, could be a user thats part of a small community/fandom that got told about their model getting ripped or the people who ripped the model making their versions public since thats what i generally see happen

                                  1 Reply Last reply
                                  🤡
                                  2
                                  • BabyBlueBunnyB
                                    BabyBlueBunnyB
                                    BabyBlueBunny
                                    wrote on last edited by
                                    #62

                                    Yeah that sounds more likely honestly, the only "ripping detection" I've heard about is Gonzo which in my opinion the weirdest shit, on the creator side of things I wouldn't touch it with a 10ft pole

                                    1 Reply Last reply
                                    3
                                    • V
                                      V
                                      vrchat_account
                                      wrote on last edited by
                                      #63
                                      This post is deleted!
                                      1 Reply Last reply
                                      1
                                      • V
                                        V
                                        vrchat_account
                                        wrote on last edited by
                                        #64
                                        This post is deleted!
                                        1 Reply Last reply
                                        1
                                        • S
                                          S
                                          stetamatea
                                          wrote on last edited by
                                          #65

                                          So few things I discovered from my analysis.

                                          1. For now encryption is client side and assets are encrypted only after they are downloaded

                                          2. Seems they are using AES which is very strong BUT the game has to have a key to decrypt it so just like with Unreal Engine PAK files it should be possible to eventually find where the key is and get it, there are three possibilities, one is that key is hardcoded into the game and is same for all users, second is that key is derived from some sort of unique ID like HWID so that every user has different key (I have yet to test it by transfering cache to another PC) third option is that the decrpytion key isnt even in the game at all and that its sent by the server upon loading into the world.

                                          3. Using Fiddler doesnt work as game seems to use SSL Pinning so when running network sniffing asset related connections are rejected, Fiddler used to work few years ago for getting VRCA and VRCW files from CDN but looks like thats now fixed and VRCX JSON asset URL field is empty and even if you get the URL to asset on CDN connection is rejected because its expecting VRC user agent and auth key, it should be possible to spoof VRC user agent and somehow get users auth key but I havent tried that
                                            I think SARS already does that but I havent tested it for now.

                                          4. Even tho encryption is currently done client side its possible that in the future any new uploads of bundles might be encrypted upon upload either in SDK or on server after upload.
                                            Whats already unencrypted on CDN will probably stay that way because it would be very hard on servers CPUs to go and encrypt all the old content but future content is uncertian.

                                          I still gotta check if there is some sort of temp file during encryption process but Im gonna have to do that on old laptop since my main desktop is done with encryption in less than a second while old laptop I dug up freezes for a few seconds during encryption after download is done so I might try killing the game during that process

                                          devonda745D 1 Reply Last reply
                                          0

                                          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                                          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                                          With your input, this post could be even better 💗

                                          Register Login
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular