Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Zephyr)
  • No Skin
Collapse
RipperStore Logo
  1. Home
  2. Community
  3. General Discussions
  4. VRChat added VRCA (?maybe VRCW too) protection

VRChat added VRCA (?maybe VRCW too) protection

Scheduled Pinned Locked Moved General Discussions
protectionvrchatvrcaripping
142 Posts 47 Posters 9.6k Views 46 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • crystaldustieC Offline
    crystaldustieC Offline
    crystaldustie
    Grunt
    wrote last edited by
    #117

    so i went out of my way and memory dumped vrchat so if anyone want to look throw it go for it https://drive.google.com/file/d/1VsTPjzQY9LgPkNshV0nZHF6O3mmfIHsF/view

    T ReymR StinkerGuy115S 3 Replies Last reply
    👍
    1
    • VisaeresV Offline
      VisaeresV Offline
      Visaeres
      Grunt
      wrote last edited by
      #118

      XDDDDDDDDDDDDDDDDDD

      1 Reply Last reply
      👰
      0
      • crystaldustieC crystaldustie

        so i went out of my way and memory dumped vrchat so if anyone want to look throw it go for it https://drive.google.com/file/d/1VsTPjzQY9LgPkNshV0nZHF6O3mmfIHsF/view

        T Offline
        T Offline
        TheFoxBig
        wrote last edited by
        #119

        @crystaldustie can this be used to rip models again ?

        1 Reply Last reply
        0
        • J Offline
          J Offline
          Jumbojaw
          wrote last edited by
          #120

          Since VRC is a DX11 game, would it be possible to use gpu buffer rippers like NinjaRipper to extract at least the mesh & textures? Or would anticheat cause problems here?

          crystaldustieC 1 Reply Last reply
          0
          • J Jumbojaw

            Since VRC is a DX11 game, would it be possible to use gpu buffer rippers like NinjaRipper to extract at least the mesh & textures? Or would anticheat cause problems here?

            crystaldustieC Offline
            crystaldustieC Offline
            crystaldustie
            Grunt
            wrote last edited by
            #121

            @Jumbojaw maybe

            1 Reply Last reply
            0
            • crystaldustieC crystaldustie

              Link Preview Image
              AES-GCM and breaking it on nonce reuse

              In this post, we will look at how the security of the AES-GCM mode of operation can be completely compromised when a nonce is reused.

              favicon

              frereit's blog (frereit.de)

              crystaldustieC Offline
              crystaldustieC Offline
              crystaldustie
              Grunt
              wrote last edited by
              #122

              @crystaldustie vrchat is encryted in aes gcm

              1 Reply Last reply
              0
              • crystaldustieC crystaldustie

                so i went out of my way and memory dumped vrchat so if anyone want to look throw it go for it https://drive.google.com/file/d/1VsTPjzQY9LgPkNshV0nZHF6O3mmfIHsF/view

                ReymR Offline
                ReymR Offline
                Reym
                wrote last edited by
                #123

                @crystaldustie how you do memory dump? there is a part i want to check

                I'm bad at understanding english word

                I fix .vrca stuff for free and for fun! Depending on file, every outcome and vary might be different than the original avatar has due to the toggles and much more, send me a pm if you need an avi that i can ripp (public avatar only, private still risky, unless you have the cache of those avatar you can send them over for request for fix) and fix for you or cracking a password locked avatar or send me .vrca file or vrchat avatar link through my pms!

                VRCHAT HAS ADDED SORT OF PROTECTION ON __DATA (aka .vrca or .vrcw) FILE, EVERY FUTURE REQUEST IS CLOSED UNTIL ALTERNATIVE PROGRAM FOR EXTRACTING FILE OUT IS MADE

                crystaldustieC 1 Reply Last reply
                0
                • ReymR Reym

                  @crystaldustie how you do memory dump? there is a part i want to check

                  crystaldustieC Offline
                  crystaldustieC Offline
                  crystaldustie
                  Grunt
                  wrote last edited by
                  #124

                  @Reym run vrchat without eac

                  ReymR 1 Reply Last reply
                  0
                  • crystaldustieC Offline
                    crystaldustieC Offline
                    crystaldustie
                    Grunt
                    wrote last edited by
                    #125

                    and use process hacker

                    1 Reply Last reply
                    0
                    • crystaldustieC crystaldustie

                      so i went out of my way and memory dumped vrchat so if anyone want to look throw it go for it https://drive.google.com/file/d/1VsTPjzQY9LgPkNshV0nZHF6O3mmfIHsF/view

                      StinkerGuy115S Offline
                      StinkerGuy115S Offline
                      StinkerGuy115
                      wrote last edited by
                      #126

                      @crystaldustie pretty cool, lotta data to shift through and sort. Put that bad boy in a hex editor and type "avtr" lmao. Or throw it into WinDbg.

                      Oh yea thought I'd share this, VRChat creates a __data file in C:\Users\username\AppData\LocalLow\Unity\Temp\

                      It's an avatar data file. VRChat creates it and instantly deletes it. I set permissions to not allow VRChat to delete files in that folder in hopes it might be some sorta briefly made unencrypted data file, I genuinely believe the VRChat devs would be that lazy to do something like this lol. Unfortunately file is still encrypted, though it's essential to loading the avatar.

                      Disable VRChat's access to the folder and the avatar throws an error bot.

                      1 Reply Last reply
                      1
                      • crystaldustieC crystaldustie

                        @Reym run vrchat without eac

                        ReymR Offline
                        ReymR Offline
                        Reym
                        wrote last edited by
                        #127

                        @crystaldustie sounds risky, do i just task kill eac as the game starts?

                        I'm bad at understanding english word

                        I fix .vrca stuff for free and for fun! Depending on file, every outcome and vary might be different than the original avatar has due to the toggles and much more, send me a pm if you need an avi that i can ripp (public avatar only, private still risky, unless you have the cache of those avatar you can send them over for request for fix) and fix for you or cracking a password locked avatar or send me .vrca file or vrchat avatar link through my pms!

                        VRCHAT HAS ADDED SORT OF PROTECTION ON __DATA (aka .vrca or .vrcw) FILE, EVERY FUTURE REQUEST IS CLOSED UNTIL ALTERNATIVE PROGRAM FOR EXTRACTING FILE OUT IS MADE

                        crystaldustieC 1 Reply Last reply
                        0
                        • ReymR Reym

                          @crystaldustie sounds risky, do i just task kill eac as the game starts?

                          crystaldustieC Offline
                          crystaldustieC Offline
                          crystaldustie
                          Grunt
                          wrote last edited by
                          #128

                          @Reym u need to just go to vrchat main exe that is in a steam folder and launch that

                          Dr.beepD 1 Reply Last reply
                          👍
                          0
                          • crystaldustieC crystaldustie

                            @Reym u need to just go to vrchat main exe that is in a steam folder and launch that

                            Dr.beepD Offline
                            Dr.beepD Offline
                            Dr.beep
                            wrote last edited by
                            #129

                            @crystaldustie
                            That version of the game isn't very useful because from a server side perspective it doesn't even give the ok to download models that aren't yours, I guess it's ok if you need to rip models that are yours , but I checked the network traffic for this and it doesn't actually send data that isn't yours

                            Currently investigating ways to bypass VRC's new encryption on VRCA's and VRCW's. Msg me if you have any leads

                            1 Reply Last reply
                            0
                            • StinkerGuy115S Offline
                              StinkerGuy115S Offline
                              StinkerGuy115
                              wrote last edited by
                              #130

                              @Reym @crystaldustie @Dr.beep not sure if it is useful but you can still kill the EAC process post launch. still download models, go to public worlds and such. though im sure theres some background service running, however I tried poking around with Process Explorer and didnt see anything related to EAC running.

                              But I dont think this is useful as injections need to happen pre-launch unless someone has anything they can go off of with this?

                              1 Reply Last reply
                              0
                              • glen-G Offline
                                glen-G Offline
                                glen-
                                wrote last edited by
                                #131

                                Is it possible to rip worlds from ChillOutVR? Just curious.

                                1 Reply Last reply
                                0
                                • StinkerGuy115S Offline
                                  StinkerGuy115S Offline
                                  StinkerGuy115
                                  wrote last edited by
                                  #132

                                  Did anyone else see this? Lmao
                                  https://youtu.be/QTq0nKzni5s?si=m4G_-t5paDo_eJtI

                                  DeepDishBussyD 1 Reply Last reply
                                  0
                                  • StinkerGuy115S StinkerGuy115

                                    Did anyone else see this? Lmao
                                    https://youtu.be/QTq0nKzni5s?si=m4G_-t5paDo_eJtI

                                    DeepDishBussyD Offline
                                    DeepDishBussyD Offline
                                    DeepDishBussy
                                    wrote last edited by
                                    #133

                                    @StinkerGuy115 lmao what is that 😲

                                    DM me if any of my links go down or if there's an update you need.

                                    StinkerGuy115S 1 Reply Last reply
                                    0
                                    • DeepDishBussyD DeepDishBussy

                                      @StinkerGuy115 lmao what is that 😲

                                      StinkerGuy115S Offline
                                      StinkerGuy115S Offline
                                      StinkerGuy115
                                      wrote last edited by
                                      #134

                                      @DeepDishBussy No idea some dude ig showing that they can still rip models post encryption patch. Was poking around google and came across it.

                                      1 Reply Last reply
                                      0
                                      • DeepDishBussyD Offline
                                        DeepDishBussyD Offline
                                        DeepDishBussy
                                        wrote last edited by
                                        #135

                                        I think the video may have been satirical based on the description

                                        DM me if any of my links go down or if there's an update you need.

                                        StinkerGuy115S 1 Reply Last reply
                                        👍
                                        1
                                        • DeepDishBussyD DeepDishBussy

                                          I think the video may have been satirical based on the description

                                          StinkerGuy115S Offline
                                          StinkerGuy115S Offline
                                          StinkerGuy115
                                          wrote last edited by
                                          #136

                                          @DeepDishBussy Honestly I agree, like some edgelord posting their clips of them using a client.

                                          Been really interested in this whole thing myself. I ran wireshark with procmon and compared them to the Output log txt file in the LocalLow folder for VRChat so i can get time stamps of what happens.

                                          There are several servers VRChat communicates with for like authentication. From what it looks like, it seems it just kinda is reading and confirming with a server as it's downloading the files. You find that it repeatedly is checking with a server while it is reading from the __data file.

                                          I did a TCP stream follow of one of the addresses it was communicating with and I saw it initializes by communicating with a "photonengine.io" then it goes to a site called "http://www.digicert.com" and another one by the domain of rapidssl.com

                                          VRChat also around this phase is repeatedly interacting with the PhotoEncryptorPlugin.dll while reading from the __data files in the cache folder. I dont know if any of this is user authentication or actual encryption of the files themself. Can reverse engineer the dll with Ghidra, or just pop it into a hex editor lol.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • Users