Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Zephyr)
  • No Skin
Collapse
RipperStore Logo
  1. Home
  2. Community
  3. General Discussions
  4. VRChat added VRCA (?maybe VRCW too) protection

VRChat added VRCA (?maybe VRCW too) protection

Scheduled Pinned Locked Moved General Discussions
protectionvrchatvrcaripping
156 Posts 50 Posters 10.7k Views 51 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • VisaeresV Offline
    VisaeresV Offline
    Visaeres
    Grunt
    wrote last edited by
    #118

    XDDDDDDDDDDDDDDDDDD

    1 Reply Last reply
    👰
    0
    • crystaldustieC crystaldustie

      so i went out of my way and memory dumped vrchat so if anyone want to look throw it go for it https://drive.google.com/file/d/1VsTPjzQY9LgPkNshV0nZHF6O3mmfIHsF/view

      T Offline
      T Offline
      TheFoxBig
      wrote last edited by
      #119

      @crystaldustie can this be used to rip models again ?

      1 Reply Last reply
      0
      • J Offline
        J Offline
        Jumbojaw
        wrote last edited by
        #120

        Since VRC is a DX11 game, would it be possible to use gpu buffer rippers like NinjaRipper to extract at least the mesh & textures? Or would anticheat cause problems here?

        crystaldustieC 1 Reply Last reply
        0
        • J Jumbojaw

          Since VRC is a DX11 game, would it be possible to use gpu buffer rippers like NinjaRipper to extract at least the mesh & textures? Or would anticheat cause problems here?

          crystaldustieC Offline
          crystaldustieC Offline
          crystaldustie
          Grunt Banned
          wrote last edited by
          #121

          @Jumbojaw maybe

          1 Reply Last reply
          0
          • crystaldustieC crystaldustie

            Link Preview Image
            AES-GCM and breaking it on nonce reuse

            In this post, we will look at how the security of the AES-GCM mode of operation can be completely compromised when a nonce is reused.

            favicon

            frereit's blog (frereit.de)

            crystaldustieC Offline
            crystaldustieC Offline
            crystaldustie
            Grunt Banned
            wrote last edited by
            #122

            @crystaldustie vrchat is encryted in aes gcm

            1 Reply Last reply
            0
            • crystaldustieC crystaldustie

              so i went out of my way and memory dumped vrchat so if anyone want to look throw it go for it https://drive.google.com/file/d/1VsTPjzQY9LgPkNshV0nZHF6O3mmfIHsF/view

              ReymR Offline
              ReymR Offline
              Reym
              wrote last edited by
              #123

              @crystaldustie how you do memory dump? there is a part i want to check

              I'm bad at understanding english word

              I fix .vrca stuff for free and for fun! Depending on file, every outcome and vary might be different than the original avatar has due to the toggles and much more, send me a pm if you need an avi that i can ripp (public avatar only, private still risky, unless you have the cache of those avatar you can send them over for request for fix) and fix for you or cracking a password locked avatar or send me .vrca file or vrchat avatar link through my pms!

              VRCHAT HAS ADDED SORT OF PROTECTION ON __DATA (aka .vrca or .vrcw) FILE, EVERY FUTURE REQUEST IS CLOSED UNTIL ALTERNATIVE PROGRAM FOR EXTRACTING FILE OUT IS MADE

              crystaldustieC 1 Reply Last reply
              0
              • ReymR Reym

                @crystaldustie how you do memory dump? there is a part i want to check

                crystaldustieC Offline
                crystaldustieC Offline
                crystaldustie
                Grunt Banned
                wrote last edited by
                #124

                @Reym run vrchat without eac

                ReymR 1 Reply Last reply
                0
                • crystaldustieC Offline
                  crystaldustieC Offline
                  crystaldustie
                  Grunt Banned
                  wrote last edited by
                  #125

                  and use process hacker

                  1 Reply Last reply
                  0
                  • crystaldustieC crystaldustie

                    so i went out of my way and memory dumped vrchat so if anyone want to look throw it go for it https://drive.google.com/file/d/1VsTPjzQY9LgPkNshV0nZHF6O3mmfIHsF/view

                    StinkerGuy115S Offline
                    StinkerGuy115S Offline
                    StinkerGuy115
                    wrote last edited by
                    #126

                    @crystaldustie pretty cool, lotta data to shift through and sort. Put that bad boy in a hex editor and type "avtr" lmao. Or throw it into WinDbg.

                    Oh yea thought I'd share this, VRChat creates a __data file in C:\Users\username\AppData\LocalLow\Unity\Temp\

                    It's an avatar data file. VRChat creates it and instantly deletes it. I set permissions to not allow VRChat to delete files in that folder in hopes it might be some sorta briefly made unencrypted data file, I genuinely believe the VRChat devs would be that lazy to do something like this lol. Unfortunately file is still encrypted, though it's essential to loading the avatar.

                    Disable VRChat's access to the folder and the avatar throws an error bot.

                    1 Reply Last reply
                    1
                    • crystaldustieC crystaldustie

                      @Reym run vrchat without eac

                      ReymR Offline
                      ReymR Offline
                      Reym
                      wrote last edited by
                      #127

                      @crystaldustie sounds risky, do i just task kill eac as the game starts?

                      I'm bad at understanding english word

                      I fix .vrca stuff for free and for fun! Depending on file, every outcome and vary might be different than the original avatar has due to the toggles and much more, send me a pm if you need an avi that i can ripp (public avatar only, private still risky, unless you have the cache of those avatar you can send them over for request for fix) and fix for you or cracking a password locked avatar or send me .vrca file or vrchat avatar link through my pms!

                      VRCHAT HAS ADDED SORT OF PROTECTION ON __DATA (aka .vrca or .vrcw) FILE, EVERY FUTURE REQUEST IS CLOSED UNTIL ALTERNATIVE PROGRAM FOR EXTRACTING FILE OUT IS MADE

                      crystaldustieC 1 Reply Last reply
                      0
                      • ReymR Reym

                        @crystaldustie sounds risky, do i just task kill eac as the game starts?

                        crystaldustieC Offline
                        crystaldustieC Offline
                        crystaldustie
                        Grunt Banned
                        wrote last edited by
                        #128

                        @Reym u need to just go to vrchat main exe that is in a steam folder and launch that

                        Dr.beepD 1 Reply Last reply
                        👍
                        0
                        • crystaldustieC crystaldustie

                          @Reym u need to just go to vrchat main exe that is in a steam folder and launch that

                          Dr.beepD Offline
                          Dr.beepD Offline
                          Dr.beep
                          wrote last edited by
                          #129

                          @crystaldustie
                          That version of the game isn't very useful because from a server side perspective it doesn't even give the ok to download models that aren't yours, I guess it's ok if you need to rip models that are yours , but I checked the network traffic for this and it doesn't actually send data that isn't yours

                          Currently investigating ways to bypass VRC's new encryption on VRCA's and VRCW's. Msg me if you have any leads

                          1 Reply Last reply
                          0
                          • StinkerGuy115S Offline
                            StinkerGuy115S Offline
                            StinkerGuy115
                            wrote last edited by
                            #130

                            @Reym @crystaldustie @Dr.beep not sure if it is useful but you can still kill the EAC process post launch. still download models, go to public worlds and such. though im sure theres some background service running, however I tried poking around with Process Explorer and didnt see anything related to EAC running.

                            But I dont think this is useful as injections need to happen pre-launch unless someone has anything they can go off of with this?

                            1 Reply Last reply
                            0
                            • glen-G Offline
                              glen-G Offline
                              glen-
                              wrote last edited by
                              #131

                              Is it possible to rip worlds from ChillOutVR? Just curious.

                              1 Reply Last reply
                              0
                              • StinkerGuy115S Offline
                                StinkerGuy115S Offline
                                StinkerGuy115
                                wrote last edited by CodeAngel
                                #132

                                Did anyone else see this? Lmao
                                [REMOVED BY ADMIN]

                                DeepDishBussyD E 2 Replies Last reply
                                0
                                • StinkerGuy115S StinkerGuy115

                                  Did anyone else see this? Lmao
                                  [REMOVED BY ADMIN]

                                  DeepDishBussyD Offline
                                  DeepDishBussyD Offline
                                  DeepDishBussy
                                  wrote last edited by
                                  #133

                                  @StinkerGuy115 lmao what is that 😲

                                  DM me if any of my links go down or if there's an update you need.

                                  StinkerGuy115S 1 Reply Last reply
                                  0
                                  • DeepDishBussyD DeepDishBussy

                                    @StinkerGuy115 lmao what is that 😲

                                    StinkerGuy115S Offline
                                    StinkerGuy115S Offline
                                    StinkerGuy115
                                    wrote last edited by
                                    #134

                                    @DeepDishBussy No idea some dude ig showing that they can still rip models post encryption patch. Was poking around google and came across it.

                                    1 Reply Last reply
                                    0
                                    • DeepDishBussyD Offline
                                      DeepDishBussyD Offline
                                      DeepDishBussy
                                      wrote last edited by
                                      #135

                                      I think the video may have been satirical based on the description

                                      DM me if any of my links go down or if there's an update you need.

                                      StinkerGuy115S 1 Reply Last reply
                                      👍
                                      1
                                      • DeepDishBussyD DeepDishBussy

                                        I think the video may have been satirical based on the description

                                        StinkerGuy115S Offline
                                        StinkerGuy115S Offline
                                        StinkerGuy115
                                        wrote last edited by
                                        #136

                                        @DeepDishBussy Honestly I agree, like some edgelord posting their clips of them using a client.

                                        Been really interested in this whole thing myself. I ran wireshark with procmon and compared them to the Output log txt file in the LocalLow folder for VRChat so i can get time stamps of what happens.

                                        There are several servers VRChat communicates with for like authentication. From what it looks like, it seems it just kinda is reading and confirming with a server as it's downloading the files. You find that it repeatedly is checking with a server while it is reading from the __data file.

                                        I did a TCP stream follow of one of the addresses it was communicating with and I saw it initializes by communicating with a "photonengine.io" then it goes to a site called "http://www.digicert.com" and another one by the domain of rapidssl.com

                                        VRChat also around this phase is repeatedly interacting with the PhotoEncryptorPlugin.dll while reading from the __data files in the cache folder. I dont know if any of this is user authentication or actual encryption of the files themself. Can reverse engineer the dll with Ghidra, or just pop it into a hex editor lol.

                                        1 Reply Last reply
                                        0
                                        • VisaeresV Offline
                                          VisaeresV Offline
                                          Visaeres
                                          Grunt
                                          wrote last edited by
                                          #137

                                          The desperation from you guys is hilarious lmfao

                                          StinkerGuy115S 1 Reply Last reply
                                          👍
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • Users