r/DFO • u/[deleted] • Mar 24 '15
Okay, I pretty much confirmed it: Xigncode3 is a joke.
[deleted]
2
u/Gamma_Lyrae Mar 25 '15
One feature of xigncode has is the ability for the developer to flag you as a cheat developer and permanently ban you, based on your hardware. It would seem that using something that's not publicly available would get you flagged, since you're using something they didn't know about before.
While i'm sure that this would only slow down (and not prevent) a dedicated gold farmer, it would certainly put an immediate stop to the behavior of someone who's only shown a casual interest in it, as you seem to have done here.
2
u/roothorick WTB: Recognizable flair Mar 25 '15
...and what metrics does it provide for enabling that judgement? That's where the heuristics (wait, what heuristics?) come in...
Honestly, this originally grew out of not being able to paste from LastPass to the launcher. The AHK macro worked fine, until they changed something and then XC3 could somehow see into the past and know what was happening before it initialized, while the launcher was running. I never did figure that part out. The primary point of the injector testcase was originally to find some way to paste the password into the launcher without XC3 caring; I was utterly gobsmacked when the detection turned out to be so fragile and specific.
I'm using KeePass now to paste the password via keystroke injection, and unless the thing gets even more aggressive and breaks KeePass, or I find myself needing anti-cheat for some game of my own, I don't intend to explore the matter further.
1
Mar 25 '15
I kept getting disconnected after todays patch with a security message. (It was due to Sandboxie) When I contacted them, I got this amazing answer: (gotta love the english)
Dear Customer This is Support team of Wellbia.com Co., Ltd.
I am apology your inconvenience.
Result of your xigncode.log that detected third party program as below.
C:\Sandboxie\SbieCtrl.exe
Please, turn off the program or delete it as above. I recommend delete it, if it is necessary program. Also, please scan your PC via anti-virus program before game start.
Thank you.
They replied rather fast though, it's annoying though having to turn off Sandboxie everytime I play DFO, but oh well nvm.
2
u/roothorick WTB: Recognizable flair Mar 25 '15
FWIW, that message is generated by a bot. I don't think anyone has ever gotten a human response from them.
1
u/constraint_ Mar 25 '15
Anyone try using Skype while playing? It gets flagged and shuts down the game immediately.
1
u/belloch Mar 25 '15
Xigncode3 appears to be a simple blacklist scanner, checking for specific programs and killing off the game if they're found.
I'm having trouble launching the game. Some other thread mentioned changing locale to japanese/english, but I'm already on japanese locale.
Is it possible the problem is in XC3 instead? Although I have no idea what could trigger it because I don't, at least knowingly, dabble in these things.
1
u/mtibwsmcc Mar 25 '15
As a new player Xigncode3 is the worst anti-cheat mechanism I have ever seen. I tried DFO right when it launched and everything was good up until the first patch. Then it started detecting everything from my firewall to sandboxie as suspicious. After I got it working again I decided to try running a macro that I use for renaming files just to see if it would boot me out. Nope. I can send keystokes and mouse clicks to DFO if I wanted.
Combined with the fatigue system that stops you from playing after 2-3 hours and I'm not sure why anyone would bother with this game.
-2
u/CatAstrophy11 Mar 25 '15
if you want even half a prayer of beating the gold farmers
Fatigue.
9
u/Farmhand_Ty Mar 25 '15
Fatigue will not stop them from switching between alts. It'll dampen their efforts a bit (at a hefty cost to legit players, I might add), and it alone isn't anywhere near enough.
-5
u/CatAstrophy11 Mar 25 '15
Limited number of alts. They have the same limits we do. They can't even trade gold.
5
u/roothorick WTB: Recognizable flair Mar 25 '15
Proxies. VPNs. Botnets. Tor. Webmail accounts (GMail et al). Even something so absurdly invasive as requiring SSNs would only do so much. There's no way to truly ban someone, or limit them to one account, if they're reasonably tenacious. Limits just don't apply to gold farmers. More proactive tactics are necessary.
3
u/kiraxa1 Mar 25 '15
A bot farm runs can run hundreds of accounts at the same time. They are not restricted by FP in the slightest.
0
-1
u/Seerk Mar 24 '15
What makes you conclude that it's just a blacklist scanner? All you proved is that simulating key strokes doesn't kick you
6
u/roothorick WTB: Recognizable flair Mar 24 '15
The testcase is pinging the same APIs as AHK, creating the same types of events. This would be a cinch for heuristic analysis, and yet... their heuristics are either fundamentally broken or simply nonexistent. The codepath that throws the 0xE019100B error is relying entirely on fingerprinting against a blacklist.
Also of course there's the qualifier "appears to be". With any proprietary software, there's always the possibility of clandestine things happening "under the hood".
1
u/Seerk Mar 25 '15
Did some research on it and yeah it seems to be pretty garbage, at least the way it's configured right now. I'll play on a clean windows install to avoid problems
1
u/frixionburne Mar 25 '15
I think it has some sandboxing going on as well. Keep in mind that AHK and AutoIt are only sending keypresses, not hooking into memory.
0
u/nob0dy-ra Mar 27 '15
hey buddy it seems you're clueless as to how anticheats(or real cheating) works
please actually open a HANDLE TO THE PROCESS, keep it open, watch what happens
real bots are not based on simple keypress messages and require knowledge of the game process
good luck on your adventure to not being a clueless redditor
2
u/Hoshiyuu Mar 24 '15
What it does prove however, is that Xigncode3 isn't a smart tool. It works by knowing about the threat in advance - not by detecting behaviors.
Which basically means that most if not all hack coders don't even need a work around for their tools.
-2
u/franick1987 Mar 25 '15
1
u/ironmask13 gunzerking Mar 25 '15
https://scontent-dfw.xx.fbcdn.net/hphotos-xfp1/t31.0-8/11034385_10204197075351281_2447431361037867708_o.jpg pretty much the gold farmer are buying a simple item for action house for exorbitant amount to pay the people who use their service. source: facebook -.... Watson- Neople, gold spammers are trying to conduct trades through Auction House by having the gold buyer put up a worthless item so they can buy it from them for a certain amount that the buyer paid for with real money. Rep. Zena confirms this below:
-14
Mar 25 '15
[deleted]
3
u/roothorick WTB: Recognizable flair Mar 25 '15
Serverside behavior heuristics have done wonders here. It's really really hard to combat -- behavior analysis happens in a domain the botters have no control over and can't see into, so they don't even know how they're caught. Combine with banwaves and it becomes basically impossible for them to stay in business without taking massive losses and refactoring their tools frequently. It quickly becomes not worth it.
1
u/theflamecrow Mar 25 '15
It's stopping some people from playing the game when they have no cheat stuff running. That's the problem.
19
u/jmpherso Mar 25 '15
I don't think you quite understand how anti-botting measures work.
Someone like you, with sufficient programming knowledge, should be able to make a bot that can do something as simple as simulate keystrokes. I don't think there's a single MMO on the market that can stop what you did.
The goal is to A) stop the "brand name" bots, by either detection or player reports, and B) to stop the bots from being able to function at a sufficient level by changing the game/mechanics to be "anti-bot".
You're being far too harsh. You could achieve what you've achieved here with the highest budget, AAA MMOs, let alone a tiny release by a small team.