Popular Post Alek Posted June 18, 2017 Popular Post Share Posted June 18, 2017 (edited) Preventing RS Botting Bans V3Written by Alek 1. Introduction This guide is Version 3 of my original guide released 4 years ago. I decided to focus more on commonly asked questions and general misconceptions about botting. Many of the topics are very technical and there are brilliant engineers who both bust bots and create them. The majority of botters who come here have little to no programming experience, or very little knowledge in subject areas such as reverse engineering. It’s very difficult to fully explain all key concepts, however hopefully this material will give you a base reference to draw your own conclusions.2. How to not get banned The secret formula to botting is keeping a very, very, low profile. This game has been around for 15+ years, that is a TON of data to play with. Generally speaking: -Don’t bot more than 4 hours per day -Don’t bot more than 10 hours per week -Diversify your tasks -Don’t use a VPN/VPS/proxy -Don’t bot more than one account -Do quests -Don’t RWT/goldfarm -Don’t bot in hot spots, use places like Zeah You’re going to have a ton of people say, “oh I suicided for 11 years straight, never logged out, I make $500k/year”, etc. They simply don’t. Either they haven’t botted long enough or their claims are baseless. If you want to keep your account relatively safe then don’t bot longer than the times I recommended above. Time played is a key factor into profiling a bot, it’s been even talked about on official livestreams during live bot busting events.3. Misconceptions The biggest misconception is that the company doesn’t have any automatic detection systems. Although the detection vectors improve over the years, there are official statements claiming that all bans are manually reviewed before being issued. THIS DOES NOT MEAN ACCOUNTS ARE NOT AUTOMATICALLY FLAGGED. Common situation: Suicide bot on the weekend without getting banned, account gets a ban on the following Monday or Tuesday. This is because your account was probably flagged over the weekend, then eventually reviewed for the final determination on the following business days. Another misconception is that if you “survived the weekend”, then you are safe. This is certainly not true, most anticheat will "flag and monitor". This means that you were in fact detected but the anticheat is watching your actions very closely to grab more information about what you are doing. Information from these monitoring sessions are used to quickly detect and ban in the future. For Runescape, one example is the use of bot worlds. Another non-Runescape example is Valve-AntiCheat profiling numerous hacks over the course of months and then issue behemoth ban waves all at once for games like Counter-Strike. 4. Antiban/Antipattern Scripters who include antiban/antipattern methods in their scripts are either naive, new scripters, or are trying to earn more sales by making false promises. Competitor clients further this perpetuation by forcing script writers to implement these methods. It’s a gimmick and overall you’re going to get banned whether you use these "special methods" or not. Some of these “special” (aka worthless) methods are: -Moving your mouse randomly -Checking your exp -Examining random objects -Moving your camera angle randomly -Implementing “fatigue” systems -Diversifying the way you interact with objects One of the special methods I’d like to talk about which was not listed above was randomizing sleep time between actions. This is especially special because there are numerous flaws with it. 1. Your computer doesn’t perfectly execute actions in the same time every time 2. Your script doesn’t perfectly loop in the same time every time 3. Your ping fluctuates causing a delay between the client and server 4. If the top three all remained constant, you could find the upper and lower bounds of the mean and use statistics to recreate the sleep time. Anti-pattern is a bit different, but a lot of scripters have been wrongly claiming their script having “antipattern” when they’re really using the same “special methods”. Examples of antipattern: - Talking to other players (Cleverbot) - Mixing up tasks (perhaps after accumulating X gold, go to the Grand Exchange and sell)The goal of anti-pattern is to reduce the chances of being manually reported by other players for botting. Although “antipattern” is more desirable than “antiban”, there is still no definitive proof of the impact it has in the total picture.5. Client detection 5A. I’m going to keep this relatively brief because this is probably the most technical aspect of this guide. There is an overarching debate over Injection vs Reflection and it’s pretty silly. Both are detectable because both have different ways you can detect it. In the non-Java hacking world, this would be equivalent to something like ReadProcessMemory versus LoadLibrary. To better put it, reading memory from outside the process versus inside. There are ways to hide it, ways to find it, ways to hide against the ways to find it, and ways to find the ways how to hide it against from finding it. As you can see, it’s really cat and mouse and it boils down to implementation. 5B. Additionally, you can be detected for macroing without even using a client. You can banned for using Gary's Hood or AutoHotKey. Both of these use some sort of Windows API function like SendInput, from protected mode. This is how color-bots also get detected without injecting/reflecting the client. 5C. Mirror Mode adds some protection to users where the normal OSBot client can be detected. Think of mirror-mode as a safety catch rather than a comprehensive antiban measure; and yes mirror mode has genuinely protected users at least on one confirmed occasion. In summary, you will still get banned because mirror-mode only protects you from one aspect of botting and there are potentially hundreds of detection vectors. 6. Conclusion and final remarks Having good botting habits like I outlined in section two, and having a good script which is reliable and not prone to getting baited (locked behind doors, etc), is your safest bet. There are people who do “studies” and “research” but ultimately their results are inconclusive, non-definitive, and certainly only proves a correlation and not causation. There are too many variables to isolate to make any data worthwhile; ip address, computer, scripts, clients, botting locations, skills, account time, bot time, quests, RWT, java exceptions, client detection, the list goes on and on. Too many variables to isolate, too much that we cannot prove. The bottom-line is that the only people who know specifics about the anticheat system are the anticheat developers. Edited December 29, 2018 by Alek 68 2 5 Quote Link to comment Share on other sites More sharing options...
HeyImJamie Posted June 18, 2017 Share Posted June 18, 2017 10 Hours per week 20 19 Quote Link to comment Share on other sites More sharing options...
Santonio Posted June 18, 2017 Share Posted June 18, 2017 Love bro Quote Link to comment Share on other sites More sharing options...
Fruity Posted June 18, 2017 Share Posted June 18, 2017 hmmmmms, not sure if its worth reading and ending up being a troll 1 Quote Link to comment Share on other sites More sharing options...
Alek Posted June 18, 2017 Author Share Posted June 18, 2017 Just now, Fruity said: hmmmmms, not sure if its worth reading and ending up being a troll It isn't April first. Quote Link to comment Share on other sites More sharing options...
Mainio Posted June 18, 2017 Share Posted June 18, 2017 Freshing up the memory again, thanks! I think everyone on this community should read this, word to word. 1 Quote Link to comment Share on other sites More sharing options...
Acerd Posted June 18, 2017 Share Posted June 18, 2017 bababoey 3 Quote Link to comment Share on other sites More sharing options...
Eliot Posted June 18, 2017 Share Posted June 18, 2017 Notice "How to not get banned" basically makes botting worthless. The key to botting is to accept that you will get banned and maximize profit before it happens. 24 Quote Link to comment Share on other sites More sharing options...
Savvir Posted June 18, 2017 Share Posted June 18, 2017 Thanks for the update! I've also found that there really was no difference between ban rates botting via injection or reflection. I would also say from the accounts that I've botted so far to keep your tasks cycled every few hours or so. Mixing up the tasks has really kept my accounts alive far longer. 3 Quote Link to comment Share on other sites More sharing options...
Alek Posted June 18, 2017 Author Share Posted June 18, 2017 2 minutes ago, Eliot said: Notice "How to not get banned" basically makes botting worthless. The key to botting is to accept that you will get banned and maximize profit before it happens. Definitely not good for farms, at some point farms will certainly get banned while you could probably slowly build up a maxed main over the course of a couple years. 4 Quote Link to comment Share on other sites More sharing options...
Fearsy Posted June 18, 2017 Share Posted June 18, 2017 Some good information, thanks 1 Quote Link to comment Share on other sites More sharing options...
Codiene Posted June 18, 2017 Share Posted June 18, 2017 Goodpost, thx. 2 Quote Link to comment Share on other sites More sharing options...
Botre Posted June 18, 2017 Share Posted June 18, 2017 10 hours a week ew 1 Quote Link to comment Share on other sites More sharing options...
Kissy Posted June 18, 2017 Share Posted June 18, 2017 (edited) Ty Alek [ Edited June 18, 2017 by Kissy 1 Quote Link to comment Share on other sites More sharing options...
ProjectPact Posted June 18, 2017 Share Posted June 18, 2017 If this is all true Alek, then explain why @Tom has the best antiban the world has ever seen. 5 Quote Link to comment Share on other sites More sharing options...