I made a tool to scrape Roblox backdoors...

Поделиться
HTML-код
  • Опубликовано: 10 янв 2025

Комментарии •

  • @Sonickirbystar
    @Sonickirbystar 11 часов назад +22

    Roblox a muti-billion dollar company who blantly refuses to improve their horrid moderation. Meanwhile moderation tools made by their OWN community which can detect inappropriate users, accessories, shirts, group, backdoors (like this), and more which does 100% better then Roblox's OWN moderation.

    • @Hoofer
      @Hoofer  11 часов назад +8

      This tool isn't fullproof, it requires me to look and verify that they are indeed malicious. It would be much harder for Roblox to implement this in a way that would not false positive. I think this will improve over time.

    • @davidkra230
      @davidkra230 10 часов назад +3

      you gotta understand that roblox is indeed trying, and it is working,
      if you put a code highlighter into a modulescript, and then upload it, you get an instant ban.

    • @cosmic7140
      @cosmic7140 5 часов назад

      @@Hoofer yeah

    • @Sonickirbystar
      @Sonickirbystar 2 часа назад

      @@Hoofer I agree and what should happen is this tool be NOT be relied on 100% with moderating assets uploaded to the marketplace. A tool can help "flag" sus models detected by the tool, but a human reviewer should be the one to click the ban button.

  • @vaskerino
    @vaskerino 2 часа назад +1

    it definitely goes so deep... impressive tbf
    you gained a sub btw

  • @atuux
    @atuux 10 часов назад +5

    Dude, I wish I had something like this for games. Having to constantly search require, getfenv, etc especially with games that have to require modules it gets very time consuming and is a lot of hassle. I think more people should start to learn how to build and script on their own as in my opinion lua is quite easy to understand! Keep up the awesome work dude, you're teaching me things I either forgot about or am just learning now!!!

    • @NaraSherko
      @NaraSherko 9 часов назад

      I just print the name of the modulein in joints service thats how i found out

    • @atuux
      @atuux 8 часов назад

      @@NaraSherko I just press Ctrl+Shift+F and just search for require or getfenv, its so horribly tedious.

  • @ScriptiqueOfficial
    @ScriptiqueOfficial 8 часов назад +3

    awesome that you did this man, also trying to delete the webhook was smart and you've definetly earned respect for it bro

  • @World7Goalkeeping
    @World7Goalkeeping 10 часов назад +4

    i manage the largest serverside in the community and i just find it hilarious how you have easily just cracked nova like that, they're our like only competition, i'd like to see you attempt to crack luna though

    • @yqqy
      @yqqy 6 часов назад

      do you have a server?

  • @jorm6969
    @jorm6969 10 часов назад +1

    ur last 2 videos are so cool man, keep it up

  • @aperture59
    @aperture59 9 часов назад +1

    you've just earned another sub, never seen someone do this before

  • @JayP016
    @JayP016 4 часа назад

    This guy deserves million subscribers, what a great work!

  • @ogcnlitfvmlhf
    @ogcnlitfvmlhf 12 часов назад

    I subscribed to you because of Oaklands but these videos keep getting recommended to me. Love it

  • @justDarian
    @justDarian 11 часов назад

    man this is actually cool, i was amazed on how easily you dumped that script too

  • @bigtoony225
    @bigtoony225 8 часов назад

    nice one on getting this backdoor, i chose a random roblox backdoor model made by the same people who made that ui (that are impersonating roblox as a fake account) and did exactly what you did

  • @Fl0py
    @Fl0py 11 часов назад +1

    As someone who know c sharp and roblox lua this is amazing good work :)

  • @Czarlo
    @Czarlo 10 часов назад +2

    hoofer please stop scratching my backdoor I can't even get a singular moment of rest because of you

  • @Kars._spdr
    @Kars._spdr 6 часов назад

    I appreciate your work

  • @ENTERNALV01D
    @ENTERNALV01D 10 часов назад +3

    6:33 LMAO THAT IS THE MOST FAKEST SH## IV EVER SEEN AND THE FUNNIEST

  • @WaaaYoutube
    @WaaaYoutube 7 часов назад

    you should get hired by roblox

  • @drax6108
    @drax6108 6 часов назад

    is this public? please make this public, it doesnt need to look fancy, its so good as it is right now. im not sure if you have heard of termers? they exist since roblox was obligated to push out the DSA Report Form. they are basically people reporting illegal content on roblox and terminating it, hence the term "terming". it is known to be way more effective as roblox employees have to finish these requests of in a given timeline after EU policy, thats why reporting through the DSA Report form is deemed so much more effective than through any other means. Right now mostly people who spreaded bypassed clothing or who wore bypassed clothing are being terminated. but with a tool like this the community could expand to terming illegal backdoors.

    • @Hoofer
      @Hoofer  5 часов назад +1

      I'll release the source code & binary once I fix some of the issues with it.

  • @мемныйтелик
    @мемныйтелик 10 часов назад

    thats crazy. roblox moderation needs that. im subscribing

    • @nicki8731
      @nicki8731 9 часов назад

      they no doubt have their own tool, and probably more sophisticated :D

    • @popbottoms
      @popbottoms 9 часов назад

      They already have a system for ai that does this, and this scanner isnt exactly always correct, Stuff like HD Admin, or ANYTHING that calls require will flag it, and also u can just bypass this with getfenv

    • @Hoofer
      @Hoofer  8 часов назад

      @@popbottoms I added detection for getfenv a bit ago and haven't gotten any hits. It seems like people avoid it, likely due to AI detections?

    • @popbottoms
      @popbottoms 7 часов назад

      @@Hoofer Most likely

    • @mountainchicken9409
      @mountainchicken9409 Час назад

      ​@@Hoofergetfenv is fully banned while require can be used in some cases

  • @saugadude
    @saugadude 43 минуты назад

    this is when skids want to backdoor famous games but a huge developer stops them even tho they obfuscated stuff

  • @keepyoursockson
    @keepyoursockson 12 часов назад +1

    Why is this guy so handsome

  • @vndz-Hack
    @vndz-Hack 11 часов назад

    Amazing work

  • @rudydev4046
    @rudydev4046 10 часов назад

    Woah, you are underrated

  • @egghaed
    @egghaed 4 часа назад

    waiting for the cure for cancer...

  • @RealCookedSteak
    @RealCookedSteak 9 часов назад

    Alr no, actually now im sleeping with this, I swear this is asmr

    • @-eternal
      @-eternal 9 часов назад

      DUDE THATS WHAT IVE BEEN SAYING

    • @RealCookedSteak
      @RealCookedSteak 9 часов назад

      @@-eternal BROOO XD

  • @𤙵
    @𤙵 10 часов назад

    if not you, i didnt know i have that kind of backdoor inside my own game, it was inside fake bloxycola that my friend added, thanks. it was using the fake 429 error

    • @Hoofer
      @Hoofer  10 часов назад

      Happy to hear that you were able to remove it!

  • @Ruich
    @Ruich 8 часов назад

    At 11:00 how can you tell where and what to print out to dump all the constants?

    • @Hoofer
      @Hoofer  5 часов назад

      I cheated by learning from another tutorial that 0.6.0 of that obfuscator is vulnerable there, I just search for ~=0 and find where that definition is. The latest version does some sort of xor on the constants so I have to do another method to view how it does things.

  • @cyalata
    @cyalata 4 часа назад

    How are you downloading the models, Is this a beta thing or a extension you use?

    • @Hoofer
      @Hoofer  Час назад

      It's BTRoblox, an extension, but you can also use an API endpoint to download them.

  • @NoobapRBLX
    @NoobapRBLX 11 часов назад

    what browser do you use, also these backdoors are insanely elaborate- but I might just not know anything.

    • @Hoofer
      @Hoofer  11 часов назад

      librewolf, it's a fork of Firefox!

    • @-eternal
      @-eternal 9 часов назад

      ​@@HooferWHY DO WE USE THE SAME PROGRAMS

  • @jadedxQnabos
    @jadedxQnabos 11 часов назад

    actually insane

  • @-eternal
    @-eternal 9 часов назад

    so when is the hoofer vtuber unveiling

  • @-eternal
    @-eternal 9 часов назад

    lol this video is gonna go wild just watch

  • @Pervenire
    @Pervenire 8 часов назад

    How do you make your Roblox Studio look like that?

    • @Hoofer
      @Hoofer  5 часов назад

      My studio icons are Vanilla by Elttob

  • @ADZURE
    @ADZURE 10 часов назад

    all that just to get admin in some random persons game who uses toolbox assets????

  • @babusgah
    @babusgah 9 часов назад

    Yo bro can u drop the source code of the backdoor scrapper it’s so cool and I wanna know how to scan for strings in models like that

    • @Hoofer
      @Hoofer  9 часов назад

      There's some issues I have to work out first!

    • @babusgah
      @babusgah 9 часов назад

      @@Hooferwhat’s the issue?

  • @bruhmoment3206
    @bruhmoment3206 10 часов назад

    you can do this but roblox cant automatically flag them upon upload? maybe they should spend less time making the worst AI products i've seen and listen to the community 🤔

  • @phoenixmai.n
    @phoenixmai.n 8 часов назад

    what visual studio code theme?

    • @Hoofer
      @Hoofer  8 часов назад

      marketplace.visualstudio.com/items?itemName=atomiks.moonlight
      atomiks.moonlight

    • @phoenixmai.n
      @phoenixmai.n 8 часов назад

      @@Hoofer Thanks!

  • @epoctustwo
    @epoctustwo 11 часов назад

    i never knew that the C language can detect lua code??

    • @vndz-Hack
      @vndz-Hack 11 часов назад

      just checking strings ig lol, anything that matches 'require'

    • @bruhmoment3206
      @bruhmoment3206 10 часов назад

      well just about any programming language could detect any other language its just string operations

  • @Ultralgae
    @Ultralgae 6 часов назад

    🚪

  • @Kechiph23
    @Kechiph23 10 часов назад +1

    Le' Epic

  • @RandomytchannelGD
    @RandomytchannelGD 10 часов назад

    Hi

  • @fireremix8
    @fireremix8 11 часов назад

    Do you know what those lines with random text and numbers are? (Mostly letters)
    Example:
    pqiepwbjfoevjzpkwpqsowodjeiwkdjsjfkwlpqbwufkqpwjoejieowjdqjqosvjf
    Like are they ciphered or something or are they just there to hide code?
    Also will you make a tutorial on how to make such a tool? Seems very useful even though you need to verify if it's malicious, it's good workflow.
    Great content as always, I like how you show what you think and how you come to work on finding these malicious contents.

    • @cosmic7140
      @cosmic7140 10 часов назад

      it's encrypted, if you see ANY script with it, it's 99.999999999% a virus.

    • @Hoofer
      @Hoofer  10 часов назад

      The random lines are either obfuscated code, or the VM executed code. All of it is just obfuscated code, they do it to hide themselves, but it's not very hard to figure it out.
      As for the tool, it's not very helpful outside of scanning public assets to look for them. I wouldn't rely on it to check resources. Personally, I recommend not using models that contain scripts. I'd rather write my own scripts for the models. It's the safest way.

    • @fireremix8
      @fireremix8 10 часов назад

      ​@@HooferAhhh ok I understand it now thank you. Yeah I am working on a duo project and we told ourselves to only use our own models, scripts and assets in general. But in case certain parts that take very long to do like vfx or blender models, we thought of maybe compensating depending on the situation. In that case I saw there's a plugin called RoDefender, but comment reviews aren't very happy about it, so I suppose the likes are just given without thought.

  • @4zaa4
    @4zaa4 8 часов назад

    lmaoo i made that infect code :(