Mass youtube account generator

This is my first post - how would you rate it?

  • Not clear enough

  • Too much information

  • Seems good c:


Results are only viewable after voting.
I’m using VB.NET which supports multithreading, I meant whether there’s php code observing things or if I can just invoke js methods and it’ll work fine
think about moving to C# ;) vb sucks, but anyways yes you can run the js functions inside a sandbox once you have identified them. then get the value(s) and construct your final POST request.
 
think about moving to C# ;) vb sucks, but anyways yes you can run the js functions inside a sandbox once you have identified them. then get the value(s) and construct your final POST request.

VB is an easier language to understand, provides all the features I need and I’m highly experienced with it, there is no advantage over VB which is necessary for this project.

About the cookie, this is what I mean. Let’s say this is how it is.

A change is made to some data on the account creation page. This data is sent to google. An encrypted string is then sent back and stored as the GAPS cookie. Google will only accept a post request if the GAPS cookie, when decrypted, matches the data sent and if the string is in their database.

This makes it impossible as far as I’m aware with post requests alone as I would have no cookie to send the value of
 
Ooh, that’s crucial, didn’t think about that. I don’t believe websites are able to access my location but timezone perhaps.

So I’m guessing you must be directly setting the textboxes’ values. I don’t mind phone verification as I have so many numbers at my disposal, but it’s more time wasted and sometimes calls don’t come through.

I really don’t want to have to buy proxies as each one can only make very few accounts, I’ve seen. What would be convenient is if there was a way to force an ip change from your isp without changing macs and raising suspicion, for example.

If you wouldn't mind sharing part of your script, that’d be really useful to understand the approach, or at least pseudo code would give a good idea

I would really focus on optimizing the phone verification process instead of optimizing the account creation one :)
Sorry but I cannot share the script as it has been created by a friend of mine and I've just modified it in order to support proxy and user agents rotation + IP geolocation and timezone match (have to check with my friend if he agrees to share the script). But it's just a simple textboxes filler/ buttons clicker :)...nothing 'fancy' about it.

I also use whoer .net/ext to check if I have real IP/ DNS leaks (careful with flash and javascript they are huge IP and DNS leakers - but turning them off would be, in my opinion, a huge red flag for google because common users don't turn these things off - okay...not so sure about flash but I am 100% sure that common users don't even know what javascript is) and to make sure my configuration (browser, OS, plugins, fonts etc) looks real (LE: it's a long story here too because you have to match the browser with the plugins, with the fonts, with the machine, with the screen resolution etc. For example: MAC resolutions are sometimes different from PC screen resolutions, so if you use a Chrome user agent for MAC, you need to make sure you set a MAC screen resolution )

Buying proxies is not very efficient from the financial point of view., indeed..you can create 3-5 accounts max/ proxy (considering the proxy is of high-quality). Proxy pools (residential or data-center) have been abused and flagged by google (at least, this is my opinion after using 2-3 services of this type).

But, again, instead of taking care of so many variables, you should focus on optimizing the phone verification :D. Most people are spending a lot of time 'polishing' these variables because phone verification is too expensive.
 
Last edited:
And what if the fields are sent to the server, encrypted, stored and sent back? I would have to figure out how to perform that encryption. If I give the same one, it’ll see it’s already been used. Or the generated one won’t match the one I produce even though the inputs are the same due to randomisation

And what would your browser do after that?

If your browser then decrypts the encrypted data: how the decryption is done (and the key, if necessary) is in the JS code. However, I'd guess they don't do this, because it adds unnecessary computation on the client-side (making it slower) while providing no additional security benefit to Google.

A change is made to some data on the account creation page. This data is sent to google. An encrypted string is then sent back and stored as the GAPS cookie. Google will only accept a post request if the GAPS cookie, when decrypted, matches the data sent and if the string is in their database.

If it sends the same way it was received, then don't worry about decrypting it. Just take it from the "Set-Cookie" response header, and send it right back in the "Cookie:" header in your next request.
 
lol I told you guys to stay away but it seems you guys are so obsessed with these things :)
creating mass google accounts might be possible if you pour tons of your energy & resources like PVs, Residential proxies, Counter measures, etc.. certainly it's becoming far far more than a work affordable for one person. You'd need a dedicated team to do that without wasting so much time.
and suppose you made a 100k google accounts spending your money on Residential proxies for $1000, now what?? sell the accounts? :D who knows, you could age them for 1 year and sell each for $2, making you profit like $200k - 1k
but here's the nightmare comes in, google knows there account creation BG isn't perfect. So they've prepared another booby trap for you :p
now they want to watch your account activity and punish you. (remember i said "Don't touch sleeping lion?" :D)
meaning, google don't want your accounts to age for 1 year without no activity. They want to see if it's real account used by human. So you must now MAINTAIN your Residential proxies binding same city proxy for each account and do some random activities like watching Youtube, which is a total nightmare job for you guys :D
there's much more to say why pissing off google is very bad idea but i guess you guys aren't the type for being persuaded :p

Believe me, you guys are walking wrong ways not knowing what's awaiting for you at the dead-end.
You guys think you are very smart? Oh, come on! let's be very logical here. The brainpower fight (1000 Google PhD Team) VS (Just You), who do you think will win?
To OP, you seem to know nothing judging by what you saying like "I didn't know timezone, browser emulation.."
If you are SO obsessed with fooling Google and piss them off, Go ahead, no one will bother to stop you. :D Maybe there's something to learn, who knows. You could start automating other low security sites and profit but not Google.
And do watch the damn news if you don't mind. Google is experimenting human like robots in 2017 while you guys are collecting dusts :p:p:p
 
lol I told you guys to stay away but it seems you guys are so obsessed with these things :)
You referring to another thread? Can you link?

You could start automating other low security sites and profit but not Google.
Agreed. That was one of my suggestions earlier.

If you are SO obsessed with fooling Google and piss them off, Go ahead, no one will bother to stop you. :D
If we can help by pointing them in the right direction in the forum, great. If not, telling them not to do it doesn't help. After all, Google didn't develop all these countermeasures in one go; it was developed over a long back-and-forth of Google improving their system and people getting past it.

Google is experimenting human like robots in 2017 while you guys are collecting dusts :p:p:p
That's nice, but humans are pretty fucking stupid and can be tricked. This is no reason to stop trying.
 
You referring to another thread? Can you link?


Agreed. That was one of my suggestions earlier.


If we can help by pointing them in the right direction in the forum, great. If not, telling them not to do it doesn't help. After all, Google didn't develop all these countermeasures in one go; it was developed over a long back-and-forth of Google improving their system and people getting past it.


That's nice, but humans are pretty fucking stupid and can be tricked. This is no reason to stop trying.
You don't quite understand.
Google is the one of the biggest MASTERMINDS behind of project of stopping bad bots, browsers, spammers like you. (Have ever heard of Hidden Recaptcha, My friend? :D)
Mentioning some shitty stories of people bypassing Google BG while they were only like baby doesn't help a bit.
Google intelligence growth is far from linear while so ego-proud brain of stupid people like you lags behind stationary. It only takes very little time for Google now to improve their securities compared to 10 years ago.
And now you need 100*100 more brainpower to breach their systems. Future? It'll take (100*100)*(100*100) more brainpower needed to even scratch the Google Fortress :D And no way it's job for one person.
Just don't be bad guy to their eyes and you should be fine, my friend ;)

Oh, btw same goes for FB. I strongly advise you to don't touch these two lions if you are doing blackhats :)
 
lol I told you guys to stay away but it seems you guys are so obsessed with these things :)
Still don't know what this refers to. Provide a link, I don't want to read all 100+ of your posts to figure out what you're talking about.

Google is the one of the biggest MASTERMINDS behind of project of stopping bad bots, browsers, spammers like you.
I'm not spamming anyone, I'm just trying to help with programming. But what's your point? Everyone should just give up and let them win? Great advice bro. When life gets hard: give up.

Google intelligence growth is far from linear while so ego-proud brain of stupid people like you lags behind stationary
Yes, we got it. Google is god, and you are smart for not messing with them. Everyone except you has an ego problem. Please tell us more about how stupid we are.

Mentioning some shitty stories of people bypassing Google BG while they were only like baby doesn't help a bit.
What shitty story? Did you even read what I said? I'm talking about the progression of attacks vs defenses; it has been and continues to be ongoing. Regardless of pathetic unmotivated losers deciding to give up because "Google is smart". This is how all security/fraud/virus/etc. systems evolve. Attackers outsmart defenders, defenders outsmart attackers, repeat.

And now you need 100*100 more brainpower to breach their systems. Future? It'll take (100*100)*(100*100) more brainpower needed to even scratch the Google Fortress :D And no way it's job for one person.
I'd say you pulled these numbers out of your ass but your head is so far up it, I don't see how it's possible. This thread is not about "breaching" Google, it's about creating accounts.

Oh, btw same goes for FB. I strongly advise you to don't touch these two lions if you are doing blackhats :)
"hai guyz, i came to dis blakhat forum 2 tell u not to blakhat da good sites, they r smrtr than u. ur welcom for this signifnct contribution, okbyenow"
 
what browser auomation sofwere can make google accounts .

someone tell me who doing this then?
and what the app is?

proper ansaw from proven adventurer,,,,
 
Still don't know what this refers to. Provide a link, I don't want to read all 100+ of your posts to figure out what you're talking about.


I'm not spamming anyone, I'm just trying to help with programming. But what's your point? Everyone should just give up and let them win? Great advice bro. When life gets hard: give up.


Yes, we got it. Google is god, and you are smart for not messing with them. Everyone except you has an ego problem. Please tell us more about how stupid we are.


What shitty story? Did you even read what I said? I'm talking about the progression of attacks vs defenses; it has been and continues to be ongoing. Regardless of pathetic unmotivated losers deciding to give up because "Google is smart". This is how all security/fraud/virus/etc. systems evolve. Attackers outsmart defenders, defenders outsmart attackers, repeat.


I'd say you pulled these numbers out of your ass but your head is so far up it, I don't see how it's possible. This thread is not about "breaching" Google, it's about creating accounts.


"hai guyz, i came to dis blakhat forum 2 tell u not to blakhat da good sites, they r smrtr than u. ur welcom for this signifnct contribution, okbyenow"
Yeah Go on then :) Go research "How to create mass Google accounts 2018" and sell the ebook for $19, sell your holy 100k accounts for $2 each, which is likely to only happen in your dream :)
Regarding bhw, i advised you to stay away from G and FB, not entire blackhats.
You really need to fix your eyeglasses and read carefully if you want to succeed my friend ;)
 
Yeah Go on then :) Go research "How to create mass Google accounts 2018" and sell the ebook for $19, sell your holy 100k accounts for $2 each, which is likely to only happen in your dream :)
Regarding bhw, i advised you to stay away from G and FB, not entire blackhats.
You really need to fix your eyeglasses and read carefully if you want to succeed my friend ;)
there must be a way loads sell the accounts and there all automated made .....


i hate the way programmers hold everthink to there chest why i gave up pure selfishness all me me me, still same stuff going on since i left in 2013 unreal...
 
Lothric you’ve overstayed your welcome, piss off away from my thread. Your answers are of no relevance and only serve to be intentionally yet unsuccessfully demotivational.
 
Lothric you’ve overstayed your welcome, piss off away from my thread. Your answers are of no relevance and only serve to be intentionally yet unsuccessfully demotivational.
Sure, I don't intend to stay here for long afterall :) because i know you'll only make dusts from your research :D
Good luck with your "Mass creating Google accounts in 2017" ;)
 
Sure, I don't intend to stay here for long afterall :) because i know you'll only make dusts from your research :D
Good luck with your "Mass creating Google accounts in 2017" ;)
lol you are such a google fanboi. listening to you sounds like we should all just give up. dude i'm doing IM and programming since before google even existed. google pretends to be so advanced with detecting spam, then how come there is still so much spam in the serps? so many cloaked pages they dont find. all these obviously hacked sites for seo spam that could be easily detected and yet it still works. you talk about recaptcha which has been broken since ages by OCR like xrumer has for example and even the new recaptcha v2 (nocaptcha) is currently being automated by xrumer. sure google has very advanced bot detection on their social networks and accounts, however it is still possible to automated without as much effort as you claim it to be. yes you have to know what you are doing and OP is trying to learn. even if he fails, its good to learn these things and when he picks a hard target and understands how it works then it will be easier later on easier targets. the point is that he tries to understand how to automate things so like i said even if he fails with google, its still good to learn WHY it didnt work and what needs to be done. that being said you think nobody is able to beat google, besides blackhats are always a step ahead. even google got hacked themselfs a few times so how did that happen if they are so almighty and such MASTERMINDS ?! :P they are also just human and its not like the single best coders in the world work for google, there are better coders in other fields. you can have 1000 smart coders and it still just needs 1 guy to outsmart them all with something they all didnt think of. constantly happens all over the place. take the IT security field for example. there are hundreds of thousands of security companies world wide, yet there is always 1 or 2 guys who find something new that all the rest didnt find. they also find holes in multi million dollar software and also in google software like android and chrome and web services constantly. so when someone can find a security hole in google, its far easier to fool some detection algorithm. people constantly find holes in google chrome to hack users, so how come if the google coders are sooooo powerful and almighty that they cant make a secure browser ? or another example: adobe flash gets special security hardening from google security team a while back to block certain types of exploits. well a few days later 1 single guy writes a new flash exploit using a whole new technique that even the google security team didnt know and it broke their security hardening that they just gave to adobe to fix flash against attacks. so you see if everyone would just give up without even trying like you then we'd get nowhere.. people can still circumvent google, they arent the smartest people on the planet....
 
lol you are such a google fanboi. listening to you sounds like we should all just give up. dude i'm doing IM and programming since before google even existed. google pretends to be so advanced with detecting spam, then how come there is still so much spam in the serps? so many cloaked pages they dont find. all these obviously hacked sites for seo spam that could be easily detected and yet it still works. you talk about recaptcha which has been broken since ages by OCR like xrumer has for example and even the new recaptcha v2 (nocaptcha) is currently being automated by xrumer. sure google has very advanced bot detection on their social networks and accounts, however it is still possible to automated without as much effort as you claim it to be. yes you have to know what you are doing and OP is trying to learn. even if he fails, its good to learn these things and when he picks a hard target and understands how it works then it will be easier later on easier targets. the point is that he tries to understand how to automate things so like i said even if he fails with google, its still good to learn WHY it didnt work and what needs to be done. that being said you think nobody is able to beat google, besides blackhats are always a step ahead. even google got hacked themselfs a few times so how did that happen if they are so almighty and such MASTERMINDS ?! :p they are also just human and its not like the single best coders in the world work for google, there are better coders in other fields. you can have 1000 smart coders and it still just needs 1 guy to outsmart them all with something they all didnt think of. constantly happens all over the place. take the IT security field for example. there are hundreds of thousands of security companies world wide, yet there is always 1 or 2 guys who find something new that all the rest didnt find. they also find holes in multi million dollar software and also in google software like android and chrome and web services constantly. so when someone can find a security hole in google, its far easier to fool some detection algorithm. people constantly find holes in google chrome to hack users, so how come if the google coders are sooooo powerful and almighty that they cant make a secure browser ? or another example: adobe flash gets special security hardening from google security team a while back to block certain types of exploits. well a few days later 1 single guy writes a new flash exploit using a whole new technique that even the google security team didnt know and it broke their security hardening that they just gave to adobe to fix flash against attacks. so you see if everyone would just give up without even trying like you then we'd get nowhere.. people can still circumvent google, they arent the smartest people on the planet....

Agreed, I mean I have sufficient experience and knowledge to have produced an almost fully-automated system to create an account and complete phone verification. All I'm seeking is an understanding of google's techniques so the accounts I create can stay under the radar. All of the tips such as keeping the timezone and such consistent are really useful and are almost definitely used by google.
 
Probably impossible with get/post requests, other route shouldnt be so difficult. You just have to turn on your brain and think a bit and ofcourse test.
 
also read this http://webkay.robinlinus.com/ and research a bit deeper and you should be good to go :)

I had a look and it turns out my webbrowser is fooling every check on that page already :/

Here are what I believe to be my downfalls, please let me know whether you think google cares about these or not:

1) The first and last name were randomly generated in a pattern of XXXWWXXX where X resembles 1-3 random characters and W resembles 1-2 real words from a dictionary. Google may detect the pattern
2) The password was between 32 and 64 characters and was completely random using all a-zA-Z0-9 and all of the symbols on my keyboard. Google may believe this is too difficult for a human to realistically use.
3) Some strange inconsistencies between web browsers meant the page code was slightly different and sometimes I was not able to inject a gender or birth day. Sometimes a terms and conditions checkbox appeared, and sometimes there was an issue with the page where it complained the phone prefix (put there by the page, I hadn't changed it) did not match the country (again, placed there by the page). My bot's fallback made it refresh the page and try again, but it's inefficient as it happens unfortunately often.
4) I did not set my timezone to that of the country in which the proxy server resides.
5) I was injecting the values directly into the page as opposed to sending clicks and keypresses.
6) My bot worked quickly. Perhaps google thought the form was being filled out too quickly.
7) All of the numbers I was using for verification were from the company I worked for, which means google may see too many verification requests for the same telecoms provider. I doubt this is the case.
8) I did not vary my screen size for each account created. I definitely think this had something to do with it, especially as the web browser itself was a strange size. I should make it fullscreen or change to a random, realistic size each time.

Something I just read about is that google definitely looks for cookies and I should do the following:

1) Make the webbrowser visit the account creation page and complete it by hand
2) Save all of the cookies, they prove I was legit
3) Use those cookies for any future account creations.
 
Last edited:
So I've done some more research and I'm now sending the following headers:

upload_2017-11-16_19-26-38.png


I noticed that google's captcha demo page showed a captcha every single time before I was using these headers, now it's only sometimes - I guess because I'm not using a proxy and my IP is always the same.
 
In addition to that header work I've done some more involving user agents and proxies. Here's my code so far if you're interested. Before request() is called, the WebBrowser quickly expands to fullscreen to trick the webpage into believing it's a normal browser size c:

Code:
    Private Shared rand As New Random()
    Private Shared proxies As New List(Of String)
    Private Shared userAgents() As String =
    {
        "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36",
        "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko",
        "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:47.0) Gecko/20100101 Firefox/47.0"
    }

    Public Shared Function request(address As String) As Stream
        proxies.Clear()

        For Each x As String In New WebClient().DownloadString("http://spys.me/proxy.txt").Split(vbLf)
            Dim _x = x.Trim()
            If _x.Split(".").Count <> 4 Then Continue For
            If Not _x.Contains("+") Then Continue For 'google safe
            If Not _x.Contains("H") Then Continue For 'make it seem like i'm not using a proxy
            If Not _x.Contains("GB") Then Continue For 'GB servers only to match timezone and telephone number
            proxies.Add(_x.Split(" ")(0))
        Next

        Dim stream As Stream

retry:
        Try
            Dim req As HttpWebRequest = WebRequest.Create(address)
            req.KeepAlive = True
            req.UserAgent = getRandomUserAgent()
            req.Headers.Clear()
            req.Headers.Add("Accept-Language", "en-GB, en;q=0.8")
            req.Accept = "application/xml,application/xhtml+xml,text/html;q=0.9, text/plain;q=0.8,image/png,*/*;q=0.5"

            Dim proxy() As String = getRandomProxy().Split(":")
            req.Proxy = New WebProxy(proxy(0), Integer.Parse(proxy(1)))

            stream = req.GetResponse().GetResponseStream()
        Catch ex As Exception
            GoTo retry
        End Try

        Return stream
    End Function
 
Back
Top