Spoofing canvas and webgl

multi login is already bypassing this then how?
they are multi profile browser too.

botting google is not that hard especially for views.
i already have my own solution for this.
each viewer watches video from isolated browser environment with no fingerprint leaks.
like vm with unique fingerprints.

u add random Human activity with aged Google accounts.
that way even normal quality proxies work.

the reason why most botting method fails is coz the method sucks. not coz of proxies.

if proxies are the problem then my normal account Should be banned when i access from vpn.
but i dont get banned coz there is human activity.

my team already has bot that bypasses Google for views.

but that bot is only for views im looking for a good solution for multi account management besides vps or vms.


what do u think about vms?
will there still be some leak?
something that i need to look into?
Go0gle is able to detect you are using vm when you use gg chrome.
Multilogin is enough for your need, as it provide consistent fingerprints llike from real devices
 
You can try INCOGNITON it's a multilogin tool the seller is a BHW member, and it's free for 10 profiles
 
Just a quick update guys
tested on iPhone for some time now, not worth it.
don't have time right now to go in details, it is just not worth the cost and the lack of scalability and reliability.

My current config in playwright is able to pass distil and often also recaptcha, but still 0 success with Datadome. I can navigate to the site but after 2-3 clicks I get instant blocked, even by making hotspot with my phone (just in case problem was some proxies leak)
Has anyone figured out how to beat these guys?
it's becoming something personal
Hello,

could you DM me about datadome bypass ? Working on one too and i'm quite close to getting it, just need a few answers ! .paul#7172 or directly via dm
 
You can totally eliminate fingerprints by using something like Pullovers Macro Creator
The problem with browsers like Selenium is that they were never designed for stealth. TSL (Test Script Language) was designed for load testing servers or applications by lazy engineers. They have finger prints because that's how the metrics software tracked performance... Scorpion & the frog.
Purist of TSL will tell you Macro script like AutoHotKey are none contact. No injection into the browser code.
You can scale up using VMware which is free as well.
Use decent proxies and you will never be detected.
 
You can totally eliminate fingerprints by using something like Pullovers Macro Creator
The problem with browsers like Selenium is that they were never designed for stealth. TSL (Test Script Language) was designed for load testing servers or applications by lazy engineers. They have finger prints because that's how the metrics software tracked performance... Scorpion & the frog.
Purist of TSL will tell you Macro script like AutoHotKey are none contact. No injection into the browser code.
You can scale up using VMware which is free as well.
Use decent proxies and you will never be detected.
Yep, very true.
But you still have to find a way to cover your tracks by changing your browser's footprints if your goal is to create accounts for example.
 
Yep, very true.
But you still have to find a way to cover your tracks by changing your browser's footprints if your goal is to create accounts for example.
Not if you start a fresh instance of chrome everytime.. again easy to do with AHK
You can copy out the cookies then import them back in when you re use an account... again easy to do with AHK
 
Not if you start a fresh instance of chrome everytime.. again easy to do with AHK
You can copy out the cookies then import them back in when you re use an account... again easy to do with AHK
fingerprints reaches far more deeper than just what is happening in browser relating to cookies and storage.

to successfully and fully evade fingerprinting, you need to change your video rendering device

that is why nothing beats mobile in account creation
 
fingerprints reaches far more deeper than just what is happening in browser relating to cookies and storage.

to successfully and fully evade fingerprinting, you need to change your video rendering device

that is why nothing beats mobile in account creation
You can do that with VMware - Macro miners have been doing this for years.

https://www.macrolab-online.com/knowledgebase/index.htm > farming tutorial > VMware setup
 
You can do that with VMware - Macro miners have been doing this for years.

https://www.macrolab-online.com/knowledgebase/index.htm > farming tutorial > VMware setup
No, you can't change your graphic engine by that, the canvas/webgl render output will stay the same as it still uses hosts graphics.

Again, these fingerprinting techniques uses HARDWARE to determine same devices, thus my advice for mobile phones as there it's a norm to have same vendor hardware so fingerprinting mobile devices have less sense than desktop machines.

And even if you could change that by using vmware, scalability by such a setup would be close to none, good luck creating 1000 Instagram accounts by using vmware.
 
No, you can't change your graphic engine by that, the canvas/webgl render output will stay the same as it still uses hosts graphics.

Again, these fingerprinting techniques uses HARDWARE to determine same devices, thus my advice for mobile phones as there it's a norm to have same vendor hardware so fingerprinting mobile devices have less sense than desktop machines.

And even if you could change that by using vmware, scalability by such a setup would be close to none, good luck creating 1000 Instagram accounts by using vmware.
You create a vanilla copy of win10 virtual machine.
Snapshot the machine at the point before the macro creates creates the account.
Export the cookies and the VM settings file to a shared folder/drive.
Then roll back the VM instance to the vanilla.
Rinse repeat.
You can use the VM manager tool from MacroLab's to auto run 10 vm's at a time.
 
Well it depends on the platform you create the accounts on.
I used to bot on virtualbox machines to create adwords accounts and I can tell you it's not enough to start a fresh copy of chrome, nor a new VM. You have to change you hardware fingerprint too, which is very complicated and doesn't work 100%.
For some platforms like reddit though you don't need to take such precautions, it really depends on your goal.
 
Depends on platform. most of the platforms and forums these days are detecting duplicate users based on Hardware , timezone and other fingerprints. you can easily get detected with Virtual machines / Fresh browser profiles if dealing with challenging system.

IP is not a factor since long time ago but it's good in any case that your information is required by a third-party agency
 
Well it depends on the platform you create the accounts on.
I used to bot on virtualbox machines to create adwords accounts and I can tell you it's not enough to start a fresh copy of chrome, nor a new VM. You have to change you hardware fingerprint too, which is very complicated and doesn't work 100%.
For some platforms like reddit though you don't need to take such precautions, it really depends on your goal.
You don't need it for reddit? I would have thought you would, maybe i'm thinking too much about it? Do you know specifically what things reddit DOES look for? Or the best way to figure that out for myself? I've been trying to figure out a more reliable solution than me forking out money for incogniton (though it's worked great, i'm broke currently lol)

I've been thinking just getting some spoofing browser plugins to at least mask it?
 
You don't need it for reddit? I would have thought you would, maybe i'm thinking too much about it? Do you know specifically what things reddit DOES look for? Or the best way to figure that out for myself? I've been trying to figure out a more reliable solution than me forking out money for incogniton (though it's worked great, i'm broke currently lol)

I've been thinking just getting some spoofing browser plugins to at least mask it?
Back in time (a year ago) when I was creating accs on reddit it was enough to change ip, delete cookies, and spoof the user agent.
Same for upvoting posts.
I don't know if it's still as simple today.
 
Back in time (a year ago) when I was creating accs on reddit it was enough to change ip, delete cookies, and spoof the user agent.
Same for upvoting posts.
I don't know if it's still as simple today.
Ah, fair enough, i've been using incogniton for my browsers while doing my testing and coding functionality, but I don't even know what reddit actually detects, i'm going to be doing a bunch of things differently, using gmail accounts instead of temp emails, my own selenium browsers with profiles etc just need to figure out how to create and use the profiles properly, doesn't seem to be much in the way of tutorials for that specifically, that work anyway.


This was all about 6-7 months or so ago? But for the most part, unless I did something stupid while testing code, or it broke during long operations, most of my accounts were fine, I was just curious if I was thinking about it too much. Then again, I guess when it comes to this, there's no such thing as "too careful" haha
 
Ah, fair enough, i've been using incogniton for my browsers while doing my testing and coding functionality, but I don't even know what reddit actually detects, i'm going to be doing a bunch of things differently, using gmail accounts instead of temp emails, my own selenium browsers with profiles etc just need to figure out how to create and use the profiles properly, doesn't seem to be much in the way of tutorials for that specifically, that work anyway.


This was all about 6-7 months or so ago? But for the most part, unless I did something stupid while testing code, or it broke during long operations, most of my accounts were fine, I was just curious if I was thinking about it too much. Then again, I guess when it comes to this, there's no such thing as "too careful" haha
You can type whatever email you want they don't even require a verification to be able to post on reddit.
The biggest problem on reddit is people flagging your posts at the speed of light, so better spend some time to elaborate a method to fly under the radar, instead of coding a complicated bot :)
 
No, you can't change your graphic engine by that, the canvas/webgl render output will stay the same as it still uses hosts graphics.

Again, these fingerprinting techniques uses HARDWARE to determine same devices, thus my advice for mobile phones as there it's a norm to have same vendor hardware so fingerprinting mobile devices have less sense than desktop machines.

And even if you could change that by using vmware, scalability by such a setup would be close to none, good luck creating 1000 Instagram accounts by using vmware.
So you're saying that is more optimized to spoof a Chrome Mobile fingerprint on Puppeteer than a Chrome Desktop fingerprint ?
 
So you're saying that is more optimized to spoof a Chrome Mobile fingerprint on Puppeteer than a Chrome Desktop fingerprint ?
No.

- Same mobile devices uses same hardware.
- Same hardware, same fingerprints.
- If all fingerprints are same, no need to spoof them.
 
No.

- Same mobile devices uses same hardware.
- Same hardware, same fingerprints.
- If all fingerprints are same, no need to spoof them.
Ok I see, and for Social Media creation, you spoof fingerprint with Puppeteer ?
Or you're using a customized browser ?
 
Back
Top