Article

Paper anti-xray bypass: what gets through, and how to spot it

Paper's anti-xray holds against anything that just reads what the server sends: no mod or texture pack can find an ore that was never transmitted. The bypasses that work come from elsewhere: what the server still sends in the clear, or information that doesn't come from the packets at all. Here they are, what limits them, and how to spot them as a moderator.

Published

What anti-xray really blocks

The mechanism is covered in detail in our article on engine modes: before sending a chunk, the server swaps the ores it considers invisible for rock (mode 1) or for noise made of fake ores (modes 2 and 3). A modified client cannot "undo" this: the information simply isn't in what it receives. A bypass can therefore only exploit four things.

1. Ores touching air

In engine-mode: 1, only ores entirely surrounded by solid blocks are hidden. Any ore touching a cave, a ravine or a mineshaft is sent as is, since any player walking by could see it. And since 1.18, caves are huge: a large share of deep ores touch air.

That's what mods that highlight caves or visible ores at a distance (so-called "cave finders" or "cave detectors") exploit: they don't see anything hidden, but they list at once everything exposed in the loaded chunks, far beyond what a player would notice.

What limits this bypass

Switching to engine-mode: 2 or 3 with air in hidden-blocks: exposed ores are then drowned among fake ones. The trade-off, documented by PaperMC: the FPS of every player can drop. Full configuration in the engine modes article.

2. The world seed

This is the most serious bypass, and Paper's documentation says so itself: world generation is deterministic. A client that knows the seed can recompute the location of every generated ore, without ever looking at what the server sends. Obfuscation then has no effect.

The seed can leak in several ways: shared publicly (a "server seed" posted on a forum), available through the /seed command to someone who shouldn't have it, or rebuilt by public tools from observable features of the terrain. That last point is why keeping it secret is not enough.

What limits this bypass

Never publish the seed, and keep /seed for administrators. On the Paper side, feature-seeds in paper-world-defaults.yml (generate-random-seeds-for-all: true) gives random seeds to the generation of world features; on the Spigot side, the seed-* options in spigot.yml (seed-village, seed-slime, seed-ancientcity…) do the same for structures. Two limits: this only affects terrain generated after the change, and PaperMC states that it is not a complete solution.

3. Range extension

Paper's documentation also notes that xray range can be extended "by a not insignificant amount" without an anticheat plugin to prevent it. Paper offers no setting against this: treat it as a known limit, and rely on detection rather than prevention.

4. The bypass permission

With use-permission: true, players who have paper.antixray.bypass receive the world without obfuscation. Handy for staff, but it is an official bypass: a compromised staff account, or a team member who abuses it, sees exactly what an x-rayer sees.

What limits this bypass

Leave use-permission: false if nobody needs it; otherwise, grant paper.antixray.bypass only to a very small group, and regularly check who actually has it.

And everything that happened before

One last blind spot isn't a bypass but amounts to the same thing: anti-xray only protects the future. Everything mined before it was turned on stays out of reach, and none of the bypasses above leaves any trace on Paper's side.

How to spot a bypass

Paper's anti-xray produces no log and no alert: a player who gets through is invisible on that side. Their mining, however, leaves traces in your block history, and they look alike whatever bypass was used, classic x-ray, recomputed seed or cave mod: the player goes straight to the ores, without the exploration that not knowing where they are forces on everyone else.

Key points

Limits and settings checked against the official PaperMC documentation and the spigot.yml reference.

Keep reading

Article Why a suspicion score should never be enough to ban →

Detecting what anti-xray lets through

TunnelVision rereads the CoreProtect history your server already records, rebuilds mining sessions and surfaces the ones whose trajectory can't be explained, whatever was used to know where the ores were. Every session comes with the indicators behind its score, and the decision stays yours.