
Anti-Dupe
Плагин Anti-Dupe для серверов Minecraft защищает от эксплойтов дублирования предметов. Использует гибридную систему хэшей и уникальных ID, сканирует инвентари и поддерживает кастомные предметы.
Список изменений
Anti-Dupe 3.5
Advanced item-duplication protection for Paper servers
Anti-Dupe 3.5 combines live transaction verification, persistent quantity accounting, signed unique-item identities, cross-inventory scanning, and safe administrator recovery in one complete Paper security system.
It is designed for vanilla and customized servers that need strong detection without making everyday inventory management difficult.
Verify item creation, preserve the original, secure the evidence, and give staff a fast way to review and restore anything they need.
What Is New in 3.5
Anti-Dupe 3.5 greatly expands incident forensics. When a dupe happens, staff can now determine Who / What / When / Where, while the new Chunk Audit and Command Audit provide evidence that may help explain why and how the duplication occurred.
New incidents now record:
- Backend server, world, and precise coordinates
- Nearby players within 32 blocks
- Player UUID, distance, and optional game mode
- Subject-versus-nearby incident history
- Repeat nearby-appearance counts
- A fixed 3×3 chunk audit area: the offender's chunk plus all eight neighbouring chunks
- Redstone, mechanisms, storage blocks, exact coordinates, and totals
- The offender's last 10 player-issued commands when an incident begins
- Commands displayed newest-first with timestamps and allowed/cancelled state
- Automatic redaction of passwords, PINs, OTPs, tokens, and authentication arguments
!1 !dsadads!afhadfhafdhadfh!dfsgasdfhdfhashf
The 3.5 release also includes:
- Player → incidents → incident-items recovery workflow
- Individual and incident-wide restoration
- Back navigation throughout the recovery interface
- Persistent global quantity ledger
- HMAC-SHA256 signed identities for unique items
- Automatic version-1 to version-2 identity migration
- Two-stage enforcement using independent confirmation reads
- Atomic cross-server inventory transfers
- Exclusive database-backed player leases
- One-time network transfer claims and inventory hashes
- Trusted-plugin authorization without inventory-title patterns
- Holderless custom-GUI attribution
- Full exemption for Anti-Dupe-owned menus
- Combined inventory, cursor, and material-level conservation
- Automated detection simulations and regression testing
- SQLite, MySQL, MariaDB, and PostgreSQL support
Lag Reduction and Further Optimization
Anti-Dupe 3.5 continues to spread expensive work across multiple ticks and avoids unnecessary repeated scans. The goal is to preserve strong detection and forensic evidence while minimizing impact on TPS and normal gameplay.
Performance and lag-reduction measures include:
- One chunk per tick processing for 3×3 incident chunk audits
- Staggered scheduled scans instead of running every audit simultaneously
- Configurable batching for player, Ender Chest, container, UUID, and ledger scans
- Delayed chunk scans that confirm a chunk is still loaded before inspecting it
- Two-stage enforcement that lets transactions settle before performing confirmation reads
- Movement stabilization for joins, teleports, portals, world changes, rapid chunk transitions, and high-speed Elytra travel
- Asynchronous Discord webhook delivery after evidence has been saved and enforcement completed
- Focused 3×3 incident auditing instead of unrestricted world-wide mechanism scanning
- Bounded command history collection limited to the last 10 player-issued commands per incident
- Persistent database-backed ledger, recovery, and network-transfer state to avoid unnecessary reconstruction work
Together, these optimizations keep heavier forensic work bounded and distribute it over time, reducing single-tick workload while retaining the information administrators need to investigate duplication incidents.
Core Features
- Immediate inventory transaction verification
- Persistent authorized-supply accounting
- Stack-safe canonical item fingerprints
- Signed UUID identities for non-stackable items
- Cross-inventory duplicate detection
- Two-stage confirmation before normal quarantine
- Player, Ender Chest, container, and entity scanning
- Automatic delayed chunk scanning
- High-speed movement and chunk-transition stabilization
- Trusted shop and reward-plugin compatibility
- Crafting and workstation transaction handlers
- Bundle and nested-item accounting
- Monitored plugin-command transfers
- Plugin-managed storage auditing
- Safe item recovery and complete inventory rollback
- World-specific audit and quarantine rules
- Velocity and BungeeCord backend coordination
- Known exploit-pattern classification
- Private staff notifications and daily logs
- Discord webhook alerts
- 28 locale variants
- Operator and Creative Mode protection
- Administrator testing tools
Detection Architecture
Anti-Dupe does not depend on one periodic scan or one piece of item metadata. Version 3.5 combines several independent evidence layers:
Live Transaction Verification
+
Persistent Quantity Ledger
+
Signed Unique Identities
+
Cross-Inventory Scanning
+
Independent Confirmation
↓
Confirmed Incident Evidence
This lets Anti-Dupe distinguish ordinary item movement from actual quantity creation while retaining strong evidence for administrator review.
Persistent Global Quantity Ledger
Anti-Dupe maintains a persistent authorized-supply ceiling for every observed stackable fingerprint.
The first complete startup scan establishes the existing supply. After that, validated vanilla outputs and approved trusted-plugin grants add idempotent authorization records to the configured database.
Repeated global observations above authorized supply become confirmed ledger incidents. Global reconciliation currently operates as a reporting layer, allowing staff to investigate confirmed excess before applying broader enforcement to servers with custom item-generation plugins.
persistent-global-ledger:
enabled: true
startup-baseline-delay-ticks: 40
learning-period-minutes: 1440
required-matching-scans: 2
The ledger persists across restarts and never authorizes a transaction twice when the same transaction ID is replayed.
Signed Unique-Item Identities
Non-stackable items receive a hidden serial UUID protected by HMAC-SHA256.
The signature authenticates:
- Identity version
- Unique serial UUID
- Issuing server
Names, damage, repairs, enchantments, and other legitimate item changes are tracked separately, so the stable signed identity can continue to follow the same item.
Version 3.5 automatically upgrades unsigned legacy items and authentic version-1 identities to the current version-2 format.
The signing key is generated at:
plugins/Anti-Dupe/identity.key
Back up this file. Every backend in a network must use the same identity key.
Two-Stage Enforcement
Normal quantity and identity detections require independent confirmation.
First Observation
↓
Record Candidate
↓
Wait for the Transaction to Settle
↓
Read Fresh Inventory State
↓
Evidence Still Present?
/ \
No Yes
↓ ↓
Clear Confirm
↓
Backup and Quarantine
two-stage-enforcement:
enabled: true
required-matches: 2
confirmation-delay-ticks: 3
candidate-expiry-seconds: 30
The administrator-only /dupe diagnostic remains immediate so staff can verify the
configured enforcement mode on demand.
Transaction and Material Conservation
Inventory clicks are evaluated across the complete transaction scope:
- Top inventory
- Player inventory
- Cursor/carried item
- Nested bundle contents
Anti-Dupe also verifies the combined material quantity. A fingerprint transition with no material increase is treated as an item-state change, while genuine quantity growth continues through confirmation.
Protected transaction families include:
- Inventory click and drag
- Pickup All and Place All
- Shift-click and number-key transfers
- Stack split, merge, and double-click collection
- Offhand swaps
- Hopper transfers
- Crafting Tables and player crafting
- Furnaces, Blast Furnaces, and Smokers
- Smithing Tables, Anvils, and Grindstones
- Brewing Stands and Crafters
- Stonecutters, Cartography Tables, and Looms
- Villager trading
- Bundle transfers
- Player joins and network transitions
- Monitored plugin commands
- Plugin-managed storage open and close operations
Trusted Plugin Compatibility
Trusted shops, crates, quests, rewards, and other approved systems can authorize the items they legitimately grant.
compatibility:
external-plugin-inventories:
enabled: true
grace-delay-ticks: 4
trusted-plugins:
- UltimateShop
- EconomyShopGUI
- ShopGUIPlus
Trust is based on the plugin that owns or opens the custom inventory. GUI titles are not used as a trust requirement. Holderless custom menus are attributed from the plugin call that opened them.
Physical inventories such as chests, barrels, player inventories, and entity inventories remain under normal verification.
Accepted trusted grants:
- Update transaction history
- Add authorized supply to the global ledger
- Normalize signed identities when required
- Keep the rest of the player's inventory protected
⚠️ Trusted Plugin Warning: A trusted plugin becomes an intentional item-creation authority. Keep this list small, use reputable plugins, and monitor their security updates.
Crafting and Workstation Protection
Virtual result previews are handled separately from owned inventory contents. Anti-Dupe validates consumed inputs and authorizes the corresponding output only after Minecraft has completed the transaction.
This includes shift-crafted output, crafting remainder items, repeated villager trades, and workstation result collection.
Bundle Protection
Items inside vanilla bundles remain part of the player's total ownership.
Bundle Contents
↕
Cursor
↕
Player Inventory
Moving an item between these locations conserves the total. Recursive accounting can also inspect nested supported contents.
transaction-handlers:
bundles:
enabled: true
delay-ticks: 2
include-contained-items-in-accounting: true
recursive-content-check: true
Cross-Inventory Protection
Anti-Dupe compares signed UUIDs across:
- Player inventories
- Ender Chests
- Chests and Trapped Chests
- Barrels and Shulker Boxes
- Hoppers
- Furnaces, Smokers, and Blast Furnaces
- Brewing Stands
- Droppers and Dispensers
- Crafters
- Chest and Hopper Minecarts
- Other loaded inventory-holding entities
If the same identity is confirmed in independent live locations, Anti-Dupe preserves the registered original, backs up the conflicting copy, creates a recovery incident, and applies the configured world policy.
Movement stabilization accounts for joins, teleports, portals, world changes, rapid chunk transitions, and high-speed Elytra travel before cross-inventory enforcement.
Automatic and Manual Scanning
Scheduled scans are staggered and processed in configurable batches.
| Scan | Default Interval |
|---|---|
| Online Player Inventories | 5 minutes |
| Ender Chests | 10 minutes |
| Loaded Containers | 15 minutes |
| Cross-Inventory UUID Check | 15 minutes |
| Ledger Audit | 30 minutes |
Manual commands:
/antidupe scan all
/antidupe scan players
/antidupe scan ender
/antidupe scan containers
/antidupe scan chunk
Delayed chunk scans verify that a chunk is still loaded before inspecting it, keeping the evidence tied to a current live inventory.
Atomic Network Transfers
Anti-Dupe 3.5 provides database-backed coordination for Velocity and BungeeCord networks.
When a player leaves a backend, Anti-Dupe commits:
- A unique transfer ID
- The source and destination state
- An ordered SHA-256 inventory hash
- Storage slots
- Armor slots
- Offhand slot
- Ender Chest slots
- Transfer expiry information
The destination must atomically claim the transfer and present the matching arrival hash. Player leases prevent the same player inventory from being active on two backends at once, and each transfer can be claimed only once.
Network requirements:
- Install Anti-Dupe on every Paper backend
- Use one shared MySQL, MariaDB, or PostgreSQL database
- Give every backend a unique
network.server-id - Use the same
identity.keyor shared signing secret everywhere
network:
enabled: false
proxy: NONE
server-id: survival-1
player-lease-seconds: 45
reject-join-while-locked: true
inventory-mismatch-action: KICK
shared-ledger: true
cross-server-uuid-checks: true
cross-server-stack-accounting: true
Standalone Paper servers can leave network mode disabled.
Inventory Rollbacks
Anti-Dupe can store complete player snapshots containing inventory storage, armor, offhand, and Ender Chest contents.
/antidupe rollback list [player]
/antidupe rollback snapshot
/antidupe rollback restore <id> [player]
Rollback snapshots complement item-level recovery when staff need to restore a broader inventory state.
World-Aware Rules
Different worlds can use different policies:
world-rules:
enabled: true
default-mode: inherit
worlds:
world:
mode: inherit
creative:
mode: audit
scan-ender-chest: false
Available world modes are:
inheritdisabledauditquarantine
Operator and Creative Protection
Optional UUID-based security can restrict operator status and Creative Mode access.
/antidupe opprot add <player>
/antidupe opprot remove <player>
/antidupe opprot list
/antidupe creativeprot add <player>
/antidupe creativeprot remove <player>
/antidupe creativeprot list
⚠️ Configure every legitimate administrator UUID before enabling OP protection. An empty allowed list means nobody is authorized.
Database Support
Supported database backends:
- SQLite
- MySQL
- MariaDB
- PostgreSQL
SQLite is ready for standalone installations. Network mode requires all backends to share the same remote database.
Automatic schema migrations preserve compatible data as Anti-Dupe evolves.
Private Reporting and Discord Alerts
Detection details are sent to controlled administrator channels:
- Paper console
- Staff with
antidupe.notify - Daily UTF-8 log files
- Discord webhook, when configured
Daily logs are stored under:
plugins/Anti-Dupe/logs/anti-dupe-YYYY-MM-DD.log
Discord delivery is asynchronous and occurs only after recovery evidence has been saved and enforcement has completed.
Console verbosity can be changed without disabling recovery, Discord, daily logs, or staff notifications:
/antidupe verbosity off
/antidupe verbosity low
/antidupe verbosity med
/antidupe verbosity high
Multi-Language Support
Anti-Dupe 3.5 includes 28 locale variants with optional client-locale detection:
ar_SA, cs_CZ, da_DK, de_DE, el_GR, en_US, es_ES, fi_FI,
fr_CA, fr_FR, he_IL, hi_IN, hu_HU, id_ID, it_IT, ja_JP,
ko_KR, nl_NL, no_NO, pl_PL, pt_BR, ro_RO, ru_RU, sv_SE,
tr_TR, uk_UA, zh_CN, and zh_TW.
language:
default: en_US
use-client-locale: true
Commands
/antidupe status
/antidupe audit
/antidupe scan <all|players|ender|containers|chunk>
/antidupe recovery
/antidupe recovery player <player>
/antidupe recovery restore <id> [player]
/antidupe rollback list [player]
/antidupe rollback snapshot
/antidupe rollback restore <id> [player]
/antidupe whitelist add <player>
/antidupe whitelist remove <player>
/antidupe whitelist check <player>
/antidupe whitelist list
/antidupe opprot <add|remove|list>
/antidupe creativeprot <add|remove|list>
/antidupe verbosity <off|low|med|high>
/antidupe reload
/dupe
Permissions
antidupe.admin
antidupe.notify
antidupe.whitelist
antidupe.recovery
antidupe.rollback
antidupe.security
antidupe.dupe
antidupe.bypass
Recommended Deployment
Anti-Dupe requires Paper 1.21.x and Java 21.
For a new installation:
- Install the JAR and start the server once.
- Back up
plugins/Anti-Dupe/identity.key. - Configure trusted item-granting plugins.
- Begin with
mode: AUDIT. - Test your crafting, shops, rewards, containers, bundles, and network transfers.
- Run
/dupein a controlled environment to verify detection. - Switch to
mode: QUARANTINEwhen ready.
Never delete or replace identity.key during an upgrade. Network servers must share
the same key and remote database.
Detection Regression Suite
The 3.5 source project includes 46 automated tests covering:
- Legitimate and illegitimate quantity paths
- Inventory pickup/place conservation
- Trusted grants
- Signed-identity tampering and legacy migration
- Two-stage candidate confirmation
- Persistent database state across restart
- Idempotent transaction authorization
- Exclusive player leases
- Transfer hash matching
- Concurrent and replayed transfer claims
Build verification also checks that the deployable shaded JAR contains plugin.yml
and all required database drivers.
bStats Metrics
Anti-Dupe uses bStats plugin ID 25245 for anonymous usage and configuration statistics. Custom charts do not include player names, UUIDs, IP addresses, inventory contents, recovery data, coordinates, webhook URLs, whitelist entries, or trusted plugin names.
Global bStats controls are available through the standard bStats configuration.
!ads
