[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Source is So Poorly Programmed It Allowed Hackers To Access Your

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 61
Thread images: 6

File: Valve hack tf2 community.webm (488KB, 480x288px) Image search: [Google]
Valve hack tf2 community.webm
488KB, 480x288px
Hackers hijacked PCs using Source Engine kill animation exploit

>Counter-Strike: Global Offensive, Team Fortress 2, Portal 2 and other Source Engine games were all affected by a particularly nasty exploit until recently. Basically, by uploading custom assets into a custom map, hackers could use them to trigger a "buffer overflow vulnerability" which resulted in the victim PC being open to remote code execution.

>In other words, merely shooting at an enemy could cause your machine to be remotely hijacked. The exploit was identified by One Up Security (via Motherboard) who notified Valve.

>"Valve's Source SDK contained a buffer overflow vulnerability which allowed remote code execution on clients and servers," OUP's statement reads. "The vulnerability was exploited by fragging a player, which caused a specially crafted ragdoll model to be loaded.

*breathes in*

AHHAHAHAHAHAHHAHAHAHAHHAHAHAHAHHAHAHAHAHAAAHAHAHHAHAHAH

Defend this Valvefuccbois
>>
This is old faggot.
>>
Is global rule 6 enforced on these stupid breathes in threads? Inb4 im a valve fanboy.
>>
>>385104998
Valve cuckboy found
>>
>>385105107
it was patched stupid
>>
>>385105210
>Exploit found in Windows
>OMG FUCK YOU M$ DIE YOU SHITTY COMPANY IM SWITCHING TO A HOMO DISTRO OF LINUX

>Exploit found in Source/Steam
>YAAAAAAAAAS VALVE QUEEN SLAY WE STILL LOVE YOU EVEN IF ALL MY STUFF WAS STOLEN
>>
>>385105210
I don't think you understand. That doesn't erase it from ever happening, like you seem to be suggesting.
>>
many game engines are not written with security in mind, it's not indicative of them being "poorly programmed", they just don't see it as an issue during development

i can guarantee that any given game engine will have a number of RCEs just waiting to be found
>>
>>385105397
Source engine is well over a decade old and has received numerous updates. This is a direct "indication" of complete incompetence.
>>
> In other words, merely shooting at an enemy could cause your machine to be remotely hijacked. The exploit was identified by One Up Security (via Motherboard) who notified Valve.

Can't get hacked if you don't get hit.

Git gud fgt
>>
>>385105397
Hang on, I'm sure there's an exploit for Unity that would allow me to rape you with my penis through the internet...

Oh wait
>>
File: 1449356535643.jpg (7KB, 300x185px) Image search: [Google]
1449356535643.jpg
7KB, 300x185px
>>385105494
this
>>
File: this goes on for 3 episodes.gif (715KB, 400x300px) Image search: [Google]
this goes on for 3 episodes.gif
715KB, 400x300px
>>385104935
>1v1
>winner gets control of the losers pc
>>
>>385105478
This post is direct indication that you have no clue what you're talking about and are purely getting a pathetic rise out of shitposting about a decade old engine (already patched) from a company I can only assume touched you in a special place.

Get a fucking life.
>>
>>385105658
>(already patched)
Only took 13 years. You sound pretty upset? Maybe you should learn to look at things objectively instead of like a manchild.
>>
>>385105658
Hear no evil, speak no evil, see no evil

That's the fanboy motto
>>
>>385104935
>by uploading custom assets into a custom map
so don't play on shaggy community servers you dillweed
>>
>>385105774
only took 13 years to be detected
>>
>>385105478
im not a valve fanboy, i know source is a joke at this point in terms of tech and capabilities

however it's pretty disingenuous to suggest that number of patches is equal to quality
game engines are huge messes of code, it's hardly surprising that something that has been used as long as source receives updates

>>385105527
are you five years old? "i can't see something so it doesn't exist"
look up the definition of a zero day for a start, or don't talk about things you don't understand
>>
>>385105774
>>385105836
One more time boys, with passion!
>>
>>385104935
>Source is So Poorly Programmed
*Was so poorly programmed
>>
>>385105836
not him, but do you actually believe that someone's a fanboy of a fucking engine of all things? also, Valve fanboys don't even exist anymore. do you want to discuss this thing or do you just want to have a reskinned console war thread where you can spout your favorite insults? yes I am a valve fanboy, OP, whatever floats your boat
>>
>>385105853
By Valve or the hackers? This could have been abused without anyone knowing for years.
>>
>>385104935
That's not true, there are no hackers in video games, you're just bad.
>>
File: Untitled-1.png (132KB, 532x536px) Image search: [Google]
Untitled-1.png
132KB, 532x536px
>>385104935
>merely shooting at an enemy could cause your machine to be remotely hijacked.
unless these people are looking for a folder containing 78 gigabytes of furry porn they're not going to find anything
>>
>>385104935
>the source engine is shit
This hasn't been news since 2006, where were you.
>>
>>385106007
>whataboutism
the hackers. do you have any evidence people were abused by this exploit?
>>
BLIZZARD ALWAYS WINS BABY.
>>
>if you die, you get hacked

This seems like a pretty cool concept for a game
>>
>>385106007
keep in mind that this exploit was found by security researchers and patched by valve before it was made public:
https://oneupsecurity.com/research/remote-code-execution-in-source-games

it's possible that "hackers" had been using it for some time but unlikely that no one would have noticed up until now
>>
>>385104935
>connect to some random server and let it download 4 gigabytes of non-official files onto your pc
>what the FUCK valve broke my comptuder
retards like you must be why they removed the server browser from the main menu
>>
>>385106007
>zero day located by a security company and sold to developer, white hat no matter how you slice it
you realize this shit happens all the time to every internet-utilizing business, right? how do you think these security companies stay in business? only reason this had an article written about it is because its funny that the trigger is getting fragged in an online game
>>
>>385104935
>lose the game
>lose computer

I don't expect a casual like you to understand.
>>
>>385104935
>Defend this Valvefuccbois

Literally nobody is defending Valve anymore.
They haven't made a game in years.
They can barely even be considered a dev anymore
>>
>>385106342
The server browser is on the main menu
>>
>>385106085
This level of delusion is absolutely insane. Of course not because nobody would have any fucking clue they were compromised let along from a video game.
>>
>>385106608
>hackers may or may not have used an exploit to remotely execute code on people's machines
>no one's identity's been stolen, no one's CC details leaked, no spyware found
>no evidence whatsoever that this has ever happened
>other people are delusional for thinking maybe it never happened
the electronics you used today have hundreds if not thousands of zero-day exploits that white hats haven't discovered yet, some of which ARE in the hands of black hats. by your logic you should just move to that cabin off the grid, so, bye.
>>
>>385106608
>nobody saw command prompt open and tell them they were installing a virus
>>
>>385104935
so does this affect the titanfall games too
>>
>>385106807
Nobodies a fanboy of credit card companies like they are of Valve
>>
>>385104935
>defend this
even if i wanted to fellate gabe until he passed out, why would i defend something that is clearly bad you autistic fuck.
who is this imaginary person that you fuckers have invented, that completely denies any and all fuckups from the video game company he likes? this person doesnt exist. this is shitposting about a type of person that isnt real. do we really need more visual hiv shitting up this cesspool of a board
>>
>>385104935
>t. Overwatch fanboy

Just get over the fact your game is casual garbage and go away
>>
>>385107156
"Defend this" is standard reply bait procedure in /v/. This board moves so fast that people here compete for those precious (You)'s by baiting as many people as possible with their shitty posts.
>>
Nothing new, everybody know that Valve are incompetent hacks.
>>
File: 1466283381657.png (54KB, 248x189px) Image search: [Google]
1466283381657.png
54KB, 248x189px
>>385104935
>being concerned
look at this shitter, just don't die faggot
>>
>>385104935
Reminds me of Arby n the Chief, the storyline where hackers ban the console of whoever they kill.
>>
>>385104935

>If you die your whole PC gets fucked

Damn. Sounds intense.
>>
there are still arbitrary file execution exploits or whatever it's called by changing the directory that sprays download to (valve ""patched"" it but people found workarounds on the first day)

fun fact, every spray you've ever seen in a game, official or custom server regardless, automatically gets download onto your pc in game/vgui/temp/

the exploit involves changing that location to windows startup and dropping whatever the hell they want in there
>>
>>385105309
delete
>>
>>385106216
I'd play that.
with the power cable wrapped around my ankle for quick abort
>>
>>385107868
>In other words, merely shooting at an enemy could cause your machine to be remotely hijacked

can you read?
>>
>>385106216
>Not already playing Lose/Lose and lostboy
>>
File: 1492799932332.jpg (119KB, 730x1005px) Image search: [Google]
1492799932332.jpg
119KB, 730x1005px
>>385110298
>lostboy
>>
>>385107007
nobody is a fanboy of (you)
so kill yourself
>>
>>385109351
Sunrise Hackaton
>>
>>385105494
Now this is extreme hardcore gaming, casuals don't even attempt, its not just your virtual life and k/d on the line, but your entire PC, talk about high stakes gaming.
>>
Now imagine playing against Kim
>>
>>385104935
Another reason besides furry mlp shit why I laugh at any faggot that seriously complains about the lack of community servers in Overwatch.
>>
>>385106069
yiff in hell
>>
>>385105478
They are also the only games that degenerate slavs play.
>>
>>385104935
It is impossible to create that much C code and keep it secure. Here is a great course about computer security if anyone is actually interested in the topic and knows how to program:

https://ocw.mit.edu/courses/electrical-engineering-and-computer-science/6-858-computer-systems-security-fall-2014/
Thread posts: 61
Thread images: 6


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.