Jump to content
Sign in to follow this  
THEGordonFreeman

Is this the whole Exploit story?

Recommended Posts

WOW!  Some of this tracks with what we know is true.  WOW!  Every DayZ player should watch this.

 

But on the other hand, this guy is claiming that there are many, many mods on the workshop that undo the exploit fix that BI did, and it gives these exploiters access to your computer..... that is a BOLD and ALARMING claim, but I'd like to see proof of that.

Edited by THEGordonFreeman
  • Like 1

Share this post


Link to post
Share on other sites

@ImpulZ  Can you or someone from BI confirm or deny any of this?  Direct access to a computer from a mod sounds like a crazy claim.  But, the next question is if the exploit is fixed, can it be undone in a mod?

  • Like 1

Share this post


Link to post
Share on other sites

Arkensor responded in the comments for the video...

This video needs a lot of corrections: 1. Mods have no system access that could harm anyone. The only info that could he collected clientside that is not already known to the server is the users windows user name. But those are of no value to anyone. The only other thing mods can do us write files into the profile directory (meant for logs etc) which unless a user goes there to manually execute a trolling batch file would not do anything on its own. There is no danger. None of you who play modded dayz need to fear anything. Whatever you were told here is made up. 2. You accuse InclementDab to have malicious intend because he is on some kind of payroll. Too bad IT WAS ME who made those decisions - and I am not affiliated or close to ANY dayz server. I coordinated the feedback gathering and testing group with Dedmen. All admins of the modders discord including me pinged servers who sufferd from the issue AND we had some first hand trusted contact with. This was meant to keep out the hackers from sniffing on our fix discussion. I have contacted multiple servers but they did not was not partake and just wait for the fix to arrive or they were not affected. Yes Dab when asked also made suggestions who else we could ask but ultimately the selection was not under his sole control. Then it was also ME who banned MDC because he leaked the internal build to everyone. Dab was not even around when this happened. He was not banned to delay anything but because he broke our trust. We have done all that effort to make sure useful feedback reaches the correct people asap - which did succeed. Dedmen was tasked to look into the collected information because he's a skilled programmer who also had prior exposure to the existence or a similar bug in A3. It was the feedback provided though this effort that ended up finding the issue. The delay between finding the issue and the fix arriving on all platforms is just the usual production interval issues. There was a lot of communication needed at BI to fast lane the fix. You can all thank Dedmen for his commitment on fixing this. Also he and the other BI developers were in sole control when the fix comes out. Nobody, not even Dab or me could have made them not release it. 3. I understand the frustration of server owners and the consequent creation of the petition, but it was indeed a waste of time pretty much. The issue was known for months of not years before it. Could never be properly reproduced and without a special executable server logs would not provide any useful info. At the time of the petition creation the issue was however already investigated with new info that could finally narrow it down to unauthorised network messages. So even if the petition was not made, the issue would have been fixed and probably also in the same timeframe it ended up taking. Servers collaboration with cheaters is probably the only correct thing in this video. That is a real issue that most likely still exists - but any exploit that BI can fix they do fix. You just need to give them some proper into to work with and not just cry fix pls. They have even less info about an issue than the server owner, as they otherwise can only make guesses from the outside.

As I expected his claim about accessing computers with compromised mods is bogus.  But I disagree about the petition, it was meant to pressure as we all know BI doesn't exactly fix things in any kind of reasonable time, and when whole communities are being set on fire by a stupid exploit that should have never existed (7 years development and one month Beta, anybody?)  Bottom line, this should not have happened.

Edited by THEGordonFreeman

Share this post


Link to post
Share on other sites

The suggestion to replace the dev team at the end of the video is absurd.

There's a lot of money at stake and people can just do whatever.  It's a shame that there's no effective systems in place to mitigate cyber criminal behavior.   The problem is obviously way beyond Battleye and they're not held accountable. 

I guess the lesson here is to expect cheaters if you buy DayZ.

Share this post


Link to post
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×