New godmode has fairly major exploit
|
|
Eata Kitty
Registered User
Join date: 21 Jan 2005
Posts: 387
|
07-31-2006 16:05
But obviously I can't really tell you what it is!
It doesn't allow theft and won't cause most residents problem but could cause some serious problems with scripting and is effective for griefing, I've had people test it on my own objects for verification.
|
|
Bedpan Unknown
Agent of Influence
Join date: 16 Nov 2005
Posts: 8
|
07-31-2006 16:29
this thread reminds me of a song:
I need to buy some CDs I need to buy some gum I mow the grass, I clean the house, I think I deserve some... some more allowance
I need more allowance, yodelayeoo I need more allowance, yodelayeoo I need more allowance, yodelayeoo Why? Because I do Yodelayeoo, I need more allowance Yodelayeoo, I need more allowance...
|
|
Jesse Malthus
OMG HAX!
Join date: 21 Apr 2006
Posts: 649
|
07-31-2006 16:31
From: Eata Kitty But obviously I can't really tell you what it is!
It doesn't allow theft and won't cause most residents problem but could cause some serious problems with scripting and is effective for griefing, I've had people test it on my own objects for verification. Erk. Make sure you get in direct contact with a Linden ASAP.
_____________________
Ruby loves me like Japanese Jesus. Did Jesus ever go back and clean up those footprints he left? Beach Authority had to spend precious manpower. Japanese Jesus, where are you? Pragmatic!
|
|
Ice Brodie
Head of Neo Mobius
Join date: 28 May 2004
Posts: 434
|
07-31-2006 16:31
It's been in older versions, a Linden should probobly be notified directly (as in IMing an online one)
|
|
Eata Kitty
Registered User
Join date: 21 Jan 2005
Posts: 387
|
07-31-2006 16:33
From: Jesse Malthus Erk. Make sure you get in direct contact with a Linden ASAP. Already done, but do we get banned for revealing it to them? 
|
|
Ice Brodie
Head of Neo Mobius
Join date: 28 May 2004
Posts: 434
|
07-31-2006 16:35
No, historically telling a Linden directly yeilds possible cash on first report, but that's iffy at any given time.
Saying it on the forums is not advised as then people can use it before LL can patch it.
|
|
Eata Kitty
Registered User
Join date: 21 Jan 2005
Posts: 387
|
07-31-2006 17:13
Security through obscurity sucks. If people don't know whats going on they could be majorly affected by an exploit.
|
|
Adam Zaius
Deus
Join date: 9 Jan 2004
Posts: 1,483
|
07-31-2006 17:38
From: Ice Brodie No, historically telling a Linden directly yeilds possible cash on first report, but that's iffy at any given time. Saying it on the forums is not advised as then people can use it before LL can patch it. L$10,000 for the first report -- send the bug report to [email]security@lindenlab.com[/email]
|
|
nimrod Yaffle
Cavemen are people too...
Join date: 15 Nov 2004
Posts: 3,146
|
07-31-2006 17:42
From: Adam Zaius L$10,000 for the first report -- send the bug report to [email]security@lindenlab.com[/email] Whhaattt, I reported a bug that let anyone make anything under 31 prims become physical and I got nothing! 
_____________________
"People can cry much easier than they can change." -James Baldwin
|
|
Eddy Stryker
libsecondlife Developer
Join date: 6 Jun 2004
Posts: 353
|
07-31-2006 18:44
This bug can be avoided by locking your object containing important scripts, and should be fixed in a server patch on Wednesday.
Oh, and it has been known for some time now, the L$10k is only for zero-day exploits.
_____________________
http://www.libsecondlife.org From: someone Evidently in the future our political skirmishes will be fought with push weapons and dancing pantless men. -- Artemis Fate
|
|
nimrod Yaffle
Cavemen are people too...
Join date: 15 Nov 2004
Posts: 3,146
|
07-31-2006 20:12
Oh man, this is way too easy. LL, please check his bug report and fix his now!!
_____________________
"People can cry much easier than they can change." -James Baldwin
|
|
Nepenthes Ixchel
Broadly Offended.
Join date: 6 Dec 2005
Posts: 696
|
07-31-2006 20:22
What does the bug allow? Letting us know what the bug does (without knowing how to actually do it) lets us take some sort of action if needed.
I assume this has something to do with scripted objects?
|
|
nimrod Yaffle
Cavemen are people too...
Join date: 15 Nov 2004
Posts: 3,146
|
07-31-2006 20:23
From: Nepenthes Ixchel What does the bug allow? Letting us know what the bug does (without knowing how to actually do it) lets us take some sort of action if needed.
I assume this has something to do with scripted objects? Hmm, any object really. Can't say what it does because it's so obvious.
_____________________
"People can cry much easier than they can change." -James Baldwin
|
|
Cristiano Midnight
Evil Snapshot Baron
Join date: 17 May 2003
Posts: 8,616
|
07-31-2006 20:46
From: Nepenthes Ixchel What does the bug allow? Letting us know what the bug does (without knowing how to actually do it) lets us take some sort of action if needed.
I assume this has something to do with scripted objects? Those who do that are rewarded with suspensions.
_____________________
Cristiano ANOmations - huge selection of high quality, low priced animations all $100L or less. ~SLUniverse.com~ SL's oldest and largest community site, featuring Snapzilla image sharing, forums, and much more. 
|
|
Ice Brodie
Head of Neo Mobius
Join date: 28 May 2004
Posts: 434
|
07-31-2006 22:19
If a report's been filed, give the SL# bug number to help them figure out what bug you're complaining about.
|
|
Moonshine Herbst
none
Join date: 19 Jun 2004
Posts: 483
|
08-01-2006 07:29
Ok, I've had some issues with some of my items today, issues I've never experienced before. I read this thread earlier, so I suspected they were connected. Installed God Mode, and after some fiddling, YES!! This problem must be fixed asap! Thousands upon thousands of objects in world can be critically harmed with this. We're talking millions of L$ in all kinds of industries. Merchants, landlords, and much more! I can't go into more details, given the seriousness of the problem, and LL's hang to ban the messenger. LOCK ALL your important scripted objects! ALL OF THEM! That will stop the problem for now. Detailed bug report sent, with plea to fix it ASAP. Bug report: #366719
|
|
Wendel Gascoigne
Registered User
Join date: 19 May 2005
Posts: 226
|
08-01-2006 07:35
From tomorrow onwards, make sure any such exploit is reported as such and not as a bug and it will be brought to the immediate attention of a Linden: /3/bc/125920/1.htmlWendel
|
|
Infiniview Merit
The 100 Trillionth Cell
Join date: 27 Apr 2006
Posts: 845
|
08-01-2006 07:38
From: Eata Kitty But obviously I can't really tell you what it is!
It doesn't allow theft and won't cause most residents problem but could cause some serious problems with scripting and is effective for griefing, I've had people test it on my own objects for verification. L$ Bounty on Exploit Reporting Hotline
|
|
Cindy Claveau
Gignowanasanafonicon
Join date: 16 May 2005
Posts: 2,008
|
08-01-2006 07:39
From: Moonshine Herbst LOCK ALL your important scripted objects! ALL OF THEM! That will stop the problem for now. What about scripts in items you've already sold? Need I worry about those?
|
|
Moonshine Herbst
none
Join date: 19 Jun 2004
Posts: 483
|
08-01-2006 07:41
From: Cindy Claveau What about scripts in items you've already sold? Need I worry about those? As long as the object is locked, you're safe. Your customers should lock their objects too. I'm sorry i cant get into more details. Ive also notified the only tech Linden online, Jeff, hoping he will see the seriousness of the problem.
|
|
Sitting Lightcloud
Registered User
Join date: 13 May 2004
Posts: 109
|
08-01-2006 08:33
Ok, so I'm wondering if anyone with god mode can modify my scripts since there is this MAJOR EXPLOIT when using God Mode. Then I wonder if maybe some people wonder, hey, major exploit... let's go see what I can do, maybe I can steal someone's money or delete someone's objects, I sure could use some $$$$ This is why you shouldn't report an exploit here, it makes more harm than good. http://blog.secondlife.com/2006/07/31/new-express-exploit-reporting-feature-and-l-bounty/ God mode should be banned and I don't see why LL put up with ppl using it. It should report the ones using it and they should get suspended. People who use it don't realize that any 'godmode' program itself can be doing anything it wants on your computer, record cc-info etc. If there's functions that are helpful in god mode they should be added to the UI not accessed through a third party program. just my 2 cents
|
|
windozer Vargas
Registered User
Join date: 6 Feb 2006
Posts: 99
|
08-01-2006 08:51
i know what the bug is,it was in the previous god mode patch,its been reported several times,hopefully tomorrow will be fixed...but LOCK YOUR SCRIPTED OBJECTS!
|
|
Tre Giles
Registered User
Join date: 16 Dec 2005
Posts: 294
|
08-01-2006 09:12
From: Moonshine Herbst Ok, I've had some issues with some of my items today, issues I've never experienced before. I read this thread earlier, so I suspected they were connected. Installed God Mode, and after some fiddling, YES!! This problem must be fixed asap! Thousands upon thousands of objects in world can be critically harmed with this. We're talking millions of L$ in all kinds of industries. Merchants, landlords, and much more! I can't go into more details, given the seriousness of the problem, and LL's hang to ban the messenger. LOCK ALL your important scripted objects! ALL OF THEM! That will stop the problem for now. Detailed bug report sent, with plea to fix it ASAP. Bug report: #366719 OMFG!!!!! MY... its.... worked so hard on it.... gone..... GONE!!!! Meh, I make a new one. Thank god I didn't rez my server yet! Stupid God Mode... why do we even have a god mode? We don't need a god mode!
|
|
Schwanson Schlegel
SL's Tokin' Villain
Join date: 15 Nov 2003
Posts: 2,721
|
08-01-2006 09:26
It's a pretty major exploit. It's already caused me alot of grief over the last few days. LL needs to fix this asap.
|
|
Moonshine Herbst
none
Join date: 19 Jun 2004
Posts: 483
|
08-01-2006 09:28
I think they should fix it ASAP. I've had 10+ objects affected maliciously by this today, and I've found out that others have too the last few days, probably from competitors without moral. The "attacks" have very specific targets, aimed to hurt my business. Luckily, on my stuff (out in the public) it only caused a temporary problem. If this gets too widespread, the damage can be huge, especially on some types of objects. IMHO this is important enough to fix it NOW. It is very, very disturbing to hear that this has been known by LL for a long time. I hope this isn't true.
|