Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

Does anyone have details about the perms bug/exploit?

Francis Chung
This sentence no verb.
Join date: 22 Sep 2003
Posts: 918
10-09-2006 19:22
Hi all :)

I was recently made aware of the permissions exploits that occured in a version of SL that was running last night. I've been trying to piece together what little bits of information I have.

The only posts I can find from the Lindens regarding this are here:
http://blog.secondlife.com/2006/10/09/second-life-open-outage-recap/
/139/e1/142156/1.html

I asked LL for more details here:
/139/28/142318/1.html

To summarize:

1) Items for sale->copy between 7:30pm Sunday and 8am Monday were sold fully permissive. Items that were in object contents retained their permissions, although you could still freely distribute copies of the entire object as well as their contents..

2) People could, and did, use this bug as an exploit to bypass permissions of items they had previously obtained. So, for instance, suppose I bought a shirt last year that was no-transfer. I could use this bug to give myself and my friends a boxed copy of said shirt.

3) Later on, LL went through and attempted to "fix" the affected items in the database. I am hearing reports that some (but not all) fully-permissive items reverted back to their "safe" state.

4) Copies of items that were made using this exploit will remain.

5) You can no longer create new items using this exploit.

Some of these details might be a bit vague, or entirely incorrect. Does anyone have any more details about this that they can share?
_____________________
--
~If you lived here, you would be home by now~
Cottonteil Muromachi
Abominable
Join date: 2 Mar 2005
Posts: 1,071
10-10-2006 01:27
Lets pretend it didn't happen. Okay? :D
Rica Wolfe
Registered User
Join date: 28 Dec 2004
Posts: 1
10-10-2006 02:01
Items set to sell as copy of rather than contents of were delivered full perms to the inventories of purchasers. The purchaser could then rez as many copies of the item as they liked, or send to friends as many copies of the item as they liked but the perms on the rezed copies would then be as the creator set them. The original purchaser was also able to pass as many items to friends from the orignal copy in inventory as they liked. The purchaser was able to change the perms of the original item in inventory, but once rezed the item would revert to the original perms set by the creator.
Items passed to another person arrived in their inventories with the perms set by the creator on the item originally. I am unsure if this is the case with items bought a year ago that were set to sell in a box 'sell copy of' rather than the 'sell contents' option, but I do know that items sold this way last night are still effected by the bug.
Usagi Musashi
UM ™®
Join date: 24 Oct 2004
Posts: 6,083
10-10-2006 02:01
From: Francis Chung

1) Items for sale->copy between 7:30pm Sunday and 8am Monday were sold fully permissive. Items that were in object contents retained their permissions, although you could still freely distribute copies of the entire object as well as their contents..



OMG that long of time!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! thats crazy and totally typical of occurance letting the bug continue that long! Thats Unreal!!!!!!! this is a joke right?! Oh please say its a joke! :confused:
Darkness Anubis
Registered User
Join date: 14 Jun 2004
Posts: 1,628
10-10-2006 04:16
I was given the Impression by a Linden that this bug only those items in sims that actually underwent the second rolling update. If your sim did not get the update (as ours did not) then you were unafected.

Was I told wrong?
_____________________
Johan Durant
Registered User
Join date: 7 Aug 2006
Posts: 1,657
10-10-2006 09:39
So this only affected items set for sale in the built-in way? Whew, then I'm safe, I use JEVN.
_____________________
(Aelin 184,194,22)

The Motion Merchant - an animation store specializing in two-person interactions
Lex Neva
wears dorky glasses
Join date: 27 Nov 2004
Posts: 1,361
10-10-2006 10:48
From: Johan Durant
Whew, then I'm safe, I use JEVN.


...I think that's the first time in history anyone's uttered that phrase.
Darkness Anubis
Registered User
Join date: 14 Jun 2004
Posts: 1,628
10-10-2006 10:59
From: Lex Neva
...I think that's the first time in history anyone's uttered that phrase.


Cleaning soda off my monitor. ;)
_____________________
Jopsy Pendragon
Perpetual Outsider
Join date: 15 Jan 2004
Posts: 1,906
10-10-2006 11:19
From: Rica Wolfe
The purchaser was able to change the perms of the original item in inventory, but once rezed the item would revert to the original perms set by the creator.


That's somewhat re-assuring at least. I don't mind a handful of lost sales due to a copy bug, so long as folks aren't out there using the exploit to peek at my code to mimic my works for their own profit.
Takuan Daikon
choppy choppy!
Join date: 22 Jun 2006
Posts: 305
10-10-2006 12:21
From: Jopsy Pendragon
That's somewhat re-assuring at least. I don't mind a handful of lost sales due to a copy bug, so long as folks aren't out there using the exploit to peek at my code to mimic my works for their own profit.


But I do think that's what people are most concerned with, although maybe the fact that someone can turn around and re-sell unlimited copies is right up on top as well (it was *full* perms? I thought so, anyways).
Stephanie Abernathy
Susan Ivanova Wannabe
Join date: 8 May 2006
Posts: 352
10-10-2006 15:48
Francis, i don't know it this will help you much. I was still in world when the grid went down, and stayed connected thru the whole event.

Linden took scripts offline shortly after the first incident. They stayed off till around 7:30 or so (sorry didn't pay attention to the clock, i had other concerns). Although official Linden in world messages said scripts were disabled, they came back up around 7:30pm SLT. I know, i tested with my own. My home security IM'd me when it came back online, which was shortly after my home sim was restarted.

I went Lucky Chair hunting with some friends and we won about 3 items. We spent maybe an hour, Lucky Chairing. Suddenly scripts stopped working again... no notice or reason. During that hour, Linden in world messages continue to say scripts were disabled. I would say that based on hindsight, Linden had discovered the permissions bug and had turned scripts back off at this point.

[Edit:] The chair scripts were intermittent. We found the scripts still off at Awesome Designs (no chairs worked), but they were on at Adored Clothing & Twistted Designs. I'm guessing that the scripts were turned on as each sim was restarted. But, not every script came back online. I have a stargate in my home sim, in my tiny shop, while my vendor scripts were working (and i have 2 different manufacturers of my vendors), the stargate was not working. And i tested that by tp'ing to a known stargate to verify that sim was up and that scripts were working in that sim. [end edit]

When scripts were taken back offline, tp's still worked so i tp'd around to test scripts in various sims using a personal radar (maybe it was just a few sims with them off). I found them off everywhere.

You have maybe a hour... 2 tops (because i'm not entirely certain of the times), where you are in danger of loss due to that bug.

I gave up and logged out around 11pm SLT. Scripts had not come back up when i logged out. During this this time, things were acting strangely. I watched the ground eat my friends (not lag... the ground became phantom momentarily) every now and then. It was kind of funny and we made a drinking game of it... take a drink every time our AV sank into the ground. hehe
Michi Lumin
Sharp and Pointy
Join date: 14 Oct 2003
Posts: 1,793
10-10-2006 20:08
Seems like some damage has been done by the fix, as well.

From what I can tell, if you had a mod/copy/notrans item attached to your avatar, or any mod/copy/notrans item with a nomod/copy/notrans script in it, the entire object became nomod after the 'fix'.


We've been getting lots of reports that our avatar heads have gone nomod. They're sold as mod/notrans, but have a script inside of them that is nomod. (This does not make the entire object nomod.)

So there are folks who have put hours of modifications into their avatars, and now those objects are 'locked" and cannot be modified any further.

The objects also go "creator (nobody)", which is an excellent joy for future IP issues, especially since LL has said that the creator tag is the holy grail when it comes to who created the content.

I think it's going to be a while until we see the full reach of this bug...
_____________________
Stephanie Abernathy
Susan Ivanova Wannabe
Join date: 8 May 2006
Posts: 352
10-11-2006 07:00
From: Michi Lumin
The objects also go "creator (nobody)", which is an excellent joy for future IP issues, especially since LL has said that the creator tag is the holy grail when it comes to who created the content.


Ack!!

I saw one of those in my own inventory last night! I was afraid to rez it to see what it was, for fear of triggering something bad. But at the same time, i know i didn't accept anything "given" to me, so i wasn't sure about deleting it either. I intended to rez it the next time i ran across a no-script zone to see what it was.
Llauren Mandelbrot
Twenty-Four Weeks Old.
Join date: 26 Apr 2006
Posts: 665
10-11-2006 07:31
I`ve been noticing lately that most [all?] of my items say "creator (unknown)" in inventory, and only reveal who created them in-world.
GeForce Go
Registered User
Join date: 8 Oct 2006
Posts: 26
10-11-2006 09:47
From: Lex Neva
...I think that's the first time in history anyone's uttered that phrase.

LOL }:-)>
Lex Neva
wears dorky glasses
Join date: 27 Nov 2004
Posts: 1,361
10-11-2006 10:45
From: Llauren Mandelbrot
I`ve been noticing lately that most [all?] of my items say "creator (unknown)" in inventory, and only reveal who created them in-world.


I think that might just mean that the object has items in its contents that have multiple different creators.
Llauren Mandelbrot
Twenty-Four Weeks Old.
Join date: 26 Apr 2006
Posts: 665
10-11-2006 11:08
From: Lex Neva
I think that might just mean that the object has items in its contents that have multiple different creators.
I don`t. I think I`ve seen this on no-content objects. I`m pretty sure I`ve seen it on objects with only a single creator of both the entire object and all contents. In any event, it should give me the same results from Properties in Inventory as it does in General in Edit. It doesn`t.
Dellybean North
Registered User
Join date: 8 May 2006
Posts: 321
10-11-2006 14:08
I think Llauren is right. I'm seeing items in my Inventory that I made from scratch myself just within the past few days, listed as Creator Unknown, both in Inventory and when rezzed out.