Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

Self replicating prim attack - don't rez unknown objects!

Phoenix Psaltery
Ninja Wizard
Join date: 25 Feb 2005
Posts: 2,599
09-18-2006 21:47
For anyone who doesn't seem to understand what's going on, it appears that objects are being given to group members by unknown individuals, which self replicate when they are rezzed.

PLEASE, DO NOT REZ ANY OBJECTS THAT YOU ARE GIVEN BY SOMEONE YOU DO NOT KNOW. Treat them EXACTLY like you would an unknown e-mail attachment -- delete them.

P2

_____________________
:cool:
Taco Rubio
also quite creepy
Join date: 15 Feb 2004
Posts: 3,349
09-18-2006 21:48
From: Phoenix Psaltery
For anyone who doesn't seem to understand what's going on, it appears that objects are being given to group members by unknown individuals, which self replicate when they are rezzed.

PLEASE, DO NOT REZ ANY OBJECTS THAT YOU ARE GIVEN BY SOMEONE YOU DO NOT KNOW. Treat them EXACTLY like you would an unknown e-mail attachment -- delete them.

P2




THIS IS NOT A QUESTION! :mad:
_____________________
From: Torley Linden
We can't be clear enough, ever, in our communication.
Sansarya Caligari
BLEH!
Join date: 25 Apr 2005
Posts: 1,206
09-18-2006 21:49
From: Taco Rubio
THIS IS NOT A QUESTION! :mad:


<3 Taco
_____________________
Phoenix Psaltery
Ninja Wizard
Join date: 25 Feb 2005
Posts: 2,599
09-18-2006 21:50
From: Taco Rubio
THIS IS NOT A QUESTION! :mad:


Oops. Scuse me.

For anyone who doesn't seem to understand what's going on, it appears that objects are being given to group members by unknown individuals, which self replicate when they are rezzed.

WOULD YOU PLEASE NOT REZ ANY OBJECTS THAT YOU ARE GIVEN BY SOMEONE YOU DO NOT KNOW, and treat them EXACTLY like you would an unknown e-mail attachment -- delete them, please?


[Better, Taco?]

P2
_____________________
:cool:
Taco Rubio
also quite creepy
Join date: 15 Feb 2004
Posts: 3,349
09-18-2006 21:52
What a great question!

Yes I will not. And I suggest you don't either!

Please feel free to im me in what's left of the world with any further questions!
_____________________
From: Torley Linden
We can't be clear enough, ever, in our communication.
Flavian Molinari
Broadly Offensive Content
Join date: 1 Aug 2004
Posts: 662
09-19-2006 04:11
Is this the objects Prok made?
_____________________



Never mind the Bollox here is Second Citizen!
Lewis Nerd
Nerd by name and nature!
Join date: 9 Oct 2005
Posts: 3,431
09-19-2006 04:17
From: Flavian Molinari
Is this the objects Prok made?


A known fault of the SL tracking system is that if avatar A gives avatar B an object, resizes and retextures it so that bears no resemblance ot the original object, then it still shows avatar A as the creator.

You could give me a chair, which I turned into a self replicating 10ft penis, and it would show you as the object owner and 'responsible' for the grid crash.

The person responsible for the attack yesterday afternoon no longer appears in 'search' - that was the owner of the objects, although I don't know who the creator was. I believe the objects were 100% alpha transparent anyway. I just kept hitting auto return on other people's objects, as they kept piling up... the less there are, the slower they replicate, so I hope my minor input helped reduce a little of the load. I noticed little to no performance degredation in Rosieri as I happened to be 'on it' as it was happening. The first thing I knew about it was when my auto greeter welcomed "object" to the Stratics Headquarters as I was on the second floor building.

Lewis
_____________________
Second Life Stratics - your new premier resource for all things Second Life. Free to join, sign up today!

Pocket Protector Projects - Rosieri 90,234,84 - building and landscaping services
Usagi Musashi
UM ™®
Join date: 24 Oct 2004
Posts: 6,083
09-19-2006 04:27
I like alittle LESS caps Thank you very much :rolleyes:
Bosozoku Kato
insurrectionist midget
Join date: 16 Jun 2003
Posts: 452
09-19-2006 05:21
From: Lewis Nerd
A known fault of the SL tracking system is that if avatar A gives avatar B an object, resizes and retextures it so that bears no resemblance ot the original object, then it still shows avatar A as the creator.

You could give me a chair, which I turned into a self replicating 10ft penis, and it would show you as the object owner and 'responsible' for the grid crash.

This isn't, in all cases, true (certainly in most cases it is true). Because I heard about an owner/creator of some self-replicating "goo" being an upstanding citizen of SL (see post in scripting tips forum) I set about tonight proving that the Creator/Owner can be spoofed.

This venture took all of about 15 minutes to figure out, script, execute, and oogle over. (however it'd probably take a little more time for a real malicious act to accomplish, still once set it's a simple matter of a few minutes work to launch something capable of what we saw yesterday -- and hide your identity).

Suffice it to say... Not that I would, but I could (and have, in a controlled manner of course) make a scripted self-replicating widget run wild, giving itself to any avatar it can find, rez'n copies of itself, etc and thus spreading like wildfire -- with absolutely no trace to the identity of the malicous person. Not in the prims, not in the scripts. In fact, all "blame" (Creator/Owner) goes to other (innocent) people! Fun. :p Naturally I emailed my findings to LL (I expect the standard auto-reply within a few days).
_____________________
float llGetAFreakingRealTimeStampSince00:00:00Jan11970();
Yiffy Yaffle
Purple SpiritWolf Mystic
Join date: 22 Oct 2004
Posts: 2,802
09-19-2006 05:29
to quote myself from teh linden answeres thread i made

I think after the grid attack tonight someone has attempted to hack my account. Please view the JPG file by clicking here (it is quite large to post onto a forum). Someone or some object in-world spammed my gmail account with about 120 emails containing nothing but giberish. The UUID key of whoever or whatever did this is listed in the header of each email. I emailed support about this already.

As a follow up thismorning, when i logged in i found these were inventory objects passed to me by one of the attackers. IM me for persons name

The self replicator kept renaming it's self to bypass the goo fence and kept giving copies of its self to people.
_____________________
SuezanneC Baskerville
Forums Rock!
Join date: 22 Dec 2003
Posts: 14,229
09-19-2006 05:46
From: Bosozoku Kato
I emailed my findings to LL (I expect the standard auto-reply within a few days).
Sounds like it might should have a EXPLOIT style bug report and filed or email to brent.
_____________________
-

So long to these forums, the vBulletin forums that used to be at forums.secondlife.com. I will miss them.

I can be found on the web by searching for "SuezanneC Baskerville", or go to

http://www.google.com/profiles/suezanne

-

http://lindenlab.tribe.net/ created on 11/19/03.

Members: Ben, Catherine, Colin, Cory, Dan, Doug, Jim, Philip, Phoenix, Richard,
Robin, and Ryan

-
Mia Winthorpe
Pirttihirmu
Join date: 2 Apr 2006
Posts: 128
09-19-2006 05:53
Here's a question, honestly!

If we were to receive such an object to our inventory. Should we just delete it, or do LL need it for veryifying, inspecting or catching the jerk? I only just received e-mail that someone sent me something in-world, login to accept it blah blah..

So, do I just delete it, or save it for further inspection?

I'd prefer sending it back to that person, with a bug in it that will destroy his whole inventory, everything he has ever built, rob him of all his money, make him stark naked with words "I'm an a**hole" pasted on his skin. Then let all residents use him as a target practice, trying out new weapons on him...

*Gathers her composure* Or just cut his balls off.
_____________________
*~Mia~*

That which doesn't kill you, makes you stronger.
Bosozoku Kato
insurrectionist midget
Join date: 16 Jun 2003
Posts: 452
09-19-2006 05:57
From: SuezanneC Baskerville
Sounds like it might should have a EXPLOIT style bug report and filed or email to brent.


Alas, support@sl is the only email I know of. :p I couldn't tell you a single Linden's actual responsibilities. Nor do I have a clue where one might find email addresses to email anyone in particular (and I won't use the crappy bug report dialog in game). So, support@ can figure out where to direct my email.

I did try Live Help, first time I've used that. Probably the last time I'll use it too.
_____________________
float llGetAFreakingRealTimeStampSince00:00:00Jan11970();
Bosozoku Kato
insurrectionist midget
Join date: 16 Jun 2003
Posts: 452
09-19-2006 06:01
From: Mia Winthorpe
Here's a question, honestly!

If we were to receive such an object to our inventory. Should we just delete it, or do LL need it for veryifying, ...


I don't know about sending it to a Linden (first you'd want to rez it to know it's malicious, wouldn't you?).

But more to your question, I'd say treat it like you do email. Do you open all email attachments you get? Or just the ones you expected and/or from trusted friends? I get a few things tossed my way from strangers. Most I open, cuz well unlike my computer and email attachments, I'm not too worried over SL grief attacks. It's annoying, but it's not gonna kill me.
So -- use yer noodle (brain). Something you didn't expect from someone/some object you don't know about? Delete.

--Bos
_____________________
float llGetAFreakingRealTimeStampSince00:00:00Jan11970();
Arianna Oranos
Registered User
Join date: 9 Sep 2006
Posts: 44
09-19-2006 09:29
I'd just send the suspicious object to a Linden for investigation or discard it completely.
Odysseus Fairymeadow
Registered Explorer
Join date: 18 May 2006
Posts: 44
09-19-2006 10:12
Umm, if you are going to rez such an unknown object, please make sure that you are in a build/noscript zone with a nice strong roof over your head, otherwise it could get out of control *really* quickly and cause a new grid infection.

Unfortunately I don't know too many build/norez areas to use. I heard about an "unpack" zone in a store, but rezzing a sim bomb in the middle of a store is not exactly good for my heart...
Jesse Malthus
OMG HAX!
Join date: 21 Apr 2006
Posts: 649
09-19-2006 10:18
From: Odysseus Fairymeadow
Umm, if you are going to rez such an unknown object, please make sure that you are in a build/noscript zone with a nice strong roof over your head, otherwise it could get out of control *really* quickly and cause a new grid infection.

Unfortunately I don't know too many build/norez areas to use. I heard about an "unpack" zone in a store, but rezzing a sim bomb in the middle of a store is not exactly good for my heart...

A friend of mine has a "hotbox" where he goes to unpack/rez things he doesn't know about.
_____________________
Ruby loves me like Japanese Jesus.
Did Jesus ever go back and clean up those footprints he left? Beach Authority had to spend precious manpower.
Japanese Jesus, where are you?
Pragmatic!
Kokoro Fasching
Pixie Dust and Sugar
Join date: 23 Dec 2005
Posts: 949
09-19-2006 10:29
It is really sad that people are reaching this point. The reason I say this is for the last several months I have greatly enjoyed handing out Cuddle Kittens. You wear them, and it has a animation where you are rubbing and cuddling the kitten.

These are not even items that I have created - I puchase them and hand them out free simply so that everyone I meet has at least one drama free source for hugs.

But from what I am see here, if I was to hand these to anyone so far in this thread, they would simply be deleted.
Rose Karuna
Lizard Doctor
Join date: 5 Jun 2004
Posts: 3,772
09-19-2006 11:53
From: Kokoro Fasching
It is really sad that people are reaching this point. The reason I say this is for the last several months I have greatly enjoyed handing out Cuddle Kittens. You wear them, and it has a animation where you are rubbing and cuddling the kitten.

These are not even items that I have created - I puchase them and hand them out free simply so that everyone I meet has at least one drama free source for hugs.

But from what I am see here, if I was to hand these to anyone so far in this thread, they would simply be deleted.


Kokoro - ask people if they want one before you drop one in their inventory and tell them what it is so that way they know it's not something bad. It's sad that it's come to this, but it has. :(
_____________________
I Do Whatever My Rice Krispies Tell Me To :D
Cage Mandala
Registered User
Join date: 13 Jan 2004
Posts: 36
Hmmm
09-19-2006 12:01
A chair that doubles as a 10ft penis i see a new sex toy for the market thats a good idea now for a name hmmmm Sit on my big 10 ft? Might as well make fun of all of this lindens wont really do a damn thing except keep booting us out of the game lol
SuezanneC Baskerville
Forums Rock!
Join date: 22 Dec 2003
Posts: 14,229
09-20-2006 00:28
From: Bosozoku Kato
Alas, support@sl is the only email I know of. :p I couldn't tell you a single Linden's actual responsibilities. Nor do I have a clue where one might find email addresses to email anyone in particular (and I won't use the crappy bug report dialog in game). So, support@ can figure out where to direct my email.

I did try Live Help, first time I've used that. Probably the last time I'll use it too.


The Linden staff emails use [email]firstname@lindenlab.com[/email]

Torley is [email]torley@lindenlab.com[/email], Brent is [email]brent@lindenlab.com[/email], etc.

The bug report filer inworld is said to contact Brent Linden in realtime if filled out properly for an exploit. Note that the problem needs to be an exploit by Brent's definition. You can find every post that Brent has made in the forums as well as on the blog site quite easily.
_____________________
-

So long to these forums, the vBulletin forums that used to be at forums.secondlife.com. I will miss them.

I can be found on the web by searching for "SuezanneC Baskerville", or go to

http://www.google.com/profiles/suezanne

-

http://lindenlab.tribe.net/ created on 11/19/03.

Members: Ben, Catherine, Colin, Cory, Dan, Doug, Jim, Philip, Phoenix, Richard,
Robin, and Ryan

-