Join our Discord Channels!
Join our Steam Groups! Image TacBF Mod & TacBF Event Notifications.
@CBA_A3 & TacBF updated. | Get TacBF Launcher!
Recent updates applied: @CBA_A3 3.3.1-170504, @TacBF 3.24.10. (13 May 2017)
Image $ Please donate a little, to keep server. - Read more...

Arma3 exploit allows arbitary acess to files on your computer

Anything other than TacBF talk.

Alan
Community Confidant
Community Confidant
Posts: 805
Joined: 20 Jan 2014, 13:36
In-game Name:

Re: Arma3 exploit allows arbitary acess to files on your computer

Postby Alan » 29 Aug 2015, 18:11

From what I can make out this vulnerability can only happen if the server admin is actively being an asshole and/or the server allows the client to execute malicious code server-side. Since Gunther is not a asshole, and since we have the strictest signature checks enabled on our server, (meaning that a guy with a malicious mod is not getting on the server) I really really doubt there is any reason to worry playing on our server.

hiddengearz
Community Confidant
Community Confidant
Posts: 720
Joined: 23 Jan 2013, 17:00
In-game Name:

Re: Arma3 exploit allows arbitary acess to files on your computer

Postby hiddengearz » 29 Aug 2015, 22:05

Ya not so much tacbf but any server you don't trust. I'm sure there are many people in the community who jump on random servers to play missions for fun so you should be aware of this exploit.

Schadler17
Global Moderator
Global Moderator
Posts: 1180
Joined: 16 May 2015, 13:26
In-game Name: Schadler17

Re: Arma3 exploit allows arbitary acess to files on your computer

Postby Schadler17 » 29 Aug 2015, 22:24

Yeah basically until this is patched, don't join any un-trusted servers. Or any servers that pop up after this was announced.
Servers without strict mod restrictions are also at risk. So the servers that allow any mods are very risky, as the client can tell the server to do almost anything through mods/scripts. Although its limited to what they can do, there are still some malicious things they can pull off.
Do I care if you hate me? Do you wanna know the truth?
C'est la vie, adios, good riddance, f*** you.

Wake
Ranked
Ranked
Posts: 64
Joined: 13 Dec 2013, 20:32
In-game Name:

Re: Arma3 exploit allows arbitary acess to files on your computer

Postby Wake » 30 Aug 2015, 17:27

I am pretty confident that this is really nothing of concern and was an overreaction from Noubernou.

The exploit can only occur in Single Player missions and would be very difficult to abuse without the user constantly receiving error pop ups. It has to do with allowing relative and absolute paths in include calls in a single player missions. Anything that is a multi player mission only allows includes on files that are in the same directory or are a subdirectory of the mission.

If you look in the reddit thread you can see killzone_kid and Dwarden talk about it, and how it really isn't abusable in the way that Noubernou describes.


Return to “Off-Topic”

Who is online

Users browsing this forum: No registered users and 1 guest

cron