Posts: 21
Threads: 2
Joined: Jul 2017
Reputation:
0
Someone already told this,but there is BIG security issue bout new update.When downloading server-side model,there is chance to download some viruses from server(and if u wonderin why someone will put viruses in server,well,it dont have to be scripters.Some hackers could hack server and get into server files which allows them to put viruses in filrs.I know Kalcor said bout dis,but there is a issue.
And even if he fixes dat with some type of file extension check,hackers could perform RTLO attack(changing file extension but the virus is still executable).
Posts: 6,242
Threads: 8
Joined: Jun 2008
This has got to be the most terrible hype post ever...
You've posted this in Scripting Help, rather than bug reports, with no information other than someone has said that there's an exploit.
The person you are coining had his thread 'deleted', yet it's likely that it got hidden so no-one can see the method...
Seriously though, why'd you even post this here?
Posts: 805
Threads: 75
Joined: Aug 2013
Reputation:
0
Can you fucking stop spreading this? you're legit cancer dude, can't you simply report it to the support team? retard
Posts: 320
Threads: 23
Joined: Aug 2012
Reputation:
0
How can he download virus if files are only downloaded with formats .txd and .dff, its not like an exe so u can extract it..+ files are being called only when u enter server via gta_sa.exe probably.. stop spreading shit around
Posts: 21
Threads: 2
Joined: Jul 2017
Reputation:
0
But the SAMP will think that is .dff or .txd file but it is .exe so it will be opened and...BOOM!
I'll try to make my application and then perform a RTLO and see if da theory is right
Posts: 38
Threads: 4
Joined: Feb 2014
Reputation:
0
Anyway if you do a "RTLO" (right-to-left unicode char) you won't be able to do anything. The client won't magically open .exe files only because has a .exe extension.
Maybe an buffer overflow can be exploited (be honestly, if you install a bad skin, gta will crash).
Best regards.
Posts: 120
Threads: 37
Joined: Sep 2016
Reputation:
0
We need KYE here :P
No one is crazy enough to test this :P
Posts: 457
Threads: 7
Joined: Jul 2017
if you are scared that much, buy youself an anti virus, and stop using free/cracked ones
Posts: 21
Threads: 2
Joined: Jul 2017
Reputation:
0
I will test it,but i will make a simple batch file which create a notepad file(or msgbox) with some text and change extension and then put into the localhost 0.3.8 server and test it.
Posts: 21
Threads: 2
Joined: Jul 2017
Reputation:
0
Yeah
And that can be anything.Even .bat file with command format c
And u can say goodbye to ur system...
And yeah,i cant test it now,so i will try this tommorow
And EVERYTHING whats here till testing is just a theory...
Posts: 21
Threads: 2
Joined: Jul 2017
Reputation:
0
Can u tell me which forum is it?(here or pm)