ESOUI

ESOUI (https://www.esoui.com/forums/index.php)
-   News (https://www.esoui.com/forums/forumdisplay.php?f=5)
-   -   Malicious code in Atlas (https://www.esoui.com/forums/showthread.php?t=2493)

Sasky 01/16/15 08:04 PM

Quote:

Originally Posted by BornDownUnder (Post 18280)
I full agree, there should be no place at all for people like that in any community, in the real world it is called fraud. There should be no difference in stance at all in any format just because this happened in a game.

Out of curiosity, what was the decision made and actions taken as a result of this incident?

I'm not sure the user on the ESOUI site was banned. However, it wouldn't make as much of a difference since account creation isn't tied to $$ like an account name. Also, I don't think the user has posted anything (forums or addons) since then.

On the ZOS side, they refunded the gold. After discussing with users and addon devs here (and I think the main site too), they implemented the confirmation box for sending mail with gold or attachments. They could have more drastically gutted the API for addons, but kept as much around for legitimate addons while still protecting users from this sort of action.

Quote:

Originally Posted by Cerulean2013 (Post 18281)
I know people are complaining to this forum that he should be banned, but has anyone reported him to Zenimax?

If not people who were effected should report them.

I reported the account name to Zenimax. (For better or worse, I was probably one of the first people affected by it.) The @name was in the code directly to read, so it was fairly simple to find where the gold went. ZOS has a policy to not comment on banning/etc.

It's good policy to not comment on those, especially on something that can be as volatile as forums. Consider that there's no link established between ESOUI and an account name. While anyone who knows Lua can establish that the addon was deliberate and malicious, it's really not known who made it. The @name could've been someone else entirely that was being framed. Then again, they were rather sloppy in adding the code so perhaps they thought they'd get away with it.

Cerulean2013 01/17/15 12:08 AM

Quote:

Originally Posted by Sasky (Post 18282)
I'm not sure the user on the ESOUI site was banned. However, it wouldn't make as much of a difference since account creation isn't tied to $$ like an account name. Also, I don't think the user has posted anything (forums or addons) since then.

On the ZOS side, they refunded the gold. After discussing with users and addon devs here (and I think the main site too), they implemented the confirmation box for sending mail with gold or attachments. They could have more drastically gutted the API for addons, but kept as much around for legitimate addons while still protecting users from this sort of action.



I reported the account name to Zenimax. (For better or worse, I was probably one of the first people affected by it.) The @name was in the code directly to read, so it was fairly simple to find where the gold went. ZOS has a policy to not comment on banning/etc.

It's good policy to not comment on those, especially on something that can be as volatile as forums. Consider that there's no link established between ESOUI and an account name. While anyone who knows Lua can establish that the addon was deliberate and malicious, it's really not known who made it. The @name could've been someone else entirely that was being framed. Then again, they were rather sloppy in adding the code so perhaps they thought they'd get away with it.


Good, sorry you were effected but glad you reported. If the @name was the coder or someone who took it over doesn't really matter. In the latter case they should have taken the time to verify the code before publishing it. Anyway hopefully justice was served.

Baertram 01/17/15 09:21 PM

About the @name inside code, and reporting it:

In 99% the person getting the gold in the LUA source code would be the addon developer.
But waht if the @name inside source code was NOT the one of the "bad guy" who changed the addon, and someone poor (just pick any @name you get known ingame, what is really simple) will get all that money/stuff and doesn't know why he gets reported ;-)


All times are GMT -6. The time now is 01:47 PM.

vBulletin © 2024, Jelsoft Enterprises Ltd
© 2014 - 2022 MMOUI