Closed DanJF closed 2 years ago
We have found a person, in our logs from 18.5.2022, who has used the same name, he has been banned on The Happy Traitor for the longest time, number 163/706 bans, I can't be 100% sure if this is the same guy so obviously it would be careless for me to publish he's steamid, how ever if you want the steam id that we have identified as a potential hacker, please contact me in steam. And Regalis can contact me via email, if it is of interest to them.
Tested, working correctly. Closing.
For the record, the commit that fixes the issue is https://github.com/Regalis11/Barotrauma-development/commit/53c1aa26d4e8d22d6a258077a64352a980e2021b
Disclaimers
What happened?
Hosting a Campaign game, custom sub. (ECN Rockfish MkII [Campaign])
No Jovian radation, 3mission cap. Hosting a game via the Menu option for "Host Game" PUBLIC server, because I typically thrive on that environment, and generally believe in not having walled-community servers in an effort to expose more players to the game.
To the point: Russian player was, somehow, able to assign themselves ban-permissions through my Client name.
The Deep Dank Depths - Campaign Edition_2022-05-22_1445 (2).txt
Here is the specific moment from the log: [5/22/2022 2:33:43 PM] Client "Bonzo" set the permissions of the client "ватник гопник" to Ban
Hypothesis : because I was playing as a client, and hosting, there is communication between the client and host apps. Man in the middle attack could be likely? The bigger issue : I witnessed what happened and was aware of it in the moment (concerned I as host would be banned next (which brings another question: what would happen if a host got banned from their own IP?)), and logically went to the banlist txt in the baro directory, and cleared out my friend's (rizzjag) ban. However when he tried to join again (after we both restarted Baro), he was stuck on the "connecting..." notice, and so it's sort of turned into some strange sort of "phantom-ban"
This is an issue because it demonstrates that all public servers are potentially compromised to this same issue.
I would hope it is not a "targeted event" but in the log they also asked, [5/22/2022 2:31:15 PM] ватник гопник: USA?
But! If you also examine and translate the things player "Useless" said...they were another Russian player, who was aware of this troll, and trying to vie for peace. The world we live in is complicated, certainly.
So hopefully this is not in any way directly related to current relations with Finland and NATO, and by extension of nato the USA...but in all my time playing Baro since first release in 2014, I've never heard, seen, nor experienced anything quite like this of clients giving themselves admin permissions. Seems perhaps like one rogue person taking out aggression.
Server files to follow :
The Deep Dank Depths - Campaign Edition_2022-05-22_1445 (2).txt The Deep Dank Depths - Campaign Edition_2022-05-22_1445.txt
I'm on the outside looking in but, hopefully this report still helps. Thanks for your work, and best wishes.
Reproduction steps
No response
Bug prevalence
Just once
Version
0.17.15.0
-
No response
Which operating system did you encounter this bug on?
Windows
Relevant error messages and crash reports